The application discloses a kind of based on defining organization
attack preference guard graph decision method and
system, its method includes steps: from the log
server of
honeypot collection
attack information, through the joint search of
threat intelligence
knowledge graph and external
threat intelligence
library, ascription defines the behavior mode of
attack organization, and the attack preference of attack organization is sorted;From the perspective of attacker, through the
topological information in target network, asset information and configuration information generation
attack graph, and the mapping of defining organization attack preference to
attack graph node is carried out, generates guard graph, and then generates the guard matrix for quantifying calculation
attack graph attack mode preference influence;Based on the analysis of the guard matrix of attack graph to defining organization attack preference, with emphasis, generate
honeypot service, provide decision support for the deployment of defense measures.The application can more flexible quickly generate the type of
honeypot service, greatly saves manpower and
time cost for the analysis and deployment of deception defense.