The invention belongs to the field of mobile ad hoc network routing security, and discloses a black hole attack detection and tracking method based on doubtful accumulation. According to the method, in a detection period, a passive monitoring mode is adopted, a node detects whether current topology update meets a suspicious condition, and if a data packet of the topology update meets the suspicious condition, the node adds a IV-type suspicious degree to a reputation registration table corresponding to the suspicious node; The node monitors the packet loss rate in each routing path, and triggers active detection if the packet loss rate exceeds the threshold value; an active detection mode is aodpted to detect suspicious behaviors so as to determine a correspondingly increased doubtful value, and performing weighted calculation on credit changes at different moments according to a forgetting factor so as to obtain a final doubtful value; And according to the final doubtful value of the suspicious node, the network control station determines whether the suspicious node is a malicious node through analysis, and once the suspicious node is confirmed to be the malicious node, the networkcontrol station broadcasts the whole network so as to isolate the malicious node from the whole network.