The method comprises the following steps: constructing an intelligent research and judgment model, carrying out environment modeling on the intelligent research and judgment model, constructing a
network attack path according to the intelligent research and judgment model, and identifying a
network attack by using a known signature of the
network attack or a rule-based detection technology; classifying and marking the data of the
network security equipment by using an SVM classification
algorithm, training an intelligent study and judgment model, establishing a
threat identification strategy of the network
attack, and identifying the features of the network
attack; performing context learning and
state prediction by using the intelligent study and judgment model, and optimizing a
threat identification strategy of network attacks; a
data field of a normal HTTP request is slightly disturbed, an adversarial sample is generated by using a
threat of a known network
attack, adversarial training is performed in combination with a forged HTTP request, and a deceptive network attack is identified. According to the method,
cross validation and
correlation analysis of high-quality and multi-source
threat intelligence are realized, and the attack defense capability is improved.