Attack traffic processing method and device, equipment, medium and program product
By unifying the redirection of attack traffic to a shared honeypot system for virtual mapping and interactive analysis in a multi-tenant cloud environment, the problems of resource waste and insufficient cross-domain defense in honeypot systems are solved, thereby reducing costs and improving defense capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA UNIONPAY
- Filing Date
- 2025-12-02
- Publication Date
- 2026-04-17
AI Technical Summary
In a multi-tenant cloud environment, deploying honeypot systems independently leads to redundant investment in hardware resources, high operation and maintenance costs, and the distributed deployment architecture makes it difficult to achieve cross-tenant attack intelligence sharing and collaborative defense.
By unifying the attack traffic from multiple network domains to a shared honeypot system, virtual attack information is generated using virtual mapping technology and then redirected to the shared honeypot system for interactive analysis, enabling cross-domain resource reuse and information sharing.
It reduces tenant deployment costs, improves attack detection and analysis efficiency, and enhances the system's collaborative defense capabilities against cross-network domain attacks.
Smart Images

Figure CN121887440A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to an attack traffic processing method, apparatus, device, medium, and program product. Background Technology
[0002] In multi-tenant cloud computing environments, tenants are typically deployed in isolated virtual network domains, facing increasingly complex internal network security threats. Honeypot systems, as a proactive defense mechanism, attract and analyze attack behavior by deploying decoy resources, effectively identifying potential threats that are difficult for traditional security devices to detect.
[0003] The current mainstream approach is to deploy a dedicated honeypot system independently for each tenant, and to capture and analyze targeted attacks by configuring honeypot clusters and probes within their respective network domains.
[0004] However, when a cloud platform hosts a large number of tenants, the independent deployment model leads to redundant investment in hardware resources, a sharp increase in operation and maintenance costs, and low resource utilization. At the same time, the decentralized deployment architecture makes it difficult to effectively share attack intelligence, hindering the formation of collaborative defense capabilities and making it inadequate in the face of advanced persistent threats across tenants. Summary of the Invention
[0005] This application provides an attack traffic processing method, apparatus, device, medium, and program product to solve the technical problems of high cost and difficulty in cross-domain communication of honeypot systems in multi-tenant cloud environments. By unifying the attack traffic of multiple network domains to a shared honeypot system, cross-domain communication and resource reuse are realized, thereby reducing tenant deployment costs and platform maintenance costs.
[0006] Firstly, this application provides an attack traffic processing method applied to a cloud server, wherein the cloud server includes multiple network domains, a traffic processing module, and a shared honeypot system; attack traffic from each of the network domains is sent to the shared honeypot system through the traffic processing module for attack interaction;
[0007] The method includes:
[0008] Obtain attack traffic targeting the network domain;
[0009] The original attack information in the attack traffic is processed by network virtual mapping to generate corresponding virtual attack information.
[0010] Based on the virtual attack information, the attack traffic is redirected to the shared honeypot system for attack interaction, and the interaction information of the attack traffic is obtained;
[0011] Based on the mapping relationship between the virtual attack information and the original attack information, the interactive information is returned to the attack terminal corresponding to the network domain.
[0012] In one optional implementation, acquiring attack traffic targeting the network domain includes:
[0013] The data flow accessing the network domain is monitored by a traffic monitoring unit deployed in the network domain.
[0014] When the traffic monitoring unit detects a data flow that matches the preset attack characteristics, it determines that it is attack traffic targeting the network domain.
[0015] The attack traffic is forwarded to the traffic processing module through the traffic redirection unit in the network domain according to the preset traffic redirection strategy.
[0016] In one optional implementation, when the traffic monitoring unit detects a data flow that matches preset attack characteristics, it determines that it is attack traffic targeting the network domain, including:
[0017] When a data stream accessing a preset network port and / or a non-existent network address is detected, the data stream is collected;
[0018] Obtain domain identifier information that represents the network domain, and encapsulate the collected data stream based on the domain identifier information to generate attack traffic targeting the network domain.
[0019] In one optional implementation, the collected data stream is encapsulated based on the domain identification information to generate attack traffic targeting the network domain, including:
[0020] Obtain the virtual local area network label corresponding to the network domain as the domain identification information;
[0021] Based on the virtual LAN tag, the collected data stream is encapsulated using a preset encapsulation protocol, and the encapsulated data stream tag is used as attack traffic targeting the network domain.
[0022] In one optional implementation, the original attack information in the attack traffic is subjected to virtual mapping processing to generate corresponding virtual attack information, including:
[0023] The attack traffic is analyzed to obtain the original attack information of the attack traffic; the original attack information includes the original source network location information and the original destination network location information, wherein the network location information includes network port and / or network address;
[0024] The original source network location information is subjected to virtual mapping processing to obtain the corresponding virtual source network location information;
[0025] The original destination network location information is subjected to virtual mapping processing to obtain the corresponding virtual destination network location information.
[0026] In one optional implementation, the original source network location information is subjected to virtual mapping processing to obtain corresponding virtual source network location information, including:
[0027] Obtain the intermediate network location information of the traffic processing module;
[0028] The intermediate network location information is mapped to the virtual source network location information of the attack traffic.
[0029] In one alternative implementation, the shared honeypot system includes multiple sub-honeypot systems;
[0030] The original destination network location information is subjected to virtual mapping processing to obtain corresponding virtual destination network location information, including:
[0031] Based on the original attack information and the resource status of each of the sub-honeypot systems, the target sub-honeypot system corresponding to the attack traffic is determined;
[0032] The target network location information of the target sub-honeypot system is mapped to the virtual target network location information of the attack traffic.
[0033] In one optional implementation, determining the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the system resource status of each sub-honeypot system includes:
[0034] Based on the original attack information, candidate sub-honeypot systems with corresponding analysis capabilities are matched for the attack traffic;
[0035] Obtain the real-time resource status of each of the candidate sub-honeypot systems;
[0036] Based on the real-time resource status, a target sub-honeypot system whose resource load meets preset conditions is selected from the candidate sub-honeypot systems.
[0037] In one optional implementation, based on the original attack information, matching the attack traffic with candidate sub-honeypot systems possessing corresponding analytical capabilities within the shared honeypot system includes:
[0038] Based on the original attack information, identify the attack characteristics corresponding to the attack traffic;
[0039] Based on the attack characteristics, candidate sub-honeypot systems with corresponding analytical capabilities are matched within the shared honeypot system.
[0040] In one optional implementation, the interactive information is returned to the attack terminal corresponding to the network domain based on the original attack information and the virtual attack information, including:
[0041] Based on the virtual attack information corresponding to the interactive information, determine the corresponding original attack information and domain identification information;
[0042] The interaction information is encapsulated based on the domain identifier information to generate encapsulated interaction data.
[0043] Based on the original attack information, the encapsulated interactive data is returned to the corresponding attacker's terminal.
[0044] In one alternative implementation, the method further includes:
[0045] Obtain the attack analysis results generated by the shared honeypot system based on the attack interaction, and the attack analysis results include alarm information;
[0046] Based on the original attack information and the virtual attack information, the network domain corresponding to the attack traffic is determined;
[0047] The alarm information is sent to the user terminal corresponding to the network domain.
[0048] Secondly, this application provides an attack traffic processing device applied to a cloud server, the cloud server including multiple network domains, a traffic processing module, and a shared honeypot system; the attack traffic of each network domain is sent to the shared honeypot system through the traffic processing module for attack interaction;
[0049] The device includes:
[0050] An attack traffic acquisition module is used to acquire attack traffic targeting the network domain;
[0051] The virtual mapping module is used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information;
[0052] An interactive information acquisition module is used to redirect the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information, and obtain the interactive information of the attack traffic.
[0053] The interactive information feedback module is used to return the interactive information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information.
[0054] Thirdly, this application provides a server, including: a processor, and a memory communicatively connected to the processor;
[0055] The memory stores computer-executed instructions;
[0056] The processor executes computer execution instructions stored in the memory to implement the method as described in the first aspect.
[0057] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect.
[0058] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.
[0059] The attack traffic processing technology provided in this application generates corresponding virtual attack information by virtually mapping the original attack information in the attack traffic; based on the virtual attack information, the traffic is redirected to a shared honeypot system for attack interaction; and the interaction information is returned to the corresponding attacker according to the mapping relationship. This achieves cross-domain reuse of honeypot resources, reduces the deployment cost of honeypots in multi-tenant environments, and improves the efficiency of attack perception and analysis through centralized processing, thereby enhancing the system's collaborative defense capability against cross-network domain attacks. Attached Figure Description
[0060] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0061] Figure 1 An application scenario diagram of the attack traffic processing method provided in this application;
[0062] Figure 2 A flowchart illustrating an attack traffic processing method provided in this application embodiment. Figure 1 ;
[0063] Figure 3 A flowchart illustrating an attack traffic processing method provided in this application embodiment. Figure 2 ;
[0064] Figure 4 A schematic diagram of an attack traffic processing device provided in this application;
[0065] Figure 5 This is a block diagram of a server provided in this application.
[0066] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0067] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0068] The collection, storage, use, processing, transmission, provision, and disclosure of financial data or user data involved in the technical solution of this application all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0069] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0070] In multi-tenant cloud computing environments, tenants are typically deployed in isolated virtual network domains, facing increasingly complex internal network security threats. Honeypot systems, as a proactive defense mechanism, attract and analyze attack behavior by deploying decoy resources, effectively identifying potential threats that are difficult for traditional security devices to detect.
[0071] The current approach involves deploying a dedicated honeypot system independently for each tenant, configuring honeypot clusters and probes within their respective network domains to capture and analyze targeted attacks.
[0072] For example, the current solution uses black hole routing technology to divert network domain attack traffic to tenant-specific honeypot clusters via VPC probes. However, when the cloud platform hosts a large number of tenants, the independent deployment model leads to redundant investment in hardware resources, a sharp increase in operation and maintenance costs, and low resource utilization. At the same time, the distributed deployment architecture makes it difficult to effectively share attack intelligence, hindering the formation of collaborative defense capabilities and making it inadequate in the face of advanced persistent threats across tenants.
[0073] The attack traffic processing method provided in this application aims to solve the aforementioned technical problems of the prior art. Specifically, it generates corresponding virtual attack information by virtually mapping the original attack information in the attack traffic; it redirects the traffic to a shared honeypot system for attack interaction based on the virtual attack information; and it returns the interaction information to the corresponding attacker according to the mapping relationship. This achieves cross-domain reuse of honeypot resources, reduces the deployment cost of honeypots in multi-tenant environments, and improves the efficiency of attack detection and analysis through centralized processing, thereby enhancing the system's collaborative defense capability against cross-network domain attacks.
[0074] The attack traffic processing method provided in this application is applicable to network security protection scenarios in multi-tenant cloud environments. For example, in cloud platform security protection scenarios in industries such as finance, government affairs, and e-commerce, different tenants are deployed in mutually isolated virtual private clouds. This solution can achieve unified detection and analysis of attack traffic while ensuring the isolation requirements of each tenant's network.
[0075] Furthermore, the above methods can also be applied to the collaborative network security protection of multiple branches of an enterprise group. The network traffic of each branch can be centrally diverted to the group-level security analysis platform through this solution to achieve threat intelligence sharing and joint protection.
[0076] In summary, any application scenario that requires centralized detection and resource sharing of cross-network domain attack traffic while maintaining network isolation requirements falls under the application scenario of the attack traffic processing technology solution in this application.
[0077] For ease of understanding, the following is based on Figure 1 The application scenarios applicable to the embodiments of this application are described below. Figure 1 This diagram illustrates an application scenario of the attack traffic processing method provided in this application. (See also...) Figure 1 Taking a multi-tenant cloud platform security protection scenario as an example, this scenario mainly involves attacker terminals and cloud servers; among them, the cloud server includes multiple network domains, traffic processing modules and a shared honeypot system; specifically, the attack traffic of each network domain is sent to the shared honeypot system through the traffic processing module for attack interaction.
[0078] Based on this, the attack traffic handling method in this scenario includes the following steps:
[0079] 1. The attacker's terminal launches attack traffic towards the target network domain;
[0080] 2. The traffic monitoring unit in the network domain identifies attack traffic and forwards it to the traffic processing module;
[0081] 3. The traffic processing module performs protocol parsing and virtual mapping on the attack traffic to generate virtual attack information;
[0082] 4. Redirect attack traffic to the shared honeypot system based on virtual attack information;
[0083] 5. The shared honeypot system interacts with attack traffic for analysis, generating interactive information;
[0084] 6. The traffic processing module returns the interaction information to the corresponding attacker's terminal based on the mapping relationship.
[0085] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0086] Figure 2 A flowchart illustrating an attack traffic processing method provided in this application embodiment. Figure 1 This method can be executed by an attack traffic processing device, which may be deployed on a cloud server. The cloud server includes multiple network domains, a traffic processing module, and a shared honeypot system. Attack traffic from each network domain is sent to the shared honeypot system via the traffic processing module for attack interaction. This attack traffic processing device can be a server or an electronic device; the following description uses a server as an example. The method in this embodiment can be implemented through software, hardware, or a combination of both, such as... Figure 2 As shown, the method includes the following steps:
[0087] S201. Obtain attack traffic targeting the network domain.
[0088] The cloud server comprises multiple isolated network domains, each corresponding to an independent operating environment for a single tenant. Each network domain is equipped with a dedicated traffic monitoring unit to continuously monitor and analyze its internal traffic. Upon detecting attack traffic, it forwards it to a pre-configured traffic processing module within the cloud server. This module then forwards the traffic to a shared honeypot system shared by all network domains. Within the honeypot system, the attack traffic undergoes interactive processing to obtain relevant information, effectively misleading attackers, delaying or blocking their attack process, and enhancing the overall network security.
[0089] In this embodiment, the traffic monitoring unit can be deployed in the following ways: first, by installing lightweight traffic acquisition tools on key servers and terminal devices within the network domain; second, by deploying traffic acquisition tools at key acquisition ports within the network domain. It should be understood that the above methods can be used individually or in combination to achieve flexible and efficient acquisition and analysis of attack traffic.
[0090] Specifically, when an attacker scans and probes the current network domain, this unit can filter data streams within the network domain using preset attack traffic identification rules, thereby extracting data streams that match attack characteristics. Further, based on information such as the domain identifier of the current network domain, the identified data streams are encapsulated to generate attack traffic targeting that network domain, and the generated attack traffic is sent to the traffic processing module.
[0091] S202. Perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information.
[0092] In this embodiment, virtual mapping processing can be understood as mapping the attacker's network location information and the network location information of the current network domain that the attacker intends to access, contained in the attack traffic, to the network location information of the traffic processing module and the shared honeypot system. This enables the traffic processing module to redirect the attack traffic to the shared honeypot, thereby establishing traffic interaction between the attacker and the honeypot, misleading the attacker, and enhancing the security protection of the network domain.
[0093] Specifically, when the traffic processing module receives encapsulated attack traffic, it parses the attack traffic to obtain the original attack information. The original attack information includes, but is not limited to, one or more of the following fields: source IP address, destination IP address, source port, destination port, protocol type, attack type label, traffic occurrence timestamp, and packet payload summary.
[0094] To accurately forward attack traffic to the shared honeypot system for interactive analysis, a virtual mapping process is performed on the network location information in the original attack information. This network location information includes one or more of the following: source address, destination address, source port, and destination port. The virtual mapping process maps the address and / or port to the virtual network location corresponding to the traffic processing module and the shared honeypot system. This guides the attack traffic to the honeypot environment for further analysis without exposing the real network domain information.
[0095] S203. Based on virtual attack information, redirect attack traffic to the shared honeypot system for attack interaction and obtain the interaction information of the attack traffic.
[0096] In this embodiment, the traffic processing module redirects and forwards the parsed and restored attack traffic based on the virtual attack information generated in the aforementioned steps. Specifically, the module, according to the virtual network location obtained after virtual mapping, guides the attack traffic from the original current network domain to the shared honeypot system by modifying the packet header or configuring routes.
[0097] Once attack traffic enters the shared honeypot system, the system simulates real network services to interact with the attacker, fully recording all interactions, including handshake processes, command transmissions, file uploads, and vulnerability exploitation attempts, thus generating detailed interaction information. This information not only serves to immediately confuse and delay attackers but also provides a data foundation for subsequent attack analysis and security strategy optimization.
[0098] S204. Based on the mapping relationship between virtual attack information and original attack information, return the interactive information to the attack terminal corresponding to the network domain.
[0099] In this embodiment, the shared honeypot system sends the generated interactive information to the traffic processing module based on the virtual attack information. The traffic processing module then performs reverse forwarding processing on the interactive information from the shared honeypot system based on the established mapping relationship between the virtual attack information and the original attack information.
[0100] Specifically, based on the above mapping relationship, the traffic processing module restores the source network location information and destination network location information in the interactive information from the virtual address of the shared honeypot system to the real address in the original attack traffic.
[0101] Subsequently, the module encapsulates the processed interactive information into a seemingly normal response data packet from the current network domain and returns it to the corresponding attacker along its original path. This allows the attacker to continuously receive seemingly genuine interactive feedback, thereby maintaining the continuity of the deceptive session and enhancing the overall honeypot system's ability to confuse and restrain attack behavior.
[0102] In the above technical solution, attack traffic detected in multiple network domains is uniformly forwarded to a shared honeypot system for interaction. The original information in the attack traffic is transformed and restored using a network virtual mapping mechanism. This achieves continuous deception and attack analysis of attackers while isolating attacks, realizes cross-domain reuse of honeypot resources, reduces the deployment cost of honeypots in multi-tenant environments, and improves the efficiency of attack perception and analysis through centralized processing, thereby enhancing the system's collaborative defense capability against cross-network domain attacks.
[0103] Based on the above implementation methods, the detailed process of attack traffic processing will be further described in detail below. It should be noted that the following description is merely an exemplary implementation of the attack traffic processing scheme and does not constitute a limitation on the technical solution of this application.
[0104] In this embodiment, taking any tenant's network domain as an example, an optional implementation method for obtaining attack traffic targeting the current network domain may include: monitoring the data flow accessing the network domain through a traffic monitoring unit deployed in the network domain; when the traffic monitoring unit detects a data flow that matches preset attack characteristics, determining that it is attack traffic targeting the network domain; and forwarding the attack traffic to the traffic processing module through a traffic redirection unit in the network domain according to a preset traffic redirection strategy.
[0105] In this embodiment, at least one cloud server or offline host is deployed within the current network domain, and each server or host is used to process data streams corresponding to different services. To effectively identify attack traffic, traffic monitoring units, such as traffic probes implemented in the form of lightweight agents, can be pre-deployed on each server or host to comprehensively and continuously monitor all data streams entering the current network domain.
[0106] Specifically, in this embodiment, the traffic monitoring unit pre-stores judgment conditions for identifying attack characteristics; then, based on the judgment conditions, the unit performs real-time analysis on the data flow accessing the current network domain, and when the data flow meets any judgment condition, it is identified as attack traffic targeting the current network domain.
[0107] Building upon the above, pre-deployed traffic redirection units within the current network domain can be used to redirect traffic according to a preset strategy. For example, a black hole routing mechanism can be employed to automatically redirect identified attack traffic to a traffic processing module deployed within the same cloud server, thus achieving redirected forwarding of attack traffic.
[0108] Specifically, after identifying attack traffic, the traffic redirection unit redirects all identified attack traffic packets to the traffic processing module by configuring blackhole routing rules pointing to the traffic processing module. Upon receiving the traffic, the module performs protocol parsing and information extraction on the attack traffic, and then forwards it to the shared honeypot system for subsequent attack interactions and behavior analysis.
[0109] The above methods enable the identification and redirection of attack traffic targeting network domains, improving the real-time performance and accuracy of threat detection. At the same time, centralized processing of attack traffic enables cross-domain communication and resource reuse, reducing deployment costs.
[0110] In the above embodiments, an optional implementation of the traffic monitoring unit monitoring data streams that meet the attack characteristics may include: collecting data streams when a data stream accessing a preset network port and / or not having a network address is detected.
[0111] In this embodiment, to optimize resource utilization, key network ports in the current network domain can be monitored, including but not limited to port 22 for SSH service, port 3306 for MySQL database service, and ports 80 and 443 commonly used by web applications. When external traffic is detected attempting to access the above ports, it is determined that the data stream matches the preset attack characteristics, and the data stream is collected.
[0112] Furthermore, the traffic monitoring unit provided in this embodiment also has the ability to monitor network address access behavior. When a data flow is detected attempting to access a network address that does not exist in the current network domain or has been marked as invalid, the data flow is also determined to meet the attack characteristics, and the data flow is collected.
[0113] By combining port monitoring and address monitoring as described above, this embodiment can improve the identification coverage and detection accuracy of malicious traffic such as scanning probes and targeted attacks while taking into account system resource consumption, thereby improving the attack detection rate.
[0114] Based on the above, in order to ensure that the shared honeypot system can accurately establish the association between attack behavior and the corresponding tenant network domain, thereby effectively improving the accuracy of security alerts, this embodiment encapsulates the data stream based on the domain identification information of the current network domain before forwarding the data stream that meets the attack characteristics as attack traffic to the traffic processing module, generating attack traffic with a clear domain identifier.
[0115] Specifically, the traffic monitoring unit encapsulates the identified data streams, including but not limited to embedding information for uniquely identifying network domains in specific fields of the data packets. This information may include at least one of tenant ID, network domain number, or virtual private cloud identifier. In this way, even when processing mixed attack traffic from multiple network domains in a shared honeypot environment, the system can still accurately trace and reconstruct the original network domain to which each attack traffic originated, thus providing a reliable basis for subsequent accurate alerts and tenant security analysis.
[0116] In the above embodiments, an optional implementation method for encapsulating the collected data stream based on domain identification information to generate attack traffic targeting the network domain may include: obtaining a virtual local area network (VLAN) tag corresponding to the network domain as domain identification information; based on the VLAN tag, performing protocol encapsulation processing on the collected data stream using a preset encapsulation protocol, and using the encapsulated data stream tag as attack traffic targeting the network domain.
[0117] Specifically, the virtual local area network (VLAN) tag corresponding to the current network domain is obtained and determined as the domain identification information of the current local area network. Based on the VLAN tag, the collected data stream is encapsulated using a preset encapsulation protocol.
[0118] For example, the data stream can be marked and encapsulated at the data link layer by adding a VLAN tag header; or, an overlay network encapsulation protocol such as VLAN or GRE can be used to embed the VLAN identification information as an extended field into the data stream header at the network layer or transport layer to achieve encapsulation, and the encapsulated data stream can be used as attack traffic targeting the network domain.
[0119] In the above implementation, the encapsulated data stream retains the original attack characteristics while carrying a clear network domain affiliation identifier, enabling the subsequent traffic processing module to accurately distinguish attack traffic from different tenants (network domains) based on the encapsulation information, thereby achieving precise tracing and secure isolation of attack behavior.
[0120] When the traffic processing module receives attack traffic from the network domain, it parses it to obtain the original attack information, and then performs virtual mapping on the network location information in the original attack information to establish traffic interaction between the attacker and the honeypot.
[0121] Based on this, an optional implementation of virtual mapping of the original attack information in this embodiment may include: parsing the attack traffic to obtain the original attack information of the attack traffic; the original attack information includes original source network location information and original destination network location information, wherein the network location information includes network port and / or network address; performing virtual mapping processing on the original source network location information to obtain the corresponding virtual source network location information; and performing virtual mapping processing on the original destination network location information to obtain the corresponding virtual destination network location information.
[0122] Specifically, the traffic processing module parses the received attack traffic and extracts the original attack information contained within it. This original attack information mainly includes the original source network location information and the original destination network location information. Optionally, the network location information can be understood as a location identifier used to uniquely identify a communication endpoint or service within the network, such as containing a network port and / or network address.
[0123] For example, the parsed original source network location information may include the attacker's real IP address (e.g., 192.168.1.100) and / or source port (e.g., 54321); the original destination network location information may include the non-existent (bait) IP address of the attack target (e.g., 10.0.0.250) and / or destination port (e.g., 80).
[0124] Furthermore, the original source network location information is virtually mapped. Specifically, based on a pre-defined mapping table within the module, a temporary virtual source IP address (e.g., 172.16.0.10) and / or a corresponding virtual source port (e.g., 40001) are assigned to the attack traffic. This not only hides the attacker's true identity and original port information, preventing the backend honeypot system from directly obtaining its real network location, but also provides a routing basis for the correct return of subsequent honeypot response traffic.
[0125] In addition, the original destination network location information is virtually mapped. For example, according to a preset policy, attack traffic that originally pointed to the non-existent (bait) IP address 10.0.0.250 and / or destination port 80 can be redirected to one or more real honeypot system IP addresses (such as 192.168.100.5) and / or service ports (such as 8080).
[0126] In this way, by bidirectionally mapping and converting source and destination network location information (including IP address and / or port), the attacker's traffic is seamlessly guided to the honeypot without the attacker's knowledge. This establishes an attack interaction channel between the attacker and the honeypot, enabling the redirection of attack traffic to the honeypot environment without exposing the real network domain information.
[0127] In the above implementation process, an optional implementation method for virtually mapping the original source network location information may include: obtaining the intermediate network location information of the traffic processing module; and mapping the intermediate network location information to the virtual source network location information of the attack traffic.
[0128] Specifically, after the traffic processing module obtains the original source network location information contained in the original attack information, it acquires its own intermediate network location information. Here, the intermediate network location information can be understood as the network interface IP address (such as 172.16.0.1) and / or port number (such as 65432) used by the traffic processing module to communicate with the backend shared honeypot system.
[0129] The acquired intermediate network location information is directly mapped to the virtual source network location information of the attack traffic. In this way, before forwarding the attack traffic to the honeypot system, the traffic processing module will modify the header information of the data stream, replacing the source IP address and / or source port number from the attacker's real information (192.168.1.100 and / or 54321) with the traffic processing module's own intermediate network location information (172.16.0.1 and / or 65432).
[0130] Through the above implementation, when the honeypot system receives attack traffic, it assumes that the traffic originates from the traffic processing module (172.16.0.1), thus concealing the attacker's true identity. Simultaneously, the traffic processing module records the mapping relationship between the attacker's real IP and / or port and the intermediate IP and / or port. When the honeypot system generates interactive information, i.e., response traffic, this module can use this record to translate the destination address of the response traffic from the intermediate IP (172.16.0.1) back to the attacker's real IP (192.168.1.100), ensuring that the traffic can be correctly transmitted back, thereby establishing an interactive channel between the attacker and the honeypot.
[0131] In this embodiment, the shared honeypot system consists of multiple sub-honeypot systems. Considering that attack traffic from all network domains needs to share the same honeypot resources, this solution divides the honeypot system into multiple sub-honeypot systems with differentiated characteristics through preset configuration. Each sub-honeypot system is specifically deployed based on different network domain attributes and / or attack type characteristics. When attack traffic from a specific network domain is detected, the system can accurately guide it to the corresponding target sub-honeypot system for attack interaction based on a preset forwarding strategy.
[0132] By adopting the above-mentioned hierarchical deployment method, we can not only achieve the intensive use of honeypot resources, but also ensure the ability to process attack traffic from different sources and of different types, effectively improving the authenticity of attack interactions and the accuracy of security analysis.
[0133] Based on this, an optional implementation method for virtually mapping the original destination network location information may include: determining the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the resource status of each sub-honeypot system; and mapping the destination network location information of the target sub-honeypot system to the virtual destination network location information of the attack traffic.
[0134] In this application, the original attack information includes the network attributes and attack type of the corresponding network domain, such as which tenant's network domain the attack traffic comes from, whether the business type of the network domain is finance, energy or government affairs, etc., and SQL injection, DDoS attack or ransomware identified by signature.
[0135] Furthermore, the traffic processing module also has a pre-defined forwarding policy rule base. This rule base predefines which source or type of attack traffic should be forwarded to which sub-honeypot system(s). For example, the policy might stipulate that "attack traffic from the financial industry network domain should be preferentially forwarded to sub-honeypot A, which has deployed a financial transaction simulation environment," or "detected ransomware traffic should be forwarded to sub-honeypot B, which is specifically used for dynamic analysis of malicious code." At the same time, the traffic processing module also queries the current resource status of each sub-honeypot system, such as CPU utilization, memory usage, and the number of attack sessions currently being hosted, to avoid directing new attack traffic to overloaded sub-honeypots, ensuring the smoothness of attack interactions and the effectiveness of analysis.
[0136] Based on this, the traffic processing module matches the attack characteristics identified in the original information against the aforementioned forwarding policy rule base to determine the corresponding target sub-honeypot system. Furthermore, the traffic processing module maps the real destination network location information of the target sub-honeypot system (i.e., the real IP address and / or monitoring port of the sub-honeypot system, such as 192.168.100.10 and / or 8080) to the virtual destination network location information of the attack traffic. In this way, the traffic processing module modifies the destination IP address and destination port of the attack traffic packets, replacing them with non-existent (bait) IP addresses and / or ports (such as 10.0.0.250 and / or 80) with the real IP address and port (192.168.100.10 and / or 8080) of the selected target sub-honeypot system.
[0137] Through the above implementation method, attack traffic originally sent to non-existent addresses is redirected to target sub-honeypot systems with corresponding analysis capabilities. This not only realizes the sharing and efficient utilization of honeypot resources, but also ensures that different types of attacks can be captured and analyzed in the most suitable simulation environment, thereby improving the realism of attack interactions, deception effects, and the analysis effect of subsequent security analysis.
[0138] In the above implementation, one optional implementation of determining the corresponding target sub-honeypot system based on the original attack information may include: matching candidate sub-honeypot systems with corresponding analysis capabilities to the attack traffic based on the original attack information; obtaining the real-time resource status of each candidate sub-honeypot system; and selecting the target sub-honeypot system whose resource load meets preset conditions from the candidate sub-honeypot systems based on the real-time resource status.
[0139] Specifically, the traffic processing module compares the attack characteristics of the attack traffic in the current network domain, namely the network attributes and attack types of the network domain, with the information stored in the rule base, and filters out at least one sub-honeypot system that meets the conditions and can analyze the attack of this type, thus obtaining candidate sub-honeypot systems.
[0140] Optionally, if there is only one candidate sub-honeypot system, then that candidate sub-honeypot system is directly designated as the target sub-honeypot system; conversely, if there are multiple candidate sub-honeypot systems of the same type, then the real-time resource status of each candidate sub-honeypot system is obtained. In this embodiment, resource status information includes, but is not limited to: CPU utilization, memory usage, number of attack sessions currently being processed, disk I / O load, and network interface traffic. This data characterizing resource status can be collected in real time by a monitoring agent deployed on each sub-honeypot system and reported to the traffic processing module.
[0141] Furthermore, the traffic processing module selects the best candidate sub-honeypot system based on the acquired actual resource status. Optionally, this can be determined by judging whether the resource load meets preset conditions. These preset conditions may include preset thresholds, such as "CPU utilization is below 70%", "memory utilization is below 80%", and "the current number of sessions is below 60% of the system's maximum concurrent processing capacity".
[0142] The traffic processing module evaluates the status of each candidate honeypot to determine if it meets a preset threshold. When multiple honeypots meet the criteria, the system can further employ load balancing strategies such as round-robin or weighted round-robin for selection. Specifically, in weighted round-robin mode, weights are dynamically assigned based on the actual processing capabilities of each candidate honeypot. Candidate honeypots with stronger processing capabilities are assigned higher weight values and are prioritized as the target honeypot system; conversely, if a candidate honeypot has relatively weak processing capabilities, it is assigned a lower weight value, thus reducing its probability of being selected.
[0143] The above implementation methods ensure that the target honeypot has the basic ability to handle attack traffic, while also optimizing the utilization of system resources, effectively improving the overall processing efficiency and stability of the honeypot cluster.
[0144] In the above embodiments, an optional implementation of determining candidate sub-honeypot systems may include: identifying attack characteristics corresponding to attack traffic based on the original attack information; and matching candidate sub-honeypot systems with corresponding analytical capabilities within the shared honeypot system based on the attack characteristics.
[0145] In this embodiment, the attack characteristics include the network attributes of the network domain and the attack type mentioned in the preceding embodiments. After obtaining the original attack information, information extraction is performed on the original attack information to determine the network attributes of the network domain corresponding to the attack traffic. Simultaneously, a pre-integrated lightweight machine learning model, such as a long short-term memory network model or a decision tree model, can be invoked to perform feature analysis on the original attack information to identify the attack type corresponding to the attack traffic.
[0146] Based on this, the analytical capabilities of each sub-honeypot system in the shared honeypot system are matched with the identified network attributes and attack types to determine candidate sub-honeypot systems.
[0147] It should be understood that each sub-honeypot system in the shared honeypot system provided in this embodiment is pre-set with an "analysis capability tag", which is associated with its simulated vulnerability environment, service type, analysis tools, etc.
[0148] For example, a sub-honeypot may be configured to simulate a web server environment and have built-in tools for detecting and analyzing SQL injection and XSS vulnerabilities, so it will be labeled with "Web service", "SQL injection analysis", "XSS analysis", etc.; another sub-honeypot may be specifically used to analyze DDoS attacks, so it is labeled "DDoS traffic analysis"; then, based on the above, a mapping relationship between attack characteristics and the analysis capabilities of each sub-honeypot system is constructed.
[0149] After identifying attack characteristics, the system matches these characteristics with the aforementioned mapping relationship to find all sub-honeypot systems whose analytical capability tags match the current attack characteristics. For example, if the identified attack characteristic is "SQL injection," the system will filter out all sub-honeypots tagged with "SQL injection analysis" and use them as candidate sub-honeypot systems to handle that attack traffic.
[0150] By employing the above methods, it is ensured that only sub-honeypot systems with corresponding analytical capabilities are selected, thereby improving the processing effectiveness of subsequent attack interactions and analysis.
[0151] In this embodiment, after the target sub-honeypot system in the shared honeypot system analyzes the attack traffic and generates interactive information, it can feed back the generated interactive information to the traffic processing unit based on its corresponding virtual attack information. The traffic processing unit determines the network location information of the attacker's terminal based on the mapping relationship between the corresponding original attack information and the virtual attack information, and feeds back the interactive information to the attacker's terminal.
[0152] Based on the above implementation methods, an optional implementation method for returning interactive information to the attacking terminal corresponding to the network domain according to the original attack information and the virtual attack information may include: determining the corresponding original attack information and domain identification information according to the virtual attack information corresponding to the interactive information; encapsulating the interactive information based on the domain identification information to generate encapsulated interactive data; and returning the encapsulated interactive data to the corresponding attacker terminal according to the original attack information.
[0153] Specifically, after the target sub-honeypot system in the shared honeypot system interacts with the attack traffic, a series of interaction information is generated, such as the honeypot's response data packets and log records. In order to correctly return the above interaction information, the traffic processing module should first perform reverse mapping processing, that is, according to the virtual attack information corresponding to the interaction information, for example, the network interface IP address (such as 172.16.0.1) and / or port number (such as 65432) used by the traffic processing module to communicate with the backend shared honeypot system, query the mapping relationship to obtain the original attack information corresponding to the virtual attack information, such as the attacker's real information (192.168.1.100 and / or 54321), and the domain identification information of the network domain to which the attack traffic belongs.
[0154] Then, based on the retrieved domain identifier information, the above-mentioned interaction information is encapsulated to obtain encapsulated interaction data. For example, the encapsulation process can refer to the aforementioned encapsulation process for attack traffic, that is, specific tags or header information can be added at the data link layer or network layer, such as adding the network domain ID to the VLAN tag, or embedding an identifier in the option field of the IP packet.
[0155] In this way, during subsequent network transmissions, especially in a multi-tenant shared network environment, it is possible to clearly identify which network domain the interactive data belongs to, so that network devices or subsequent processing modules can correctly route and forward it, avoiding information confusion between different tenants.
[0156] Furthermore, based on the original source network location information in the previously determined original attack information, the encapsulated interactive data is sent back to the corresponding attacker's terminal via network protocols. Optionally, during the transmission process, the traffic processing module further ensures that the destination IP address and / or port number of the data packet is correctly set to the attacker's real information, thereby enabling the attacker to receive a response from the "network domain".
[0157] Through the above implementation method, the information backhaul from honeypot interaction information to the attacker's terminal was successfully completed, while strictly ensuring the isolation between different network domains and the correct routing of data.
[0158] Building upon the above implementation, the shared honeypot system generates attack analysis results, i.e., alarm information, simultaneously with the generation of interactive information. To enhance tenant network security, the shared honeypot system also returns the alarm information to the traffic processing module, which then forwards it to user terminals in the corresponding network domain.
[0159] Optionally, one possible way for the traffic processing module to feed back the received alarm information to the corresponding user terminal is to: obtain the attack analysis results generated by the shared honeypot system based on the attack interaction, the attack analysis results including alarm information; determine the network domain corresponding to the attack traffic based on the original attack information and the virtual attack information; and send the alarm information to the user terminal corresponding to the network domain.
[0160] Specifically, while the target sub-honeypot system of the shared honeypot system interacts with the attack traffic and generates interaction information (such as response data packets), its built-in analysis engine simultaneously performs in-depth analysis of the attack behavior and generates attack analysis results. These results include alert information related to the attack interaction. For example, precise determination of the attack type, the vulnerability number exploited, the success or failure of the attack, and a threat level assessment of the attack behavior. The shared honeypot system returns these alerts, along with the interaction information, to the traffic processing module.
[0161] When the traffic processing module receives alarm information and interactive information, it obtains the original attack information corresponding to the virtual attack information of the attack traffic and the domain identifier information of the network domain to which the attack traffic belongs, based on the mapping relationship between virtual attack information and original attack information.
[0162] Based on this, the module can query the contact information of the administrator corresponding to the network domain, such as mobile phone number, email address, or dedicated alarm receiving server IP, according to the preset information table and the domain identifier information of the corresponding network domain. Then, the module can call the preset notification interface, such as SMTP email service, SMS gateway, or API interface, to send the extracted alarm information to the corresponding user terminal.
[0163] Through the above implementation methods, administrators of relevant network domains can be informed of threats in a timely manner, thereby taking timely response and disposal measures and improving the overall security protection efficiency of the platform.
[0164] Based on the above embodiments, this application also provides an exemplary embodiment of an attack traffic processing method. Figure 3 A flowchart illustrating an attack traffic processing method provided in this application embodiment. Figure 2 See also Figure 3 The specific implementation steps are as follows:
[0165] 1) The traffic probe diverts the attack traffic to the traffic processing and forwarding module (i.e., the traffic processing module described in the above implementation) through the black hole routing.
[0166] Specifically, the traffic probe monitors all traffic within the current network domain that accesses IPs that do not exist. The traffic probe encapsulates this traffic, adding the network domain ID to the encapsulation, and then sends the encapsulated traffic to the traffic processing and forwarding module via a black hole route.
[0167] 2) The traffic processing and forwarding module constructs multi-group information.
[0168] Specifically, the traffic processing and forwarding module receives encapsulated traffic from the traffic probe, decapsulates this traffic, extracts information such as network domain ID, source IP, source port, destination IP, destination port, and timestamp, and constructs tuple information.
[0169] 3) The traffic processing and forwarding module modifies the original traffic and sends it to the existing honeypot system.
[0170] Specifically, the traffic processing and forwarding module modifies the original traffic by changing the destination IP of the original traffic to the real IP of the existing honeypot and the source IP of the original traffic to the IP of the traffic processing and forwarding module, and then sends the modified traffic to the honeypot system.
[0171] 4) The traffic processing and forwarding module receives traffic from the existing honeypot system, matches the network domain according to the tuple information, processes the traffic, and sends it to the host in the corresponding network domain.
[0172] Specifically, the traffic processing and forwarding module receives traffic returned from the existing honeypot system, matches the content in the tuple to find the network domain ID and the real source IP of the connection, modifies the traffic by changing the destination IP to the real source IP, and then re-encapsulates the modified traffic and sends it to a host in the specific network domain based on the network domain ID.
[0173] 5) The alarm aggregation module accepts logs from existing honeypots, combines them with tuple information to form real alarm logs, and sends them to tenants.
[0174] Specifically, the alarm aggregation module receives alarm information from the existing honeypot system, forms real alarm information based on the tuple information from the traffic processing and forwarding module, and sends it to the tenants in the corresponding network domain.
[0175] Figure 4 A schematic diagram of an attack traffic processing device provided in this application. See also... Figure 4 The attack traffic processing device 40 is equipped with a cloud server, which includes multiple network domains, a traffic processing module, and a shared honeypot system. Attack traffic from each network domain is sent to the shared honeypot system through the traffic processing module for attack interaction.
[0176] Attack traffic processing device 40 includes:
[0177] Attack traffic acquisition module 401 is used to acquire attack traffic targeting a network domain;
[0178] The virtual mapping module 402 is used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information.
[0179] The interactive information acquisition module 403 is used to redirect attack traffic to the shared honeypot system for attack interaction based on virtual attack information, and obtain the interactive information of the attack traffic.
[0180] The interactive information feedback module 404 is used to return interactive information to the attack terminal corresponding to the network domain based on the mapping relationship between virtual attack information and original attack information.
[0181] In one optional implementation, the attack traffic acquisition module 401 includes:
[0182] The data flow monitoring submodule is used to monitor the data flow accessing the network domain through traffic monitoring units deployed in the network domain;
[0183] The attack traffic determination submodule is used to determine that when the traffic monitoring unit detects a data flow that matches the preset attack characteristics, it is attack traffic targeting the network domain.
[0184] The attack traffic sending submodule is used to forward attack traffic to the traffic processing module through the traffic redirection unit in the network domain, according to the preset traffic redirection strategy.
[0185] In one optional implementation, the attack traffic determination submodule includes:
[0186] The data stream acquisition unit is used to acquire data streams when a data stream accessing a preset network port and / or a non-existent network address is detected.
[0187] The attack traffic determination unit is used to acquire domain identification information that represents the network domain, and encapsulate the collected data stream based on the domain identification information to generate attack traffic targeting the network domain.
[0188] In one optional implementation, the attack traffic determination unit includes:
[0189] The domain identification information acquisition subunit is used to acquire the virtual LAN label corresponding to the network domain as domain identification information.
[0190] The attack traffic determination subunit is used to encapsulate the collected data stream based on the virtual LAN tag using a preset encapsulation protocol, and then use the encapsulated data stream tag as attack traffic targeting the network domain.
[0191] In one alternative implementation, the virtual mapping module 402 includes:
[0192] The raw attack information acquisition submodule is used to parse attack traffic and obtain the raw attack information of the attack traffic; the raw attack information includes the raw source network location information and the raw destination network location information, wherein the network location information includes network port and / or network address;
[0193] The first virtual mapping submodule is used to perform virtual mapping processing on the original source network location information to obtain the corresponding virtual source network location information.
[0194] The second virtual mapping submodule is used to perform virtual mapping processing on the original destination network location information to obtain the corresponding virtual destination network location information.
[0195] In one alternative implementation, the first virtual mapping submodule includes:
[0196] The intermediate network location information acquisition unit is used to acquire the intermediate network location information of the traffic processing module.
[0197] The virtual source network location information determination unit is used to map intermediate network location information into virtual source network location information of attack traffic.
[0198] In one alternative implementation, the shared honeypot system includes multiple sub-honeypot systems;
[0199] The second virtual mapping submodule includes:
[0200] The target sub-honeypot system determination unit is used to determine the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the resource status of each sub-honeypot system.
[0201] The virtual destination network location information determination unit is used to map the destination network location information of the target sub-honeypot system to the virtual destination network location information of the attack traffic.
[0202] In one optional implementation, the virtual destination network location information determination unit includes:
[0203] The candidate sub-honeypot system determination sub-unit is used to match the attack traffic with candidate sub-honeypot systems with corresponding analysis capabilities based on the original attack information;
[0204] The real-time resource status acquisition subunit is used to acquire the real-time resource status of each candidate honeypot system;
[0205] The virtual destination network location information determination sub-unit is used to select a target sub-honeypot system whose resource load meets preset conditions from the candidate sub-honeypot systems based on the real-time resource status.
[0206] In one alternative implementation, the candidate sub-honeypot system determines sub-units, including:
[0207] Attack signature identification node is used to identify the attack signatures corresponding to the attack traffic based on the original attack information;
[0208] The candidate sub-honeypot system identifies nodes used to match candidate sub-honeypot systems with corresponding analytical capabilities within the shared honeypot system based on attack characteristics.
[0209] In one optional implementation, the interactive information acquisition module 403 includes:
[0210] The information determination submodule is used to determine the corresponding original attack information and domain identification information based on the virtual attack information corresponding to the interactive information.
[0211] The encapsulated interaction data determination submodule is used to encapsulate and process interaction information based on domain identification information to generate encapsulated interaction data.
[0212] The encapsulated interactive data sending submodule is used to return encapsulated interactive data to the corresponding attacker's terminal based on the original attack information.
[0213] In one optional implementation, the interactive information feedback module 404 includes:
[0214] The alarm information acquisition submodule is used to acquire the attack analysis results generated by the shared honeypot system based on attack interactions. The attack analysis results include alarm information.
[0215] The network domain determination submodule is used to determine the network domain corresponding to the attack traffic based on the original attack information and the virtual attack information.
[0216] The alarm information sending submodule is used to send alarm information to the user terminals corresponding to the network domain.
[0217] Figure 5 This is a block diagram of a server provided in this application. See also... Figure 5 The server 500 may include one or more of the following components: processing component 502, memory 504, power supply component 506, multimedia component 508, audio component 510, input / output interface 512, sensor component 514, and communication component 516.
[0218] Processing component 502 typically controls the overall operation of server 500, such as operations associated with display, telephone calls, data communication, camera operation, and recording. Processing component 502 may include one or more processors 520 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 502 may include one or more modules to facilitate interaction between processing component 502 and other components. For example, processing component 502 may include a multimedia module to facilitate interaction between multimedia component 508 and processing component 502.
[0219] Memory 504 is configured to store various types of data to support the operation of server 500. Examples of this data include instructions for any application or method operating on server 500, contact data, phonebook data, messages, pictures, videos, etc. Memory 504 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0220] Power supply component 506 provides power to various components of server 500. Power supply component 506 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to server 500.
[0221] Multimedia component 508 includes a screen that provides an output interface between server 500 and user. In some embodiments, the screen may include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the screen includes a Touch Panel, the screen may be implemented as a touchscreen to receive input signals from the user. The Touch Panel includes one or more touch sensors to sense touches, swipes, and gestures on the Touch Panel. The touch sensors may sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 508 includes a front-facing camera and / or a rear-facing camera. When server 500 is in an operating mode, such as a shooting mode or video mode, the front-facing camera and / or rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0222] Audio component 510 is configured to output and / or input audio signals. For example, audio component 510 includes a microphone (MIC) configured to receive external audio signals when server 500 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 504 or transmitted via communication component 516. In some embodiments, audio component 510 also includes a speaker for outputting audio signals.
[0223] Input / output interface 512 provides an interface between processing component 502 and peripheral interface modules, which may be keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, start buttons, and lock buttons.
[0224] Sensor assembly 514 includes one or more sensors for providing status assessments of various aspects of server 500. For example, sensor assembly 514 may detect the on / off state of server 500, the relative positioning of components such as the display and keypad of server 500, changes in the position of server 500 or a component of server 500, the presence or absence of user contact with server 500, the orientation or acceleration / deceleration of server 500, and temperature changes of server 500. Sensor assembly 514 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 514 may also include optical sensors, such as complementary metal-oxide-semiconductor (CMOS) sensors or charge-coupled device (CCD) sensors, for use in imaging applications. In some embodiments, sensor assembly 514 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.
[0225] Communication component 516 is configured to facilitate wired or wireless communication between server 500 and other devices. Server 500 can access wireless networks based on communication standards, such as WiFi, 4G, or 5G, or combinations thereof. In one exemplary embodiment, communication component 516 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 516 also includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on Radio Frequency Identification (RFID), Infrared Data Association (IrDA), Ultra Wide Band (UWB), Bluetooth (BT), and other technologies.
[0226] In an exemplary embodiment, server 500 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processors (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.
[0227] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 504 including instructions, which can be executed by the processor 520 of the server 500 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0228] A non-transitory computer-readable storage medium, wherein instructions in the storage medium, when executed by a server's processor, enable the server to perform the methods described above.
[0229] This application also provides a chip for executing instructions, which is used to execute the technical solutions of the methods in the above embodiments.
[0230] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed on a computer, cause the computer to perform the technical solution of the method described in the above embodiments.
[0231] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solutions of the methods in the above embodiments.
[0232] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0233] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
[0234] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0235] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for processing attack traffic, characterized in that, It is applied to cloud servers, which include multiple network domains, traffic processing modules, and a shared honeypot system; Attack traffic from each of the network domains is sent to the shared honeypot system for attack interaction through the traffic processing module; The method includes: Obtain attack traffic targeting the network domain; The original attack information in the attack traffic is processed by network virtual mapping to generate corresponding virtual attack information. Based on the virtual attack information, the attack traffic is redirected to the shared honeypot system for attack interaction, and the interaction information of the attack traffic is obtained; Based on the mapping relationship between the virtual attack information and the original attack information, the interactive information is returned to the attack terminal corresponding to the network domain.
2. The method according to claim 1, characterized in that, Acquiring attack traffic targeting the network domain includes: The data flow accessing the network domain is monitored by a traffic monitoring unit deployed in the network domain. When the traffic monitoring unit detects a data flow that matches the preset attack characteristics, it determines that it is attack traffic targeting the network domain. The attack traffic is forwarded to the traffic processing module through the traffic redirection unit in the network domain according to the preset traffic redirection strategy.
3. The method according to claim 2, characterized in that, When the traffic monitoring unit detects a data flow that matches preset attack characteristics, it determines that it is attack traffic targeting the network domain, including: When a data stream accessing a preset network port and / or a non-existent network address is detected, the data stream is collected; Obtain domain identifier information that represents the network domain, and encapsulate the collected data stream based on the domain identifier information to generate attack traffic targeting the network domain.
4. The method according to claim 3, characterized in that, Based on the domain identification information, the collected data stream is encapsulated and processed to generate attack traffic targeting the network domain, including: Obtain the virtual local area network label corresponding to the network domain as the domain identification information; Based on the virtual LAN tag, the collected data stream is encapsulated using a preset encapsulation protocol, and the encapsulated data stream tag is used as attack traffic targeting the network domain.
5. The method according to claim 1, characterized in that, The original attack information in the attack traffic is virtually mapped to generate corresponding virtual attack information, including: The attack traffic is analyzed to obtain the original attack information of the attack traffic; the original attack information includes the original source network location information and the original destination network location information, and the network location information includes the network port and / or network address; The original source network location information is subjected to virtual mapping processing to obtain the corresponding virtual source network location information; The original destination network location information is subjected to virtual mapping processing to obtain the corresponding virtual destination network location information.
6. The method according to claim 5, characterized in that, The original source network location information is subjected to virtual mapping processing to obtain the corresponding virtual source network location information, including: Obtain the intermediate network location information of the traffic processing module; The intermediate network location information is mapped to the virtual source network location information of the attack traffic.
7. The method according to claim 5, characterized in that, The shared honeypot system includes multiple sub-honeypot systems; The original destination network location information is subjected to virtual mapping processing to obtain corresponding virtual destination network location information, including: Based on the original attack information and the resource status of each of the sub-honeypot systems, the target sub-honeypot system corresponding to the attack traffic is determined; The target network location information of the target sub-honeypot system is mapped to the virtual target network location information of the attack traffic.
8. The method according to claim 7, characterized in that, Based on the original attack information and the system resource status of each of the sub-honeypot systems, the target sub-honeypot system corresponding to the attack traffic is determined, including: Based on the original attack information, candidate sub-honeypot systems with corresponding analysis capabilities are matched for the attack traffic; Obtain the real-time resource status of each of the candidate sub-honeypot systems; Based on the real-time resource status, a target sub-honeypot system whose resource load meets preset conditions is selected from the candidate sub-honeypot systems.
9. The method according to claim 8, characterized in that, Based on the original attack information, candidate sub-honeypot systems with corresponding analysis capabilities within the shared honeypot system are matched to the attack traffic, including: Based on the original attack information, identify the attack characteristics corresponding to the attack traffic; Based on the attack characteristics, candidate sub-honeypot systems with corresponding analytical capabilities are matched within the shared honeypot system.
10. The method according to any one of claims 1-9, characterized in that, Based on the original attack information and the virtual attack information, the interactive information is returned to the attack terminal corresponding to the network domain, including: Based on the virtual attack information corresponding to the interactive information, determine the corresponding original attack information and domain identification information; The interaction information is encapsulated based on the domain identifier information to generate encapsulated interaction data. Based on the original attack information, the encapsulated interactive data is returned to the corresponding attacker's terminal.
11. The method according to any one of claims 1-9, characterized in that, The method further includes: Obtain the attack analysis results generated by the shared honeypot system based on the attack interaction, and the attack analysis results include alarm information; Based on the original attack information and the virtual attack information, the network domain corresponding to the attack traffic is determined; The alarm information is sent to the user terminal corresponding to the network domain.
12. An attack traffic processing device, characterized in that, It is applied to cloud servers, which include multiple network domains, traffic processing modules, and a shared honeypot system; Attack traffic from each of the network domains is sent to the shared honeypot system for attack interaction through the traffic processing module; The device includes: An attack traffic acquisition module is used to acquire attack traffic targeting the network domain; The virtual mapping module is used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information; An interactive information acquisition module is used to redirect the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information, and obtain the interactive information of the attack traffic. The interactive information feedback module is used to return the interactive information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information.
13. A server, characterized in that, include: A processor and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor, when executing the computer execution instructions, is used to implement the attack traffic processing method as described in any one of claims 1 to 11.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the attack traffic processing method as described in any one of claims 1 to 11.
15. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the attack traffic processing method as described in any one of claims 1 to 11.