The invention relates to an ATT&CK-based spoofing defense
system, construction method and full-link defense implementation method.
Attack technology of each technical point under each tactic in an ATT& CK framework is researched. In the initial
database, a spoofing defense technology corresponding to each
attack technology is given from tactical and technical levels; all spoofing defense technologies are hierarchically divided according to different action points of the network deception technology; an initial
database is constructed from three dimensions of tactics, technology and action points; and in combination with the network asset condition in the current environment. For the behavior of the attacker in each stage during the intrusion period, spoofing defense technology is selectedfrom an initial
database in three dimensions of tactics, technology and action point to fuse with the current network asset condition, and constructing an omnibearing spoofing defense
system. Spoofing technology runs through the whole life cycle of an
attack link, the TTP of an attacker is detected, defended and responded, and active
trapping is carried out from the perspective of the attacker.