Network anomaly detection is an important part of the intrusion detection system,however,there are many problems in traditional network anomaly detection methods,such as high false positive rate and the limitation of detecting multiple types of the intrusion actions.A distributed anomaly detection model and the fusion method are proposed based on extended D-S evidence theory.Meanwhile,considering the unreasonableness in the traditional D-S evidence theory when there exist conflictions in the evidences,an extended D-S evidence theory with weights is adopted,and a newly fusion policy is proposed to build an anomaly detection model with multiple classifiers.According to the verification of the KDD99 data set,experiments show that the proposed model and method can obviously reduce the false positve rate,and simultaneously improve the detection rate.