The invention discloses a network access
security management system and a dynamic equipment behavior evaluation method, and belongs to the technical field of
network security. The
system aims at the problems that the behavior of a new access device of an
intranet is difficult to assess accurately and the risk of an abnormal device cannot be controlled in real time: when the device is accessed, MAC, fingerprints,
confidentiality levels and timestamps are verified through an
authentication module, and information is stored in a
shared database; the semi-supervised SVM model evaluates the equipment based on historical behaviors and real-time characteristics, and generates a risk integral (PRS); the PRS over-threshold device triggers isolation or permission adjustment. Internal communication adopts an
encryption protocol, external access verifies
authentication information and a PRS through an exit gateway, equipment with qualified authority accesses an external network through a VPN, and equipment with insufficient authority or overdue authority is isolated. And the
system periodically calibrates the dynamic
label, evaluates the threshold value and the PRS logic, and realizes long-term stable operation. The device behavior can be accurately evaluated, the risk is controlled, the internal and external
network security is ensured, and the method is suitable for enterprise internal networks, campus networks, data centers and
Internet of Things.