一种面向工控设备基于蜜点的流量绊线生成方法及系统

By constructing a traffic tripwire generation model, identifying and generating decoy data, embedding it into industrial control protocol frames, and actively releasing decoy traffic, the passive defense and high cost problems of existing industrial control honeypot technologies are solved, achieving highly realistic adaptive defense and enhancing the active defense capabilities of industrial control systems.

CN121967096BActive Publication Date: 2026-07-17GUANGZHOU UNIVERSITY

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGZHOU UNIVERSITY
Filing Date
2026-04-03
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing industrial control honeypot technologies suffer from problems such as lagging passive defense, insufficient depth of simulation interaction, lack of adaptive capabilities in static strategies, and high deployment and maintenance costs, making it difficult to effectively deal with advanced persistent threats to industrial control systems.

Method used

A honeypot-based traffic tripwire generation method is adopted. By constructing a traffic tripwire load generation model, sensitive fields are identified and decoy data is generated and embedded into the industrial control protocol frame. The decoy traffic is actively released to simulate the behavior of real industrial control equipment, dynamically deceive attackers, and achieve adaptive defense.

Benefits of technology

It achieves proactive detection, dynamic deception, and adaptive defense against potential attacks, reducing deployment and maintenance costs, enhancing the adversarial nature and simulation depth of the defense system, and reducing the risk of attacker identification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967096B_ABST
    Figure CN121967096B_ABST
Patent Text Reader

Abstract

本发明提供了一种面向工控设备基于蜜点的流量绊线生成方法及系统,涉及网络安全技术领域。本发明提供的方法包括:基于配置文件和绊线策略生成指令;获取原始载荷序列,基于流量绊线载荷生成模型识别其中敏感字段,并将其替换为掩码标记,形成掩码载荷序列;预测掩码载荷序列中的掩码标记位置生成诱饵数据;将诱饵数据填充至掩码标记位置,与掩码载荷序列中的非敏感字段组合,生成伪装载荷数据;基于指令将伪装载荷数据嵌入至标准协议帧中,构建流量绊线数据包,并将蜜点的地址信息嵌入至流量绊线数据包;在生成时间到达时,根据发送间隔将流量绊线数据包主动对外发送。本发明通过主动发送模拟数据流量实现对潜在攻击的主动诱捕感知、动态欺骗。
Need to check novelty before this filing date? Find Prior Art