The invention discloses a
software operation state monitoring method based on
software safe operation, relates to the technical field of
software operation, and solves the problem that the trend and continuity of flow change are ignored because only matching is carried out for a flow value at a single moment or an isolated
attack feature. According to the method, through the multi-layer
verification process of feature mean value comparison, recognition section locking and curve
overlap ratio analysis, the undetermined
attack features can be quickly screened out, and through the movement comparison of the recognition sections in the flow change curve, the matching degree is quantified through the
overlap ratio, so that the
attack feature recognition accuracy is greatly improved; meanwhile, in combination with secondary
verification of historical interaction characteristics, buffer testing is carried out on abnormal traffic appearing for the first time, and
data security is judged according to registry generation conditions, so that misjudgment on known normal fluctuation is avoided, novel attack data can be effectively identified, and double targets of'reducing false alarms' and'covering unknown threats' are achieved.