The invention discloses a multi-source
attack detection method for computing power cluster security protection, and belongs to the technical field of host security
attack detection. The method comprises the following steps: inputting an
operating system auditing log of a computing node in a computing power cluster to be identified into a pre-trained
time sequence anomaly detection model to calculate an anomaly probability
score of the
operating system auditing log, when the anomaly probability
score exceeds a threshold value, judging that the
operating system auditing log is attacked, and otherwise, judging that the operating
system auditing log is safe; the pre-trained
time sequence anomaly detection model is obtained through the following steps: collecting an operating
system audit log of each computing node, analyzing an event in the log into a standardized quintuple event, and obtaining a global cause and effect
graph based on the event; active entity nodes in the global causal graph are screened, and multi-dimensional
feature coding is carried out to generate a feature sequence; and inputting the feature sequence into a pre-constructed
time sequence anomaly detection model to obtain a trained time sequence anomaly detection model. According to the invention, the problem that the existing detection technology is difficult to restore a cross-host complete
attack link is solved.