The invention belongs to the technical field of
network security, and particularly relates to a
network security detection method based on
artificial intelligence, which comprises the following steps of: acquiring network flow data,
system log data, user behavior data and external
threat intelligence data, generating a multi-source heterogeneous
data set, preprocessing the multi-source heterogeneous
data set, and acquiring a multi-source heterogeneous
data set; comprising the steps of data normalization, missing value filling and
noise filtering,
feature extraction is conducted on preprocessed data through a multi-
modal fusion model, extracted multi-
modal features are input into a mixed detection engine, the
detection rate of zero-day attacks can be increased to a high level through multi-
modal data fusion, and compared with the prior art, the
detection rate of zero-day attacks is increased. The
detection rate of a traditional method has obvious advantages in the aspect of coping with novel threats, and meanwhile, the
false alarm rate can be reduced below a normal value in the aspect of
false alarm rate control, so that the burden of safety personnel for handling invalid alarms is greatly reduced, and the situation that a large number of false alarms cause waste of manpower and
material resources and possibly cause the fact that real safety threats are neglected is avoided.