An MCP
flooding attack detection method based on behavior characteristics comprises the following steps: collecting and learning a large amount of legal MCP traffic, extracting parameter length, request interval, nesting depth and
response time characteristics, and constructing four-dimensional normal distribution as a legal
traffic model based on the parameters, the request interval, the nesting depth and the
response time characteristics; the probability density of the
feature vector of each new request under the legal model is calculated to judge the abnormal request and the
attack type thereof, finally, an SIR infectious
disease dynamic model and an ARIMA
time sequence model are further innovatively integrated to predict the
zombie node scale and the
attack trend, and the prediction result is used as input to automatically trigger and adjust a defense strategy; according to the method,
botnet attack detection is carried out on the large
language model integrated with the MCP protocol by utilizing the multi-dimensional behavior characteristics, so that attack detection and an adaptive defense strategy are effectively realized, and a security protection capability is also provided for a
complex network environment in which the large
language model is integrated with the MCP protocol; the invention further comprises a
system, equipment and a storage medium for implementing the method.