The invention relates to the technical field of
network security, and discloses a
network defense method, device and equipment, a storage medium and a
computer program product.The method comprises the steps that whether malicious oscillation exists or not is judged according to at least one of
route change information of a
border gateway protocol, a time window threshold value and a
route updating frequency threshold value; and analyzing the current traffic characteristics through an
attack detection model, judging whether an
attack behavior of distributed denial of service exists, limiting the speed of the current network traffic according to the malicious oscillation characteristics, and guiding the
attack traffic of the attack behavior to a
black hole address based on the extracted attack characteristics. According to the application, malicious oscillation and attack behaviors are monitored and identified in real time, when malicious oscillation is detected, the speed of the current network flow is limited according to the characteristics of the malicious oscillation, for the attack behaviors, the attack flow is guided to the
black hole address based on the extracted attack characteristics, the attack source is quickly blocked, and a dual detection and response mechanism is adopted. And the timeliness and effectiveness of
network defense are improved.