The invention provides a network
threat identification and defense method and
system based on data enhancement and adversarial evolution, and relates to the technical field of
network security defense, and the method comprises the steps: obtaining a log
stream of a network event, and carrying out the preprocessing and vectorization of the log
stream; performing
knowledge base RAG retrieval on the vectorized network events, and retrieving to obtain
attack and defense tags of similar network events in a
knowledge base; constructing cue words, inputting the cue words into the LLM reasoning model, and predicting the next
network attack operation; a double-agent
adversarial network mechanism is started in the LLM reasoning model, a
reinforcement learning evaluation process is introduced, a multi-objective
loss function is constructed, and the multi-objective
loss function is used as an optimization index of an
attack sample and a standard whether the multi-objective
loss function is handed over to a defense agent or not; and the defense agent identifies an
attack sample, and improves the discrimination capability of fuzzy attack features by optimizing cue words to obtain a discrimination prediction result. According to the invention, the modeling and prediction capability of the attack sequence is improved.