The invention discloses a baseline construction and unknown abnormal behavior detection method oriented to a system log. The method comprises the following steps: I, user operation log quantification, namely, user behavior quantification; II, user behavior feature screening; III, abnormal behavior detection; and IV, abnormal behavior description. The baseline construction and unknown abnormal behavior detection method oriented to the system log disclosed by the invention comprises the following specific steps: firstly, quantifying a user operation log to generate a behavior feature vector; secondly, performing abnormity marking on samples to construct a reference sample set, and evaluating and screening sub-features at the same time to construct a new feature vector; and lastly, performing active clustering analysis on the user behavior feature vector, constructing a behavior baseline, and detecting abnormal behaviors. Abnormal points are eliminated in a detection process, so that an abnormal point effect can be effectively avoided, and typical user behaviors and abnormal behaviors can be detected accurately.