Due to the situation of unequal attack and defense in the current cyberspace
the protection system based on "known risks" can no longer meet the increasingly severe attack pressure
so it is necessary to build a security architecture that can protect against "unknown risks" and has certain adaptive ability. This paper introduces red-blue experience into the construction of security protection system
takes website protection as an example
studies the construction of security architecture model based on mimicry defense
and proposes the method of integrating adaptive defense capabilities into security work
so as to improve the protection ability of information system against unknown threat attacks.