The invention discloses an API (Application Program Interface) monitoring security audit model based on a government affair
system, which relates to the technical field of
network security, and comprises the following steps: collecting and converging network traffic of each collection point; analyzing the distribution condition of APIs in the collected flow, identifying and displaying key information, meanwhile, realizing data real-
time processing,
data stream splitting, data reading and writing and offline
data analysis, and detecting risk behaviors by utilizing a rule strategy
library; aPI asset weaknesses are identified and marked,
state management is supported, and an attacker portrait, security study and judgment and
attack traceability model is constructed; and pushing and displaying
risk model early warning, realizing multi-dimensional
data source real-time association analysis based on a
big data framework, automatically converging alarms to form an event file, and linking with automatic arrangement to complete event response and
report generation. According to the method, the problem of insufficient security and stability of the government affair
system is solved, and complex attacks and advanced persistent threats can be identified more accurately.