The invention provides a multi-layer heterogeneous graph construction method based on a TCP session, and relates to the technical field of
network security. The method comprises the following steps: reading original network flow data in a PCAP form and splitting the original network flow data into TCP sessions; sorting the data packets in the TCP session according to the timestamps, and generating data packet nodes; constructing a data packet
time sequence edge according to the sequence of the timestamps, and associating each data packet node to construct a data packet
sequence diagram; constructing an initial
server-side state node and an initial
client-side state node; traversing the data packet nodes of the data packet
sequence diagram in sequence, and judging whether the states of the
server-side state nodes and the
client-side state nodes are changed or not; if so, newly establishing a
server-side state node and a
client-side state node, and constructing a corresponding state
transition edge and a corresponding mapping association edge; and if not, constructing a corresponding mapping association edge. According to the method, the key information of the TCP session can be completely described, staged accurate extraction of subsequent features can be conveniently realized, and cross-stage feature
dilution can be avoided.