Attack traffic processing method, apparatus, device, medium and program product
Patent Information
- Application Number
- HK42026126516
- Authority / Receiving Office
- HK · HK
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-07-22
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2045-12-01
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
(19) State Intellectual Property Office (12) Invention Patent Application (10) Application Publication Number (43) Application Publication Date (21) Application Number 202511808714.X (22) Application Date 2025.12.02 (71) Applicant China UnionPay Co., Ltd. Address UnionPay Building, No. 36 Hanxiao Road, Pudong New Area, Shanghai 200135 (72) Inventors Song Chao, Zhou Jiajing, Liu Zhen, Zhou Ji'en (74) Patent Agency Beijing Tongli Juncheng Intellectual Property Agency Co., Ltd. 11205 Patent Attorney Lv Xianzi (51) Int.Cl. H04L 9 / 40 (2022.01) (54) Invention Title Attack Traffic Processing Method, Apparatus, Device, Medium and Program Product (57) Abstract This application provides an attack traffic processing method, apparatus, device, medium and program product. It relates to the field of network security technology. This method is applied to a cloud server, which includes multiple network domains, a traffic processing module, and a shared honeypot system. The method includes: acquiring attack traffic targeting a network domain; performing network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information; based on the virtual attack information, redirecting the attack traffic to the shared honeypot system for attack interaction to obtain interaction information; and returning the interaction information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information. This method, by uniformly diverting attack traffic from multiple network domains to the shared honeypot system, achieves cross-domain communication and resource reuse, thereby reducing tenant deployment costs and platform maintenance costs. Claims 3 pages, Description 17 pages, Drawings 2 pages, CN 121887440 A 2026.04.17 CN 1 21 88 74 40 A 1. An attack traffic processing method, characterized in that it is applied to a cloud server, the cloud server including multiple network domains, a traffic processing module and a shared honeypot system; attack traffic of each network domain is sent to the shared honeypot system for attack interaction through the traffic processing module; the method includes: acquiring attack traffic targeting the network domain; performing network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information; based on the virtual attack information, redirecting the attack traffic to the shared honeypot system for attack interaction to obtain interaction information of the attack traffic; according to the mapping relationship between the virtual attack information and the original attack information, returning the interaction information to the attack terminal corresponding to the network domain. 2. The method according to claim 1, characterized in that acquiring attack traffic targeting the network domain includes: monitoring the data flow accessing the network domain through a traffic monitoring unit deployed in the network domain;When the traffic monitoring unit detects a data flow that matches preset attack characteristics, it determines that it is attack traffic targeting the network domain; the attack traffic is forwarded to the traffic processing module through a traffic redirection unit in the network domain according to a preset traffic redirection strategy. 3. The method according to claim 2, wherein determining that the data flow that matches preset attack characteristics is attack traffic targeting the network domain by the traffic monitoring unit includes: when a data flow accessing a preset network port and / or not having a network address is detected, the data flow is collected; domain identification information representing the network domain is obtained, and the collected data flow is encapsulated based on the domain identification information to generate attack traffic targeting the network domain. 4. The method according to claim 3, wherein encapsulating the collected data flow based on the domain identification information to generate attack traffic targeting the network domain includes: obtaining a virtual LAN tag corresponding to the network domain as the domain identification information; based on the virtual LAN tag, the collected data flow is encapsulated using a preset encapsulation protocol, and the encapsulated data flow is used as attack traffic targeting the network domain. 5. The method according to claim 1, characterized in that, performing virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information includes: parsing the attack traffic to obtain the original attack information of the attack traffic; the original attack information includes original source network location information and original destination network location information, the network location information including network port and / or network address; performing virtual mapping processing on the original source network location information to obtain corresponding virtual source network location information; performing virtual mapping processing on the original destination network location information to obtain corresponding virtual destination network location information. 6. The method according to claim 5, characterized in that, performing virtual mapping processing on the original source network location information to obtain corresponding virtual source network location information includes: obtaining intermediate network location information of the traffic processing module; mapping the intermediate network location information to the virtual source network location information of the attack traffic. Claims 1 / 3 Page 2 CN 121887440 A 7. The method according to claim 5, characterized in that the shared honeypot system includes multiple sub-honeypot systems; virtual mapping processing is performed on the original destination network location information to obtain corresponding virtual destination network location information, including: determining the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the resource status of each sub-honeypot system; mapping the destination network location information of the target sub-honeypot system to the virtual destination network location information of the attack traffic. 8. The method according to claim 7, characterized in that, based on the original attack information and the resource status of each sub-honeypot system...The method according to claim 8, wherein matching candidate sub-honeypot systems with corresponding analytical capabilities to the attack traffic based on the original attack information, includes: obtaining the real-time resource status of each candidate sub-honeypot system; and selecting a target sub-honeypot system whose resource load meets preset conditions from the candidate sub-honeypot systems based on the real-time resource status. 9. The method according to claim 8, wherein matching candidate sub-honeypot systems with corresponding analytical capabilities to the attack traffic based on the original attack information, includes: identifying attack characteristics corresponding to the attack traffic based on the original attack information; and matching candidate sub-honeypot systems with corresponding analytical capabilities in the shared honeypot system based on the attack characteristics. 10. The method according to any one of claims 1-9, wherein returning the interaction information to the attack terminal corresponding to the network domain based on the original attack information and the virtual attack information, includes: determining the corresponding original attack information and domain identification information based on the virtual attack information corresponding to the interaction information; encapsulating the interaction information based on the domain identification information to generate encapsulated interaction data; and returning the encapsulated interaction data to the corresponding attacker terminal based on the original attack information. 11. The method according to any one of claims 1-9, characterized in that the method further comprises: obtaining attack analysis results generated by the shared honeypot system based on the attack interaction, the attack analysis results including alarm information; determining the network domain corresponding to the attack traffic according to the original attack information and the virtual attack information; and sending the alarm information to the user terminal corresponding to the network domain. 12. An attack traffic processing device, characterized in that it is applied to a cloud server, the cloud server including multiple network domains, a traffic processing module, and a shared honeypot system; attack traffic from each of the network domains is sent to the shared honeypot system for attack interaction through the traffic processing module; the device includes: an attack traffic acquisition module, used to acquire attack traffic targeting the network domain; a virtual mapping module, used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information; an interaction information acquisition module, used to redirect the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information, and obtain interaction information of the attack traffic; and an interaction information feedback module, used to return the interaction information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information. 13. A server, characterized in that it comprises: a processor and a memory communicatively connected to the processor; (Claims 2 / 3, page 3, CN 121887440 A) The memory stores computer-executable instructions;The processor, when executing the computer execution instructions, is used to implement the attack traffic processing method as described in any one of claims 1 to 11. 14. A computer-readable storage medium, characterized in that the computer-readable storage medium stores computer execution instructions, which, when executed by a processor, are used to implement the attack traffic processing method as described in any one of claims 1 to 11. 15. A computer program product, characterized in that it includes a computer program, which, when executed by a processor, implements the attack traffic processing method as described in any one of claims 1 to 11. Claims 3 / 3 Page 4 CN 121887440 A Attack Traffic Processing Method, Apparatus, Device, Medium and Program Product Technical Field
[0001] This application relates to the field of network security technology, and in particular to an attack traffic processing method, apparatus, device, medium and program product. Background Art
[0002] In a cloud computing multi-tenant environment, each tenant is usually deployed in a mutually isolated virtual network domain, facing increasingly complex internal network security threats. Honeypot systems, as an active defense means, can effectively identify potential threats that are difficult for traditional security devices to detect by deploying decoy resources to attract and analyze attack behavior.
[0003] The current mainstream solution is to deploy a dedicated honeypot system independently for each tenant, and to capture and analyze targeted attacks by configuring honeypot clusters and probes in their respective network domains.
[0004] However, when the cloud platform carries a large number of tenants, the independent deployment mode leads to repeated investment in hardware resources, a sharp increase in operation and maintenance costs, and low resource utilization. At the same time, the decentralized deployment architecture makes it difficult to effectively share attack intelligence, making it difficult to form a collaborative defense capability, and it is insufficient in the face of advanced persistent threats across tenants. Summary of the Invention
[0005] This application provides an attack traffic processing method, device, equipment, medium and program product to solve the technical problems of high cost of honeypot systems and difficulty of cross-domain communication in multi-tenant cloud environments. By unifying the attack traffic of multiple network domains to a shared honeypot system, cross-domain communication and resource reuse are realized, thereby reducing tenant deployment costs and platform maintenance costs.
[0006] In a first aspect, this application provides an attack traffic processing method applied to a cloud server, the cloud server including multiple network domains, a traffic processing module, and a shared honeypot system; attack traffic from each network domain is sent to the shared honeypot system through the traffic processing module for attack interaction;
[0007] The method includes:
[0008] acquiring attack traffic targeting the network domain;
[0009] performing network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information;
[0010] redirecting the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information.
[0011] According to the mapping relationship between the virtual attack information and the original attack information, the interaction information is returned to the attack terminal corresponding to the network domain.
[0012] In an optional embodiment, obtaining the attack traffic targeting the network domain includes:
[0013] Monitoring the data flow accessing the network domain through a traffic monitoring unit deployed in the network domain;
[0014] When the traffic monitoring unit detects a data flow that meets the preset attack characteristics, it determines that it is attack traffic targeting the network domain;
[0015] Forwarding the attack traffic to the flow processing module according to the preset flow redirection strategy through a traffic redirection unit in the network domain.
[0016] In an optional embodiment, when the traffic monitoring unit detects a data flow that conforms to preset attack characteristics, it determines that it is attack traffic targeting the network domain, including:
[0017] When a data flow accessing a preset network port and / or not having a network address is detected, the data flow is collected;
[0018] Domain identification information representing the network domain is obtained, and the collected data flow is encapsulated based on the domain identification information to generate attack traffic targeting the network domain.
[0019] In an optional embodiment, the encapsulation of the collected data flow based on the domain identification information to generate attack traffic targeting the network domain includes:
[0020] Obtaining a virtual local area network (VLAN) tag corresponding to the network domain as the domain identification information;
[0021] Based on the VLAN tag, the collected data flow is encapsulated using a preset encapsulation protocol, and the encapsulated data flow is used as attack traffic targeting the network domain.
[0022] In an optional embodiment, the original attack information in the attack traffic is subjected to virtual mapping processing to generate corresponding virtual attack information, including:
[0023] Parsing the attack traffic to obtain the original attack information of the attack traffic; the original attack information includes original source network location information and original destination network location information, wherein the network location information includes network port and / or network address;
[0024] Performing virtual mapping processing on the original source network location information to obtain corresponding virtual source network location information;
[0025] Performing virtual mapping processing on the original destination network location information to obtain corresponding virtual destination network location information.
[0026] In an optional embodiment, the original source network location information is subjected to virtual mapping processing to obtain corresponding virtual source network location information, including:
[0027] Obtaining the intermediate network location information of the traffic processing module;
[0028] Mapping the intermediate network location information to the virtual source network location information of the attack traffic.
[0029] In one optional embodiment, the shared honeypot system includes multiple sub-honeypot systems;
[0030] The original destination network location information is subjected to virtual mapping processing to obtain corresponding virtual destination network location information, including:
[0031] Determining the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the resource status of each sub-honeypot system;
[0032] Mapping the destination network location information of the target sub-honeypot system to the virtual destination network location information of the attack traffic.
[0033] In one optional embodiment, determining the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the system resource status of each sub-honeypot system includes:
[0034] Matching candidate sub-honeypot systems with corresponding analysis capabilities to the attack traffic based on the original attack information;
[0035] Obtaining the real-time resource status of each candidate sub-honeypot system;
[0036] Selecting a target sub-honeypot system whose resource load meets preset conditions from the candidate sub-honeypot systems based on the real-time resource status.
[0037] In an optional embodiment, matching the attack traffic with candidate sub-honeypot systems with corresponding analytical capabilities in the shared honeypot system based on the original attack information includes:
[0038] Identifying attack characteristics corresponding to the attack traffic based on the original attack information;
[0039] Matching candidate sub-honeypot systems with corresponding analytical capabilities in the shared honeypot system based on the attack characteristics.
[0040] In an optional embodiment, returning the interaction information to the attack terminal corresponding to the network domain based on the original attack information and the virtual attack information includes:
[0041] Determining the corresponding original attack information and domain identification information based on the virtual attack information corresponding to the interaction information;
[0042] Encapsulating the interaction information based on the domain identification information to generate encapsulated interaction data;
[0043] Returning the encapsulated interaction data to the corresponding attacker terminal based on the original attack information.
[0044] In an optional embodiment, the method further includes:
[0045] obtaining attack analysis results generated by the shared honeypot system based on the attack interaction, wherein the attack analysis results include alarm information;
[0046] determining the network domain corresponding to the attack traffic based on the original attack information and the virtual attack information;
[0047] sending the alarm information to the user terminal corresponding to the network domain.
[0048] In a second aspect, this application provides an attack traffic processing device applied to a cloud server, wherein the cloud server includes multiple network domains, a traffic processing module, and a shared honeypot system; the attack traffic of each network domain is processed by the traffic processing module.The processing module sends the attack traffic to the shared honeypot system for attack interaction;
[0049] The device includes:
[0050] an attack traffic acquisition module, used to acquire attack traffic targeting the network domain;
[0051] a virtual mapping module, used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information;
[0052] an interaction information acquisition module, used to redirect the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information to obtain the interaction information of the attack traffic;
[0053] an interaction information feedback module, used to return the interaction information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information.
[0054] In a third aspect, this application provides a server, including: a processor, and a memory communicatively connected to the processor;
[0055] the memory stores computer execution instructions;
[0056] the processor executes the computer execution instructions stored in the memory to implement the method as described in the first aspect.
[0057] In a fourth aspect, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect.
[0058] In a fifth aspect, this application provides a computer program product, including a computer program, which, when executed by a processor, implements the method described in the first aspect.
[0059] The attack traffic processing technology provided by this application generates corresponding virtual attack information by virtually mapping the original attack information in the attack traffic; redirects the traffic to a shared honeypot system for attack interaction based on the virtual attack information; returns the interaction information to the corresponding attacker according to the mapping relationship; realizes cross-domain reuse of honeypot resources, reduces the deployment cost of honeypots in a multi-tenant environment, and improves the efficiency of attack perception and analysis through centralized processing, thereby enhancing the system's collaborative defense capability against cross-network domain attacks. Brief Description of the Drawings
[0060] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0061] Figure 1 is an application scenario diagram of the attack traffic processing method provided in this application;
[0062] Figure 2 is a flowchart of an attack traffic processing method provided in an embodiment of this application;
[0063] Figure 3 is a flowchart of an attack traffic processing method provided in an embodiment of this application;
[0064] Figure 4 is a structural schematic diagram of an attack traffic processing device provided in this application;
[0065] Figure 5 is a block diagram of a server provided in this application.
[0066] The accompanying drawings have illustrated specific embodiments of this application, which will be described in more detail below. These drawings and textual descriptions are not intended to limit the scope of the concept of this application in any way, but rather to illustrate the concept of this application to those skilled in the art by referring to specific embodiments. Detailed Description
[0067] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0068] In the technical solutions of this application, the collection, storage, use, processing, transmission, provision, and disclosure of information such as financial data or user data all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0069] It should be noted that in the embodiments of this application, certain software, components, models, and other existing solutions in the industry may be mentioned. These should be considered as exemplary, and their purpose is only to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0070] In a cloud computing multi-tenant environment, each tenant is usually deployed in a virtual network domain that is isolated from each other, facing increasingly complex internal network security threats. As an active defense measure, honeypot systems can effectively identify potential threats that are difficult for traditional security devices to detect by deploying decoy resources to attract and analyze attack behavior.
[0071] The current solution is to deploy a dedicated honeypot system independently for each tenant. By configuring honeypot clusters and probes in their respective network domains, targeted attacks can be captured and analyzed.
[0072] For example, the current solution uses black hole routing technology to divert network domain attack traffic to the tenant's dedicated honeypot cluster via VPC probes. However, when the cloud platform carries a large number of tenants, the independent deployment mode leads to repeated investment in hardware resources, a sharp increase in operation and maintenance costs, and low resource utilization. Meanwhile, the decentralized deployment architecture makes it difficult to effectively share attack intelligence, hindering the formation of collaborative defense capabilities and making it inadequate in the face of advanced persistent threats across tenants.
[0073] The attack traffic processing method provided in this application aims to solve the above-mentioned technical problems of the prior art. Specifically, by virtually mapping the original attack information in the attack traffic, corresponding virtual attack information is generated; based on the virtual attack information, the traffic is redirected to the shared honeypot system for attack interaction; according to the mapping relationship, the interaction information is returned to the corresponding attacker; cross-domain reuse of honeypot resources is realized, reducing the deployment cost of honeypots in a multi-tenant environment, while centralized processing improves the efficiency of attack perception and analysis, and enhances the system's collaborative defense capability against cross-network domain attacks.
[0074] The attack traffic processing method provided in this application is applicable to network security protection scenarios in multi-tenant cloud environments. For example, in cloud platform security protection scenarios in industries such as finance, government affairs, and e-commerce, different tenants are deployed in mutually isolated virtual private clouds. This solution can achieve unified detection and analysis of attack traffic while ensuring the isolation requirements of each tenant's network.
[0075] Furthermore, the above method can also be applied to the collaborative network security protection of multiple branches of an enterprise group. The network traffic of each branch can be centrally diverted to the group-level security analysis platform through this solution to achieve threat intelligence sharing and joint protection.
[0076] In summary, any application scenario that requires centralized detection and resource sharing of cross-network domain attack traffic while maintaining network isolation requirements falls under the application scenario of the attack traffic processing technology solution in this application.
[0077] For ease of understanding, the application scenarios applicable to the embodiments of this application will be described below with reference to Figure 1. Figure 1 is an application scenario diagram of the attack traffic processing method provided in this application. Referring to Figure 1, taking a multi-tenant cloud platform security protection scenario as an example, this scenario mainly involves attacker terminals and cloud servers; among which, the cloud server includes multiple network domains, traffic processing modules, and a shared honeypot system; specifically, the attack traffic of each network domain is sent to the shared honeypot system for attack interaction through the traffic processing module.
[0078] Based on this, the attack traffic processing method in this scenario includes the following steps:
[0079] 1. The attacker terminal initiates attack traffic to the target network domain;
[0080] 2. The traffic monitoring unit in the network domain identifies the attack traffic and forwards it to the traffic processing module;
[0081] 3. The traffic processing module performs protocol parsing and virtual mapping processing on the attack traffic to generate virtual attack information;
[0082] 4. Based on the virtual attack information, the attack traffic is redirected to the shared honeypot system;
[0083] 5. The shared honeypot system interacts and analyzes the attack traffic to generate interaction information;
[0084] 6. The traffic processing module returns the interaction information to the corresponding attacker terminal according to the mapping relationship.
[0085] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0086] Figure 2 is a schematic flowchart of an attack traffic processing method provided by an embodiment of this application. The method can be executed by an attack traffic processing device, which may be deployed with a cloud server. The cloud server includes multiple network domains, a traffic processing module and a shared honeypot system; the attack traffic of each network domain is sent to the shared honeypot system through the traffic processing module.The honeypot system performs attack interaction. The attack traffic processing device can be a server or an electronic device. The following description uses a server as an example. The method in this embodiment can be implemented by software, hardware or a combination of software and hardware, as shown in Figure 2. The method includes the following steps:
[0087] S201, Obtain attack traffic targeting the network domain.
[0088] The cloud server has multiple isolated network domains, each network domain corresponding to an independent operating environment of a tenant. Each network domain is equipped with a dedicated traffic monitoring unit, which is used to continuously monitor and analyze the internal traffic of the network domain. When attack traffic is detected, it is forwarded to the preset traffic processing module in the cloud server, which forwards it to the shared honeypot system shared by each network domain. Then, in the honeypot system, the attack traffic will be interactively processed to obtain the corresponding interactive information, thereby effectively misleading the attacker, delaying or blocking its attack process, and enhancing the overall network security protection capability.
[0089] In this embodiment, the traffic monitoring unit can be deployed in the following ways: First, install a lightweight traffic collection tool on the key servers and terminal devices in the network domain; second, deploy the traffic collection tool at the key collection port of the network domain. It should be understood that the above methods can be used individually or in combination to achieve flexible and efficient attack traffic acquisition and analysis. Specification 5 / 17 page 9 CN 121887440 A
[0090] Specifically, when an attacker scans and probes the current network domain, this unit can filter the data streams within the network domain using preset attack traffic identification rules, thereby extracting data streams that match the attack characteristics. Further, based on information such as the domain identifier of the current network domain, the identified data streams are encapsulated to generate attack traffic targeting the network domain, and the generated attack traffic is sent to the traffic processing module.
[0091] S202, The original attack information in the attack traffic undergoes network virtual mapping processing to generate corresponding virtual attack information.
[0092] In this embodiment, the virtual mapping process can be understood as: mapping the attacker's network location information and the network location information of the current network domain they intend to access, contained in the attack traffic, to the network location information of the traffic processing module and the shared honeypot system. This allows the traffic processing module to redirect the attack traffic to the shared honeypot, thereby establishing traffic interaction between the attacker and the honeypot, misleading the attacker, and enhancing the security protection of the network domain.
[0093] Specifically, when the traffic processing module receives the encapsulated attack traffic, it parses the attack traffic to obtain the original attack information. The original attack information includes, but is not limited to, one or more of the following fields: source IP address, destination IP address, source port, destination port, protocol type, attack type tag, traffic occurrence timestamp, and packet payload digest.
[0094] To accurately forward attack traffic to the shared honeypot system for interactive analysis, virtual mapping is performed on the network location information in the original attack information. This network location information includes one or more of the following: source address, destination address, source port, and destination port. The virtual mapping process maps the address and / or port to the virtual network location corresponding to the traffic processing module and the shared honeypot system, thereby guiding the attack traffic to the honeypot environment for further analysis without exposing the real network domain information.
[0095] S203. Based on the virtual attack information, the attack traffic is redirected to the shared honeypot system for attack interaction to obtain the interaction information of the attack traffic.
[0096] In this embodiment, the traffic processing module redirects and forwards the parsed and restored attack traffic based on the virtual attack information generated in the aforementioned steps. Specifically, the module, based on the virtual network location obtained after virtual mapping, guides the attack traffic from the original current network domain to the shared honeypot system by modifying the packet header or configuring routing.
[0097] After the attack traffic enters the shared honeypot system, the shared honeypot system simulates real network services to interact with the attacker, and fully records all interactive behaviors, including the handshake process, command transmission, file upload, and vulnerability exploitation attempts, thereby generating detailed interactive information. This interactive information is not only used to immediately confuse and delay the attacker, but also provides a data foundation for subsequent attack analysis and security strategy optimization.
[0098] S204. Based on the mapping relationship between the virtual attack information and the original attack information, the interactive information is returned to the attack terminal corresponding to the network domain.
[0099] In this embodiment, the shared honeypot system sends the generated interactive information to the traffic processing module based on the virtual attack information. The traffic processing module performs reverse forwarding processing on the interactive information from the shared honeypot system based on the established mapping relationship between the virtual attack information and the original attack information.
[0100] Specifically, the traffic processing module, based on the above mapping relationship, restores the source network location information and destination network location information in the interactive information from the virtual address of the shared honeypot system to the real address in the original attack traffic.
[0101] Subsequently, the module encapsulates the processed interactive information into a seemingly normal response data packet from the current network domain and returns it to the corresponding attacker along its original path. This allows the attacker to continuously receive seemingly real interactive feedback, thereby maintaining the continuity of the deceptive session and enhancing the overall honeypot system's ability to confuse and restrain attack behavior.
[0102] In the above technical solution, by uniformly forwarding attack traffic detected in multiple network domains to the shared honeypot specification page 6 / 17 10 CN 121887440 A system for interaction, and using a network virtual mapping mechanism to convert and restore the original information in the attack traffic, thereby...While isolating attacks, continuous deception and attack analysis of attackers are achieved, realizing cross-domain reuse of honeypot resources, reducing the deployment cost of honeypots in multi-tenant environments, and improving the efficiency of attack perception and analysis through centralized processing, thereby enhancing the system's collaborative defense capability against cross-network domain attacks.
[0103] Based on the above implementation method, the detailed process of attack traffic processing will be further described in detail below. It should be noted that the following description is only an exemplary implementation of the attack traffic processing scheme and does not constitute a limitation on the technical solution of this application.
[0104] In this embodiment, taking the network domain corresponding to any tenant as an example, an optional implementation method for obtaining attack traffic targeting the current network domain may include: monitoring the data flow accessing the network domain through a traffic monitoring unit deployed in the network domain; when the traffic monitoring unit detects a data flow that meets the preset attack characteristics, it determines that it is attack traffic targeting the network domain; and forwarding the attack traffic to the traffic processing module through a traffic diversion unit in the network domain according to a preset traffic diversion strategy.
[0105] In this embodiment, at least one cloud server or offline host is deployed in the current network domain, and each server or host is used to process the data flow corresponding to different services. To effectively identify attack traffic, traffic monitoring units, such as traffic probes implemented in the form of lightweight agents, can be pre-deployed on each server or host to comprehensively and continuously monitor all data flows entering the current network domain.
[0106] Specifically, in this embodiment, the traffic monitoring unit pre-stores judgment conditions for identifying attack characteristics; then, based on the judgment conditions, the unit performs real-time analysis on the data flows accessing the current network domain, and when the data flow meets any judgment condition, it is identified as attack traffic targeting the current network domain.
[0107] Based on the above, based on the traffic redirection unit pre-deployed in the current network domain, according to the preset traffic redirection strategy. For example, a black hole routing mechanism can be used to automatically redirect the identified attack traffic to the traffic processing module deployed in the same cloud server, thereby realizing the redirection and forwarding of attack traffic.
[0108] Specifically, after identifying the attack traffic, the traffic redirection unit configures black hole routing rules pointing to the traffic processing module to redirect all identified attack traffic data packets to the traffic processing module. After receiving the attack traffic, the module performs protocol parsing and information extraction, and then forwards it to the shared honeypot system to perform subsequent attack interactions and behavior analysis.
[0109] In the above manner, the identification and diversion of attack traffic targeting the network domain can be realized, improving the real-time performance and accuracy of threat detection. At the same time, cross-domain communication and resource reuse are achieved through centralized processing of attack traffic, reducing deployment costs.
[0110] In the above embodiment, the traffic monitoring unit monitors data streams that meet the attack characteristics.The method may include: when a data flow is detected accessing a preset network port and / or a non-existent network address, the data flow is collected.
[0111] In this embodiment, in order to optimize resource utilization, preset key network ports in the current network domain can be monitored, including but not limited to port 22 corresponding to the SSH service, port 3306 corresponding to the MySQL database service, and ports 80 and 443 commonly used by Web applications. When external traffic is detected attempting to access the above ports, it is determined that the data flow meets the preset attack characteristics, and the data flow is collected.
[0112] In addition, the traffic monitoring unit provided in this embodiment also has the ability to monitor network address access behavior. When a data flow is detected attempting to access a network address that does not exist in the current network domain or has been marked as invalid, it is also determined that the data flow meets the attack characteristics, and the data flow is collected.
[0113] By combining the above port monitoring and address monitoring, this embodiment can improve the identification coverage and detection accuracy of malicious traffic such as scanning probes and targeted attacks, thereby improving the attack perception rate, while taking into account the system resource consumption specification 7 / 17 page 11 CN 121887440 A.
[0114] Based on the above, in order to ensure that the shared honeypot system can accurately establish the association between attack behavior and the corresponding tenant network domain, thereby effectively improving the accuracy of security alarms, this embodiment, before forwarding the data stream that meets the attack characteristics as attack traffic to the traffic processing module, also encapsulates the data stream based on the domain identification information of the current network domain to generate attack traffic with a clear domain identifier.
[0115] Specifically, the encapsulation processing of the identified data stream by the traffic monitoring unit includes, but is not limited to, embedding information for uniquely identifying the network domain in specific fields of the data packet. This information may include at least one of the tenant ID, network domain number, or virtual private cloud identifier. In this way, even when processing mixed attack traffic from multiple network domains in a shared honeypot environment, the system can still accurately trace and restore the original network domain to which each attack traffic belongs, thereby providing a reliable basis for subsequent accurate alarms and tenant security analysis.
[0116] In the above embodiments, an optional implementation method for encapsulating the collected data stream based on domain identification information to generate attack traffic targeting the network domain may include: obtaining a virtual local area network (VLAN) tag corresponding to the network domain as domain identification information; performing protocol encapsulation processing on the collected data stream based on the VLAN tag using a preset encapsulation protocol, and using the encapsulated data stream tag as attack traffic targeting the network domain.
[0117] Specifically, obtaining the virtual local area network (VLAN) tag corresponding to the current network domain and determining it as the domain identification information of the current local area network; and performing protocol encapsulation processing on the collected data stream based on the VLAN tag using a preset encapsulation protocol.
[0118] For example, the data stream can be marked and encapsulated at the data link layer by adding a VLAN tag header; or, an overlay network encapsulation protocol such as VLAN or GRE can be used to embed the VLAN identification information as an extended field into the data stream header at the network layer or transport layer to achieve encapsulation, and the encapsulated data stream is marked as attack traffic targeting the network domain.
[0119] In the above embodiments, the encapsulated data stream retains the original attack characteristics while carrying a clear network domain affiliation identifier, enabling the subsequent traffic processing module to accurately distinguish attack traffic from different tenants (network domains) based on the encapsulation information, thereby achieving accurate source tracing and security isolation of attack behavior.
[0120] When the traffic processing module receives attack traffic sent from the network domain, it parses it to obtain the original attack information, and performs virtual mapping on the network location information in the original attack information to establish traffic interaction between the attacker and the honeypot.
[0121] Based on this, an optional implementation of virtual mapping of the original attack information in this embodiment may include: parsing the attack traffic to obtain the original attack information of the attack traffic; the original attack information includes original source network location information and original destination network location information, wherein the network location information includes network port and / or network address; performing virtual mapping processing on the original source network location information to obtain the corresponding virtual source network location information; performing virtual mapping processing on the original destination network location information to obtain the corresponding virtual destination network location information.
[0122] Specifically, the traffic processing module parses the received attack traffic and extracts the original attack information contained therein. The original attack information mainly includes original source network location information and original destination network location information. Optionally, network location information can be understood as a location identifier used to uniquely identify a communication endpoint or service in the network, for example, it includes network port and / or network address.
[0123] For example, the parsed original source network location information may include the attacker's real IP address (e.g., 192.168.1.100) and / or source port (e.g., 54321); the original destination network location information may include the target's non-existent (bait) IP address (e.g., 10.0.0.250) and / or destination port (e.g., 80).
[0124] Further, the above-mentioned original source network location information is subjected to virtual mapping processing. Specifically, according to the preset mapping relationship table in the module, a temporary virtual source IP address (e.g., 172.16.0.10) and / or the corresponding virtual source port (e.g., 40001) can be assigned to the attack traffic. This not only hides the attacker's real identity and original port information, making it impossible for the backend honeypot system to directly obtain its real network location, but also provides a routing basis for the correct return of subsequent honeypot response traffic.
[0125] In addition, the original destination network location information is virtually mapped. For example, according to a preset strategy, the attack traffic originally directed to the non-existent (bait) IP address 10.0.0.250 and / or destination port 80 can be redirected to one or more real honeypot system IP addresses (such as 192.168.100.5) and / or service ports (such as 8080).
[0126] In this way, through the bidirectional mapping and conversion of source and destination network location information (including IP address and / or port), the attacker's traffic is seamlessly guided to the honeypot without the attacker's knowledge. This establishes an attack interaction channel between the attacker and the honeypot, enabling the attack traffic to be guided to the honeypot environment without exposing the real network domain information.
[0127] In the above implementation process, an optional implementation method for virtually mapping the original source network location information may include: obtaining the intermediate network location information of the traffic processing module; and mapping the intermediate network location information to the virtual source network location information of the attack traffic.
[0128] Specifically, when the traffic processing module obtains the original source network location information contained in the original attack information, it obtains its own intermediate network location information. Here, the intermediate network location information can be understood as the network interface IP address (e.g., 172.16.0.1) and / or port number (e.g., 65432) used by the traffic processing module to communicate with the backend shared honeypot system.
[0129] The obtained intermediate network location information is directly mapped to the virtual source network location information of the attack traffic. In this way, before forwarding the attack traffic to the honeypot system, the traffic processing module will modify the header information of the data stream, replacing the source IP address and / or source port number from the attacker's real information (192.168.1.100 and / or 54321) with the traffic processing module's own intermediate network location information (172.16.0.1 and / or 65432).
[0130] Through the above implementation method, when the honeypot system receives attack traffic, it will assume that the traffic comes from the traffic processing module (172.16.0.1), thereby hiding the attacker's true identity. At the same time, the traffic processing module will record the mapping relationship between the attacker's real IP and / or port and the intermediate IP and / or port. When the honeypot system generates interaction information, that is, response traffic, the module can use this record to convert the destination address of the response traffic from the intermediate IP (172.16.0.1) back to the attacker's real IP (192.168.1.100), ensuring that the traffic can be correctly transmitted back, thereby establishing an interaction channel between the attacker and the honeypot.
[0131] In this embodiment, the shared honeypot system consists of multiple sub-honeypot systems. Considering that all network domain attack traffic needs to share the same honeypot resources, this solution divides the honeypot system into multiple sub-honeypot systems with differentiated characteristics through preset configuration.Sub-honeypot systems. Each sub-honeypot system is specifically deployed according to different network domain attributes and / or attack type characteristics. When attack traffic from a specific network domain is detected, the system can accurately guide it to the corresponding target sub-honeypot system for attack interaction based on a preset forwarding strategy.
[0132] Through the above-mentioned hierarchical deployment method, the intensive use of honeypot resources is realized, and the differentiated processing capability for attack traffic from different sources and of different types is ensured, effectively improving the authenticity of attack interaction and the accuracy of security analysis.
[0133] Based on this, an optional implementation method for virtually mapping the original destination network location information may include: determining the target sub-honeypot system corresponding to the attack traffic according to the original attack information and the resource status of each sub-honeypot system; mapping the destination network location information of the target sub-honeypot system to the virtual destination network location information of the attack traffic.
[0134] In this application, the original attack information includes the network attributes and attack type of the corresponding network domain, such as which tenant's network domain the attack traffic comes from, whether the business type of the network domain is finance, energy, or government affairs, and SQL injection, DDoS attack, or ransomware identified by signature codes.
[0135] Furthermore, the traffic processing module also has a preset forwarding policy rule base, which predefines which source or type of attack traffic should be forwarded to which sub-honeypot system. For example, the policy may stipulate that "attack traffic from the financial industry network domain should be forwarded to sub-honeypot A, which has deployed a financial transaction simulation environment", or "detected ransomware traffic should be forwarded to sub-honeypot B, which is specifically used for dynamic analysis of malicious code". At the same time, the traffic processing module will also query the current resource status of each sub-honeypot system, such as CPU utilization, memory usage, and the number of attack sessions currently being carried, to avoid directing new attack traffic to overloaded sub-honeypots and ensure the smoothness of attack interaction and the effectiveness of analysis.
[0136] Based on this, the traffic processing module will match the attack characteristics identified in the original information in the aforementioned forwarding policy rule base to determine the corresponding target sub-honeypot system. Furthermore, the traffic processing module will map the real destination network location information of the target sub-honeypot system (i.e., the real IP address and / or monitoring port of the sub-honeypot system, such as 192.168.100.10 and / or 8080) to the virtual destination network location information of the attack traffic. In this way, the traffic processing module will modify the destination IP address and destination port of the attack traffic data packets, replacing them with non-existent (bait) IP addresses and / or ports (such as 10.0.0.250 and / or 80) with the real IP address and port (192.168.100.10 and / or 8080) of the selected target sub-honeypot system.
[0137] Through the above implementation method, attack traffic originally sent to non-existent addresses is redirected to target sub-honeypot systems with corresponding analysis capabilities. This not only realizes the sharing and efficient utilization of honeypot resources, but also ensures that different types of attacks can be captured and analyzed in the most suitable simulation environment, thereby improving the realism of attack interactions, deception effects, and the analysis effect of subsequent security analysis.
[0138] In the above implementation method, an optional implementation method for determining the corresponding target sub-honeypot system based on the original attack information may include: matching candidate sub-honeypot systems with corresponding analysis capabilities for attack traffic based on the original attack information; obtaining the real-time resource status of each candidate sub-honeypot system; and selecting a target sub-honeypot system whose resource load meets preset conditions from the candidate sub-honeypot systems based on the real-time resource status.
[0139] Specifically, the traffic processing module compares the attack characteristics of the attack traffic of the current network domain, i.e., the network attributes and attack types of the network domain, with the information stored in the rule base, and filters out at least one sub-honeypot system that meets the conditions and can analyze the attack of this type, thus obtaining candidate sub-honeypot systems.
[0140] Optionally, if there is only one candidate sub-honeypot system, then the candidate sub-honeypot system is directly identified as the target sub-honeypot system; otherwise, if there are multiple candidate sub-honeypot systems of the same type, then the real-time resource status of each candidate sub-honeypot system is obtained. In this embodiment, the resource status information includes, but is not limited to: CPU utilization, memory usage, number of attack sessions currently being processed, disk I / O load, and network interface traffic. This data representing resource status information can be collected in real time by the monitoring agent deployed on each sub-honeypot system and reported to the traffic processing module.
[0141] Further, the traffic processing module selects the best candidate sub-honeypot system based on the obtained actual resource status. Optionally, this can be determined by judging whether the resource load meets preset conditions. The preset conditions may include preset thresholds. For example, "CPU utilization is less than 70%", "memory usage is less than 80%" and "the number of current sessions is less than 60% of the system's maximum concurrent processing capacity", etc.
[0142] The traffic processing module evaluates the status of each candidate sub-honeypot and determines whether it meets the preset threshold. When multiple sub-honeypots meet the conditions, the system can further employ load balancing strategies such as round-robin or weighted round-robin for selection. Specifically, in weighted round-robin mode, weights can be dynamically allocated based on the actual processing capabilities of each candidate sub-honeypot. Candidate sub-honeypots with stronger processing capabilities will be assigned higher weight values and will be prioritized as the target sub-honeypot system; conversely, if a candidate sub-honeypot has relatively weak processing capabilities, it will be assigned a lower weight value, correspondingly reducing its probability of being selected.
[0143] Through the above implementation methods, it is ensured that the target sub-honeypot has the basic ability to handle attack traffic, and the system resources are optimized and utilized, effectively improving the overall processing efficiency and stability of the honeypot cluster.
[0144] In the above implementation methods, an optional implementation method for determining candidate sub-honeypot systems may include: identifying the attack characteristics corresponding to the attack traffic based on the original attack information; and matching candidate sub-honeypot systems with corresponding analytical capabilities in the shared honeypot system based on the attack characteristics.
[0145] In this embodiment, the attack characteristics include the network attributes of the network domain and the attack type mentioned in the foregoing implementation methods. After obtaining the original attack information, information extraction is performed on the original attack information to determine the network attributes of the network domain corresponding to the attack traffic. At the same time, a pre-integrated lightweight machine learning model, such as a long short-term memory network model or a decision tree model, can be called to perform feature analysis on the original attack information to identify the attack type corresponding to the attack traffic.
[0146] Based on this, the analytical capabilities of each sub-honeypot system in the shared honeypot system are matched using the identified network attributes and attack types to determine the candidate sub-honeypot systems.
[0147] It should be understood that each sub-honeypot system in the shared honeypot system provided in this embodiment is preset with an "analysis capability tag", which is associated with its simulated vulnerability environment, service type, analysis tools, etc.
[0148] For example, a sub-honeypot may be configured to simulate a web server environment and has built-in SQL injection and XSS vulnerability detection and analysis tools, so it will be tagged with "Web service", "SQL injection analysis", "XSS analysis", etc.; another sub-honeypot may be specifically used to analyze DDoS attacks, so its tag is "DDoS traffic analysis"; then, based on the above content, a mapping relationship between attack features and the analysis capabilities of each sub-honeypot system is constructed.
[0149] After identifying the attack features, based on the attack features matching the above mapping relationship, all sub-honeypot systems whose analysis capability tags match the current attack features are found. For example, if the identified attack feature is "SQL injection", the system will filter out all sub-honeypots with the "SQL injection analysis" tag and use them as candidate sub-honeypot systems to handle the attack traffic.
[0150] Through the above method, it is ensured that only sub-honeypot systems with corresponding analytical capabilities will be selected, improving the processing effect of subsequent attack interactions and analysis.
[0151] In this embodiment, after the target sub-honeypot system in the shared honeypot system analyzes the attack traffic and generates interaction information, it can feed back the generated interaction information to the traffic processing unit based on its corresponding virtual attack information. The traffic processing unit determines the network location information of the attacker's terminal based on the mapping relationship between its corresponding original attack information and virtual attack information, and feeds back the interaction information to its attacker's terminal.
[0152] Based on the above implementation, an optional implementation method for returning interactive information to the attack terminal corresponding to the network domain according to the original attack information and the virtual attack information may include: determining the corresponding original attack information and domain identification information according to the virtual attack information corresponding to the interactive information; encapsulating the interactive information based on the domain identification information to generate encapsulated interactive data; and returning the encapsulated interactive data to the corresponding attacker terminal according to the original attack information.
[0153] Specifically, after the target sub-honeypot system in the shared honeypot system interacts with the attack traffic, a series of interactive information will be generated, such as the honeypot's response data packets, log records, etc. In order to correctly return the above interactive information, the traffic processing module should first perform reverse mapping processing, that is, according to the virtual attack information corresponding to the interactive information, for example, the network interface IP address (such as 172.16.0.1) and / or port number (such as 65432) used by the traffic processing module to communicate with the backend shared honeypot system, query the mapping relationship to obtain the original attack information corresponding to the virtual attack information, such as the attacker's real manual 11 / 17 page 15 CN 121887440 A information (192.168.1.100 and / or 54321), and the domain identification information of the network domain to which the attack traffic belongs.
[0154] Then, based on the queried domain identification information, the above interactive information is encapsulated to obtain encapsulated interactive data. For example, the encapsulation processing can refer to the aforementioned encapsulation processing of attack traffic, that is, specific tags or header information can be added at the data link layer or network layer, such as adding the network domain ID to the VLAN tag, or embedding the identifier in the option field of the IP packet.
[0155] In this way, in subsequent network transmission, especially in a multi-tenant shared network environment, it is possible to clearly identify which network domain the interactive data belongs to, so that network devices or subsequent processing modules can correctly route and forward the data, avoiding information confusion between different tenants.
[0156] Further, based on the original source network location information in the previously determined original attack information, the encapsulated interactive data is sent back to the corresponding attacker terminal through the network protocol. Optionally, during the sending process, the traffic processing module further ensures that the destination IP address and / or port number of the data packet is correctly set to the attacker's real information, so that the attacker can receive the response from the "network domain".
[0157] Through the above implementation method, the information return of interactive information from honeypot interactive information to the attacker terminal is successfully completed, while strictly ensuring the isolation between different network domains and the correct routing of data.
[0158] Based on the above implementation method, the shared honeypot system generates attack analysis results, i.e., alarm information, at the same time as generating interactive information. To improve the network security of tenants, the shared honeypot system also returns the alarm information to the traffic processing module.The traffic processing module further forwards the received alarm information to the user terminal in the corresponding network domain.
[0159] Optionally, the traffic processing module may feed back the received alarm information to the corresponding user terminal in the following ways: obtaining the attack analysis results generated by the shared honeypot system based on the attack interaction, the attack analysis results including alarm information; determining the network domain corresponding to the attack traffic based on the original attack information and the virtual attack information; and sending the alarm information to the user terminal corresponding to the network domain.
[0160] Specifically, while the target sub-honeypot system of the shared honeypot system interacts with the attack traffic and generates interaction information (such as response data packets), its built-in analysis engine will also perform in-depth analysis of the attack behavior and generate attack analysis results. The results include alarm information of the attack interaction. For example, accurate determination of the attack type, determination of whether the attack was successful or not based on the vulnerability number used in the attack, and threat level assessment of the attack behavior. The shared honeypot system will return the above alarm information together with the interaction information to the traffic processing module.
[0161] When the traffic processing module receives alarm information and interactive information, it obtains the original attack information corresponding to the virtual attack information of the attack traffic and the domain identifier information of the network domain to which the attack traffic belongs, based on the mapping relationship between virtual attack information and original attack information.
[0162] On this basis, the module can query the contact information of the administrator corresponding to the network domain, such as mobile phone number, email address or dedicated alarm receiving server IP, according to the preset information table and the domain identifier information of the corresponding network domain. Then the module can call the preset notification interface, such as SMTP email service, SMS SMS gateway or API interface, to send the extracted alarm information to the corresponding user terminal.
[0163] Through the above implementation method, the administrator of the relevant network domain can be informed of the threat in time, so as to take timely response and disposal measures and improve the overall platform security protection efficiency.
[0164] On the basis of the above implementation method, the present application embodiment also provides an exemplary implementation method of attack traffic processing method. Figure 3 is a flowchart of an attack traffic processing method provided by the present application embodiment. Referring to Figure 3, the specific implementation steps are as follows:
[0165] 1) The traffic probe diverts the attack traffic to the traffic processing and forwarding module (i.e., the traffic processing module described in the formula CN 121887440 A on pages 12 / 17 of the above-mentioned implementation specification) through the black hole routing.
[0166] Specifically, the traffic probe monitors all traffic in the current network domain that accesses IPs that do not exist. The traffic probe encapsulates these traffic, adds the network domain ID to the encapsulation, and then sends the encapsulated traffic to the traffic processing and forwarding module through the black hole routing.
[0167] 2) The traffic processing and forwarding module constructs tuple information.
[0168] Specifically, the traffic processing and forwarding module receives encapsulated traffic from the traffic probe, decapsulates this traffic, extracts information such as network domain ID, source IP, source port, destination IP, destination port, and timestamp, and constructs tuple information.
[0169] 3) The traffic processing and forwarding module modifies the original traffic and sends the traffic to the existing honeypot system.
[0170] Specifically, the traffic processing and forwarding module modifies the original traffic, changing the destination IP of the original traffic to the real IP of the existing honeypot, and changing the source IP of the original traffic to the IP of the traffic processing and forwarding module, and then sends the modified traffic to the honeypot system.
[0171] 4) The traffic processing and forwarding module receives traffic from the existing honeypot system, matches the network domain according to the tuple information, processes the traffic, and sends it to the host of the corresponding network domain.
[0172] Specifically, the traffic processing and forwarding module receives traffic returned from the existing honeypot system, matches the content in the tuple, finds the network domain ID and the real source IP of the connection, modifies the traffic, and changes the destination IP to the real source IP. Then the modified traffic is re-encapsulated and sent to the host of the specific network domain according to the network domain ID.
[0173] 5) The alarm aggregation module receives the logs of the existing honeypot, combines them with the tuple information to form real alarm logs and sends them to the tenant.
[0174] Specifically, the alarm aggregation module receives the alarm information of the existing honeypot system, forms real alarm information according to the tuple information of the traffic processing and forwarding module, and sends it to the tenant of the corresponding network domain.
[0175] Figure 4 is a schematic diagram of the structure of an attack traffic processing device provided in this application. Referring to Figure 4, the attack traffic processing device 40 is equipped with a cloud server, which includes multiple network domains, a traffic processing module, and a shared honeypot system. Attack traffic from each network domain is sent to the shared honeypot system for attack interaction through the traffic processing module.
[0176] The attack traffic processing device 40 includes:
[0177] an attack traffic acquisition module 401, used to acquire attack traffic targeting a network domain;
[0178] a virtual mapping module 402, used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information;
[0179] an interaction information acquisition module 403, used to redirect the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information to obtain the interaction information of the attack traffic;
[0180] an interaction information feedback module 404, used to return the interaction information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information.
[0181] In one optional embodiment, the attack traffic acquisition module 401 includes:
[0182] a data flow monitoring submodule, used to monitor data flows accessing the network domain through a traffic monitoring unit deployed in the network domain;
[0183] The attack traffic determination submodule is used to determine that the data flow that meets the preset attack characteristics is attack traffic targeting the network domain when the traffic monitoring unit detects it;
[0184] The attack traffic sending submodule is used to forward the attack traffic to the traffic processing module through the traffic diversion unit in the network domain according to the preset traffic diversion strategy. Specification 13 / 17 pages 17 CN 121887440 A
[0185] In an optional embodiment, the attack traffic determination submodule includes:
[0186] A data flow acquisition unit, used to acquire the data flow when a data flow accessing a preset network port and / or a network address that does not exist is detected;
[0187] An attack traffic determination unit, used to obtain domain identification information representing the network domain, and encapsulate the acquired data flow based on the domain identification information to generate attack traffic targeting the network domain.
[0188] In an optional embodiment, the attack traffic determination unit includes:
[0189] a domain identification information acquisition subunit, used to acquire a virtual local area network (VLAN) tag corresponding to a network domain as domain identification information;
[0190] an attack traffic determination subunit, used to perform protocol encapsulation processing on the collected data stream based on the VLAN tag using a preset encapsulation protocol, and use the encapsulated data stream tag as attack traffic targeting the network domain.
[0191] In an optional embodiment, the virtual mapping module 402 includes:
[0192] an original attack information acquisition submodule, used to parse the attack traffic and acquire the original attack information of the attack traffic; the original attack information includes original source network location information and original destination network location information, wherein the network location information includes network port and / or network address;
[0193] a first virtual mapping submodule, used to perform virtual mapping processing on the original source network location information to obtain the corresponding virtual source network location information;
[0194] a second virtual mapping submodule, used to perform virtual mapping processing on the original destination network location information to obtain the corresponding virtual destination network location information.
[0195] In an optional embodiment, the first virtual mapping submodule includes:
[0196] an intermediate network location information acquisition unit, used to acquire intermediate network location information of the traffic processing module;
[0197] a virtual source network location information determination unit, used to map the intermediate network location information to the virtual source network location information of the attack traffic.
[0198] In an optional embodiment, the shared honeypot system includes multiple sub-honeypot systems;
[0199] The second virtual mapping submodule includes:
[0200] a target sub-honeypot system determination unit, used to determine the target sub-honeypot system corresponding to the attack traffic based on the original attack information and the resource status of each sub-honeypot system;
[0201] a virtual destination network location information determination unit, used to map the destination network location information of the target sub-honeypot system to the virtual destination network location information of the attack traffic.
[0202] In an optional embodiment, the virtual destination network location information determination unit includes:
[0203] a candidate sub-honeypot system determination sub-unit, used to match candidate sub-honeypot systems with corresponding analysis capabilities for attack traffic based on the original attack information;
[0204] a real-time resource status acquisition sub-unit, used to acquire the real-time resource status of each candidate sub-honeypot system;
[0205] a virtual destination network location information determination sub-unit, used to select a target sub-honeypot system whose resource load meets preset conditions from the candidate sub-honeypot systems based on the real-time resource status.
[0206] In an optional embodiment, the candidate sub-honeypot system determination sub-unit includes:
[0207] an attack feature identification node, used to identify the attack features corresponding to the attack traffic based on the original attack information;
[0208] a candidate sub-honeypot system determination node, used to match candidate sub-honeypot systems with corresponding analysis capabilities in the shared honeypot system based on the attack features.
[0209] In an optional embodiment, the interactive information acquisition module 403 includes:
[0210] an information determination submodule, used to determine the corresponding original attack information and domain identification information based on the virtual attack information corresponding to the interactive information;
[0211] an encapsulated interactive data determination submodule, used to encapsulate the interactive information based on the domain identification information to generate encapsulated interactive data;
[0212] an encapsulated interactive data sending submodule, used to return the encapsulated interactive data to the corresponding attacker terminal based on the original attack information.
[0213] In an optional embodiment, the interactive information feedback module 404 includes:
[0214] an alarm information acquisition submodule, used to acquire the attack analysis results generated by the shared honeypot system based on attack interaction, the attack analysis results including alarm information;
[0215] a network domain determination submodule, used to determine the network domain corresponding to the attack traffic based on the original attack information and virtual attack information;
[0216] an alarm information sending submodule, used to send the alarm information to the user terminal corresponding to the network domain.
[0217] FIG5 is a block diagram of a server provided in this application. Referring to FIG5, the server 500 may include one or more of the following components: a processing component 502, a memory 504, a power supply component 506, a multimedia component 508, an audio component 510, an input / output interface 512, a sensor component 514, and a communication component 516.
[0218] The processing component 502 typically controls the overall operation of the server 500, such as operations associated with display, telephone calls, data communication, camera operation, and recording operation. Processing component 502 may include one or more processors 520 to execute instructions to complete all or part of the steps of the method described above. Furthermore, processing component 502 may include one or more modules to...For interaction between processing component 502 and other components. For example, processing component 502 may include a multimedia module to facilitate interaction between multimedia component 508 and processing component 502.
[0219] Memory 504 is configured to store various types of data to support operation on server 500. Examples of such data include instructions for any application or method operating on server 500, contact data, phonebook data, messages, pictures, videos, etc. Memory 504 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0220] Power supply component 506 provides power to various components of server 500. Power supply component 506 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to server 500.
[0221] Multimedia component 508 includes a screen that provides an output interface between server 500 and a user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 508 includes a front-facing camera and / or a rear-facing camera. When server 500 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities. Specification page 15 / 17 19 CN 121887440 A
[0222] The audio component 510 is configured to output and / or input audio signals. For example, the audio component 510 includes a microphone.The microphone (MIC) is configured to receive external audio signals when the server 500 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 504 or transmitted via communication component 516. In some embodiments, audio component 510 also includes a speaker for outputting audio signals.
[0223] Input / output interface 512 provides an interface between processing component 502 and peripheral interface modules, which may be a keyboard, click wheel, buttons, etc. These buttons may include, but are not limited to: home button, volume button, start button, and lock button.
[0224] Sensor component 514 includes one or more sensors for providing status assessments of various aspects of the server 500. For example, sensor component 514 can detect the on / off state of server 500, the relative positioning of components, such as the display and keypad of server 500, and can also detect changes in the position of server 500 or a component of server 500, the presence or absence of user contact with server 500, the orientation or acceleration / deceleration of server 500, and temperature changes of server 500. Sensor component 514 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor component 514 may also include an optical sensor, such as a Complementary Metal Oxide Semiconductor (CMOS) sensor or a Charge-coupled Device (CCD) sensor, for use in imaging applications. In some embodiments, sensor component 514 may also include an accelerometer, a gyroscope, a magnetometer, a pressure sensor, or a temperature sensor.
[0225] Communication component 516 is configured to facilitate wired or wireless communication between server 500 and other devices. Server 500 can access wireless networks based on communication standards, such as WiFi, 4G, or 5G, or combinations thereof. In one exemplary embodiment, communication component 516 receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 516 also includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module may be based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, or Ultra Wideband (UWB) technology.
[0226] In an exemplary embodiment, server 500 may be implemented using one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processors (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above-described methods.
[0227] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 504 including instructions, which may be executed by the processor 520 of server 500 to complete the above-described methods. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0228] A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by the processor of a server, enables the server to perform the above-described methods.
[0229] This application embodiment also provides a chip for executing instructions, which is used to execute the technical solution of the method in the above embodiments.
[0230] This application embodiment also provides a computer-readable storage medium storing computer execution instructions, which, when executed on a computer, cause the computer to execute the technical solution of the method in the above embodiments.
[0231] This application embodiment also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solution of the method in the above embodiments.
[0232] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge in the art not disclosed herein.Or conventional technical means. The description and embodiments are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0233] It should be understood that this application is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
[0234] Other embodiments of this application will readily conceive of those skilled in the art upon consideration of the description and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or conventional technical means in the art not disclosed in this application. The description and embodiments are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0235] It should be understood that this application is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims. Instruction Manual 17 / 17 Page 21 CN 121887440 A Figure 1 Figure 2 Figure 3 Instruction Drawing 1 / 2 Page 22 CN 121887440 A Figure 4 Figure 5 Instruction Drawing 2 / 2 Page 23 CN 121887440 A The application provides an attack traffic processing method, apparatus, device, medium and program product, and relates to the technical field of network security. The method is applied to a cloud server. The cloud server includes a plurality of network domains, a traffic processing module and a shared honeypot system. The method includes: obtaining attack traffic for a network domain; performing network virtual mapping processing on original attack information in the attack traffic togenerate corresponding virtual attack information; redirecting the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information, and obtaining interaction information of the attack traffic; and returning the interaction information to an attack terminal corresponding to the network domain according to a mapping relationship between the virtual attack information and the original attack information. According to the method of the application, the attack traffic for the plurality of network domains is uniformly directed to the shared honeypot system, so that cross-domain communication and resource reuse are realized, and tenant deployment cost and platform maintenance cost are further reduced.
Claims
1. A method for processing attack traffic, characterized in that, It is applied to cloud servers, which include multiple network domains, traffic processing modules, and a shared honeypot system; Attack traffic from each of the network domains is sent to the shared honeypot system for attack interaction through the traffic processing module; The method includes: Obtain attack traffic targeting the network domain; The original attack information in the attack traffic is processed by network virtual mapping to generate corresponding virtual attack information. Based on the virtual attack information, the attack traffic is redirected to the shared honeypot system for attack interaction, and the interaction information of the attack traffic is obtained; Based on the mapping relationship between the virtual attack information and the original attack information, the interactive information is returned to the attack terminal corresponding to the network domain.
2. The method according to claim 1, characterized in that, Acquiring attack traffic targeting the network domain includes: The data flow accessing the network domain is monitored by a traffic monitoring unit deployed in the network domain. When the traffic monitoring unit detects a data flow that matches the preset attack characteristics, it determines that it is attack traffic targeting the network domain. The attack traffic is forwarded to the traffic processing module through the traffic redirection unit in the network domain according to the preset traffic redirection strategy.
3. The method according to claim 2, characterized in that, When the traffic monitoring unit detects a data flow that matches preset attack characteristics, it determines that it is attack traffic targeting the network domain, including: When a data stream accessing a preset network port and / or a non-existent network address is detected, the data stream is collected; Obtain domain identifier information that represents the network domain, and encapsulate the collected data stream based on the domain identifier information to generate attack traffic targeting the network domain.
4. The method according to claim 3, characterized in that, Based on the domain identification information, the collected data stream is encapsulated and processed to generate attack traffic targeting the network domain, including: Obtain the virtual local area network label corresponding to the network domain as the domain identification information; Based on the virtual LAN tag, the collected data stream is encapsulated using a preset encapsulation protocol, and the encapsulated data stream tag is used as attack traffic targeting the network domain.
5. The method according to claim 1, characterized in that, The original attack information in the attack traffic is virtually mapped to generate corresponding virtual attack information, including: The attack traffic is analyzed to obtain the original attack information of the attack traffic; the original attack information includes the original source network location information and the original destination network location information, and the network location information includes the network port and / or network address; The original source network location information is subjected to virtual mapping processing to obtain the corresponding virtual source network location information; The original destination network location information is subjected to virtual mapping processing to obtain the corresponding virtual destination network location information.
6. The method according to claim 5, characterized in that, The original source network location information is subjected to virtual mapping processing to obtain the corresponding virtual source network location information, including: Obtain the intermediate network location information of the traffic processing module; The intermediate network location information is mapped to the virtual source network location information of the attack traffic.
7. The method according to claim 5, characterized in that, The shared honeypot system includes multiple sub-honeypot systems; The original destination network location information is subjected to virtual mapping processing to obtain corresponding virtual destination network location information, including: Based on the original attack information and the resource status of each of the sub-honeypot systems, the target sub-honeypot system corresponding to the attack traffic is determined; The target network location information of the target sub-honeypot system is mapped to the virtual target network location information of the attack traffic.
8. The method according to claim 7, characterized in that, Based on the original attack information and the system resource status of each of the sub-honeypot systems, the target sub-honeypot system corresponding to the attack traffic is determined, including: Based on the original attack information, candidate sub-honeypot systems with corresponding analysis capabilities are matched for the attack traffic; Obtain the real-time resource status of each of the candidate sub-honeypot systems; Based on the real-time resource status, a target sub-honeypot system whose resource load meets preset conditions is selected from the candidate sub-honeypot systems.
9. The method according to claim 8, characterized in that, Based on the original attack information, candidate sub-honeypot systems with corresponding analysis capabilities within the shared honeypot system are matched to the attack traffic, including: Based on the original attack information, identify the attack characteristics corresponding to the attack traffic; Based on the attack characteristics, candidate sub-honeypot systems with corresponding analytical capabilities are matched within the shared honeypot system.
10. The method according to any one of claims 1-9, characterized in that, Based on the original attack information and the virtual attack information, the interactive information is returned to the attack terminal corresponding to the network domain, including: Based on the virtual attack information corresponding to the interactive information, determine the corresponding original attack information and domain identification information; The interaction information is encapsulated based on the domain identifier information to generate encapsulated interaction data. Based on the original attack information, the encapsulated interactive data is returned to the corresponding attacker's terminal.
11. The method according to any one of claims 1-9, characterized in that, The method further includes: Obtain the attack analysis results generated by the shared honeypot system based on the attack interaction, and the attack analysis results include alarm information; Based on the original attack information and the virtual attack information, the network domain corresponding to the attack traffic is determined; The alarm information is sent to the user terminal corresponding to the network domain.
12. An attack traffic processing device, characterized in that, It is applied to cloud servers, which include multiple network domains, traffic processing modules, and a shared honeypot system; Attack traffic from each of the network domains is sent to the shared honeypot system for attack interaction through the traffic processing module; The device includes: An attack traffic acquisition module is used to acquire attack traffic targeting the network domain; The virtual mapping module is used to perform network virtual mapping processing on the original attack information in the attack traffic to generate corresponding virtual attack information; An interactive information acquisition module is used to redirect the attack traffic to the shared honeypot system for attack interaction based on the virtual attack information, and obtain the interactive information of the attack traffic. The interactive information feedback module is used to return the interactive information to the attack terminal corresponding to the network domain according to the mapping relationship between the virtual attack information and the original attack information.
13. A server, characterized in that, include: A processor and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor, when executing the computer execution instructions, is used to implement the attack traffic processing method as described in any one of claims 1 to 11.
14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the attack traffic processing method as described in any one of claims 1 to 11.
15. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the attack traffic processing method as described in any one of claims 1 to 11.