Safeguard Defense (SD) Mode and Threat Modeling
摘要
APTs have posed a growing challenge to conventional intrusion detection systems and static Honeypots, which often lack the adaptability, stealth, and analytical depth needed to uncover covert and evolving attack strategies. Existing Honeypot platforms provide isolated decoy services but fail to continuously track adversarial behavior or adaptively respond to emerging threats. Moreover, these systems lack integration with advanced analysis mechanisms for understanding threat provenance and intent. To address these challenges, we propose Honey-4, a deception-based framework designed to operate in stealth mode, engage with sophisticated adversaries, and extract actionable threat intelligence across multiple phases of the attack lifecycle (This chapter was supported by the Strategic Research and Consulting Project of the Chinese Academy of Engineering (No.2023-JB-13)).