The invention belongs to technical fields characterized by protocols and discloses an 
attack occurrence confidence-based 
network security situation assessment method and 
system. According to the 
attack occurrence confidence-based 
network security situation assessment method and 
system, a 
machine learning technology is adopted to analyze network 
stream data and calculate a probability that networkstreams belong to 
attack streams; a D-S evidence theory is used to fuse the information of multi-step attacks to obtain the confidence of attack occurrence; and a 
network security situation is calculated by means of situational factor integration on the basis of security 
vulnerability information, 
network service information and host protection strategies; and therefore, the accuracy of assessmentis effectively improved. Since the confidence information of detection equipment is added to the assessment 
system, the influence of false negatives and false positives can be effectively reduced. Anensemble learning method is adopted, so that the accuracy of confidence calculation can be improved. A 
network attack is regarded as a dynamic process, and merging 
processing is performed on the information of the multi-step attacks. 
Information fusion technology is adopted, so that network environment characteristics such as vulnerabilities, 
service information and protection strategies are comprehensively considered.