Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

322 results about "Honeypot" patented technology

In computer terminology, a honeypot is a computer security mechanism set to detect, deflect, or, in some manner, counteract attempts at unauthorized use of information systems. Generally, a honeypot consists of data (for example, in a network site) that appears to be a legitimate part of the site, but is actually isolated and monitored, and that seems to contain information or a resource of value to attackers, who are then blocked. This is similar to police sting operations, colloquially known as "baiting" a suspect.

Ai-controlled sensor network for threat mapping and characterization and risk adjusted response

A system and method for an AI-controlled sensor network for threat mapping and characterization. The system deploys a network of honeypots and sensors across various geographic locations and network segments, collecting and aggregating data on network traffic and potential threats. An AI orchestrator analyzes this data using advanced machine learning models, generating dynamic honeypot profiles and a comprehensive threat landscape. The system can adapt in real-time to emerging threats, optimize resource allocation, and provide actionable intelligence. By correlating data across multiple points, the system offers enhanced threat detection capabilities and proactive cybersecurity measures, surpassing traditional security information and event management (SIEM) tools.
Owner:QOMPLX INC

Dynamic honey point collaborative intelligent threat trapping system and method based on genetic algorithm

The invention discloses a dynamic honey point collaborative intelligent threat trapping system and method based on a genetic algorithm in the technical field of network security, and the system comprises a multi-source information collection and dual-mode output module, a reinforcement learning strategy engine, a graph neural network prediction module, a digital twin simulation environment, a strategy verification and optimization module, and a real network defense execution module. A dynamic honey point deployment strategy is generated in real time through a reinforcement learning strategy engine, and the problem of strategy stiffness is solved; a third-generation non-dominated sorting genetic algorithm (NSGA-III) multi-objective optimization algorithm is used for coordinating honey point density adjustment, trip line sensitivity calibration and other actions; attacking path risks are quantified based on a threat scoring formula, digital twin environment pre-verification and high-risk node precise protection are driven, closed-loop linkage of threat perception, strategy optimization and active trapping is finally achieved, and the intelligent defense capability capable of achieving autonomous evolution is formed.
Owner:积至(海南)信息技术有限公司

Network security analysis early warning system based on artificial intelligence

The invention discloses a network security analysis early warning system based on artificial intelligence, and the system comprises a data collection layer which captures full flow based on DPI, aggregates firewall logs, terminal behaviors and threat intelligence, and constructs a structured data pool; through TLS fingerprint identification of AI driving, the encrypted traffic is penetrated, and a sampling strategy is dynamically adjusted in combination with reinforcement learning. The intelligent analysis layer is used for carrying out cross validation on known threats and abnormal behaviors; the time sequence CNN extracts encrypted traffic features, and a novel threat detector is rapidly generated by using historical attack fragments in combination with a meta-learning framework; sHAP value driving dynamic feature selection and optimization feature vector input; the decision-making early warning layer is used for fusing multi-source features through a Bayesian network and generating 0-100 score risk scores; a self-adaptive threshold module is combined to adjust a score threshold in real time, and a high-risk event is pushed; the collaborative response layer is used for triggering a preset decision tree, deploying a GAN dynamic honeypot to trap an attacker and reversely tracing; the Neo4j visually restores the attack path, and blocking is executed after the threat is confirmed by a progressive response mechanism.
Owner:CHINA GEOLOGICAL SURVEY XINING NATURAL RESOURCES COMPREHENSIVE SURVEY CENT

Ai-generated virtual file honeypots for computing systems behavior-based protection against ransomware attacks

Systems and methods for protecting computing systems against ransomware attacks using AI-generated virtual file honeypots. Generative AI comprising a large language model generates virtual file honeypots automatically in response to attack vectors associated with suspect actors and ransomware families.
Owner:ACRONIS INT

Ransomware protection in advanced injection-based attacks

Systems and methods for ransomware protection in advanced injection-based attacks. The call stack(s) of injected threads are analyzed and a preliminary verdict of benign or malicious can be determined. Additional sensors collect data to associate injected threads with other activities or actors to further estimate the injected thread being benign or malicious. If the threat level is high enough, such as over a given threshold, the preliminary verdict can be determined to be malicious. Subsequently, one or more virtual honeypots are generated for the suspicious threads and the injected thread's response to the virtual honeypots included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Network attack active trapping method based on intelligent scheduling

The invention discloses a network attack active trapping method based on intelligent scheduling, and the method comprises the steps: constructing a dynamic honeypot environment according to a real business system mirror image, simulating the interaction logic and data characteristics of a real business system, and generating a honeypot system; analyzing a network equipment log of an access source according to the security situation awareness platform, and capturing multi-dimensional features to identify attack traffic; dynamically generating a drainage strategy according to an identification result of the security situation awareness platform, and seamlessly switching attack traffic to a honeypot system through load balancing equipment; and recording an attack behavior chain in the honeypot system, extracting an attack tool fingerprint and tracking an attacker identity. Through dynamic simulation environment construction, intelligent traffic scheduling, full-chain traceability and intelligent resource management, high-simulation trapping, accurate attack shunting, credible electronic evidence chain generation and efficient resource utilization are realized, and the active defense efficiency is remarkably improved.
Owner:BANK OF HANGZHOU CO LTD

Market supervision data exchange platform migration and security enhancement method and system based on credential environment

The invention discloses a market supervision data exchange platform migration and security enhancement method and system based on a credential environment, and relates to the technical field of network security. In the data migration process, the consistency and privacy protection of the data are ensured through Hash check and a multi-party security computing technology; a domestic commercial cryptographic algorithm and a quantum resistance encryption technology are introduced, so that the protection capability of the platform to existing security threats is effectively improved, and the resistance to future quantum computing threats is enhanced; an intrusion detection system and a virtual honeypot node are integrated, and a defense strategy is monitored and updated in real time in combination with a deep learning model, so that novel attack behaviors can be detected and coped with in real time; according to an intrusion detection alarm and a block chain audit result, a security policy and resource allocation are dynamically adjusted in combination with a machine learning technology, it is ensured that high-risk nodes are monitored in time, resource allocation is automatically optimized, and the resource utilization efficiency and security of the system are improved.
Owner:江苏省市场监督管理局数据中心

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Honeypot agent data leakage assessment method based on federal DQN reinforcement learning

The invention discloses a method for evaluating honeypot agent data leakage based on federal DQN reinforcement learning, and the method comprises the steps: reasoning an action set executed by an agent from model parameter updating through employing an action leakage risk quantification technology based on a gradient non-zero item characteristic, the matching degree of the reasoned action set and the real action set is used as an action leakage risk index value; state leakage is evaluated step by step from two stages of coarse granularity reconstruction and fine granularity reconstruction by using a hierarchical element inversion evaluation technology of multi-time-step model parameter updating; and taking the similarity between the reconstruction state and the real state as a state leakage risk index value. According to the method, an important basis is provided for formulating a stronger privacy protection mechanism, meanwhile, a privacy enhancement technology in practical application is guided to be developed, and the relationship between model performance and data security is balanced.
Owner:GUANGZHOU UNIVERSITY

PLC high-interaction honeypot system based on multi-agent task splitting and RAG enhancement

The invention relates to the crossing field of industrial control system (ICS) safety and artificial intelligence, and particularly discloses a PLC high-interaction honeypot system based on multi-agent task splitting and RAG enhancement, which adopts a localized multi-agent collaborative architecture based on edge computing and is composed of a high-simulation equipment layer and an intelligent decision-making layer. The high-simulation equipment layer comprises a PLC dynamic mirror image, an HMI interface and a sensor data generator, and an active trapping environment is constructed through protocol fingerprint confusion and virtual and real data fusion technologies. The decision-making layer deploys a multi-agent task scheduling engine, integrates four kinds of agents including protocol analysis, behavior analysis, threat assessment and response generation, and realizes attack context perception and strategy dynamic generation based on a local RAG knowledge base. The load balancing agent dynamically allocates tasks according to equipment resources, and cooperates with offline knowledge update (USB flash disk encryption synchronization threat features) to form a closed-loop defense system, thereby ensuring physical isolation of an industrial network and realizing high-fidelity active defense.
Owner:GUANGZHOU UNIVERSITY

Honey array defense resource allocation optimization method based on self-game reinforcement learning

The invention provides a honey array defense resource allocation optimization method based on self-game reinforcement learning, and relates to the technical field of network security defense. The optimization method comprises the following steps: deploying defense resources based on network topology, and establishing a mapping relationship between a host and the defense resources; performing attack and defense confrontation simulation based on the mapping relation to obtain an initial attack strategy and an initial defense strategy; constructing a Markov game model based on the initial attack strategy and the initial defense strategy; performing self-game reinforcement learning on attack and defense training of the Markov game model based on a depth deterministic strategy gradient algorithm; and carrying out value evaluation on the attack and defense training based on an Actor-Critic algorithm to obtain an optimal defense resource allocation strategy. By implementing the optimization method provided by the invention, the defense party and the attack party can perform self-game reinforcement learning, the defense strategy is dynamically adjusted in confrontation, and the defense effect is improved.
Owner:GUANGZHOU UNIVERSITY

Honeypot-based attack detection

In some examples, a system monitors input / output (I / O) operations to identify data matching a honeypot pattern. The system determines storage location information associated with the data identified as matching the honeypot pattern, and detects an access of the data at a storage location indicated by the storage location information. The system indicates a potential attack based on detecting the access of the data at the storage location indicated by the storage location information.
Owner:HEWLETT PACKARD ENTERPRISE DEV LP

Dynamic honeypot deployment and optimization method and system based on intelligent flow analysis

The invention provides a dynamic honeypot deployment and optimization method and system based on intelligent flow analysis, and belongs to the field of computer security and network security. The method comprises the following steps: collecting network traffic and preprocessing to obtain a feature vector; then, the trained random forest model is used for carrying out attack type identification on the network flow; clustering analysis is carried out on all the attack traffic, similar attack traffic forms clusters, priority ranking is carried out on the clusters, honeypots of corresponding positions and types are deployed according to matching rules in the sequence of the priorities of the clusters from high to low, and the attack traffic belonging to a certain cluster is introduced into the corresponding honeypot; a deep Q network is used in each honeypot for learning, and the optimal balance between the capture rate and the resource utilization rate is realized by modifying the configuration of the honeypot and observing the capture condition of attack traffic and the resource consumption of the honeypot. According to the method, intelligent deployment of the honeypot and dynamic configuration in the honeypot are realized, the attack capture rate of the honeypot is improved, and the resource utilization rate is maximized.
Owner:ZHEJIANG GUOLI SECURITY TECH CO LTD

Automated preemptive polymorphic deception

Embodiments are directed to monitoring network traffic using network monitoring computers (NMCs). Anomalous events may be classified based on the monitored network traffic and attack models such that the classification determines that targets of the anomalous events may be currently subject to attacks by entities communicating on the networks. A honeypot trap may be provided in the networks based on the classified events such that the honeypot trap mimics characteristics of the targets. The portions of the network traffic associated with the honeypot trap may be monitored. Characteristics of the attacks may be determined based on the monitored portions of network traffic. Reports that include information based on the characteristics of the attacks may be generated.
Owner:EXTRAHOP NETWORKS INC

Network security threat detection system and method based on deep learning

The invention discloses a network security threat detection system and method based on deep learning, and particularly relates to the field of network security trapping analysis based on a honeynet and a honeypot, and the method comprises the steps: collecting trapping node log data in a network security behavior trapping process; extracting a behavior event set including access time, request action types, parameter structures and node identifiers, organizing the behavior event set according to a timestamp sequence, and constructing a basic behavior node chain; and performing access sequence consistency check on the behavior node chain. A path map structure based on access tension evolution is constructed in a honeynet environment, a deep learning model is fused to execute trend reasoning and behavior disturbance prediction on a high-tension path segment, and a redundant path induction feedback mechanism is combined to realize preposed recognition and active trapping intervention on an attack path. The problem that high-concealment attacks cannot be perceived and responded in advance in a behavior window period is solved.
Owner:YANCHENG LEDU NETWORK TECHNOLOGY CO LTD

Dynamic Honeypot Generation and Deployment

A computing platform may train a machine learning model to detect and analyze threat actor activities. The computing platform may generate dynamic honeypots and deploy the generated dynamic honeypots as adaptive defenses to threat actors in a computing environment. The computing platform may adapt to threat actor activities based on analyzed behavior of the threat actor and any identified tools used to by the threat actor to gain access to the computing system. The computing platform may cause redirection of the threat actor into a specific computing environment through generation and deployment of dynamic honeypots.
Owner:BANK OF AMERICA CORP

Electric power honeypot construction method and system based on large language model

The invention provides an electric power honeypot construction method and system based on a large language model, and relates to the technical field of network security, and the method comprises the steps: constructing a virtual web server on an original web server, analyzing the request information of a user through a camouflage agent and a request filtering strategy, and dividing the user into a normal user and an attack user; extracting key semantic information according to inquiry information input by an attack user; performing association mapping on the key semantic information and an electric power knowledge graph to obtain an attack intention; according to the attack intention and the request information, virtual power service information is constructed through a large language model and fed back to the attack user, and attack behavior information is obtained; the attack type and the risk level of the attacking user are evaluated, the power deception strategy of the large language model is formulated based on the attack type and the risk level, and the virtual power service information is adjusted, and the technical problem that the defense security is reduced due to the static performance of the honeypot technology in the prior art can be solved.
Owner:POWERCHINA JIANGXI ELECTRIC POWER ENGINEERING CO LTD

Cloud native application security protection and monitoring method and system oriented to financial science and technology

The invention provides a cloud native application security protection and monitoring method and system for financial science and technology, and relates to the technical field of financial science and technology network security, and the method comprises the steps: obtaining multi-dimensional monitoring data, building a security threat knowledge graph, recognizing a high-risk attack path through a graph convolution network, generating a potential threat prediction result, and recognizing an abnormal behavior. And configuring a dynamic honeypot environment, recording behavior tracks of attackers, analyzing attack intentions and technical characteristics, and generating and deploying protection rules in real time. According to the invention, the safety protection capability of the financial cloud environment is improved, and intelligent threat prediction and active defense are realized.
Owner:JIANGSU YAOER LINGJIU TECHNOLOGY SERVICE CO LTD

Agent-free honeypot mapping method and device

The invention discloses an agent-free honeypot mapping method and device, and relates to the technical field of network security. The method comprises the following steps: analyzing metadata of core switching equipment, and establishing a domain-address mapping matrix; periodically detecting an address space, constructing an IP asset dynamic portrait and generating an asset state map; deploying a cross-domain traffic forwarding protocol stack and a virtual domain identifier mapping rule; deploying a software-defined virtual switching unit and accessing the virtual honeypot probe cluster; allocating idle addresses for the probes and establishing a binding relationship; and periodically detecting and triggering a self-healing process when an address conflict occurs. The device comprises a core exchange and domain management unit, an IP asset detection unit, a network protocol configuration unit, a probe virtualization management unit, an address resource scheduling unit and a system cooperative control unit. According to the method, agency-free and automatic deployment of the honeypot is realized, and the problems that a traditional scheme depends on agency software, deployment is complex and IP conflict processing lags are solved.
Owner:NANJING JINGWEI XINAN TECH CO LTD +1

Industrial field network security honeypot simulation and threat trapping system

The invention discloses an industrial field network security honeypot simulation and threat trapping system, which comprises an industrial control system, the industrial control system comprises an industrial protocol simulation honeypot engine, an intelligent dynamic configuration module, a context awareness analysis module, an integrated response and blocking module, a threat intelligence and situation awareness platform, a physical layer defense subsystem and a compliance report generation module. The industrial protocol simulation honeypot engine is arranged at a key position in an industrial control system, the industrial protocol simulation honeypot engine is used for simulating communication behaviors of Modbus TCP / IP, OPC UA and Profinet, the industrial protocol simulation honeypot engine dynamically adapts to equipment start and stop and protocol parameter changes, the industrial protocol simulation honeypot engine simulates an industrial environment, and the industrial control system is connected with the industrial control system. Intrusion and attack behaviors for the industrial system are induced and captured. Through cooperation of multiple modules, safety protection of the industrial control system is comprehensively improved, risks are reduced, stable operation is ensured, compliance requirements are met, and competitiveness is enhanced.
Owner:SAISHENG DIGITAL ECONOMY RESEARCH INSTITUTE (GUANGZHOU) CO LTD

Honeynet-based attack trapping and analyzing method and system

The invention discloses an attack trapping and analyzing method and system based on a honeynet, and relates to the technical field of attack analysis, and the method comprises the steps: collecting attack interaction data and an associated attack chain trajectory set; dividing attack behavior units, and constructing a behavior space attitude matrix; constructing a two-dimensional behavior relationship graph, performing interpolation enhancement of sub-time granularity, and raising the dimension of the interpolated behavior node into a three-dimensional semantic space; performing attack path trend analysis on the attack behavior unit, and constructing an attack path bending rule model; and inputting parameters such as the attack chain trajectory set and behavior nodes in the three-dimensional semantic space into the attack path bending rule model, outputting a trapping response strategy, and dynamically adjusting the honeynet environment. According to the invention, the type and position of the honeypot can be automatically adjusted according to the attack behavior change, the structure definition and processing precision of the attack behavior data are effectively improved, and the attack behavior identification result can be conveniently and directly used for trapping strategy optimization.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO

Honeypot configuration method based on graph neural network

The invention provides a honeypot configuration method based on a graph neural network. The honeypot configuration method comprises the following steps: collecting network situation data; calculating a node connection relation carried by edges of a network situation map according to the network situation data, and constructing a node feature vector to construct the network situation map; performing graph embedding processing to obtain a first feature matrix for representing node vectors in the graph; inputting the network situation map and the first feature matrix into a graph neural network, extracting node information and pooling feature expression of the node information by the graph neural network, reading node features obtained by each processing module, and splicing the node features obtained by the C processing modules to form a second feature matrix for performing security state classification and prediction on the nodes; and judging an attack situation according to the network situation maps at different time points, and generating a honeypot deployment strategy for the attack situation for adjusting honeypot resource configuration. By applying the method, the deployment strategy of the honeypot can be dynamically adjusted, and the change of a network environment and complex attack behaviors can be quickly responded.
Owner:GUANGZHOU UNIVERSITY

Electric power protocol honeypot trapping and abnormity identification method based on GAN

The invention discloses a GAN-based electric power protocol honeypot trapping and anomaly identification method, which comprises the following steps: constructing a data set by collecting real traffic of an electric power protocol, generating diversified attack samples conforming to protocol grammar by using a GAN of a Transform architecture, and improving robustness by combining data enhancement technologies such as random truncation and noise injection. Virtual honeypot equipment is deployed to simulate power equipment behaviors, attack logs and traffic features are fused in real time, a graph neural network is adopted to model a cross-message interaction relation, and self-supervised learning is introduced to detect semantic anomaly. Experiments show that the method realizes 98.2% of detection accuracy on data sets such as IEEE 123-Bus and the like, supports dynamic adaptation of protocol versions, realizes accurate tracing of attack source IP and intention through honeypot log association analysis, and effectively improves the active defense capability of a power system to novel attacks.
Owner:INFORMATION & COMM CO OF STATE GRID JILIN ELECTRIC POWER CO LTD

System, Apparatus, and Method to Generate Decoy Honeypots by Using Generated Adversarial Networks

A system, apparatus, and method to generate decoy honeypots by using generated adversarial networks. In some embodiments, a method for generating decoy honeypots, the steps comprising identifying a plurality of network device configurations on a network; instantiating a generative adversarial network comprising architecture properties; generating a plurality of decoy honeypots with the generative adversarial network, wherein the plurality of decoy honeypots imitate the plurality of network device configurations to deceive malicious actors, and wherein the generative adversarial network optimizes a distribution of the plurality of decoy honeypots according to a precision distribution and a recall distribution; activating the plurality of decoy honeypots to the network; and dynamically evolving the plurality of decoy honeypots towards one or more preferences of a network attacker.
Owner:THE UNITED STATES OF AMERICA AS REPRESENTED BY THE SECRETARY OF THE NAVY

Virtual file honey pots for computing systems behavior-based protection against ransomware attacks

Systems and methods for ransomware protection in advanced injection-based attacks. Events from a driver are analyzed to identify a potentially malicious actor. A confidence level is calculated for the potentially malicious actor identification to weigh the probability that the actor is malware or a source of malware. Behavior associated with the potentially malicious actor can be collected, if it is likely that the potentially malicious actor is associated with malware, such as if the confidence level is over a predetermined threshold. Subsequently, one or more virtual honeypots are generated for the suspicious processes and the response to the virtual honeypots is included in anti-ransomware heuristic analysis.
Owner:ACRONIS INT

Vehicle internal network intrusion detection method, system and device and storage medium

The invention belongs to the technical field of intrusion detection, and relates to a vehicle internal network intrusion detection method, system and device and a storage medium, and the method comprises the steps: 1) carrying out the data mining of a data flow of a vehicle internal area control bus network CAN in a normal state, and generating a detection rule, so as to form a rule base; 2) generating a forged node and data containing the forged node by using a honeypot system, and injecting the data containing the forged node into a real-time data stream of an in-vehicle regional control bus network CAN; 3) detecting the real-time data flow of the area control bus network CAN in the vehicle through the rule base; 4) verifying the data which does not pass the detection of the rule base and has the same node ID as the forged node ID by the honeypot system; and 5) sending the data which does not pass the verification of the honeypot system to an alarm response module for response so as to realize intrusion detection. Rapid detection of intrusion can be realized, and injection data forged by a honeypot system can be prevented from being misjudged.
Owner:BEIHANG UNIV

Honeypot interaction response generation method based on large language model

A honeypot interaction response generation method based on a large language model comprises the steps that an attacker initiates a malicious request, a firewall carries out screening based on a white list, and traffic matched with the white list is forwarded to an actual application server through a honeypot system; for the traffic not in the white list, redirecting the traffic to a honeypot system; a honeypot interaction response system is deployed in the honeypot system and comprises an embedding module, a coding module and a response decoding module, so that induction response is automatically generated and sent to an attacker, and meanwhile alarm information is generated and sent to safety analysts. The method comprises the following steps: firstly, converting input data into a vector form by using an embedding module, extracting overall characteristics of a request by using a coding module, and finally, generating an induced response by using a response decoding module. According to the method, the advantages of a large language model in the aspects of semantic comprehension, context modeling and generation capability are fully utilized, and accurate perception of attack behaviors and automatic generation of response contents are realized.
Owner:NANJING COLLEGE OF INFORMATION TECH

High-interaction deception defense and attack tracing method based on RASP technology

The invention discloses a high-interaction deception defense and attack tracing method based on an RASP technology, and the method specifically comprises the following steps: S1, RASP implantation and bait deployment, S2, attack detection and simulation triggering, S3, attack session redirection and high-interaction deception, S4, attack behavior monitoring and tracing data collection, and S5, tracing analysis and threat disposal. The invention relates to the technical field of network and information security. According to the high-interaction deception defense and attack tracing method based on the RASP technology, a deception mechanism is embedded into a real application / system in operation, and high fusion of a real business environment and a false trapping environment is achieved. Different from a traditional'main-auxiliary separation 'mode that a honeypot is placed in an independent network or a host, the method has the advantage that the application can be changed to generate a'trap' during running through the RASP. The seamless embedded spoofing makes attackers difficult to distinguish true and false: the attackers attack a part of a production system initially, and then are introduced into a parallel simulation space unconsciously.
Owner:WEIHAI POWER SUPPLY COMPANY OF STATE GRID SHANDONG ELECTRIC POWER COMPANY

Honeypot automatic coping strategy generation method based on large model

The invention discloses a honeypot automatic coping strategy generation method based on a large model. The method comprises the steps of S1, performing semantic analysis on dynamic attack behaviors; s2, performing context-aware threat reasoning; s3, adaptive strategy generation and semantic verification are carried out; s4, strategy executable compiling is carried out; s5, enhancing the efficiency of the closed-loop strategy; according to the method, the authority / service logic contradiction is thoroughly eliminated through a semantic consistency verification mechanism, so that the false alarm rate of the honeypot in the APT attack is reduced; an anti-recognition perturbation code injected by the low-entropy strategy compiling technology breaks through a traditional honeypot periodic response mode, and the fingerprint recognition success rate of an attacker is reduced; a resource penalty function of the Pareto optimal strategy sequence enables a trapping intensity mean value under limited resources to be improved; a double-channel updating mechanism promotes coevolution of a knowledge base and a constraint set, and the response generation speed for an unknown attack mode is shortened.
Owner:SHENZHEN FANYUN SHUZHI TECH CO LTD

Trapping system implementation method based on intelligent large model

The invention relates to a trapping system implementation method based on an intelligent large model, and belongs to the technical field of network security. According to the method, the attacker message is intercepted, meanwhile, the intelligent large model is utilized to generate various false messages meeting the expectation of the attacker, the false messages are returned to the attacker, so that the attacker is attracted to further attack, finally, the attack traffic is redirected and pulled to a high-interaction and high-simulation honeypot simulation environment, and trapping of the attacker is achieved. The intelligent false message generated as required is used as a bait, so that a large amount of expenditure cost for actually constructing the honeypot can be saved, and the diversity of the functions of the existing honeypot is expanded more intelligently and dynamically.
Owner:BEIJING INST OF COMP TECH & APPL