The invention relates to a network theft behavior detecting method based on HTTP flow analysis. The method comprises the steps of establishing a C&C
server blacklist database, acquiring DNS and HTTP protocol flow in a random
time segment and performing analysis restoring, performing abnormal data
elimination on HTTP traffic data generated in accessing a normal
server, performing statistics, determining a to-be-determined abnormal behavior item and a detecting use threshold, detecting whether an abnormal behavior of a
computer device in a network of an organization, if yes, performing alarming, storing a data packet in a
database, and performing risk analysis and
processing on alarming. According to the network theft behavior detecting method,
network behavior characteristic analysis is performed on a tool and malicious
software which transmit sensitive data based on an HTTP protocol, thereby determining an abnormal behavior characteristic. A threshold value is determined through performing statistics on the HTTP traffic at the network entrance of the organization, thereby identifying a sensitive
data transmission behavior by a
trojan horse on the attacked
computer device. The network theft behavior detecting method has advantages of low alarm error rate, low alarm omission rate, high accuracy and high feasibility. The network theft behavior detecting method is suitable for organizations, individuals and large-scale high-speed network.