The embodiment of the invention discloses a
Web application attack detection and defense method and
system based on AI. The method comprises the following steps: extracting a minimum effective
feature set of
attack behaviors from historical
Web attack traffic data, clustering, generating
attack micro-feature clusters, and constructing an attack micro-feature cluster
library; key features of the access traffic of the
Web application are extracted, and the current occurrence frequency, the accumulated occurrence frequency and the combination mode of the key features are counted; matching the key features based on the attack micro-feature cluster
library to obtain a matching result, constructing a structured numerical matrix in combination with statistical data, inputting the structured numerical matrix into a detection model for detection, and executing a blocking operation when a malicious attack is detected; and when the hostile attack is a novel unknown attack, updating the features of the hostile attack to the attack micro-feature cluster
library. According to the method, the computing
power consumption can be greatly reduced, the detection efficiency can be improved to adapt to a high-
concurrency scene, deformation and fragmentation novel attacks can be accurately identified, feature library self-updating can be realized, and the problem of rule
hysteresis can be solved.