Method for protecting computer networks
By generating false network traffic and shifting critical nodes in the topology, the method effectively misleads attackers about the network's characteristics, enhancing protection against reconnaissance attacks.
Patent Information
- Authority / Receiving Office
- RU · RU
- Patent Type
- Patents
- Current Assignee / Owner
- FEDERALNOE GOSUDARSTVENNOE KAZENNOE VOENNOE OBRAZOVATELNOE UCHREZHDENIE VYSSHEGO OBRAZOVANIYA KRASNODARSKOE VYSSHEE VOENNOE ORDENOV ZHUKOVA I OKTYABRSKOJ REVOLYUTSII KRASNOZNAMENNOE UCHILISHCHE IMENI GENERAL ARMII S M SHTEMENKO MINIST OBORONY ROSSIJSKOJ FEDERATSII
- Filing Date
- 2025-07-31
- Publication Date
- 2026-07-09
AI Technical Summary
Existing methods for protecting computer networks from attackers are ineffective due to the attacker's ability to detect and identify network security tools by intercepting and analyzing network traffic, compromising the security tools and altering their malicious strategy.
A method that involves generating false network traffic by periodically changing IP addresses and other network parameters across multiple subnets, using a DHCP server to mislead attackers about the network's dynamic and topological characteristics, and employing an exponential distribution model to approximate the time series of packet pauses, while shifting critical nodes in the network topology to maintain similarity and reduce the intersection of real and false critical nodes.
This approach enhances network protection by creating a false impression of the network's topology and dynamics, making it harder for attackers to identify critical nodes and compromising security tools, thus increasing the effectiveness of network defense.
Smart Images

Figure 00000033_ABST
Abstract
Description
[0001] The invention relates to telecommunications and can be used in attack detection systems for the purpose of increasing the effectiveness of protecting computer networks by creating a false impression in the attacker regarding the dynamic and topological characteristics of computer networks when generating false network traffic, in particular, in Internet-type data transmission networks based on the TCP / IP (Transmission Control Protocol / Internet Protocol) family of communication protocols.
[0002] A "Method for Protecting Computer Networks" is known under Russian Patent No. 2716220, IPC G06F 21 / 60, H04L 29 / 06, published March 6, 2020. This method includes the following sequence of actions. Network devices are connected to the computer network. The DHCP server generates synchronization parameters for the set time zone and time, assigned IP addresses and their lease time, and a subnet number for the network devices in the computer network. Network connections are then established between the network devices in the computer network. After receiving a message packet from the communication channel, the information flow identifier is extracted from the header of the received message packet.If the information flow identifier and the IP address of the sender of the message packet are unauthorized, response messages containing the new subnet number, IP addresses for the new subnet, their lease duration for the new subnet, the next subnet number, the IP address of the DHCP server, and the synchronization parameters of the set time zone and time are generated and sent to the network devices from the DHCP server.
[0003] The advantage of this method is that it misleads the attacker by changing the network addressing parameters in the source subnet when a mismatch in the identifiers of information flows is detected.
[0004] The disadvantage of this method is its relatively low protection effectiveness, due to the attacker's high ability to detect the use of network security tools and identify their characteristics. This is because, after synchronously changing the network parameters of devices in the original subnet to those in the new subnet, the original subnet, where network information exchange was previously established, will no longer have any active IP addresses for network devices. This circumstance can lead to the compromise of the security tools used and the identification of their characteristics if the attacker intercepts network traffic or scans the network, as well as to the attacker changing their malicious strategy.
[0005] A "Method for Protecting Computer Networks" is known under Russian Patent No. 2789810, IPC G06F 21 / 60, H04L 9 / 40, published February 10, 2023. The known method includes the following sequence of actions. Over a specified period of time, network traffic parameters in the protected subnet are read and the network traffic self-similarity index is calculated. If unauthorized information flows are detected, the lease of previously assigned network parameters of network devices in the source subnet is terminated. Afterwards, a network device for generating and directing false network traffic is specified in the source subnet. Then, new network parameters are generated and assigned in the new subnet to all network devices except the specified network device for generating and directing false network traffic. Then, the calculated network traffic self-similarity index is compared with a set of required values.If they don't match, false traffic with completely random parameters is generated and sent to the original subnet. Otherwise, mathematical models are created for each network traffic parameter, which are used to generate and send self-similar network traffic flows to the original subnet over a specified period of time. After the specified time for sending false network traffic to the original subnet has elapsed, the designated network device is assigned new network parameters in the new subnet.
[0006] The advantages of the considered method are the misleading of the attacker by changing the network parameters of the protected computer network under the conditions of detection of a discrepancy between the identifiers of information flows, as well as by generating and sending to the attacker false network traffic with the network parameters of the original subnet and specified dynamic characteristics obtained on the basis of calculating the self-similarity index of network traffic.
[0007] The disadvantage of this method is its relatively low protection effectiveness, due to the attacker's high ability to detect the use of network security tools and identify their characteristics. This is because the generation of false network traffic, in the event of a discrepancy between the calculated self-similarity index of network traffic and the required set of values, is carried out using completely random parameters or, otherwise, in accordance with mathematical models of self-similar network traffic.This circumstance, when generating false network traffic in accordance with mathematical models of self-similar network traffic, leads to the presence of a significant autocorrelation relationship between the moments of time of sending packets of false network traffic, which can lead to the compromise of the security tools used and the identification of their characteristics in the event of interception and analysis of the dynamic characteristics of network traffic by an intruder, as well as to a change in the intruder's strategy of malicious influence.
[0008] The closest in its technical essence to the claimed method is the "Method for Protecting Computer Networks" according to Russian Patent No. 2837233, IPC G06F 21 / 60, published March 27, 2025. This known prototype method includes the following sequence of actions. A specified number of time intervals between network traffic packets in the protected subnet are sequentially read and a point estimate of the parameters of the delay distribution function necessary for the formation and direction of false network traffic with dynamic properties close to real network traffic is calculated. If unauthorized information flows are detected, the lease of previously assigned network parameters of network devices in the source subnet is terminated. A network device for the formation and direction of false network traffic is then assigned in the source subnet.Next, new network parameters are generated and assigned in the new subnet to all network devices except the designated network device for generating and forwarding false network traffic. Then, false traffic is generated and forwarded to the original subnet at time intervals determined by a parameterized inter-packet time distribution function. To adaptively generate false traffic parameters, the distribution function parameter is re-evaluated after a specified time. After the specified time for forwarding false network traffic to the original subnet has elapsed, the designated network device is assigned new network parameters in the new subnet.
[0009] The advantage of the prototype method is the reduction of the attacker's ability to compromise the security tools used and identify their characteristics by approximating the dynamic characteristics of real network traffic with a model of the exponential law of distribution of pauses between packets when generating and sending false network traffic with specified dynamic characteristics to the protected subnet.
[0010] A disadvantage of the prototype method is the relatively low effectiveness of network protection, due to the attacker's high ability to detect critical network nodes, the use of network security tools, and identify their characteristics. This is because false network traffic is generated by misleading the attacker about the dynamic characteristics of network traffic. By intercepting and analyzing the topological characteristics of the network, the attacker has the ability to uncover the original network topology and critical nodes by using node connectivity as criticality indicators, as well as compromise the security tools used and alter the malicious strategy.
[0011] The purpose of the declared technical solution is to increase the effectiveness of the protection of computer networks by forming a false impression in the attacker’s mind regarding the dynamic and topological characteristics of computer networks when generating false network traffic.
[0012] The stated goal is achieved by the fact that in the known method of protecting computer networks, IP={IP1, IP2, …, IP is pre-set n} is a set of IP addresses of network devices in a computer network that are DHCP clients of a DHCP server, where n is the maximum allowable number of IP addresses of network devices in a computer network. Next, subsets d are specified in the set of IP addresses of network devices in a computer network IF d ={IF d 1, IF d 2, …, IP d n}, where d is the DHCP server subnet number, d=1, 2, …, z, where z is the maximum number of subnets for each subset d. After this, the IP addresses of the DHCP servers are specified.d dhcp , where IP d dhcp - DHCP server IP address, IP d dhcp ∈ IP d . Then, a memory array D=[1, 2, …, z] is pre-defined to store the DHCP server subnet numbers and t d max - the maximum lease time of all IP addresses in the subnet with number d. Next, set C={CIP1, CIP2, …, CIP m} a set of connections between network devices of a computing network, where CIP m - an identifier for a connection between network devices in a computing network, which contains the IP address of the sender c and the recipient b, the type of interaction protocol, and the interaction ports, where m is the maximum allowable number of connections between network devices in a computing network. Next, the memory array C is pre-defined. i =[CIP1, CIP2, CIP m ] for storing CIP identifiers mand a set of identifiers of authorized information flows TS ≥ 1. After this, MAC={MAC1, MAC2, …, MAC l ) a set of MAC addresses of network devices in a computing network, where l is the maximum number of network devices in the computing network. Next, the memory array N is specified. A to store the matrix of correspondence between the n-th IP address of a network device from the set of IP addresses and the l-th MAC address from the MAC memory array. After this, the FIP is set d ={FIP d 1, FIF d 2, …, FIP d f**} is the set of IP addresses of false subscribers of subnet d, where ƒ is the maximum allowable number of IP addresses of network devices of subnet d. Next, t is set - a time counter containing the value of the current time. Then t is set st - a time counter containing the time it took for network devices to connect to the subnet. Next, set t train - the period of time after which it is necessary to update the parameter estimate distribution functions of a random variable Ω del delays between packets of a computing network d. Then set b st - counter of the number of parameter estimate updates distribution functions of a random variable Ω del delays between packets of the computing network d. Next, V is set - the power of the set T del values of τ del delays between packets of network traffic of a computing network d, where T del ={τ del 1, τ del 2, …, τ del v} is the set of values of delays τ del between network traffic packets of power V of the computing network d. After which M is set z =[τ del 1, τ del 2, …, τ del v] - a memory array for storing the set T del delays τ del between network traffic packets of power V of the computing network d. Next, we define W - the power of the set T gen values of τ gendelays between the moments of time of generation of false network traffic of the computing network d, where T gen ={τ gen 1, τ gen 2, …, τ gen w} is the set of values of τ gen delays between the moments of generation of false network traffic with the power W of the computing network d. Then M is set k =[τ gen 1, τ gen 2, …, τ gen w] is a memory array for storing the set T gen values of τ gen delays of power W between the moments of time of generation of false network traffic of the computing network d. Next, set - a memory array for storing the point estimate of the parameter exponential distribution law of a random variable Ω del delays between network traffic packets of a computing network d. Next, set the time t dDirecting false network traffic to the subnet. Network devices are then connected to the computer network. Afterwards, messages are sent from the network devices to the DHCP server to obtain synchronization parameters for the set time zone and time, subnet number d, and IP addresses. d and the time of their lease, IP address of the DHCP server IP d dhcp The DHCP server then receives messages from network devices on the computer network. It then generates messages for the network devices containing the synchronization parameters for the set time zone and time, the assigned subnet number d, and the IP address IP d and their lease time, IP address of the DHCP server IP d dhcp. The generated messages are then sent to the network devices of the computer network. Each network device of the computer network then receives a message from the DHCP server. The network devices of the computer network then send response messages to the DHCP server, confirming its selection. The DHCP server then receives messages from the network devices of the computer network, confirming its selection. The network device of the computer network then sets the synchronization parameters for the established time zone and time, the assigned subnet number d, and the IP address IP. d and their lease time, for the DHCP server IP address IP d dhcp Next, the MAC and IP addresses are matched. The MAC and IP address mapping is then stored in memory array N. A . After which they are removed from the memory array N A, those network device correspondences from which they have not received confirmation messages. Connections are then established between network devices. CIP identifiers are then assigned to the established connections between network devices. m Then remember the CIP identifiers m in memory array C i , read the set T del delays between network traffic packets of power V of the computing network d. After which the set T is stored del delays between network traffic packets of power V of the computing network d in the memory array M z . After which the value of the point estimate of the parameter is calculated exponential distribution law of a random variable Ω del delays between network traffic packets of a computing network d. Next, the calculated value of the point estimate of the parameter is stored exponential distribution law of a random variable Ω del delays between network traffic packets of a computing network d in a memory array M P . Then the values of τ are calculated gen sets T gen delays between the moments of generation of false network traffic of the computing network d. After which the calculated values τ are stored gen sets T gen delays between the moments of time of generation of false network traffic of the computing network d in the memory array M k. A message packet is then received from the communication channel. The information flow identifier is then extracted from the header of the received message packet. It is then compared with the identifiers of the authorized TS information flows. If the extracted information flow identifier matches the identifiers of the authorized TS information flows, the message packet is transmitted to the recipient, after which the next message packet is received from the communication channel. If the extracted identifier does not match the identifiers of the authorized TS information flows, the recipient's IP address in the received message packet is compared with pre-defined false IP addresses of subscribers of the FIP computing network. If the recipient's IP address in the received message packet does not match the pre-defined false IP addresses of FIP subscribers, the message packet is ignored.If the IP address of the recipient in the received message packet matches the pre-set false IP addresses of the FIP subscribers, the IP address of the sender of the message packets is compared with each IP address of the network device of the computing network from the set of IPs. d If they match, the MAC address of the network device is excluded from the N array. A DHCP servers. If they don't match, the DHCP server reads the next subnet number (d=d+1) from array D. After this, messages are generated for network devices containing new synchronization parameters for the set time zone and time, the subnet number (d=d+1), and the IP addresses (IP). (d+1) and the time of their rental t (d+1) max , DHCP server IP address IP (d+1) dhcp . Then, the DHCP server sends generated messages to the network devices of the computer network, containing new synchronization parameters for the established time zone and time, the subnet number d=d+1, IP addresses IP (d+1) and the time of their rental t (d+1)max . Then, each network device in the computer network receives messages containing new synchronization parameters for the established time zone and time, subnet number d=d+1, IP addresses IP (d+1) and the time of their rental t (d+1) max Then, a network device is assigned to subnet d for generating and directing false network traffic flows in this subnet. After this, the network devices of subnet d, in addition to the network device for generating and directing false network traffic flows, are assigned the synchronization parameters of the established time zone and time, the subnet number d-d+1, and the IP addresses. (d+1) and the time of their rental t (d+1) max Then set the IP address (d+1) dhcp for the DHCP server. After which the memory array N is formed again. Ato store the matrix of MAC and IP addresses of network devices in the computer network. After this, the routing of false network traffic to the original subnet d is completed. Then, the network device from which the false network traffic was generated and routed to subnet d is given new synchronization parameters for the established time zone and time, the subnet number d = d + 1, and the IP address IP (d+1) and the time of its lease t (d+1) max , IP address of the selected DHCP server IP (d+1) dhcp. After which the memory array N is formed again. A to store the MAC and IP address mapping matrix of network devices in subnet d = d + 1, taking into account the network device that emerged from subnet d, from which the false network traffic was generated and directed. Next, we additionally specify X—the length of the read network traffic dump for computer network d. Then, we additionally specify L w - the length of vectors V j realcharacteristics of the real topology and vectors V j rand characteristics of the false topology of the computing network d, where j ∈ [1, …, I], I is the number of vectors of characteristics of the real and false topology of the computing network d; V j rand =[ν mrand j 1, …, ν ramd j Lw ], V j real =[ν real j 1, …, ν rea j Lw ], ν real j 1∈ {0, 1}, ν randn j 1∈ {0, 1} is the first element of the j-th vector V j rand characteristics of the real topology and the first element of the j-th vector V j rand characteristics of the false topology of the computing network d, respectively, the probability of the presence of the i-th unit element ν rand j i in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to P1(ν rand j i =1)=p j rand, the probability of the presence of the i-th zero element ν rand j i in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to P0(ν rand j i =0)=1-p j rand accordingly, p j rand - estimate of the probability of the presence of unit elements in the j-th vector V j rand characteristics of the false topology of the computing network d. Then, M is additionally specified IP =[(IP s bS ,IP d gD ) x ] - a memory array for storing the set H IP pairs of IP addresses of senders and recipients of network traffic of length X of a computing network d, where IP s bS ,IP d gD- IP addresses of senders and recipients of network traffic packets, respectively, x ∈ [1, …, X] is the network traffic packet number, bS ∈ [1, …, B] is the number of the IP address of the sender of the network traffic packet, B is the number of unique IP addresses of senders of network traffic packets, gD ∈ [1, …, G] is the number of the IP address of the recipient of the network traffic packet, G is the number of unique IP addresses of recipients of network traffic packets, Hip={(IP s bS IP d gD ) x}. Next, M is additionally specified. Ar =[[A r11 , …, A r1U ], …, [A rU1 , A rUU ]] - memory array for storing the adjacency matrix A r directed graph of the real topology of a computing network, reconstructed from a read dump of network traffic of a computing network d, where A r11∈ {0, 1} is the element of the first row and first column of the adjacency matrix, U=B+G is the dimension of the adjacency matrix equal to the number of unique IP addresses of sender and recipient nodes in the network traffic dump of the computing network d. After which Z is additionally specified real = {V1 real , …, V I real} is a set of vectors of characteristics of the real topology of the computing network d. Then, M is additionally specified Vreal =[[V1 real ], …, [V I r eal ]] - a memory array for storing vectors of characteristics of the real topology of the computing network d. After which p is additionally specified rand ={p rand 1, …, p rand I} - a set of point estimates of the probabilities of individual elements v rand j i vectors v j rand characteristics of the false topology of the computing network d, i∈ [1, …, Lw], j∈[1, …, I]. Then M is additionally specified θ =[p rand 1, …, p randI ] - a memory array for storing the set P rand point estimates of the probabilities of individual elements ν randn j i vectors V j rand characteristics of the false topology of the computing network d, i∈ [1, …, Lw], j∈[1, …, I]. Then, Z is additionally specified rand ={V1 rand , …, V I rand} is a set of vectors of characteristics of the false topology of the computing network. After which M is additionally specified Vrand =[[V1 rand ], …, [V I rand ]] - a memory array for storing the vectors of characteristics of the false topology of the computing network d. Then, M is additionally specified Aƒ =[[A ƒ11 , …, A ƒ1U ], …, [A ƒU1 , …, A ƒUU ]] - a memory array for storing the adjacency matrix of the directed graph of the false topology of the computing network, calculated from a set of random vectors Z rand , where A ƒ11∈{0, 1} is an element of the first row and first column of the adjacency matrix A ƒ . After which M is additionally set IP* =[(IP s* bS* , IP d* gD* ) w ] - a memory array for storing a set of H* IP pairs of IP addresses of senders and recipients of false network traffic of length W, where IP s* bS* , IP d* gD* - IP addresses of senders and recipients of false network traffic packets, respectively, w∈[1, …, W] is the number of the false network traffic packet, bS*∈[1, …, B*] is the number of the IP address of the sender of the false network traffic packet, P* is the number of unique IP addresses of senders of false network traffic packets, gD*∈[1, …, G*] is the number of the IP address of the recipient of the false network traffic packet, G* is the number of unique IP addresses of recipients of false network traffic packets, H* IP ={(IP s* bS* , IP d * gD* ) w}. Next, after memorizing the CIP identifiers m in the memory array C, read X packets of network traffic of the computing network d. Then read X packets of network traffic of the computing network d. Then store the set of pairs H IP IP addresses of senders and recipients of network traffic of length X of the computing network d in the memory array M IP . Next, the adjacency matrix A is formed. r directed graph of the real topology of the computing network, reconstructed from the read dump of the network traffic of the computing network d. After which the adjacency matrix A is stored r in the memory array M Ar . Next, the number I of characteristic vectors of the real and false topology of the computing network d. Then the set Z is calculated real vectors of characteristics of the real topology of the computing network d. Next, the calculated values of the elements of the set Z are stored real in the memory array M Vreal . After which the set P is calculated randpoint estimates of the probabilities of individual elements ν rand j i vectors V j rand characteristics of the false topology of the computing network d, i∈[1, …, Lw], j∈[1, …, I]. Then the calculated values of the elements of the set P are stored rand in the memory array M θ . Next, the set Z is calculated rand vectors of characteristics of the false topology of the computing network d. Then the calculated values of the elements of the set Z are stored rand in the memory array M Vrand . Next, the adjacency matrix Aƒ is calculated from the elements of the set Z rand . Then the calculated adjacency matrix A is stored ƒ in the memory array M Aƒ . Next, a set of pairs H* is formed. IP IP addresses of senders and recipients of packets of false network traffic of length W from the adjacency matrix A ƒ After which they remember a set of pairs P* IP IP addresses of senders and recipients of false network traffic packets of length W in the memory array M*IP . Then after forming the memory array N A to store the matrix of correspondence between MAC and IP addresses of network devices in a computing network, generated false network traffic is sent with delay intervals T gen between packets of false network traffic and IP addresses of senders and recipients of packets of false network traffic from the set H* IP into the original subnet d. Further, if the condition t - t st >(b st +1)⋅t train is executed, which corresponds to the expiration of the time interval for updating the parameter estimate distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set P rand , then the value of the counter b is increased st the number of reconfigurations of the parameters of mathematical models per unit. Then, X packets of network traffic of the computing network d are read. After that, if the condition t - t st >(b st +1)⋅t trainis not met, indicating that there is no need to update the parameter estimate distribution functions of a random variable Ω del delays between packets of a computing network d and elements of a set p rand , then compare the time interval t - t st from time t st up to the current time t with time t d generating false network traffic of the computing network d. Then, if the condition t - t st >t d is not met, then the generated false network traffic is sent with delay intervals τ gen from the set T gen between packets and IP addresses of senders and recipients of packets of false network traffic from the set H* IP into the original subnet d. After which, if the condition t - t st >t d is executed, then the value of counter b is decreased st number of parameter estimate updates distribution functions of a random variable Ω deldelays between packets of the computing network d and elements of the set P rund to zero.
[0013] As a method for calculating the total number I of characteristic vectors of real and false computing networks, an integer is selected, obtained as a result of dividing the total number of elements in the adjacency matrix A r by the length of vectors L w , rounded up.
[0014] As a method for calculating probability estimates of unit elements in vectors V j rand characteristics of the false topology of the computing network in the set P rand choose to calculate the arithmetic mean values of the elements of vectors V j real characteristics of the real topology of a computing network d with the same index j ∈ [1, …, I].
[0015] As a method for calculating the adjacency matrix A ƒ directed graph of the false topology of the computing network, a concatenation of vectors V is selected randcharacteristics of the false computing network with subsequent change in the dimension of the total array from the vector (U 2 , 1) on a square matrix (U, U). If the dimension of the array after concatenation exceeds the number of elements of U 2 matrices A r , then the corresponding number of elements are removed to the value U 2 .
[0016] Thanks to a new set of essential features, the claimed method increases the effectiveness of protecting computer networks by creating a false impression in the attacker's mind regarding the dynamic and topological characteristics of computer networks when generating false network traffic.
[0017] The claimed objects of the invention are explained by drawings, which show:
[0018] Fig. 1 - Diagram of a protected computing network using a device for generating and directing false network traffic into the network;
[0019] Fig. 2a - Block diagram of the sequence of actions implementing the declared method for protecting computer networks;
[0020] Fig. 2b - Block diagram of the sequence of actions implementing the declared method for protecting computing networks.
[0021] Fig. 3 - Scheme of the process of calculating the adjacency matrix A ƒ directed graph of the false topology of a computing network from the adjacency matrix A r directed graph of the real topology of a computing network by calculating vectors V real and V random , where: a) scheme for calculating vectors V real and V random , adjacency matrices A ƒ ; b) visualization of the original directed graph of the topology of a real computing network (200 vertices); c) visualization of the directed graph of the topology of a false computing network (200 vertices) with length L w vectors V real and V random, equal to 2 elements; d) visualization of the directed graph of the topology of a false computing network with length L w =10 elements; d) visualization of the directed graph of the topology of a false computing network with length L w =100 elements.
[0022] Fig. 4 - Quantitative assessment of the effectiveness of computer network protection when generating false network traffic containing the characteristics of the false computer network topology (sample size 2000 experiments), where: a) the dependence of the Jaccard coefficient J crit from the ratio of length L w vectors V real and V random to the total amount of U 2 elements in the adjacency matrix A r ; b) box plot of the Jaccard coefficient distribution J crit in the calculated sample; c) the dependence of the approximation of the average shortest distance (in hops) between critical nodes D on the length ratio L w vectors V real and V random to the total amount of U 2elements in the adjacency matrix A r ; d) visualization of the attainable set in the criteria space (J edge , J crit ); d) dependence of the Jaccard coefficient J edge from the ratio of length L w vectors V real and V random to the total amount of U 2 elements in the adjacency matrix A r ; e) visualization of the reachable set in the criteria space (J edge , D).
[0023] The implementation of the claimed method is explained as follows. Currently, the information security measures in government information systems include: concealing the architecture and configuration of information systems; creating (emulating) false information systems or their components; transferring the information (automated) system to a secure state in the event of failures (glitches), which is provided, for example, in the Order of the Federal Service for Technical and Export Control (FSTEC of Russia) dated December 25, 2017 "On Approval of the Requirements for Ensuring the Security of Significant Objects of the Critical Information Infrastructure of the Russian Federation (as amended by orders of FSTEC of Russia dated August 9, 2018 No. 138, dated March 26, 2019 No. 60, dated February 20, 2020 No. 35)" on page 35.
[0024] This is due to the fact that, along with information security threats associated with unauthorized interference with information systems, of which computer networks are components, a fairly large number of computer attacks are of a reconnaissance nature, aimed at obtaining information about the composition, structure, and operating algorithms, location, and ownership of information systems. In particular, the threat of determining the topology of computer networks, implemented by the intruder's network reconnaissance tools through network scanning and network traffic analysis, is aimed at reconstructing the structural and functional characteristics of information systems. Network reconnaissance tasks include identifying the topology of computer networks and determining the relative importance of their nodes, which can be used by the intruder to carry out planned ARG attacks (from the English "ARG" - "advanced group attack").advanced persistent threat - “developed persistent threat”, targeted computer attack), which are known and described, for example, in the article by Levtsov V., Demidov, N. Anatomy of a targeted attack, part 1, Information Security, 2016, No. 2, on pp. 36-39.
[0025] One of the methods for implementing the above measures to protect information systems from network intelligence is the formation of false network traffic, which is understood as a set of false (masking) message packets generated with the aim of creating persistent false stereotypes in the intruder about the composition, structure and algorithms of computer networks, which is known and described, for example, in the article by Gorbachev A.A., Maksimov R.V. The problem of masking and the application of machine learning technologies in cyberspace, Issues of Cybersecurity, 2023, No. 5 (57), on pp. 43-46.
[0026] False network traffic is generated based on the characteristics of real network traffic by a specially designated node in the computing network. To ensure the plausibility of the false network traffic, its dynamic characteristics (the time series of pauses between packets of false network traffic) are approximated by an exponential distribution model when determining a point estimate of the parameter using the maximum likelihood method in accordance with, for example, GOST R 50779.26-2007 (IEC 60605-4:2001).
[0027] Nevertheless, generating false network traffic without taking into account changes in topological characteristics (the distribution of node degrees in computer networks) entails the possibility of compromising the topology of a real computer network and its critical nodes. Critical nodes in a computer network can mathematically represent graph vertices with relatively high vertex degrees. Therefore, to effectively mislead an attacker, it is advisable to implement a representation of the topological properties of a computer network with shifted critical nodes, while maintaining an acceptable degree of similarity to the original topology, for example, as described in the article by A. A. Gorbachev, "Masking Topological Properties of Computer Networks. Part 1, Cybersecurity Issues, 2024, No. 6 (64), p. 136."
[0028] To estimate the plausibility of the generated topology of a false computing network, a binary probabilistic model is used, the input and output data of which are vectors. The model's input data are estimated probabilities of observing output elements of one or zero during a fixed number of independent trials. The model's output data are the results of the sum of independent observations, the total length of which corresponds to the total number of elements in the adjacency matrix of the directed graph of the real computing network topology, and the number of parameters (probability estimates) depends on the size of the topology characteristic vectors of the real and false computing networks. The security of the computing network is improved by increasing the indicator approximating the distance between false and real critical nodes, as well as by reducing the intersection ratio of the set of false and critical nodes.This means that, if the identifiers of information flows do not match, the attacker will form an idea of the topology as a whole and the topological characteristics of the computing network in the original address space, but with significantly shifted critical (most connected) nodes, practically non-intersecting sets of real and false critical nodes, while simultaneously achieving a relatively high similarity index between the original and false topology of the computing network under conditions of limited address space and the type of mathematical model of the generator of the topology of the false computing network.
[0029] The claimed method is implemented as follows. In the general case (see Fig. 1), the subnet is a set of correspondents 100, a DHCP server 101, which are sources and recipients of network traffic, a packet analyzer 102 for generating reports, peripheral and communication equipment 103, and a device for generating and directing false network traffic to the subnet 104.
[0030] In order to protect the computer network and mislead the intruder 105 regarding the structure of the computer network, IP addresses and other network parameters of its network devices are periodically changed within several subnets, and in order to mislead the intruder regarding the use of security tools, false network traffic is generated and sent to the original subnet.
[0031] Fig. 2a, 2b shows a block diagram of the sequence of actions implementing the claimed method for protecting computer networks, in which the following designations are adopted:
[0032] IP={IP1, IP2, …, IP n ) - a set of IP addresses of network devices of a computer network that are clients of a DHCP server;
[0033] IP d ={IP d x , IP d 2, …, IP d n} - subsets in the set of IP addresses of network devices of a computing network;
[0034] n - the maximum permissible value for the number of IP addresses of network devices in a computer network;
[0035] d- DHCP server subnet number, d=1,2, …, z;
[0036] z - maximum number of subnets;
[0037] IP d dhcp - DHCP server IP address, IP d dhcp ∈ IP d ;
[0038] t d max - the maximum lease time of all IP addresses of subnet number d;
[0039] CIP m - an identifier of a connection between network devices of a computing network, which contains the IP address of the sender - c, the recipient - b, the type of interaction protocol, and the interaction ports;
[0040] m - the maximum allowable number of connections between network devices in a computing network;
[0041] C i =[CIP1, CIP2, …, CIP m ] - memory array for storing CIP identifiers m ;
[0042] TS - a set of identifiers of authorized information flows;
[0043] N A =[[IP1IP2, …, IP n ], [MAC1, MAC2, …, MAC l ]] - a memory array for storing a matrix of correspondence to the n-th IP address of a network device from a set of IP addresses of the l-th MAC address from the MAC memory array;
[0044] FIP d ={FIP d 1, FIP d 2, …, FIP d ƒ} - a set of IP addresses of false subscribers of the computing network d;
[0045] ƒ - the maximum allowable number of IP addresses of network devices in subnet d;
[0046] t - time counter containing the current time value;
[0047] t st - a time counter containing the value of the time it took for network devices to connect to the subnet;
[0048] t train - the period of time after which it is necessary to update the parameter estimate distribution functions of a random variable Ω del delays between packets of a computing network d;
[0049] t d - time of direction of false network traffic to subnet d;
[0050] b st - counter of the number of parameter estimate updates distribution functions of a random variable Ω del delays between packets of a computing network d, b st =0 - initial value of the counter of the number of parameter estimate updates distribution functions of a random variable Ω del delays between packets of a computing network d;
[0051] T del ={τ del 1, τ del 2, …, τ del v} is the set of values of delays τ de1 between network traffic packets of power V of the computing network d;
[0052] V - power of the set T del values of τ de1 delays between network traffic packets of a computing network d;
[0053] M z =[τ del 1, τ del 2, …, τ del v] is a memory array for storing a set T del delays τ de1 between network traffic packets of power V of the computing network d;
[0054] T gen ={τ gen 1, τ gen 2, …, τ gen w} is the set of values of τ gen delays between the moments of generation of false network traffic with power W of the computing network d;
[0055] M k =[τ gen 1, τ gen 2, …, τ gen w] is a memory array for storing the set T gen values of τ gendelays of power W between the moments of time of generation of false network traffic of the computing network d;
[0056] W - the power of the set T gen values of τ gen delays between the moments of time of generation of false network traffic of the computing network d;
[0057] - a memory array for storing the point estimate of the parameter exponential distribution law of a random variable Ω del delays between packets of network traffic of a computing network d.
[0058] X - the length of the read network traffic dump of the computing network d.
[0059] L w - length of vectors V j real characteristics of the real topology and vectors V j rand characteristics of the false topology of the computing network d, where j ∈ [1, …, I], I is the number of vectors of characteristics of the real and false topology of the computing network d; V j rand =[ν rand j 1, …, ν rand jLw ], V real =[ν real j 1…, ν real j Lw ], ν real j 1∈ {0, 1}, ν rand j 1∈ {0, 1} is the first element of the j-th vector V j rand characteristics of the real topology and the first element of the j-th vector V j rand characteristics of the false topology of the computing network d, respectively, the probability of the presence of the j-th unit element ν rand j 1 in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to p1(ν rand j i =1)=p rand , the probability of the presence of the i-th zero element v rand j i in the j-th vector V j rand characteristics of the false topology of the computing network J is equal to P0(ν rand j i =0)=P j rand accordingly p j rand - estimate of the probability of the presence of unit elements in the j-th vector Vj rand characteristics of the false topology of the computer network d.
[0060] M IP =[(IP s bS ,IP d gD ) x ] - a memory array for storing the set H IP pairs of IP addresses of senders and recipients of network traffic of length X of a computing network d, where IP s bS ,IP d gD - IP addresses of senders and recipients of network traffic packets, respectively, x ∈ [1, …, X] is the network traffic packet number, bS ∈ [1, …, B] is the number of the IP address of the sender of the network traffic packet, B is the number of unique IP addresses of senders of network traffic packets, gD ∈ [1, …, G] is the number of the IP address of the recipient of the network traffic packet, G is the number of unique IP addresses of recipients of network traffic packets, Hip={(IP s b S,IP d gD ) x}.
[0061] M Ar =[[A r11 , …, A r1U ], …, [A rU1 , …, A rUU]] - memory array for storing the adjacency matrix A r directed graph of the real topology of a computing network, reconstructed from a read dump of network traffic of a computing network d, where A r11 ∈ {0, 1} is the element of the first row and first column of the adjacency matrix, U=B+G is the dimension of the adjacency matrix equal to the number of unique IP addresses of sender and recipient nodes in the network traffic dump of the computing network d.
[0062] Z real ={V1r eal , …, V I r eal} - a set of vectors of characteristics of the real topology of the computing network d.
[0063] M Vreal =[[V1 real ], …, [V I real ]] - a memory array for storing vectors of characteristics of the real topology of the computing network d.
[0064] p rand ={p rand 1, …, p rand I} - a set of point estimates of the probabilities of individual elements ν rand j i vectors V jrand characteristics of the false topology of the computing network d,i∈[1, …, Lw], j∈[1, …, I].
[0065] M θ =[p rand 1, …, p rand I ] - a memory array for storing the set P rand point estimates of the probabilities of individual elements ν rand j i vectors V j rand characteristics of the false topology of the computing network d, j∈[1, …, L w ], j∈[1, …, I].
[0066] Z rand ={V1 rand , …, V I rand} - a set of vectors of characteristics of the false topology of the computing network d.
[0067] M Vrand =[[V1 rand ], …, [V I rand ]] - a memory array for storing vectors of characteristics of the false topology of the computing network d.
[0068] M Aƒ =[[A ƒ11 , …, A ƒ1U ], …, [A ƒU1 , …, A ƒUU]] - a memory array for storing the adjacency matrix of the directed graph of the false topology of the computing network, calculated from a set of random vectors Z rand , where A ƒ11 ∈{0, 1} is an element of the first row and first column of the adjacency matrix A ƒ .
[0069] M IP* =[(IP s* bS* , IP d* gD* ) w ] - a memory array for storing a set of H* IP pairs of IP addresses of senders and recipients of false network traffic of length W, where IP s* bS* , IP d* gD*- IP addresses of senders and recipients of false network traffic packets, respectively, w∈[1, …, W] is the number of the false network traffic packet, bS*∈[1, …, B*] is the number of the IP address of the sender of the false network traffic packet, B* is the number of unique IP addresses of senders of false network traffic packets, gD*∈[1, …, G*] is the number of the IP address of the recipient of the false network traffic packet, G* is the number of unique IP addresses of recipients of false network traffic packets, H*IP={(IP s* bS* ,IP d* gD*}.
[0070] In the pre-set initial data, X is additionally set (see block 1 in Fig. 2a) - the length of the read dump of the network traffic of the computing network d, necessary for the implementation of the cycle of updating the parameters of the device for generating and sending false network traffic 104 to the subnet.
[0071] Then, in the pre-set initial data, additionally set (see block 1 in Fig. 2a) L w - the length of vectors V jreal characteristics of the real topology and vectors V j rand characteristics of the false topology of the computing network d, where j ∈ [1, …, I], I is the number of vectors of characteristics of the real and false topology of the computing network d; V j rand =[ν rand j 1, …, V rand j Lw ], V j real =[νreal j 1, …, ν real j Lw ], ν real j 1∈ {0, 1},ν rand j 1∈ {0, 1} is the first element of the j-th vector V j rand characteristics of the real topology and the first element of the j-th vector V j rand characteristics of the false topology of the computing network d, respectively, the probability of the presence of the i-th unit element ν rand j i in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to P1(ν randj i =1)=p j rand, the probability of the presence of the i-th zero element ν rand j i in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to P0(ν rand j i =0)=1-p j rand accordingly, p j rand - estimate of the probability of the presence of unit elements in the j-th vector V j rand characteristics of the false topology of the computing network d, necessary for selecting the number of parameters and, accordingly, the complexity of the binary probabilistic model for calculating the topology of the false computing network.
[0072] After which, M is additionally set into the pre-set initial data (see block 1 in Fig. 2a) IP ={IP s bS ,lP d gD ) x ] - a memory array for storing the set H IP pairs of IP addresses of senders and recipients of network traffic of length X of a computing network d, where IP s bS ,IP dgD - IP addresses of senders and recipients of network traffic packets, respectively, x ∈ [1, …, X] is the network traffic packet number, bS ∈[1, …, B] is the number of the IP address of the sender of the network traffic packet, B is the number of unique IP addresses of senders of network traffic packets, gD ∈[1, …, G] is the number of the IP address of the recipient of the network traffic packet, G is the number of unique IP addresses of recipients of network traffic packets, H IP ={(IP s bS ,IP d gD ) x}.
[0073] Then, in the pre-set initial data, additionally set (see block 1 in Fig. 2a) M Ar =[[A r11 , …, A r11U ], [A rU1 , …, A rUU ]] - memory array for storing the adjacency matrix A r directed graph of the real topology of a computing network, reconstructed from a read dump of network traffic of a computing network d, where A r11∈ {0, 1} is the element of the first row and first column of the adjacency matrix, U=B+G is the dimension of the adjacency matrix equal to the number of unique IP addresses of sender and recipient nodes in the network traffic dump of the computing network d.
[0074] After which, the pre-set initial data is additionally set (see block 1 in Fig. 2a) Z real ={ V j real , …, V j real ) is a set of vectors of characteristics of the real topology of the computing network d.
[0075] Then, in the pre-set initial data, additionally set (see block 1 in Fig. 2a) M Vreal =[[V1 real ], …, [V I real ]] - a memory array for storing vectors of characteristics of the real topology of the computing network d.
[0076] Next, additionally set the pre-set initial data (see block 1 in Fig. 2a) P rand ={p rand 1, …, p rand I} - a set of point estimates of the probabilities of individual elements ν rand j i vectors V j rand characteristics of the false topology of the computing network d, i∈[1, …, Lw], j∈[1, …, I].
[0077] After which, M is additionally set into the pre-set initial data (see block 1 in Fig. 2a) θ =[p rand 1, …, p rand I ] - a memory array for storing the set P rand point estimates of the probabilities of individual elements ν rand j i vectors V j rand characteristics of the false topology of the computing network d, i∈[1, …, Lw], j∈ [1, …, I].
[0078] Next, additionally set (see block 1 in Fig. 2a) Z into the pre-set initial data rand = {V1 rand , …, V I rand ] is a set of vectors of characteristics of the false topology of the computing network d.
[0079] Then, in the pre-set initial data, additionally set (see block 1 in Fig. 2a) M Vrand =[[V1 rand ], …, [V I rand ]] - a memory array for storing vectors of characteristics of the false topology of the computing network d.
[0080] After which, M is additionally set into the pre-set initial data (see block 1 in Fig. 2a) Aƒ =[[A ƒ11 , …, A ƒ1U ], …, [A ƒU1 , …, A ƒUU ]] - a memory array for storing the adjacency matrix of the directed graph of the false topology of the computing network, calculated from a set of random vectors Z rand , where A ƒ11 ∈{0, 1} is an element of the first row and first column of the adjacency matrix A ƒ .
[0081] Next, additionally set M in the pre-set initial data (see block 1 in Fig. 2a) IP* =[(IP s* bS* , IP d* gD*) w ] - a memory array for storing a set of H* Ippairs of IP addresses of senders and recipients of false network traffic of length W, where IP s* bS *, IP d* gD* - IP addresses of senders and recipients of false network traffic packets, respectively, we[1, …, W] is the number of the false network traffic packet, bS*∈[1, …, B*] is the number of the IP address of the sender of the false network traffic packet, B* is the number of unique IP addresses of senders of false network traffic packets, gD*∈[1, …, G*] is the number of the IP address of the recipient of the false network traffic packet, G* is the number of unique IP addresses of recipients of false network traffic packets, H*IP={(IP s* bS* , IP d* gD* ) w}.
[0082] Then connect (see block 2 in Fig. 2a) the network devices to the computer network and after their initialization send (see block 3 in Fig. 2a) messages from the network devices of the computer network to the DHCP server with the IP address IP d dhcpto obtain the synchronization parameters of the set time zone, IP addresses and the duration of their lease t a p, subnet numbers d and IP addresses of the DHCP server IP d dhcp The protocol message exchange scheme between network devices and a DHCP server is known and described, for example, in technical specifications (RFC, Request for Comments) of the Internet (see, for example, https: / / tools.ietf.org / html / rfc2131).
[0083] After this, accept (see block 4 in Fig. 2a) the DHCP server with the IP address IP d dhcp messages from network devices of a computer network.
[0084] Then they form (see block 5 in Fig. 2a) messages for network devices containing the synchronization parameters of the set time zone and time, the assigned subnet number d, the IP address IP d and their lease time, IP address of the DHCP server IP d dhcpThe need to synchronize the set time zone and time arises when the server and network devices have different times, and the server may consider the lease to have expired before the network device does. Synchronization is achieved by setting a common time zone and time for the DHCP server and network devices.
[0085] Then the DHCP server sends (see block 6 in Fig. 2a) response messages containing the synchronization parameters of the set time zone and time, the assigned subnet number d, IP addresses IP* and their lease time, the IP address of the DHCP server IP d dhcp , for the network devices of the computing network that have made a request.
[0086] Receive (see block 7 in Fig. 2a) messages from the DHCP server by each network device of the computer network and send (see block 8 in Fig. 2a) response messages to the DHCP server confirming their selection of this DHCP server.
[0087] After this, the DHCP server receives (see block 9 in Fig. 2a) messages from the network devices of the computer network confirming their selection and sets (see block 10 in Fig. 2a) the network devices of the computer network the parameters for synchronizing the set time zone and time assigned to the subnet number d, IP addresses IP d and their lease time, IP address of the DHCP server IP d dhcp selected DHCP server.
[0088] Then they establish (see block 11 in Fig. 2a) the correspondence of MAC and IP addresses and store (see block 12 in Fig. 2a) this correspondence of MAC and IP addresses in the memory array N A .
[0089] Next, they delete (see block 13 in Fig. 2a) from the memory array Na those correspondences of the network devices of the computing network from which they have not received messages confirming their selection, thereby excluding the issuance of IP addresses to inactive network devices.
[0090] After this, connections are established between the network devices of the computing network (see block 14 in Fig. 2a) and CIP identifiers are assigned (see block 15 in Fig. 2a) to the established connections between the network devices of the computing network m .
[0091] Further established CIP identifiers m are stored (see block 16 in Fig. 2a) in the memory array C i .
[0092] Then read (see block 17 in Fig. 2a) X network traffic packets of the computing network d.
[0093] After which they remember (see block 18 in Fig. 2a) a set of pairs H IP IP addresses of senders and recipients of network traffic of length X of the computing network d in the memory array M IP .
[0094] Next, the adjacency matrix A is formed (see block 19 in Fig. 2a). rdirected graph of the real topology of the computing network, restored from the read dump of the network traffic of the computing network d and store (see block 20 in Fig. 2a) the adjacency matrix A r in the memory array M Ar. Adjacency matrix A r is the main topological invariant of the original computing network (see Fig. 3a, b) and is necessary for calculating the estimates of the model parameters (see Fig. 3a), generating a false topology of the computing network (see Fig. 3c, d, d).
[0095] Then the number I of characteristic vectors of the real and false topology of the computing network d is calculated (see block 21 in Fig. 2a). As a method for calculating the total number I of characteristic vectors of real and false computing networks, an integer is selected, obtained as a result of dividing the total number of elements in the adjacency matrix A r by the length of vectors L w , rounded up. Vectors V j real , V jrand are necessary for approximating the topological characteristics of a real computing network from a set of vectors V j rand and generating a random false topology from a set of random vectors V j rand The number of vectors I determines the degree of determinism of the false topology and the degree of closeness of the topological characteristics of the false and real computing networks, since the greater the number of vectors, the smaller the number L w elements (within the j-th vector) of the adjacency matrix of the false topology of the computing network are distributed randomly generated elements with a fixed probability p j rand , j∈[1, …, I], estimated based on the values of the elements of the vector of the real computing network V j real . As I decreases, an inverse relationship is observed, in the limit under conditions I=1, that is, at L w =U 2 (the length of the vector is equal to the number of elements in the entire adjacency matrix Ar or A ƒ ), the generated matrix Aƒ corresponds to the adjacency matrix of a random Erdős-Rényi graph with one parameter - the probability of the presence of an edge in the entire graph. The second limiting case is at I=U 2 , that is, when the number of estimates of the probabilities of the presence of edges in the false topology of the computing network corresponds to the number of cells of the adjacency matrix A r , in this case the matrix A r , is identically equal to A r .
[0096] After which the set Z is calculated (see block 22 in Fig. 2a) real (see Fig. 3a) vectors of characteristics of the real topology of the computing network d.
[0097] Next, the calculated values of the elements of the set Z are stored (see block 23 in Fig. 2a). real (see Fig. 3a) in the memory array M Vreal .
[0098] After which the set P is calculated (see block 24 in Fig. 2a) rand point estimates of probabilities (see Fig. 3a) of unit elements ν rand j ivectors V j rand characteristics of the false topology of the computing network d, i∈[1, …, L w ], j∈[1,…, I]. As a method for calculating estimates p j rand probabilities of unit elements in vectors V j rand characteristics of the false topology of the computing network in the set P rand choose to calculate the arithmetic mean values of the elements of vectors V j real characteristics of the real topology of a computing network d with the same index j ∈ [1, …, I]. This method is justified based on the low computational complexity of calculating the arithmetic mean of all elements of a vector of a fixed size.
[0099] Then the calculated values of the elements of the set P are stored (see block 25 in Fig. 2a) rand in the memory array M θ .
[0100] Next, calculate (see block 26 in Fig. 2a) the set Z rand(see Fig. 3a) vectors of characteristics of the false topology of the computing network d. As a method for calculating the vectors V j rand select a sequential independent generation of binary values from the set {0, 1} with fixed probabilities p j rand for single elements and with probability 1 - p j rand for zero elements of vectors V j rand , while the lengths of the sequences (the number of independent experiments with fixed conditions, that is, the probabilities of elementary outcomes) correspond to the length of the vectors L w .
[0101] After which the calculated values of the elements of the set Z are stored (see block 27 in Fig. 2a) rand memory array M νrand .
[0102] Next, the adjacency matrix A is calculated (see block 28 in Fig. 2a). ƒ from the elements of the set Z rand As a method for calculating the adjacency matrix A ƒdirected graph of the false topology of the computing network, a concatenation of vectors V is chosen rand characteristics of the false computing network with subsequent change in the dimension of the total array from the vector (U 2 , 1) on a square matrix (U, U). If the dimension of the array after concatenation exceeds the number of elements of U 2 matrices A r , then the corresponding number of elements are removed to the value U 2 The quality of the false topology of the computing network corresponding to the adjacency matrix A ƒ using the example of the considered real computing network A r allowed us to increase the average shortest distance D between critical nodes (with degrees of connectivity higher than the 95th percentile of all degrees of the real graph) from 1.62 to 2.31 hops (see Fig. 4, c), and reduce the degree of intersection of the set of false and real critical nodes on average with J crit1.0 to 0.043 (see Fig. 4, a, b), with some decrease in the degree of similarity between the real and false topology of the computing network J edge from 1.0 to 0.02 (see Fig. 4, g, d, e). At the same time, the admissible sets in the spaces of the considered quality indicators (see Fig. 4, g, e) show a relatively high elasticity of the quality indicators of the false topology of the computing network when changing the length of the vectors L w (calculations were carried out by successively changing the length L w vectors from 2 to 40,000 elements in 2000 steps).
[0103] Then the calculated adjacency matrix A / is stored in the memory array M (see block 29 in Fig. 2a). Aƒ and form (see block 30 in Fig. 2a) a set of pairs H* IP IP addresses of senders and recipients of packets of false network traffic of length W from the adjacency matrix A ƒ .
[0104] Next, remember (see block 31 in Fig. 2a) the set of pairs H* IPIP addresses of senders and recipients of false network traffic packets of length W in the memory array M* IP .
[0105] Then read (see block 32 in Fig. 2a) the set T del delays between network traffic packets of power V of a computing network d. Study of the properties of the set T del Delays between network traffic packets allow us to synthesize time series to generate false network traffic with dynamic properties close to real network traffic.
[0106] After this, the set T is stored (see block 33 in Fig. 26) del delays between network traffic packets of power V of the computing network d in the memory array M z .
[0107] Next, the value of the point estimate of the parameter is calculated (see block 34 in Fig. 26) exponential distribution law of a random variable Ω del delays between packets of network traffic of a computing network d.
[0108] After which (see block 35 in Fig. 2b) the calculated value of the point estimate of the parameter is stored exponential distribution law of a random variable Ω del delays between network traffic packets of a computing network d in a memory array M Р .
[0109] Then the values of τ are calculated (see block 36 in Fig. 2b) gen sets T gen delays between the moments of generation of false network traffic of the computing network d. To calculate the elements of τ gen sets T gen the expression can be used given in the book by B.Ya. Sovetov, S.A. Yakovlev. Modeling of Systems: 3rd ed., revised and enlarged. - M.: Higher School, 2001, on p. 137, where x i - a random number uniformly distributed in the interval (0, 1). A pseudo-random sequence generator for generating values x i can be implemented both in hardware and software (algorithmically).
[0110] After which the calculated values of τ are stored (see block 37 in Fig. 2b) gen sets T gen delays between the moments of time of generation of false network traffic of the computing network d in the memory array Mt.
[0111] Then a message packet is received (see block 38 in Fig. 2b) from the communication channel and the CIP information flow identifier is extracted (see block 39 in Fig. 2b) from the header of the received message packet. m .
[0112] After this, it is compared (see block 40 in Fig. 2b) with the identifiers of the authorized information flows TS to determine the possibility of further transmission of the packet to the addressee.
[0113] When the allocated CIP information flow identifier matches m with the identifier of authorized information flows TS transmit (see block 41 in Fig. 2b) a message packet to the recipient, and then receive (see block 38 in Fig. 2b) the next message packet from the communication channel.
[0114] In case of mismatch of the allocated CIP identifier m with the identifiers of authorized information flows TS, compare (see block 42 in Fig. 26) the IP address of the recipient in the received message packet with pre-set false IP addresses of subscribers of the FIP computing network d .
[0115] When the recipient's IP address in the received message packet does not match the pre-set false IP addresses of FIP subscribers d , ignore (see block 43 in Fig. 2b) the message packet.
[0116] Otherwise, if the recipient's IP address in the received message packet matches the pre-set false IP addresses of FIP subscribers d determine whether the sender of the message packet is an authorized subscriber or an intruder, for this purpose they compare (see block 44 in Fig. 2b) the IP address of the sender of the message packets with each IP address of the network device of the computer network from the set of IP d .
[0117] If they coincide, the IP address of the sender of the message packets is blocked, considering it a potential intruder, for which purpose the MAC address of this network device is excluded from the memory array N (see block 45 in Fig. 2b). A DHCP servers thereby isolate the intruder from further information exchange in the computer network during subsequent reconfiguration of the network parameters of devices and communication equipment of the computer network.
[0118] If they do not match, i.e., when the sender of message packets has an illegitimate IP address, the structural and functional characteristics of the network devices in the computing network are reconfigured. To do this, the DHCP server reads (see block 46 in Fig. 2b) the next subnet number d = d + 1 from array D to generate the parameters of the network devices in the new subnet, increasing the current network number d by one.
[0119] Then they generate (see block 47 in Fig. 2b) response messages from the DHCP server, containing the parameters of the set time zone and time, as well as new IP addresses. (d+l) , t values (d+1) max , the next subnet number d=d+1 and the IP address of the selected DHCP server IP (d+1) dhcp for each of the network devices in the computing network. Formation of a new value for the lease time of IP addresses of network devices in the computing network t (d+1) max are carried out to exclude the possibility of an intruder calculating the algorithm for restructuring IP addresses.
[0120] Next, they send (see block 48 in Fig. 2b) response messages from the DHCP server containing the parameters of the set time zone and time, as well as new IP addresses. (d+1) , t values (d+1) max , the next subnet number d=d+1 and the IP address of the selected DHCP server IP (d+1) dhcp network devices of the computer network.
[0121] Then each network device of the computing network receives (see block 49 in Fig. 2b) messages containing the synchronization parameters of the established time zone and time, new IP addresses and the duration of their lease t d+1 max , subnet number d=d+1 and IP address of the selected DHCP server IF (d+1) dhcp .
[0122] Next, in order to conceal the fact that security measures are being used and to mislead the intruder, a network device is installed in subnet d (see block 50 in Fig. 2b) to generate and direct information flows of false network traffic in this subnet.
[0123] After this, the network devices of subnet d are set (see block 51 in Fig. 2b), except for the network device for generating and directing information flows of false network traffic, the parameters for synchronizing the set time zone and time, the subnet number d = d+1, IP addresses IP (d+1) and the time of their rental t (d+1) max, IP address of the selected DHCP server I (d+1) dchp .
[0124] Then set (see block 52 in Fig. 2b) the IP address (d+1) dhcp DHCP server.
[0125] Next, since the network parameters of the devices in the computing network have changed, the memory array N is formed again (see block 53 in Fig. 2b). A for the new subnet d=d+1.
[0126] Then the generated false network traffic is sent (see block 54 in Fig. 2b) with delay intervals T gen between packets of false network traffic and IP addresses of senders and recipients of packets of false network traffic from the set H* IP to the original subnet d.
[0127] If the condition tt st >(b st +1)⋅t train is executed (see block 55 in Fig. 2b), which corresponds to the expiration of the time interval for updating the parameter estimate distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set Prand , then increase (see block 56 in Fig. 2b) the value of counter b st the number of reconfigurations of parameters of mathematical models per unit.
[0128] Then again read (see block 17 in Fig. 2a) X packets of network traffic of computing network d in order to ensure the specified topological characteristics of the generated false traffic in the subnet.
[0129] If the condition tt st >(b st +1)⋅t train is not performed (see block 55 in Fig. 26), which indicates that there is no need to update the parameter estimate distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set P rand , then compare (see block 57 in Fig. 2b) the time interval tt st from time t st up to the current time t with the time td of generating false network traffic of the computing network d.
[0130] If the condition t - t st >td is not fulfilled, then the generated false network traffic is sent (see block 54 in Fig. 2b) with delay intervals τ gen from the set T gen between packets and IP addresses of senders and recipients of packets of false network traffic from the set H* IP to the original subnet d.
[0131] If the condition tt st >t d is executed, then the value of the counter b is reduced (see block 58 in Fig. 2b) st number of parameter estimate updates distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set P rand to zero and complete (see block 59 in Fig. 2b) the direction of false traffic to subnet d.
[0132] After this, the network device (see block 60 in Fig. 26), from which the formation and direction of false network traffic to subnet d was carried out, is given new parameters for synchronization of the established time zone and time, the subnet number d=d+1, the IP address IP (d+1) and the time of its lease t (d+1) max , IP address of the selected DHCP server IP (d+1) dhcp .
[0133] Next, a memory array Na is again formed (see block 61 in Fig. 26) for storing the matrix of correspondence between the MAC and IP addresses of network devices in subnet d=d+1, taking into account the network device that appeared from subnet d, from which the formation and direction of false network traffic was carried out.
[0134] Next, a report is generated (see block 62 in Fig. 2b) containing the current values of the variables T gen , H* IP .
[0135] As a point parameter estimation method exponential distribution law of a random variable Ω deldelays between network traffic packets are determined using the maximum likelihood method, the model parameters are estimated by solving a scalar optimization problem with constraints, such as where 0 is the permissible set of parameter values L is the likelihood function (functional), for an exponential distribution the optimization problem has an analytical solution and can be represented in the form given in GOST R 50779.26-2007 (IEC 60605-4:2001). Point estimates, confidence, prediction and tolerance intervals for
[0136] Exponential Distribution on page 6: where T* is the total time for reading network traffic parameters.
[0137] A computer with installed software for generating network traffic, for example, PacketSender (http: / / packetsender.com), is selected as a device for generating and directing false network traffic to the subnet.
[0138] Thus, the claimed method improves the effectiveness of computer network protection by forming a false impression in the attacker's mind regarding the dynamic and topological characteristics of computer networks when generating false network traffic in the original subnet in accordance with mathematical models of the exponential distribution law of delays between sending network packets and a binary probability model with a vector estimate of the probabilities of observing single elements in the adjacency matrix of the topology of the false computer network. The visualization of the effect in the metrics of similarity and security indicators is presented in Figs. 4a-4e in the form of an increase in the approximation of the average shortest distance ΔD between false and real (original) critical nodes, a decrease in the intersection index of the sets of false and real critical nodes Δj crit, with some decrease in the similarity index between the sets of edges of the false and real (initial) topology of the computing network ΔJ edge .
Claims
1. A method for protecting computer networks, which consists of pre-setting IP={IP1,IP2, …, IP n} the set of IP addresses of network devices of the computer network that are DHCP clients of the DHCP server, where n is the maximum permissible value of the number of IP addresses of network devices of the computer network, also define subsets d in the set of IP addresses of network devices of the computer network IP d ={IP d 1, IP d 2, IP d n}, where d is the DHCP server subnet number, d=1, 2, …, z, where z is the maximum number of subnets, for each subset d, the IP addresses of the DHCP servers are specified d dhcp , where IP d dhcp - DHCP server IP address, IP d dhcp ∈ IP d , then pre-set the memory array D=[1, 2, …, z] to store the DHCP server subnet numbers and t d max- the maximum value of the lease time of all IP addresses of the subnet with number d, then set C={CIP1, CIP2, …, CIP m} a set of connections between network devices of a computing network, where CIP m - an identifier of the connection between network devices of the computing network, which contains the IP address of the sender c and the recipient b, the type of interaction protocol, the interaction ports, where m is the maximum allowable number of connections between network devices of the computing network, and also pre-sets the memory array C i =[CIP1, CIP2, …, CIP m ] for storing CIP identifiers m and the set of identifiers of authorized information flows TS ≥ 1, after this MAC={MAC1, MAC2, MAC l} a set of MAC addresses of network devices in a computer network, where l is the maximum number of network devices in the computer network, and the memory array N Ato store the matrix of correspondence to the n-th IP address of a network device from the set of IP addresses of the l-th MAC address from the MAC memory array, then specify the FIP d ={FIP d 1, FIP d 2, FIP d ƒ} is the set of IP addresses of false subscribers of subnet d, where ƒ is the maximum allowable number of IP addresses of network devices of subnet d, t is a time counter containing the value of the current time, t st - a time counter containing the value of the time of connection of network devices to the subnet, t train - the period of time after which it is necessary to update the parameter estimate distribution functions of a random variable Ω del delays between packets of a computing network d, b st - counter of the number of parameter estimate updates distribution functions of a random variable Ω del delays between packets of a computing network d, V is the power of the set T del values of τ deldelays between packets of network traffic of a computing network d, where T del= {τ del 1, τ2, …, τ del v} is the set of values of delays τ de1 between network traffic packets of power V of the computing network d, M z =[τ de1 1, τ de1 2, …, τ de1 v] - a memory array for storing the set T del delays τ de1 between network traffic packets of power V of the computing network d, W is the power of the set T gen values of τ gen delays between the moments of time of generation of false network traffic of the computing network d, where T gen ={τ gen 1, τ gen 2, …, τ gen w} is the set of values of τ gen delays between the moments of generation of false network traffic with the power W of the computing network d, M k =[τ gen 1, τ gen 2, …, τ gen w] is a memory array for storing the set T gen values of τ gendelays of power W between the moments of time of generation of false network traffic of the computing network d, - a memory array for storing the point estimate of the parameter exponential distribution law of a random variable Ω del delays between network traffic packets of a computing network d, time t d directing false network traffic to the subnet, connecting network devices to the computer network, sending messages from network devices to the DHCP server to obtain synchronization parameters for the set time zone and time, subnet number d, IP addresses IP d and the time of their lease, the IP address of the DHCP server IF d dhcp , receive messages from the DHCP server from network devices of the computer network, generate messages for network devices containing the synchronization parameters of the set time zone and time, assigned subnet number d, IP addresses IP dand their lease time, IP address of the DHCP server IP d dhcp , send the generated messages to the network devices of the computer network, receive a message from the DHCP server by each network device of the computer network, send response messages from the network devices of the computer network to the DHCP server confirming its choice, the DHCP server receives messages from the network devices of the computer network confirming its choice, sets the synchronization parameters of the established time zone and time, assigned subnet number d, IP address IP by the network device of the computer network d and their lease time, for the DHCP server IP address IP d dhcp , then establish the correspondence between MAC and IP addresses, and store the correspondence between MAC and IP addresses in the memory array N A , are removed from the memory array N A, those network device correspondences of the computing network from which they have not received messages confirming their selection establish connections between network devices of the computing network and assign CIP identifiers to the established connections between network devices of the computing network m , then remember the CIP identifiers m in the memory array C, read the set T del delays between network traffic packets of power V of the computing network d, remember the set T del delays between network traffic packets of power V of the computing network d in the memory array M z , calculate the value of the point estimate of the parameter exponential distribution law of a random variable Ω del delays between network traffic packets of a computing network d, store the calculated value of the point estimate of the parameter exponential distribution law of a random variable Ω deldelays between network traffic packets of a computing network d in a memory array M P , calculate the values of τ gen sets T gen delays between the moments of time of generation of false network traffic of the computing network d, the calculated values τ are stored gen sets T gen delays between the moments of time of generation of false network traffic of the computing network d in the memory array M k, receive a message packet from the communication channel, then extract the information flow identifier from the header of the received message packet, then compare it with the identifiers of the authorized information flows TS and, if the extracted information flow identifier matches the identifiers of the authorized information flows TS, transmit the message packet to the recipient, after which receive the next message packet from the communication channel, and if the extracted identifier does not match the identifiers of the authorized information flows TS, compare the recipient's IP address in the received message packet with the pre-set false IP addresses of the subscribers of the FIP computing network and, if the recipient's IP address in the received message packet does not match the pre-set false IP addresses of the subscribers of the RUR, ignore the message packet, and if the recipient's IP address in the received message packet matches the pre-set false IP addresses of the subscribers of the FIP,compare the IP address of the sender of message packets with each IP address of a network device in a computing network from a set of IPs, d , if they match, the MAC address of the network device is excluded from the array N A DHCP servers, and if they do not match, the DHCP server reads from array D the next d=d+1 subnet number, after which messages are generated for network devices containing new synchronization parameters for the established time zone and time, subnet number d=d+1, IP addresses IP (d+1) and the time of their rental t (d+1) max , DHCP server IP address IP (d+1) dhcp , then send generated messages from the DHCP server to the network devices of the computer network, containing new synchronization parameters for the established time zone and time, the subnet number d=d+1, IP addresses IP (d+1) and the time of their rental t (d+1) max, then each network device in the computer network receives messages containing new synchronization parameters for the established time zone and time, subnet number d=d+1, IP addresses IP (d+1) their rental time t (d+1) max , set up a network device in subnet d for generating and directing information flows of false network traffic in this subnet, after which set up the network devices of subnet d, except for the network device for generating and directing information flows of false network traffic, the synchronization parameters of the established time zone and time, the subnet number d=d+1, IP addresses IP (d+1) and the time of their rental t (d+1) max , IP address of the selected DHCP server IP (d+1) dhcp , then again form the memory array N Ato store the matrix of correspondence between MAC and IP addresses of network devices in the computer network, complete the direction of false network traffic to the original subnet d, assign to the network device from which the formation and direction of false network traffic to subnet d was carried out new synchronization parameters for the established time zone and time, subnet number d=d+1, IP address IP (d+1) and the time of its lease t (d+1) max , IP address of the selected DHCP server IP (d+1) dhcp , then again form the memory array N A for storing the matrix of correspondence between MAC and IP addresses of network devices in subnet d=d+1, taking into account the network device that emerged from subnet d, from which the formation and direction of false network traffic was carried out, characterized in that X, the length of the read dump of network traffic of the computing network d, L, is additionally specified in the pre-set initial data w - the length of vectors V j realcharacteristics of the real topology and vectors V j rand characteristics of the false topology of the computing network d, where j ∈ [1, …, I], I is the number of vectors of characteristics of the real and false topology of the computing network d, V j rand =[ν rand j 1, …, ν rand j Lw ], V j real =[ν real j 1, …, ν real j Lw ], ν real j 1∈ {0, 1}, ν rand j 1∈ {0, 1} is the first element of the j-th vector V j rand characteristics of the real topology and the first element of the j-th vector V j rand characteristics of the false topology of the computing network d, respectively, the probability of the presence of the i-th unit element ν rand j i in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to P1(ν rand j i =1)=p j rand, the probability of the presence of the i-th zero element ν rand j i in the j-th vector V j rand characteristics of the false topology of the computing network d is equal to P0(ν rand j i =0)=1-p j rand accordingly, p j rand - estimate of the probability of the presence of unit elements in the j-th vector V j rand characteristics of the false topology of the computing network d, M IP =[(IP s bS ,IP d gD ) x ] - a memory array for storing the set H IP pairs of IP addresses of senders and recipients of network traffic of length X of a computing network d, where IP s bS , IP d gD- IP addresses of senders and recipients of network traffic packets, respectively, x ∈ [1, X] is the network traffic packet number, bS ∈ [1, …, B] is the number of the IP address of the sender of the network traffic packet, B is the number of unique IP addresses of senders of network traffic packets, gD ∈ [1, …, G] is the number of the IP address of the recipient of the network traffic packet, G is the number of unique IP addresses of recipients of network traffic packets, H IP ={(IP s bS ,IP d gD ) x}, M Ar =[[A r11 , …, A r1U ], …, [A rU1 , …, A rUU ]] - memory array for storing the adjacency matrix A r directed graph of the real topology of a computing network, reconstructed from a read dump of network traffic of a computing network d, where A r11∈ {0, 1} is the element of the first row and first column of the adjacency matrix, U=B+G is the dimension of the adjacency matrix equal to the number of unique IP addresses of sender and recipient nodes in the network traffic dump of the computing network d, Z real ={V1 real , …,V1 real ) - a set of vectors of characteristics of the real topology of the computing network d, M Vreal =[[V1 rea1 ], …, [V I real ]] - a memory array for storing vectors of characteristics of the real topology of the computing network d, P rand ={p rand 1, …, p rand I ) is a set of point estimates of the probabilities of individual elements ν rand j i vectors V j rand characteristics of the false topology of the computing network d, i ∈ [1, …, Lw], j∈[1, …, I], M θ =[p rand 1, …, p rand I ] - a memory array for storing the set P rand point estimates of the probabilities of individual elements v rand ji vectors V j rand characteristics of the false topology of the computing network d, i ∈ [1, Lw], j∈[1, …, I], Z rand ={V1 rand , …, V I rand} - a set of vectors of characteristics of the false topology of the computing network, M Vrand =[[V1 rand ], …, [V I rannd ]] - a memory array for storing vectors of characteristics of the false topology of the computing network d, M Aƒ =[[A ƒ11 , …, A ƒ1U ], …, [A ƒU1 , …, A ƒUU ]] - a memory array for storing the adjacency matrix of the directed graph of the false topology of the computing network, calculated from a set of random vectors Z rand , where A ƒ11 ∈ {0,1} is an element of the first row and first column of the adjacency matrix A ƒ , M IP* =[(IP s* bS* , IP d * gD* ) w ] - a memory array for storing a set of H* IPpairs of IP addresses of senders and recipients of false network traffic of length W, where IP s* bS* , IP d * gD* - IP addresses of senders and recipients of false network traffic packets, respectively, w∈[1, …, W] is the number of the false network traffic packet, bS*∈[1, …, B*] is the number of the IP address of the sender of the false network traffic packet, B* is the number of unique IP addresses of senders of false network traffic packets, gD*∈[1, …, G*] is the number of the IP address of the recipient of the false network traffic packet, G* is the number of unique IP addresses of recipients of false network traffic packets, H* IP ={(IP s* bS* , IP d* gD* ) w}, then after memorizing the CIP identifiers m in the memory array C, read X packets of network traffic of the computing network d, read X packets of network traffic of the computing network d, store a set of pairs H IPIP addresses of senders and recipients of network traffic of length X of the computing network d in the memory array M IP , form the adjacency matrix A r directed graph of the real topology of the computing network, restored from the read dump of the network traffic of the computing network d, the adjacency matrix A is stored r in the memory array M Ar , calculate the number I of characteristic vectors of the real and false topology of the computing network d, calculate the set Z real vectors of characteristics of the real topology of the computing network d, store the calculated values of the elements of the set Z real in the memory array M Vreal , calculate the set P rand point estimates of the probabilities of individual elements ν rand j i vectors V j rand characteristics of the false topology of the computing network d, i∈[1, …, Lw], j∈[1, …, I], store the calculated values of the elements of the set P rand in the memory array Mθ , calculate the set Z rand vectors of characteristics of the false topology of the computing network d, store the calculated values of the elements of the set Z rand in memory array V Vrand , calculate the adjacency matrix A ƒ from the elements of the set Z rand , remember the calculated adjacency matrix A ƒ in the memory array M Aƒ , form a set of pairs H* IP IP addresses of senders and recipients of packets of false network traffic of length W from the adjacency matrix A ƒ , remember a set of pairs H* IP IP addresses of senders and recipients of false network traffic packets of length W in the memory array M* IP , after forming the memory array N A to store the matrix of correspondence between MAC and IP addresses of network devices in a computing network, generated false network traffic is sent with delay intervals T genbetween packets of false network traffic and IP addresses of senders and recipients of packets of false network traffic from the set H* IP to the original subnet d, if the condition t - t st >{b st +1)⋅t train is executed, which corresponds to the expiration of the time interval for updating the parameter estimate distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set Pr and , then the value of the counter b is increased st the number of reconfigurations of the parameters of mathematical models per unit, read X packets of network traffic of the computing network d, if the condition t - t st >(b st +1)⋅t train is not met, indicating that there is no need to update the parameter estimate distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set P rand, then compare the time interval t - t st from time t st up to the current time t with time t d generation of false network traffic of the computing network d, if the condition t - t st >t d is not met, then the generated false network traffic is sent with delay intervals τ gen from the set T gen between packets and IP addresses of senders and recipients of packets of false network traffic from the set H* IP to the original subnet d, if the condition t - t st >t d is executed, then the value of counter b is decreased st number of parameter estimate updates distribution functions of a random variable Ω del delays between packets of the computing network d and elements of the set P rand to zero.
2. The method according to paragraph 1, characterized in that as a method for calculating the total number I of characteristic vectors of real and false computing networks, an integer is selected, obtained as a result of dividing the total number of elements in the adjacency matrix A r by the length of vectors L w , rounded up.
3. The method according to paragraph 1, characterized in that as a method for calculating the probability estimates of unit elements in vectors V j rand characteristics of the false topology of the computing network in the set P rand choose to calculate the arithmetic mean values of the elements of vectors V j real characteristics of the real topology of a computing network d with the same index j ∈ [1, …, I].
4. The method according to paragraph 1, characterized in that as a method for calculating the adjacency matrix A ƒ directed graph of the false topology of the computing network, a concatenation of vectors V is selected randcharacteristics of the false computing network with subsequent change in the dimension of the total array from the vector (U 2 , 1) on a square matrix (U, U), if the dimension of the array after concatenation exceeds the number of elements U 2 matrices A r , then the corresponding number of elements are removed to the value U 2 .