Honeycenter Technology
摘要
This chapter presents a proactive defense architecture centered on a HoneyCenter and driven by tactics, techniques, and procedures (TTP) prediction. It integrates three innovations: (i) attack-intent inference that realizes precise prediction of attack paths under the “unknowns-against-unknowns” principle; (ii) HoneyCenter scheduling guided by attacker preferences, enabling on-demand orchestration of deception resources as behaviors evolve; and (iii) traceable, scenario-customized deception pits (honey holes) for cross-session tracking and real-time countermeasures. We propose a unified behavioral embedding for system, network, and application activities; construct an APT knowledge graph from heterogeneous threat intelligence; learn interpretable mapping rules for TTP inference fused with IoCs; and prescreen scenario fitness via automated simulation. We further design a preference-driven dynamic path prediction algorithm and a control-defense graph (CDG) strategy with a Markov-based optimization model for predictive resource scheduling, yielding an anticipatory, adaptive, and intelligent defense loop.