The invention relates to the technical field of flow analysis and early warning, and the method comprises the steps that network flow collected by a flow analysis and
early warning system is detected and analyzed through an intrusion detection engine and a behavior detection engine, and a platform provides four
data security exchange channels and supports intrusion detection and behavior detection. According to the method, a
gene detection technology is used for detecting a variety of a known
threat, an intelligent detection technology is combined to prevent escape and avoidance, and a host behavior and a
network behavior of a malicious code in a sandbox are deeply analyzed to detect an unknown
threat. The intrusion detection engine can sense intrusion in content, environment and application
layers. The behavior detection engine carries out file restoration and
metadata extraction on traffic, the restored file carries out static detection on known threats through a built-in anti-
virus engine,
artificial intelligence engine detection is carried out, and malicious encrypted traffic, dark network traffic, hidden tunnels and the like can be detected.