The invention belongs to the technical field of
network security protection, and discloses a malicious behavior bypass interception
system based on flow analysis and detection, a
rule engine quickly matches known attacks based on a
dynamic feature library, such as
SQL injection, common port scanning,
federated learning model combined multi-node cooperative training, and
flow time, behavior and content features are combined to realize the flow analysis and detection of malicious behaviors. Unknown threats such as 0day
vulnerability variants and low-frequency hidden attacks are accurately captured; in an enterprise mixed service traffic environment, missed judgment of traditional static detection on unknown attacks can be avoided, false alarms caused by data limitation of a
single model can be reduced,
energy consumption of operation and maintenance personnel for
processing invalid alarms is reduced, core assets are prevented from being damaged by novel attacks, and comprehensiveness and reliability of network protection are remarkably improved; a bypass deployment mode is adopted, traffic is obtained through
network TAP equipment or traffic mirror images, a service main forwarding link does not need to be intervened, and
network delay and single-point failure risks introduced by traditional series deployment are avoided.