The application discloses a
network attack flow detection method based on a timing probability determination finite
automaton, and relates to the technical field of
network security, wherein the method comprises the following steps: collecting historical normal flows of a protected destination address, dividing flow streams according to five tuples, combining data packet
length distribution to complete adaptive length quantization, and outputting a standardized
symbol mapping result; constructing a feature
graph node with a quantization interval and a transmission direction, combining data packet hopping and timing interval to construct a flow feature graph, obtaining transition probability and time constraint parameters through global
statistical analysis, and constructing a special detection model. In online detection, new flow initialization is completed, state transition
verification is carried out according to the model, an abnormal
score is iterated through a unified scoring mechanism, the
score decay feature and the threshold value are combined to determine the
abnormality, and the flow identifier and the violation alarm are output, so that full-cycle
anomaly detection is realized. The application realizes high-
camouflage attack detection by fusing flow structure and timing characteristics through an
automaton, and solves the problem of single
feature dimension in traditional methods.