The invention discloses an intrusion kernel defense method and device, computing equipment and a computer storage medium, and the method comprises the steps: carrying out the detection of a process through an intrusion kernel detection
system, and judging whether the process is the process of an intrusion kernel or not; if yes, freezing the process, and obtaining calling information related to theprocess; and determining and restoring the
attack content of the process according to the calling information. After the process invading the kernel is detected, the process is frozen, so that the process is kept in the current state, currently occupied resources are not released, and attacks cannot be continued. For the frozen process, the calling information of the process is acquired and analyzed, and the
attack content of the process is determined and restored, so that the content modified by the
attack is recovered, and the problems of
system crash and the like are avoided.