The invention provides an
attack recognition method and
system of an
operating system,
computer equipment and a medium, and belongs to the technical field of
network security, the method comprises the following steps: collecting
system logs from the
operating system, an application program and network equipment, after preprocessing, generating a log text high-dimensional
semantic vector by using a pre-training unsupervised semantic coding model, and storing the log text high-dimensional
semantic vector in a
database; the features are reduced into low-dimensional features through an auto-
encoder;
mapping system entities into nodes, mapping log interaction relationships into directed edges, and constructing a
system traceability graph in combination with low-dimensional features; then, node high-dimensional representation is learned by using an enhanced graph
attention network (EGAT), a bidirectional gating loop unit is input after
time sequence serialization to capture behavior
time sequence dependence, and a node anomaly classification probability is output; and finally, the federated
server generates a
global model to realize multi-system collaborative detection under
privacy protection. According to the method, the complex
attack chain can be accurately identified, the detection precision and the data privacy are considered, and the real-time intrusion detection and security response requirements of a large-scale network environment are met.