The invention provides a flow analysis and
threat detection method and device based on
machine learning, and the method comprises the steps: collecting a real-time flow data
package of a target network environment, carrying out the protocol analysis and session recombination, and generating a real-time flow
feature data set containing multi-dimensional flow features; loading a pre-trained multi-level
threat classification model, inputting the real-time traffic
feature data set into a
feature extraction layer of the model, carrying out normalized coding on traffic features of corresponding dimensions through
feature coding channels, generating a real-time
feature vector sequence, inputting the real-time
feature vector sequence into a primary classifier of the model, and classifying the real-time traffic features according to the real-time
feature vector sequence; and performing abnormal probability calculation and cluster division on the real-time feature vector sequence through a mixed detection unit, outputting a primary
threat tag and an abnormal confidence coefficient corresponding to each real-time feature vector, inputting the primary threat tag and the abnormal confidence coefficient into an aggregation classifier, performing dynamic weighted aggregation, and generating a comprehensive threat
score so as to judge whether a threat
response strategy is triggered or not. According to the invention, the accuracy and timeliness of threat detection in a
complex network environment can be improved.