Automatic Expansion and Contraction of Trapping Resources Based on Electric Power Environment
Rixuan Qiu, Zhiyuan Luo, Qun He, Tianfu Xu, Yingkai Fan, Haoqin Chen, Naqin Zhou · 2025
In electrical system network security, honeypot technology ensnares attackers by emulating critical infrastructure, while automated Kubernetes management facilitates large-scale deployment. Nonetheless, the conventional Kubernetes scheduling mechanism exhibits limitations: firstly, the scaling strategies, such as Horizontal Pod Autoscaler (HPA), depend on CPU and memory metrics, neglecting attack detection frequency and other operational characteristics, potentially resulting in suboptimal resource allocation; secondly, the static configuration approach struggles to manage abrupt attack traffic and the delayed resource recovery during low-load periods, which can precipitate competitive resource overruns, leading to delayed honeypot responses or even failures in Advanced Persistent Threat (APT) detection. To address these issues, we propose a cost-aware trapping resource hot-loading controller (CATRHL Controller). Its dynamic hot-loading mechanism achieves elastic resource scaling during attack peaks and suspended resource recovery during idle phases. The core technologies encompass an attack characteristics resource consumption quantization model, sliding time window load prediction algorithms, and container hot migration technology. Experimental results demonstrate that compared to the default Kubernetes controller, our solution reduces system response time from 500ms to under 100ms while decreasing resource costs by 10% to 19.7%. This markedly enhances the stealth and stability of honeypot clusters under conditions of significant load variability, thereby offering robust support for critical infrastructure defense.