The invention relates to a cloud-based active immune security defense method and device. The method mainly comprises the following steps: an immune 
library management module establishes a mirror imagevirtual 
machine system which is completely consistent with an off-cloud instance 
system in an initial state in cloud; the immune cleaning module pushes the in-cloud 
mirror image system to the out-of-cloud instance system for replacement, the operation and maintenance instance system and the in-cloud 
mirror image system are kept completely consistent, and meanwhile, inconsistent heterogeneous 
software is identified; the immune updating module carries out security upgrading on the in-cloud 
mirror image system; and the 
immune agent module operates in a hardware 
remote guidance state in the cloudexternal instance system, receives a cleaning instruction issued by the cloud immune cleaning module, and executes a cleaning action. According to the invention, 
high security of the system can be realized, risks of continuous penetration and invasion of advanced threats on a system 
attack surface exposed in a network environment and an operation environment for a long time are reduced, white lists of abnormal programs such as backdoors, Trojans and the like are identified, the system is periodically restored to an initial state, cloud and terminals are isolated in a one-way manner, and 
active immunization is realized.