About Us
中文/English
DevSecOpsAISecOpsCNAPP

Huanzhen
Advanced Threat Hunting and Attack Tracing System

Product introduction
Huanzhen advanced threat hunting and attack tracing system is an advanced threat detection and defense system based on attack obfuscation and deception defense technology initiated by MoreSec. From the perspective of attackers, the system confuses the target by setting traps on the path that hackers must take, and accurately senses and traces the attack behavior of hackers. And it will isolate the attack through the cloud honeynet to protect the real assets inside the organizations, creating a crucial security barrier for the organizations.
Product advantages

Advanced threat hunting based on behavior

Based on the self-developed behavior decision engine, it accurately analyzes the attack source, attack path and method type, and provides a comprehensive hacker portrait to help enterprises perceive and defend against 0day risks.

The attack gravitation field like Black holes

The virtual asset node technology and attack takeover technology are used to create a powerful attack gravitation field, engulf all kinds of attacks in the whole link, and suppress the attacks with reverse interference, which increases the cost of confrontation greatly and protects all kinds of organizations assets.

Highly flexible and customized Lego sandbox

Users can upload customized sandbox service images, customize the content, type, and rules of the sandbox. The sandbox has a high degree of customization scalability and unlimited possibilities of arrangement.

Leading sandbox cloud market

We launched the sandbox cloud market in the industry firstly. There are hundreds of highly interactive sandboxes in the cloud market. Users can download and add sandboxes with one click, which greatly enriches the types of sandboxes and helps users build more deception defense scenarios that are more suitable for the organizations environment.

Deception as a Service

As a service, only deception nodes need to be deployed locally, which greatly reduces the local deployment cost. At the same time, attack traffic will be transferred to the cloud, which confuses attackers and prevents attacks from landing to avoid escape risks. The sandbox pool on the cloud has richer deception scenarios and provides newer and timely responses.

The intelligence is linked and connected

Through the self-developed intelligence center, it links with products and components of MoreSec such as Renjia, Jianmu, Huanzhen - relay node, Huanzhen - camouflage agent, etc., to capture the hacker intelligence covering the entire organizations, automating the whole process from monitoring to response, and helping enterprises to deal with advanced threats more easily.
Product features

Intelligent honeynet

The asset service perception ability is integrated into the deception defense to realize the adaption to the surrounding business environment. According to the statistics and mapping of data information from multiple dimensions, the security algorithm is orchestrated to highly fit the deception service to the real business environment so that attackers will fall into the deception honeynet without realizing it. At the same time, through automatic orchestration and one-click deployment, honey network can achieve unpredictable effect, greatly reducing the cost of manual operation, achieving rapid, automatic intelligent deployment.

Lego sandbox

Huanzhen splits the sandbox and service. The service IP, port can be regarded as the basis resources of sandbox, and you can choose one or more services for free combination. Sandbox had the infinite possibility of permutation and combination, which allows users to build freely and avoid the attacker tag behavior for the sandbox, and problems like fewer scenarios caused by restriction of the sandbox types.

Sandbox plug-in

Addition and deletion of Sandbox are completely removed from Huanzhen. Users can regard the sandbox as a plug-in and update the sandbox conveniently and quickly; Users can flexibly customize sandbox service images, sandbox content, type, and even detection logic, which greatly improves the operability of the sandbox while reducing the sandbox production cost. The intelligent honeynet can produce the honeypot quickly according to the latest vulnerabilities, generate the sandbox automatically and the one-click association service. And those honeypots can be pushed to each coverage point of the organizations for emergency detection and response with low cost.

Counter with traceability

Based on the device fingerprint and social ID technology, it identifies the attacker's device, attacker's methods, social ID and so on to help the organizations trace the source of the attacker and establish the deterrence of the defense system. The attack countermeasure technology in Huanzhen establishes a portrait of the attacker through a variety of reverse control means to achieve the highest level of traceability. The countermeasure supports Windows, MacOS, and Android, with more comprehensive coverage and covert camouflage, which is used to build active defense.

Sandbox Cloud Market

Huanzhen is transferred to deception and defense base. Hundreds of highly interactive sandbox in cloud market are those that attackers are interested in according to accumulation in offense and defense drills that MoreSec precipitated in. Users can enter the cloud market in Huanzhen product page, adding sandbox with one-click, building scenario, and extend deceive sandbox types to hundreds.

The attack on the cloud

Through the maintenance of sandbox services and scenarios on the cloud, MoreSec deploys relay nodes and camouflaging agents in the organizations off the cloud to transfer attack traffic to the cloud and avoid escape risks effectively. At the same time, we will provide richer cloud deception scenarios and timely response and update service.

Hacker intelligence linkage system

Through Huanzhen centralized management platform, intelligence center it can link with products and components like Renjia, Jianmu, Huanzhen - relay nodes, Huanzhen - camouflage agent, covering deployment scenario for Internet side and intranet side, realize the perception of deception and automated response in the whole organizations scenes. Once hackers are perceived, the organizations defense system will respond immediately, and form the organizations deception defense panorama covering all scenarios.
Case study

The customer profile

At present, the customer has employees of more than 20,000, with the total assets of more than 74.5 billion yuan. Its annual operating income is more than 42 billion yuan with customers of over 54 million. The scale is in forefront of China Mobile Group in all provinces, which can be regarded as benchmark in Group.

Business challenges

Customers' cloud platforms are often attacked by attackers with different methods, and the detection pressure of malicious attacks is increasing. At the same time, customers also want to improve the technical and professional capabilities in monitoring unknown malicious attack, attack event tracing, and obtaining attacker information effectively.

The solution

MoreSec deployed Huanzhen for the customer with proprietary technologies like deception, fingerprints, multi-network integration, threat detection, attack traceability and recognition for human and machines etc.. It secured the existing business stable operation in cloud platform for the customer and escorted cloud platform for business development. At the same time, it customized the sandbox according to customer requirements and simulated customer's business systems.

Project value

Based on the former security measures in the customer's cloud platform, Huanzhen helps customers change from "passive defense" to "active defense", and improves the detection capability on malicious attacks, provides corresponding gap analysis on the monitoring equipment of the network, guides customers to harden the real server, and wins valuable time for emergency response.

Customer feedback

After careful market research, scientific and rigorous evaluation and comparison, we choose MoreSec Technology as the provider of deception defense technology services for its leading technology and mature products in this field.