This paper presents a new approach to detect attacks from network activities. Network connections were transformed into data points in the predefined feature space. The influence function was designed to quantify the influence of an object and, further, the data field was divided into positive field and negative field according to the source point's category. To perform classification, all the labeled training samples were regarded as source points and build a data field in the feature space. When detecting, the influence felt by given testing point in this field was calculated and behaviors class was judged according to the sign and magnitude of the influence. Experimental results demonstrate that the detection performance of our approach is satisfying.