This invention relates to the field of intelligent security
identification technology, and discloses an intelligent AI-based security identification method and
system. The method collects historical data on abnormal behavior to establish a standard behavior model
library; after collecting real-time monitoring datasets, it determines the security scanning interval based on the data scale; within the scanning interval, it acquires all monitoring signals and calculates the average feature value as a security judgment benchmark; based on the benchmark and the
standard model library, it evaluates the monitoring signals, identifies and labels suspicious abnormal behaviors. When suspicious behavior exists, its parameter attributes and
behavioral pattern features are extracted to determine whether it is a real
threat behavior, and then a basic risk value is determined based on the frequency of
threat occurrence. Subsequently, the behavioral sequences, operation types, and interaction trajectories of real threats are analyzed, and the trajectories are used as feature vectors for classification analysis using a classification
algorithm to determine whether there are associated
attack patterns; if so, a correction factor is calculated to update the basic risk value, and the next security scanning interval is reconfigured.