Network attack protection method and device, computer equipment and readable storage medium

By constructing target association information and interactive honeypot models, the problem of insufficient deception in existing honeypots is solved, achieving flexible and realistic network responses and improving protection effectiveness.

CN121333633APending Publication Date: 2026-01-13CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511336472.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Existing low-interaction and medium-interaction honeypots are less deceptive when dealing with network attacks, making it difficult to engage in highly dynamic and realistic real-time interactions with attackers and thus easily identifiable.

Method used

By obtaining current attack commands from the attacker's interaction with the network, and combining the correlation information of the attack database and attack knowledge graph, target correlation information is constructed. The target interaction honeypot model is used to simulate network response, reducing the reliance on preset response rules and enhancing deception.

Benefits of technology

It enhances the deception against attackers, enables flexible and realistic network responses, reduces reliance on preset rules, and strengthens the protection effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333633A_ABST
    Figure CN121333633A_ABST
Patent Text Reader

Abstract

The invention relates to a network attack protection method and device, computer equipment and a readable storage medium, and relates to the technical field of network protection. The method comprises the following steps: acquiring a current attack command of an attacker aiming at a network from a current interaction behavior of the attacker and the network; obtaining first associated information of the current attack command from each piece of attack data of the attack database, obtaining second associated information of the current attack command from the attack knowledge graph, and screening out third associated information of the current attack command from the first associated information and the second associated information; combining historical interaction information of historical interaction behaviors between the attacker and the network, the current attack command and the third association information to obtain target association information of the current attack command; and according to the target association information and the target interaction honeypot model, simulating a network response of the network to the current attack command to generate a target response, and returning the target response to the attacker. By adopting the method, the fraudulence of attackers can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network protection, in particular to a network attack protection method and device, computer equipment, computer readable storage medium and computer program product. BACKGROUND

[0002] With the increasing complexity and diversification of network attack means, traditional passive defense mechanisms have been difficult to effectively respond. As an active defense technology, honeypot simulates real computer systems or services to lure, deceive and analyze attacker behavior, thereby protecting real assets while collecting threat intelligence.

[0003] Honeypot is usually divided into low-interaction honeypot, medium-interaction honeypot and high-interaction honeypot according to its interaction complexity. The low-interaction honeypot can only provide a preset fixed response, is easy to deploy but has poor authenticity and is easily identified by skilled attackers. The medium-interaction honeypot increases limited dynamic response capability on the basis of low-interaction, but still relies on preset scripts or rules and cannot flexibly respond to unknown attack means. The high-interaction honeypot uses a real operating system and application program and has high authenticity, but has high deployment and maintenance costs and the risk of being used by attackers as a stepping stone, and is not suitable for large-scale application. Therefore, low-interaction honeypot or medium-interaction honeypot is usually used for network attack protection.

[0004] However, both low-interaction honeypot and medium-interaction honeypot rely on preset response rules to some extent and are difficult to have highly dynamic and realistic real-time interaction with attackers, resulting in weak deception of attackers and easy identification by attackers. SUMMARY

[0005] Therefore, it is necessary to provide a network attack protection method, device, computer equipment, computer readable storage medium and computer program product capable of improving the deception of attackers to solve the technical problem of weak deception.

[0006] In a first aspect, the present application provides a network attack protection method, comprising:

[0007] obtaining a current attack command of an attacker against a network from current interaction behavior of the attacker and the network;

[0008] The first association information of the current attack command is obtained from each piece of attack data in an attack database, the second association information of the current attack command is obtained from an attack knowledge graph, and the third association information of the current attack command is screened out from the first association information and the second association information; each piece of attack data includes a historical attack command, a historical network response and historical user state information corresponding to a historical attack of the network;

[0009] The historical interaction information of the historical interaction behavior between the attacker and the network, the current attack command and the third association information are combined to obtain target association information of the current attack command;

[0010] According to the target association information and a target interaction honeypot model, a network response of the network to the current attack command is simulated to generate a target response, and the target response is returned to the attacker.

[0011] In one of the embodiments, the target interaction honeypot model includes preset tasks, and each of the preset tasks includes at least one of a first task, a second task, a third task and a fourth task; the first task is used to simulate a normal network response of the network to normal interaction behavior; the second task is used to maintain consistency of responses generated under different user state information; the third task is used to simulate an abnormal network response of the network to abnormal interaction behavior; and the fourth task is used to identify malicious intent in interaction behavior and generate a corresponding response.

[0012] The simulation of the network response of the network to the current attack command according to the target association information and the target interaction honeypot model to generate the target response includes:

[0013] Each of the preset tasks is executed under the target association information through the target interaction honeypot model to obtain an execution result of the target association information under each of the preset tasks.

[0014] The target response is obtained according to the execution result of the target association information under each of the preset tasks.

[0015] In one of the embodiments, the target interaction honeypot model is obtained by the following way:

[0016] An initial interaction honeypot model obtained by pre-training is obtained, and each module in the initial interaction honeypot model is determined.

[0017] A first weight is determined for each module corresponding to the initial interaction honeypot model; the first weight for each module corresponding to the initial interaction honeypot model is used to characterize the importance of the module in the initial interaction honeypot model;

[0018] A second weight is determined for each preset task corresponding to each module; the second weight for each preset task corresponding to each module is used to characterize the degree of contribution of the preset task to the module;

[0019] Based on the first weight of each module corresponding to the initial interaction honeypot model and the second weight of each preset task corresponding to each module, determine the target rank of each preset task corresponding to each module;

[0020] Based on the target rank of each module corresponding to each preset task, determine the target low-rank matrix of each preset task corresponding to each module;

[0021] Based on the target low-rank matrix of each module corresponding to each preset task, the initial interaction honeypot model is fine-tuned to obtain the target interaction honeypot model.

[0022] In one embodiment, obtaining the first association information of the current attack command from each attack data entry in the attack database includes:

[0023] Determine the current user state information corresponding to the current interaction behavior, and based on the current user state information and the current attack command, filter out at least one associated attack data that matches the current user state information and the current attack command from each of the attack data;

[0024] For each piece of associated attack data, an associated information is obtained based on the historical attack commands and historical network responses in the associated attack data.

[0025] In one embodiment, obtaining the second association information of the current attack command from the attack knowledge graph includes:

[0026] Identify each target entity in the current attack command and the target relationships between each target entity;

[0027] Traverse the attack knowledge graph and determine at least one association path that matches each of the target entities and the target relationships from the attack knowledge graph; each association path includes each of the nodes that match each of the target entities and each of the connecting edges that match the target relationships;

[0028] For each of the associated paths, a second association information is obtained based on each of the nodes and each of the connecting edges included in the associated path.

[0029] In one embodiment, the step of filtering out the third association information of the current attack command from the first association information and the second association information includes:

[0030] Combine the first association information and the second association information to obtain each candidate association information;

[0031] Based on the historical interaction information, the current user state information corresponding to the current interaction behavior, and the attack knowledge graph, determine the matching degree between each candidate association information and the current attack command;

[0032] The candidate association information is sorted according to the matching degree from high to low to obtain the sorting result of the candidate association information;

[0033] Based on the sorting results, the third association information is selected from each of the candidate association information.

[0034] Secondly, this application also provides a network attack protection device, including:

[0035] The command acquisition module is used to acquire the attacker's current attack commands against the network from the attacker's current interaction behavior with the network;

[0036] The information acquisition module is used to acquire first association information of the current attack command from each attack data entry in the attack database, acquire second association information of the current attack command from the attack knowledge graph, and filter out third association information of the current attack command from the first and second association information. Each attack data entry includes historical attack commands, historical network responses, and historical user state information corresponding to a historical attack suffered by the network. The attack knowledge graph is constructed using sample entities in each attack data entry as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command.

[0037] The information combination module is used to combine historical interaction information of the historical interaction behavior between the attacker and the network, the current attack command, and the third association information to obtain the target association information of the current attack command.

[0038] The response generation module is used to simulate the network response of the network to the current attack command based on the target association information and the target interaction honeypot model to generate a target response and return the target response to the attacker.

[0039] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:

[0040] Obtain the attacker's current attack commands against the network from the attacker's current interaction behavior with the network;

[0041] From each attack data entry in the attack database, the first association information of the current attack command is obtained; from the attack knowledge graph, the second association information of the current attack command is obtained; and from the first and second association information, the third association information of the current attack command is selected. Each attack data entry includes the historical attack command, historical network response, and historical user state information corresponding to a historical attack suffered by the network. The attack knowledge graph is constructed using sample entities in each attack data entry as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command.

[0042] By combining the historical interaction information of the attacker's historical interaction behavior with the network, the current attack command, and the third association information, the target association information of the current attack command is obtained.

[0043] Based on the target association information and the target interaction honeypot model, the network response to the current attack command is simulated to generate a target response, and the target response is returned to the attacker.

[0044] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:

[0045] Obtain the attacker's current attack commands against the network from the attacker's current interaction behavior with the network;

[0046] From each attack data entry in the attack database, the first association information of the current attack command is obtained; from the attack knowledge graph, the second association information of the current attack command is obtained; and from the first and second association information, the third association information of the current attack command is selected. Each attack data entry includes the historical attack command, historical network response, and historical user state information corresponding to a historical attack suffered by the network. The attack knowledge graph is constructed using sample entities in each attack data entry as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command.

[0047] By combining the historical interaction information of the attacker's historical interaction behavior with the network, the current attack command, and the third association information, the target association information of the current attack command is obtained.

[0048] Based on the target association information and the target interaction honeypot model, the network response to the current attack command is simulated to generate a target response, and the target response is returned to the attacker.

[0049] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:

[0050] Obtain the attacker's current attack commands against the network from the attacker's current interaction behavior with the network;

[0051] From each attack data entry in the attack database, the first association information of the current attack command is obtained; from the attack knowledge graph, the second association information of the current attack command is obtained; and from the first and second association information, the third association information of the current attack command is selected. Each attack data entry includes the historical attack command, historical network response, and historical user state information corresponding to a historical attack suffered by the network. The attack knowledge graph is constructed using sample entities in each attack data entry as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command.

[0052] By combining the historical interaction information of the attacker's historical interaction behavior with the network, the current attack command, and the third association information, the target association information of the current attack command is obtained.

[0053] Based on the target association information and the target interaction honeypot model, the network response to the current attack command is simulated to generate a target response, and the target response is returned to the attacker.

[0054] The aforementioned network attack protection methods, devices, computer equipment, computer-readable storage media, and computer program products, by combining historical interaction information of historical interactions between the attacker and the network, current attack commands, and third-party association information obtained based on attack databases and attack knowledge graphs, can obtain target association information of the current attack command based on the historical interactions between the attacker and the network, the attacker's current attack command to the network, and the enhancement of the current attack command by historical attacks suffered by the network. Through the enhanced target association information and the target interaction honeypot model, the network attack protection method can flexibly and realistically simulate the network response by comprehensively considering the historical interactions between the attacker and the network, the attacker's current attack command to the network, and the historical attacks suffered by the network. Compared with low-interaction or medium-interaction honeypots, the network attack protection method based on the above process reduces the dependence on preset response rules and responds comprehensively based on the actual situation of the attacker and the network, such as the historical interactions between the attacker and the network, the attacker's current attack command to the network, and the historical attacks suffered by the network, thus improving the deception against attackers. Attached Figure Description

[0055] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0056] Figure 1 This is a flowchart illustrating a network attack protection method in one embodiment;

[0057] Figure 2 This is a flowchart illustrating the steps involved in fine-tuning the target interactive honeypot model in one embodiment.

[0058] Figure 3 This is a flowchart illustrating the construction and application method of an interactive honeypot system with adaptive multi-task fine-tuning and hybrid retrieval in one embodiment.

[0059] Figure 4 This is a structural block diagram of a network attack protection device in one embodiment;

[0060] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0062] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0063] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0064] In one exemplary embodiment, such as Figure 1 As shown, a network attack protection method is provided. This embodiment illustrates the method by applying it to a server. It is understood that this method can also be applied to terminals, and to systems including servers and terminals, and is implemented through interaction between the server and the terminal. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart vehicle devices, projection devices, etc. Portable wearable devices can be smartwatches, smart bracelets, head-mounted devices, etc. Head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. In this embodiment, the method includes the following steps S102 to S108:

[0065] Step S102: Obtain the attacker's current attack commands against the network from the attacker's current interaction behavior with the network.

[0066] Specifically, the server obtains the attacker's current interaction behavior with the network and extracts the attack commands launched by the attacker to the network from the current interaction behavior.

[0067] In practical applications, the server reads the attacker's current session with the network, reads the commands the attacker sends to the network from the current session, and determines whether the command is an attack command. If the command is an attack command, the server inputs the attack command into the target interactive honeypot model mounted on the server.

[0068] The target interaction honeypot model is an interaction honeypot implemented based on LLM (Large Language Model).

[0069] Step S104: Obtain the first association information of the current attack command from each attack data in the attack database, obtain the second association information of the current attack command from the attack knowledge graph, and filter out the third association information of the current attack command from the first association information and the second association information.

[0070] Each attack data entry includes the historical attack commands, historical network responses, and historical user-state information corresponding to a previous attack on the network. The historical network response can be a real response returned by the network or a simulated response returned by the target honeypot model. The user-state information describes the paths, directories, files, and network environment corresponding to the interaction behavior. In practical applications, historical attacks can be launched against the network by any attacker.

[0071] The attack knowledge graph is constructed using sample entities from each attack data entry as nodes and the relationships between these entities as edges. In practical applications, each node in the attack knowledge graph and the edges connecting them represent the attack logic corresponding to historical attacks suffered by the network.

[0072] The second set of related information includes each node and each connection edge in the attack knowledge graph that matches the current attack command.

[0073] Specifically, the server collects historical attack commands, historical network responses, and historical user state information corresponding to each historical attack on the network, and constructs an attack database and an attack knowledge graph based on the historical attack commands, historical network responses, and historical user state information corresponding to each historical attack. When the target interaction honeypot model receives an attack command input from the server, the target interaction honeypot model retrieves the associated information matching the attack command from the attack database and attack knowledge graph through multi-path recall.

[0074] For the attack database, the server uses vector retrieval to find attack data matching the current attack command from each attack data entry in the database, which serves as the first association information for the current attack command. For the attack knowledge graph, the server uses a graph traversal algorithm to identify paths matching the current attack command from the attack knowledge base, which serve as the second association information for the current attack command.

[0075] Then, the server takes the union of the first and second association information, and filters out the third association information that matches the current attack command from the union of the first and second association information.

[0076] Step S106: Combine the historical interaction information of the attacker's historical interaction behavior with the network, the current attack command, and the third-party association information to obtain the target association information of the current attack command.

[0077] Interaction information refers to the sessions corresponding to interactive behaviors. A session includes at least the commands entered by the attacker and the responses received by the attacker. In practical applications, to ensure continuity while avoiding excessively long contexts, the server employs a memory filtering strategy to remember historical interaction information. For example, it may retain only the most recent N rounds of interaction sessions, or prioritize interaction sessions that are crucial to understanding the attack intent based on factors such as command type and execution result.

[0078] Specifically, the target interaction honeypot model obtains historical sessions between the attacker and the network to obtain historical interaction information between the attacker and the network; then, the target interaction honeypot model combines historical interaction information, current attack commands, and third-party association information to construct dynamic prompts for the current attack commands to obtain target association information for the current attack commands.

[0079] In steps S104 and S106 above, firstly, the target interaction honeypot model constructs prompt words through parallel multi-path recall, enabling it to dynamically generate prompt words specifically for each attack command and ensuring that the generated prompt words do not omit any relevant information. Secondly, by combining historical interaction information between the attacker and the network, the target interaction honeypot model constructs prompt words, ensuring that the generated prompt words are not isolated or fragmented, but rather combined with a coherent attack context. This avoids logical jumps or contextual "amnesia" in the final generated target response, thus preventing it from being detected by experienced attackers.

[0080] Step S108: Based on the target association information and the target interaction honeypot model, simulate the network response to the current attack command to generate the target response and return the target response to the attacker.

[0081] Specifically, the target interaction honeypot model simulates the network response to the current attack command based on semantic understanding and text generation of target-related information to generate a target response; the server returns the target response generated by the target interaction honeypot model to the attacker to achieve real-time interaction with the attacker and protect the network from the attacker's attack.

[0082] In this step, the target interaction honeypot model implements RAG (Retrieval-augmented Generation) based on target association information.

[0083] In the aforementioned network attack protection method, the server combines historical interaction information between the attacker and the network, the current attack command, and third-party association information obtained based on the attack database and attack knowledge graph. This allows the server to enhance the current attack command based on historical interactions between the attacker and the network, the attacker's current attack command, and the historical attacks the network has suffered, thereby obtaining target association information for the current attack command. Through this enhanced target association information and the target interaction honeypot model, the server can flexibly and realistically simulate the network's response by comprehensively considering historical interactions between the attacker and the network, the attacker's current attack command, and the historical attacks the network has suffered. Compared to low-interaction or medium-interaction honeypots, this network attack protection method reduces reliance on pre-defined response rules and responds by comprehensively considering the actual situation of the attacker and the network, such as historical interactions between the attacker and the network, the attacker's current attack command, and the historical attacks the network has suffered. Therefore, it enhances the deception capability against attackers.

[0084] In an exemplary embodiment, the target interaction honeypot model includes preset tasks, each preset task including at least one of a first task, a second task, a third task, and a fourth task.

[0085] The first task is to simulate normal network responses to normal interactive behavior. In specific applications, the first task is a command response and style simulation task, used to learn standard Linux shell (a command interpreter) syntax and regular command responses.

[0086] The second task is to maintain consistency in responses generated under different user-mode information. This second task is a system state and path structure simulation task, used to generate consistent responses under different directories and permissions.

[0087] The third task is used to simulate abnormal network responses to unusual interactive behaviors. In practical applications, the third task is an anomaly and error spoofing task, used to simulate various highly realistic error messages, such as prompts for illegal input or unauthorized operations.

[0088] The fourth task is used to identify malicious intent in interactive behavior and generate corresponding responses. In specific applications, the fourth task is a security alignment and malicious intent identification task, which is used to identify and reject commands involving sensitive operations from interactive behavior and return preset, harmless security warnings or error messages.

[0089] Step S108 above, which simulates the network response to the current attack command to generate the target response based on the target association information and the target interaction honeypot model, specifically includes the following steps: executing each preset task under the target association information through the target interaction honeypot model to obtain the execution results of the target association information under each preset task; and obtaining the target response based on the execution results of the target association information under each preset task.

[0090] Specifically, the target interaction honeypot model infers and executes each preset task based on the target association information, obtains the execution results of the target association information under each preset task, and then realizes the simulation of the network response to the current attack command, and obtains the target response.

[0091] Traditional techniques typically treat honeypot interaction as a single, homogeneous task—"given a command, generate a response"—ignoring the complexity of honeypot scenarios. In this embodiment, honeypot interaction is broken down into different pre-defined tasks. Through the synergistic effect of these tasks, a highly realistic target interactive honeypot model is constructed, capable of deep understanding and precise response to complex attack behaviors, thus enhancing its deception capabilities against attackers.

[0092] like Figure 2 As shown, in an exemplary embodiment, the target interaction honeypot model is obtained in the following way:

[0093] Step S202: Obtain the pre-trained initial interaction honeypot model and determine each module in the initial interaction honeypot model.

[0094] Step S204: Determine the first weight of the initial interaction honeypot model corresponding to each module.

[0095] Step S206: Determine the second weight of each module corresponding to each preset task.

[0096] Step S208: Determine the target rank of each module corresponding to each module based on the first weight of the initial interaction honeypot model corresponding to each module and the second weight of each preset task corresponding to each module.

[0097] Step S210: Determine the target low-rank matrix for each module corresponding to each preset task based on the target rank of each module corresponding to each preset task.

[0098] Step S212: Based on the target low-rank matrix of each module corresponding to each preset task, fine-tune the initial interaction honeypot model to obtain the target interaction honeypot model.

[0099] The target interaction honeypot model is obtained by fine-tuning the initial interaction honeypot model; the target interaction honeypot model has the same structure and the same preset tasks as the initial interaction honeypot model; the initial interaction honeypot model includes multiple modules.

[0100] Each module corresponds to the first weight of the initial interaction honeypot model, which is used to characterize the importance of the module in the initial interaction honeypot model.

[0101] Each preset task corresponds to a second weight of each module, which is used to characterize the degree of contribution of the preset task to the module.

[0102] In this embodiment, the server uses a low-rank adaptive fine-tuning method to fine-tune the pre-trained initial interaction honeypot model; however, unlike the traditional low-rank adaptive fine-tuning method, the rank in this embodiment is not fixed, but is adaptively determined for different modules and different preset tasks in the initial interaction honeypot model.

[0103] Specifically, the server acquires the pre-trained initial interaction honeypot model and identifies its modules. Then, based on the importance of each module in the initial interaction honeypot model, the server determines the first weight of each module corresponding to the initial interaction honeypot model, and based on the contribution of each preset task to each module, determines the second weight of each preset task corresponding to each module. Next, based on the first weight of each module corresponding to the initial interaction honeypot model and the second weight of each preset task corresponding to each module, the server determines the target rank of each preset task corresponding to each module, and thus determines the target low-rank matrix of each preset task corresponding to each module. Finally, based on the target low-rank matrix of each preset task corresponding to each module, the server fine-tunes the initial interaction honeypot model to obtain the target interaction honeypot model.

[0104] In practical applications, the server determines the target rank of each module corresponding to each preset task based on the following formula 1:

[0105] (Formula 1)

[0106] Where L represents the number of modules, and M represents the total number of modules. m Let T be the m-th module; T be the preset task, and N be the total number of preset tasks. n For the nth preset task; Rank(L) m ,T n ) represents the target rank of the m-th module corresponding to the n-th preset task; Rank minThe preset minimum rank; α is an adjustable hyperparameter used to control the ratio; I(L) m C(T) represents the first weight of the initial interaction honeypot model corresponding to the m-th module; n ,L m ) represents the second weight of the m-th module corresponding to the n-th preset task.

[0107] In this embodiment, the server adaptively determines the corresponding rank for different modules and preset tasks, which ensures that modules and preset tasks that are crucial to honeypot style and security are fully trained, thus solving the resource waste and performance bottleneck problems caused by existing fixed rank allocation.

[0108] In an exemplary embodiment, the server fine-tunes the initial interactive honeypot model using a loss function as shown in Equation 2:

[0109] (Formula 2)

[0110] Among them, L total L1 represents the total loss; L2 and L3 represent the cross-entropy losses for the first, second, and third tasks, respectively; L4 represents the penalty loss for the fourth task, which is used to penalize unsafe or out-of-bounds responses, such as a penalty function based on reinforcement learning.

[0111] In an exemplary embodiment, step S104 above, which involves obtaining the first association information of the current attack command from each piece of attack data in the attack database, specifically includes the following steps: determining the current user state information corresponding to the current interaction behavior; filtering out at least one piece of associated attack data that matches the current user state information and the current attack command from each piece of attack data based on the current user state information and the current attack command; and obtaining association information for each piece of associated attack data based on the historical attack commands and historical network responses in the associated attack data.

[0112] Specifically, the server obtains the current user state information corresponding to the current interaction behavior, and vectorizes and fuses the current user state information and the current attack command to obtain a multi-dimensional query vector V. query Then, the server uses vector retrieval to filter out data from the attack database that matches the query vector V. query The top-k most matching attack data are used as each associated attack data; then, for each of the selected associated attack data, the server combines the historical attack commands and historical network responses in the associated attack data into an association information.

[0113] In practical applications, the server can also combine the attacker's user identifier and IP (Internet Protocol) address to generate a query vector V. query .

[0114] In this embodiment, the server uses vector retrieval to filter out the first associated information of the current attack command from the attack database.

[0115] In an exemplary embodiment, step S104 above, which involves obtaining the second association information of the current attack command from the attack knowledge graph, specifically includes the following steps: identifying each target entity in the current attack command and the target relationships between each target entity; traversing the attack knowledge graph and determining at least one association path that matches each target entity and target relationship from the attack knowledge graph; and for each association path, obtaining a second association information based on each node and each connecting edge included in the association path.

[0116] Each associated path includes nodes that match each target entity, and connecting edges that match the target relationship.

[0117] Specifically, the server identifies the entities and relationships between them in the current attack command, obtaining each target entity and the target relationships between them. Then, the server traverses the attack knowledge graph based on the target entities and their relationships, using a graph traversal algorithm, to determine the top-k most relevant paths that best match each target entity and its relationship. Next, for each relevant path, the server combines the nodes and edges included in that path into a second set of relevant information.

[0118] In this embodiment, the server, based on graph traversal, is able to determine the second associated information of the current attack command from the attack knowledge graph.

[0119] In an exemplary embodiment, step S104 above, which involves filtering out the third association information of the current attack command from the first association information and the second association information, specifically includes the following steps: combining the first association information and the second association information to obtain each candidate association information; determining the matching degree between each candidate association information and the current attack command based on historical interaction information, the current user state information corresponding to the current interaction behavior, and the attack knowledge graph; sorting each candidate association information according to the matching degree from high to low to obtain the sorting result of each candidate association information; and filtering out the third association information from each candidate association information based on the sorting result.

[0120] Specifically, the server uses each of the first and second association information as candidate association information. Then, the server inputs each candidate association information into a pre-trained reordering model. The reordering model determines the matching degree between each candidate association information and the current attack command based on the attacker's historical sessions with the network, the current user state information corresponding to the current interaction behavior, and the attack knowledge graph. The model then sorts the candidate association information in descending order of matching degree to obtain the ranking result of each candidate association information. Finally, based on the ranking result, the server selects the top-k most matching candidate association information from each candidate association information as the third association information.

[0121] In practical applications, the k value used in the top-k algorithm when determining the first, second, and third related information can be the same or different.

[0122] In this embodiment, the server can improve the accuracy of the filtered third association information by rearranging the first and second association information based on historical interaction information, current user state information, and the attack logic contained in the attack knowledge graph.

[0123] In one exemplary embodiment, the server updates the attack database and attack knowledge graph based on the attacker's interaction behavior and interaction information with the network.

[0124] To more clearly illustrate the network attack protection method provided in the embodiments of this application, a specific embodiment is used below to describe the network attack protection method in detail. However, it should be understood that the embodiments of this application are not limited thereto. Figure 3 As shown, in one exemplary embodiment, this application also provides a method for constructing and applying an interactive honeypot system based on adaptive multi-task fine-tuning and hybrid retrieval, specifically including the following:

[0125] The system specifically includes a knowledge base module, a hybrid retrieval enhancement module, an adaptive multi-task fine-tuning module, a dynamic interaction and state maintenance module, and a log recording and data analysis module.

[0126] The dynamic interaction and state preservation module records, synchronizes, and manages the internal state of the honeypot system in real time. This ensures that each response is deeply coupled with the attacker's behavior and the current state of the simulated environment, guaranteeing that each interaction is stateful, memory-based, and logical. This makes the honeypot system's trapping process for attackers more realistic, coherent, and difficult to detect. To maintain coherence while avoiding excessively long contexts, the dynamic interaction and state preservation module employs a memory filtering strategy. For example, the strategy can be set to retain only the most recent N rounds of interaction history, or, based on command type, execution result, and other weights, prioritize retaining historical commands crucial for understanding the attack intent. This mechanism ensures that the LLM can effectively utilize key historical information when handling multi-round interactions, avoiding "amnesia" or logical jumps. The dynamic interaction and state preservation module can also identify and deconstruct complex commands input by the attacker, thereby achieving deep integration of the response with the simulated environment and significantly enhancing the honeypot's deceptiveness.

[0127] The logging and data analysis module is used to achieve closed-loop continuous optimization and threat intelligence generation of the honeypot system. This module treats each interaction within the honeypot system as a structured data point, using streaming capture and sequence analysis to systematically record and automatically respond to attack behaviors, thus supporting the honeypot system's continuous learning and evolution. The logging and data analysis module employs a lightweight log broker to capture the structured interaction data in real time. The data stream is synchronously written to a local log file for backup and asynchronously sent to a backend distributed database for centralized storage. This dual-write mechanism ensures data reliability and facilitates subsequent large-scale querying and analysis.

[0128] The knowledge base module is responsible for building and maintaining the core knowledge base of the honeypot system, aiming to provide rich and structured data to support subsequent retrieval and generation processes. Unlike existing technologies that use a single vector database, the knowledge base module adopts a dual-mode storage, specifically including a vector database (attack database) and a knowledge graph (attack knowledge graph).

[0129] The hybrid retrieval enhancement module is responsible for providing accurate and context-coherent enhanced knowledge to the large language model in each interaction. Unlike existing technologies that rely on a single vector retrieval process, the hybrid retrieval enhancement module adopts a multi-source, multi-stage hybrid retrieval method, aiming to fundamentally improve the breadth and depth of retrieval.

[0130] The adaptive multi-task fine-tuning module is used to perform customized fine-tuning training on the basic large language model, aiming to simultaneously improve its response realism and security resilience in honeypot scenarios. In specific applications, the adaptive multi-task fine-tuning module subdivides tasks into command response and style simulation tasks, system state and path structure simulation tasks, anomaly and error masquerading tasks, and security alignment and malicious intent recognition tasks; fine-tuning training is achieved through adaptive rank allocation as shown in Equation 1 and multi-task learning training as shown in Equation 2.

[0131] The following will use a specific attack scenario to illustrate in detail how the various modules work together to achieve dynamic and highly realistic deception of attackers. Suppose that the attacker successfully logs into the honeypot system via SSH (Secure Shell), with the initial intention of conducting reconnaissance, and then attempts to escalate privileges.

[0132] Step 1: Reconnaissance Phase (Single Command Interaction).

[0133] 1. Attacker inputs: whoami.

[0134] 2. Dynamic Interaction and State Preservation Module: Capture the command and record the current session ID, initial permissions (such as user), and current path (such as / home / user).

[0135] 3. Enhanced Hybrid Search Module:

[0136] Multi-source parallel recall: The whoami command is vectorized, and historical responses (e.g., root, user, etc.) semantically related to the command are retrieved from the vector database. Simultaneously, entities related to whoami are traversed in the knowledge graph to find the logical path that serves as the reconnaissance command.

[0137] Reordering and Knowledge Integration: The reordering model combines the current user permission status with the response fragments for the "user" permission to be placed first.

[0138] 4. LLM Response Generation: Dynamic prompts that incorporate multi-dimensional context and rearranged knowledge are input into an LLM that has been adaptively fine-tuned for multi-task operations to generate a response.

[0139] 5. Honeypot Response: The honeypot system returns a response to the attacker.

[0140] 6. Log recording and data analysis module: Writes the whoami command, user response and related metadata (such as session ID, timestamp) into the log, laying the foundation for subsequent analysis.

[0141] Step 2: Privilege escalation attempt phase (compound commands and state dependencies).

[0142] 1. The attacker inputs: id && cat / etc / passwd | grep root.

[0143] 2. Dynamic Interaction and State Preservation Module: Recognizes that this is a compound command and breaks it down into two subcommands: id and cat / etc / passwd | grep root; synchronizes the current system state and confirms that the current permissions are still user.

[0144] 3. Enhanced Hybrid Search Module:

[0145] Multi-source parallel recall: The compound command is vectorized to retrieve historical responses related to the id and `cat / etc / passwd`, recalling fragments that may contain root information. Simultaneously, `cat / etc / passwd` is traversed in a knowledge graph to find the underlying logical path: accessing this file requires specific permissions, and filtering root user information (`grep root`) is typically a prerequisite for privilege escalation or account reconnaissance.

[0146] Reordering and Knowledge Integration: The reordering model plays a crucial role here. It comprehensively considers: ① the fact that permissions are "user" in historical sessions; ② the logical path in the knowledge graph that "accessing root account information requires root privileges". Therefore, it prioritizes response fragments that display "Permission denied", "No such file or directory", or only show ordinary user information.

[0147] LLM response generation: Input dynamic prompts containing rearranged knowledge (such as non-root privilege information) and multi-task fine-tuning into LLM. LLM will generate a response that appears realistic but is consistent with the current privilege state.

[0148] 4. Honeypot Response: The system returns a response similar to the following to the attacker, cleverly disguising a genuine lack of privileges situation:

[0149] uid=1001(user) gid=1001(user) groups=1001(user)

[0150] cat: / etc / passwd: Permission denied

[0151] 5. Log Recording and Data Analysis Module: This module records the complex interaction as a complete log entry and marks it as an attack behavior of "privilege escalation attempt." If the attacker's subsequent commands are also of high value, the session will be filtered and fed back to the attack knowledge base and fine-tuning module, enabling the honeypot to continuously learn.

[0152] Compared with existing technologies, this embodiment fundamentally solves the three major pain points of response realism, contextual coherence, and security resilience, bringing the following significant technical advantages:

[0153] 1. Significantly improves the authenticity and professionalism of the response content.

[0154] Traditional RAG mechanisms rely solely on vector semantic retrieval, making it difficult to understand complex attack intentions. This results in generated responses that lack professionalism and are easily identifiable by attackers. Furthermore, fine-tuning based on LoRA / QLoRA, due to its fixed-rank allocation limitations, cannot provide refined task customization for the model, leading to insufficient realism in responses to specific attacks.

[0155] In this embodiment, a knowledge graph is introduced to structure entities such as commands, files, and permissions in the attack knowledge base, along with their logical relationships. During retrieval, the system not only performs vector similarity matching but also understands the internal logic and dependencies of attack behaviors through graph traversal. Furthermore, adaptive multi-task fine-tuning is employed, with refined training for different attack tasks (such as reconnaissance and privilege escalation), enabling the model to generate responses that conform to domain-specific knowledge. This dual innovation ensures that the responses generated by the honeypot possess both semantic authenticity and logical consistency with the attack path, significantly enhancing the honeypot's deceptive capabilities and effectively extending the attacker's dwell time.

[0156] 2. Greatly alleviates the problem of inconsistent context in multi-turn interactions.

[0157] Existing RAG technology mainly relies on single vector retrieval, which cannot capture the contextual state in multi-turn interactions, such as the current path and user permissions. This makes the model prone to "amnesia" or logical jumps in multi-turn dialogues, for example, returning the response information of the root user when the user does not have root permissions.

[0158] In this embodiment, by introducing multi-dimensional vectorization, attack commands are fused and encoded with non-textual state data (paths, permissions, etc.) of the simulated environment to construct a more contextually relevant query vector. Simultaneously, a multi-stage reordering mechanism is employed. After retrieval, an independent reordering model performs secondary filtering on candidate results, ensuring high consistency with the entire session history and real-time system state. By integrating real-time state into the entire retrieval and generation process, each round of response is guaranteed to match the current simulated environment state. Whether it's the decomposition of complex commands or the masquerading of errors under restricted permissions, the system can generate logically consistent responses, greatly enhancing the honeypot's coherence and making it more difficult for attackers to detect.

[0159] 3. Enhance the security resilience and defense capabilities of the honeypot system.

[0160] Traditional fine-tuning methods lack built-in security safeguards when dealing with malicious or high-risk inputs, which may lead to the model unintentionally leaking sensitive information or reducing its defense capabilities against attacks such as Prompt injection due to improper training.

[0161] In this embodiment, security alignment and malicious intent recognition tasks are introduced during fine-tuning, and a joint loss function incorporating security losses is used for training. This allows the model to learn how to identify and reject dangerous commands while simultaneously learning the honeypot's response style. This innovation ensures that the honeypot system not only successfully lures attackers but also provides pre-set, harmless security warnings or error messages when faced with malicious commands, thereby protecting the honeypot system's own security and preventing it from being exploited or used as a springboard by attackers.

[0162] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0163] Based on the same inventive concept, this application also provides a network attack protection device for implementing the network attack protection method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more network attack protection device embodiments provided below can be found in the limitations of the network attack protection method described above, and will not be repeated here.

[0164] In one exemplary embodiment, such as Figure 4 As shown, a network attack protection device is provided, including: a command acquisition module 402, an information acquisition module 404, an information combination module 406, and a response generation module 408, wherein:

[0165] Command acquisition module 402 is used to acquire the attacker's current attack commands against the network from the attacker's current interaction with the network.

[0166] The information acquisition module 404 is used to obtain the first association information of the current attack command from each attack data in the attack database, obtain the second association information of the current attack command from the attack knowledge graph, and filter out the third association information of the current attack command from the first and second association information. Each attack data includes the historical attack command, historical network response and historical user state information corresponding to a historical attack on the network. The attack knowledge graph is constructed with the sample entities in each attack data as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command.

[0167] The information combination module 406 is used to combine historical interaction information of the attacker's historical interaction behavior with the network, the current attack command, and the third-party association information to obtain the target association information of the current attack command.

[0168] The response generation module 408 is used to simulate the network response to the current attack command based on the target association information and the target interaction honeypot model to generate the target response and return the target response to the attacker.

[0169] In an exemplary embodiment, the target interaction honeypot model includes preset tasks, each preset task including at least one of a first task, a second task, a third task, and a fourth task; the first task is used to simulate the normal network response to normal interaction behavior; the second task is used to maintain the consistency of responses generated under different user state information; the third task is used to simulate the abnormal network response to abnormal interaction behavior; and the fourth task is used to identify malicious intent in the interaction behavior and generate a corresponding response.

[0170] The response generation module 408 is also used to execute various preset tasks under the target association information through the target interaction honeypot model, and obtain the execution results of the target association information under each preset task; and obtain the target response based on the execution results of the target association information under each preset task.

[0171] In an exemplary embodiment, the network attack protection device further includes a model training module, configured to acquire a pre-trained initial interaction honeypot model, determine each module in the initial interaction honeypot model; determine a first weight for each module corresponding to the initial interaction honeypot model; the first weight for each module corresponding to the initial interaction honeypot model is used to characterize the importance of the module in the initial interaction honeypot model; determine a second weight for each preset task corresponding to each module; the second weight for each preset task corresponding to each module is used to characterize the contribution of the preset task to the module; determine a target rank for each preset task corresponding to each module based on the first weight for each module corresponding to the initial interaction honeypot model and the second weight for each preset task corresponding to each module; determine a target low-rank matrix for each preset task corresponding to each module based on the target rank for each preset task corresponding to each module; and fine-tune the initial interaction honeypot model based on the target low-rank matrix for each preset task corresponding to each module to obtain a target interaction honeypot model.

[0172] In an exemplary embodiment, the information acquisition module 404 is further configured to determine the current user state information corresponding to the current interaction behavior, and based on the current user state information and the current attack command, to filter out at least one associated attack data that matches the current user state information and the current attack command from each attack data; and for each associated attack data, to obtain an associated information based on the historical attack commands and historical network responses in the associated attack data.

[0173] In an exemplary embodiment, the information acquisition module 404 is further configured to identify each target entity and the target relationship between each target entity in the current attack command; traverse the attack knowledge graph and determine at least one association path that matches each target entity and target relationship from the attack knowledge graph; each association path includes each node that matches each target entity and each connecting edge that matches the target relationship; for each association path, a second association information is obtained based on each node and each connecting edge included in the association path.

[0174] In an exemplary embodiment, the information acquisition module 404 is further configured to combine the first association information and the second association information to obtain each candidate association information; determine the matching degree between each candidate association information and the current attack command based on historical interaction information, the current user state information corresponding to the current interaction behavior, and the attack knowledge graph; sort each candidate association information according to the matching degree from high to low to obtain the sorting result of each candidate association information; and select the third association information from each candidate association information based on the sorting result.

[0175] Each module in the aforementioned network attack protection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0176] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 5 As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores data exchanged between the user and the network. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a network attack protection method.

[0177] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0178] In one exemplary embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.

[0179] In one exemplary embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above-described method embodiments.

[0180] In one exemplary embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above-described method embodiments.

[0181] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0182] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0183] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for protecting against network attacks, characterized in that, The method includes: Obtain the attacker's current attack commands against the network from the attacker's current interaction behavior with the network; From each attack data entry in the attack database, the first association information of the current attack command is obtained; from the attack knowledge graph, the second association information of the current attack command is obtained; and from the first and second association information, the third association information of the current attack command is selected. Each attack data entry includes the historical attack command, historical network response, and historical user state information corresponding to a historical attack suffered by the network. The attack knowledge graph is constructed using sample entities in each attack data entry as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command. By combining the historical interaction information of the attacker's historical interaction behavior with the network, the current attack command, and the third association information, the target association information of the current attack command is obtained. Based on the target association information and the target interaction honeypot model, the network response to the current attack command is simulated to generate a target response, and the target response is returned to the attacker.

2. The method according to claim 1, characterized in that, The target interaction honeypot model includes preset tasks, each preset task including at least one of a first task, a second task, a third task, and a fourth task; the first task is used to simulate the normal network response of the network to normal interaction behavior; the second task is used to maintain the consistency of the responses generated under different user state information; the third task is used to simulate the abnormal network response of the network to abnormal interaction behavior; and the fourth task is used to identify malicious intent in the interaction behavior and generate a corresponding response. The step of simulating the network response to the current attack command based on the target association information and the target interaction honeypot model to generate the target response includes: Using the target interaction honeypot model, each preset task is executed under the target association information to obtain the execution result of the target association information under each preset task. The target response is obtained based on the execution results of the target association information under each of the preset tasks.

3. The method according to claim 2, characterized in that, The target interactive honeypot model is obtained through the following method: Obtain the pre-trained initial interaction honeypot model and determine each module in the initial interaction honeypot model; Determine the first weight of each module corresponding to the initial interaction honeypot model; Each module corresponds to a first weight in the initial interaction honeypot model, which is used to characterize the importance of the module in the initial interaction honeypot model; Determine the second weight of each module corresponding to each of the preset tasks; Each preset task corresponds to a second weight of each module, which is used to characterize the degree of contribution of the preset task to the module; Based on the first weight of each module corresponding to the initial interaction honeypot model and the second weight of each preset task corresponding to each module, determine the target rank of each preset task corresponding to each module; Based on the target rank of each module corresponding to each preset task, determine the target low-rank matrix of each preset task corresponding to each module; Based on the target low-rank matrix of each module corresponding to each preset task, the initial interaction honeypot model is fine-tuned to obtain the target interaction honeypot model.

4. The method according to claim 1, characterized in that, The step of obtaining the first association information of the current attack command from each attack data entry in the attack database includes: Determine the current user state information corresponding to the current interaction behavior, and based on the current user state information and the current attack command, filter out at least one associated attack data that matches the current user state information and the current attack command from each of the attack data; For each piece of associated attack data, an associated information is obtained based on the historical attack commands and historical network responses in the associated attack data.

5. The method according to claim 1, characterized in that, The step of obtaining the second association information of the current attack command from the attack knowledge graph includes: Identify each target entity in the current attack command and the target relationships between each target entity; Traverse the attack knowledge graph and determine at least one association path that matches each of the target entities and the target relationships from the attack knowledge graph; each association path includes each of the nodes that match each of the target entities and each of the connecting edges that match the target relationships; For each of the associated paths, a second association information is obtained based on each of the nodes and each of the connecting edges included in the associated path.

6. The method according to any one of claims 1 to 5, characterized in that, The step of filtering out the third association information of the current attack command from the first association information and the second association information includes: Combine the first association information and the second association information to obtain each candidate association information; Based on the historical interaction information, the current user state information corresponding to the current interaction behavior, and the attack knowledge graph, determine the matching degree between each candidate association information and the current attack command; The candidate association information is sorted according to the matching degree from high to low to obtain the sorting result of the candidate association information; Based on the sorting results, the third association information is selected from each of the candidate association information.

7. A network attack protection device, characterized in that, The device includes: The command acquisition module is used to acquire the attacker's current attack commands against the network from the attacker's current interaction behavior with the network; The information acquisition module is used to acquire first association information of the current attack command from each attack data entry in the attack database, acquire second association information of the current attack command from the attack knowledge graph, and filter out third association information of the current attack command from the first and second association information. Each attack data entry includes historical attack commands, historical network responses, and historical user state information corresponding to a historical attack suffered by the network. The attack knowledge graph is constructed using sample entities in each attack data entry as nodes and the relationships between the sample entities as edges. The second association information includes each node and each edge in the attack knowledge graph that matches the current attack command. The information combination module is used to combine historical interaction information of the historical interaction behavior between the attacker and the network, the current attack command, and the third association information to obtain the target association information of the current attack command. The response generation module is used to simulate the network response of the network to the current attack command based on the target association information and the target interaction honeypot model to generate a target response and return the target response to the attacker.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.