By taking full advantage of the security features of intrusion detection products, this paper designs a policy-diverting intrusion prevention and recovery system architecture.Using dual NIDS system as the front-end detection module, through the strategy diversion, the dual NIDS system fully covers the intrusion detection Each protocol layer, give full play to the detection advantages of the two NIDS systems, and achieve efficient intrusion detection.And combined with HIDS host log protection mechanism and key content recovery mechanism, even in the event of invasion and destruction of data, the system can still guarantee the key Site safety.