The present application relates to a kind of
network security CTF competition multi-class
cheating identification and
trace analysis method, belong to
network security technical field.The present application first monitors and records log to the process of player competition answering question;Then use
finite state machine to analyze the logic
abnormality of player of answering question step, based on normal distribution to judge the time
abnormality of answering question step of player, and according to flag submission time, propose player correlation degree calculation method, find suspicious high similarity player, analyze and trace back the source of player
cheating;Finally, collect and comprehensively judge suspicious player Writeup, answering question log under new and old environment, output
cheating identification result and analysis report.The method effectively identifies the cheating behaviors in CTF competition, such as proxy participation, multiple accounts, plagiarism of other players' flags or solution ideas, and locates suspicious similar players.