The invention discloses a
network security investigation method based on a behavior sequence, and relates to the technical field of
network security, which comprises the following steps: performing normalization
processing on massive heterogeneous original logs to construct a uniform
event stream basis, introducing a double attention coding mechanism, performing local context focusing on a normalized
event stream on an
event level, and obtaining a uniform
event stream; according to the method, the short-term intention of the threatening threatening
system is analyzed to construct a tactical fragment sequence capable of representing the short-term intention, then long-time-sequence context focusing is carried out again on the tactical level, the discrete tactical fragment sequences are aggregated into global context representation capable of describing a complete
attack chain, and finally accurate threatening scoring is carried out based on the global context. Therefore, by performing automatic and deep construction and
cognition on the context scene of the
attack behavior, accurate and efficient investigation on complex attacks can be realized, so that the automatic analysis level and response capability of
network security threats are effectively improved.