The application provides a method and
system for alarm research and judgment and empowerment optimization based on reinforcement
adaptation, which comprises constructing an intelligent research and judgment model, modeling the environment of the intelligent research and judgment model, constructing a
network attack path according to the intelligent research and judgment model, and identifying a
network attack by using a known signature of the
network attack or a rule-based detection technology; classifying and labeling data of a
network security device by using an SVM classification
algorithm and training the intelligent research and judgment model, establishing a
threat identification strategy of the network
attack, and identifying features of the network
attack; performing context learning and
state prediction by using the intelligent research and judgment model, and optimizing the
threat identification strategy of the network
attack; generating adversarial samples by using known threats of the network attack through slight perturbation of data fields of normal HTTP requests, and performing adversarial training in combination with fake HTTP requests to identify deceptive network attacks. The application realizes cross
verification and
correlation analysis of high-quality and multi-source
threat intelligence, and improves attack defense capability.