The invention provides a network traffic
anomaly detection model training method and device and a readable storage medium, and the method comprises the steps: extracting a traffic statistical
feature vector according to original network traffic data, and generating an initial mixed
data set; generating a confrontation disturbance sample output enhanced
feature matrix based on the initial mixed
data set; constructing a self-adaptive
feature fusion rule based on the enhanced
feature matrix, embedding asset association degree parameters into an attention calculation layer of a feature
encoder, and outputting encoding features fusing
threat intelligence; inputting the coding features fused with the
threat intelligence into a pre-constructed initial detection model, generating false report and missing report correction labels based on the suspicious traffic fragments, and outputting an adversarial sample correction
data set; and performing adversarial training on the initial detection model through the adversarial sample correction data set to obtain an incremental detection model for network traffic
anomaly detection. According to the invention, the detection precision, the anti-interference capability and the real-time defense response capability of the detection model to novel attacks can be improved.