The present application relates to the technical field of
information security, and more particularly to a dynamic white
list management method and
system based on immune-Kalman collaborative evolution, which comprises the following steps: receiving the
observation data of the service access request collected and sent by the edge access gateway; predicting and updating the
state vector of the current service baseline through the
Kalman filter state estimator to obtain the prior
state prediction value and the
prediction residual; dynamically adjusting the "self-non-self" judgment threshold of the
immune system, if it is judged as self, the characteristics of the service access request are fed back to the
Kalman filter state estimator as observation samples and updated; if it is judged as non-self, an isolation instruction is generated and sent to the
software defined network controller, and a denial of access instruction is sent to the edge access gateway; based on the
prediction residual and the comprehensive health degree index, the running state of the
system is judged, and the corresponding matching strategy is selected from the preset white
list matching strategy set and sent to the edge access gateway for execution.