In order to overcome the problems of low accuracy and poor stability of attack behavior detection in traditional active defense system, a new covert network active defense system based on attack behavior detection is proposed and designed in this paper. In terms of hardware, the overall architecture of the active defense system, network communication protocol and attack behavior data capture module are designed. In terms of software, information entropy combined with mutation detection is used to accurately detect the network attack behavior. The experimental results show that compared with the traditional defense system, the designed system can accurately detect the attack behavior in the network, and the detection accuracy is more than 98%; and the operation stability of the system has been effectively improved. Therefore, it shows that the designed system has strong practical application performance.