The invention discloses a
network attack analysis method. Through the method, the current
network attack condition can be evaluated and the
attack situation deserving most attention currently can be described according to a huge amount of logs produced by an
intrusion detection system. The method comprises the following steps: acquiring the logs of an
intrusion detection system, and judging whether there is a large-scale
network attack event by calculating the distribution of the source addresses and destination addresses of the logs of the
intrusion detection system; merging the logs of the intrusion detection
system according to three parameters, namely,
source address, destination address and
event type, and detecting and reporting abnormal addresses and hot events; making a
statistical analysis of and displaying the propagation process of the hot events in a specified period of time; and associating the output results, and presenting a comprehensive evaluation of the current network
attack condition. The
system comprises an entropy module unit, a triple module unit, a hot
event propagation display module unit, and a comprehensive association analysis module unit.