The invention discloses an
active defense system and method based on biological immune. The
system comprises a terminal, wherein the terminal is equipped with a known behavior
library which is trainedthrough utilization of a cloud and is used for carrying out local detection and real-time monitoring on behaviors through utilization of a quasi-biological immune mechanism, wherein the behaviors aregenerated based on internal and
external data, and the terminal is also used for carrying out first-level
active defense, and sending unidentified unknown behaviors to the cloud; and the cloud, wherein the cloud is equipped with the known behavior
library which is trained through utilization of the cloud, and the cloud is used for collecting the unknown behaviors sent by the terminal, importing
deep learning, carrying out
cloud detection and behavior early warning, pushing new behaviors to the terminal in real time and carrying out second level-defense. According to the
system and the method,on the basis of the quasi-biological immune mechanism and an improved NAS
negative selection algorithm, unsecure computer behaviors can be actively identified, prevented, traced and checked, and integrated defense and
active defense of a cloud-terminal cooperative computing environment is realized.