Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

139 results about "Honeypot" patented technology

In computer terminology, a honeypot is a computer security mechanism set to detect, deflect, or, in some manner, counteract attempts at unauthorized use of information systems. Generally, a honeypot consists of data (for example, in a network site) that appears to be a legitimate part of the site, but is actually isolated and monitored, and that seems to contain information or a resource of value to attackers, who are then blocked. This is similar to police sting operations, colloquially known as "baiting" a suspect.

Honeynet-based attack trapping and analyzing method and system

The invention discloses an attack trapping and analyzing method and system based on a honeynet, and relates to the technical field of attack analysis, and the method comprises the steps: collecting attack interaction data and an associated attack chain trajectory set; dividing attack behavior units, and constructing a behavior space attitude matrix; constructing a two-dimensional behavior relationship graph, performing interpolation enhancement of sub-time granularity, and raising the dimension of the interpolated behavior node into a three-dimensional semantic space; performing attack path trend analysis on the attack behavior unit, and constructing an attack path bending rule model; and inputting parameters such as the attack chain trajectory set and behavior nodes in the three-dimensional semantic space into the attack path bending rule model, outputting a trapping response strategy, and dynamically adjusting the honeynet environment. According to the invention, the type and position of the honeypot can be automatically adjusted according to the attack behavior change, the structure definition and processing precision of the attack behavior data are effectively improved, and the attack behavior identification result can be conveniently and directly used for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

System, Apparatus, and Method to Generate Decoy Honeypots by Using Generated Adversarial Networks

A system, apparatus, and method to generate decoy honeypots by using generated adversarial networks. In some embodiments, a method for generating decoy honeypots, the steps comprising identifying a plurality of network device configurations on a network; instantiating a generative adversarial network comprising architecture properties; generating a plurality of decoy honeypots with the generative adversarial network, wherein the plurality of decoy honeypots imitate the plurality of network device configurations to deceive malicious actors, and wherein the generative adversarial network optimizes a distribution of the plurality of decoy honeypots according to a precision distribution and a recall distribution; activating the plurality of decoy honeypots to the network; and dynamically evolving the plurality of decoy honeypots towards one or more preferences of a network attacker.
Owner:THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY

Honeypot automatic coping strategy generation method based on large model

The invention discloses a honeypot automatic coping strategy generation method based on a large model. The method comprises the steps of S1, performing semantic analysis on dynamic attack behaviors; s2, performing context-aware threat reasoning; s3, adaptive strategy generation and semantic verification are carried out; s4, strategy executable compiling is carried out; s5, enhancing the efficiency of the closed-loop strategy; according to the method, the authority / service logic contradiction is thoroughly eliminated through a semantic consistency verification mechanism, so that the false alarm rate of the honeypot in the APT attack is reduced; an anti-recognition perturbation code injected by the low-entropy strategy compiling technology breaks through a traditional honeypot periodic response mode, and the fingerprint recognition success rate of an attacker is reduced; a resource penalty function of the Pareto optimal strategy sequence enables a trapping intensity mean value under limited resources to be improved; a double-channel updating mechanism promotes coevolution of a knowledge base and a constraint set, and the response generation speed for an unknown attack mode is shortened.
Owner:SHENZHEN FANYUN SHUZHI TECH CO LTD

Honeypot system and management method thereof

The application provides a honeypot system and a management method thereof. A trapping node captures a first attack request of an attacker and forwards the first attack request to an intermediate proxy layer. The intermediate proxy layer edits the first attack request into a second attack request and forwards the second attack request to a corresponding first honeypot instance. The first honeypot instance controls a corresponding target process to execute an attack instruction of the second attack request, establishes a first mapping relationship between the target process and an identifier ID of the attacker, establishes a second mapping relationship between a file system operation log and the target process, and uploads the first mapping relationship, the second mapping relationship, the file system operation log and the second attack request to a message queue if a reverse shell appears. The identifier ID of the attacker and the file system operation log can be associated through the first mapping relationship and the second mapping relationship, the target process and the file operated by an attack source IP corresponding to the identifier ID of the attacker can be obtained, and the attack behavior of the attacker can be tracked.
Owner:BEIJING KNOWNSEC INFORMATION TECHNOLOGY CO LTD

Primary equipment network security reinforcement method, computer equipment and storage medium

The invention relates to the technical field of network security, and discloses a primary equipment network security reinforcement method, computer equipment and a storage medium, by setting a dynamic threshold judgment and hierarchical response mechanism in an instruction receiving link, abnormal high-frequency operation for primary equipment can be effectively identified and blocked, and the security of the primary equipment is enhanced. The equipment operation risk caused by a malicious instruction is obviously reduced; meanwhile, in combination with double judgment of an upper limit of operation times and a preset multiple, accurate grading alarm from suspected attacks to confidential attacks is realized, the accuracy of threat identification is greatly improved, and false alarms are reduced; by intelligently agenting the confidential attack traffic to the electric power honeypot, the security of real equipment is protected, an effective environment is provided for analysis and tracking of attack behaviors, and the active defense capability of the system in an industrial network environment in which a feature library cannot be updated in real time is enhanced.
Owner:YISHITE ENERGY STORAGE TECH CO LTD

Method for secure operation of an operating system

The application discloses a safe operation method of an operating system, comprising the following steps: collecting access traffic data of an Hfish honeypot in a sub-domain operating system, and sending the access traffic data to a network attack detection module; wherein the operating system comprises a plurality of mutually isolated sub-domain operating systems, and each of the sub-domain operating systems comprises the Hfish honeypot; the network attack detection module is used for detecting network attacks on the access traffic data; in the case that it is determined based on the network attack detection module that the access traffic data contains attack data, the sub-domain operating system is determined as a high-risk sub-domain operating system; and a defense action is performed based on a defense strategy in an attack defense module in the high-risk sub-domain operating system.
Owner:CHINA MOBILE INTERNET CO LTD +1

Transverse movement attack path analysis method and system based on virtualized trap network

The invention relates to the technical field of honeypot trapping networks, in particular to a transverse movement attack path analysis method and system based on a virtualized trapping network. The method comprises the steps that system logs of N network nodes in the virtualized trapping network are collected regularly, honeypot servers are deployed in all the network nodes in the virtualized trapping network, and N is an integer larger than or equal to 1; updating the constructed attack path according to the association degree between the system log of the Nth network node and the constructed attack path; traversing the system logs of the N network nodes until the system logs collected in the current period are processed. According to the method, all the log data in all the nodes in the virtualized trapping network are integrated, and a complete and comprehensive attack graph is established, so that comprehensive analysis of cross-system and cross-device behaviors of attackers is realized, and the depth and accuracy of existing analysis are improved.
Owner:GUANGZHOU UNIVERSITY

High-interaction sip honeypot system based on phased interaction control

This invention discloses a highly interactive SIP honeypot system based on phased interactive control, comprising: a message receiving module for receiving external SIP requests; a SIP interactive control module supporting multiple interaction modes and generating corresponding responses according to the current configuration mode; a session state machine module for maintaining the SIP session protocol state; a phase switching control module for maintaining phase state variables and dynamically selecting the interaction mode according to preset trigger conditions; and a recording and statistics module for recording request behavior characteristics, interaction logs, and switching logs. This invention achieves runtime schedulable management of interactive capabilities, enabling low-resource-consumption recording of scanning behavior and deep trapping of advanced attacks and collection of complete attack chain data, providing reliable data support for the detection of encrypted malicious traffic.
Owner:SUN YAT SEN UNIV

VERIFICATION OF BACKUP DATA USING HONEYPOT OBJECTS

In some examples, a system receives a representation of a honeypot pattern and information about a honeypot object containing the honeypot pattern injected into primary data. The system examines backup data created by a backup management system by identifying an instance of the honeypot object within the backup data and determining whether the data of that honeypot object instance deviates from the honeypot pattern. Based on the finding that the data of that honeypot object instance deviates from the honeypot pattern, the system triggers a corrective action regarding the backup data.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Web honeypot automatic script identification and countering method based on large language model and related equipment

The invention discloses a Web honeypot automatic script identification and countering method based on a large language model and related equipment, and the method comprises the steps: obtaining a real IP address of an attack request through a WebRTC protocol; analyzing the attack request through a headless browser and a large language model, judging whether the attack request is an automatic script behavior or not, countering the attack request if the attack request is the automatic script behavior, and guiding the attack request to a honeypot if the attack request is not the automatic script behavior. The method can improve the accuracy of automatic script recognition, improves the honeypot stability, and can be widely applied to the technical field of network security.
Owner:GUANGZHOU UNIVERSITY

Back door embedded honeypot induced active defense method

The invention discloses a backdoor embedded honeypot induced active defense method, and relates to the field of data processing. And malicious aggressive input can be actively defended on the basis of not influencing the classification detection rate. The backdoor embedded honeypot induced active defense method comprises the following steps: acquiring a to-be-detected input signal, and inputting the input signal into a classification prediction model and an anomaly detection model to obtain a prediction category output by the classification prediction model and an anomaly score output by the anomaly detection model; determining whether the prediction category triggers a honeypot trap, and outputting the prediction category as an output target when the honeypot trap is not triggered; and when a honeypot trap is triggered, determining whether the input signal is a hostile attack signal through the abnormal score, and blocking output when the input signal is determined to be the hostile attack signal.
Owner:XIDIAN UNIV

Method for deploying a honeypot

ActiveCN120710730BData sourceHoneypot
The application provides a deployment method of a honeypot, comprising the following steps: receiving tunnel data sent by a tunnel server and analyzing the tunnel data to output a target port number, wherein the tunnel data is derived from IP data packets of a public network attack end; querying a MAC mapping table based on the target port number, matching a virtual MAC address, obtaining a first Ethernet frame carrying the virtual MAC address, and forwarding the first Ethernet frame to a honeypot container so that the honeypot container generates a response packet; and returning the response packet to the public network attack end through the tunnel server. The method sets a MAC mapping table and a frame reconstruction operation at the honeypot host layer, ensures that the virtual MAC address is reserved in the Ethernet frame, makes the attack traffic always carry a virtual identity, avoids protocol layer stripping, maintains the original MAC layer context of the response packet generated by the honeypot container when the response packet is returned to the public network, and enhances the geographical camouflage effect.
Owner:BEIJING ANBOTONG TECH CO LTD

Network asset simulation method and device based on honeypot technology, equipment and medium

The present disclosure provides a network asset simulation method and device based on honeypot technology, equipment and medium, the method comprises: obtaining the attribute information of each target network asset in the target network segment in the active state and the service information of the opened target network service; for each target network asset, based on the service information and attribute information corresponding to the target network asset, determine whether there is a target honeypot service matched with the target network service in each honeypot service pre-generated in the honeypot system; if so, bind the target network asset to the target honeypot service. By using the method, when simulating network assets, the existing honeypot services in the honeypot system can be matched with the target network services, and the existing honeypot services in the honeypot system can be directly used to simulate network assets, so that the honeypot services do not need to be created every time, thereby saving the time of simulating network assets and realizing rapid simulation.
Owner:HARBIN ANTIY TECH

Lightweight Internet honeypot system based on dual-stage attack guidance

The invention relates to the technical field of network security, and provides a lightweight Internet honeypot system based on dual-stage attack guidance, comprising a basic filtering module used for filtering network information and retaining effective attacker connection requests; the guiding agent is used for driving a generative model engine based on the first cue word template, generating a first response and obtaining a first attack operation command initiated by an attacker; the remote command conversion module is used for converting the first attack operation command into a preset structured data format; the high-sweetness service agent is used for driving the generative model engine based on a second cue word template, generating a second response and acquiring second attack operation information; and the cue word template library is used for storing the first cue word template and the second cue word template. According to the invention, through a system architecture combining intelligent noise filtering and dual-stage dynamic guidance, efficient and accurate trapping and deep intelligence generation of advanced continuous threats of a public network are realized.
Owner:GUANGZHOU UNIVERSITY

Industrial control system honeynet cluster deployment method

ActiveCN115913632BControl engineeringHoneypot
The application discloses an industrial control system honeynet cluster deployment method, comprising the following steps: step 1, deploying a probe in an industrial control honeynet, automatically scanning an industrial control network distribution, and obtaining industrial control equipment fingerprint information; step 2, generating a honeypot according to the industrial control equipment fingerprint information obtained in step 1; and step 3, deploying the industrial control honeypot generated in step 2 in the industrial control network. Through the application, an industrial control network deception defense system can be quickly deployed and constructed, dynamic deployment of the industrial control honeypot equipment is realized, the industrial control honeypot is mixed into a real industrial control equipment network, and the purposes of reducing an attack surface and accurate response are achieved.
Owner:CHINA TRANSPORT INFORMATION TECH GRP CO LTD

A method, device, medium and electronic equipment for generating a honeycomb transformation configuration

The application provides a honey array transformation configuration generation method and device, a medium and an electronic equipment, comprising: obtaining TTP information matching CVE to obtain CVE information; obtaining CVSS score according to the CVE information, selecting M CVE information associated with the highest score to generate corresponding CVE mirror configuration section; extracting scene feature information according to the TTP information to generate a feature mirror configuration section; generating a new honeypot configuration section of the service feature according to the TTP information; and mixing the CVE mirror configuration section, the feature mirror configuration section and the honeypot configuration section to generate a honey array transformation configuration file for transforming a trapping scene configuration. By designing the TTP scene information highly associated with the attacker's attack behavior and various threat modeling scales, the application completes the mapping of the attacker's behavior to the vulnerability and the service, selects the honeypot mirror of interest of the attacker, and highly adaptively generates the honey array transformation configuration file in combination with the scene information.
Owner:GUANGZHOU UNIVERSITY

A dynamic security defense method and system based on thermal migration and deep learning

ActiveCN116318779BAttackHoneypot
The application discloses a kind of dynamic security defense method and system based on thermal migration and deep learning, by preliminary discrimination of traffic using intrusion detection system, again using the malicious traffic detection module based on deep learning review and determine as malicious traffic, SDN controller forwards traffic to low interaction honeypot, when attack depth reaches critical point, the copy of normal host of timed snapshot is activated as high interaction honeypot by honeypot management system, then using redirection forwarding engine TCP_REPAIR agent switches connection to high interaction honeypot.The application relates to the field of network defense technology, uses the malicious traffic detection technology based on deep learning, accurately shunts encrypted or non-encrypted normal and malicious traffic, makes up the defect that traditional defense system can only detect non-encrypted traffic, simultaneously using TCP thermal migration technology, optimizes the shortcomings of long time consumption and non-concealed switching in traditional TCP connection switching process, effectively improves the dynamic defense capability of system and utilization rate and decoy capability of honeypot cluster.
Owner:GUILIN UNIV OF ELECTRONIC TECH

Cloud-native application security protection and monitoring method and system for financial technology

The application provides a cloud-native application security protection and monitoring method and system for financial technology, relates to the technical field of network security of financial technology, and comprises the following steps: acquiring multidimensional monitoring data, establishing a security threat knowledge graph, identifying a high-risk attack path through a graph convolution network, generating a potential threat prediction result, identifying abnormal behavior, configuring a dynamic honeypot environment, recording the behavior trajectory of an attacker, analyzing attack intention and technical characteristics, and generating and deploying protection rules in real time. The application improves the security protection capability of a financial cloud environment and realizes intelligent threat prediction and active defense.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

Systems and Methods for Inactive Number Message Governance

PendingUS20260189919A1Networked systemHoneypot
A method comprises receiving an Application-to-Peer (A2P) message, wherein the A2P message comprises a destination Mobile Station International Subscriber Directory Number (MSISDN), transmitting via the service delivery gateway and aggregator system, a stop message to the sender system when the destination MSISDN is inactive and currently not attached to an active line of a subscriber associated with the core network system, and instructing, by the honeypot application, performance of a governance action with respect to the sender system based on a rule.
Owner:T MOBILE INNOVATIONS LLC

Industrial control network attack packet response method and response system based on honeypot system

The application discloses a kind of based on honeypot system's industrial control network attack message response method and response system, wherein, the method includes the following steps: receiving attack message and screening out the valid industrial control protocol message in the attack message;From the valid industrial control protocol message, corresponding industrial control application data unit function code field and industrial control application data unit request data domain field are extracted, and the corresponding field of the data in the request response table in the honeypot system is matched, and according to different matching results, the response message corresponding to the result is replied.The based on honeypot system's industrial control network attack message response method and response system, by collecting and processing specific power industrial control network flow data, request response table can be generated, using the request response table, reasonable response with high fraud can be returned to the sniffer behavior of attacker.
Owner:STATE GRID LIAONING SHENYANG ELECTRIC POWER SUPPLY COMPANY

Honeynet-based abnormal detection flow identification method, electronic device, storage medium and program product

The embodiment of the invention provides an abnormal detection flow identification method based on a honeynet, electronic equipment, a storage medium and a program product. The method comprises the following steps: in response to abnormal detection flow received by a boundary honeypot, determining first interaction information of the abnormal detection flow and the boundary honeypot; wherein the boundary honeypot is in communication connection with an external gateway; a detection stage currently corresponding to the abnormal detection flow is determined according to the interaction information, a response honeypot corresponding to the abnormal detection flow is determined according to the detection stage, and the response honeypot is in communication connection with the boundary honeypot through an intranet; and obtaining response information obtained by responding to the abnormal detection flow by a response honeypot, and determining an abnormal type of the abnormal detection flow according to the response information. The method is used for achieving the effect of quickly identifying the abnormal type of the abnormal detection flow.
Owner:AGRI BANK OF CHINA CO LTD INNER MONGOLIA BRANCH

Dynamic trapping network deployment method and system based on Markov decision process

The invention provides a dynamic trapping network deployment method and system based on a Markov decision process, and relates to the technical field of network security. The method provided by the invention comprises the following steps: extracting TTP features from multi-source attack behavior data, mapping the TTP features into TTP feature vectors corresponding to attack steps, and constructing a TTP feature vector sequence according to an attack sequence; based on a Markov decision process model combined with multi-source threat intelligence, performing threat degree quantitative evaluation and sorting on the TTP feature vector sequence to obtain a sorted TTP feature vector sequence, and mapping the TTP feature vector sequence to a corresponding CVE number; based on the CVE serial number, selecting a honey point mirror image containing the corresponding vulnerability from a honey point warehouse; and based on the selected honey spot mirror image and the network defense demand, dynamically adjusting a honey spot deployment strategy and network topology configuration, and constructing a dynamic trapping network. According to the method, adaptive topological optimization from threat assessment to honey spot deployment is realized through the Markov decision process model.
Owner:GUANGZHOU UNIVERSITY

Network system protection method, device, equipment, storage medium and product

ActiveCN115695008Bachieve the purpose of protectionplay a role in confusingSecuring communicationAttackNetworked system
The application relates to a protection method and device of a network system, equipment, a storage medium and a product. It relates to the technical field of information security. The method comprises the following steps: acquiring a honeypot camouflage feature corresponding to a network system to be protected; adding the honeypot camouflage feature to the network system; and publishing the network system to which the honeypot camouflage feature is added; wherein the honeypot camouflage feature is used to make an attack party identify the published network system as a honeypot system and stop attacking the network system. By using the method, the attack party can mistakenly believe that the network system is a honeypot system, thereby giving up the attack, and the purpose of protecting the network system is achieved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Honeypot deployment method and device fusing Bayesian attack graph and reinforcement learning algorithm, and computer equipment

The invention relates to a honeypot deployment method and device fusing a Bayesian attack graph and a reinforcement learning algorithm, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: acquiring network observation data associated with an abnormal network activity when detecting that the abnormal network activity exists in a target network; determining updated attack information according to the network observation data and a Bayesian attack graph corresponding to the target network; the updated attack information represents the updated belief state and the updated attack path probability; according to the updated attack information, a defense strategy set for the target network is optimized through a reinforcement learning algorithm, and a honeypot deployment strategy is output based on the updated defense strategy; the attacked probability and the defense efficiency of the target node meet preset conditions; and according to the honeypot deployment strategy, deploying preset honeypot resources on the target node. By adopting the method, the capability of resisting network attack behaviors can be improved.
Owner:CHINA SOUTHERN POWER GRID COMPANY

Attack traffic processing method and device, equipment, medium and program product

The invention provides an attack traffic processing method and device, equipment, a medium and a program product. Relates to the technical field of network security. The method is applied to a cloud server, and the cloud server comprises a plurality of network domains, a flow processing module and a shared honeypot system. The method comprises the following steps: acquiring attack traffic for a network domain; performing network virtual mapping processing on original attack information in the attack traffic to generate corresponding virtual attack information; based on the virtual attack information, redirecting the attack traffic to a shared honeypot system for attack interaction, and obtaining interaction information of the attack traffic; and returning the interaction information to an attack terminal corresponding to the network domain according to a mapping relationship between the virtual attack information and the original attack information. According to the method provided by the invention, the attack traffic of the plurality of network domains is uniformly drained to the shared honeypot system, so that cross-domain communication and resource reuse are realized, and the deployment cost of tenants and the maintenance cost of the platform are further reduced.
Owner:CHINA UNIONPAY

Network defense method, device, apparatus and storage medium

This invention relates to the field of network security technology and discloses a network defense method, apparatus, device, and storage medium. The method is applied to a security defense system deployed in a network environment, where device nodes and honeypot nodes are deployed, and the device nodes deploy defense strategies. The method includes: acquiring reward information from the network environment based on the defense strategies, where the reward information represents the current attack losses after deploying the defense strategies; receiving attacker information from each honeypot node after inducing an attacker to launch an attack; and determining whether to redeploy the defense strategies based on the reward information and the attacker information. This invention combines the reward information from the network environment and the attacker information from the honeypot nodes to comprehensively determine whether to redeploy the defense strategies. Compared to the static defense strategies of existing technologies, the above method of this invention can flexibly respond to changing attack methods and effectively improve security defense efficiency.
Owner:PENG CHENG LAB

Honeypot concealment enhancement method based on mimicry defense and IP separation

The invention belongs to the technical field of network space security and deep learning, and particularly relates to a mimicry defense and IP separation-based honeypot concealment enhancement method, which comprises the steps of constructing a dynamic heterogeneous mimicry service set, improving a distribution arbiter in an original mimicry service set, constructing an intelligent agent and forming a mimicry set. Using a reinforcement learning algorithm to find an optimal IP separation opportunity; a honeypot selector is constructed for a honeypot and a normal server set in a dynamic heterogeneous mimicry service set at an optimal separation opportunity found by a reinforcement learning algorithm, APT attack chain driven attack simulation is performed on a morphological heterogeneous mimicry service set and a mimicry set, and attack-defense interaction data is generated by repeatedly executing an IP separation and reconstruction strategy. And providing a training sample for the reinforcement learning model to train the reinforcement learning model. According to the invention, the anti-detection capability of the honeypot is improved, and the safety of the system is guaranteed.
Owner:NANJING UNIV OF POSTS & TELECOMM

A system for detecting and diverting attacks on in-vehicle controllers and networks

A vehicle system comprising: a first vehicle bus, wherein the first vehicle bus comprises one or more electronic control units (ECUs) configured to operate, wherein the one or more ECUs are configured to communicate with a remote server; a second vehicle bus, wherein the second vehicle bus is configured to communicate with the one or more ECUs, wherein the second vehicle bus comprises one or more vehicle drive ECUs configured to operate vehicle drive functions; a gateway controller configured to control communication between the first vehicle bus and the second vehicle bus; and a honeypot configured to emulate vehicle data, wherein the honeypot is further configured to monitor activity from a remote attacker.
Owner:ROBERT BOSCH GMBH

Graded honey spot trapping method and device based on adaptive UEBA score

The invention provides a graded honey spot trapping method and device based on adaptive UEBA scoring. The method comprises the following steps: filtering and limiting original network traffic to obtain filtered data; collecting user behavior metadata to generate behavior feature vectors; calculating a user risk score, and comparing the user risk score with a detection threshold to judge a risk level; processing by a corresponding processing module according to the risk level, and injecting identity context parameters of an abnormal user into a high-risk model to start an exclusive container instance and manage the life cycle of a container session; and the high-risk model collection container feedback data is used for optimizing the high-risk model and updating the feature dynamic weight and the detection threshold. By applying the method, the dynamic weight and the detection threshold of the feature can be dynamically adjusted in real time in response to the attack trend, the response sensitivity to attack behaviors is improved, defense resources are allocated according to needs for abnormal users, deep evidence obtaining of high-value targets is guaranteed, and normalized calculation and loads of a system are reduced.
Owner:GUANGZHOU UNIVERSITY