The application discloses a
camouflage encrypted traffic auditing method and
system based on
server role consistency, relates to the technical field of
network security, and comprises the following steps: S1, acquiring encrypted communication traffic and extracting feature information; S2, determining a service type and constructing an access correlation graph; S3, analyzing rationality features and
server role results of a destination
server IP; S4, analyzing consistency scores of the destination server IP; S5, analyzing rationality scores; S6, analyzing
access structure scores; S7, analyzing comprehensive auditing scores; and S8, analyzing auditing results. The actual behavior features of the destination server IP are analyzed to determine the
server role, the
server role consistency analysis mechanism is used to verify whether the role is consistent with the service type corresponding to the access behavior, the destination server IP rationality analysis and multi-target
access structure analysis are combined, and the
camouflage encrypted traffic is identified from the business
semantics and
network behavior levels, so that the effective auditing of the
camouflage encrypted traffic is realized without decrypting the communication content.