Data center network security defense system

By constructing a feature mapping library and a highly realistic virtual subnet, combined with intelligent trapping and security defense modules, and dynamically adjusting strategies, the system addresses the problem of insufficient identification and handling capabilities of data center network security defense systems against new types of attacks, achieving efficient and real-time network security protection.

CN121508962APending Publication Date: 2026-02-10HANGZHOU JIWANG COMM TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511668905.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-14
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing data center network security defense systems are unable to effectively detect new types of attacks, cannot parse encrypted traffic, and have outdated security policies, resulting in low threat response efficiency and failing to meet the requirements for real-time and high-efficiency protection.

Method used

By constructing a feature mapping library, highly realistic virtual subnets and trapping nodes are generated. Combined with intelligent trapping and security defense modules, trapping strategies and defense measures are dynamically adjusted to form a closed loop from feature foundation building to simulated trapping, dynamic defense to continuous optimization, thereby improving trapping accuracy and defense response capabilities.

Benefits of technology

It has improved the initiative, adaptability and accuracy of data center networks, enhanced the ability to identify and deal with new types of attacks, and ensured the safe and stable operation of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508962A_ABST
    Figure CN121508962A_ABST
Patent Text Reader

Abstract

The invention provides a data center network security defense system, and belongs to the technical field of network security. The system comprises a feature acquisition module for constructing a standardized feature mapping library; the honeynet simulation module is used for generating a virtual subnet containing virtual nodes and trapping strategies based on the scene library, and generating bait data for the nodes according to the scene library to form trapping nodes; the intelligent trapping module is used for collecting attack interaction data and dynamically generating a trapping intensity instruction through an attack popularity scoring model to adjust a strategy; and the security defense module is used for constructing an attack chain graph, calculating a threat score, driving a hierarchical response mechanism, generating defense efficiency data, and feeding back the defense efficiency data to the feature library and scoring model weight adjustment. According to the method, dynamic construction of a high-simulation network environment, intelligent trapping of attack behaviors, bait adaptive evolution and closed-loop optimization of defense are realized, and the trapping efficiency, the response speed and the active defense capability for novel attacks are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically to a data center network security defense system. Background Technology

[0002] With the rapid development of the digital economy, data centers, as the core of information storage, processing, and transmission, support critical business operations such as enterprise operations and financial transactions. The widespread adoption of technologies such as cloud computing and the Internet of Things has dramatically increased their scale and complexity, making cybersecurity a critical issue in the digital age, concerning both corporate privacy and national information security. Currently, data center network security primarily relies on traditional devices such as perimeter firewalls and web application firewalls (WAFs), operating based on rule-based matching. However, these systems struggle to detect zero-day attacks and APT penetrations due to the lack of historical feature matching. Furthermore, encrypted traffic attacks often fail to parse the content, leading to missed detections. Additionally, the formulation and deployment of security policies frequently depend on manual operations or outdated update mechanisms, making it difficult to quickly adapt to evolving attack methods. This results in inefficient threat response and fails to meet the real-time and efficient network security protection requirements of data centers. Summary of the Invention

[0003] This invention provides a data center network security defense system to solve the problems of inefficient trapping and poor defense against new attacks in existing technologies.

[0004] To achieve the above objectives, this invention provides a data center network security defense system, comprising: a feature acquisition module for acquiring multi-dimensional features of nodes in a data center network and standardizing the multi-dimensional features to construct a feature mapping library; and a honeynet simulation module, comprising a network construction unit and a decoy construction unit. The network construction unit is used to construct a virtual subnet consistent with the data center network topology and node characteristics based on the feature mapping library. The virtual subnet includes a preset trapping strategy, several virtual nodes, and their corresponding role type data. The decoy construction unit is used to determine a target business scenario based on the role type data of each virtual node, combined with a preset scenario library, and generate a corresponding decoy. The data is embedded in virtual nodes to form trap nodes; the intelligent trapping module includes a strategy optimization unit and a strategy execution unit. The strategy optimization unit is used to collect the interaction information between the attacker and the trapping node and generate attack interaction data. It is also used to calculate the attack heat value according to the attack interaction data through a preset attack heat scoring model and generate a trapping strength command to adjust the trapping strategy. The strategy execution unit is used to execute the adjusted trapping strategy according to the attacker's behavior. The security defense module is used to construct an attack chain graph and calculate a threat score according to the attack interaction data. It is also used to execute a preset graded response according to the attack chain graph and threat score, and generate defense effectiveness data according to the results of the graded response to adjust the weight of virtual node features and the attack heat scoring model.

[0005] Optionally, the scenario library contains several preset scenarios, each preset scenario is configured with a corresponding scenario tag, and the determination of the business scenario includes: extracting core features from the role type data of each virtual node and matching them with the scenario tag to filter out candidate scenarios; calculating the first matching degree between the core features and each candidate scenario; if the highest first matching degree reaches a first preset value, then the candidate scenario corresponding to the first matching degree is taken as the target business scenario; if the first matching degree is less than the first preset value, then the core features are further verified.

[0006] Optionally, the supplementary verification includes: retrieving business scenario features of real nodes with the same role type as virtual nodes from the feature mapping library; comparing the core features of the virtual node with the business scenario features of the corresponding real nodes to calculate a second matching degree; if the second matching degree reaches a second preset value, the business scenario corresponding to the real node is determined as the target business scenario; if the second matching degree is less than the second preset value, retrieving the business scenario features of other real nodes of the same role type in the feature mapping library for repeated verification until a unique matching business scenario is determined.

[0007] Optionally, the data center network security defense system further includes a decoy evolution module, used to calculate the attack probability of each decoy node through a preset evaluation strategy, and based on the attack probability, update the features of the decoy node through a preset update strategy to optimize the simulation degree of the decoy node; the evaluation strategy includes: extracting the effective interactions and total number of probes of the attacker to the decoy node according to the interaction information, the effective interactions including probing interactions and targeted interactions; calculating the proportion of probing interactions and targeted interactions in the total number of probes respectively, and calculating the initial attack probability by combining the similarity decay coefficient of the features of the decoy node and the real node; assigning dynamic weights to targeted interactions according to the threat level corresponding to the attack heat value, and calculating the final attack probability by combining the basic attack probability.

[0008] Optionally, the features of the decoy node include dynamic features and static features, and the update strategy includes: calculating the comprehensive attack probability of the decoy node based on multiple attack probabilities of the decoy node within a preset period; when the comprehensive attack probability is higher than a first threshold, using a feature mutation algorithm to update the dynamic features of the decoy node at preset time intervals; when the comprehensive attack probability is between the first threshold and a second threshold, updating the static features of the decoy node at preset time intervals; and pausing updates when the comprehensive attack probability is lower than the second threshold.

[0009] Optionally, each of the trapping intensity commands corresponds to a trapping level, and each of the trapping levels corresponds to a heat range. The generation of the trapping intensity command includes: a strategy optimization unit extracting feature parameters from attack interaction data; calculating an attack heat value based on the feature parameters using the attack heat scoring model; and comparing the attack heat value with the heat range to determine the trapping level and the trapping intensity command.

[0010] Optionally, the adjustment of the trapping strategy includes: the strategy execution unit determining the strategy dimensions to be adjusted according to the trapping level; adjusting each strategy dimension based on preset adjustment rules; integrating the parameters of each strategy dimension after adjustment and updating the trapping strategy.

[0011] Optionally, constructing the attack chain graph and calculating the threat score includes: extracting attacker behavior information from attack interaction data; performing correlation analysis on the extracted behavior information, establishing connections between behavior nodes based on the sequential logic and causal relationship of the behaviors to form an initial behavior chain; dividing the initial behavior chain into corresponding attack stages according to a preset attack lifecycle model; constructing an attack chain graph based on the attack stages, behavior nodes, and the correlation between behavior nodes; determining the dimensions used to calculate the threat score based on the attack chain graph and attack interaction data; extracting feature information corresponding to each dimension from the attack interaction data and feature mapping library, and determining the score value of each dimension based on the feature information and preset scoring rules; and performing a comprehensive calculation on the score values ​​of each dimension based on preset weights to obtain the threat score.

[0012] Optionally, the graded response includes several response levels, and each response level corresponds to a defense mechanism. The determination of the response level includes: extracting the correlation strength between attack stage features and behavioral nodes from the attack chain graph; fusing and analyzing the attack stage features, correlation strength, and threat score to form an attack threat feature set; matching the attack threat feature set with a preset response level judgment standard, and determining the corresponding response level and response mechanism based on the matching result.

[0013] Optionally, the generation of the defense effectiveness data includes: acquiring the execution information of the defense mechanism and the changes in the attack state after the execution of the defense mechanism; performing quantitative analysis on the execution information and changes in the attack state based on preset effectiveness evaluation indicators; and integrating the quantitative analysis results to generate defense effectiveness data to reflect the actual effect of the graded response.

[0014] The data center network security defense system provided by this invention, through a feature acquisition module that constructs a feature mapping library, provides a foundation for the honeynet simulation module that is consistent with the real network topology and node characteristics of the data center. This enables the virtual subnet and the decoy nodes to have high simulation fidelity, improving the effectiveness of decoys against attackers. The intelligent decoy module generates attack heat values ​​by collecting attack interaction data and dynamically adjusts the decoy strategy, achieving targeted optimization of the decoy strategy and enhancing the accuracy and flexibility of decoys. The security defense module constructs an attack chain graph based on attack interaction data, calculates threat scores, and executes graded responses. At the same time, it uses defense effectiveness data to feed back and optimize the virtual node characteristics and attack heat score model, forming a closed loop of "simulation decoy - dynamic defense - continuous optimization". This comprehensively improves the initiative, adaptability, and accuracy of data center network security defense, effectively enhancing the ability to identify, decoy, and handle new types of network attacks. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in this invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings: Figure 1 This is a framework diagram of a data center network security defense system provided in an embodiment of the present invention; Figure 2 This is a flowchart of the feature mapping library construction process provided in this embodiment of the invention; Figure 3 This is a flowchart of the virtual subnet and trapping node construction process provided in the embodiments of the present invention; Figure 4 This is a flowchart of the intelligent trapping strategy adjustment provided in the embodiments of the present invention; Figure 5 This is a flowchart of attack chain graph construction and threat score calculation provided in an embodiment of the present invention; Figure 6 This is a flowchart of the hierarchical response provided in an embodiment of the present invention. Detailed Implementation

[0016] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.

[0017] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application all comply with the relevant provisions of national laws and regulations. In the embodiments of this application, certain existing industry solutions such as software, components, and models may be mentioned. These should be considered exemplary, intended only to illustrate the feasibility of implementing the technical solution of this application, and do not imply that the applicant has already used or necessarily used such solutions.

[0018] As mentioned above, with the deep integration of data centers with cloud computing and the Internet of Things, network boundaries are becoming increasingly blurred. Attacks targeting data centers are becoming more diverse and covert. Traditional security protection technologies struggle to create highly realistic decoy environments to accurately attract attackers, and they also cannot dynamically adjust defense strategies based on attacks. This results in insufficient decoy effectiveness and delayed response, making it difficult to balance security protection with efficient network operation. Therefore, developing a more intelligent data center network security defense system is extremely important.

[0019] To address this issue, this invention provides a data center network security defense system. It lays the foundation by collecting multi-dimensional node features to build a feature mapping library, and utilizes a honeycomb simulation module to generate highly realistic virtual subnets and decoy nodes for precise decoy capture. Combining an intelligent decoy module and a security defense module, it dynamically adjusts decoy strategies and defense measures based on attack dynamics. Finally, it uses defense effectiveness data to feed back and optimize virtual node features and scoring models, forming a closed-loop process from feature foundation building to simulated decoy capture, and from dynamic defense to continuous optimization. This effectively improves the accuracy of attack decoy capture and defense response capabilities of the data center, ensuring the stable operation of network security.

[0020] The following is combined with Figures 1-6 This invention is described in detail.

[0021] like Figure 1 and Figure 2 As shown in the figure, this invention provides a data center network security defense system, which includes: a feature acquisition module for acquiring multi-dimensional features of nodes in a data center network and standardizing the multi-dimensional features to construct a feature mapping library; and a honeynet simulation module, including a network construction unit and a decoy construction unit. The network construction unit is used to construct a virtual subnet consistent with the data center network topology and node features according to the feature mapping library. The virtual subnet includes a preset trapping strategy, several virtual nodes, and their corresponding role type data. The decoy construction unit is used to determine the target business scenario based on the role type data of each virtual node, combined with a preset scenario library, and generate corresponding decoy data to embed into the virtual subnet. The system includes a virtual node that forms a decoy node; an intelligent decoy module comprising a strategy optimization unit and a strategy execution unit. The strategy optimization unit collects interaction information between the attacker and the decoy node and generates attack interaction data. It also calculates an attack heat value based on the attack interaction data using a preset attack heat scoring model, and generates a decoy strength command based on the attack heat value to adjust the decoy strategy. The strategy execution unit executes the adjusted decoy strategy based on the attacker's behavior. The security defense module constructs an attack chain graph and calculates a threat score based on the attack interaction data. It also executes a preset graded response based on the attack chain graph and threat score, and generates defense effectiveness data based on the results of the graded response to adjust the weights of virtual node features and the attack heat scoring model.

[0022] Multidimensional features refer to the multi-dimensional information of nodes in the data center network, such as hardware configuration, operating status, and business attributes, comprehensively reflecting the characteristic attributes of the nodes. Standardization processing, through operations such as unifying data formats, normalizing numerical ranges, and removing redundant information, ensures the consistency and comparability of multidimensional features, facilitating subsequent module calls. The feature mapping library is a database that stores standardized node features, recording the feature associations of real nodes, serving as a benchmark template for honeynet simulation. The decoy strategy is a set of pre-set rules in the virtual subnet used to attract and respond to attackers, including decoy activation conditions, traffic redirection methods, and interactive response logic. Role type data refers to the role information of real nodes simulated by virtual nodes, such as database servers, office terminals, and routers. Decoy data is fake data generated based on the target business scenario, mimicking real business data, such as simulated user logs, database table structures, and transaction records, used to enhance the deceptiveness of decoy nodes. Embedding decoy data into virtual nodes forms decoy nodes, which have a similar appearance and interactive capabilities to real nodes, specifically designed to attract attackers and record their behavior.

[0023] The data center network security defense system provided in this invention ensures a high similarity between the virtual subnet and the real network through standardized processing and feature mapping library construction of the feature acquisition module. This provides a realistic simulation basis for decoy nodes, increasing their attractiveness to attackers. The honeynet simulation module generates bait data by accurately matching business scenarios, making the decoy nodes more deceptive and improving the success rate of decoy capture. The intelligent decoy module dynamically adjusts the decoy strategy based on attack interaction data, achieving real-time adaptation between decoy intensity and attack heat, enhancing the flexibility and accuracy of decoy capture. The security defense module visualizes attack paths through attack chain graphs and quantifies threat levels through threat scoring, making graded responses more targeted. The feedback optimization of defense effectiveness data forms a closed loop of simulation-decoy-defense-optimization, comprehensively improving the data center network's ability to proactively identify, accurately decoy, and dynamically defend against complex attacks, effectively balancing security protection and network operation efficiency.

[0024] like Figure 3 As shown, preferably, the scenario library contains several preset scenarios, each preset scenario is configured with a corresponding scenario tag, and the determination of the business scenario includes: extracting core features from the role type data of each virtual node and matching them with the scenario tag to filter out candidate scenarios; calculating the first matching degree between the core features and each candidate scenario; if the highest first matching degree reaches a first preset value, then the candidate scenario corresponding to the first matching degree is taken as the target business scenario; if the first matching degree is less than the first preset value, then the core features are further verified.

[0025] Further preferably, the supplementary verification includes: retrieving business scenario features of real nodes with the same role type as the virtual node from the feature mapping library; comparing the core features of the virtual node with the business scenario features of the corresponding real node to calculate a second matching degree; if the second matching degree reaches a second preset value, the business scenario corresponding to the real node is determined as the target business scenario; if the second matching degree is less than the second preset value, retrieving the business scenario features of other real nodes of the same role type in the feature mapping library for repeated verification until a unique matching business scenario is determined.

[0026] The scenario library is a database storing multiple preset business scenarios. Each scenario includes scenario tags, typical business characteristics, and corresponding decoy templates, used to match the business scenario requirements of virtual nodes. Core features refer to key attributes extracted from virtual node role type data, including functional positioning, data interaction patterns, and business-related objects, serving as the core basis for scenario matching. Matching degree is calculated using cosine similarity. The first matching degree calculation uses an 8-dimensional numerical vector as the core feature vector. Its elements are: attack type encoding assigned according to a preset attack classification system; attack tool version feature value generated as a 0-1 standardized value based on the tool fingerprint database; the similarity between the interaction command sequence and the historical attack command sequence is in the 0-1 range; the target port feature value is a weighted value of 0.2-0.8 for commonly used port mappings; the data packet length fluctuation coefficient is the normalized value of the standard deviation of the attack data packet length; the timestamp distribution feature is the periodic quantification value of the attack initiation time; the error response trigger rate is the proportion of the target error response triggered during the attack; and the authentication information attempt frequency is the normalized value of the number of times authentication information is submitted per unit time. The second matching degree calculation uses a 5-dimensional numerical vector for the scenario label vector. Its elements are as follows: scenario type identifier assigned according to business scenario classification; environmental security level is a 0-1 quantitative value based on the target network protection strength; business sensitivity coefficient is the sensitivity of the target's carried business in the range of 0.1-1.0; historical attack frequency is the normalized value of the number of attacks in the past 30 days for this scenario; and asset value weight is the asset importance score of the target node in the range of 0-1.

[0027] Specifically, the decoy construction unit extracts core features from the role type data of virtual nodes and matches them with scene tags in the scene library to filter out potential matching candidate scenes. It calculates the first matching degree between the core features and each candidate scene using cosine similarity. If the highest first matching degree reaches a first preset value, the candidate scene is directly identified as the target business scene. If all first matching degrees are lower than the first preset value, the decoy construction unit retrieves the business scene features of real nodes with the same role type as the virtual nodes from the feature mapping library. It compares the core features of the virtual node with the business scene features of the real node to calculate the second matching degree. If the second matching degree reaches a second preset value, the business scene corresponding to the real node is identified as the target business scene. If not, it continues to retrieve the business scene features of other real nodes with the same role type for repeated verification until a unique matching target business scene is determined.

[0028] For example, assuming the virtual node role is an "e-commerce order server," the decoy construction unit extracts its core features, such as processing order payment instructions and high-frequency interaction from 9:00 to 21:00 daily. These features are then matched with tags in the scenario library to select the candidate scenario "e-commerce platform order processing." The first matching degree calculated using cosine similarity is 0.8, which is higher than the first preset value of 0.7, and is directly identified as the target business scenario. If the first matching degree is only 0.5, supplementary verification is triggered: the business scenario features of the real e-commerce order server are retrieved from the feature mapping library, and the second matching degree between the core features of the virtual node and the real features is calculated to be 0.65, which is higher than the second preset value of 0.6. Finally, the scenario corresponding to the real node is identified as the target business scenario.

[0029] The business scenario matching scheme provided in the preferred embodiment of the present invention ensures the consistency between the target business scenario and the virtual node role through precise matching of core features and scenario tags, providing a scenario basis that fits the business logic for the generation of decoy data. The quantitative judgment of the first matching degree avoids the subjectivity of scenario selection, improves the objectivity and efficiency of scenario determination, and thus ensures the business scenario simulation degree of the decoy node, enhancing its deceptiveness to attackers. At the same time, by introducing the business scenario features of real nodes as a reference, the problem of insufficient scenario library matching is solved, improving the authenticity and adaptability of the target business scenario. The multi-round repeated verification mechanism avoids the limitations of a single real node feature, ensuring that the target business scenario can accurately reflect the general business rules of nodes with the same role, providing a more realistic scenario basis for the generation of decoy data, and further enhancing the simulation effect of the decoy node.

[0030] Preferably, the data center network security defense system further includes a decoy evolution module, used to calculate the attack probability of each decoy node through a preset evaluation strategy, and based on the attack probability, update the features of the decoy node through a preset update strategy to optimize the simulation degree of the decoy node; the evaluation strategy includes: extracting the effective interactions and total number of probes of the attacker to the decoy node according to the interaction information, the effective interactions including probing interactions and targeted interactions; calculating the proportion of probing interactions and targeted interactions in the total number of probes respectively, and calculating the initial attack probability by combining the similarity decay coefficient of the features of the decoy node and the real node; assigning dynamic weights to targeted interactions according to the threat level corresponding to the attack heat value, and calculating the final attack probability by combining the basic attack probability.

[0031] Effective interactions refer to actions between the attacker and the decoy node that are of substantial value in determining the attacker's intent and behavioral patterns. These include probing interactions (such as port scanning and basic vulnerability detection) and targeted interactions (such as launching attacks using specific vulnerabilities and stealing decoy data). Ineffective interactions refer to interactions without substantial offensive significance, such as accidental access or random data packet sending, and are not included in the attack heat calculation. The similarity decay coefficient is a parameter used to correct the change in the similarity between the decoy node and the real node over time; the coefficient ranges from 0 to 1 and decreases as time increases. Dynamic weights are coefficients that adjust the proportion of targeted interactions based on the threat level corresponding to the attack heat value. For example, higher threat levels are given higher weights, making the probability of being attacked more closely match the actual threat level of the current attack.

[0032] Specifically, the decoy evolution module calculates the attack probability by evaluating strategies: First, it extracts the attacker's effective interactions with the decoy and the total number of probes from the interaction information, calculating the proportion of each type of effective interaction in the total number of probes; then, it obtains the initial attack probability by combining the similarity decay coefficient between the decoy and real node features; next, it assigns dynamic weights to targeted interactions based on the threat level corresponding to the attack popularity value, and combines this with the initial probability to calculate the final attack probability. Subsequently, based on the update strategy, it updates the features of the decoy nodes according to the attack probability to optimize the simulation accuracy.

[0033] The initial probability of being attacked is calculated as follows: Initial probability of being attacked = (First matching degree × Similarity decay coefficient + Second matching degree × (1 - Similarity decay coefficient)) × (Proportion of tentative interactions × Tentative weight + Proportion of targeted interactions × Targeted weight). The similarity decay coefficient balances the timeliness impact of the two matching degrees. Its value is dynamically adjusted based on the time interval between the attack event and historical data: 0.8 for intervals within 24 hours, 0.5 for intervals between 24 and 72 hours, and 0.2 for intervals exceeding 72 hours. This rule ensures a higher weighting for recent attack characteristics. The proportion of tentative interactions refers to the percentage of probe-type operations without a clear target during the attack, while the proportion of targeted interactions refers to the percentage of precise operations targeting specific vulnerabilities or resources. The weighting is 30% for tentative interactions and 70% for targeted interactions, highlighting the impact of precise attack behavior on the probability of being attacked.

[0034] The preferred embodiment of this invention quantifies the probability of being attacked by evaluating strategies, accurately reflecting the actual attractiveness of the decoy nodes. It introduces a similarity decay coefficient and dynamic weights, ensuring that probability calculations balance the timeliness of simulation and the level of attack threat, resulting in results that better reflect real-world attack and defense scenarios. The probability-based update strategy enables differentiated updates to the characteristics of the decoy nodes, reducing ineffective resource consumption while continuously optimizing the simulation of the decoy nodes, extending their effective decoy period, and enhancing the system's long-term adversarial capabilities.

[0035] Preferably, the features of the decoy node include dynamic features and static features, and the update strategy includes: calculating the comprehensive attack probability of the decoy node based on multiple attack probabilities of the decoy node within a preset period; when the comprehensive attack probability is higher than a first threshold, using a feature mutation algorithm to update the dynamic features of the decoy node at preset time intervals; when the comprehensive attack probability is between the first threshold and a second threshold, updating the static features of the decoy node at preset time intervals; and pausing updates when the comprehensive attack probability is lower than the second threshold.

[0036] The overall attack probability refers to the weighted average of multiple attack probabilities calculated for the same decoy node over a certain period, used to more stably assess the long-term attractiveness of the node. Dynamic characteristics refer to attributes of the decoy node that change dynamically over time or through interaction, such as real-time port open status, process running lists, temporary file generation records, and session connection logs. These are volatile and time-sensitive, directly affecting the attacker's real-time interactive experience. Static characteristics refer to relatively stable and unchanging basic attributes of the decoy node, such as hardware configuration information, operating system version, fixed service ports, and core software installation lists. These are the basic basis for attackers to identify node types. The feature mutation algorithm is an adaptive algorithm based on a dynamic feature library and environmental feedback. It is used to dynamically update the features of the decoy nodes, thereby improving the decoy capability against variant attacks. The feature mutation algorithm first extracts features and divides them into three categories: static, dynamic behavior, and interactive response, with corresponding weights of 40%, 35%, and 25%, respectively. Mutation is triggered periodically or by events, with mutation ranges of ≤20%, 20%-50%, and a maximum of 80% depending on the feature type, following specific mutation rules for features such as port and version identifiers. After mutation, verification is performed, which must meet the following requirements: similarity to the real system ≥60%, difference from the previous version ≥15%, and functional compatibility ≥95%. After passing the verification, the feature set is updated. If the decoy success rate drops by more than 10%, it is backtracked and adjusted to balance deception and dynamism, thereby improving the continuous decoy capability.

[0037] For example, a decoy node simulates an e-commerce payment server with a preset period of 3 hours. The probability of a single attack on this decoy node in the past 3 hours is 0.684, 0.72, and 0.75, respectively. Weights are assigned according to the time decay rule: 0.5 for the most recent hour, 0.3 for the previous 1-2 hours, and 0.2 for the previous 2-3 hours. The calculated comprehensive attack probability is 0.684×0.2+0.72×0.3+0.75×0.5=0.724, which is higher than the first threshold of 0.7. Every hour, dynamic features are updated through a feature mutation algorithm: 3 sets of payment session IDs are randomly changed, and 8 fake transaction temporary records simulating users are generated.

[0038] The preferred embodiment of this invention provides an update strategy that achieves precise feature optimization by differentiating the update timing of dynamic and static features. High-attractiveness nodes are prioritized for updating dynamic features that are easily detected by attackers to maintain continuous deception; medium-attractiveness nodes are moderately updated with stable features to avoid excessive changes that could lead to a decrease in simulation accuracy; and low-attractiveness nodes are paused for updates to save system resources. This differentiated update strategy not only ensures the long-term simulation effect of the decoy nodes but also improves system operating efficiency by allocating resources on demand, effectively extending the lifespan of the decoy nodes and increasing the success rate of decoy capture.

[0039] As shown in the figure, preferably, each of the trapping intensity commands corresponds to a trapping level, and each of the trapping levels corresponds to a heat range. The generation of the trapping intensity command includes: the strategy optimization unit extracting feature parameters from the attack interaction data; calculating the attack heat value based on the feature parameters through the attack heat scoring model; and comparing the attack heat value with the heat range to determine the trapping level and the trapping intensity command.

[0040] More preferably, the adjustment of the trapping strategy includes: the strategy execution unit determining the strategy dimensions to be adjusted according to the trapping level; adjusting each strategy dimension based on preset adjustment rules; integrating the parameters of each strategy dimension after adjustment and updating the trapping strategy.

[0041] Among them, the feature parameters are quantitative indicators extracted from attack interaction data that reflect the intensity of attack behavior, including attack frequency, attack tool complexity, and interaction depth. The heat range is a preset range of attack heat values, with each range corresponding to a unique trapping level: heat values ​​of 0-30 correspond to the basic level, 31-60 to the enhanced level, and 61-100 to the emergency level. The strategy dimension is the core element constituting the trapping strategy, including bait type, response speed, and interaction depth; each dimension collectively determines the overall effectiveness of the strategy. The adjustment rules specifically include: Basic level: only basic business data is released, read-only permissions are granted, 15% of attack traffic is diverted to edge nodes, and requests are responded to immediately; Enhanced level: 5% sensitive data simulation is added, partial write permissions are granted with a 1-second delay in response, 40% of traffic is directed to core nodes, and 20% of traffic is mirrored to the analysis platform; Emergency level: 30% highly realistic vulnerability decoys are released, limited execution permissions are granted, 90% of traffic enters core nodes and dynamic routing spoofing is initiated, a 2-second delay in response is provided with a false success message, and all traffic is mirrored to the analysis platform. The adjustment rules are triggered based on attack heat values, with an effective period of 1 hour. If the heat value fluctuates by more than ±10 points or remains below the lower limit for 2 consecutive hours, a reassessment or rollback will be conducted. The attack heat scoring model is a hybrid model integrating rule-based and machine learning approaches, balancing score interpretability and dynamic adaptability. The model's input parameters are derived from attack interaction data collected by the intelligent trapping module, specifically including four core features: attack frequency, attack tool complexity, interaction depth, and attack duration. The attack heat scoring model outputs an attack heat value ranging from 0 to 100, and its calculation process is as follows: First, the four types of input feature parameters are standardized by using Min-Max normalization to map the parameters to the 0-1 range, eliminating dimensional differences. Second, a basic heat score is calculated based on preset rules, where attack frequency accounts for 30%, attack tool complexity for 25%, interaction depth for 30%, and attack duration for 15%, and the initial score is obtained by weighting according to these weights. Third, a machine learning sub-model is introduced, based on the random forest algorithm. The training data consists of historical attack events and their corresponding threat level labels. The machine learning sub-model dynamically corrects the basic heat score and optimizes the weights of each feature to adapt to new attack patterns. Fourth, the corrected score is adjusted by incorporating a time decay factor, ultimately generating an attack heat value that reflects the current attack intensity, providing a quantitative basis for the intelligent trapping module to generate trapping intensity commands.

[0042] For example, if an attacker launches 30 attacks on an e-commerce payment trapping node within one hour, the strategy optimization unit extracts feature parameters such as attack frequency, tool complexity, and interaction depth, inputs them into the attack popularity scoring model to calculate a popularity score of 70, matches the emergency level popularity range of 61-100, and generates an emergency level trapping strength instruction. Based on this, the strategy execution unit adjusts the strategy: releases 30% of highly realistic vulnerability decoys containing 3 fake vulnerability features, opens limited execution permissions in the sandbox, directs 90% of the attack traffic to the core trapping node and starts dynamic routing deception, delays the response to attacker requests by 2 seconds and returns a fake "injection successful" prompt, and mirrors all attack traffic to the analysis platform. Finally, these parameters are integrated to update the trapping strategy and execute it.

[0043] In a preferred embodiment of the present invention, attack behavior is quantified by feature parameters and the trapping level is accurately classified by combining heat range, thus avoiding the subjectivity of strategy adjustment. Targeted adjustment of strategy dimensions enables dynamic matching between trapping strategy and attack intensity, significantly improving the deception of advanced attackers and the trapping success rate. Standardized adjustment rules ensure the consistency and efficiency of strategy updates, reduce the cost of manual intervention, and avoid resource waste through hierarchical adjustment, thus balancing the defense effect and system overhead.

[0044] like Figure 5 As shown, preferably, the construction of the attack chain graph and calculation of the threat score includes: extracting attacker behavior information from attack interaction data; performing correlation analysis on the extracted behavior information, establishing connections between behavior nodes based on the sequential logic and causal relationship of the behaviors, forming an initial behavior chain; dividing the initial behavior chain into corresponding attack stages according to a preset attack lifecycle model; constructing an attack chain graph based on the attack stages, behavior nodes, and the correlation between behavior nodes; determining the dimensions used to calculate the threat score based on the attack chain graph and attack interaction data; extracting feature information corresponding to each dimension from the attack interaction data and feature mapping library, and determining the score value of each dimension based on the feature information and preset scoring rules; and performing a comprehensive calculation on the score values ​​of each dimension based on preset weights to obtain the threat score.

[0045] in, refer to An attack chain graph is a topological map that visualizes the complete path of an attack. An attack lifecycle model is a pre-defined standard for dividing attack behavior into stages, allowing the initial attack chain to be divided into corresponding attack stages. Threat scoring dimensions are core indicators for measuring the severity of an attack, including attack stage progression, destructiveness, and tool complexity. Scoring rules are the quantitative standards for each dimension, assigning scores and weights to each.

[0046] Specifically, the security defense module first extracts behavioral information from the attack interaction data; it then establishes behavioral node connections through correlation analysis to form an initial behavioral chain, such as scanning-injection-download; based on the attack lifecycle model, the chain is divided into three stages: "reconnaissance-exploitation-target action"; combining stage labels, behavioral nodes, and correlation strength, an attack chain graph is generated; subsequently, the threat scoring dimensions are determined, and corresponding features are extracted from the data, such as the tool being "automated SQL injection script" and the destructiveness being "medium," and scores are assigned according to rules: stage progress 30 points, tool complexity 20 points, and destructiveness 25 points; finally, based on preset weights: stage 30%, tool 25%, and destructiveness 25%, a comprehensive calculation is performed to obtain a threat score of 30×30%+20×25%+25×25%=24.25 points.

[0047] In a preferred embodiment of the present invention, fragmented attack behaviors are transformed into a visualized complete path through an attack chain graph, which intuitively presents the attacker's tactical intent and solves the problem of "only seeing single points of behavior and not the overall path" in traditional log analysis; multi-dimensional threat scoring, combined with factors such as attack stage and tool characteristics, achieves accurate quantification of threat level; both together provide a scientific basis for subsequent graded response.

[0048] like Figure 6 As shown, preferably, the graded response includes several response levels, and each response level corresponds to a defense mechanism. The determination of the response level includes: extracting the attack stage features and the correlation strength between behavioral nodes from the attack chain graph; fusing and analyzing the attack stage features, correlation strength, and threat score to form an attack threat feature set; matching the attack threat feature set with a preset response level judgment standard, and determining the corresponding response level and defense mechanism based on the matching result.

[0049] More preferably, the generation of the defense effectiveness data includes: acquiring the execution information of the defense mechanism and the changes in the attack state after the execution of the defense mechanism; performing quantitative analysis on the execution information and changes in the attack state based on preset effectiveness evaluation indicators; and integrating the quantitative analysis results to generate defense effectiveness data to reflect the actual effect of the graded response. The attack phase characteristics refer to the distinctive behavioral attributes of each phase in the attack chain graph, such as the port scanning frequency in the reconnaissance phase and the vulnerability type in the exploitation phase, used to determine the threat phase of the attack. Correlation strength is the tightness of the causal relationship between behavioral nodes in the attack chain, quantified as a value between 0 and 1. The attack threat feature set is a comprehensive feature set formed by integrating attack phase characteristics, correlation strength, and threat scores, such as "reconnaissance phase + strong correlation + threat score 45 points" and "targeting phase + strong correlation + threat score 80 points," used to match response levels. The criteria for determining the response level are the preset correspondence rules between the threat feature set and the response level, including: "targeting phase + threat score ≥ 70 points" corresponds to Level 1 response, "exploitation phase + threat score 40-69 points" corresponds to Level 2 response, etc. Defense mechanisms are the specific defense measures preset for each response level. Effectiveness evaluation indicators are quantitative parameters that measure the effectiveness of the defense mechanisms, including attack blocking rate, response latency, and false positive rate. Attack blocking rate = number of blocked attacks / total number of attacks.

[0050] Specifically, the generation process of graded response and defense effectiveness data includes: the security defense module extracts attack stage features from the attack chain graph, such as the action target stage and the correlation strength of behavioral nodes, such as 0.9, and merges them with the threat score, such as 80 points, to form an attack threat feature set; the feature set is matched with the response level judgment criteria to determine it as a level one response; then the corresponding defense mechanism is executed to automatically block IPs, start full traffic cleaning, and generate emergency work orders; the execution information of the defense mechanism is obtained, such as blocking time, cleaning traffic size, and changes in attack status, such as attack interruption and traffic decrease; the above data is quantitatively analyzed based on effectiveness evaluation indicators such as attack blocking rate and response latency, such as a blocking rate of 95% and a latency of 2 seconds; the results are integrated to generate defense effectiveness data, which is used to adjust virtual node features, such as enhancing the simulation degree of the corresponding node and the weight of the attack heat scoring model, such as increasing the weight of the action target stage features.

[0051] In a preferred embodiment of this invention, the response level is accurately determined through multi-dimensional fusion of attack threat feature sets, avoiding over-defense or under-defense. The tiered defense mechanism is dynamically matched with the threat level, ensuring defense effectiveness while reducing resource waste. A closed-loop feedback mechanism for defense performance data enables the system to continuously optimize virtual node simulation and scoring models, improving long-term defense adaptability. The combination of these two elements forms a complete closed loop of "threat identification - tiered response - performance optimization," significantly enhancing the dynamic defense capabilities of data center networks.

[0052] This invention provides a data center network security defense system. A feature acquisition module constructs a high-fidelity data center feature mapping library, providing accurate modeling basis for a honeynet simulation module. Based on this library, the honeynet simulation module dynamically generates virtual subnets consistent with the real network topology and uses a scenario matching algorithm to embed highly realistic decoy data into each virtual node, forming a trapping node. When an attacker interacts with a trapping node, the intelligent trapping module analyzes the interaction behavior in real time and automatically optimizes the trapping strategy strength based on attack heat values, achieving dynamic control over attack traffic. The decoy evolution module further calculates the attack probability of the trapping node and triggers differentiated feature update strategies based on probability thresholds, continuously improving the simulation and deceptiveness of the decoy. Simultaneously, the security defense module transforms the interaction behavior into a visualized attack chain graph and quantifies threat scoring, driving refined hierarchical responses. The resulting defense effectiveness data is fed back to the feature library and heat scoring model weight adjustments, forming a closed-loop adaptive defense system of "environment simulation - behavior trapping - intelligent evolution - threat assessment - dynamic defense - effectiveness feedback," significantly improving the proactive trapping capability, trapping efficiency, and response speed against new attacks.

[0053] In summary, the above description is merely a preferred embodiment of the technical solution of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A data center network security defense system, characterized in that, The data center network security defense system includes: The feature acquisition module is used to acquire multidimensional features of nodes in the data center network and to standardize the multidimensional features in order to build a feature mapping library. The honeycomb simulation module includes a network construction unit and a decoy construction unit. The network construction unit is used to construct a virtual subnet consistent with the data center network topology and node characteristics according to the feature mapping library. The virtual subnet includes a preset trapping strategy, several virtual nodes and their corresponding role type data. The decoy construction unit is used to determine the target business scenario according to the role type data of each virtual node and a preset scenario library, and generate corresponding decoy data to embed into the virtual node to form a trapping node. The intelligent trapping module includes a strategy optimization unit and a strategy execution unit. The strategy optimization unit is used to collect interaction information between the attacker and the trapping node and generate attack interaction data. It is also used to calculate the attack heat value based on the attack interaction data through a preset attack heat scoring model and generate a trapping strength command to adjust the trapping strategy. The strategy execution unit is used to execute the adjusted trapping strategy according to the attacker's behavior. The security defense module is used to construct an attack chain graph and calculate a threat score based on attack interaction data; it is also used to execute a preset graded response based on the attack chain graph and threat score, and generate defense effectiveness data based on the results of the graded response, so as to adjust the weight of virtual node characteristics and attack heat scoring model.

2. The data center network security defense system according to claim 1, characterized in that, The scenario library contains several preset scenarios, each with a corresponding scenario tag. The determination of the business scenario includes: Extract core features from the role type data of each virtual node and match them with scene labels to filter out candidate scenes; Calculate the first matching degree between the core features and each candidate scene; If the highest first matching degree reaches the first preset value, then the candidate scenario corresponding to the first matching degree is taken as the target business scenario; If the first matching degree is less than the first preset value, then the core features are further verified.

3. The data center network security defense system according to claim 2, characterized in that, The supplementary verification includes: Retrieve business scenario features of real nodes that match the virtual node role type from the feature mapping library; The core features of the virtual node are compared with the business scenario features of the corresponding real node to calculate the second matching degree; If the second matching degree reaches the second preset value, then the business scenario corresponding to the real node is determined as the target business scenario; If the second matching degree is less than the second preset value, the business scenario features of other real nodes of the same role type in the feature mapping library are retrieved for repeated verification until a unique matching business scenario is determined.

4. The data center network security defense system according to claim 1, characterized in that, The data center network security defense system also includes a decoy evolution module, used to calculate the attack probability of each decoy node through a preset evaluation strategy, and based on the attack probability, update the characteristics of the decoy nodes through a preset update strategy to optimize the simulation degree of the decoy nodes; the evaluation strategy includes: Based on the interaction information, extract the attacker's effective interactions and total number of probes on the trapping node. The effective interactions include probing interactions and targeted interactions. The proportion of exploratory interactions and targeted interactions in the total number of probes is calculated separately, and the initial probability of being attacked is calculated by combining the similarity decay coefficient of the features of the decoy node and the real node. The targeted interactions are dynamically weighted according to the threat level corresponding to the attack popularity value, and the final attack probability is calculated by combining the basic attack probability.

5. The data center network security defense system according to claim 1, characterized in that, The characteristics of the trapping node include dynamic characteristics and static characteristics. The update strategy includes: Based on the multiple attack probabilities of the decoy node within a preset period, calculate the overall attack probability of the decoy node. When the overall probability of being attacked is higher than the first threshold, the feature mutation algorithm is used to update the dynamic features of the trapping node at preset time intervals. When the overall probability of being attacked is between the first threshold and the second threshold, the static characteristics of the trapping node are updated at preset time intervals. Updates will be paused when the overall probability of being attacked falls below the second threshold.

6. The data center network security defense system according to claim 1, characterized in that, Each of the trapping intensity commands corresponds to a trapping level, and each trapping level corresponds to a heat range. The generation of the trapping intensity command includes: The strategy optimization unit extracts feature parameters from the attack interaction data; Based on the feature parameters, the attack popularity score is calculated using the attack popularity scoring model. Compare the attack heat value with the heat range to determine the trapping level and trapping intensity command.

7. The data center network security defense system according to claim 6, characterized in that, The adjusted trapping strategy includes: The strategy execution unit determines the strategy dimensions that need to be adjusted based on the trapping level; Adjustments are made to each strategy dimension based on preset adjustment rules; The parameters of each strategy dimension are integrated and adjusted and then updated to the trapping strategy.

8. The data center network security defense system according to claim 1, characterized in that, The construction of the attack chain graph and calculation of the threat score include: Extract attacker behavior information from attack interaction data; The extracted behavioral information is analyzed for correlation, and the connections between behavioral nodes are established based on the sequential logic and causal relationship of the behaviors to form an initial behavioral chain. Based on the preset attack lifecycle model, the initial behavior chain is divided into corresponding attack stages; Based on the attack phases, action nodes, and the relationships between action nodes, an attack chain graph is constructed. Based on the attack chain graph and attack interaction data, determine the dimensions used to calculate the threat score; Extract feature information corresponding to each dimension from attack interaction data and feature mapping library, and determine the score value of each dimension according to the feature information and preset scoring rules; A threat score is obtained by comprehensively calculating the scores of each dimension based on preset weights.

9. The data center network security defense system according to claim 1, characterized in that, The tiered response includes several response levels, and each response level corresponds to a defense mechanism. The determination of the response level includes: Extract the correlation strength between attack phase features and behavioral nodes from the attack chain graph; The attack phase characteristics, correlation strength, and threat score are integrated and analyzed to form an attack threat feature set; The attack threat signature set is matched with the preset response level judgment criteria, and the corresponding response level and defense mechanism are determined based on the matching results.

10. The data center network security defense system according to claim 9, characterized in that, The generation of the defense effectiveness data includes: Obtain information on the execution of the defense mechanism and the changes in the attack status after the defense mechanism is executed; Based on preset performance evaluation indicators, quantitative analysis is performed on changes in execution information and attack status. By integrating the results of quantitative analysis, defense effectiveness data is generated to reflect the actual effect of tiered response.

Citation Information

Patent Citations

  • Efficiency evaluation method and system for honeypot high-simulation scene

    CN114666122A

  • Threat intelligence detection method, device, equipment and medium based on honeypot trapping

    CN119766493A

  • Network security defense method and system based on intrusion modeling trapping

    CN119996093A

  • Network attack AI detection analysis method and system based on smart Internet

    CN120281555A

  • Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

    CN120639470A