The embodiment of the invention provides an
attack defense method and device, and the method comprises the steps: when access flow is monitored, the performance state of equipment is determined; when the performance state is a target state, a
score value corresponding to the access flow is determined; calculation is performed according to the present performance data, and a trust threshold value of the equipment is determined; when the
score value is lower than the trust threshold value, whether the access flow matches with a preset
attack characteristic is determined; and when the access flow matches with the
attack characteristic, the access flow is
cut. According to the embodiment, a
trust score function of WAF equipment is triggered under a flow excess pressure state, whether the
score value corresponding to the access flow is lower than the trust threshold value is judged to determine if the access flow needs to be subjected to a deep attack detection, so that attack flow can be detected and intercepted, safety of
web server can be ensured, which means, the protecting effect is reached.