Network surveying and mapping behavior defense alarm method and system
By constructing a mapping feature dataset and implementing differentiated defense measures, the problem of insufficient accurate detection and defense strategies for network mapping behavior in existing technologies has been solved. This has enabled accurate detection and differentiated defense against network mapping behavior, thereby improving network security protection capabilities.
Patent Information
- Application Number
- CN202511106208.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-07
- Publication Date
- 2025-12-12
AI Technical Summary
Existing cybersecurity behavioral defense technologies are unable to accurately detect scanning risks, lack in-depth intent analysis and differentiated defense strategies, making it difficult to effectively respond to cybersecurity threats.
By constructing a mapping feature dataset, accurately matching scanning behavior, generating hierarchical alarm events, performing aggregation analysis and target identification, and combining honeypot network redirection and device fingerprint spoofing differentiated defense measures, targeted defense against different threat levels can be achieved.
It enables accurate detection and differentiated defense against network mapping activities, significantly improving network security protection capabilities, reducing the security risks of malicious mapping activities, and ensuring the stable operation of network systems.
Smart Images

Figure CN121125166A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network mapping behavior defense technology, specifically to a network mapping behavior defense alarm method and system. Background Technology
[0002] In today's digital age, cyberspace has become a crucial platform for information exchange, business activities, and social services, making its security issues increasingly prominent. Network mapping, as a key technology for cyberspace situational awareness, is widely used in network security protection, network planning and optimization, and network resource management. Network mapping primarily involves using various scanning tools to probe and collect information about network devices, services, and topology, providing data support for subsequent network analysis and security assessments. With the rapid development of network technology, network mapping tools and methods are constantly being innovated, significantly improving scanning efficiency and accuracy, enabling the rapid and comprehensive acquisition of various types of network information. However, network mapping also brings numerous security risks. Some malicious mapping activities may be exploited by hackers as preliminary reconnaissance tools for network attacks, providing crucial information for subsequent intrusion, data theft, and service disruption attacks, seriously threatening the security and stability of network systems.
[0003] Existing network mapping behavior defense technologies mainly focus on the simple detection and blocking of scanning behavior, such as restricting scanning traffic through firewall rules and intrusion detection systems based on specific scanning characteristics. While these methods can prevent some scanning behavior to a certain extent, they have many shortcomings. Summary of the Invention
[0004] The purpose of this invention is to provide a network mapping behavior defense alarm method and system, which is used to accurately detect and analyze network mapping behavior and implement differentiated defense alarms, thereby effectively resisting the threat of malicious mapping behavior to network security and ensuring the safe and stable operation of the network system.
[0005] To achieve the above objectives, this invention provides a network mapping behavior defense alarm method, comprising: collecting network traffic mirroring data, device logs, and external mapping intelligence to construct a mapping feature dataset; based on the mapping feature dataset, matching scanning behaviors through a preset mapping tool fingerprint database, and generating hierarchical alarm events according to the scanning density and target sensitivity of the matched scanning behaviors; performing aggregate analysis on the hierarchical alarm events, and generating behavior combination features based on the aggregate analysis results; performing intent characterization on the behavior combination features through a preset behavior rule database, and generating a mapping intent analysis report; and executing differentiated defense alarms including honeypot network redirection and device fingerprint spoofing based on the mapping intent analysis report.
[0006] Optionally, the step of collecting network traffic mirror data, device logs, and external mapping intelligence to construct a mapping feature dataset includes: collecting network traffic mirror data and extracting scanning protocol features and device fingerprint information through a protocol parsing engine; simultaneously collecting device logs and external mapping intelligence and labeling target assets; labeling the target exposure status and scanning source threat level based on the external mapping intelligence; and integrating the scanning protocol features, device fingerprint information, target asset labeling results, target exposure status, and scanning source threat level through a feature fusion engine to construct a mapping feature dataset.
[0007] Optionally, the step of matching scanning behaviors based on the mapping feature dataset and a preset mapping tool fingerprint database, and generating graded alarm events according to the scanning density and target sensitivity of the matched scanning behaviors, includes: parsing the scanning protocol features and device fingerprint information in the mapping feature dataset; using the preset mapping tool fingerprint database, performing protocol behavior feature matching based on the scanning protocol features, and performing payload content feature matching based on the device fingerprint information to determine the scanning behavior type; based on the mapping feature dataset, counting the number of Internet protocol addresses scanned by a single scanning source within a unit time window; when the number of Internet protocol addresses scanned within the unit time window exceeds a preset density threshold, marking this scanning behavior as a high-density scanning behavior; while counting the number of Internet protocol addresses scanned within the unit time window, simultaneously calculating the total number of communication ports detected by a single target asset; when the total number of detected communication ports exceeds a preset breadth threshold, determining this scanning behavior as a deep mapping behavior.
[0008] Optionally, the step of matching scanning behaviors with a preset surveying tool fingerprint database based on the surveying feature dataset, and generating graded alarm events according to the scanning density and target sensitivity of the matched scanning behaviors, further includes: calculating the target object sensitivity coefficient based on the network topology hierarchy annotation in the surveying feature dataset; and generating alarm events with predefined risk levels based on the scan behavior type, high-density scan behavior markers, depth surveying behaviors, and target object sensitivity coefficients, according to set graded alarm rules.
[0009] Optionally, the step of performing aggregate analysis on the hierarchical alarm events and generating behavioral combination features based on the aggregate analysis results includes: performing aggregate analysis on the hierarchical alarm events through spatial aggregation and target aggregation; the spatial aggregation includes merging continuous network address segments scanned by the same attack source within a set time window and detecting cross-routing domain behavior; the target aggregation includes identifying multi-source collaborative scans targeting the same target asset and constructing an asset dependency topology map.
[0010] Optionally, the step of defining the intent of the behavior combination features through a preset behavior rule base and generating a mapping intent analysis report includes: extracting behavior combination features; traversing the behavior rule base to match the behavior combination features, and generating an intent determination label and response strategy code after a successful match; and generating a mapping intent analysis report based on the intent determination label and the response strategy code.
[0011] Optionally, the threat level in the mapping intent analysis report includes low risk, medium risk, and high risk.
[0012] Optionally, the step of executing differentiated defense alerts based on the mapping intent analysis report, which includes honeypot network redirection and device fingerprint spoofing, includes: when the threat level is low risk, executing device fingerprint spoofing, sending fake service version information to the scanning source, and blocking the real device response; when the threat level is medium risk, redirecting scanning traffic to a pre-configured honeypot node through dynamic route hijacking, wherein the honeypot node simulates a complete forged fingerprint of the target asset; when the threat level is high risk, hijacking scanning traffic to a distributed honeypot cluster, calculating the honeypot request growth rate in real time, and immediately switching the honeypot instance and updating the global forged fingerprint of the cluster when the honeypot request growth rate exceeds a set growth rate threshold.
[0013] Optionally, the step of executing differentiated defense alarms based on the mapping intent analysis report, which includes honeypot network redirection and device fingerprint spoofing, further includes: continuously monitoring the target asset traffic status, detecting whether the scanning behavior has completely stopped and all deep mapping features have disappeared, and marking the deception defense as successful when it is confirmed that the scanning traffic has returned to zero and there are no deep mapping traces; and simultaneously parsing the honeypot captured traffic, extracting attack chain feature parameters, and generating a defense execution report.
[0014] On the other hand, the present invention provides a network mapping behavior defense alarm system for implementing a network mapping behavior defense alarm method. The system includes a control module, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the network mapping behavior defense alarm method.
[0015] The above technical solution, by constructing a mapping feature dataset, accurately matches scanning behavior and generates tiered alarm events, enabling accurate assessment of the risk level of scanning behavior and avoiding misjudgments. Aggregate analysis and intent identification functions delve deeper into scanning intent, making defense more targeted. Differentiated defense alarm measures, such as device fingerprint spoofing and honeypot network redirection, effectively address mapping behaviors with different threat levels, ensuring normal network operation while significantly improving network security protection capabilities and reducing the security risks posed by malicious mapping behavior.
[0016] Other features and advantages of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0017] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the following detailed description to explain the invention, but do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of the network mapping behavior defense alarm method.
[0018] Figure 2 This is a flowchart of adaptive honeypot defense based on threat level. Detailed Implementation
[0019] The following is in conjunction with the appendix Figure 1 -Appendix Figure 2 The specific implementation methods of the embodiments of the present invention will be described in detail below. It should be understood that the specific implementation methods described herein are only for illustrating and explaining the embodiments of the present invention, and are not intended to limit the embodiments of the present invention.
[0020] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application all comply with the relevant provisions of national laws and regulations. In the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.
[0021] In the process of realizing this invention, the inventors of this application discovered that the prior art has problems with insufficient accuracy in scanning behavior detection, insufficient depth of intent analysis, and insufficient differentiated defense strategies, and is unable to accurately judge the risks of scanning behavior and take targeted defense measures.
[0022] Example 1 Reference Figures 1-2 This is the first embodiment of the present invention, which provides a network mapping behavior defense alarm method, including: S100: Collects network traffic mirroring data, device logs, and external mapping intelligence to construct a mapping feature dataset.
[0023] Furthermore, network traffic mirroring data is collected, and scanning protocol features and device fingerprint information are extracted through a protocol parsing engine; device logs and external mapping intelligence are collected simultaneously, and target assets are labeled; the target exposure status and scanning source threat level are labeled based on the external mapping intelligence; through a feature fusion engine, the scanning protocol features, the device fingerprint information, the target asset labeling results, the target exposure status, and the scanning source threat level are integrated to construct a mapping feature dataset.
[0024] Specifically, raw network traffic is captured through mirrored ports to ensure complete network data packets are obtained. Encrypted traffic in the collected raw traffic must be decrypted in accordance with corporate security policies (decryption must meet regulatory requirements, such as anonymizing user privacy data). Deep protocol analysis is performed on the collected raw traffic to extract scanning protocol features, including but not limited to ICMP Echo requests (Internet Control Message Protocol Echo) (Type 8 messages), TCP SYN (TCP Synchronization Scan), and DNS (Domain Name System) domain transfer requests. At the same time, device fingerprint information is extracted, such as device model and version information in protocols such as HTTP (Hypertext Transfer Protocol), SMTP (Simple Mail Transfer Protocol), and SNMP (Simple Network Management Protocol), to identify the device type and specific version in the target network.
[0025] Furthermore, log information generated by key devices (such as firewalls and routers) is collected synchronously. These logs provide detailed records of device operating status, security events, and network traffic. External mapping intelligence (such as scanning records from platforms like the National Information Security Vulnerability Sharing Platform and the National Internet Emergency Center) is introduced to obtain the characteristics and behavioral patterns of known scanning sources, enriching the understanding and identification capabilities of network mapping behavior.
[0026] Furthermore, by combining the collected device logs and external mapping intelligence, the target assets are labeled in detail, including the mapping relationship between open ports and services (such as port 80 corresponding to the Apache 2.4.52 server), as well as the hierarchical position of the device in the network topology (such as core layer routers, access layer switches, etc.), in order to more accurately identify and assess the importance and exposure risks of the target assets.
[0027] Furthermore, based on external mapping intelligence, the exposure status of target assets is assessed and labeled to determine their visibility and potential risks in the network; at the same time, the threat level of scanning sources is assessed and labeled to distinguish the potential harm level of different scanning sources.
[0028] Furthermore, by utilizing a feature fusion engine, multi-dimensional data such as scanning protocol features, device fingerprint information, target asset annotation results, target exposure status, and scanning source threat level are integrated and fused to construct a complete mapping behavior feature dataset. This dataset contains key fields such as source IP, target IP, protocol, port, service version, device type, and network layer, comprehensively reflecting the characteristics and attributes of network mapping behavior.
[0029] Preferably, the above-mentioned multi-source heterogeneous data fusion (traffic mirroring, device logs, external intelligence) constructs a full-dimensional mapping feature dataset containing scanning protocol characteristics, device fingerprint information, target asset annotation, and threat level, significantly improving the completeness and accuracy of network mapping behavior identification. Encrypted traffic decryption and anonymization ensure compliance and avoid the risk of data leakage; target asset annotation and exposure status assessment provide a key foundation for subsequent risk quantification, enabling the defense system to focus on high-value assets and vulnerable links.
[0030] S200: Based on the surveying feature dataset, the scanning behavior is matched through a preset surveying tool fingerprint database, and a graded alarm event is generated according to the scanning density and target sensitivity of the matched scanning behavior.
[0031] Furthermore, the scanning protocol features and device fingerprint information in the mapping feature dataset are analyzed; using a preset mapping tool fingerprint database, protocol behavior feature matching is performed based on the scanning protocol features, and payload content feature matching is performed based on the device fingerprint information to determine the scanning behavior type; based on the mapping feature dataset, the number of Internet protocol addresses scanned by a single scanning source within a unit time window is counted; when the number of Internet protocol addresses scanned within the unit time window exceeds a preset density threshold, this scanning behavior is marked as a high-density scanning behavior; while counting the number of Internet protocol addresses scanned within the unit time window, the total number of communication ports detected by a single target asset is simultaneously calculated; when the total number of detected communication ports exceeds a preset breadth threshold, this scanning behavior is determined to be a depth mapping behavior.
[0032] Specifically, the scanning protocol features previously extracted and recorded by the protocol parsing engine are parsed from the mapping feature dataset. These features include the characteristics of various scanning packets such as ICMP Echo requests, TCP SYN, and DNS domain transfer requests, thus obtaining the device fingerprint information contained in the mapping feature dataset. The extracted scanning protocol features are compared with a preset mapping tool fingerprint database. For example, if a large number of SYN (Synchronize Sequence Numbers) packets are detected without subsequent ACK (Acknowledgment) packets, the fingerprint of Nmap-sS (TCP half-open scan) can be matched by combining other features. Similarly, if a pattern of sending DNS queries at fixed intervals is found, it matches the tool fingerprint of Zmap (full network segment scan), thereby determining the type of tool used for the scanning behavior.
[0033] Furthermore, based on the device fingerprint information, it is also matched with the payload content characteristics in the preset surveying tool fingerprint database. Different surveying tools may carry payloads with specific formats or content during scanning. By analyzing and comparing these payload contents, the scanning behavior type can be further confirmed, improving the accuracy of identification.
[0034] Furthermore, based on the mapping feature dataset, the number of Internet Protocol addresses (IPs) scanned by a single scanning source within a unit time window (e.g., 1 minute) is counted. If this number exceeds a preset density threshold (e.g., 500 per minute), the scanning behavior is marked as a high-density scanning behavior, indicating that the scanning source has scanned a large number of IP addresses in a short period of time, which may pose a high risk.
[0035] Preferably, while counting the number of IPs scanned within a unit time window, the total number of communication ports probed for a single target asset is calculated simultaneously. If the total number of probed communication ports exceeds a preset breadth threshold (e.g., 100 ports), the scanning behavior is determined to be a depth mapping behavior, meaning that the scanning source has conducted a relatively in-depth and comprehensive port probe on a single target asset, and the intent may be more complex and dangerous.
[0036] Furthermore, based on the network topology hierarchy annotations in the mapping feature dataset, the sensitivity coefficient of the target object is calculated; based on the scanning behavior type, high-density scanning behavior marker, depth mapping behavior, and the sensitivity coefficient of the target object, alarm events with predefined risk levels are generated according to the set hierarchical alarm rules.
[0037] Specifically, based on the network topology hierarchy labels centrally recorded in the mapping feature dataset, the importance and sensitivity of target assets are assessed. For example, critical assets such as core layer routers and main database servers have higher sensitivity coefficients, while relatively peripheral assets such as access layer switches have lower sensitivity coefficients. Using predefined algorithms (such as the AHP-TOPSIS composite evaluation method or the analytic hierarchy process-approximation ideal solution ranking method composite evaluation method) or rules, the target asset's location, function, and the services it carries within the network are comprehensively considered to calculate the target object sensitivity coefficient (TARQ), which is used to measure the potential risks of scanning behavior.
[0038] Furthermore, the tiered alarm rules are set as shown in Table 1.
[0039]
[0040]
[0041] Furthermore, by matching scanning behavior type, high-density markers, depth mapping markers, and TARQ values, and based on the hierarchical alarm rule table, structured alarm events with predefined risk levels (low risk / medium risk / high risk) are generated. These alarm events automatically include risk level fields and trigger condition evidence chains (such as protocol characteristics, number of ports, and TARQ values).
[0042] Preferably, the aforementioned dual-mode matching mechanism (protocol behavior features + payload content features) based on the mapping tool fingerprint database can accurately identify the fingerprint features of mainstream scanning tools such as Nmap and Zmap. By combining scanning density (number of IPs / time window) and depth mapping (port breadth) indicators, dynamic classification of scanning behavior is achieved. By introducing the Network Topology Sensitivity Coefficient (TARQ), the quantification of asset importance is integrated into risk assessment, making alarm classification more aligned with actual business scenarios and significantly reducing false alarm and false negative rates.
[0043] S300: Perform aggregate analysis on the hierarchical alarm events and generate behavioral combination features based on the aggregate analysis results.
[0044] Furthermore, the hierarchical alarm events are aggregated and analyzed through spatial aggregation and target aggregation; the spatial aggregation includes merging continuous network address segments scanned by the same attack source within a set time window and detecting cross-routing domain behavior; the target aggregation includes identifying multi-source collaborative scans targeting the same asset and constructing an asset dependency topology map.
[0045] Specifically, when performing aggregated analysis on graded alarm events, spatial aggregation is first used, with a 24-hour time window. Then, within this time window, alarm records with the same source IP address are filtered from network mapping behavior alarm events with risk levels. The target IP address of the record is analyzed, and based on CIDR (Classless Inter-Domain Routing) rules, the target IP addresses scanned by the source IP are merged into contiguous network segments. Simultaneously, it is checked whether the source IP scans multiple subnets across routing domain boundaries (e.g., 10.0.0.0 / 8 and 172.16.0.0 / 12). If it scans multiple subnets across routing domain boundaries, it is marked as cross-routing domain behavior. Subsequently, target aggregation is used to correlate core asset information, and the frequency of the same core asset (e.g., a database server) being scanned by different source IPs within one hour is counted to identify multi-source collaborative scanning behavior (e.g., multiple IPs initiating TCP attacks on the same target). SYN scanning is performed, and combined with data such as firewall logs, the communication relationships of the target device are extracted. If the mapping behavior covers ≥70% of the dependent nodes (such as simultaneously scanning databases, application servers, and load balancers), it is determined to be critical path mapping. The spatial aggregation scanning range (such as cross-routing domain network segments) is combined with the target aggregation collaborative detection mode (such as multi-source scanning of core assets) to obtain behavioral combination characteristics (such as cross-domain collaborative scanning of core paths, high-density scanning of asset groups, and in-depth mapping of critical infrastructure).
[0046] Preferably, the above-mentioned spatial aggregation and target aggregation can reveal concealed distributed mapping patterns. For example, the combined characteristics of cross-network segment scanning and multi-source detection of core assets can effectively identify early reconnaissance behaviors in APT attacks, transform fragmented alerts into high-level threat clues, and provide a macro-level attack path analysis for defense decisions.
[0047] S400: The intention of the behavioral combination features is defined by a preset behavioral rule base, and a mapping intention analysis report is generated.
[0048] Furthermore, behavioral combination features are extracted; the behavioral rule base is traversed to match the behavioral combination features, and upon successful matching, an intent determination label and a response strategy code are generated; based on the intent determination label and the response strategy code, a mapping intent analysis report is generated.
[0049] Furthermore, the threat levels in the mapping intent analysis report include low risk, medium risk, and high risk.
[0050] Specifically, the system uses a pre-defined behavioral rule base to characterize input behavioral combinations. First, it extracts the names of the behavioral combination features and then iterates through the predefined rules in the rule base for precise matching. When a behavioral combination feature name matches a rule entry, the corresponding intent determination label and response strategy code are automatically output. Threat levels are determined based on the risk levels in the tiered alert rule table. If the risk level in the tiered alert rule table is low risk, the threat level is also low risk; similarly, medium and high risk are determined. Finally, a mapping intent analysis report is generated. Its core fields inherit from the matching results and associated data, including key attack source IPs (the top 5 most active source IPs), high-risk assets (automatically associated scanned core devices), the identified intent determination labels, response strategy codes, and threat levels. This process relies strictly on the predefined rule base for automated decision-making and requires no manual intervention.
[0051] Preferably, the above-mentioned method utilizes a preset behavioral rule base to automatically characterize combined features, mapping complex attack patterns into executable threat tags and associating them with dynamic response strategy codes. This mechanism achieves intelligent binding between threat levels and defensive actions, significantly shortening the closed-loop time from detection to response. Simultaneously, the generated intent analysis report provides a structured chain of evidence to support subsequent source tracing and countermeasures.
[0052] S500: Based on the mapping intent analysis report, execute differentiated defense alerts including honeypot network redirection and device fingerprint spoofing.
[0053] Furthermore, when the threat level is low-risk, device fingerprint spoofing is performed, sending disguised service version information to the scanning source while blocking the real device from responding; when the threat level is medium-risk, scanning traffic is redirected to a pre-configured honeypot node through dynamic routing hijacking, the honeypot node simulating a complete forged fingerprint of the target asset; when the threat level is high-risk, scanning traffic is hijacked to a distributed honeypot cluster, the honeypot request growth rate is calculated in real time, and when the honeypot request growth rate exceeds the set growth rate threshold, the honeypot instance is immediately switched and the global forged fingerprint of the cluster is updated.
[0054] Specifically, when the threat level is low risk, a low-risk alert is issued. A low-risk alert includes executing device fingerprint spoofing, sending pre-defined masquerading service information (such as changing the actual operating system to a disabled version) to the scanning source, and simultaneously triggering firewall rules to block the real device's response, ensuring that attackers can only obtain fake fingerprints.
[0055] When the threat level is medium risk, a medium risk alert is issued. The medium risk alert includes automatically activating dynamic route hijacking, which redirects scan traffic to a pre-configured honeypot node via a border protocol. This honeypot node completely clones the device fingerprint of the target asset (including port response characteristics, protocol interaction behavior, and system identifier), constructing a highly realistic interactive environment.
[0056] When the threat level is high, a high-risk alert is issued. This alert includes forcibly hijacking traffic to a distributed honeypot cluster, initializing a three-node honeypot pool (A / B / C), and calculating the request growth rate per minute in real time. Once the growth rate exceeds the set threshold of 50%, the system immediately switches to a backup node (e.g., A→B) and globally updates the forged fingerprint (e.g., by changing the firewall system), completely disrupting the attacker's mapping continuity.
[0057] Furthermore, continuously monitor the target asset traffic status, detect whether the scanning behavior has completely stopped and all depth mapping features have disappeared. When it is confirmed that the scanning traffic has returned to zero and there are no depth mapping traces, mark the deception defense as successful; simultaneously analyze the traffic captured by the honeypot, extract the attack chain feature parameters, and generate a defense execution report.
[0058] Specifically, during the defense process, the original target assets are continuously monitored. When the scan traffic remains at zero for more than 5 minutes and the deep mapping characteristics (such as vulnerability probe packets and domain transfer requests) completely disappear for 30 minutes, the deception defense is considered successful. Simultaneously, the traffic captured by the honeypot is analyzed to extract the scanning tool fingerprint (through TCP window / TTL value matching), attack commands (by parsing HTTP header parameters), and vulnerability exploitation traces (such as SQL injection signatures; SQL is a structured query language). A defense execution report containing response action records, attack chain analysis, and validity verification is generated.
[0059] Preferably, the strength or type of the defense strategy can be adjusted based on the defense execution report, and the mapping tool fingerprint database or behavior rule database can be updated based on the attacker behavior captured by the honeypot.
[0060] Preferably, the aforementioned threat-level-based differentiated defense system achieves optimal resource allocation. At low risk, it misleads attackers by forging device fingerprints; at medium risk, it dynamically hijacks routes to highly realistic honeypots; and at high risk, a distributed honeypot cluster collaboratively counters large-scale scanning. By consuming attack resources through traffic redirection and disrupting mapping continuity through a real-time fingerprint update mechanism, it protects real assets while proactively collecting attacker characteristics, forming a "detection-deception-countermeasure" defense.
[0061] The present invention also provides a network mapping behavior defense alarm system for implementing a network mapping behavior defense alarm method. The system includes a control module, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the network mapping behavior defense alarm method.
[0062] This invention provides a storage medium storing a program that, when executed by a processor, implements the network mapping behavior defense alarm method.
[0063] This invention provides a processor for running a program, wherein the program executes the network mapping behavior defense alarm method during runtime.
[0064] This invention provides a device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements a network mapping behavior defense alarm method. The device described herein can be a server, PC, PAD, mobile phone, etc.
[0065] This application also provides a computer program product that, when executed on a data processing device, is suitable for performing a network mapping behavior defense alarm method.
[0066] Those skilled in the art will understand that embodiments of this application can provide methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0067] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0068] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0069] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0070] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0071] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0072] Computer-readable media include both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0073] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0074] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A network mapping behavior defense alarm method, characterized in that, include: Collect network traffic mirroring data, device logs, and external mapping intelligence to construct a mapping feature dataset; Based on the mapping feature dataset, scanning behavior is matched using a preset mapping tool fingerprint database, and graded alarm events are generated according to the scanning density and target sensitivity of the matched scanning behavior. The hierarchical alarm events are aggregated and analyzed, and behavioral combination features are generated based on the aggregation analysis results; The intention analysis report is generated by defining the combined behavioral features using a preset behavioral rule base. Based on the mapping intent analysis report, execute differentiated defense alerts that include honeypot network redirection and device fingerprint spoofing.
2. The network mapping behavior defense alarm method according to claim 1, characterized in that, The collection of network traffic mirroring data, device logs, and external mapping intelligence is used to construct a mapping feature dataset, including: Collect network traffic mirror data and extract scanning protocol features and device fingerprint information through a protocol parsing engine; Simultaneously collect equipment logs and external surveying intelligence, and mark target assets; Based on the external mapping intelligence, the target exposure status and the threat level of the scanning source are marked; By using a feature fusion engine, the scanning protocol features, device fingerprint information, target asset annotation results, target exposure status, and scanning source threat level are integrated to construct a mapping feature dataset.
3. The network mapping behavior defense alarm method according to claim 1, characterized in that, The step of matching scanning behaviors based on the surveying feature dataset and a preset surveying tool fingerprint database, and generating graded alarm events according to the scanning density and target sensitivity of the matched scanning behaviors, includes: Analyze the scanning protocol features and device fingerprint information in the mapping feature dataset; By using a preset mapping tool fingerprint database, the scanning behavior feature is matched according to the scanning protocol characteristics, and the payload content feature is matched according to the device fingerprint information to determine the scanning behavior type. Based on the aforementioned mapping feature dataset, the number of Internet Protocol addresses scanned by a single scanning source within a unit time window is counted. When the number of Internet Protocol addresses scanned within the unit time window exceeds a preset density threshold, the scanning behavior is marked as a high-density scanning behavior. When counting the number of Internet Protocol addresses scanned within the unit time window, the total number of communication ports probed for a single target asset is calculated simultaneously. When the total number of detected communication ports exceeds a preset breadth threshold, the scanning behavior is determined to be a depth mapping behavior.
4. The network mapping behavior defense alarm method according to claim 3, characterized in that, The step of matching scanning behaviors with a preset surveying tool fingerprint database based on the surveying feature dataset, and generating graded alarm events according to the scanning density and target sensitivity of the matched scanning behaviors, further includes: Calculate the sensitivity coefficient of the target object based on the network topology hierarchy annotation in the mapping feature dataset; Based on the scanning behavior type, high-density scanning behavior marker, depth mapping behavior, and target object sensitivity coefficient, alarm events with predefined risk levels are generated according to the set hierarchical alarm rules.
5. The network mapping behavior defense alarm method according to claim 1, characterized in that, The aggregation analysis of the hierarchical alarm events, and the generation of behavioral combination features based on the aggregation analysis results, includes: The hierarchical alarm events are aggregated and analyzed through spatial aggregation and target aggregation; The spatial aggregation includes merging consecutive network address ranges scanned by the same attack source within a set time window and detecting cross-routing domain behavior; The target aggregation includes identifying multi-source collaborative scans targeting the same target asset and constructing an asset dependency topology graph.
6. The network mapping behavior defense alarm method according to claim 1, characterized in that, The step of defining the intent of the behavioral combination features using a preset behavioral rule base and generating a mapping intent analysis report includes: Extract behavioral combination features; The behavior rule base is traversed to match the behavior combination features. If a match is successful, an intent determination label and a response strategy code are generated. A mapping intent analysis report is generated based on the intent determination label and the response strategy encoding.
7. The network mapping behavior defense alarm method according to claim 1, characterized in that, The threat levels in the mapping intent analysis report are categorized as low risk, medium risk, and high risk.
8. The network mapping behavior defense alarm method according to claim 7, characterized in that, Based on the mapping intent analysis report, the execution of differentiated defense alerts, including honeypot network redirection and device fingerprint spoofing, includes: When the threat level is low risk, device fingerprint spoofing is performed, and fake service version information is sent to the scanning source, while blocking the real device from responding. When the threat level is medium risk, scanning traffic is directed to a pre-configured honeypot node through dynamic routing hijacking. The honeypot node simulates a complete forged fingerprint of the target asset. When the threat level is high risk, the scanning traffic is hijacked to the distributed honeypot cluster, the honeypot request growth rate is calculated in real time, and when the honeypot request growth rate exceeds the set growth rate threshold, the honeypot instance is switched immediately and the global fake fingerprint of the cluster is updated.
9. The network mapping behavior defense alarm method according to claim 1, characterized in that, The step of executing differentiated defense alerts based on the mapping intent analysis report, which includes honeypot network redirection and device fingerprint spoofing, also includes: Continuously monitor the target asset traffic status, detect whether the scanning behavior has completely stopped and all depth mapping features have disappeared. When it is confirmed that the scanning traffic has returned to zero and there are no depth mapping traces, mark the deception defense as successful. Synchronously analyze the traffic captured by the honeypot, extract attack chain characteristic parameters, and generate a defense execution report.
10. A network mapping behavior defense alarm system, characterized in that, The system includes a control module, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the network mapping behavior defense alarm method according to any one of claims 1-9.
Citation Information
Cited By
Network space anti-mapping method, device, equipment and medium
CN122053184A