Graded honey spot trapping method and device based on adaptive UEBA score

By dynamically adjusting feature weights and detection thresholds using an adaptive UEBA scoring method, a personalized honeypot trapping environment is generated. This solves the problems of high false negative rates and resource waste in the early stages of attacks in existing UEBA systems, and achieves effective trapping of advanced attackers and efficient utilization of defense resources.

CN121887548APending Publication Date: 2026-04-17GUANGZHOU UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU UNIVERSITY
Filing Date
2026-03-20
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing UEBA systems have high false positive and false negative rates in the early stages of an attack. Their honeypot trapping methods are limited, making it difficult to effectively trap advanced attackers. They also suffer from significant resource waste, are unable to capture rapid penetration behaviors in a timely manner, and lack the ability to identify low-deviation, high-privilege-exception behaviors.

Method used

By using an adaptive UEBA scoring method, feature weights and detection thresholds are dynamically adjusted to generate personalized honeypot trapping environments. User behavior is scored in real time, dedicated container instances are launched to manage session lifecycles, and features and thresholds are optimized through a high-risk model to achieve on-demand allocation and adaptive learning of defense resources.

Benefits of technology

It improves the sensitivity and effectiveness of the defense system, reduces the load on computing and storage resources, and enables in-depth forensics and automated iterative optimization of high-value targets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887548A_ABST
    Figure CN121887548A_ABST
Patent Text Reader

Abstract

The invention provides a graded honey spot trapping method and device based on adaptive UEBA scoring. The method comprises the following steps: filtering and limiting original network traffic to obtain filtered data; collecting user behavior metadata to generate behavior feature vectors; calculating a user risk score, and comparing the user risk score with a detection threshold to judge a risk level; processing by a corresponding processing module according to the risk level, and injecting identity context parameters of an abnormal user into a high-risk model to start an exclusive container instance and manage the life cycle of a container session; and the high-risk model collection container feedback data is used for optimizing the high-risk model and updating the feature dynamic weight and the detection threshold. By applying the method, the dynamic weight and the detection threshold of the feature can be dynamically adjusted in real time in response to the attack trend, the response sensitivity to attack behaviors is improved, defense resources are allocated according to needs for abnormal users, deep evidence obtaining of high-value targets is guaranteed, and normalized calculation and loads of a system are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication security technology, and in particular to a hierarchical honeypot trapping method and apparatus based on adaptive UEBA scoring. Background Technology

[0002] With increasingly stringent requirements for network communication security, Transport Layer Security (TLS) and Hypertext Transfer Security (HTTPS) have been widely deployed in enterprise internal and external networks. This trend has effectively improved data privacy and integrity protection, but it has also posed challenges to traditional content analysis-based security detection technologies. Against this backdrop, User and Entity Behavior Analysis (UEBA) technology is gradually becoming an important means of identifying potential threats in encrypted environments.

[0003] In recent years, proactive defense systems have gained widespread attention. These systems aim to proactively predict and identify threats before or during an attack, and to break the attack chain through intervention, thereby reducing the success rate of attacks at the source. UEBA is a core technology in the "pre-attack perception and early warning" stage of proactive defense. By constructing a baseline of normal user / entity behavior, it monitors in real time for anomalies deviating from the baseline (such as unauthorized access by internal employees or abnormal logins after account hijacking), issuing early warnings before threats escalate into actual attacks.

[0004] In recent years, in order to deal with advanced persistent threats (APTs) and covert attacks such as lateral movement within the interior, the industry has begun to explore the integration of User and Entity Behavior Analysis (UEBA) with deception defense technologies. While existing technologies have improved upon earlier separate architectures by integrating UEBA with deception defense techniques, they still suffer from the following key technical shortcomings: Existing UEBA systems often use static configuration or slow sliding updates for feature weights and risk thresholds, failing to adaptively adjust detection sensitivity based on real-time attack activity. This results in high false negative rates in the early stages of an attack wave and increased false positive rates during calmer periods. Honeypots are often single-mode, universal decoys, making it difficult to effectively lure legitimate internal malicious actors or advanced attackers. Advanced attackers can easily identify and evade universal honeypots. High-interaction honeypots typically run as fixed, persistent instances, leading to significant waste of idle resources. On-demand startup modes, due to initialization delays, cannot promptly capture rapid penetration behaviors. While high-confidence attack data captured by honeypots can be used for model optimization, actual updates often rely on manual analysis or T+1 batch processing, making it difficult to cope with rapid changes in attack methods. Existing UEBA primarily focuses on behavioral deviation, lacking sufficient ability to identify "low-deviation but high-privilege-escalation" internal malicious behaviors (such as ordinary employees accessing financial data outside of working hours).

[0005] Therefore, it is necessary to provide a new defense method that integrates UEBA and deception defense technologies, which can dynamically adjust the perception and sensitivity of attack trends and carry out personalized trapping on demand, so as to continuously adapt to new attack methods and improve the overall defense effectiveness. Summary of the Invention

[0006] The purpose of this invention is to provide a hierarchical honeypot trapping method and device based on adaptive UEBA scoring, which can continuously adapt to new attack methods and improve overall defense effectiveness.

[0007] In a first aspect, the hierarchical honeypot trapping method based on adaptive UEBA scoring provided by the present invention includes: filtering and rate limiting the original network traffic to obtain filtered data; collecting the filtered data according to a set time window and converting it into structured user behavior metadata, and generating a behavior feature vector based on the user behavior metadata; calculating the user risk score based on the behavior feature vector and the corresponding feature dynamic weights and comparing it with a detection threshold to determine the risk level; introducing the user into the corresponding processing module for processing according to the risk level, injecting the identity context parameters of the user determined to be abnormal into the high-risk model to start a dedicated container instance and manage the lifecycle of the container session; and collecting container feedback data from the high-risk model to optimize the high-risk model, update the feature dynamic weights and detection thresholds.

[0008] The beneficial effects of the hierarchical honeypot trapping method based on adaptive UEBA scoring provided by this invention are as follows: User behavior risk is assessed through user and entity behavior analysis; feature dynamic weights and detection thresholds are dynamically adjusted in real time in response to attack trends, resulting in a highly sensitive response to attack behaviors. Targeted processing of users is performed based on risk classification results, and dedicated container instances are designed according to the identity attributes of abnormal users. This effectively eliminates the homogeneity of common honeypots, enabling on-demand allocation of defense resources. While ensuring in-depth forensics against high-value targets, it reduces the computational and storage resource load of the system under normal operation. Collecting container feedback information is used to optimize high-risk models, update feature dynamic weights and detection thresholds, enabling automated closed-loop iteration of defense strategies and endowing the defense system with adaptive learning capabilities against new attack methods.

[0009] In one possible embodiment, honeypot interaction data is collected simultaneously with the filtered data, and honeypot interaction features are extracted from the honeypot interaction data; the dynamic weight calculation of the features includes: calculating the original feature score according to the following formula: , Indicates the first The first time window The raw scores of each behavioral feature Indicates the first The first time window The raw scores of each behavioral feature Indicates the time decay factor. Indicates the adjustment factor. Indicates the first The first time window The popularity of honey spots corresponding to each behavioral characteristic Indicates the first The confidence level of the attack intent triggered by each behavioral feature is determined; the original scores of the features are normalized and calibrated to obtain the dynamic weights of the features.

[0010] In another possible embodiment, the user risk score calculation includes: calculating the original risk score of the feature according to the following formula: , This represents the original risk score of the feature. Indicates the first Normalized values ​​of each behavioral feature Indicates the first Dynamic weights of each behavioral feature This represents the number of behavioral features in the behavioral feature vector; the user risk score is obtained by normalizing the original risk scores of the features. , This represents the user's risk score. This represents the minimum original risk score of a feature in the behavioral feature vector. This represents the maximum original risk score of the feature in the behavioral feature vector.

[0011] In other possible embodiments, the detection thresholds include a normal threshold and a high-risk threshold; when a user's risk score is greater than the high-risk threshold, the user is determined to be a high-risk user and transferred to the honeypot buffer; when a user's risk score is between the normal threshold and the high-risk threshold, the user is determined to be a suspicious user, the suspicious user is continuously monitored and personalized honeypots are dynamically deployed to guide the suspicious user into the deceptive environment; when a user's risk score is less than the normal threshold, the user is determined to be a normal user, communication is allowed for the normal user and resources are released periodically.

[0012] The high-risk model is used to generate container configuration files based on user identity information, behavioral information, and system environment. When the container instance starts, a personalized trapping environment is built based on the container configuration file. A comprehensive risk score describing the risk of high-risk user attack behavior is calculated. After the container instance starts, the corresponding response strategy is executed based on the comprehensive risk score.

[0013] The overall raw score for the risk of user attack behavior is calculated using the following formula: , A comprehensive raw score representing the risk of user attack behavior. This represents the number of behavioral features in the behavioral feature vector. Indicates the first Dynamic weights of each behavioral feature Indicates the first Confidence of attack intent triggered by a single behavioral characteristic in honeypots The constraint coefficients are used to normalize the user's original comprehensive score, resulting in the user's comprehensive risk score. , This represents the user's overall risk score. This represents the minimum original risk score of a feature in the feature vector. This represents the maximum original risk score of the feature in the feature vector.

[0014] Based on the user's comprehensive risk score and the preset risk score range, the risk type of the user's attack behavior is determined as low-risk suspicious attack, medium-risk attack, or high-risk confirmed attack. According to the risk type of the user's attack behavior, the container is activated to execute the corresponding response strategy and control the container's session lifecycle. When the user's attack behavior triggers a new honeypot within the container, the comprehensive risk score of the high-risk user is recalculated and updated, and the response strategy is adjusted according to the updated comprehensive risk score. The response strategies executed according to the risk type of the user's attack behavior include: for low-risk suspicious attacks, deploying lightweight decoys within the container instance to respond, and synchronizing user behavior data to assess the user's risk score; for medium-risk attacks, deploying highly realistic services within the container instance, limiting the weight of high-risk operations, and performing full session recording; for high-risk confirmed attacks, deploying high-value decoys within the container instance, blocking the user's connection to the real environment, capturing the fingerprint of the attack tool, and generating a standardized attack attribution report.

[0015] In each time window, after collecting container feedback data, the detection threshold is updated based on the attack capture results of the current time window, combined with the user behavior risk score distribution and density heat of the previous time window, for risk level determination in the next time window; the calculation of the detection threshold satisfies the following formula: , ,in, Indicates the first The normal threshold is calculated using a time window. Indicates the first The high-risk threshold is calculated using a time window. The inertia coefficient represents the adjustment of the detection threshold. , The corresponding role group represents the pth and qth percentiles in the [missing information]. The score for each time window, , Represents positive real numbers. Indicates the first Within the first time window The honey spot heat value of the first behavioral characteristic and the first The product of the dynamic weights of each behavioral feature. Indicates the first The normal threshold is calculated using a time window. Indicates the first The high-risk threshold is calculated using a time window. , Indicates the external threat intelligence response coefficient. This indicates the external threat intelligence compensation factor.

[0016] Initial value of normal threshold Set as the 80th percentile value of the behavior score sequence of the role group within the first time window; the initial value of the high-risk threshold. Set as the 95th percentile value of the behavior rating sequence within the first time window of the character group.

[0017] Secondly, the present invention also provides a hierarchical honeypot trapping device based on adaptive UEBA scoring, comprising: a filtering unit for filtering and rate limiting raw network traffic to obtain filtered data; a data acquisition unit for collecting filtered data according to a set time window and converting it into structured user behavior metadata, and generating a behavior feature vector based on the user behavior metadata; a user and entity behavior analysis unit for calculating a user risk score based on the behavior feature vector and the corresponding feature dynamic weights, and comparing it with a detection threshold to determine the risk level; a hierarchical response unit for introducing users into corresponding processing modules for processing according to the risk level, injecting the identity context parameters of users judged to be abnormal into the high-risk model to start a dedicated container instance and manage the lifecycle of the container session; and a feedback and optimization unit for the high-risk model to collect container feedback data for optimizing the high-risk model, updating feature dynamic weights and detection thresholds.

[0018] For the beneficial effects of the second aspect mentioned above, please refer to the description of the first aspect mentioned above. Attached Figure Description

[0019] Figure 1 A flowchart illustrating a graded honey trapping method based on adaptive UEBA scoring provided in an embodiment of the present invention;

[0020] Figure 2 This invention provides a schematic diagram of a process for migrating a user's access environment based on user information, as provided in an embodiment of the invention.

[0021] Figure 3 This is a schematic diagram of a graded honey trapping device based on adaptive UEBA scoring, provided as an embodiment of the present invention. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions in the embodiments of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without inventive effort are within the scope of protection of this invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art. The terms "comprising" and similar expressions used herein mean that the element or object preceding the word covers the element or object listed following the word and its equivalents, but do not exclude other elements or objects.

[0023] This embodiment provides a graded honey spot trapping method and apparatus based on adaptive UEBA scoring.

[0024] See the instruction manual appendix Figure 1 The hierarchical honey trapping method based on adaptive UEBA scoring includes:

[0025] S101: Filter and rate-limit the raw network traffic to obtain filtered data.

[0026] At the entry point of the enterprise network system, a lightweight rate control strategy is used to perform initial filtering and rate limiting on raw network traffic. This filtering and rate limiting process smoothly regulates access requests, ensuring that only legitimate requests that can be further analyzed enter the enterprise network system. This prevents high-frequency scanning or Denial-of-Service (DoS) attacks from overwhelming the backend system and overloading it, ensuring that subsequent modules operate under a controllable load. During the initial filtering and rate limiting process, frequently accessing IP addresses are recorded and marked as "high-risk," subsequently entering the traffic routing process; normal traffic is allowed to enter the enterprise network system.

[0027] In one specific embodiment, a lightweight token bucket rate limiting mechanism is used to filter and limit all raw network traffic requests entering the enterprise network system.

[0028] S102: Collect filtered data according to the set time window and transform it into structured user behavior metadata, and generate a behavior feature vector based on the user behavior metadata.

[0029] In one possible embodiment, honeypot interaction data is collected while collecting filtered data, and honeypot interaction features are extracted from the honeypot interaction data.

[0030] In one possible embodiment, based on the filtered data, multi-source heterogeneous user behavior data is collected according to a set time window: the user behavior data collected in each time window mainly includes user ID, number of connections per unit time, average connection duration, peak number of concurrent connections, target IP entropy value, access ratio of sensitive ports, number of external traffic, non-standard ports running common protocols, TLSJA3 fingerprint changes, packet length, user activity time, geographical location of the same user login, first access ratio, etc.

[0031] In one possible implementation, within each time window, in addition to collecting user behavior data, honeypot container interaction data (including honeypot logs, operation sequences, and C2 communication records); external threat intelligence data (including vulnerability activity status, industry attack event warnings, and IP reputation ratings); and identity and permission data (user roles, department affiliation, and permission levels, synchronized by the enterprise IAM system) are also collected to provide raw materials for subsequent high-precision threat and external compensation factor determination.

[0032] For example, the collection of honeypot container interaction data specifically includes honeypot logs (the paths to honeypot resources accessed by the attacker, the types of decoys triggered, records of fake credential usage, and interaction response results), operation sequences (continuous attacker actions sorted by timestamps, such as "scanning ports → accessing the / config path → downloading fake configuration files → attempting to log in to the database → connecting to the fake C2 endpoint"), and C2 communication data (including communication protocol type, packet length, JA3 fingerprint, request frequency, command encoding format, interaction address, etc.). The collected user behavior data and honeypot container interaction data are preprocessed to generate structured behavioral feature vectors and honeypot interaction features. For example, the preprocessing of user behavior data and honeypot container interaction data includes deduplication, format normalization, and missing value imputation.

[0033] In one possible embodiment, the length of the set time window can be in the range of 3-10 minutes, and the specific duration can be adjusted to suit different attack frequency scenarios.

[0034] Preferably, when collecting user behavior data within a time window, a simple filter is performed based on the user's identity information: if the user's identity is in the blacklist, they are directly guided to the multi-level honeypot collaborative environment.

[0035] In this embodiment of the invention, the multi-level honeypot collaborative environment consists of two parts: a lightweight honeypot buffer and a complete virtual simulation system. The lightweight initial buffer is used to isolate the user from the real environment when transferring the user to the deceptive environment and to create time for the complete virtual simulation system to start. The lightweight honeypot buffer consists of several lightweight honeypots running in real time on the system edge nodes. The lightweight honeypots are pre-set virtual web pages (such as user authentication web pages, forged internal document pages, etc.). When a user is guided to a lightweight honeypot, they will be required to perform some simple verifications or provide the attacker with some false honeypot information, thereby providing time for the complete virtual simulation system to start and also paving the way for undetectably guiding suspicious users to the complete virtual simulation system. The complete virtual simulation system is a deception unit that is logically and physically independent of the real business environment. It specifically simulates the external appearance of high-value data storage modules in a real system, including but not limited to data interface paths, response structures, file formats, and metadata. All components of the system, including data content, network addresses, storage paths, and service endpoints, are composed of pre-defined honeypots. No real business assets or accessible production resources exist within the system. All interactive interfaces return artificially constructed deceptive responses, and the honeypots form a closed-loop inducement network through context-consistent virtual references, ensuring that all operations performed by attackers in this environment can be fully recorded and analyzed. The complete virtual simulation system is pre-built as a container image and stored in a private image repository. When user behavior meets the pre-defined honeypot trigger conditions, the system pulls the corresponding business scenario's deception environment image from the image repository, injects user identity context parameters into the high-risk model, and starts a dedicated container instance. The container instance runs in an isolated network, is only visible to the corresponding user, and is automatically destroyed after the session ends. The jump trigger condition for transferring the user to the lightweight honeypot buffer includes the user's identity information being on a blacklist.

[0036] In one specific embodiment, the principle for setting the user blacklist is: as long as a user captures a honeypot in a real environment or in a multi-level honeypot collaborative environment, they will be added to the blacklist.

[0037] In one specific embodiment, the collected and filtered data is transformed into structured network behavior metadata, which includes, but is not limited to, information such as IP address, access time, target path, operation type, and session ID. Behavioral feature engineering is then performed on the user behavior metadata. Specifically, this process involves normalization, temporal aggregation, and anomaly baseline construction to extract quantifiable behavioral feature vectors. After behavioral feature engineering, the user behavior metadata is output as a behavioral feature vector describing the user's overall behavioral characteristics. For example, when a user's behavioral characteristics include… At this time, the user's behavioral feature vector is .

[0038] The collected honeypot interaction data undergoes specialized feature extraction to obtain honeypot interaction features, specifically including the extraction of static features, dynamic features, and correlation features. Static features include: honeypot value weight (Wh), honeypot trigger type encoding, and attacker access resource sensitivity labels; dynamic features include: operation sequence temporal features (such as operation intervals and step durations), C2 communication features (such as protocol identifiers, packet length distribution, and request frequency), and tool instruction features (such as SQL injection statement keywords and command line instruction features); correlation features include: temporal correlation labels between honeypot triggering and user behavior, and matching degree labels between permission levels and operation behaviors.

[0039] In one possible implementation, a feature mapping between honeypots and user behavior is constructed to establish a mapping relationship between specific honeypot resources and their associated behavioral patterns, thereby enhancing the model's focus on key assets. For example, the feature mapping between honeypots and user behavior is shown in the table below:

[0040] Table 1. Example of Feature Mapping Between Honeypots and User Behavior

[0041]

[0042] S103: Calculate the user risk score based on the behavioral feature vector and the corresponding dynamic feature weights, and compare it with the detection threshold to determine the risk level.

[0043] In one possible embodiment, the dynamic weight calculation of features includes: calculating the original feature score according to the following formula: , Indicates the first The first time window The original score of each behavioral feature represents the absolute activity of that attack feature in the time dimension; Indicates the first The first time window The raw scores of each behavioral feature; This represents the time decay factor, with a value range of [0.01, 0.05]. The time decay factor is used to ensure that the scores of outdated attack features gradually decrease over time, preventing historical data from causing long-term interference to current decisions. This represents the adjustment coefficient, used to control the impact of a single honeypot trigger on the score; Indicates the first The first time window The honeypot popularity corresponding to a behavioral feature is the number of times that honeypot corresponding to that behavioral feature is triggered by different attackers. Indicates the first The attack intent confidence level triggered by each behavioral feature is used to measure the maliciousness of the triggering behavior; the original scores of the features are normalized and calibrated to obtain the dynamic weights of the features. Specifically, in order to transform the original scores into weights in the form of a probability distribution and to ensure that the sum of all feature weights is always 1, the Softmax function is used to calculate the final weights. : , Indicates the first The first time window The exponential transformation value of the original score of each behavioral feature. Indicates the first The first time window The raw scores of each behavioral feature Indicates the first The first time window The exponential transformation value of the original score of each behavioral feature.

[0044] The attack intent confidence score is quantified based on the user's behavioral feature vector and honeypot interaction features. Specifically, the attack intent confidence score can be calculated by constructing a "permission-behavior-intent" ternary quantification model, as shown in the following formula: Intent confidence is used to measure the risk of a user's behavioral characteristics triggering a honeypot attack.

[0045] Among them, the permission level weight : Assigns permissions based on the user's preset permission level (range 0.1-1.0), and the permission level is synchronized and updated in real time by the enterprise IAM (Identity and Access Management) system; behavioral deviation. Calculate the degree of deviation of user behavior from the user's "historical normal baseline" for this permission (value range 0-1.0); honeypot trigger weight. The value of the trigger point is assigned according to its value level (range 0.2-1.0).

[0046] In one specific embodiment, the permission level weights are defined based on different user permissions as follows: External customers (no access to internal resources): Regular internal staff (access to departmental resources only): Administrator (with access to all sensitive resources): Behavioral deviation is calculated using a combination of "time-series difference + resource sensitivity matching". Time-series difference: For example, access during non-working hours (e.g., 23:00-06:00) has a time-series difference coefficient of 0.8, while access during working hours has a coefficient of 0.2. Resource sensitivity matching: Access to "highly sensitive resources" (e.g., database configuration files, financial data) has a sensitivity coefficient of 1.0, while access to "ordinary resources" (e.g., public documents) has a coefficient of 0.2. For example, regular employees accessing financial data outside of working hours. Define the trigger weight for honeypots as follows: Lightweight honeypots (such as fake web pages): High-value honeypots (such as fake database credentials, administrator account honeypots): .

[0047] In one possible embodiment, in order to prevent the weight of a specific attack feature from accumulating indefinitely over time and causing an imbalance in user and entity behavior analysis, at the end of each time window, the dynamic weight of the feature in the previous time window is decayed and the data collected in the current time window is added to update the dynamic weight of the feature.

[0048] In one possible embodiment, the user risk score calculation includes: calculating the original risk score of the feature according to the following formula: , This represents the original risk score of the feature. Indicates the first Normalized values ​​of each behavioral feature , Indicates the first Dynamic weights of each behavioral feature , This represents the number of behavioral features in the behavioral feature vector; the user risk score is obtained by normalizing the original risk scores of the features. , This represents the user's risk score. This represents the minimum original risk score of a feature in the behavioral feature vector. This represents the maximum original risk score of the feature in the behavioral feature vector.

[0049] The detection thresholds include a normal threshold and a high-risk threshold. When a user's risk score is greater than the high-risk threshold, the user is determined to be a high-risk user. When a user's risk score is between the normal threshold and the high-risk threshold, the user is determined to be a suspicious user. When a user's risk score is less than the normal threshold, the user is determined to be a normal user.

[0050] S104: Based on the risk level, the user is introduced into the corresponding processing module for processing. The identity context parameters of the user who is judged to be abnormal are injected into the high-risk model to start a dedicated container instance and manage the lifecycle of the container session.

[0051] In one possible implementation, high-risk users are transferred to a honeypot buffer zone, suspicious users are continuously monitored, and personalized honeypots are dynamically deployed to guide suspicious users into a deceptive environment, while normal users are allowed to communicate and resources are released periodically.

[0052] See the instruction manual appendix Figure 2In addition to the trigger condition that the user's identity information is in the blacklist, the redirection trigger conditions that transfer the user to the lightweight honeypot buffer also include: when the user's score is higher than the high-risk threshold or when a real environment honeypot is triggered, the seamless redirection process is automatically started; the criteria for successful redirection are: the attacker's session is not interrupted, there are no error messages, and the operation behavior is continuous (such as continuing to browse files or trying to log in).

[0053] In one specific embodiment, different processing modules are designed for different risk levels, including a high-risk decision processing module, a monitoring processing module, and a normal behavior processing module. The processing in each module includes:

[0054] High-risk users are treated as attackers. The high-risk decision-making module initiates "transparent traffic migration technology based on reverse proxy" for high-risk users, seamlessly transferring high-risk traffic from a lightweight buffer to a dedicated container. The specific steps are as follows: 1. Connection anchoring: All external user traffic does not directly access the backend service, but is terminated by the front-end reverse proxy gateway. The TCP connection of high-risk users is always established between the gateway (in the ESTABLISHED state), and the gateway masks the real IP changes of the backend; 2. Traffic suspension and caching: When a redirect is decided based on the user's risk level, the gateway temporarily "suspends" the traffic. 1. HTTP session with the user: Cache subsequent incoming data packets in a memory queue, do not send TCP / RST packets or close the connection, and keep the front end silent; 2. Backend hot switching: The backend asynchronously starts a dedicated high-interaction container instance. After the container is ready, the gateway dynamically updates the routing rules of the session ID and points the backend upstream to the IP address of the new container; 3. State replay: The gateway replays the cached request data packets to the newly started container and transparently forwards the container's response data back to the high-risk user. Throughout the process, the TCP connection of the high-risk user is not interrupted or reported in any way, thereby achieving zero-latency and imperceptible environment upgrade.

[0055] Suspicious users are considered potential attackers. The suspicious activity monitoring module continuously monitors these users and dynamically deploys personalized honeypots to lure them into a deceptive environment. When a suspicious user's risk score reaches a preset warning range, preparations are made in advance to guide them into a multi-level honeypot collaborative environment. Once a genuine attack (acquiring honeypots) is confirmed, the suspicious user is upgraded to a high-risk user for further processing. The warning range is set to minimize the deployment time of honeypots within the high-risk threshold range. When an attacker's behavior score falls within the warning range, the system prepares in advance to lure the user to a honeypot. The warning range is... , Indicates the first The high-risk threshold is calculated using a time window. The specific value is set based on the system's computing power redundancy and the evolution rate of historical attack behaviors: when the system has sufficient resources or faces highly covert, slow attacks, a larger value can be set. This value expands the warning range, allowing the system to trigger the preloading of the complete virtual simulation system and dedicated container instances earlier, thus providing ample initialization time for seamless traffic migration. When the system load is high, a smaller value can be set. This narrows the warning range and avoids allocating idle resources too early, thus achieving an optimal balance between trapping sensitivity and system computational overhead.

[0056] If a normal user's behavior is deemed legitimate, the user is allowed to continue accessing the site. The normal behavior processing module periodically clears the behavior records of normal users.

[0057] In one possible embodiment, the high-risk model is used to generate a container configuration file based on user identity information, behavioral information, and system environment. When the container instance starts, a personalized trapping environment is built based on the container configuration file. A comprehensive risk score describing the risk of high-risk user attack behavior is calculated. After the container instance starts, the corresponding response strategy is executed based on the comprehensive risk score.

[0058] In a specific embodiment, a high-risk model that generates integrated system core features and feedback data, possesses accurate context injection capabilities and container scheduling adaptability, is used to generate container configuration files and manage container instances based on user identity information, behavioral information, and system environment. The generation process of the high-risk model is as follows: 1. Collect basic datasets: including historical attack data, normal behavior data of users with different identities (administrators, ordinary employees, external users, etc.), and system configuration data of business scenarios. The collected data is labeled with binary tags, and the data is expanded using the "behavioral sequence recombination + noise injection" method. 2. Based on the document "permission-behavior-intent" ternary model, four types of core features are selected: identity permission features, abnormal behavior features, attack features, and environment adaptation features. Feature standardization processing is performed: numerical features (such as UEBA scores and intent confidence) are mapped to the [0,1] interval using Min-Max normalization; categorical features (such as role type and attack type) are converted into vectors using one-hot encoding; temporal features (such as operation sequences) are extracted using LSTM to extract temporal dependency features, finally forming a fixed-dimensional (128-dimensional) feature vector. 3. The data after feature standardization is input into Gradient Boosting Tree (XGBoost) and Multilayer Perceptron (MLP) for training, specifically as follows: Feature selection and preliminary classification: The XGBoost model ranks the 128-dimensional features by importance, selecting the top 64 key features, and simultaneously performs binary classification of "high-risk scenarios," outputting the scenario suitability confidence (0-100%); Parameter mapping generation: The key features output by XGBoost and the scenario confidence are input into the MLP model. The MLP contains 3 hidden layers and outputs 3 core mapping results: context parameter weight allocation, container resource configuration suggestions, and image type suitability score. 4. Training optimization: With "minimizing parameter prediction error + maximizing container scheduling success rate" as the dual objective function, the Adam optimizer is used for training. The initial learning rate is set to 0.001, and the learning rate decays by 10% every 100 iterations for model training optimization. 5. Model Deployment Architecture: Input parameter formats (including user ID, UEBA score, feature vector, and business scenario identifier) ​​and output parameter formats (context parameter configuration, container scheduling instructions) are defined through a RESTful API interface to enable data interaction between the model and other modules. 6. The model is optimized in real-time based on a closed-loop feedback module to ensure it adapts to changes in attack methods and business scenarios.

[0059] After the high-risk model is deployed, it synchronously generates behavioral feature vectors by collecting filtered data, honeypot interaction data, external threat intelligence data, and identity and permission data. Real-time data obtained by calculating user risk scores is used to extract 128-dimensional feature vectors, specifically including: user ID, role type, and permission level weight. UEBA risk score, behavioral deviation The system extracts 128-dimensional feature vectors, including intent confidence (I), honeypot popularity (H), attack tool fingerprint, and business scenario identifier. These features are then input into a high-risk model, which outputs context parameter configuration, container configuration instructions, and injection method identifiers. This enables the system to launch a dedicated container for the attacker based on the context.

[0060] In one possible implementation, a "dynamic configuration generation + runtime volume mounting" scheme is used to inject real business information into an isolated container to achieve targeted generation of dedicated container instances. Specifically, after injecting the identity context parameters of abnormal users into a high-risk model, the high-risk model first extracts the context based on the target user's ID to extract its real attributes from the enterprise IAM system (e.g., name="Zhang San", department="Finance Department", common filename="2024_Q1_Report"). Then, two types of configuration files are dynamically generated: environment variable files and decoy seed files. The environment variable files contain key-value pairs such as USER_ROLE=Finance_Manager, Fake_DB_PASS=123456; the decoy seed files are fake file metadata generated based on the user's common filenames. When calling the container engine to start the container instance, the generated configuration files are dynamically mounted to the container's / app / config directory in read-only mode using the -v parameter or the ConfigMap mechanism. The container image includes a pre-installed initialization script. Upon container startup, this script automatically reads dynamically mounted configuration files, uses the `sed` command to dynamically modify the welcome message on the web page (e.g., replacing "HelloUser" with "Welcome back, User Xiaoming"), and generates decoy files with specific timestamps in batches in the user's directory, thus creating a personalized trapping environment. After starting its dedicated container, the high-risk model immediately invokes the attacker risk profiling module to generate a comprehensive risk score describing the attacker's overall risk (if the user has already interacted within the container, the comprehensive risk score can be updated based on new behavioral data), and executes tiered response measures according to the comprehensive risk score range.

[0061] In one possible embodiment, a comprehensive raw score for the risk of user attack behavior is calculated according to the following formula: , A comprehensive raw score representing the risk of user attack behavior. This represents the number of behavioral features in the behavioral feature vector. Indicates the first Dynamic weights of each behavioral feature Indicates the first Confidence of attack intent triggered by a single behavioral characteristic in honeypots The constraint coefficients are used to normalize the user's original comprehensive score, resulting in the user's comprehensive risk score. , This represents the user's overall risk score. This represents the minimum original risk score of a feature in the feature vector. This represents the maximum original risk score of the feature in the feature vector.

[0062] Among them, "honey spot popularity" refers to the number of times a trend has occurred within the most recent sliding time window, triggering a trend related to the first trend. The number of users in a honeypot where each behavioral characteristic has a mapping relationship. The value of the constraint coefficient is related to the popularity of the honeypot, as shown in the table below:

[0063] Table 2. Relationship between constraint coefficient and honey spot heat

[0064]

[0065] Based on the user's comprehensive risk score and the preset risk score range, the risk type of the user's attack behavior is determined as low-risk suspicious attack, medium-risk attack, or high-risk confirmed attack. According to the risk type of the user's attack behavior, the container is activated to execute the corresponding response strategy and control the container's session lifecycle. When the user's attack behavior triggers a new honeypot within the container, the comprehensive risk score of the high-risk user is recalculated and updated, and the response strategy is adjusted according to the updated comprehensive risk score. The response strategies executed according to the risk type of the user's attack behavior include: for low-risk suspicious attacks, deploying lightweight decoys within the container instance to respond, and synchronizing user behavior data to assess the user's risk score; for medium-risk attacks, deploying highly realistic services within the container instance, limiting the weight of high-risk operations, and performing full session recording; for high-risk confirmed attacks, deploying high-value decoys within the container instance, blocking the user's connection to the real environment, capturing the fingerprint of the attack tool, and generating a standardized attack attribution report.

[0066] In one specific embodiment, the risk of a user's attack behavior can be classified into three categories based on the user's comprehensive risk score. The risk types and corresponding response measures are shown in the table below:

[0067] Table 3. Correspondence between Risk Types and Response Measures

[0068]

[0069] The risk profile of the aforementioned attack behavior will decay over time. If the user who committed the attack behavior does not exhibit any abnormal behavior during the preset silent period, the risk score will automatically decrease to avoid long-term misjudgment.

[0070] Simultaneously, the high-risk model manages the entire lifecycle of container sessions and collects container feedback data into the closed-loop optimization module. For example, session lifecycle control dynamically adjusts container survival time based on a comprehensive risk score to avoid resource waste. For example: <60: The container has a default lifespan of 1 hour; it will automatically destroy itself if there is no activity for 30 minutes; 60≤ <85: The container will survive for 2 hours; if there is no operation for 1 hour, it will be automatically destroyed. ≥85: The container survives until "attack behavior terminates (connection disconnected for more than 10 minutes)" or "SOC manually confirms source tracing complete," ensuring that complete attack data is captured. During the container session, if a new honeypot is triggered within the container, the high-risk model will be based on the new honeypot. The intent confidence level I is recalculated and updated in real time, and the user's comprehensive risk score is dynamically updated accordingly, with response measures adjusted accordingly.

[0071] S105: High-risk model collection container feedback data is used to optimize the high-risk model, update feature dynamic weights and detection thresholds.

[0072] In one possible embodiment, after the container session ends, the high-risk model collects container feedback data and feeds it back to the closed-loop feedback and optimization module, which enables the overall process of the hierarchical honeypot trapping method based on adaptive UEBA scoring to achieve self-learning and continuous evolution. Specifically, the high-risk model first anonymizes the container logs (attack operation records, tool fingerprints, C2 information) (e.g., hiding the real IP range and obfuscating the user ID) to avoid leakage of sensitive information; then it synchronizes the anonymized logs, the comprehensive risk score change curve, and the response measure effect data (e.g., whether C2 was captured, whether a complete attack chain was induced) to the closed-loop feedback and optimization module.

[0073] In one possible embodiment, the data that can be used for optimization processing in the closed-loop feedback and optimization module includes two categories: effect feedback data and new feature data. The effect feedback data specifically refers to the container scheduling success rate (such as whether the context parameter injection was successful or whether the container started normally), the attack trapping success rate (such as whether the complete attack chain was captured), and resource consumption data (such as container CPU / memory usage). The feedback indicators are statistically analyzed on a daily basis. The new feature data refers to the new attack features (such as new tool fingerprints and communication data packet features) automatically extracted when new attack methods (such as attacks using unknown tools or new C2 communication protocols) appear. The new feature data is added to the model feature library.

[0074] In one possible implementation, the timing pattern for updating feature dynamic weights, updating detection thresholds, and optimizing high-risk models is as follows: At the end of each time window, the popularity of different honeypots is calculated. Based on the system's attack capture results in the current time window, the feature dynamic weights, high-risk thresholds, and normal thresholds are updated and applied to the next time window. Every 24 hours, based on the daily feedback data, the high-risk model weights are updated using a "sliding window iteration" method. For example, if the trigger frequency of a certain type of honeypot (such as a fake cloud storage certificate honeypot) surges (H≥10), the corresponding honeypot trigger weight is increased. The importance of features in the model determines the priority of including honeypot configurations in the context parameters.

[0075] The priority of the feature dynamic weight adjustment process is as follows: after each time window ends, time decay calculation is performed on all feature dynamic weights first, then incremental adjustment is performed according to the honey point triggering situation, and finally Softmax normalization calibration is used to ensure that the sum of all feature weights is always 1, so as to avoid weight imbalance.

[0076] In one specific embodiment, after collecting container feedback data in each time window, the detection threshold is updated based on the attack capture results of the current time window, combined with the user behavior risk score distribution and density heat of the previous time window, for risk level determination in the next time window; the calculation of the detection threshold satisfies the following formula: , ,in, Indicates the first The normal threshold is calculated using a time window; Indicates the first The high-risk threshold is calculated using a time window; The inertia coefficient represents the adjustment of the detection threshold; , The corresponding role group represents the pth and qth percentiles in the [missing information]. The score for the first time window; a role group refers to a set of users with the same permission level or business attributes, including the target users involved in the current update detection threshold. The group division is based on identity and permission data synchronized from the enterprise Identity and Access Management (IAM) system. The role group... The score for each time window is the score for all users within that role group in the [number]th time window. The user risk score calculated within a time window is arranged in ascending order from low to high to form a numerical set. The p and q percentiles are the p and q percentiles in the numerical set. , These represent positive real numbers, used to adjust the intensity of the effect of honey spot heat on normal and high-risk thresholds, respectively. Indicates the first Within the first time window The honey spot heat value of the first behavioral characteristic and the first The product of the dynamic weights of each behavioral feature; This means summing the products of the honey spot popularity values ​​of all features and their risk value weights, and using this as one of the threshold determination criteria; Indicates the first The normal threshold is calculated using a time window; Indicates the first The high-risk threshold is calculated using a time window; , Indicates the external threat intelligence response coefficient; This indicates the external threat intelligence compensation factor.

[0077] Some of the parameter designs also need to meet the following conditions:

[0078] The honey spot heat value corresponds to the specific values ​​of p and q. The values ​​of p and q are determined using a multi-level threshold triggering rule based on honey spot heat, and the correspondence between honey spot heat and the specific values ​​of q and p can be adjusted according to actual needs. For example, the correspondence between honey spot heat and the specific values ​​of q and p can be shown in the following table:

[0079] Table 4. Correspondence between honey spot heat and specific values ​​of q and p

[0080]

[0081] set up The maximum value is 90, and the minimum value is 50; The maximum value is 99, the minimum value is 75, and it must always satisfy... > .

[0082] The external threat intelligence compensation factor is the core variable for solving the cold start problem, with a value range of [0, 10]. This value comes from the external threat intelligence interface. When external intelligence indicates the outbreak of high-risk vulnerabilities or an industry-wide wave of attacks, even if the local honeypot has not yet been triggered (i.e., the local heat value is 0), the compensation factor will be applied. It will remain at a high value, thereby lowering the threshold.

[0083] The external threat intelligence response coefficient is used to control the weight of external threat intelligence on the threshold, satisfying the following conditions: > .

[0084] Initial value of normal threshold Set as the 80th percentile value of the behavior score sequence of the role group within the first time window; the initial value of the high-risk threshold. The threshold is set to the 95th percentile of the behavior score sequence within the first time window of the role group. If the system has no historical behavior data, a pseudo-behavior log generated based on business rules is used for threshold initialization, and reasonable upper and lower boundaries are set to ensure system stability.

[0085] This invention provides a tiered honeypot trapping method based on adaptive UEBA scoring, which introduces honeypot popularity and external threat intelligence compensation factors as dynamic variables, directly mapping attack activity to detection sensitivity. When external intelligence alerts or local honeypots are triggered frequently, the risk judgment threshold is automatically lowered through a mathematical model (normal / high-risk dual thresholds are lowered simultaneously). This mechanism ensures that the system can automatically enter a high-sensitivity mode in the early stages of an attack, effectively reducing the false negative rate for covert, slow attacks or sudden zero-day attacks. The dynamic adaptation of the detection threshold solves the problem of slow response from static rules during attack outbreaks in existing technologies.

[0086] By constructing a ternary quantitative analysis model of "permissions-behavior-intent" and combining it with container runtime context dynamic injection technology, the system can dynamically mount simulated resources (such as departmental business documents and specific database configurations) that are highly matched to the target entity's permission level and business role during the dedicated container startup phase, based on the target entity's identity attributes. This personalized construction mechanism effectively eliminates the homogeneity of general honeypots, improves the deception and capture success rate of malicious insiders with legitimate credentials and advanced persistent threat (APT) attackers, enhances the accuracy of insider threat identification and capture, and solves the problem of general honeypots being easily detected.

[0087] Employing a cascaded architecture of "lightweight buffer + highly interactive simulation container," the system utilizes lightweight nodes to filter large-scale scanning traffic at low cost and leverages reverse proxy technology to seamlessly migrate high-risk targets to a highly interactive environment. Combined with a container lifecycle management strategy based on comprehensive risk scoring, the system achieves on-demand allocation and dynamic reclamation of defense resources. While ensuring in-depth forensics against high-value targets, it reduces the computational and storage resource load on the system during normal operation, achieving an optimal balance between trapping depth and system resource overhead.

[0088] This system constructs real-time feedback from high-fidelity interactive data from honeypots to user and entity behavior analysis, directly using captured attack characteristics (such as tool fingerprints and C2 communication protocols) to drive parameter updates for the feature weight matrix and high-risk prediction models. This mechanism endows the defense system with adaptive learning capabilities against new attack methods, enabling defense strategies to automatically evolve within minutes following changes in the attack landscape, achieving automated closed-loop iteration of defense strategies.

[0089] See the instruction manual appendix Figure 3This embodiment also provides a graded honey trapping device based on adaptive UEBA scoring, which is used to implement the above-described method embodiment. The device includes:

[0090] The filtering unit 201 is used to filter and limit the original network traffic to obtain filtered data.

[0091] The data acquisition unit 202 is used to collect filtered data according to a set time window and convert it into structured user behavior metadata, and generate a behavior feature vector based on the user behavior metadata.

[0092] User and entity behavior analysis unit 203 is used to calculate user risk score based on behavior feature vector and corresponding feature dynamic weights, and compare it with detection threshold to determine risk level.

[0093] The graded response unit 204 is used to introduce users into the corresponding processing modules for processing according to the risk level, and inject the identity context parameters of abnormal users into the high-risk model to start a dedicated container instance and manage the lifecycle of the container session.

[0094] Feedback and optimization unit 205 is used to collect container feedback data for high-risk models to optimize high-risk models, update feature dynamic weights and detection thresholds.

[0095] All relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.

[0096] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0097] In the embodiments of this application, the functional units can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0098] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, essentially, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as flash memory, portable hard disk, read-only memory, random access memory, magnetic disk, or optical disk.

[0099] The above description is merely a specific implementation of the embodiments of this application, but the protection scope of the embodiments of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the embodiments of this application should be covered within the protection scope of the embodiments of this application. Therefore, the protection scope of the embodiments of this application should be determined by the protection scope of the claims.

Claims

1. A hierarchical honey trapping method based on adaptive UEBA scoring, characterized in that, include: The raw network traffic is filtered and rate-limited to obtain filtered data; Data collected and filtered within a set time window is transformed into structured user behavior metadata, and a behavior feature vector is generated based on the user behavior metadata. The user risk score is calculated based on the behavioral feature vector and the corresponding dynamic feature weights, and compared with the detection threshold to determine the risk level; Users are directed to the corresponding processing modules based on their risk level. The identity context parameters of users identified as abnormal are injected into the high-risk model to start a dedicated container instance and manage the lifecycle of the container session. The high-risk model collects container feedback data to optimize the high-risk model, update feature dynamic weights, and detection thresholds.

2. The method according to claim 1, characterized in that, While collecting filtered data, honey spot interaction data is also collected, and honey spot interaction features are extracted from the honey spot interaction data. Feature dynamic weight calculation includes: The original feature score is calculated using the following formula: , Indicates the first The first time window The raw scores of each behavioral feature Indicates the first The first time window The raw scores of each behavioral feature Indicates the time decay factor. Indicates the adjustment factor. Indicates the first The first time window The popularity of honey spots corresponding to each behavioral characteristic Indicates the first Confidence of attack intent triggered by each behavioral characteristic in honeypots; The original scores of the features are normalized and calibrated to obtain the dynamic weights of the features.

3. The method according to claim 1, characterized in that, User risk score calculation includes: The original risk score of the feature is calculated using the following formula: , This represents the original risk score of the feature. Indicates the first Normalized values ​​of each behavioral feature Indicates the first Dynamic weights of each behavioral feature This represents the number of behavioral features in the behavioral feature vector; The user risk score is obtained by normalizing the original risk scores of the features: , This represents the user's risk score. This represents the minimum original risk score of a feature in the behavioral feature vector. This represents the maximum original risk score of the feature in the behavioral feature vector.

4. The method according to claim 1, characterized in that, The detection thresholds include normal thresholds and high-risk thresholds; When a user's risk score is greater than the high-risk threshold, the user is identified as a high-risk user and transferred to the honey point buffer zone. When a user’s risk score is between the normal threshold and the high risk threshold, the user is identified as a suspicious user. Suspicious users are continuously monitored and personalized honey spots are dynamically deployed to guide them into a deceptive environment. When a user's risk score is less than the normal threshold, the user is determined to be a normal user, and communication is allowed for normal users and resources are released periodically.

5. The method according to claim 1, characterized in that, The high-risk model is used to generate container configuration files based on user identity information, behavioral information, and system environment. When the container instance starts, a personalized trapping environment is built based on the container configuration file. Calculate a comprehensive risk score describing the risk of high-risk user attack behavior, and execute the corresponding response strategy based on the comprehensive risk score after the container instance starts.

6. The method according to claim 5, characterized in that, The overall raw score for the risk of user attack behavior is calculated using the following formula: , A comprehensive raw score representing the risk of user attack behavior. This represents the number of behavioral features in the behavioral feature vector. Indicates the first Dynamic weights of each behavioral feature Indicates the first Confidence of attack intent triggered by a single behavioral characteristic in honeypots Indicates the constraint coefficient; The user's overall risk score is obtained by normalizing the user's original comprehensive rating. , This represents the user's overall risk score. This represents the minimum original risk score of a feature in the feature vector. This represents the maximum original risk score of the feature in the feature vector.

7. The method according to claim 5, characterized in that, Based on the user's comprehensive risk score and the preset risk score range, the risk type of the user's attack behavior will be determined as low-risk suspicious attack, medium-risk attack, or high-risk confirmed attack. The container is started to execute the corresponding response strategy and the session lifecycle of the container is controlled according to the risk type of the user's attack behavior; When a user's attack triggers a new honeypot within the container, the overall risk score of the high-risk user is recalculated and updated, and the response strategy is adjusted based on the updated overall risk score. The response strategies implemented based on the risk type of user attack behavior include: for low-risk suspicious attacks, deploying lightweight decoys within container instances to respond and synchronizing user behavior data to assess user risk scores; for medium-risk attacks, deploying highly realistic services within container instances, limiting the weight of high-risk operations, and recording all sessions; and for high-risk confirmed attacks, deploying high-value decoys within container instances to block the user's connection to the real environment, capturing the fingerprints of attack tools, and generating standardized attack attribution reports.

8. The method according to claim 1, characterized in that, In each time window, after collecting container feedback data, the detection threshold is updated based on the attack capture results of the current time window, combined with the user behavior risk score distribution and density heat of the previous time window, for the risk level determination of the next time window. The detection threshold is calculated according to the following formula: , ,in, Indicates the first The normal threshold is calculated using a time window. Indicates the first The high-risk threshold is calculated using a time window. The inertia coefficient represents the adjustment of the detection threshold. , The corresponding role group represents the pth and qth percentiles in the [missing information]. The score for each time window, , Represents positive real numbers. Indicates the first Within the first time window The honey spot heat value of the first behavioral characteristic and the first The product of the dynamic weights of each behavioral feature. Indicates the first The normal threshold is calculated using a time window. Indicates the first The high-risk threshold is calculated using a time window. , Indicates the external threat intelligence response coefficient. This indicates the external threat intelligence compensation factor.

9. The method according to claim 8, characterized in that, Initial value of normal threshold Set as the 80th percentile value of the character group's behavior rating sequence within the first time window; Initial value of high-risk threshold Set as the 95th percentile value of the behavior rating sequence within the first time window of the character group.

10. A graded honey trapping device based on adaptive UEBA scoring, characterized in that, The device includes: The filtering unit is used to filter and rate limit the raw network traffic to obtain filtered data. The data acquisition unit is used to collect filtered data according to a set time window and convert it into structured user behavior metadata, and generate a behavior feature vector based on the user behavior metadata. The user and entity behavior analysis unit is used to calculate the user risk score based on the behavior feature vector and the corresponding feature dynamic weights, and compare it with the detection threshold to determine the risk level. The graded response unit is used to guide users to the corresponding processing modules for processing according to their risk level. It injects the identity context parameters of abnormal users into the high-risk model to start a dedicated container instance and manage the lifecycle of the container session. The feedback and optimization unit is used to collect container feedback data for high-risk models to optimize them, update feature dynamic weights, and adjust detection thresholds.