The invention belongs to the technical field of
network security, and discloses a multi-method mixed distributed APT malicious traffic detection and defense
system and method, and the method comprises the steps that a network equipment layer carries out traffic bypass and equipment management and control, and sends the bypass traffic to a detection and defense layer for detection; the detection and defense layer performs flow detection and instruction execution; the analysis and
control layer is used for summarizing and analyzing detection logs and issuing instructions; and a display and management layer performs
data display and user interaction. According to the method, the malicious traffic in the network can be accurately detected in an omnibearing and multi-angle manner, so the potential APT
attack can be identified. Meanwhile, by using a distributed architecture, accurate and comprehensive
threat modeling can be carried out on the intrusion situation of the whole protected network. Meanwhile, a Cyber
Kill Chain theoretical model is used, association between alarms in the network under long time and wide space span is fully mined, potential APT
attack actions in the network are identified, and corresponding alarms are given.