一种基于树突状细胞算法的动态蜜阵防御方法和相关设备

By employing a dynamic honeycomb defense method based on dendritic cell algorithm, real attacks and false scans can be distinguished in real time. This solves the problems of high false alarm rate and slow response in traditional honeycomb defense schemes, realizes intelligent and real-time network protection, and reduces the risk of lateral movement.

CN121644139BActive Publication Date: 2026-07-17GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-11
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Traditional honeycomb defense solutions cannot effectively distinguish between real attacks and false scans, resulting in high false alarm rates, long signal-to-decision links, slow response times, high risk of attackers moving laterally, and insufficient intelligence, precision, and real-time capabilities in network protection.

Method used

A dynamic honeycomb defense method based on dendritic cell algorithm is adopted. By acquiring the original network traffic and antigen ID when the honey point is touched, four types of immune native signals are quantified. The dendritic cell algorithm unit is used to generate immune decision signals, and dendritic cell agents are embedded in the honey point to perform accumulation operations. High-risk and low-risk behaviors are distinguished in real time, and the honeycomb transformation mechanism is triggered to achieve micro-isolation.

Benefits of technology

Significantly reduces false alarm rate, improves the intelligence, precision and real-time level of network protection, maximizes the time to hold attackers, induces attackers to expose more information, locally cuts off attack traffic, and reduces the risk of lateral movement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644139B_ABST
    Figure CN121644139B_ABST
Patent Text Reader

Abstract

本申请公开了一种基于树突状细胞算法的动态蜜阵防御方法和相关设备,方法包括:对网络流量进行量化得到免疫原生信号;将免疫原生信号、抗原ID及时间戳封装成结构化文件数据输入数据队列;通过树突状细胞算法单元对数据队列进行随机采样,生成协同刺激分子、半成熟信号和成熟信号;当协同刺激分子的累加值达到预设防御阈值时,若成熟信号的累加值大于半成熟信号的累加值,则确定触碰蜜点的动作为高危行为;若蜜点的抗原成熟环境抗原值超过预设成熟抗原阈值,则确定触碰蜜点的攻击者深陷蜜点,并触发蜜阵变换机制。本申请能实时区分真实攻击与误触扫描,降低误报率,提升网络防护的智能化、精细化和实时化水平,可广泛应用于网络安全技术领域。
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Network data anomaly detection method based on dendritic cell algorithm

    CN102123062A

  • Intrusion detection method and system based on intelligent algorithm

    CN110912882A