The invention relates to the technical field of
network security defense, in particular to a distributed
threat intelligent honeynet
trapping method, which comprises the following steps: S1, on the basis of an
attack deception defense technology, constructing a trap on the inevitable way of a
hacker, confusing the
attack target of the
hacker, accurately sensing the
attack behavior of the
hacker, and guiding and isolating the attack traffic into an intelligent honeynet; and S2, combining attack countering and attack tracing to accurately obtain network identity and
fingerprint information of the hacker. According to the distributed
threat intelligent honeynet
trapping method, through dynamic
assembly of a bait environment and a monitoring module and reconstruction of a polymorphic module, resources of basic elements (a sandbox, bait and the like) forming the intelligent honeynet are servitized, and the maximum flexibility is ensured through
modular design. When deception resources are deployed, different types of sandboxes can be randomly arranged according to an existing template or a user-defined mode, various disguise
confusion capability combinations adaptive to a typical
power application scene are called, and existing anti-
trapping techniques and tactics of attackers can be effectively coped with.