Network situation awareness technology is an important technology in the field of network security. It can sense and evaluate the real-time status of the network through real-time monitoring, analysis and processing of network data flow. However, the current implementation of network situation awareness technology is not compatible and efficient. To this end, this paper proposes network situation awareness technology based on EBPF. In this paper, we use an optimized Scalable Bloom filter (EBPF) to capture network protocol data and store this data in HBase. Then, we use network situation awareness technology to analyze these data, so as to realize the detection of DOS attacks. Through experiments, this paper verifies the effectiveness and practicability of this method in detecting Denial of service attacks (DDOS), and provides a new idea and method for future network security research.