The invention belongs to the technical field of
network security and security operation, and relates to a hidden
attack detection method and
system based on UEBA and AI agents, and the method comprises the steps: carrying out the analysis, mapping,
time sequence correction and entity disambiguation of multi-source behavior data and security
event data, and obtaining a standardized event containing a unified
entity identifier and a unified time identifier; establishing a behavior baseline based on the standardized event, and performing abnormal detection to generate an alarm containing risk grading and evidence identification; the evidence block vectors are put into a
database, and context evidences are retrieved under the constraint of entities and time;
time sequence data and a
knowledge graph are constructed based on the context, and a candidate
attack chain is searched; the AI intelligent experience
certificate generates a
certificate chain update risk and outputs a disposal judgment; and the
processing and certification chain feedback attribution is used for updating the baseline, and detection, retrieval and chain scoring rules are carried out. According to the technical scheme, the hidden
attack research and judgment basis stability and the disposal decision consistency can be improved, and the reliability and
traceability of detection and
verification are enhanced.