Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

236 results about "Honeypot" patented technology

In computer terminology, a honeypot is a computer security mechanism set to detect, deflect, or, in some manner, counteract attempts at unauthorized use of information systems. Generally, a honeypot consists of data (for example, in a network site) that appears to be a legitimate part of the site, but is actually isolated and monitored, and that seems to contain information or a resource of value to attackers, who are then blocked. This is similar to police sting operations, colloquially known as "baiting" a suspect.

Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

The invention discloses a dynamic honey point collaborative intelligent threat trapping system and method based on a genetic algorithm in the technical field of network security, and the system comprises a multi-source information collection and dual-mode output module, a reinforcement learning strategy engine, a graph neural network prediction module, a digital twin simulation environment, a strategy verification and optimization module, and a real network defense execution module. A dynamic honey point deployment strategy is generated in real time through a reinforcement learning strategy engine, and the problem of strategy stiffness is solved; a third-generation non-dominated sorting genetic algorithm (NSGA-III) multi-objective optimization algorithm is used for coordinating honey point density adjustment, trip line sensitivity calibration and other actions; attacking path risks are quantified based on a threat scoring formula, digital twin environment pre-verification and high-risk node precise protection are driven, closed-loop linkage of threat perception, strategy optimization and active trapping is finally achieved, and the intelligent defense capability capable of achieving autonomous evolution is formed.
Owner:积至(海南)信息技术有限公司

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Ai-generated virtual file honeypots for computing systems behavior-based protection against ransomware attacks

Systems and methods for protecting computing systems against ransomware attacks using AI-generated virtual file honeypots. Generative AI comprising a large language model generates virtual file honeypots automatically in response to attack vectors associated with suspect actors and ransomware families.
Owner:ACRONIS INT

Honeypot-based attack detection

In some examples, a system monitors input / output (I / O) operations to identify data matching a honeypot pattern. The system determines storage location information associated with the data identified as matching the honeypot pattern, and detects an access of the data at a storage location indicated by the storage location information. The system indicates a potential attack based on detecting the access of the data at the storage location indicated by the storage location information.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Dynamic honeypot deployment and optimization method and system based on intelligent flow analysis

The invention provides a dynamic honeypot deployment and optimization method and system based on intelligent flow analysis, and belongs to the field of computer security and network security. The method comprises the following steps: collecting network traffic and preprocessing to obtain a feature vector; then, the trained random forest model is used for carrying out attack type identification on the network flow; clustering analysis is carried out on all the attack traffic, similar attack traffic forms clusters, priority ranking is carried out on the clusters, honeypots of corresponding positions and types are deployed according to matching rules in the sequence of the priorities of the clusters from high to low, and the attack traffic belonging to a certain cluster is introduced into the corresponding honeypot; a deep Q network is used in each honeypot for learning, and the optimal balance between the capture rate and the resource utilization rate is realized by modifying the configuration of the honeypot and observing the capture condition of attack traffic and the resource consumption of the honeypot. According to the method, intelligent deployment of the honeypot and dynamic configuration in the honeypot are realized, the attack capture rate of the honeypot is improved, and the resource utilization rate is maximized.
Owner:ZHEJIANG GUOLI SECURITY TECH CO LTD

Network security threat detection system and method based on deep learning

InactiveCN120602140AKnowledge representationInference methodsRequest - actionPathPing
The invention discloses a network security threat detection system and method based on deep learning, and particularly relates to the field of network security trapping analysis based on a honeynet and a honeypot, and the method comprises the steps: collecting trapping node log data in a network security behavior trapping process; extracting a behavior event set including access time, request action types, parameter structures and node identifiers, organizing the behavior event set according to a timestamp sequence, and constructing a basic behavior node chain; and performing access sequence consistency check on the behavior node chain. A path map structure based on access tension evolution is constructed in a honeynet environment, a deep learning model is fused to execute trend reasoning and behavior disturbance prediction on a high-tension path segment, and a redundant path induction feedback mechanism is combined to realize preposed recognition and active trapping intervention on an attack path. The problem that high-concealment attacks cannot be perceived and responded in advance in a behavior window period is solved.
Owner:YANCHENG LEDU NETWORK TECHNOLOGY CO LTD

Cloud native application security protection and monitoring method and system oriented to financial science and technology

The invention provides a cloud native application security protection and monitoring method and system for financial science and technology, and relates to the technical field of financial science and technology network security, and the method comprises the steps: obtaining multi-dimensional monitoring data, building a security threat knowledge graph, recognizing a high-risk attack path through a graph convolution network, generating a potential threat prediction result, and recognizing an abnormal behavior. And configuring a dynamic honeypot environment, recording behavior tracks of attackers, analyzing attack intentions and technical characteristics, and generating and deploying protection rules in real time. According to the invention, the safety protection capability of the financial cloud environment is improved, and intelligent threat prediction and active defense are realized.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

Agent-free honeypot mapping method and device

The invention discloses an agent-free honeypot mapping method and device, and relates to the technical field of network security. The method comprises the following steps: analyzing metadata of core switching equipment, and establishing a domain-address mapping matrix; periodically detecting an address space, constructing an IP asset dynamic portrait and generating an asset state map; deploying a cross-domain traffic forwarding protocol stack and a virtual domain identifier mapping rule; deploying a software-defined virtual switching unit and accessing the virtual honeypot probe cluster; allocating idle addresses for the probes and establishing a binding relationship; and periodically detecting and triggering a self-healing process when an address conflict occurs. The device comprises a core exchange and domain management unit, an IP asset detection unit, a network protocol configuration unit, a probe virtualization management unit, an address resource scheduling unit and a system cooperative control unit. According to the method, agency-free and automatic deployment of the honeypot is realized, and the problems that a traditional scheme depends on agency software, deployment is complex and IP conflict processing lags are solved.
Owner:NANJING JINGWEI XINAN TECH CO LTD +1

Honeynet-based attack trapping and analyzing method and system

The invention discloses an attack trapping and analyzing method and system based on a honeynet, and relates to the technical field of attack analysis, and the method comprises the steps: collecting attack interaction data and an associated attack chain trajectory set; dividing attack behavior units, and constructing a behavior space attitude matrix; constructing a two-dimensional behavior relationship graph, performing interpolation enhancement of sub-time granularity, and raising the dimension of the interpolated behavior node into a three-dimensional semantic space; performing attack path trend analysis on the attack behavior unit, and constructing an attack path bending rule model; and inputting parameters such as the attack chain trajectory set and behavior nodes in the three-dimensional semantic space into the attack path bending rule model, outputting a trapping response strategy, and dynamically adjusting the honeynet environment. According to the invention, the type and position of the honeypot can be automatically adjusted according to the attack behavior change, the structure definition and processing precision of the attack behavior data are effectively improved, and the attack behavior identification result can be conveniently and directly used for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Electric power protocol honeypot trapping and abnormity identification method based on GAN

The invention discloses a GAN-based electric power protocol honeypot trapping and anomaly identification method, which comprises the following steps: constructing a data set by collecting real traffic of an electric power protocol, generating diversified attack samples conforming to protocol grammar by using a GAN of a Transform architecture, and improving robustness by combining data enhancement technologies such as random truncation and noise injection. Virtual honeypot equipment is deployed to simulate power equipment behaviors, attack logs and traffic features are fused in real time, a graph neural network is adopted to model a cross-message interaction relation, and self-supervised learning is introduced to detect semantic anomaly. Experiments show that the method realizes 98.2% of detection accuracy on data sets such as IEEE 123-Bus and the like, supports dynamic adaptation of protocol versions, realizes accurate tracing of attack source IP and intention through honeypot log association analysis, and effectively improves the active defense capability of a power system to novel attacks.
Owner:INFORMATION & COMM CO OF STATE GRID JILIN ELECTRIC POWER CO LTD

System, Apparatus, and Method to Generate Decoy Honeypots by Using Generated Adversarial Networks

A system, apparatus, and method to generate decoy honeypots by using generated adversarial networks. In some embodiments, a method for generating decoy honeypots, the steps comprising identifying a plurality of network device configurations on a network; instantiating a generative adversarial network comprising architecture properties; generating a plurality of decoy honeypots with the generative adversarial network, wherein the plurality of decoy honeypots imitate the plurality of network device configurations to deceive malicious actors, and wherein the generative adversarial network optimizes a distribution of the plurality of decoy honeypots according to a precision distribution and a recall distribution; activating the plurality of decoy honeypots to the network; and dynamically evolving the plurality of decoy honeypots towards one or more preferences of a network attacker.
Owner:THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Honeypot interaction response generation method based on large language model

A honeypot interaction response generation method based on a large language model comprises the steps that an attacker initiates a malicious request, a firewall carries out screening based on a white list, and traffic matched with the white list is forwarded to an actual application server through a honeypot system; for the traffic not in the white list, redirecting the traffic to a honeypot system; a honeypot interaction response system is deployed in the honeypot system and comprises an embedding module, a coding module and a response decoding module, so that induction response is automatically generated and sent to an attacker, and meanwhile alarm information is generated and sent to safety analysts. The method comprises the following steps: firstly, converting input data into a vector form by using an embedding module, extracting overall characteristics of a request by using a coding module, and finally, generating an induced response by using a response decoding module. According to the method, the advantages of a large language model in the aspects of semantic comprehension, context modeling and generation capability are fully utilized, and accurate perception of attack behaviors and automatic generation of response contents are realized.
Owner:NANJING COLLEGE OF INFORMATION TECH

High-interaction deception defense and attack tracing method based on RASP technology

The invention discloses a high-interaction deception defense and attack tracing method based on an RASP technology, and the method specifically comprises the following steps: S1, RASP implantation and bait deployment, S2, attack detection and simulation triggering, S3, attack session redirection and high-interaction deception, S4, attack behavior monitoring and tracing data collection, and S5, tracing analysis and threat disposal. The invention relates to the technical field of network and information security. According to the high-interaction deception defense and attack tracing method based on the RASP technology, a deception mechanism is embedded into a real application / system in operation, and high fusion of a real business environment and a false trapping environment is achieved. Different from a traditional'main-auxiliary separation 'mode that a honeypot is placed in an independent network or a host, the method has the advantage that the application can be changed to generate a'trap' during running through the RASP. The seamless embedded spoofing makes attackers difficult to distinguish true and false: the attackers attack a part of a production system initially, and then are introduced into a parallel simulation space unconsciously.
Owner:WEIHAI POWER SUPPLY COMPANY OF STATE GRID SHANDONG ELECTRIC POWER COMPANY

Honeypot automatic coping strategy generation method based on large model

The invention discloses a honeypot automatic coping strategy generation method based on a large model. The method comprises the steps of S1, performing semantic analysis on dynamic attack behaviors; s2, performing context-aware threat reasoning; s3, adaptive strategy generation and semantic verification are carried out; s4, strategy executable compiling is carried out; s5, enhancing the efficiency of the closed-loop strategy; according to the method, the authority / service logic contradiction is thoroughly eliminated through a semantic consistency verification mechanism, so that the false alarm rate of the honeypot in the APT attack is reduced; an anti-recognition perturbation code injected by the low-entropy strategy compiling technology breaks through a traditional honeypot periodic response mode, and the fingerprint recognition success rate of an attacker is reduced; a resource penalty function of the Pareto optimal strategy sequence enables a trapping intensity mean value under limited resources to be improved; a double-channel updating mechanism promotes coevolution of a knowledge base and a constraint set, and the response generation speed for an unknown attack mode is shortened.
Owner:SHENZHEN FANYUN SHUZHI TECH CO LTD

Network attack defense system based on virtual honeypot

The invention discloses a network attack defense system based on a virtual honeypot, and relates to the technical field of network attack defense. The system comprises a lightweight probe arranged in a target system and a virtual honeypot module used for constructing and updating a virtual environment, static system characteristics and dynamic behavior characteristics of the target system are collected through the lightweight probe, and the virtual environment consistent with the static performance of the target system is constructed based on the static characteristics; the virtual environment is dynamically adjusted in combination with the dynamic characteristics, and the probe periodically updates the characteristic data, so that the virtual honeypot unit can be dynamically adapted along with the change of the target system; according to the method, the problem that a traditional virtual honeypot is easy to recognize due to static or unchanged reset features is effectively solved, the fidelity of the honeypot is remarkably improved, the probability that the honeypot is recognized by an attacker is reduced, and the attack trapping capacity is enhanced.
Owner:NEIMENGGU XINLIAN INFORMATION IND CO LTD

Edge side attack aggregation analysis method based on flow self-learning

The invention relates to the field of network traffic analysis, and particularly discloses an edge side attack aggregation analysis method based on traffic self-learning, which performs self-learning modeling on edge side real-time traffic through an unsupervised learning model and intelligently identifies unknown suspicious traffic deviating from a normal behavior mode in a mode of not depending on an attack sample. Once high threat traffic is detected, a dynamic honeypot environment will be automatically arranged and deployed, and suspicious traffic is introduced into an isolated analysis environment through a traffic redirection technique. In a honeypot, deep interaction and behavior capture are performed on malicious traffic, and a high-value attack indicator is extracted. And finally, carrying out aggregation association on the obtained attack indicator and the source information of the flow to form a complete and high-credibility attack evidence chain. Therefore, accurate identification, deep analysis and effective traceability of edge side attacks can be realized, so that the automatic analysis and response capability of an edge network to deal with advanced and unknown attacks is effectively improved.
Owner:STATE GRID HENAN INFORMATION & TELECOMM CO

Honeypot-based attack detection

In some examples, a system monitors input / output (I / O) operations to identify data matching honeypot patterns. The system determines storage location information associated with data identified as matching a honeypot pattern, and detects access to data at a storage location indicated by the storage location information. The system indicates a potential attack based on detecting access to data at the storage location indicated by the storage location information.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Honey array transformation configuration generation method and device, medium and electronic equipment

The invention provides a honey array transformation configuration generation method and apparatus, a medium and an electronic device. The method comprises the steps of obtaining TTP information and matching CVE to obtain CVE information; obtaining a CVSS score according to the CVE information, and selecting M mirror images associated with the CVE information with the highest score to generate a corresponding CVE mirror image configuration section; extracting scene feature information according to the TTP information to generate a feature mirror image configuration section; generating honey point configuration segments of newly added honey points and service features according to the TTP information; and mixing the CVE mirror image configuration section, the feature mirror image configuration section and the honey point configuration section to generate a honey array transformation configuration file for transforming trapping scene configuration. According to the method, TTP scene information highly associated with attacking behaviors of an attacker and various threat modeling scales are designed and introduced, mapping from the attacker behaviors to vulnerabilities and services is completed, honey point mirror images interested by the attacker are selected, and a honey array transformation configuration file is generated in a highly self-adaptive mode in combination with the scene information.
Owner:GUANGZHOU UNIVERSITY

A Reinforcement Learning-Based Method for Generating Honeynet Deployment Strategies in an Intranet Environment

This invention discloses a method for generating honeypot deployment strategies based on reinforcement learning in an intranet environment. The method includes: randomly generating multiple nodes to construct an intranet environment; constructing attack agents, which interact with the intranet environment in stages to pre-train the attack agents; assigning pre-trained attack agents with different attack intentions to each honeypot agent, and pre-training the honeypot agents in the intranet environment; initializing the pre-trained honeypot agents and constructing the honeypot environment using them; in the honeypot environment, the pre-trained attack agents interact with the pre-trained honeypot agents to pre-train decision agents; training all agents using the MADDPG algorithm, constructing a hierarchical defense agent using the pre-trained honeypot agents and the pre-trained decision agents, and updating the policy network and value network of each agent. This invention improves the adaptability of the honeypot system and enhances the security protection level of the intranet environment through dynamic deployment strategies.
Owner:GUANGZHOU UNIVERSITY

Intrusion detection and defense method, device and equipment based on dynamic honeypot and medium

The invention provides an intrusion detection and defense method, device and equipment based on a dynamic honeypot and a medium, and belongs to the technical field of information security, and the method comprises the steps: deploying a honeypot trapping environment on a vehicle controller; monitoring and recording behavior logs of suspected attackers accessing the honeypot trapping environment; based on a hidden Markov model, identifying the current attack stage of the suspected visitor according to the behavior log, and predicting the next attack behavior of the suspected visitor; and generating a new honeypot configuration strategy according to the next attack behavior, and dynamically updating the honeypot trapping environment according to the honeypot configuration strategy. According to the method, the vehicle end honeypot is dynamically deployed, and the vehicle end safety is improved while the intrusion detection efficiency is improved.
Owner:DONGFENG COMML VEHICLE CO LTD

HONEYPOT-BASED ATTACK DETECTION

In some examples, a system monitors input / output (I / O) operations to identify data that matches a honeypot pattern. The system determines memory location information associated with the data identified as matching the honeypot pattern and detects access to the data at a memory location indicated by the memory location information. The system indicates a potential attack based on detecting access to the data at the location indicated by the memory location information.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Deception induction method based on preposed honey court and related equipment

The invention discloses a deception induction method based on a preposed honey court and related equipment. The method comprises the following steps: constructing an original data set according to an attack full life cycle induction principle; generating false account information by adopting a false account information generation method, generating false text information by adopting a false text information generation method, and constructing a bait file according to the false account information and the false text information; modifying a configuration file of the preposed honey court according to the bait file, screening out a target bait page according to a graph theory method, and dynamically embedding the bait file into the target bait page in combination with the modification response capability of the preposed honey court; and monitoring an access behavior aiming at the bait file, and if detecting that the bait file has an abnormal access behavior, triggering a flow traction mechanism by a detection module to migrate the access flow to the honey point system for analysis. The method can enable the cheating induction of the preposed honey court to cover the most probable penetration path of the attacker, actively guides the exposure of potential attack behaviors, and can be widely applied to the technical field of network security.
Owner:GUANGZHOU UNIVERSITY

Honeypot system and management method thereof

The application provides a honeypot system and a management method thereof. A trapping node captures a first attack request of an attacker and forwards the first attack request to an intermediate proxy layer. The intermediate proxy layer edits the first attack request into a second attack request and forwards the second attack request to a corresponding first honeypot instance. The first honeypot instance controls a corresponding target process to execute an attack instruction of the second attack request, establishes a first mapping relationship between the target process and an identifier ID of the attacker, establishes a second mapping relationship between a file system operation log and the target process, and uploads the first mapping relationship, the second mapping relationship, the file system operation log and the second attack request to a message queue if a reverse shell appears. The identifier ID of the attacker and the file system operation log can be associated through the first mapping relationship and the second mapping relationship, the target process and the file operated by an attack source IP corresponding to the identifier ID of the attacker can be obtained, and the attack behavior of the attacker can be tracked.
Owner:BEIJING KNOWNSEC INFORMATION TECHNOLOGY CO LTD

A deception defense device and method for seamlessly migrating website backdoors

The present invention discloses a deception defense device and method for seamlessly migrating website backdoors. The deception defense device deploys a website backdoor detection module on a user's real business server. The website backdoor detection module detects website backdoor files by monitoring changes in the business server's website directory files; a file ferry module transfers the website backdoor files to a honeypot environment and runs them, obtaining the website backdoor address running in the honeypot; a file rewriting module rewrites the website backdoor file without modifying the file path and file name, only rewriting the file content to the reverse proxy file content. In the reverse proxy file content, the reverse proxy destination address points to the website backdoor address running in the honeypot; malicious instructions and interactive operations issued by attackers to the website backdoor can be monitored in the virtual honeypot module. The present invention greatly enhances the integration of deception defense technology with real business and improves the ability of the honeypot network to actively trap attackers' actions.
Owner:STATE GRID JIANGSU ELECTRIC POWER CO LTD RESEARCH INSTITUTE +2

Primary equipment network security reinforcement method, computer equipment and storage medium

The invention relates to the technical field of network security, and discloses a primary equipment network security reinforcement method, computer equipment and a storage medium, by setting a dynamic threshold judgment and hierarchical response mechanism in an instruction receiving link, abnormal high-frequency operation for primary equipment can be effectively identified and blocked, and the security of the primary equipment is enhanced. The equipment operation risk caused by a malicious instruction is obviously reduced; meanwhile, in combination with double judgment of an upper limit of operation times and a preset multiple, accurate grading alarm from suspected attacks to confidential attacks is realized, the accuracy of threat identification is greatly improved, and false alarms are reduced; by intelligently agenting the confidential attack traffic to the electric power honeypot, the security of real equipment is protected, an effective environment is provided for analysis and tracking of attack behaviors, and the active defense capability of the system in an industrial network environment in which a feature library cannot be updated in real time is enhanced.
Owner:YISHITE ENERGY STORAGE TECH CO LTD

Industrial control honeypot defense system and method based on mirror simulation

The present invention belongs to the technical field of industrial network defense, and discloses an industrial control honeypot defense system and method based on mirror simulation; the system comprises: identifying the industrial control network in a factory, obtaining device information data, industrial protocols, device topology structure and communication behavior data in the industrial control network; constructing a simulated industrial control honeypot network based on the obtained data; deploying an identification node in the simulated industrial control honeypot network, and generating a corresponding access identification verification code based on the simulated communication behavior data in the simulated industrial control honeypot network through the identification node, and encrypting the simulated communication behavior data to obtain encrypted simulated communication behavior data; verifying the access identification verification code obtained by decrypting the encrypted simulated communication behavior data by the visitor, and judging whether it is a normal access based on the inspection result, and making a corresponding response; thereby further improving the defense capability of the industrial control network in the factory.
Owner:南京迅集科技有限公司

A method for constructing and deploying command honeypots based on large models

The present invention provides a method for constructing and deploying command honey spots based on a large model, and relates to the field of cyberspace security technology. The method for constructing and deploying command honey spots includes the following steps: constructing a user behavior model based on the command history record of the user terminal, and constructing an attack behavior model based on the attack log; generating a command honey spot template based on the user behavior model and the attack behavior model, and dynamically generating multiple command honey spots by matching the command honey spot template with the user's current operating environment based on the large model; selecting the deployment location of the command honey spot based on the user behavior model, the attack behavior model, and the user's current operating environment; issuing an alarm when the command honey spot is triggered and recording the triggering event of the command honey spot, generating structured feedback data based on the triggering event, and optimizing the command honey spot based on the structured feedback data. The method for constructing and deploying command honey spots provided by the present invention improves the problems of low defense effect and insufficient security of command history records in traditional methods.
Owner:GUANGZHOU UNIVERSITY

Method for secure operation of an operating system

The application discloses a safe operation method of an operating system, comprising the following steps: collecting access traffic data of an Hfish honeypot in a sub-domain operating system, and sending the access traffic data to a network attack detection module; wherein the operating system comprises a plurality of mutually isolated sub-domain operating systems, and each of the sub-domain operating systems comprises the Hfish honeypot; the network attack detection module is used for detecting network attacks on the access traffic data; in the case that it is determined based on the network attack detection module that the access traffic data contains attack data, the sub-domain operating system is determined as a high-risk sub-domain operating system; and a defense action is performed based on a defense strategy in an attack defense module in the high-risk sub-domain operating system.
Owner:CHINA MOBILE INTERNET CO LTD +1

Transverse movement attack path analysis method and system based on virtualized trap network

The invention relates to the technical field of honeypot trapping networks, in particular to a transverse movement attack path analysis method and system based on a virtualized trapping network. The method comprises the steps that system logs of N network nodes in the virtualized trapping network are collected regularly, honeypot servers are deployed in all the network nodes in the virtualized trapping network, and N is an integer larger than or equal to 1; updating the constructed attack path according to the association degree between the system log of the Nth network node and the constructed attack path; traversing the system logs of the N network nodes until the system logs collected in the current period are processed. According to the method, all the log data in all the nodes in the virtualized trapping network are integrated, and a complete and comprehensive attack graph is established, so that comprehensive analysis of cross-system and cross-device behaviors of attackers is realized, and the depth and accuracy of existing analysis are improved.
Owner:GUANGZHOU UNIVERSITY