The invention discloses a
network security protection method and device based on distributed
threat identification, and relates to the field of
network security. The method comprises the following steps: firstly, determining
target acquisition granularity and frequency based on equipment
type distribution,
service load and link
quality data; capturing the original flow in real time by an
edge computing node, and extracting a distributed
threat fingerprint containing a behavior sequence and a protocol variation feature; after block chain
consensus verification,
synchronizing to a collaborative detection network, and constructing an on-chain trusted
threat knowledge base; simulating a target threat
fingerprint propagation path in combination with real-time
network topology and an on-chain trusted threat
knowledge base, and generating a dynamic threat propagation map; and determining a multi-dimensional risk
score based on the atlas, and further generating a self-adaptive protection strategy and issuing and executing the self-adaptive protection strategy. According to the method, technologies such as multi-dimensional data
perception, edge calculation and block chain
consensus are fused, and efficient, credible and real-
time response distributed
network security protection is realized.