AD graph honeypot optimization deployment method based on large model and multi-agent collaboration and related equipment
By constructing an AD attack graph and utilizing a large language model and multi-agent collaborative decision-making, the honeypot deployment is optimized, solving the problem that traditional honeypot deployment cannot be dynamically adjusted in large-scale network environments. This achieves efficient and accurate honeypot deployment and response to multi-stage attacks.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-18
- Publication Date
- 2026-03-13
AI Technical Summary
Traditional honeypot deployments cannot be dynamically adjusted in large-scale network environments, resulting in detection blind spots. Furthermore, high-fidelity honeypot deployments are costly, and existing methods struggle to effectively analyze multi-stage attack paths, limiting their defensive effectiveness.
By constructing an AD attack graph of the target network, using large language model analysis and combining multi-agent collaborative decision-making, a honeypot deployment strategy list is generated, and the honeypot deployment location is dynamically adjusted.
Improve the accuracy of honeypot deployment, enhance attack capture rate and interference effect, reduce resource consumption, support dynamic adjustment, and cope with multi-stage attacks.
Smart Images

Figure CN121664468A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to an AD graph honeypot optimization deployment method and related equipment based on large model and multi-agent collaboration. Background Technology
[0002] As cyberattack methods continue to evolve, traditional static defense methods are increasingly inadequate to address dynamically changing cyber threats. Honeypots, as a proactive defense technology, protect real assets by deploying decoy systems to attract and mislead attackers. However, in large-scale network environments, traditional honeypot deployments are typically based on fixed rules or human experience, making it impossible to adjust to dynamic changes in network topology and threat landscape. Large-scale deployment of highly interactive honeypots consumes significant computing and storage resources and often only covers partial network areas, resulting in detection blind spots. Existing methods struggle to effectively analyze and predict multi-stage attack paths, leading to inappropriate honeypot deployment locations and limited defensive effectiveness. Low-simulation honeypots are easily detected by attackers, while high-simulation honeypots are costly to deploy and maintain. Summary of the Invention
[0003] In view of this, the main objective of this invention is to provide an AD graph honeypot optimization deployment method and related equipment based on large model and multi-agent collaboration, in order to solve at least one of the problems in the prior art. This invention can improve the accuracy of honeypot deployment.
[0004] To achieve the above objectives, one aspect of this invention provides an optimized deployment method for AD graph honeypots based on large models and multi-agent collaboration, the method comprising: Construct an AD attack graph for the target network; The AD attack graph was analyzed using a large language model, and the analysis results were obtained. The AD attack graph and the analysis results are processed by multiple agents to generate a honeypot deployment strategy list. Based on the honeypot deployment strategy list, determine the deployment of the target honeypot in the target network.
[0005] In some embodiments, constructing the AD attack graph of the target network includes the following steps: Obtain the topology information, asset information, and vulnerability information of the target network; Based on the topology information, asset information, and vulnerability information, the AD attack graph is constructed.
[0006] In some embodiments, the AD attack graph is analyzed to obtain analysis results, including the following steps: Convert the AD attack graph into prompt words; The prompt words are input into the large language model to obtain key vulnerabilities and attack paths.
[0007] In some embodiments, the multi-agent system includes an attack graph parsing agent, a vulnerability assessment agent, a path analysis agent, a honeypot deployment agent, a simulation agent, and a management agent.
[0008] In some embodiments, the process of using multiple agents to process the AD attack graph and the analysis results to generate a honeypot deployment strategy list includes the following steps: The attack graph is analyzed by an attack graph parsing agent to obtain the key hub nodes; The vulnerability assessment agent evaluates critical vulnerabilities and obtains dynamic risk scores. By using a path analysis agent, attack paths are sorted to obtain a ranking of path hazard values. The key hub nodes, the dynamic risk scores, and the path hazard values are sorted and input into the honeypot deployment agent. Based on preset cost constraints and optimization algorithms, a honeypot deployment strategy scheme is generated. By simulating intelligent agents, the simulation content of each target honeypot in the honeypot deployment strategy scheme is generated; By managing the intelligent agent, the honeypot deployment strategy list is output based on the honeypot deployment strategy scheme, the target honeypot, and the simulation content.
[0009] In some embodiments, the method further includes the following steps: Acquire the interaction data of the target honeypot and the network situation of the target network, and generate situational awareness results; Based on the situational awareness results, detect changes in attack patterns and updated attack paths; Based on the changes in the attack pattern and the updated attack path, the honeypot deployment strategy list is updated. In response to the update request of the honeypot deployment strategy list, the step of constructing the AD attack graph of the target network is returned, and the updated honeypot deployment strategy list is generated; Based on the updated honeypot deployment strategy list, invalid honeypots in the target honeypots are removed, and the deployment of new honeypots in the target network is determined.
[0010] To achieve the above objectives, another aspect of this invention proposes an AD graph honeypot optimization deployment device based on large model and multi-agent collaboration, the device comprising: The attack graph generation module is used to construct the AD attack graph of the target network. The large model analysis module is used to analyze the AD attack graph using a large language model and obtain analysis results. The multi-agent decision-making module is used to process the AD attack graph and the analysis results through multiple agents to generate a honeypot deployment strategy list. The honeypot deployment module is used to determine the deployment of the target honeypot in the target network based on the honeypot deployment strategy list.
[0011] To achieve the above objectives, another aspect of the present invention provides an electronic device, the electronic device including a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the method described above.
[0012] To achieve the above objectives, another aspect of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods described above.
[0013] To achieve the above objectives, another aspect of the present invention provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions to cause the computer device to perform the aforementioned method.
[0014] The embodiments of the present invention include at least the following beneficial effects: The present invention provides an AD graph honeypot optimization deployment method and related equipment based on large model and multi-agent collaboration. This scheme provides a data foundation for large model analysis by constructing an AD attack graph of the target network; by analyzing the AD attack graph through a large language model, the attack graph can be deeply analyzed, key data can be accurately identified, and analysis results can be obtained; through multi-agent collaborative decision-making, the AD attack graph and analysis results are processed to generate a honeypot deployment strategy list, determine the deployment of target honeypots in the target network, and make honeypot deployment more accurate, effectively improving the attack capture rate and interference effect. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1This is a flowchart of the AD graph honeypot optimization deployment method based on large model and multi-agent collaboration provided in the embodiments of the present invention; Figure 2 This is a schematic diagram of the overall architecture for optimized deployment of AD graph honeypots based on large model and multi-agent collaboration provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the AD attack graph generation and analysis process provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the multi-agent collaborative decision-making process provided in an embodiment of the present invention; Figure 5 This is a flowchart of the honeypot deployment optimization algorithm provided in the embodiments of the present invention; Figure 6 This is a schematic diagram of the process for dynamically adjusting honeypot deployment provided in an embodiment of the present invention; Figure 7 This is a schematic diagram of the hardware structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those of this invention; they are merely examples of apparatuses and methods consistent with some aspects of the embodiments of this invention as detailed in the appended claims.
[0018] It should be noted that although functional modules are divided in the system diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first / S100" and "second / S200" in the specification, claims, and the foregoing drawings may be used herein to describe various concepts, but unless specifically stated otherwise, these concepts are not limited by these terms. These terms are used only to distinguish one concept from another. For example, first information may also be referred to as second information without departing from the scope of the embodiments of the invention, and similarly, second information may also be referred to as first information. Depending on the context, the words "if" or "when" as used herein may be interpreted as "when," "in response to a determination," or "in the event of a determination."
[0019] The terms “at least one,” “multiple,” “each,” “any,” etc., used in this invention, “at least one” includes one, two, or more than two; “multiple” includes two or more than two; “each” refers to each of the corresponding multiple; and “any” refers to any one of the multiple.
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein is for the purpose of describing embodiments of the invention only and is not intended to limit the invention.
[0021] Before providing a detailed description of the embodiments of the present invention, some of the nouns and terms involved in the embodiments of the present invention will be explained first. The nouns and terms involved in the embodiments of the present invention are subject to the following interpretations.
[0022] Active Directory (AD) attack graphs are created by visually representing and recording the sum of potential network attack paths used to gain control of Active Directory. AD stores information about network objects (such as users, groups, systems, networks, applications, digital assets, etc.) and their relationships.
[0023] As cyberattack methods continue to evolve, traditional static defenses are increasingly inadequate to address dynamically changing cyber threats. Honeypots, as a proactive defense technology, protect real assets by deploying decoy systems to attract and mislead attackers. In recent years, several new technologies have been attempted to improve honeypot deployments; however, these technologies suffer from limitations such as insufficiently intelligent attack graph analysis, inability to handle large-scale complex networks, and a lack of synergy in AI applications.
[0024] In view of this, embodiments of the present invention provide an AD graph honeypot optimization deployment method and related equipment based on large model and multi-agent collaboration, such as... Figure 2 As shown, this solution comprehensively acquires environmental information of the target network through a data acquisition module; transforms the acquired environmental data into a visualized attack graph through an attack graph generation module; deeply interprets this visualized attack graph using a large model analysis module; and formulates the optimal strategy through a multi-agent decision-making module using a multi-agent system (MAS) architecture, leveraging the division of labor and collaboration among agents. Finally, the honeypot deployment and management module translates the decision into actual honeypot deployment actions, achieving high-precision honeypot deployment. After honeypot deployment, a dynamic adjustment module analyzes data from the honeypot data collector and network traffic in real time, continuously monitoring changes in key indicators. Once a significant change is detected, an alarm is sent to the management agent, triggering a strategy recalculation process, thus achieving a leap from static defense to dynamic adaptive defense.
[0025] Figure 1 This is an optional flowchart of an AD graph honeypot optimization deployment method based on large model and multi-agent collaboration provided in an embodiment of the present invention. Figure 1The method may include, but is not limited to, steps S100 to S400: Step S100: Construct the AD attack graph of the target network; Step S200: Analyze the AD attack graph using a large language model to obtain the analysis results; Step S300: Through multi-agent processing, the AD attack graph and analysis results are processed to generate a honeypot deployment strategy list. Step S400: Determine the deployment of the target honeypot in the target network based on the honeypot deployment strategy list.
[0026] In some embodiments, steps S100 to S200, such as Figure 3 As shown, network asset discovery and vulnerability scanning are used to obtain the target network's topology, asset information, and vulnerability information. Based on this information, an attack graph (AD) is constructed using attack graph generation tools (such as MulVAL), representing all potential attack paths that an attacker might exploit. The AD attack graph is then converted to a new format to provide a data foundation for subsequent large-scale model analysis. In the large-scale model analysis, by identifying key vulnerabilities and nodes, inferring attack paths and probabilities, and assessing potential impacts, an analysis report is generated, outputting a list of key attack paths, a list of key nodes, and a probability and impact assessment report.
[0027] In some embodiments, step S100 may include, but is not limited to, steps S110 to S120: Step S110: Obtain the topology information, asset information, and vulnerability information of the target network; Step S120: Construct an AD attack graph based on topology information, asset information, and vulnerability information.
[0028] In step S110 of some embodiments, by integrating multiple scanning tools (such as Nmap for network discovery and port scanning, and Nessus or OpenVAS for vulnerability scanning), the target network segment is actively scanned periodically or as needed to obtain vulnerability information of the target network. Through the asset inventory manager, the target network's asset database is automatically discovered and maintained. This asset database records asset information including host IP addresses, MAC addresses, operating system types and versions, installed software services and their versions, etc. The connection relationships, communication paths, and logical structures between various assets (such as servers, workstations, and network devices) in the target network are obtained to acquire topology information.
[0029] In this embodiment of the invention, a vulnerability database interface is also included for interacting with local or online vulnerability databases (such as the CVE database or the NVD national vulnerability database) to obtain detailed descriptions of identified vulnerabilities, Common Vulnerability Scoring System (CVSS) scores, remediation suggestions, etc. Furthermore, a data preprocessing unit is used to clean, deduplicatize, standardize, and perform correlation analysis on the collected raw topology information, asset information, and vulnerability information to form structured data in a unified JSON or XML format for use by downstream tasks.
[0030] In step S120 of some embodiments, based on the standardized topology information, asset information, and vulnerability information, an attack graph generation tool is run to obtain an AD attack graph. Optionally, the attack graph generation tool can be a logic-based inference engine (such as MulVAL). Internally, the engine performs automated inference based on a predefined attack rule base (e.g., "If the attacker has user privileges on host A, and host A has a trust relationship with host B, then the attacker can access host B") to generate all possible attack paths. The inference results are constructed into a directed graph (DAG), where nodes represent system states (e.g., "Attacker compromised host X," "Attacker gained database read / write privileges"), and edges represent conditions for state transitions (e.g., "Exploiting the CVE-2024-1234 vulnerability"). This graph is typically output in formats such as GraphML or JSON.
[0031] In some embodiments, step S200 may include, but is not limited to, steps S210 to S220: Step S210: Convert the AD attack graph into prompt words; Step S220: Input the prompt words into the large language model to obtain the key vulnerabilities and attack paths.
[0032] In step S210 of some embodiments, the AD attack graph is converted into a natural language description or structured data prompts, enabling the Large Language Model (LLM) to understand the AD attack graph. Optionally, API calls to the Large Language Model (such as GPT-4, Claude, or specialized models fine-tuned in the cybersecurity domain) are encapsulated through the LLM integration interface. An efficient prompt template is designed to convert structured attack graph data into a natural language description rich in contextual information for LLM processing. For example: "Please analyze the following attack graph. The graph contains [N] nodes and [M] edges. Node A indicates that the attacker has gained web privileges on the web server and can escalate to root privileges (node B) by exploiting the CVE-2024-5678 vulnerability (CVSS 9.8). There is a trust relationship between node B and node C (database server)... Please identify the three most critical attack paths and estimate their success probability and potential business impact." In step S220 of some embodiments, the prompt words are submitted to the LLM (Limited Language Management) system. Leveraging the LLM's semantic understanding and reasoning capabilities, the system analyzes key vulnerabilities, critical nodes, and high-risk attack paths in the attack graph, analyzes the probability and potential impact of different attack paths, and stores these analysis results in a structured manner. For example, after submitting the prompt words to the LLM, the LLM utilizes its powerful semantic understanding capabilities to perform the following key analyses: 1) Critical assessment: Identify critical assets in the network (such as core databases and domain controllers) and their associated vulnerabilities.
[0033] 2) Path analysis and ranking: Infer the most likely efficient paths that attackers will take, and estimate the path probability based on factors such as vulnerability exploitability and required skill level.
[0034] 3) Impact Analysis: Quantitatively assess the potential business impacts of a successful attack, such as data breaches, service interruptions, and economic losses.
[0035] 4) Output formatting: Restructure the LLM analysis results into machine-readable data (such as JSON), mark key nodes, high-risk paths and their attributes, and provide a basis for subsequent decision-making.
[0036] In some embodiments, the multi-agent system includes an attack graph parsing agent, a vulnerability assessment agent, a path analysis agent, a honeypot deployment agent, a simulation agent, and a management agent. These agents work together to handle tasks such as attack graph parsing, vulnerability scoring, path ranking, and honeypot deployment cost-benefit analysis, and jointly formulate the optimal honeypot deployment strategy.
[0037] For example, such as Figure 4 As shown, the system adopts a multi-agent system (MAS) architecture, formulating optimal strategies through the division of labor and cooperation among agents. The management agent acts as the system's "commander," responsible for task coordination, resource allocation, conflict resolution, and final decision-making. It receives the analysis results from the large model module and decomposes tasks to dedicated subordinate agents. 1) Attack Graph Analysis Agent: Proficient in graph theory algorithms, responsible for analyzing the topological structure of the attack graph, calculating the centrality of nodes (such as betweenness centrality and compactness centrality), and identifying hub nodes from the graph structure itself.
[0038] 2) Vulnerability assessment agent: Based on standards such as CVSS and EPSS, and combined with real-time threat intelligence (such as a vulnerability already being exploited in the wild), dynamically scores the actual risk of a vulnerability.
[0039] 3) Path Analysis Agent: Combining the output of LLM and the results of graph analysis, the attack paths are comprehensively ranked, and the overall risk value (Risk = Probability × Impact) of each path is calculated.
[0040] 4) Honeypot Deployment Agents: Built-in optimization algorithms (such as game theory models and genetic algorithms). It comprehensively considers the following factors: Defense benefits: After deploying a honeypot on a certain node, how many high-risk paths can it cover, and to what extent can it increase the attacker's cost (latency, obfuscation)?
[0041] Deployment costs include the hardware resource consumption, operational complexity, and license fees (for commercial honeypot software). High-interaction honeypots are more expensive, while low-interaction honeypots are less expensive.
[0042] Budget constraint: The total cost limit set by the user.
[0043] 5) Simulated Intelligent Agent: Responsible for generating content for highly realistic honeypots. Based on the target node's role (such as file server, database), it automatically generates fake but seemingly reasonable file directories, database tables, login pages, and service response banners, greatly reducing the risk of being detected by attackers.
[0044] Agents communicate with each other through standard Agent Communication Languages (such as FIPA ACL) to negotiate, bid, or share information. Finally, the management agent integrates all opinions to generate a detailed honeypot deployment plan.
[0045] In some embodiments, step S300 may include, but is not limited to, steps S310 to S360: Step S310: The attack graph is analyzed by the attack graph analysis agent to obtain the key hub nodes; Step S320: The vulnerability assessment agent assesses the critical vulnerabilities and obtains a dynamic risk score. Step S330: The attack paths are sorted by the path analysis agent to obtain the path hazard value ranking. Step S340: Input the key hub nodes, dynamic risk scores and path hazard values into the honeypot deployment agent, and generate a honeypot deployment strategy based on preset cost constraints and optimization algorithms. Step S350: Through the simulation agent, generate the simulation content of each target honeypot in the honeypot deployment strategy scheme; Step S360: Through the management agent, output a honeypot deployment strategy list based on the honeypot deployment strategy scheme, target honeypot, and simulation content.
[0046] In step S310 of some embodiments, after the management agent receives the LLM analysis structure, it initiates a decision-making process. The management agent sends the AD attack graph data to the attack graph parsing agent, requesting the attack graph parsing agent to integrate the betweenness centrality, eigenvector centrality, proximity centrality (normalization), and asset value weights of the nodes, according to... The top-K nodes, or critical hub nodes, are selected from highest to lowest. The formulas used to calculate critical hub nodes include: ; In the formula, Represents a node The comprehensive importance index is obtained by integrating multiple centrality indicators and asset value weights, and is used to measure the criticality of a node in the entire network. , , , Indicates the weighting coefficient; Represents a node Normalized betweenness centrality; Represents a node The normalized eigenvector centrality; Represents a node Normalization approaches centrality; Represents a node The asset value weight.
[0047] Betweenness centrality refers to the centrality of a network through nodes. The proportion of the number of shortest paths to the total number of shortest paths. Eigenvector centrality considers the importance of a node's neighbors; a high eigenvector centrality for a node not only means it has many connections, but also that its neighbors are important. Proximity centrality is the reciprocal of the sum of the shortest path lengths from a node to all other nodes in the target network. It reflects the node's "central position" in the network; a higher value indicates a shorter average distance from the node to other nodes, making it easier to interact with other nodes in the network. Asset value weight represents the proportion of the value of the asset represented by the node in the total value.
[0048] In step S320 of some embodiments, the management agent sends a list of critical vulnerabilities (i.e., a set of vulnerabilities) to the vulnerability assessment agent, requesting the node... The risk is caused by this node It is a dynamic aggregation of all vulnerabilities and risks, through 1 The product algorithm considers the Common Vulnerability Scoring System (CVSS), the Exploit Prediction Scoring System (EPSS), exposure surface, patch lag, and in-the-wild exploitation for nodes. The formulas used for dynamic risk scoring include: ; In the formula, Represents a node The dynamic risk score, the closer the value is to 1, the higher the risk; Represents a node A collection of vulnerabilities; , , These represent weighting coefficients, indicating the weights of CVSS, EPSS, and exposure surface in the risk calculation, and are used to adjust the relative importance of each factor. Indicates vulnerability The scoring of a general vulnerability scoring system; Indicates vulnerability The vulnerability exploits the scoring system's prediction score; Indicates vulnerability Exposure score; Indicates vulnerability Patch delay time; Indicates the baseline patch lag time; Represents the natural base; Indicates the time decay coefficient; This represents the field utilization coefficient, which is used to adjust the degree of impact of field utilization on risk. The larger the value, the higher the risk amplification of field utilization. Indicates vulnerability The "exploitation in the wild" indicator represents a vulnerability. Whether there is exploitation in the wild is usually a boolean value (0 or 1).
[0049] In step S330 of some embodiments, the management agent sends a list of attack paths to the path analysis agent. A comprehensive path score is obtained by linearly weighting the success probability, impact, and average node risk. The comprehensive path scores are then sorted in descending order to obtain a ranking of path hazard values. The formula used includes: ; In the formula, Representing a path Overall score; 、 、 These represent the weighting coefficients, which indicate the weights of path success probability, impact, and node risk in the overall score, and are used to adjust the relative importance of each factor. Indicates a path; Representing a path One of the edges in; Representing an edge The probability of success; Indicates the endpoint weight; Indicates the endpoint node Asset value weighting; Representing a path The length.
[0050] In step S340 of some embodiments, the honeypot deployment agent integrates the outputs (including key hub nodes, dynamic risk scores, and path hazard rankings) of the attack graph analysis agent, vulnerability assessment agent, and path analysis agent as input data, and runs an optimization algorithm under given cost constraints to generate a honeypot deployment strategy scheme. For example, the honeypot deployment agent transforms the input data into optimization problem parameters, and the objective function expression of the optimization problem is: ; In the formula, This represents the set of decision variables, indicating whether a node is selected for deployment. Represents a node Decision variables, if Then the node If selected, ,node Not selected; Represents a set of paths; Indicates path weight; Represents a node The interaction type weight represents the node. The contribution of the interaction type (e.g., high or low interaction) to the objective function; Represents the Sigmoid function; Indicates the adjustment parameter; This represents a threshold used to distinguish the importance of nodes; nodes that exceed this threshold are considered more important. Indicates the risk penalty coefficient; Represents a node Risk score; This represents the cost penalty coefficient; Represents a node Deployment costs.
[0051] In solving the above optimization problem, a greedy algorithm is used in the initial stage, based on unity gain. Select high-yield nodes; replace inefficient nodes through neighborhood swapping; if the solution quality is insufficient, call MILP or genetic algorithms for global optimization; when the budget is tight or the critical path is scarce ( (Smaller), the algorithm automatically adjusts the node filtering strategy, prioritizing... High-interaction honeypots are deployed on nodes that traverse the Top-Score path; a dynamic risk mitigation mechanism monitors these nodes in real time. ,when Increase the risk penalty coefficient when the risk level is significantly increased (honeypots are easily identifiable). Automatically suppress this type of deployment. Map the optimization results to an offensive-defensive game strategy, verify the robustness of the scheme in an adversarial environment by calculating Nash equilibrium, and ensure that it maximizes the expected defensive payoff (objective function value). For example, such as Figure 5 As shown, the honeypot deployment problem is modeled as a game between the defender (our side) and the attacker. The defender's strategy is to deploy which type of honeypot on which nodes, while the attacker's strategy is to choose which path to attack. A payoff matrix is constructed: the defender's payoff is the probability of the attack being detected / misdirected multiplied by the asset value, minus the deployment cost; the attacker's payoff is the probability of the attack succeeding multiplied by the asset value, minus their attack cost (including the cost of delays and misdirection). By solving the Nash equilibrium of this game, the optimal honeypot deployment strategy that maximizes the defender's expected payoff under the current information is obtained.
[0052] In step S350 of some embodiments, the honeypot deployment agent submits the plan to the management agent, and the simulation agent generates simulation content for each target honeypot in the plan as needed. The finished products produced by the simulation agent (service banners, data / catalog samples, business behavior scripts, etc.) are the core materials that make the honeypot "like a real asset"; when these finished products are customized to node roles (such as database, domain controller, web) and prioritized for deployment on key hub nodes ( When targeting nodes with high values or those traversing high-risk paths, the maximum trapping and misleading effect can be achieved with minimal deployment: it is easier to intercept intrusions at critical intersections, divert attack traffic away from real assets, prolong the opponent's stay to accumulate complete evidence, and reduce the probability of being identified due to the high fingerprint fit; conversely, non-critical nodes only require lightweight finished products to save costs and noise.
[0053] In step S360 of some embodiments, the management agent finally approves and outputs a list of deployment strategies. When generating the honeypot deployment strategy list, the management agent will include each key hub node ( Items with high values and high path weights are ranked first, and each key hub node is bound to a simulation artifact (such as a specific version of a mirror, banner, dataset, or script) that matches its role attributes. Based on the bound simulation artifacts, the expected benefit of this list item is calculated. Identify risks With cost This process determines the following: the level of honeypot interaction (high / medium / low), the deployment order, the specific simulation package used and its parameter configuration, and the proportion of budget allocated. The final output list is not simply a description of "where to deploy honeypots," but rather a structured list of entries. Each entry includes: node identifier, honeypot interaction type, simulation package and parameters used, priority marker, and budget allocation. Through this mechanism, critical nodes will receive priority access to high-interaction, high-simulation honeypot resources, while non-critical nodes will have their configurations downgraded or deployment delayed, achieving maximum coverage efficiency and overall risk control within budget constraints.
[0054] In step S400 of some embodiments, target honeypots (including high-interaction honeypots and low-interaction honeypots) are deployed at key nodes in the target network according to the honeypot deployment strategy list output by the multi-agent system decision. Network status and attack behavior are monitored in real time, and the honeypot deployment location and type are dynamically adjusted based on this monitoring data to cope with changing threat environments. Optionally, the honeypot deployment strategy list is read through the orchestrator of the honeypot deployment and management module, and target honeypots of specified types and configurations are automatically deployed at the target location by calling an API. The network policy is adjusted as needed using an SDN controller (such as OpenDaylight), copying or redirecting suspicious traffic destined for real services to the honeypots. All interaction activities are continuously recorded while all honeypots are operational. The data collector of the honeypot deployment and management module aggregates the logs to a central database. This data collector centrally collects the interaction logs of all honeypots, recording the attacker's IP address, behavior sequence, attack tools, intent, etc., forming a detailed attack dataset.
[0055] In some embodiments, after deploying the target honeypot, the honeypot deployment strategy is dynamically evaluated and adjusted, which may include, but is not limited to, the following steps: acquiring the interaction data of the target honeypot and the network situation of the target network, and generating situational awareness results; detecting changes in attack patterns and updated attack paths based on the situational awareness results; triggering an update of the honeypot deployment strategy list based on the changes in attack patterns and updated attack paths; responding to the update request of the honeypot deployment strategy list, returning to the step of constructing the AD attack graph of the target network, and generating an updated honeypot deployment strategy list; removing invalid honeypots in the target honeypot based on the updated honeypot deployment strategy list, and determining the deployment of new honeypots in the target network.
[0056] For example, such as Figure 6As shown, in dynamic assessment and adjustment, the situational awareness engine of the dynamic adjustment module analyzes data streams from honeypot data collectors, network IDS / IPS, and external threat intelligence sources in real time, continuously monitoring changes in key indicators, such as: whether new attack patterns or exploit attempts have emerged; whether the activity frequency of an attack path for a deployed honeypot has significantly decreased; and whether there are indications that a honeypot has been identified and bypassed by attackers. Once a significant change is detected, the dynamic adjustment module sends an alert to the management agent, triggering a policy recalculation process ("backflow" to the multi-agent decision-making module), thereby achieving a leap from static defense to dynamic adaptive defense. Suppose the engine detects a new zero-day exploit attempt targeting a node not covered by existing honeypots. The change detector determines that the current policy is no longer optimal. The dynamic adjustment module sends a "recalculation" request to the management agent. The entire multi-agent decision-making process is triggered again, but this time incorporating new threat information. The system generates a new deployment policy; the deployment module may remove some invalid honeypots and deploy new honeypots on new critical nodes. This cycle repeats, allowing the defense system to continuously evolve and remain highly efficient.
[0057] This invention also provides an AD graph honeypot optimization deployment device based on large model and multi-agent collaboration, which can realize the above-mentioned AD graph honeypot optimization deployment method based on large model and multi-agent collaboration. The device includes: The attack graph generation module is used to construct the AD attack graph of the target network. The large model analysis module is used to analyze AD attack graphs using large language models and obtain analysis results. The multi-agent decision-making module is used to process the AD attack graph and analysis results through multiple agents to generate a list of honeypot deployment strategies. The honeypot deployment module is used to determine the deployment of target honeypots in the target network based on the honeypot deployment policy list.
[0058] It is understood that the content of the above method embodiments is applicable to the present device embodiments. The specific functions implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0059] This invention also provides an electronic device, which includes a processor and a memory. The memory stores a computer program, and the processor executes the computer program to implement the above-described method. This electronic device can be any smart terminal, including a tablet computer, an in-vehicle computer, or similar device.
[0060] It is understood that the content of the above method embodiments is applicable to this device embodiment. The specific functions implemented by this device embodiment are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0061] refer to Figure 7 , Figure 7 The hardware structure of an electronic device according to another embodiment is illustrated. The electronic device includes: The processor 501 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present invention. The memory 502 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 502 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 502 and is called and executed by the processor 501. The input / output interface 503 is used to implement information input and output; The communication interface 504 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.). Bus 505 transmits information between various components of the device (e.g., processor 501, memory 502, input / output interface 503, and communication interface 504); The processor 501, memory 502, input / output interface 503, and communication interface 504 are connected to each other within the device via bus 505.
[0062] This invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.
[0063] It is understood that the content of the above method embodiments is applicable to this storage medium embodiment. The specific functions implemented in this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those achieved in the above method embodiments.
[0064] This invention also provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device can read the computer instructions from the computer-readable storage medium and execute the computer instructions to cause the computer device to perform the aforementioned method.
[0065] In summary, the AD graph honeypot optimization deployment method and related equipment based on large model and multi-agent collaboration of the present invention have the following advantages: 1. The embodiments of the present invention use large-scale model deep analysis of attack graphs and multi-agent collaborative decision-making to more accurately identify key attack paths and nodes, making honeypot deployment more precise and effectively improving attack capture rate and interference effect.
[0066] 2. The embodiments of the present invention optimize the deployment strategy to avoid unnecessary honeypot deployment and reduce resource consumption; support dynamic adjustment of honeypots to improve resource utilization.
[0067] 3. The embodiments of the present invention can effectively deal with multi-stage and covert APT attacks, and extend the attack chain and increase the attack cost by intelligently interacting with attackers.
[0068] 4. The embodiments of the present invention enable the multi-agent system to autonomously learn and adjust strategies based on real-time threat data, and the large model provides powerful reasoning capabilities, making the system more intelligent and adaptable.
[0069] In some alternative embodiments, the functions / operations mentioned in the block diagrams may not occur in the order shown in the operation diagrams. For example, depending on the functions / operations involved, two consecutively shown blocks may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order. Furthermore, the embodiments presented and described in the flowcharts of this invention are provided by way of example to provide a more comprehensive understanding of the technology. The disclosed methods are not limited to the operations and logic flows presented herein. Alternative embodiments are contemplated in which the order of various operations is altered and sub-operations described as part of a larger operation are executed independently.
[0070] Furthermore, although the invention has been described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the described functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in a separate physical device or software module. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the invention. Rather, given the properties, functions, and internal relationships of the various functional modules in the apparatus disclosed herein, the actual implementation of the module will be understood within the scope of conventional skill of an engineer. Therefore, those skilled in the art can implement the invention as set forth in the claims using ordinary techniques without excessive experimentation. It is also understood that the specific concepts disclosed are merely illustrative and not intended to limit the scope of the invention, which is determined by the full scope of the appended claims and their equivalents.
[0071] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, essentially, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0072] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0073] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0074] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0075] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0076] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.
[0077] The above is a detailed description of the preferred embodiments of the present invention. However, the present invention is not limited to the embodiments described. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of the present invention. All such equivalent modifications or substitutions are included within the scope defined by the claims of the present invention.
Claims
1. An optimized deployment method for AD graph honeypots based on large models and multi-agent collaboration, characterized in that, Includes the following steps: Construct an AD attack graph for the target network; The AD attack graph was analyzed using a large language model, and the analysis results were obtained. The AD attack graph and the analysis results are processed by multiple agents to generate a honeypot deployment strategy list. Based on the honeypot deployment strategy list, determine the deployment of the target honeypot in the target network.
2. The method according to claim 1, characterized in that, The construction of the AD attack graph for the target network includes the following steps: Obtain the topology information, asset information, and vulnerability information of the target network; Based on the topology information, asset information, and vulnerability information, the AD attack graph is constructed.
3. The method according to claim 1, characterized in that, The analysis of the AD attack graph using a large language model to obtain the analysis results includes the following steps: Convert the AD attack graph into prompt words; The prompt words are input into the large language model to obtain key vulnerabilities and attack paths.
4. The method according to claim 1, characterized in that, The multi-agent system includes an attack graph parsing agent, a vulnerability assessment agent, a path analysis agent, a honeypot deployment agent, a simulation agent, and a management agent.
5. The method according to claim 1, characterized in that, The process of using multiple agents to process the AD attack graph and the analysis results to generate a honeypot deployment strategy list includes the following steps: The attack graph is analyzed by an attack graph parsing agent to obtain the key hub nodes; The vulnerability assessment agent evaluates critical vulnerabilities and obtains dynamic risk scores. By using a path analysis agent, attack paths are sorted to obtain a ranking of path hazard values. The key hub nodes, the dynamic risk scores, and the path hazard values are sorted and input into the honeypot deployment agent. Based on preset cost constraints and optimization algorithms, a honeypot deployment strategy scheme is generated. By simulating intelligent agents, the simulation content of each target honeypot in the honeypot deployment strategy scheme is generated; By managing the intelligent agent, the honeypot deployment strategy list is output based on the honeypot deployment strategy scheme, the target honeypot, and the simulation content.
6. The method according to claim 1, characterized in that, The method further includes the following steps: Acquire the interaction data of the target honeypot and the network situation of the target network, and generate situational awareness results; Based on the situational awareness results, detect changes in attack patterns and updated attack paths; Based on the changes in the attack pattern and the updated attack path, the honeypot deployment strategy list is updated. In response to the update request of the honeypot deployment strategy list, the step of constructing the AD attack graph of the target network is returned, and the updated honeypot deployment strategy list is generated; Based on the updated honeypot deployment strategy list, invalid honeypots in the target honeypots are removed, and the deployment of new honeypots in the target network is determined.
7. An AD graph honeypot optimization deployment device based on large model and multi-agent collaboration, characterized in that, include: The attack graph generation module is used to construct the AD attack graph of the target network. The large model analysis module is used to analyze the AD attack graph using a large language model and obtain analysis results. The multi-agent decision-making module is used to process the AD attack graph and the analysis results through multiple agents to generate a honeypot deployment strategy list. The honeypot deployment module is used to determine the deployment of the target honeypot in the target network based on the honeypot deployment strategy list.
8. An electronic device, characterized in that, Including the processor and memory; The memory is used to store programs; The processor executes the program to implement the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, The storage medium stores a program that is executed by a processor to implement the method as described in any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Network spoofing defense decision-making method and system based on Flipit intelligent game
CN116962050A
Automatic generation method of attack graph interaction rule for honey point deployment
CN118101346A
PLC high-interaction honeypot system based on multi-agent task splitting and RAG enhancement
CN120433955A