The invention belongs to the technical field of communication security, in particular to a
Diameter flooding attack detection device and method, The device comprises a parameter extracting module, which is used for extracting the signaling message parameters flowing through the signaling, and matching the state
machine according to the parameters, wherein the signaling message parameters include the session identification parameters, the source host parameters and the user name parameters, and setting and initializing each signaling message parameter counter, a signaling flow analysis module which is used for early warning analysis of the signaling message parameters in the signaling according to the state
machine matching condition and using the counter count value, a detection alarm module which is used for
flooding attack alarm according to the warning analysis result of the signaling message parameters. The invention is applicable to an IMS network in a
mobile communication network, security detection and early warning of
Diameter flooding attacks are implemented, Automatic identification and detection of
Diameter flooding attacks are performed based on IMS signaling flows, detection and early warning of Diameter flooding attacks are detected and early warned from signaling flows, thus improving IMS
network security and having important guiding significance for the securityof communication networks.