The invention relates to an intrusion detection method based on cross-domain
security management and a shared behavior model. The method comprises the following steps: acquiring multi-dimensional
original data according to a preset cross-domain
data acquisition rule and multi-domain
node deployment; performing compliance, integrity and format matching degree
verification on the
original data, shielding sensitive information by using a dynamic desensitization technology based on a
verification result, converting a heterogeneous
data format, filtering missing field abnormal data, and obtaining compliance data; the method comprises the following steps: extracting a multi-dimensional
feature set of user cross-domain access, constructing a shared behavior
feature vector through weighted calculation, constructing a reference behavior model
library in combination with a cross-domain
security policy, and screening out intrusion behaviors and feature deviation data through feature comparison and behavior deviation calculation; according to the method, cross-domain security audit logs are fused for
correlation analysis, intrusion behavior types and risk levels are judged by means of a
Bayesian network model, differential security response strategies are generated and executed, and cross-domain intrusion detection and protection are achieved.