Dynamic trapping defense method and system based on software defined deception defense
By employing a dynamic trapping method based on software-defined deception defense, multimodal digital components are generated using P4 programmable switches and array scheduling algorithms. This method reconstructs the network topology in real time and transparently redirects attack traffic, solving the problems of dynamic adjustment and concealment in the face of advanced persistent threats in existing network security systems and achieving efficient multimodal defense.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU UNIVERSITY
- Filing Date
- 2026-03-24
- Publication Date
- 2026-04-24
AI Technical Summary
Existing cybersecurity systems struggle to dynamically adjust their topology, adapt to multimodal attacks, and maintain stealth when facing advanced persistent threats, leading to a decline in defense effectiveness.
A dynamic trapping method based on software-defined deception defense is adopted. The P4 programmable switch is used to monitor network traffic, and a custom parser is used to extract the feature values of data packets. Combined with the Digest digest mechanism and the array scheduling algorithm, multimodal digital components are generated, the network topology is reconstructed in real time, and attack traffic is transparently redirected. The defense strategy is continuously monitored and iteratively updated.
It enables real-time perception and dynamic response to attack behavior, enhances multimodal decoy capabilities and stealth, effectively addresses changes in attackers' strategies, and significantly improves the real-time nature and stealth of defense.
Smart Images

Figure CN121923938A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a dynamic deception defense method and system based on software-defined deception defense. Background Technology
[0002] As cyberattacks become increasingly complex, automated, and covert, traditional defense-oriented cybersecurity systems struggle to cope with persistent, high-intensity, and targeted attacks. To enhance the ability to observe and guide attackers, proactive deception techniques have emerged. Honeypot technology, which deploys deceptive resources to lure attackers and record their behavioral paths, has become a classic proactive defense method. However, traditional honeypots still have the following limitations: static deployment results in a fixed topology and service configuration, making dynamic adjustments difficult based on attack scenarios, significantly reducing their effectiveness against advanced persistent threats; single-modal designs can only simulate specific types of services, failing to address the complex needs of multimodal attacks; and insufficient stealth makes them vulnerable to detection through fingerprinting or behavioral analysis, leading to reduced defense effectiveness.
[0003] Currently, the closest technical solutions to this invention include Cisco Application Centric Infrastructure (ACI) and VMware NSX-T Data Center. Cisco ACI uses the Application Policy Infrastructure Controller to centrally manage and dynamically configure network policies, supporting the dynamic deployment of multimodal network modes and security policies. VMware NSX-T uses NSX Manager and NSX Controller to implement network virtualization and security policy deployment, supporting virtualized firewalls, load balancers, and micro-segmentation. However, these solutions still have the following technical shortcomings: limited support for multimodal solutions; support for non-standard or emerging protocols requires additional development, making it difficult to adapt to unknown attack methods; topology adjustments rely on pre-configured policy templates and rules, resulting in poor dynamic change capabilities and an inability to respond in real-time to the rapid, multi-stage policy changes of advanced attackers; and insufficient stealth optimization, with relatively fixed traffic patterns and network behavior, making it easy for attackers to identify honeypot characteristics by analyzing packet headers, protocol fields, or response delays. Therefore, there is an urgent need to provide a solution to improve upon these problems. Summary of the Invention
[0004] The purpose of this invention is to provide a dynamic decoy defense method and system based on software-defined deception defense, which can improve the problems in the prior art caused by insufficient dynamic response capability due to static deployment, difficulty of adapting a single modality to multimodal attacks, and poor concealment of the decoy environment, making it easy to be identified.
[0005] In a first aspect, the present invention provides a dynamic decoy defense method based on software-defined deception defense, comprising:
[0006] An initial network topology is constructed, and digital components are deployed within it. A P4 programmable switch is used to monitor these digital components. The P4 programmable switch extracts the five-tuple information and application layer load characteristics of data packets using a custom parser. Based on the stateful registers within the P4 programmable switch, the connection frequency and probe span of the accessing source IP address are recorded. When the load characteristics match a preset threat awareness flow table, or when the connection frequency and probe span exceed a preset security threshold, it is determined that the digital component has been attacked. Based on a Digest mechanism, the attack source IP address, target port, and malicious metadata are packaged into a telemetry log and exported in real time.
[0007] Analyze the telemetry logs to extract TTP behavior sequences; based on the TTP behavior sequences, generate a digital component deployment array using array scheduling and resource mapping algorithms; according to the digital component deployment array, call the honeycomb array controller to perform dual-mode matching and generate multimodal digital components;
[0008] Based on the digital component deployment array and the multimodal digital components, the network topology is reconstructed, and the multimodal digital components are deployed in the reconstructed network topology;
[0009] Based on real-time threat intelligence, flow table rules based on the match-action paradigm are issued to the P4 programmable switch through the P4 runtime interface to transparently redirect attack traffic to the reconstructed network topology; the interaction between the multimodal digital components and the attacker is continuously monitored, and the deployment diagram of the digital components and the network topology are iteratively updated according to the interaction results.
[0010] This invention provides a dynamic deception defense method based on software-defined deception defense. It constructs an initial network topology and deploys digital components. A P4 programmable switch monitors the digital components and collects and exports attack logs when attacked. After analyzing the logs and extracting TTP (Transactions-Based Transaction) behavior sequences, a deployment map of the digital components is generated using a map scheduling and resource mapping algorithm. Based on the deployment map, a honeycomb controller is invoked to perform dual-mode matching to generate multimodal digital components. The network topology is reconstructed based on the deployment map and the multimodal digital components, and the multimodal digital components are deployed again. Based on real-time threat intelligence, flow table rules with a matching-action paradigm are issued to the P4 programmable switch through the P4 runtime interface to guide attack traffic to the reconstructed network topology. The interaction between the multimodal digital components and the attacker is continuously monitored, iteratively updating the deployment map and network topology. This enables real-time perception and dynamic response to attack behavior, constructing an adaptive deception defense environment with multimodal deception capabilities and high stealth.
[0011] Optionally, when generating a digital component deployment map based on the TTP behavior sequence using a real soil scheduling and resource mapping algorithm, the process includes:
[0012] Based on the TTP behavior sequence and combined with the preset ATT&CK knowledge graph, the threat stage corresponding to the TTP behavior sequence is evaluated; the attacker's attack intent is judged by combining real-time threat intelligence; according to the threat stage and the judgment result, the type and network location of the digital component to be deployed are determined by the matrix scheduling algorithm; and the resource requirements of the digital component to be deployed are mapped to available computing and network resources by the resource mapping algorithm.
[0013] Optionally, when calling the honeycomb array controller to perform dual-mode matching according to the digital component deployment diagram, the process includes:
[0014] The honey array controller performs dual-mode matching based on TTP characteristics: for known CVE vulnerability characteristics, it accurately matches the pre-made CVE images in the honey database server; for unknown attack scenario characteristics, it performs fuzzy matching based on operating system characteristics, file extensions, or process paths to dynamically generate lightweight simulation components.
[0015] Optionally, the multimodal digital component includes a service tripwire, a traffic tripwire, a domain controller tripwire, and a cloud service tripwire; wherein, the service tripwire is a network service quickly built based on script tools; the traffic tripwire is used to simulate normal business traffic and generate business traffic containing simulation vulnerability features; the domain controller tripwire is a deployed Windows domain controller environment and contains simulated usernames generated based on a high-order Markov model; the cloud service tripwire is a cloud resource service that simulates preset vulnerabilities or misconfigurations.
[0016] Optionally, when reconstructing the network topology based on the digital component deployment map and the multimodal digital components, the process includes: determining the node layout and connection relationships of the reconstructed network topology based on the digital component types and network location information in the digital component deployment map.
[0017] Optionally, when deploying the multimodal digital component in the reconstructed network topology, it includes:
[0018] The resource optimizer is invoked to determine the resource configuration of each multimodal digital component based on the deployment diagram and the current host load, using a load balancing strategy.
[0019] The dynamic converter is invoked to generate the corresponding container or virtual machine configuration file according to the resource configuration; the network deployment tool is used to instantiate the multimodal digital component according to the configuration file; the network control tool is used to connect the instantiated multimodal digital component to the corresponding network location according to the digital component deployment map, and ensure network connectivity.
[0020] The network deployment tools include Docker, KVM, QEMU, and Podman; the network control tools include ODL, Ryu, POX, and ACI.
[0021] Optionally, when issuing flow table rules based on the match-action paradigm to the P4 programmable switch via the P4 runtime interface based on real-time threat intelligence to transparently redirect attack traffic to the reconstructed network topology, the process includes: issuing flow table rules based on the match-action paradigm to the P4 programmable switch via the P4 runtime interface based on real-time threat intelligence to update the match-action table in the data plane; when subsequent attacker traffic arrives, performing network address translation actions to rewrite the destination IP address and destination MAC address of the data packets, transparently redirecting the attack traffic to the reconstructed network topology during the line-speed forwarding phase, without interrupting the attacker's network connection status.
[0022] Secondly, the present invention also provides a dynamic trapping network deployment system based on Markov decision processes, comprising:
[0023] A topology building module is used to construct an initial network topology and deploy digital components within it. A P4 programmable switch is used to monitor these digital components. The P4 programmable switch extracts the five-tuple information and application layer load characteristics of data packets using a custom parser. Based on the stateful registers within the P4 programmable switch, the connection frequency and probe span of the access source IP address are recorded. When the load characteristics match a preset threat awareness flow table, or when the connection frequency and probe span exceed a preset security threshold, it is determined that the digital component has been attacked. Based on a Digest mechanism, the attack source IP address, target port, and malicious metadata are packaged into a telemetry log and exported in real time.
[0024] The intelligent orchestration module is used to analyze the telemetry logs and extract TTP behavior sequences; based on the TTP behavior sequences, it generates a digital component deployment array through array scheduling and resource mapping algorithms; according to the digital component deployment array, it calls the honeycomb array controller to perform dual-mode matching and generate multimodal digital components.
[0025] The component deployment module is used to reconstruct the network topology based on the digital component deployment array and the multimodal digital components, and to deploy the multimodal digital components in the reconstructed network topology;
[0026] The update control module is used to issue flow table rules based on the match-action paradigm to the P4 programmable switch through the P4 runtime interface based on real-time threat intelligence, so as to transparently redirect attack traffic to the reconstructed network topology; continuously monitor the interaction between the multimodal digital components and the attacker, and iteratively update the deployment diagram of the digital components and the network topology based on the interaction results.
[0027] Thirdly, the present invention also provides a storage medium that stores one or more programs that, when executed by a processor, implement the above-described dynamic deception defense method based on software-defined deception defense.
[0028] Fourthly, the present invention also provides an electronic device, the electronic device comprising a memory and a processor, wherein:
[0029] The memory is used to store computer programs;
[0030] When the processor executes the computer program stored in the memory, it implements the above-mentioned dynamic deception defense method based on software-defined deception defense.
[0031] Compared with the prior art, the present invention has the following beneficial effects:
[0032] 1. This invention deeply couples the P4 state register, custom parser, Digesr digest mechanism and deception defense, realizing a unified design of line-speed detection of attack behavior, lightweight reporting and transparent redirection, which greatly improves the real-time performance and accuracy of attack response.
[0033] 2. Compared with static rules or manual configuration, this invention introduces the ATT&CK knowledge graph and real-time threat intelligence into the array scheduling process, resulting in a more targeted and dynamically adaptable decoy environment that can effectively respond to changes in attackers' strategies.
[0034] 3. This invention achieves transparent and seamless redirection of attack traffic through the dynamics of the P4 programmable switch. Attackers are introduced into a dynamically evolving honeypot environment without their knowledge. Their network connection status remains continuous, and they cannot identify the existence of the defense through abnormal phenomena such as connection interruption. This significantly improves the concealment of the deception defense and the success rate of trapping. Attached Figure Description
[0035] Figure 1 A flowchart illustrating a dynamic deception defense method based on software-defined deception defense provided in an embodiment of the present invention;
[0036] Figure 2 A schematic diagram of a dynamic decoy defense system based on software-defined deception defense provided in an embodiment of the present invention;
[0037] Figure 3 This is a functional flowchart of the intelligent orchestration module provided in an embodiment of the present invention;
[0038] Figure 4 This is a schematic diagram of the intelligent orchestration and network topology construction process provided in an embodiment of the present invention. Detailed Implementation
[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art. The terms "comprising" and similar expressions used herein mean that the element or object preceding the word covers the element or object listed after the word and its equivalents, but does not exclude other elements or objects.
[0040] Before formally describing each step, we will first define and explain two core concepts involved in this invention:
[0041] In this invention, digital components are programmable, atomic defense resource units. As the specific technical entity for constructing multimodal decoys, their core value lies in standardization and programmability. The digital components discussed here generally refer to the service tripwires, traffic tripwires, domain controller tripwires, and cloud service tripwires of the honeypot in the four-honeypot system. These components are intelligently scheduled through the API interface of the SDN control plane—when the honeypot scheduling algorithm analyzes the attacker's intent, the honeypot controller accurately matches the corresponding service image from the component library and instantiates it in seconds via KVM / Docker. Digital components are primarily intended as a technical carrier for engineering implementation, solving the problem of resource rigidity. They replace high-cost physical devices with lightweight virtualization deployment, improve defense efficiency through component reuse, and ultimately support an "on-demand, dynamic" proactive defense architecture.
[0042] In this invention, multimodality refers to a technical strategy in deception defense systems that constructs dynamic decoy environments through heterogeneous data formats and interactive methods. Its core is to break attackers' singular understanding of the defense system and build defense modeling that possesses both horizontal and vertical depth. In APT attack scenarios, attackers continuously change TTPs (tactics, techniques, processes) and penetrate across network domains. Traditional static decoys, lacking diversity, struggle to cover fragmented attack chains. Multimodal technology integrates multi-dimensional attack surface features, including network layer (using protocols to simulate traffic), system layer (forging registry entries / processes), application layer (building intelligent vulnerability signature services), and file layer (constructing deceptive malicious scripts), creating a "fog of war" effect. When attackers launch various network attacks, multimodal guidance digital components are distributed throughout the attacker's next possible actions. This multi-dimensional, full-chain decoy coverage prevents attackers from identifying defense patterns through long-term observation, thus solving the problem of attack clue breaks caused by "sampling bias." Essentially, multimodality is an adversarial design philosophy for defense systems, emphasizing dynamic heterogeneity to address the stealth and persistence of attacks.
[0043] See Figure 1 This invention provides a dynamic decoy defense method based on software-defined deception defense, comprising the following steps:
[0044] S1. Construct an initial network topology and deploy digital components within it; monitor the digital components using a P4 programmable switch. The P4 programmable switch extracts the five-tuple information and application layer load characteristics of data packets through a custom parser; record the connection frequency and probe span of the access source IP address based on the stateful registers inside the P4 programmable switch; when the load characteristics match the preset threat awareness flow table, or the connection frequency and probe span exceed the preset security threshold, it is determined that the digital component has been attacked, and the attack source IP address, target port, and malicious characteristic metadata are packaged into a telemetry log and exported in real time based on the Digest digest mechanism.
[0045] S2. Analyze telemetry logs and extract TTP behavior sequences; based on the TTP behavior sequences, generate a digital component deployment array diagram through array diagram scheduling and resource mapping algorithms; according to the digital component deployment array diagram, call the honey array controller to perform dual-mode matching and generate multimodal digital components;
[0046] S3. Based on the deployment of digital component array and multimodal digital components, reconstruct the network topology, and deploy the multimodal digital components in the reconstructed network topology;
[0047] S4. Based on real-time threat intelligence, issue flow table rules based on the match-action paradigm to the P4 programmable switch through the P4 runtime interface to transparently redirect attack traffic to the reconstructed network topology; continuously monitor the interaction between multimodal digital components and attackers, and iteratively update the digital component deployment diagram and network topology based on the interaction results.
[0048] In some embodiments, step S1 includes first constructing an initial network topology based on Software-Defined Networking (SDN) and deploying several basic digital components within the initial network topology. Next, a P4 programmable switch is used to monitor the deployed digital components in real time. During normal network traffic forwarding, the underlying P4 programmable switch extracts the five-tuple information of data packets through its custom parser in the data plane, including the source IP address, destination IP address, source port, destination port, and protocol type. Based on this, it further delves into the application layer to extract specific load characteristic values. Simultaneously, the P4 programmable switch maintains a status register to continuously record the connection frequency and probe span of a specific source IP address. The connection frequency is the number of connection requests initiated by the source IP address per unit time, and the probe span is the number of different target ports and different protocol types accessed by the source IP address. When the application layer load characteristic value extracted by the custom parser matches a preset threat awareness flow table, or when the connection frequency and probe span recorded by the status register exceed a preset security threshold, it is determined that the digital component is under attack. Upon confirming the attack, the P4 programmable switch stops forwarding the suspicious traffic via conventional routing and immediately triggers the Digest mechanism to ensure the processing efficiency of the management plane. This mechanism packages the extracted attack source IP address, target port, and malicious metadata into a lightweight telemetry log and reports it to the intelligent orchestration module in real time via the P4 runtime interface. This targeted Digest reporting mechanism for attack events avoids uploading large amounts of raw traffic to the control plane, achieving lightweight and real-time attack detection, and providing accurate decision-making basis for subsequent matrix generation and dynamic traffic redirection. This step deeply couples the P4 switch's data plane programming capabilities with deception defense, achieving fine-grained line-speed detection of attack behavior through stateful registers, accurate extraction of application-layer malicious features through a custom parser, and lightweight reporting of attack information through the Digest mechanism. This coupling method provides accurate and low-latency attack intelligence support for subsequent dynamic trapping.
[0049] In some embodiments, in step S2, telemetry logs are analyzed to extract TTP behavior sequences. Based on these TTP behavior sequences, when generating a digital component deployment array using array scheduling and resource mapping algorithms, the intelligent orchestration module first receives telemetry logs exported from the P4 programmable switch. The intelligent orchestration module has a built-in TTP extraction engine that uses natural language processing technology and pattern matching algorithms to parse the logs and identify the tactics, techniques, and procedures (TPs) used by the attacker. For example, when an attacker performs a port scan, reconnaissance tactics (TA0043) and corresponding techniques such as active scanning (T1595) can be identified; when an attacker uploads a WebShell, persistence tactics (TA0003) and techniques such as server software components (T1505.003) can be identified. The TTP extraction engine stores the identified TTP behavior sequences in a structured manner to form a profile of the attacker's behavior.
[0050] After extracting the TTP (Tracking Points to Action) behavior sequence, the intelligent orchestration module invokes a pre-defined ATT&CK (Attack Tolerance & Detection) knowledge graph to match the current TTP behavior sequence with attack patterns within the knowledge graph. The ATT&CK knowledge graph contains detailed information on various attack techniques, their preconditions, possible subsequent techniques, and the tactical stage they belong to. Through correlation analysis, the intelligent orchestration module can assess the current threat stage of the attack (e.g., reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement, etc.). Simultaneously, it correlates the TTP behavior sequence with real-time threat intelligence to identify whether the attacker belongs to a known attack group, whether they used the latest disclosed exploit techniques, and the attacker's potential skill level. Based on the combined analysis results, the module determines the attacker's intent and potential next actions. For example, if a network scan (T1595) is detected, it is determined to be in the reconnaissance stage, and potential subsequent exploit attempts are predicted. After the assessment, the intelligent orchestration module begins generating a new network topology. Specifically, based on the analyzed attack characteristics, the intelligent orchestration module reallocates computing resources in the management plane, dynamically instantiates and launches corresponding lightweight simulation components or highly interactive images, thereby constructing a new multimodal network topology containing decoy nodes.
[0051] Based on the analysis results and the requirements of the decoy environment to be constructed, the intelligent orchestration module initiates the matrix scheduling algorithm. This algorithm first queries the component library, which predefines mirror templates of various digital components, including service tripwires, traffic tripwires, domain control tripwires, and cloud service tripwires. Each component is associated with its applicable attack scenario, simulated service type, network location preference, and resource requirements. The matrix scheduling algorithm selects suitable digital component types from the component library based on the current threat stage and TTP characteristics, and determines their network deployment locations. For example, if the attacker is in the reconnaissance phase, it may be necessary to deploy traffic tripwires and low-interaction service tripwires on critical network paths to induce further probing; if the attacker has entered the lateral movement phase, domain control tripwires need to be deployed to simulate internal systems. The matrix scheduling algorithm uses graph theory to plan the connections between the component nodes to be deployed and real and virtual nodes in the existing network topology, generating a preliminary matrix diagram containing component types, network locations, and connection relationships.
[0052] After the initial deployment map is generated, the intelligent orchestration module invokes the resource mapping algorithm. This algorithm comprehensively considers currently available computing resources, network resources, and the resource requirements of each component template. Through optimization, it maps the resource requirements of each digital component in the map to actually available physical or virtual resources, ensuring reasonable resource allocation and load balancing. Simultaneously, the algorithm also considers the isolation between the component's deployment location and the real network environment to prevent the decoy environment from interfering with real services. After mapping, the final digital component deployment map is generated. This map includes a unique identifier for each digital component to be deployed, resource configuration parameters, network configuration, and deployment priority. These steps transform attack logs into intelligent decision-making, mapping the attacker's dynamic behavior into highly targeted dynamic decoy strategies, laying the decision-making foundation for building an adaptive deception defense environment.
[0053] In some embodiments, during step S2, when the honeycomb controller is invoked to perform dual-mode matching based on the digital component deployment diagram to generate multimodal digital components, the intelligent orchestration template sends the generated digital component deployment diagram to the honeycomb controller. The honeycomb controller parses the digital component deployment diagram, extracts the type, quantity, and associated TTP features of the multimodal digital components to be generated, and forms a component list. Subsequently, the honeycomb controller initiates a dual-mode matching mechanism based on the TTP features: the first mode is precise matching, where for known CVE vulnerability features, the honeycomb controller queries the honey database server, retrieves and calls pre-made CVE images as component templates; the second mode is fuzzy matching, where for unknown attack scenario features, the honeycomb controller dynamically generates description files for lightweight simulation components based on the path information, operating system type, process information, and other context specified in the digital component deployment diagram, using a fuzzy matching algorithm.
[0054] See Figure 3 The internal workflow of the intelligent orchestration module includes: First, the SDN switch collects and reports attack logs; second, the module generates a dynamic network topology based on the logs, determining the types of digital components to be deployed and their network locations; next, it calls the honeycomb dynamic converter to execute specific component generation and configuration; finally, it constructs the network topology based on the generated digital components and sends the topology information to the underlying layer for execution.
[0055] In some embodiments, during step S3, when reconstructing the network topology based on the digital component deployment map and multimodal digital components, and deploying the multimodal digital components in the reconstructed network topology, the component deployment module receives the component list and digital component deployment map from step S2. First, the component deployment module parses the digital component deployment map to obtain the type, network location, and interconnection relationships of the multimodal digital components to be deployed, thereby determining the reconstructed network topology. This topology includes the connection methods between newly added honeypot nodes and existing network nodes, as well as the overall network layout.
[0056] Next, the component deployment module invokes the resource optimizer to configure resources. Based on the resource requirements of each component in the digital component deployment matrix and the real-time load status of the current host, the resource optimizer allocates appropriate physical or virtual resources to each digital component using a load balancing strategy, ensuring reasonable resource allocation and overall system load balancing. After resource allocation is complete, the component deployment module invokes the dynamic transformer. The dynamic transformer generates corresponding container configuration files or virtual machine configuration files based on the component type, image identifier, and resource configuration parameters, while also configuring the component's network parameters. These configuration files encapsulate the component's runtime environment and startup parameters.
[0057] Subsequently, the component deployment module distributes the generated configuration files to the underlying containerization or virtualization engine. Specifically, for containerized components, it calls the Docker daemon or Podman engine to start the corresponding container according to the configuration file; for virtual machine components, it calls the KVM or QEMU hypervisor to create and start the virtual machine according to the configuration file. Through the above operations, the instantiation of the multimodal digital component is completed. The instantiated component has complete service functions and predefined interactive behaviors. After instantiation, the component deployment module calls network control tools to perform topology reconstruction and network access. Network control tools (such as Ryu, ODL, POX, and ACI) communicate with the virtualized SDN switch through the southbound interface, configure the corresponding flow table entries according to the node connection relationship specified in the deployment diagram, and connect the instantiated multimodal digital components to the corresponding network locations according to the diagram. This process includes establishing logical links between components, setting traffic forwarding rules, configuring access control policies, etc., thereby reconstructing the topology and network access of the deployment module. Figure 1The target network topology is determined. After completing the flow table configuration, the deployment module verifies the network connectivity between each component to ensure that attackers can normally access the newly deployed decoy environment, while ensuring the isolation between the real business and the decoy environment.
[0058] Finally, the component deployment module feeds back the instantiated component status information to the honeycomb controller for dynamic detection and iterative updates in subsequent steps. Through the above steps, step S3 realizes the physical or virtual construction from the honeycomb diagram to the actual trapping environment, completing the dynamic reconstruction of the network topology and the precise deployment of multimodal digital components.
[0059] See Figure 4 After completing log collection and analysis, the intelligent orchestration module generates a digital component deployment diagram and distributes it to the virtualized SDN switch. Based on the diagram information, the virtualized SDN switch uses complex network deployment tools (Docker, KVM, QEMU, and Podman) to deploy multimodal digital components and complex network control tools (ODL, Ryu, POX, and ACI) to build the network topology. Finally, the deployed digital components are integrated into the completed network topology, forming a complete decoy environment.
[0060] In some embodiments, in step S4, based on real-time threat intelligence, flow table rules based on the match-action paradigm are issued to the P4 programmable switch through the P4 runtime interface to transparently redirect attack traffic to the reconstructed network topology. When continuously monitoring the interaction between multimodal digital components and attackers, and iteratively updating the digital component deployment map and network topology based on the interaction results, the update control module first obtains real-time threat intelligence from external threat intelligence sources (such as commercial threat intelligence platforms or open-source intelligence communities) or internal security devices (such as firewalls or intrusion detection systems). Real-time threat intelligence can be attacker fingerprints, malicious IP address pools, attack payload characteristics of the latest CVE vulnerabilities, and common protocol anomaly patterns used by attackers. The update control module performs correlation analysis between the obtained real-time threat intelligence and the TTP behavior sequence extracted in step S2 to identify the latest attack methods and potential variants of the current attacker, and determine the characteristics of the attack traffic to be redirected (such as source IP, destination port, protocol type, and packet characteristics). Simultaneously, the update control module retrieves the currently valid digital component deployment map to obtain the network location (such as IP address, port, and access point) of the multimodal digital components in the reconstructed network topology. Based on the above information, the update control module generates dynamic redirection rules, which specify which attack traffic needs to be redirected and to which specific decoy node. The update control module converts the generated dynamic redirection rules into match-action flow table entries recognizable by the P4 switch. Matching fields can include Ethernet headers, IP headers, transport layer headers, and even application layer characteristics; action fields can include modifying the destination MAC / IP / port, encapsulating tunnels, directly forwarding to a specified port, or dropping the data. Subsequently, the update control module sends the flow table entries to the P4 programmable switch via the P4 runtime interface. Upon receiving the flow table entries, the P4 programmable switch immediately updates its data plane's match-action table. When subsequent attacker traffic reaches the P4 programmable switch again, the switch pipeline extracts the source IP address and the malicious status bit pre-marked from the data packet, compares it with the matching fields of the flow table entries, and then the P4 programmable switch forcibly executes network address translation (NAT) actions, directly rewriting the destination IP address and destination MAC address of the data packet during the linear forwarding stage, modifying them to the real addresses of the corresponding decoy components in the reconstructed network topology. The modified data packets are forwarded to the specified output port, maintaining continuous network connectivity.
[0061] After the attack traffic is transparently redirected to the reconstructed network topology, the attacker begins interacting with the multimodal digital components within it. The P4 programmable switch and the multimodal digital components themselves continuously record the attacker's subsequent actions, generating new attack logs. These logs include the attacker's commands, accessed resources, uploaded payloads, attempted exploits, and lateral movement paths. These logs are reported in real-time to the intelligent orchestration module for analysis of the attacker's new TTP behaviors and evolving attack intentions. Based on the newly received attack logs, the intelligent orchestration module repeats the analysis methods in step S2: re-extracting the TTP behavior sequence, assessing the current threat stage using the ATT&CK knowledge graph, and predicting the attacker's next possible actions. If the attacker's behavior exceeds the current decoy environment's response capabilities, or if the prediction necessitates enhancing the decoy capabilities of certain attack surfaces, the intelligent orchestration module re-executes the array scheduling and resource mapping algorithms to generate an updated digital component deployment array. The updated array may include newly added digital component types, adjustments to the positions or configurations of existing components, or even the removal of ineffective decoys. Subsequently, step S3 is repeated, and the network topology is reconstructed or adjusted according to the updated network map, deploying new multimodal digital components. Simultaneously, the update control module adjusts the redirection rules on the P4 switch according to the updated network map, ensuring that subsequent attack traffic is correctly guided to the updated decoy environment. Through the continuous loop of the above steps, step S4 implements a dynamic redirection and closed-loop iterative update mechanism based on real-time threat intelligence. This mechanism enables the defense system to respond to the attacker's dynamic changes in real time, maintaining the targeting and deception of the decoy environment. Attackers face a constantly evolving "fog of war" environment, making it difficult to identify defense patterns through long-term observation, thus significantly improving the depth and effectiveness of deception defense. This step utilizes the dynamic address rewriting capability of the P4 switch at its underlying layer to transparently redirect traffic to dynamically constructed decoy components without interrupting the attacker's network connection. This transparent decoy mechanism, imperceptible to the attacker, significantly improves the stealth and effectiveness of deception defense.
[0062] This invention proposes a dynamic decoy defense method based on software-defined deception defense. Building upon existing honeypot scheduling research, this method integrates SDN and P4 programmable switching technologies to achieve dynamic construction of multimodal network topologies and intelligent orchestration of digital components. Specifically, the SDN-based multimodal network topology construction technology utilizes P4 programmable switches and SDN controllers to automatically generate multimodal services at different levels and dynamically manage flow tables through the P4 runtime interface. It can reconstruct the network topology in real time based on attack behavior, accurately guiding attack traffic to a customized honeypot. The intelligent digital component orchestration technology analyzes telemetry logs reported by the P4 programmable switches, uses a matrix scheduling algorithm and a TTP extraction engine to analyze attacker behavior sequences, combines ATT&CK knowledge graphs to assess the threat stage, and initiates dual-mode matching based on TTP characteristics: accurately calling pre-made service images for known vulnerabilities, and dynamically generating lightweight simulation components for unknown attacks through fuzzy matching of paths and processes. Finally, based on the generated components and topology, a three-dimensional honeypot environment that is difficult for attackers to identify is constructed. Through the aforementioned technical means, this invention significantly enhances the ability to lure and capture multi-level and multi-mode attacks, improves response speed and honeypot concealment, effectively luring advanced attackers deep into the honey field and reversing the passive defensive situation of "the enemy is in the dark while we are in the light".
[0063] See Figure 2 This invention provides a dynamic decoy defense system based on software-defined deception defense, comprising:
[0064] The topology building module 100 is used to build the initial network topology and deploy digital components in the initial network topology; it uses a P4 programmable switch to monitor the digital components. The P4 programmable switch extracts the five-tuple information and application layer load characteristics of data packets through a custom parser; based on the stateful register inside the P4 programmable switch, it records the connection frequency and probe span of the access source IP address; when the load characteristics hit the preset threat awareness flow table, or the connection frequency and probe span exceed the preset security threshold, it is determined that the digital component has been attacked, and the attack source IP address, target port and malicious characteristic metadata are packaged into telemetry logs and exported in real time based on the Digest digest mechanism;
[0065] The intelligent orchestration module 200 is used to analyze attack logs and extract TTP behavior sequences; based on the TTP behavior sequences, it generates a digital component deployment array through array scheduling and resource mapping algorithms; according to the digital component deployment array, it calls the honey array controller to perform dual-mode matching and generate multimodal digital components.
[0066] The component deployment module 300 is used to reconstruct the network topology based on the digital component deployment array and multimodal digital components, and to deploy the multimodal digital components in the reconstructed network topology;
[0067] The update control module 400 is used to issue flow table rules based on the match-action paradigm to the P4 programmable switch through the P4 runtime interface based on real-time threat intelligence, so as to transparently redirect attack traffic to the reconstructed network topology; continuously monitor the interaction between multimodal digital components and attackers, and iteratively update the digital component deployment diagram and network topology based on the interaction results.
[0068] In another aspect, the present invention provides a computer device including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the dynamic decoy defense method based on software-defined deception defense as described in any of the above claims.
[0069] In another aspect, the present invention provides a readable storage medium storing a computer program that can be executed by a processor of the device in which the storage medium is located, to implement the dynamic decoy defense method based on software-defined deception defense as described in any of the above claims.
[0070] Those skilled in the art will understand that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can mean any means that can contain stored, communicated, propagated, or transmitted programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0071] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0072] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0073] While embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations can be made to these embodiments. However, it should be understood that such modifications and variations fall within the scope and spirit of the invention as set forth in the claims. Furthermore, the invention described herein may have other embodiments and can be implemented or carried out in various ways.
Claims
1. A dynamic decoy defense method based on software-defined deception defense, characterized in that, include: An initial network topology is constructed, and digital components are deployed within it. A P4 programmable switch is used to monitor these digital components. The P4 programmable switch extracts the five-tuple information and application layer load characteristics of data packets using a custom parser. Based on the stateful registers within the P4 programmable switch, the connection frequency and probe span of the accessing source IP address are recorded. When the load characteristics match a preset threat awareness flow table, or when the connection frequency and probe span exceed a preset security threshold, it is determined that the digital component has been attacked. Based on a Digest mechanism, the attack source IP address, target port, and malicious metadata are packaged into a telemetry log and exported in real time. Analyze the telemetry logs to extract TTP behavior sequences; based on the TTP behavior sequences, generate a digital component deployment array using array scheduling and resource mapping algorithms; according to the digital component deployment array, call the honeycomb array controller to perform dual-mode matching and generate multimodal digital components; Based on the digital component deployment array and the multimodal digital components, the network topology is reconstructed, and the multimodal digital components are deployed in the reconstructed network topology; Based on real-time threat intelligence, flow table rules based on the match-action paradigm are issued to the P4 programmable switch through the P4 runtime interface to transparently redirect attack traffic to the reconstructed network topology; The interaction between the multimodal digital components and the attacker is continuously monitored, and the deployment diagram and network topology of the digital components are iteratively updated based on the interaction results.
2. The method as described in claim 1, characterized in that, When generating a digital component deployment array based on the TTP behavior sequence using array scheduling and resource mapping algorithms, the process includes: Based on the TTP behavior sequence and combined with the preset ATT&CK knowledge graph, the threat stage corresponding to the TTP behavior sequence is evaluated; the attacker's attack intent is judged by combining real-time threat intelligence; according to the threat stage and the judgment result, the type and network location of the digital component to be deployed are determined by the matrix scheduling algorithm; and the resource requirements of the digital component to be deployed are mapped to available computing and network resources by the resource mapping algorithm.
3. The method as described in claim 1, characterized in that, When calling the honeycomb array controller for dual-mode matching based on the digital component deployment diagram, the process includes: The honey array controller performs dual-mode matching based on TTP characteristics: for known CVE vulnerability characteristics, it accurately matches the pre-made CVE images in the honey database server; for unknown attack scenario characteristics, it performs fuzzy matching based on operating system characteristics, file extensions, or process paths to dynamically generate lightweight simulation components.
4. The method as described in claim 1, characterized in that, The multimodal digital components include service tripwires, traffic tripwires, domain controller tripwires, and cloud service tripwires; wherein, the service tripwire is a network service quickly built based on script tools; the traffic tripwire is used to simulate normal business traffic and generate business traffic containing simulated vulnerability features; the domain controller tripwire is a deployed Windows domain controller environment and contains simulated usernames generated based on a high-order Markov model; the cloud service tripwire is a cloud resource service that simulates preset vulnerabilities or misconfigurations.
5. The method as described in claim 1, characterized in that, When reconstructing the network topology based on the digital component deployment map and the multimodal digital components, the process includes: determining the node layout and connection relationships of the reconstructed network topology based on the digital component types and network location information in the digital component deployment map.
6. The method as described in claim 1, characterized in that, When deploying the multimodal digital components in the reconstructed network topology, the following are included: The resource optimizer is invoked to determine the resource configuration of each multimodal digital component based on the deployment diagram and the current host load, using a load balancing strategy. The dynamic converter is invoked to generate the corresponding container or virtual machine configuration file according to the resource configuration; the network deployment tool is used to instantiate the multimodal digital component according to the configuration file; the network control tool is used to connect the instantiated multimodal digital component to the corresponding network location according to the digital component deployment map, and ensure network connectivity. The network deployment tools include Docker, KVM, QEMU, and Podman; the network control tools include ODL, Ryu, POX, and ACI.
7. The method as described in claim 1, characterized in that, When attack traffic is transparently redirected to the reconstructed network topology by issuing flow table rules based on the match-action paradigm to the P4 programmable switch through the P4 runtime interface based on real-time threat intelligence, the process includes: issuing flow table rules based on the match-action paradigm to the P4 programmable switch through the P4 runtime interface based on real-time threat intelligence to update the match-action table of the data plane; when subsequent traffic from the attacker arrives, performing network address translation actions to rewrite the destination IP address and destination MAC address of the data packets, transparently redirecting the attack traffic to the reconstructed network topology during the line-speed forwarding phase, without interrupting the attacker's network connection status.
8. A dynamic decoy defense system based on software-defined deception defense, characterized in that, include: A topology building module is used to construct an initial network topology and deploy digital components within it. A P4 programmable switch is used to monitor these digital components. The P4 programmable switch extracts the five-tuple information and application layer load characteristics of data packets using a custom parser. Based on the stateful registers within the P4 programmable switch, the connection frequency and probe span of the access source IP address are recorded. When the load characteristics match a preset threat awareness flow table, or when the connection frequency and probe span exceed a preset security threshold, it is determined that the digital component has been attacked. Based on a Digest mechanism, the attack source IP address, target port, and malicious metadata are packaged into a telemetry log and exported in real time. The intelligent orchestration module is used to analyze the telemetry logs and extract TTP behavior sequences; based on the TTP behavior sequences, it generates a digital component deployment array through array scheduling and resource mapping algorithms; according to the digital component deployment array, it calls the honeycomb array controller to perform dual-mode matching and generate multimodal digital components. The component deployment module is used to reconstruct the network topology based on the digital component deployment array and the multimodal digital components, and to deploy the multimodal digital components in the reconstructed network topology; The update control module is used to issue flow table rules based on the match-action paradigm to the P4 programmable switch through the P4 runtime interface based on real-time threat intelligence, so as to transparently redirect attack traffic to the reconstructed network topology; The interaction between the multimodal digital components and the attacker is continuously monitored, and the deployment diagram and network topology of the digital components are iteratively updated based on the interaction results.
9. A storage medium, characterized in that, The storage medium stores one or more programs that, when executed by a processor, implement the dynamic decoy defense method based on software-defined deception defense as described in any one of claims 1-7.
10. An electronic device comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor executes the computer program stored in the memory, it implements the dynamic decoy defense method based on software-defined deception defense as described in any one of claims 1-7.
Citation Information
Patent Citations
Intelligent array graph generation method and system based on deception defense strategy
CN120110791A