The invention discloses a
network security monitoring method, which comprises the following steps of: acquiring full-life-cycle data and attributes of network processes in real time, constructing a process chain table and an associated network, and sorting a relationship between the processes; secondly, matching a network event with a process timeline, dynamically dividing a time window according to a process life cycle, calculating a
process time characteristic and a
network activity characteristic, comparing a historical
normal mode, quantifying a difference by utilizing an
algorithm, and identifying an abnormal process; then, inputting the comparison process into a
support vector machine to establish a prediction model, and predicting an abnormal process in real time; and finally, abnormal
process information is fed back to the security equipment, and abnormal files are positioned and isolation / deletion operation is executed in combination with
network behavior data association analysis. According to the method, the abnormal process can be accurately identified, misjudgment is reduced, the sensitivity requirements of different service scenes are met, the abnormal file is positioned by means of network behaviors, and the accuracy and timeliness of
network security protection are effectively improved.