This invention discloses a security
threat perception and detection method for
global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and
attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework
algorithm to optimize the deployment of logical monitoring points (feature nodes) in the
virtual network and calculates the dynamic intensity of
threat propagation at each point, thereby constructing a node-level
threat field that quantifies the
spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the
raw data, forming a six-dimensional vector. This vector is input into a pre-trained global
threat level classification model, outputting a discrete
threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.