**6. Conclusion**

This chapter first introduces the related work of SA technology, the concept, definition and formula of DS evidence theory, and then aims at the problem of slow response of network security SA to burst vulnerabilities in the network. A method of network security SA based on DS evidence theory is proposed. Finally, according to the experiment of Mirai botnet, a surveillance camera in NJUPT's campus network, it is proved that the SA method based on DS evidence theory is feasible and effective, and this method can detect the major threat in a protected network in time.
