Honey pot operation method using dark web decoy information and computing device for performing same
By using dark web bait information to attract attackers to honeypots, the method enhances the detection and analysis of malicious activities while assessing the risk of dark web portal sites, addressing the limitations of existing honeypot systems.
Patent Information
- Application Number
- PCT/KR2023/018633
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-13
- Filing Date
- 2023-11-20
- Publication Date
- 2025-05-22
AI Technical Summary
Existing honeypot systems are not effectively exposed to attackers due to lack of awareness about honeypot information, reducing their usability and increasing the risk of undetected attacks, especially with the exposure of personal information on dark web portal sites.
A method for operating a honeypot using dark web bait information involves creating honeypots, generating bait information, and posting link information on dark web portal sites to attract attackers, while analyzing network traffic to identify intrusion paths and measure risk levels of dark web portal sites.
This approach increases the number and frequency of attacks on honeypots, allowing for efficient collection and analysis of malicious activities, and provides a means to calculate the risk level of dark web portal sites based on network traffic patterns.
Smart Images

Figure KR2023018633_22052025_PF_FP_ABST
Abstract
Description
A method for operating a honeypot using dark web lure information and a computing device for performing the same.
[0001] An embodiment of the present invention relates to a honeypot technology using dark web lure information.
[0002] A honeypot is a technology used in computer security. It involves deploying physical or virtual systems and applications within a computing environment to detect and analyze attacks by attackers (hackers). While these systems are not actually in use, they are designed to create the illusion of a real system for attackers, thereby inducing attacks. This allows for analysis and tracing of attacker techniques and patterns.
[0003] Honeypots must be easily exposed to attackers and appear vulnerable, suggesting they are easily hacked. This means that even if a honeypot system is installed, attackers will be unable to access it if they don't know the honeypot information, reducing its usability. Furthermore, numerous cases of damage have been reported on dark web portals, including personal information or information from hacked sites. Therefore, tackling these attacks and strengthening security is essential.
[0004] An embodiment of the present invention provides a honeypot operation method using dark web lure information that can increase the number and frequency of attacks by attackers on a honeypot, and a computing device for performing the same.
[0005] A method for operating a honeypot using dark web decoy information according to one embodiment of the present disclosure is a method performed on a computing device having one or more processors and a memory storing one or more programs executed by the one or more processors, the method comprising: creating one or more honeypots in a honeypot network; creating decoy information corresponding to the honeypots and posting the created decoy information on a dark web camouflage site; and posting link information of the decoy information on one or more dark web portal sites.
[0006] The above-mentioned lure information may include one or more of network information for accessing the service of the honeypot, account information for accessing the user account of the honeypot, and email account information for accessing the email of the honeypot.
[0007] The step of posting on the above dark web portal site may include the step of collecting a list of dark web portal sites existing on the dark web; the step of posting link information of the above enticing information on each of the collected dark web portal sites; and the step of matching and storing the link information of the above enticing information and the dark web portal site on which the link information is posted.
[0008] The above honeypot operating method may further include a step of receiving network traffic; a step of checking whether the network traffic includes link information of the lure information; and a step of connecting the network traffic to a honeypot network or a user network depending on whether the network traffic includes link information of the lure information.
[0009] The above connecting step may include a step of connecting the network traffic to a honeypot corresponding to the lure information in the honeypot network when the network traffic includes link information of the lure information.
[0010] The above honeypot operation method may further include a step of confirming an attacker's inflow path based on link information of lure information included in the network traffic.
[0011] The above honeypot operation method may further include a step of measuring the risk of a dark web portal site that serves as an inflow path for the attacker based on at least one of the number and frequency of network traffic connected to the honeypot.
[0012] A computing device according to one embodiment disclosed comprises one or more processors and a memory storing one or more programs executed by the one or more processors, and is a computing device for operating a honeypot using dark web decoy information, the computing device comprising a honeypot management module for creating one or more honeypots in a honeypot network; and a decoy information distribution module for creating decoy information corresponding to the honeypot, posting the created decoy information on a dark web camouflage site, and posting link information of the decoy information on one or more dark web portal sites.
[0013] The above-mentioned lure information distribution module collects a list of dark web portal sites existing on the dark web, posts link information of the lure information on each of the collected dark web portal sites, and matches and stores the link information of the lure information and the dark web portal site on which the link information is posted.
[0014] The computing device may further include a traffic management module that receives network traffic, determines whether the network traffic includes link information of the lure information, and connects the network traffic to a honeypot network or a user network depending on whether the network traffic includes link information of the lure information.
[0015] The traffic management module may, if the network traffic includes link information of the lure information, connect the network traffic to a honeypot corresponding to the lure information in the honeypot network.
[0016] The above traffic management module can identify the attacker's inflow path based on link information of the lure information included in the network traffic.
[0017] The above traffic management module can measure the risk of a dark web portal site that serves as an inflow path for the attacker based on at least one of the number and frequency of network traffic connected to the honeypot.
[0018] According to the disclosed embodiment, by posting link information of baiting information on a dark web portal site where many attackers are active, attackers can be induced to a honeypot network, thereby increasing the number and frequency of attacks by attackers on the honeypot network, and efficiently collecting and analyzing malicious actions of attackers.
[0019] Additionally, by analyzing network traffic connected to the honeypot network, the risk level for each dark web portal site can be calculated, which allows the extent of attacker activity on each dark web portal site to be identified.
[0020] Figure 1 is a diagram showing a honeypot system using dark web lure information according to one embodiment of the present invention.
[0021] Figure 2 is a block diagram showing the configuration of an attack induction management device according to one embodiment of the present invention.
[0022] FIG. 3 is a diagram schematically illustrating a situation in which link information of enticing information posted on a dark web camouflage site is posted on a dark web portal site in one embodiment of the present invention.
[0023] Figure 4 is a flowchart illustrating a honeypot operation method using dark web lure information according to one embodiment of the present invention.
[0024] FIG. 5 is a block diagram illustrating a computing environment including a computing device suitable for use in exemplary embodiments.
[0025] Hereinafter, specific embodiments of the present invention will be described with reference to the drawings. The following detailed description is provided to facilitate a comprehensive understanding of the methods, devices, and / or systems described herein. However, these are merely examples and the present invention is not limited thereto.
[0026] In describing embodiments of the present invention, if a detailed description of a known technology related to the present invention is judged to unnecessarily obscure the gist of the present invention, the detailed description will be omitted. In addition, the terms described below are terms defined in consideration of their functions in the present invention, and this may vary depending on the intention or custom of the user or operator. Therefore, the definitions should be made based on the contents throughout this specification. The terminology used in the detailed description is only for the purpose of describing embodiments of the present invention and should not be limited in any way. Unless clearly used otherwise, the singular form includes the plural form. In this description, expressions such as "comprises" or "having" are intended to indicate certain features, numbers, steps, operations, elements, parts or combinations thereof, and should not be construed to exclude the presence or possibility of one or more other features, numbers, steps, operations, elements, parts or combinations thereof other than those described.
[0027] In the following description, the terms "transmission," "communication," "sending," "receiving," and other similar terms for signals or information include not only the direct transmission of signals or information from one component to another, but also transmission via another component. In particular, "transmitting" or "sending" a signal or information to one component indicates the final destination of the signal or information, and does not mean the direct destination. The same applies to "receiving" a signal or information. In addition, in this specification, the "relationship" of two or more pieces of data or information means that when one piece of data (or information) is acquired, at least a portion of the other piece of data (or information) can be acquired based on it.
[0028] Additionally, while terms such as "first" and "second" may be used to describe various components, these components should not be limited by these terms. These terms may be used to distinguish one component from another. For example, without departing from the scope of the present invention, a first component may be referred to as a "second component," and similarly, a second component may also be referred to as a "first component."
[0029] FIG. 1 is a diagram illustrating a honeypot system using dark web lure information according to one embodiment of the present invention.
[0030] Referring to FIG. 1, a honeypot system (100) may include an attack induction management device (102), an attacker terminal (104), a user terminal (106), a honeypot network (108), and a user network (110).
[0031] Here, the attacker terminal (104) and the user terminal (106) can be mutually communicatively connected to the attack induction management device (102) via a communication network (150). In one embodiment, the communication network (150) can include the Internet, one or more local area networks, wide area networks, a cellular network, a mobile network, other types of networks, or a combination of these networks.
[0032] The attack induction management device (102) may be a device for inducing an attacker (i.e., an attacker terminal (104)) by using bait information posted on a dark web camouflage site. FIG. 2 is a block diagram showing the configuration of the attack induction management device (102) according to one embodiment of the present invention. Referring to FIG. 2, the attack induction management device (102) may include a honeypot management module (111), a bait information distribution module (113), and a traffic management module (115).
[0033] The honeypot management module (111) can create one or more honeypots (121) in the honeypot network (108). The honeypot management module (111) can create honeypots (121) in the honeypot network (108) that correspond to each decoy information distributed by the decoy information distribution module (113). In one embodiment, the honeypot (121) may be configured to provide a specific service or configured to be a specific user or email account. The honeypot (121) may be implemented as physical hardware or implemented through a virtual device.
[0034] A honeypot (121) may be arranged to collect attack behaviors of an attacker terminal (104) and transmit them to a honeypot management module (111). The honeypot management module (111) may analyze attack behaviors of an attacker terminal (104) collected from each honeypot (121).
[0035] The decoy information distribution module (113) may serve to distribute decoy information to lure an attacker terminal (104). Specifically, the decoy information distribution module (113) may create a dark web disguised site and post decoy information on the created dark web disguised site. Here, the dark web disguised site is a type of dark web site created to lure an attacker terminal (104), and may be a site that is configured to be accessible through a dedicated browser such as Tor.
[0036] The decoy information posted on the dark web disguised site may include network information (e.g., IP address and port information) required to access the honeypot (121) service. Furthermore, the decoy information may include account information (e.g., ID and password) required to access the honeypot (121) user account. Furthermore, the decoy information may include email account information required to access the honeypot (121) email.
[0037] The decoy information distribution module (113) can post link information for each decoy posted on a dark web disguised site on one or more dark web portal sites. Here, a dark web portal site refers to a dark web portal site that already exists and where hackers are active. In other words, a dark web portal site may be a portal site that actually exists on the dark web. The decoy information distribution module (113) can collect a list of dark web portal sites using a dark web crawler or the like.
[0038] Figure 3 is a schematic diagram illustrating a situation in which link information for baiting information posted on a dark web camouflaged site is posted on a dark web portal site in one embodiment of the present invention. Referring to Figure 3, the baiting information distribution module (113) can collect link information for each baiting information posted on the dark web camouflaged site and post it on the collected dark web portal site. At this time, the baiting information distribution module (113) can match and store the link information for the baiting information and the dark web portal site. In other words, it can match and store the link information for each baiting information and the dark web portal site on which it is posted.
[0039] The traffic management module (115) can manage network traffic for accessing the honeypot network (108) or the user network (110). The traffic management module (115) can analyze the network traffic to determine whether the network traffic contains link information of the decoy information. The traffic management module (115) can connect the network traffic to the honeypot network (108) or the user network (110) depending on whether the network traffic contains link information of the decoy information.
[0040] Specifically, if network traffic contains link information of lure information, the traffic management module (115) can determine that the network traffic is from an attacker terminal (104) and connect the network traffic to a honeypot network (108). At this time, the traffic management module (115) can connect the network traffic to a honeypot (121) corresponding to the lure information included in the network traffic.
[0041] On the other hand, if the network traffic does not contain link information of the lure information, the traffic management module (115) determines that the network traffic is from the user terminal (106) and can connect the network traffic to the user network (110).
[0042] When the traffic management module (115) connects network traffic to the honeypot network (108), it can identify the attacker's inflow path based on the link information of the lure information included in the network traffic. That is, since the link information of the lure information and the dark web portal site are matched and stored, by checking the link information of the lure information included in the network traffic, it is possible to determine which dark web portal site the network traffic originated from, thereby identifying the attacker's inflow path.
[0043] The traffic management module (115) can measure the risk level of each dark web portal site based on network traffic connected to the honeypot network (108). The traffic management module (115) can measure the risk level of the corresponding dark web portal site based on at least one of the number and frequency of network traffic connected to the honeypot network (108).
[0044] Meanwhile, the attacker terminal (104) may be a variety of wired or wireless devices that perform security attacks. The attacker terminal (104) can access a dark web portal site and obtain link information that allows access to lure information on a disguised dark web site. That is, since information about dark web sites is posted on dark web portal sites, attackers access the dark web portal site to obtain such information. In the disclosed embodiment, the link information for lure information is posted on the dark web portal site, and the attacker who accesses the dark web portal site clicks on it to obtain the link information for the lure information.
[0045] Here, since the lure information is intended to lure the attacker to the honeypot network (108), the attacker terminal (104) that has acquired the link information of the lure information transmits network traffic containing the link information of the lure information to the attack induction management device (102). Then, the attack induction management device (102) connects the network traffic to the honeypot network (108) to lure the attacker to the honeypot (121) corresponding to the lure information.
[0046] The user terminal (106) is a normal user terminal for using the service provided by the user network (110). The user terminal (106) can transmit network traffic for using the service to the attack induction management device (102). Then, since the attack induction management device (102) does not contain link information for the lure information in the network traffic, it connects the network traffic to the user network (110).
[0047] According to the disclosed embodiment, by posting link information of baiting information on a dark web portal site where many attackers are active, attackers can be induced to a honeypot network (108), thereby increasing the number and frequency of attacks by attackers on the honeypot network (108), and efficiently collecting and analyzing malicious actions of attackers.
[0048] In addition, by analyzing network traffic connected to the honeypot network (108), the risk level for each dark web portal site can be calculated, thereby making it possible to check the level of activity of attackers on each dark web portal site.
[0049] As used herein, the term "module" may refer to a functional and structural combination of hardware for implementing the technical concepts of the present invention and software for operating the hardware. For example, the term "module" may refer to a logical unit of a given code and hardware resources for executing the given code, and does not necessarily refer to physically connected code or a single type of hardware.
[0050] Figure 4 is a flowchart illustrating a honeypot operation method utilizing dark web lure information according to one embodiment of the present invention. While the illustrated flowchart divides the method into multiple steps, at least some of the steps may be performed in a different order, combined with other steps, omitted, divided into substeps, or performed with one or more additional steps not shown.
[0051] Referring to FIG. 4, the attack induction management device (102) can create one or more honeypots (121) in the honeypot network (108) (S 101).
[0052] Next, the attack induction management device (102) can generate lure information corresponding to each honeypot (121) and post the generated lure information on a dark web camouflage site (S 103).
[0053] Next, the attack induction management device (102) can post link information of each lure information posted on the dark web camouflage site on one or more dark web portal sites (S 105).
[0054] Next, the attack induction management device (102) can check whether the received network traffic includes link information of the lure information (S 107).
[0055] As a result of the verification of S 107, if the network traffic contains link information of the lure information, the attack induction management device (102) can connect the network traffic from the honeynet network (108) to the honeypot (121) corresponding to the lure information (S 109).
[0056] Next, the attack induction management device (102) can measure the risk level of each dark web portal site based on network traffic connected to the honeypot network (108) (S 111).
[0057] The attack induction management device (102) can identify the attacker's inflow path based on link information of the lure information included in network traffic, and measure the risk of a dark web portal site that serves as the attacker's inflow path based on at least one of the number and frequency of network traffic connected to the honeypot network (108).
[0058] As a result of the verification of S 107, if the network traffic does not contain link information of the lure information, the attack induction management device (102) can connect the network traffic to the user network (111) (S 113).
[0059] FIG. 5 is a block diagram illustrating a computing environment (10) including a computing device suitable for use in exemplary embodiments. In the illustrated embodiment, each component may have different functions and capabilities other than those described below, and may include additional components other than those described below.
[0060] The illustrated computing environment (10) includes a computing device (12). In one embodiment, the computing device (12) may be an attack induction management device (102). Additionally, the computing device (12) may be an attacker terminal (104). Additionally, the computing device (12) may be a user terminal (106).
[0061] A computing device (12) includes at least one processor (14), a computer-readable storage medium (16), and a communication bus (18). The processor (14) may cause the computing device (12) to operate according to the exemplary embodiments mentioned above. For example, the processor (14) may execute one or more programs stored in the computer-readable storage medium (16). The one or more programs may include one or more computer-executable instructions, which, when executed by the processor (14), may be configured to cause the computing device (12) to perform operations according to the exemplary embodiments.
[0062] A computer-readable storage medium (16) is configured to store computer-executable instructions or program code, program data, and / or other suitable forms of information. A program (20) stored in the computer-readable storage medium (16) includes a set of instructions executable by the processor (14). In one embodiment, the computer-readable storage medium (16) may be a memory (volatile memory such as random access memory, non-volatile memory, or a suitable combination thereof), one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, any other form of storage medium that is accessible by the computing device (12) and capable of storing desired information, or a suitable combination thereof.
[0063] A communication bus (18) interconnects various other components of the computing device (12), including the processor (14) and computer-readable storage media (16).
[0064] The computing device (12) may also include one or more input / output interfaces (22) that provide interfaces for one or more input / output devices (24) and one or more network communication interfaces (26). The input / output interfaces (22) and the network communication interfaces (26) are connected to the communication bus (18). The input / output devices (24) may be connected to other components of the computing device (12) via the input / output interfaces (22). Exemplary input / output devices (24) may include input devices such as pointing devices (such as a mouse or a trackpad), a keyboard, a touch input device (such as a touchpad or a touchscreen), a voice or sound input device, various types of sensor devices and / or photographing devices, and / or output devices such as display devices, printers, speakers and / or network cards. The exemplary input / output devices (24) may be included within the computing device (12) as a component constituting the computing device (12), or may be connected to the computing device (12) as a separate device distinct from the computing device (12).
[0065] While representative embodiments of the present invention have been described in detail above, those skilled in the art will appreciate that various modifications to the above-described embodiments are possible without departing from the scope of the present invention. Therefore, the scope of the present invention should not be limited to the described embodiments, but should be defined not only by the claims set forth below but also by equivalents thereof.
Claims
1. One or more processors, and A method performed on a computing device having a memory storing one or more programs executed by one or more processors, A step of creating one or more honeypots in a honeypot network; A step of generating a decoy corresponding to the above honeypot and posting the generated decoy on a dark web camouflaged site; and A method for operating a honeypot using dark web bait information, comprising the step of posting link information of the above bait information on one or more dark web portal sites.
2. In claim 1, The above information is, A method for operating a honeypot using dark web bait information, comprising at least one of network information for accessing the service of the honeypot, account information for accessing a user account of the honeypot, and email account information for accessing the email of the honeypot.
3. In claim 1, The steps for posting on the above dark web portal site are: Step of collecting a list of dark web portal sites existing on the dark web; Step of posting the link information of the above-mentioned lure information on each of the collected dark web portal sites; and A honeypot operation method using dark web baiting information, comprising a step of matching and storing link information of the above baiting information and a dark web portal site on which the link information is posted.
4. In claim 3, The above honeypot operation method is, Step of receiving network traffic; A step of checking whether the above network traffic includes link information of the above lure information; and A method for operating a honeypot using dark web bait information, further comprising a step of connecting the network traffic to a honeypot network or a user network depending on whether link information of the bait information is included.
5. In claim 4, The above connecting steps are: A method for operating a honeypot using dark web bait information, comprising a step of connecting the network traffic to a honeypot corresponding to the bait information in the honeypot network when the network traffic includes link information of the bait information.
6. In claim 5, The above honeypot operation method is, A honeypot operation method using dark web bait information, further comprising a step of confirming an attacker's inflow path based on link information of bait information included in the above network traffic.
7. In claim 6, The above honeypot operation method is, A method for operating a honeypot using dark web lure information, further comprising a step of measuring the risk of a dark web portal site that serves as an inflow path for the attacker based on at least one of the number and frequency of network traffic connected to the honeypot.
8. One or more processors, and A computing device having a memory storing one or more programs executed by one or more processors, and operating a honeypot using dark web bait information, A honeypot management module that creates one or more honeypots in a honeypot network; and A computing device comprising a decoy information distribution module that generates decoy information corresponding to the honeypot, posts the generated decoy information on a dark web camouflage site, and posts link information of the decoy information on one or more dark web portal sites.
9. In claim 8, The above-mentioned lure information distribution module is, A computing device that collects a list of dark web portal sites existing on the dark web, posts link information of said lure information on each of the collected dark web portal sites, and matches and stores the link information of said lure information and the dark web portal sites on which said link information is posted.
10. In claim 9, The above computing device, A computing device further comprising a traffic management module for receiving network traffic, determining whether the network traffic includes link information of the lure information, and connecting the network traffic to a honeypot network or a user network depending on whether the network traffic includes link information of the lure information.
11. In claim 10, The above traffic management module, A computing device that connects the network traffic to a honeypot corresponding to the bait information in the honeypot network when the network traffic includes link information of the bait information.
12. In claim 11, The above traffic management module, A computing device that identifies an attacker's inflow path based on link information of lure information included in the above network traffic.
13. In claim 12, The above traffic management module, A computing device that measures the risk of a dark web portal site that serves as an inflow path for attackers based on at least one of the number and frequency of network traffic connected to the honeypot.
Citation Information
Patent Citations
Apparatus and method for intrusion detection using client terminal, system and method for network security of the same
KR1020090106197A
A honeypot deployment method on a network
KR102259732B1
Detecting automated site scans
US20150067848A1
Dynamically Configuring A Honeypot
US20190132359A1
Anti-hacker system with honey pot
WO2006131124A1