The application discloses an abnormal flow cooperative detection method and
system, relates to the field of
network communication, and comprises the following steps: protocol
adaptive identification and dynamic
attack detection are carried out on a north-south WAF layer,
attack fingerprints are generated, and global session IDs are bound; the application behavior is monitored in a whole link on an east-west
RASP layer, context association and
threat analysis are realized through the session IDs; WAF and
RASP data are aggregated based on the session IDs, an
attack feature propagation graph is constructed, and attack chain confidence is evaluated; when the confidence exceeds a threshold value, attack features are extracted by the
RASP layer, virtual patch rules are generated, and feedback is fed back to the WAF layer for real-time updating; finally, bidirectional confidence fusion decision is realized through the WAF and the RASP, and cooperative blocking is realized. The application solves the problem that the north-south and east-west detection are split in the prior art, and cross-layer attack chains cannot be effectively blocked, realizes accurate and dynamic protection on complex attacks, especially encrypted flow and horizontal penetration.