The invention discloses a high-interaction deception defense and
attack tracing method based on an
RASP technology, and the method specifically comprises the following steps: S1,
RASP implantation and bait deployment, S2,
attack detection and
simulation triggering, S3,
attack session redirection and high-interaction deception, S4, attack
behavior monitoring and tracing data collection, and S5, tracing analysis and
threat disposal. The invention relates to the technical field of network and
information security. According to the high-interaction deception defense and attack tracing method based on the
RASP technology, a deception mechanism is embedded into a real application /
system in operation, and high fusion of a real
business environment and a false
trapping environment is achieved. Different from a traditional'main-auxiliary separation 'mode that a
honeypot is placed in an independent network or a host, the method has the
advantage that the application can be changed to generate a'trap' during running through the RASP. The seamless embedded spoofing makes attackers difficult to distinguish true and false: the attackers attack a part of a production
system initially, and then are introduced into a
parallel simulation space unconsciously.