Title:
NETWORK TRAFFIC SENDING METHOD AND APPARATUS, AND HYBRID HONEYPOT SYSTEM
Document Type and Number:
WIPO Patent Application WO/2019/127141
Kind Code:
A1
Abstract:
The present invention provides a network traffic sending method and apparatus, and a hybrid honeypot system. The method includes: receiving a first attack traffic flow; determining that a request type of the first attack traffic flow is a first request type and determining maturity of a virtual honeypot model for the first request type; and if the maturity of the virtual honeypot model for the first request type is higher than a preset maturity threshold that is set for the first request type, forwarding the first attack traffic flow to a virtual honeypot using the model, or forwarding the first attack traffic flow to a virtual honeypot using the model and a physical honeypot; otherwise, forwarding the first attack traffic flow to a physical honeypot. Therefore, a virtual honeypot using a virtual honeypot model of relatively high maturity is used to respond to an attack traffic flow, and is not easily identified by an attacker.
Inventors:
LI RUI (CN)
QI LIN (CN)
QI LIN (CN)
Application Number:
PCT/CN2017/119117
Publication Date:
July 04, 2019
Filing Date:
December 27, 2017
Export Citation:
Assignee:
SIEMENS AG (DE)
LI RUI (CN)
QI LIN (CN)
LI RUI (CN)
QI LIN (CN)
International Classes:
H04L9/36
Foreign References:
CN101087196A | 2007-12-12 | |||
CN104506507A | 2015-04-08 | |||
CN107426242A | 2017-12-01 | |||
US20160164894A1 | 2016-06-09 |
Other References:
FAN ET AL.: "Adaptive and Flexible Virtual Honeynet", ICIAP, 25 November 2015 (2015-11-25)
Attorney, Agent or Firm:
KANGXIN PARTNERS, P.C. (CN)
Download PDF: