H$^{4}$4: A Software-Defined Deception Defense System in Safeguard Defense Mode
Rui Wang, Yuan Liu, Yanbin Sun, Shen Su, Binxing Fang, Zhihong Tian · IEEE Transactions on Dependable and Secure Computing · 2025
In the battlefield of cyberspace, sophisticated attackers often operate by following meticulously designed cyber kill chains, enabling them to maintain a persistent presence within victim systems while evading conventional detection mechanisms. Traditional honeypot-based deception defenses aim to uncover such threats by luring attackers into exposing their malicious activities through decoy systems. However, advanced attackers are frequently able to identify and avoid these traps, making it increasingly challenging to detect and engage them effectively. To overcome this challenge, this study proposes a novel defensive paradigm named as the safeguard mode, which emphasizes the covert identification of attackers rather than solely preventing initial breaches. By proactively recognizing potential threats in a hidden manner, victim systems can be better protected through early threat intelligence. Based on the propsoed safeguard mode concept, we propose$Honey^{4}$, abbreviated as$H^{4}$, a comprehensive framework designed to systematically entrap advanced threats.$H^{4}$comprises four core components: Honeypoint, Honeyproxy, Honeytrace, and Honeycenter, which work in concert to deceive, monitor, and analyze attacker behavior. Furthermore, we explore how Artificial Intelligence Generated Content (AIGC) techniques can enhance$H^{4}$'s capabilities, particularly as attackers themselves begin to leverage AI-driven tactics. The practical efficacy of the proposed safeguard mode and the$H^{4}$framework has been validated through being deployed in real scenarios including the 19th Asian Games and the Canton Fairs, and$H^{4}$has successfully captured a significant number of threatening IP addresses and malicious behavioral patterns, generating actionable cyber threat intelligence that fundamentally safeguards system defense.