WO2026118391 - CYBER ATTACK THREAT TRAPPING METHOD, APPARATUS AND DEVICE

National phase entry is expected:
Publication Number WO/2026/118391
Publication Date 11.06.2026
International Application No. PCT/CN2025/096636
International Filing Date 22.05.2025
Title **
[English] CYBER ATTACK THREAT TRAPPING METHOD, APPARATUS AND DEVICE
[French] PROCÉDÉ, APPAREIL ET DISPOSITIF DE PIÉGEAGE DE MENACE DE CYBERATTAQUE
[Chinese] 一种网络攻击威胁诱捕方法、装置及设备
Applicants **
SHANGHAI MOULE NETWORK TECHNOLOGY CO., LTD
Inventors
SHANG, Xia
LUO, Qinglan
CHEN, Ning
ZHANG, Xuesong
Priority Data
202411772103.X   04.12.2024   CN
Application details
Total Number of Claims/PCT *
Number of Independent Claims *
Number of Priorities *
Number of Multi-Dependent Claims *
Number of Drawings *
Pages for Publication *
Number of Pages with Drawings *
Pages of Specification *
*
Number of Office Actions *
*
International Searching Authority
*
Recordal of a Change of the Applicant's Name/Address
*
Type of Assignment
*
Applicant's Legal Status
*
*
*
*
*
*
Entry into National Phase under
*
Patent Delivery
*
Translation

* The data is based on automatic recognition. Please verify and amend if necessary.

** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.

Quotation for National Phase entry

Country StagesTotal
China Filing, Examination, Granting1573
EPO Filing, Examination, Granting11565
Japan Filing, Examination, Granting2016
South Korea Filing, Examination, Granting1784
USA Filing, Examination, Granting4740
MasterCard Visa
Total: 21,678
Contact Us
Abstract[English] The present invention relates to a cyber attack threat trapping method, apparatus and device. The method comprises: sequentially performing preprocessing and prompt engineering processing on a web intrusion request; using a detection model to determine whether the processed web intrusion request is an attack request, and if the processed web intrusion request is an attack request, generating an attack type result; on the basis of an existing website resource and related data, constructing an attack knowledge base corresponding to different network attack types; on the basis of the attack type result and attack content of the web intrusion request, retrieving similar data from the attack knowledge base; and concatenating the attack content and the similar data, and then inputting same into a first large language model to obtain a simulated response for the attack content. The technical solution provided in the present invention can use the detection model to accurately identify the type of the attack request, thereby improving the detection capability. The obtained simulated response can interact with an attacker in a more complex and flexible manner, thereby better deceiving an attack behavior and trapping same.[French] La présente invention concerne un procédé, un appareil et un dispositif de piégeage de menace de cyberattaque. Le procédé consiste à : effectuer séquentiellement un prétraitement et un traitement d'ingénierie de requête sur une demande d'intrusion Web ; utiliser un modèle de détection pour déterminer si la demande d'intrusion Web traitée est une demande d'attaque, et si la demande d'intrusion Web traitée est une demande d'attaque, générer un résultat de type attaque ; sur la base d'une ressource de site Web existante et de données associées, construire une base de connaissances d'attaque correspondant à différents types d'attaque de réseau ; sur la base du résultat de type attaque et du contenu d'attaque de la demande d'intrusion Web, récupérer des données similaires à partir de la base de connaissances d'attaque ; et concaténer le contenu d'attaque et les données similaires, puis les entrer dans un premier grand modèle de langage pour obtenir une réponse simulée pour le contenu d'attaque. La solution technique fournie dans la présente invention peut utiliser le modèle de détection pour identifier avec précision le type de la demande d'attaque, ce qui permet d'améliorer la capacité de détection. La réponse simulée obtenue peut interagir avec un attaquant de manière plus complexe et flexible, ce qui permet de mieux feindre un comportement d'attaque et de le piéger.[Chinese] 本发明涉及一种网络攻击威胁诱捕方法、装置及设备,能够对Web入侵请求依次进行预处理和提示工程加工;利用检测模型判断加工后的Web入侵请求是否为攻击请求,若是,则生成攻击类型结果;根据现有的网站资源和相关数据构建得到对应不同网络攻击类型的攻击知识库;根据Web入侵请求的攻击类型结果和攻击内容,从所述攻击知识库中检索得到相似数据;将所述攻击内容和所述相似数据拼接后,输入至第一大语言模型,得到针对攻击内容的模拟响应。本发明示出的技术方案,能够利用检测模型准确识别攻击请求的类型,提高了检测能力。得到的模拟响应能够与攻击者进行更加复杂和灵活的交互,从而更好地欺骗攻击行为并对其进行诱捕。

Rejoining the server...