The invention discloses a network unknown threat detection method based on a feature extension CNN, and the method comprises the steps: constructing a feature extension CNN model according to the characteristics that many network unknown threats and known threats are from the same family, and are represented as sample features are similar, firstly carrying out the convolution operation of original data at each layer of the CNN, and obtaining a native feature map; performing linear random operation on the native feature map to obtain an extended feature map; finally, combining the two to obtain extended reconstruction data of the original data, the dimension of which is lower than that of the original data, and realizing dimension reduction extended reconstruction of the data; and constructing a security data classification model based on a shallow machine learning algorithm to realize detection of unknown threats in the network security big data. According to the network unknown threat detection method based on the feature extension CNN provided by the invention, the generated extension reconstruction feature not only realizes dimension reduction, but also expands the data representation of the unknown threat, realizes high-precision detection of the unknown threat, and also reduces the calculation complexity.