The invention discloses a malicious traffic message interception and retention method based on
threat intelligence, and the method comprises the following steps: S1, importing a
threat intelligence
data set, generating an intelligence
label dictionary, and caching the intelligence
label dictionary; s2, receiving a
network data packet through a traffic mirroring device or an acquisition probe, and aggregating the
network data packet into a traffic aggregation
object based on a quintuple; s3, modeling and recording a state transition sequence based on a protocol state
machine; s4, detecting a state transition sequence by using the information
label dictionary, and identifying potential malicious traffic; s5, extracting
data messages corresponding to the key nodes to form an extracted message set; s6, grouping according to the information labels and encrypting by using an improved AES symmetric
encryption algorithm to generate an encrypted message file; s7, constructing an index data table containing a quintuple, capture time and an information label, and associating the index data table with the encrypted message file; and S8, storing the encrypted message file and the index data table in a separated storage
system, and updating the index data table regularly. The method and the device are suitable for a
threat-driven encrypted
message processing scene.