A computer information security management method and system based on big data

Through the computer information security management method based on big data, and the real-time collection and multiple verification mechanisms of multiple data sources are used to solve the problems of inaccurate data processing and inaccurate risk identification in financial transactions, the accuracy and flexibility of real-time risk identification and abnormal handling of computer information security is realized, and transaction security and user experience are improved.

CN120047250BActive Publication Date: 2025-07-18JIANGMEN POLYTECHNIC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510534504.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-18
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

When facing massive financial transaction data, the existing technology has problems such as inaccurate data processing and inaccurate risk identification, and lacks user participation, resulting in more misjudgment and misjudgment, and it is impossible to flexibly obtain more information for verification.

Method used

Through a computer information security management method based on big data, financial transaction data is collected in real time using multiple data sources to identify risk prediction models, combining multi-factor authentication and multiple verification mechanisms, including first verification, second verification and third verification, obtain user authorization for further verification, and create exception tags.

Benefits of technology

It realizes the accuracy and flexibility of real-time risk identification and exception handling of computer information security during financial transactions, reduces misjudgments and misjudgments, and improves transaction security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047250B_ABST
    Figure CN120047250B_ABST
Patent Text Reader

Abstract

The present invention discloses a computer information security management method and system based on big data, which relates to the technical field of information security management. It performs risk identification on the computer-stored data of financial transaction applications, marks out key transaction attention objects, and then conducts the first verification to mark out abnormal computer information conditions. For the marked abnormal computer information conditions, it identifies and marks out the financial computer information abnormal type with the highest matching degree, and then conducts the second verification to determine whether there is such a financial computer information abnormal type. When there is no such financial computer information abnormal type, it obtains relevant verification data for the third verification. Based on the result of the third verification, it determines whether to give approval for security. If the security approval is passed, it triggers the need for manual inspection, obtains the specific reasons for the abnormalities marked by manual inspection, and creates abnormal labels for the specific reasons for the abnormalities. It realizes multi-level security verification and intelligent abnormal management, and significantly improves transaction security and user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security management, and in particular to a computer information security management method and system based on big data. Background Art

[0002] With the continuous development of the financial market, the scale of financial transactions continues to expand, the types of transactions are becoming increasingly complex and diverse, and new financial products and transaction models continue to emerge, such as financial derivatives transactions, cross-border e-commerce financial transactions, etc. This makes the risks faced by financial transactions more complex and changeable, and puts forward higher requirements for computer information security management in the process of financial transactions; and in the era of big data, the amount of computer data generated by financial transactions is exploding. These data contain rich information, but how to effectively collect, process and analyze these data, tap their value, and use them for risk identification and security management has become an important issue facing the financial industry.

[0003] When faced with massive amounts of financial transaction data, existing technologies have problems such as untimely data processing and inaccurate risk identification; and existing anomaly detection methods only rely on single-dimensional data or simple rules, resulting in a large number of misjudgments and missed judgments; some existing computer information security management methods in financial transaction processes lack user participation, and when a transaction encounters anomalies, it is impossible to flexibly obtain more information for verification.

[0004] Therefore, in response to the above problems, there is an urgent need for a computer information security management method and system based on big data. Summary of the invention

[0005] In view of the deficiencies in the prior art, the present invention provides a computer information security management method based on big data, which solves the problems of low efficiency and insufficient accuracy in real-time risk identification and exception handling of computer information security in financial transactions.

[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A computer information security management method based on big data, comprising the following steps: S1, real-time collect the computer storage data of financial transaction applications based on multiple data sources of the financial transaction system, and the computer storage data of financial transaction applications includes basic transaction information and information of both parties to the transaction; S2, use a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then mark key transaction attention objects based on the risk identification results; S3, conduct multi-factor authentication on the key transaction attention objects, and then conduct a first verification on the security of the key transaction attention objects based on the multi-factor authentication results, and identify and mark abnormal computer information conditions; S4, for the marked abnormal computer information conditions, extract abnormal features, and then compare the abnormal proportion coefficient of the abnormal features with the reference proportion coefficients of various abnormal patterns stored to identify and mark the financial computer information abnormal type with the highest matching degree; S5, for the marked financial computer information abnormal type, obtain the relevant feature information of the financial computer information abnormal type, and then conduct a second verification on the relevant feature information of the financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; S6, when there is no such financial computer information abnormal type, display a secondary financial transaction application page to the user, obtain the user's authorization for obtaining relevant verification data, and then obtain relevant verification data from the corresponding data sources according to the authorization result, and then conduct a third verification on the relevant verification data; S7, determine whether to grant security approval based on the third verification result. If the security approval is passed, trigger a manual inspection requirement, obtain the specific reasons for the abnormalities marked by the manual inspection, and create an abnormal information label for the specific reasons for the abnormalities. If the security approval is not passed, send a warning prompt to the user.

[0007] Further, the specific steps of S2 include: input the real-time monitored computer storage data of financial transaction applications into the risk prediction model, output a risk probability value, and then compare the risk probability value with a risk probability threshold. The financial transaction applications with a risk probability value greater than or equal to the risk probability threshold are marked as key transaction attention objects.

[0008] Further, the specific analysis of the first verification is as follows: Use a convolutional neural network and a support vector machine to output the authentication results of each multi-factor authentication, and then sum the authentication results of each multi-factor authentication to obtain a first verification score. Compare the first verification score with a first verification score threshold. When the first verification score is greater than or equal to the first verification score threshold, it is marked as an abnormal computer information condition.

[0009] Further, the specific steps of S4 include: obtaining the abnormal proportion coefficient of the marked abnormal computer information status and the reference proportion coefficients of various abnormal modes, and then respectively taking the absolute differences between the abnormal proportion coefficient and the reference proportion coefficients of various abnormal modes, and marking the one with the smallest absolute difference as the financial computer information abnormal type with the highest matching degree.

[0010] Further, the specific analysis of obtaining the abnormal proportion coefficient of the marked abnormal computer information status and the reference proportion coefficients of various abnormal modes is as follows: performing quantization processing on the abnormal features, and then based on logistic regression, training and inputting the abnormal features, and outputting to obtain the abnormal proportion coefficient; extracting the stored features of various abnormal modes, and respectively training and inputting the features of various abnormal modes based on logistic regression, and outputting to obtain the reference proportion coefficients of various abnormal modes.

[0011] Further, the specific steps of S5 include: according to the marked financial computer information abnormal type, retrieving the typical feature information of this financial computer information abnormal type, and then obtaining the typical confidence interval of this financial computer information abnormal type; using the relevant feature information of this financial computer information abnormal type to compare with the typical confidence interval, when the relevant feature information of this financial computer information abnormal type conforms to the typical confidence interval of this financial computer information abnormal type, it is determined that there is this financial computer information abnormal type, the second verification is qualified, and security approval is given, otherwise it is determined that there is no such financial computer information abnormal type.

[0012] Further, the specific steps of S6 include: when the user refuses authorization, the security approval fails, sending a risk warning prompt to the user, and marking the user as a risk; when the user agrees to authorize, obtaining the user's relevant verification data, respectively performing retrieval and verification of relevant typical modes on the relevant verification data, when there is relevant verification data that does not conform to the relevant typical mode, marking the third verification as unqualified, otherwise giving security approval.

[0013] A computer information security management system based on big data, applying the above-mentioned computer information security management method based on big data, includes: a data acquisition module, used for real-time collecting the financial transaction application computer storage data based on multiple data sources of the financial transaction system, and the financial transaction application computer storage data includes transaction basic information and transaction party information; a risk identification module, used for using a risk prediction model to identify the risks of the financial transaction application computer storage data, and then marking key transaction attention objects based on the risk identification results.

[0014] The first verification module is used to conduct multi-factor authentication on the key transaction attention objects, and then based on the multi-factor authentication results, conduct the first verification on the security of the key transaction attention objects, and identify and mark the abnormal computer information status; the retrieval module is used to extract abnormal features for the marked abnormal computer information status, and then compare the abnormal ratio coefficient of the abnormal features with the reference ratio coefficients of various abnormal patterns stored, and identify and mark the financial computer information abnormal type with the highest matching degree; the second verification module is used to obtain the relevant feature information of the marked financial computer information abnormal type, and then conduct the second verification on the relevant feature information of the financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; the third verification module is used to, when there is no such financial computer information abnormal type, display a secondary financial transaction application page to the user, obtain the user's authorization for obtaining relevant verification data, and then obtain relevant verification data from the corresponding data sources according to the authorization result, and then conduct the third verification on the relevant verification data; the approval management module is used to determine whether to give a security approval based on the third verification result. If the security approval is passed, trigger a manual inspection requirement, obtain the specific reason for the abnormality marked by the manual inspection, and create an abnormal information label for the specific reason for the abnormality. If the security approval is not passed, send a warning prompt to the user.

[0015] The present invention has the following beneficial effects:

[0016] The computer information security management method and system based on big data constructs a comprehensive computer information security risk prevention and control system from data collection to multi-factor authentication, and then to the identification and multiple verifications of abnormal types of financial computer information. By collecting transaction application data in real time from multiple data sources, it can obtain richer and more accurate information, providing a solid foundation for subsequent risk identification. The multiple verification mechanism further improves the accuracy of information risk identification and comprehensively guarantees the security of financial transactions. In terms of dealing with abnormal computer information conditions, by extracting abnormal features and comparing and retrieving them with stored abnormal patterns, it can accurately identify the financial computer information abnormal type with the highest matching degree, conduct a second verification on the characteristic information related to the financial computer information abnormal type, and conduct a third verification when there is no established financial computer information abnormal type, ensuring the accurate judgment of abnormal transactions, reducing misjudgments and missed judgments, and improving the accuracy of abnormal information detection. When there is no known financial computer information abnormal type, it displays a secondary financial transaction application page to obtain authorization from the user, which not only guarantees transaction security but also gives the user the opportunity to participate in transaction verification, improving the user experience to a certain extent. At the same time, it allows obtaining more verification data when necessary, increasing the flexibility of transactions and enabling adaptation to complex and changeable financial transaction scenarios. If the security approval is passed, it triggers the need for manual inspection and creates an abnormal label, which helps to continuously accumulate experience and improve the financial computer information abnormal type library and risk prediction model. Brief Description of the Drawings

[0017] Figure 1 It is a flowchart of a computer information security management method based on big data according to the present invention.

[0018] Figure 2 It is a structural diagram of a computer information security management system based on big data according to the present invention. Detailed Embodiments

[0019] In the embodiments of the present application, through a computer information security management method and system based on big data, multi-level computer information security verification and intelligent abnormal management are realized, significantly improving transaction security and user experience.

[0020] The general idea of the embodiments of this application is as follows: First, real-time collect transaction application data through multiple data sources of the financial trading system to ensure the comprehensiveness and timeliness of the data; then, use a risk prediction model to identify risks in the collected data and mark key transaction attention objects; next, conduct multi-factor authentication on the key transaction attention objects to conduct a first verification of their security from multiple dimensions and identify and mark abnormal computer information conditions; for the marked abnormal computer information conditions, extract abnormal features and compare and retrieve them with the stored abnormal patterns to determine the financial computer information abnormal type with the highest matching degree; for the marked financial computer information abnormal type, obtain relevant feature information for a second verification to determine whether there is such a financial computer information abnormal type; when there is no such financial computer information abnormal type, obtain authorization from the user and obtain relevant verification data from the corresponding data source for a third verification; finally, determine whether to grant security approval based on the results of the third verification. If it passes, trigger manual inspection and create an abnormal information label. If it fails, send a warning prompt to the user.

[0021] Please refer to Figure 1 , the embodiments of the present invention provide a technical solution: A computer information security management method based on big data, including the following steps: S1, real-time collect the computer storage data of financial transaction applications based on multiple data sources of the financial trading system. The computer storage data of financial transaction applications includes basic transaction information and information of both parties to the transaction; S2, use a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then mark key transaction attention objects based on the risk identification results; S3, conduct multi-factor authentication on the key transaction attention objects, and then conduct a first verification of the security of the key transaction attention objects based on the multi-factor authentication results, and identify and mark abnormal computer information conditions; S4, for the marked abnormal computer information conditions, extract abnormal features, and then compare the abnormal ratio coefficient of the abnormal features with the reference ratio coefficients of various stored abnormal patterns to identify and mark the financial computer information abnormal type with the highest matching degree; S5, for the marked financial computer information abnormal type, obtain the relevant feature information of this financial computer information abnormal type, and then conduct a second verification of the relevant feature information of this financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; S6, when there is no such financial computer information abnormal type, display a secondary financial transaction application page to the user, obtain the user's authorization to obtain relevant verification data, and then obtain relevant verification data from the corresponding data source according to the authorization result, and then conduct a third verification of the relevant verification data; S7, determine whether to grant security approval based on the results of the third verification. If the security approval passes, trigger a manual inspection requirement, obtain the specific reasons for the abnormalities marked by the manual inspection, and create an abnormal label for the specific reasons for the abnormalities. If the security approval fails, send a warning prompt to the user.

[0022] Specifically, the specific steps of S2 include: cleaning and feature extraction of the computer-stored data of financial transaction applications. The basic transaction information includes but is not limited to transaction amount, transaction time, transaction frequency, and transaction device. The information of both parties to the transaction includes but is not limited to the DIs of both parties to the transaction, the credit scores of both parties to the transaction, the historical transaction records of both parties to the transaction, the occupational types of both parties to the transaction, and the risk marking status of both parties to the transaction; dividing the computer-stored data of financial transaction applications into a training set and a test set, training using logistic regression to obtain a risk prediction model; inputting the computer-stored data of real-time monitored financial transaction applications into the risk prediction model, outputting a risk probability value, and then comparing the risk probability value with a risk probability threshold. A financial transaction application with a risk probability value greater than or equal to the risk probability threshold is marked as a key transaction attention object.

[0023] In this implementation plan, the specific steps for training using logistic regression to obtain a risk prediction model are as follows: After completing the cleaning and feature extraction of the computer-stored data of financial transaction applications, divide the data into a training set and a test set according to a certain ratio (such as 70% - 30% or 80% - 20%). The training set is used for model training, and the test set is used for evaluating model performance; screen the extracted features, remove features with high correlation or small contribution to risk prediction to reduce the complexity and overfitting risk of the model; perform standardization processing on the features to scale the feature values to the same scale range; initialize the parameters of the logistic regression model, including the intercept term and the coefficients of each feature, specifically initialize the coefficients to zero or random values; use the training set data to train the logistic regression model; the logistic regression model estimates the parameters of the model through the maximum likelihood estimation method, making the probability predicted by the model and the likelihood function of the actual label maximized; update the parameters of the model iteratively, continuously reducing the value of the loss function until the convergence condition is reached; use the test set data to evaluate the trained model, calculate the performance indicators of the model, such as accuracy, recall rate, F1 value, etc., to evaluate the prediction ability and generalization ability of the model; according to the evaluation results, adjust the parameters of the model or perform feature engineering to further optimize the model performance; after multiple adjustments and evaluations, determine the final risk prediction model. An example of the specific acquisition expression of the risk prediction model is:

[0024] , where represents the probability of risk when given the computer-stored data of a financial transaction application , represents the intercept term, which is obtained through the maximum likelihood estimation method, represents the risk prediction model parameters, which are obtained through the maximum likelihood estimation method, represents the specific feature values in the computer-stored data of a financial transaction application, Represents the total number of computer - stored data for financial transaction applications.

[0025] The transaction amount refers to the amount of funds involved in each financial transaction, which is directly obtained from the transaction records of the financial transaction system and is quantified using the actual transaction amount value directly; the transaction time represents the specific moment or time period when the transaction occurs. Similarly, the timestamp information of the transaction is obtained from the transaction records, and the transaction time is converted into a timestamp, or the characteristics of the transaction time are extracted for quantification; the transaction frequency refers to the number of transactions that occur within a certain period of time, which is calculated by counting the number of transaction records within a certain period of time, and the counted number of transactions is used as the quantification value; the transaction device refers to the type of device used for the transaction, such as mobile phones, computers, ATMs, etc. The transaction system records the device identification information used when the transaction is initiated, and the one - hot encoding is used to convert different device types into binary vectors for quantification.

[0026] The transaction - party IDs represent the identity numbers used to uniquely identify the two parties of the transaction, which are assigned by financial institutions or the transaction system and recorded in the transaction records, and are quantified by hash encoding or simple number - mapping; the credit scores of the two transaction parties reflect the score values of the credit status of the two transaction parties, which are obtained from credit rating agencies or calculated by financial institutions according to their own credit assessment models, and the numerical values of the credit scores are directly used for quantification; the historical transaction records of the two transaction parties represent the past transaction behavior records of the two transaction parties, which are obtained from the historical data of the financial transaction system, and some statistical features can be extracted, such as the number of transactions, the total transaction amount, the average transaction amount, etc. for quantification; the occupational types of the two transaction parties represent the occupational categories engaged by the two transaction parties, which are identified from the information collected during user registration or transactions, and the one - hot encoding is used to convert different occupational types into binary vectors for quantification; the risk - marking status of the two transaction parties represents the identification information indicating whether there are risks for the two transaction parties, and the marking information is converted into a numerical value, where "0" indicates no risk and "1" indicates risk.

[0027] The method for obtaining the risk probability threshold is as follows: According to the historical experience and business requirements of financial institutions, a fixed risk probability threshold is set. For example, based on past risk control experience, a financial institution sets the risk probability threshold to 0.5 or 0.6. It is also possible to determine the risk probability threshold according to the business objectives of financial institutions, such as risk preference, return target, etc. If a financial institution pays more attention to risk prevention and control, it may set a lower threshold; if it pays more attention to business expansion, the threshold can be appropriately increased. By evaluating the performance indicators of the model under different thresholds on the validation set, it is also possible to select a threshold that enables the model to achieve the best performance under business requirements. For example, an ROC curve can be plotted, and a suitable threshold can be selected according to the shape of the curve and business requirements. It is also possible to consider the risk losses and business revenues under different risk probability thresholds, and by calculating the cost-benefit ratio, select the threshold that optimizes the cost-benefit ratio. For example, when the risk probability exceeds the threshold, a financial institution may need to take additional risk control measures, which will incur certain costs, while when it is lower than the threshold, it may increase business risks and lead to losses.

[0028] Cleaning the computer-stored data of financial transaction applications can remove noisy, duplicate, and incorrect data, ensuring the accuracy and consistency of the data, providing a high-quality data foundation for subsequent risk prediction, and improving the reliability of the model. Extracting features from the basic transaction information and the information of both parties to the transaction helps to discover potential rules and risk factors in the data, enabling the model to consider various factors affecting transaction risks more comprehensively and enhancing the accuracy of risk prediction. The logistic regression model has good interpretability, and its coefficients can intuitively reflect the direction and degree of the impact of each feature on the risk probability, facilitating financial institutions to understand and analyze risk factors and make reasonable decisions. Inputting the computer-stored data of real-time monitored financial transaction applications into the risk prediction model can promptly output the risk probability value, and by comparing it with the risk probability threshold, quickly mark the key transaction objects of concern, realizing the real-time monitoring and early warning of financial transaction risks, and helping to take measures to prevent risks in a timely manner.

[0029] Specifically, multi-factor authentication includes but is not limited to personal identification number authentication, biometric authentication, and device identification. The specific analysis of the first verification is as follows: Using a convolutional neural network and a support vector machine to output the authentication results of each multi-factor authentication, and then summing the authentication results of each multi-factor authentication to obtain the first verification score. Comparing the first verification score with the first verification score threshold, when the first verification score is greater than or equal to the first verification score threshold, it is marked as an abnormal computer information status.

[0030] In this implementation plan, the specific steps for using a convolutional neural network and a support vector machine to output the authentication results of each multi-factor authentication are as follows:

[0031] For PIN authentication: Collect the PIN entered by the user and convert it into a format suitable for model input, such as encoding the PIN into a vector form; perform normalization on the PIN data to ensure that all data has the same scale range; input the preprocessed PIN data into the trained CNN model. The CNN model will automatically extract the features in the PIN data and perform feature extraction and dimensionality reduction on the data through operations such as convolutional layers and pooling layers; finally, map the extracted features to the output layer through the fully connected layer to output a probability value indicating the likelihood that the PIN passes the authentication. Use the features extracted by the CNN as the input to the SVM model. The SVM model will classify the input features according to the trained classification hyperplane and output a classification result (pass or fail authentication) and the corresponding confidence. Combine the probability value output by the CNN and the classification result and confidence output by the SVM to obtain the final authentication result of PIN authentication. The specific combination method can use weighted average for result fusion.

[0032] For biometric authentication: Collect biometric data such as fingerprints, facial images, iris images, etc. Perform preprocessing on the collected biometric data, including operations such as image enhancement, normalization, and cropping, to improve the quality and consistency of the data; convert the preprocessed biometric data into a format suitable for CNN input; input the preprocessed biometric data into the CNN model. The CNN model extracts the features in the biometric data and learns the essential features of the biometric; output a probability value through the output layer indicating the likelihood that the biometric data matches the registered data. Use the biometric features extracted by the CNN as the input to the SVM model. The SVM model classifies the biometric features according to the trained classification hyperplane and outputs a classification result (match or no match) and confidence. Combine the probability value output by the CNN and the classification result and confidence output by the SVM to obtain the final authentication result of biometric authentication. The specific combination method can use weighted average for result fusion.

[0033] For device identification: Collect relevant information about the device, such as device model, operating system version, device unique identifier, etc. Perform encoding and normalization on the device information and convert it into a vector form suitable for model input; input the preprocessed device information into the CNN model. The CNN model will extract the features in the device information and learn the feature pattern of the device; output a probability value through the output layer indicating the likelihood that the device is a trusted device. Use the device features extracted by the CNN as the input to the SVM model. The SVM model classifies the device features according to the trained classification hyperplane and outputs a classification result (trusted or untrusted) and confidence. Combine the probability value output by the CNN and the classification result and confidence output by the SVM to obtain the final authentication result of device identification. The specific combination method can use weighted average for result fusion.

[0034] The method for obtaining the first verification score threshold is as follows: According to the historical experience and business practices of financial institutions, a fixed first verification score threshold is set. For example, a financial institution can set the threshold as an empirical value, such as 70 points or 80 points, based on past authentication data and the marking situation of abnormal computer information. It can also determine the threshold according to the business objectives and risk preferences of the financial institution. If the financial institution pays more attention to risk prevention and control and hopes to minimize the occurrence of abnormal transactions as much as possible, the threshold can be set relatively high. If it pays more attention to user experience and business efficiency and hopes to reduce misjudgments, the threshold can be appropriately lowered. Use historical authentication data for model evaluation. By adjusting the threshold and observing indicators such as the marking accuracy and recall rate of abnormal computer information under different thresholds, select a threshold that can achieve the best balance of these indicators under business requirements. For example, an ROC curve can be drawn and a suitable threshold can be selected according to the shape of the curve and business requirements. It is also possible to consider the risk losses and authentication costs under different thresholds. When the threshold is too high, more normal transactions may be misjudged as abnormal, increasing the authentication cost and user inconvenience. When the threshold is too low, more abnormal transactions may be missed, increasing the risk loss. By calculating the cost-benefit ratio under different thresholds, select the threshold that optimizes the cost-benefit ratio.

[0035] Multi-factor authentication (PIN authentication, biometric authentication, device identification) is used to authenticate the identity of key transaction attention objects from multiple dimensions, greatly increasing the difficulty of identity theft and fraud and effectively improving the security of financial transactions. Two different machine learning models, convolutional neural network (CNN) and support vector machine (SVM), are used to output the authentication results. CNN has strong feature extraction capabilities and is especially suitable for processing data with spatial structures, such as biometric data. SVM performs well in processing high-dimensional data and small-sample data and can provide accurate classification results. The combination of the two can give full play to their respective advantages and improve the accuracy and reliability of authentication. By summing the authentication results of each multi-factor authentication to obtain the first verification score and comparing it with the first verification score threshold, a quantitative evaluation and standardized judgment of the authentication results are achieved, making the authentication process more objective and scientific, reducing the interference of human factors, and improving the accuracy and consistency of marking abnormal computer information. The multi-factor authentication method in the design can be extended and adjusted according to actual needs, such as adding new authentication factors or replacing the authentication model. At the same time, the first verification score threshold can also be dynamically adjusted according to different business scenarios and risk preferences, with strong scalability and flexibility.

[0036] Specifically, the specific steps of S4 include: obtaining the abnormal ratio coefficient of the marked abnormal computer information status and the reference ratio coefficients of various abnormal modes, and then respectively taking the absolute differences between the abnormal ratio coefficient and the reference ratio coefficients of various abnormal modes, and marking the one with the smallest absolute difference as the financial computer information abnormal type with the highest matching degree.

[0037] The specific analysis of obtaining the abnormal ratio coefficient of the marked abnormal computer information status and the reference ratio coefficients of various abnormal modes is as follows: The abnormal features include but are not limited to the fund inflow time, source account, and debt-to-income ratio; the abnormal features are quantified, and then based on logistic regression, the abnormal features are trained and input, and the abnormal ratio coefficient is output; the features of various abnormal modes stored are extracted, and the abnormal modes include but are not limited to market fluctuations, business expansion, and interest rate and exchange rate changes; for various abnormal modes, based on logistic regression, the features of various abnormal modes are respectively trained and input, and the reference ratio coefficients of various abnormal modes are output.

[0038] In this implementation plan, the fund inflow time represents the specific time point when the funds enter the trading account, which is extracted from the timestamp record of the financial trading system. The specific quantification can convert the time into a time interval based on a certain fixed time point. For example, based on the zero point of the day when the transaction occurs, calculate the number of minutes or hours between the fund inflow time and this reference time; the source account refers to the information of the transfer account of the funds, and the relevant account identifier is obtained from the financial transaction record. The quantification method can encode the account, such as using hash encoding or digital encoding, to convert the account information into a digital form for easy processing; the debt-to-income ratio refers to the ratio of the total debt to the total income, and the acquisition method is to calculate it by obtaining the debt information and income information of both parties to the transaction. The quantification method is to directly use the calculated ratio value.

[0039] The specific steps for training the input of abnormal features based on logistic regression and outputting the abnormal proportion coefficient are as follows: Clean and standardize the abnormal features to ensure the quality and consistency of the data; According to business experience and correlation analysis, select the abnormal features that have a significant impact on the abnormal computer information status as the input variables of the logistic regression model. For example, if it is found that certain features have a low correlation with the abnormal computer information status, they can be considered excluded to improve the efficiency and accuracy of the model; Construct a logistic regression model, using the processed abnormal features as independent variables and the abnormal computer information status (e.g., marked as abnormal or normal) as the dependent variable; Use the training data set to train the logistic regression model. By adjusting the parameters of the model, the model can best fit the training data. During the training process, the maximum likelihood estimation method is used to solve the parameters of the model, minimizing the difference between the predicted results of the model and the actual results; After training, the output of the model is the abnormal proportion coefficient, which represents the comprehensive quantitative value of the abnormal computer information status.

[0040] For various abnormal patterns, the specific steps for training the input of the features of each abnormal pattern based on logistic regression and outputting the reference proportion coefficient of each abnormal pattern are as follows: For each abnormal pattern, extract the corresponding features from the relevant data and perform preprocessing, including cleaning, standardization, etc. For example, for the abnormal pattern of market volatility, it is necessary to extract the volatility data of relevant market indices and perform normalization processing. For the abnormal pattern of business expansion, it may be necessary to extract the business expansion index data of the enterprise, such as new business areas, new customer numbers, etc., and perform standardization processing; According to the characteristics of each abnormal pattern and business understanding, select the representative features of the abnormal pattern as the input variables of the logistic regression model. For example, for the abnormal pattern of interest rate and exchange rate changes, select the indicators related to interest rates and exchange rates as features and exclude other features irrelevant to this pattern; For each abnormal pattern, construct a logistic regression model separately and use the corresponding training data set for training. During the training process, also by adjusting the parameters of the model, the model can accurately fit the relationship between the features of this abnormal pattern and the actual situation; After training, the output of the model is the reference proportion coefficient of each abnormal pattern, and these coefficients reflect the comprehensive quantitative value of each abnormal pattern.

[0041] An example of the calculation formula for the absolute difference between the abnormal proportion coefficient and the reference proportion coefficient of each abnormal pattern is as follows: , where represents the absolute difference between the abnormal proportion coefficient and the reference proportion coefficient of abnormal pattern C, represents the abnormal proportion coefficient, , represents the reference proportion coefficient of abnormal pattern C, , and respectively represent the calculation parameters of the abnormal ratio coefficient and the reference ratio coefficient of the abnormal mode C, and are obtained by the maximum likelihood estimation method. and respectively represent the specific values of the abnormal feature and the abnormal mode C feature. m and w respectively represent the total numbers of the abnormal feature and the abnormal mode C feature.

[0042] Through quantitative analysis and comparison, the matching degree between the abnormal computer information status and various abnormal modes can be accurately identified, providing a strong basis for subsequent targeted processing. Using logistic regression for training can fully explore the potential relationship between abnormal features and abnormal modes, improving the accuracy and reliability of identification. At the same time, by calculating the absolute difference, the abnormal type of financial computer information with the highest matching degree can be determined. The method is simple and intuitive, with strong operability.

[0043] Specifically, the specific steps of S5 include: according to the marked abnormal type of financial computer information, retrieve the typical feature information of this abnormal type of financial computer information in the database of the financial trading system, combine the typical feature information to form a typical feature set, and obtain the typical confidence interval of this abnormal type of financial computer information in combination with the preset confidence level; based on real-time monitoring, obtain the relevant feature information of this abnormal type of financial computer information, and then use the relevant feature information of this abnormal type of financial computer information to compare with the typical confidence interval of this abnormal type of financial computer information. When the relevant feature information of this abnormal type of financial computer information conforms to the typical confidence interval of this abnormal type of financial computer information, it is determined that this abnormal type of financial computer information exists, then the second verification is qualified, and the security approval is passed; when the relevant feature information of this abnormal type of financial computer information does not conform to the typical confidence interval of this abnormal type of financial computer information, it is determined that this abnormal type of financial computer information does not exist.

[0044] In this implementation plan, taking market fluctuations as an example, typical characteristic information includes but is not limited to trading price fluctuations, trading volume changes, market index movements, and correlations with macroeconomic indicators. Specifically, trading price fluctuations indicate that the trading prices of financial products have experienced significant increases or decreases, exceeding the normal fluctuation range. For example, stock prices have risen or fallen sharply in a short period, or foreign exchange rates have fluctuated violently, etc.; trading volume changes indicate that the trading volume in the trading market has significantly increased or decreased, showing anomalies compared with the same period in history. For instance, the trading volume of stocks on a certain trading day suddenly becomes several times that of usual, or the trading volume in the bond market continues to shrink; market index movements indicate that relevant market indices, such as the overall market index or sector indices in the stock market, have fluctuated significantly, reflecting the instability of the overall market or a specific sector. For example, if a sector index drops by more than a certain percentage in a short period, it may imply that the sector is facing market fluctuation risks; correlations with macroeconomic indicators indicate abnormal correlations with changes in macroeconomic indicators. For example, changes in indicators such as interest rates and inflation rates have had an impact on financial transactions that exceeds expectations. For example, when interest rates rise, the decline in bond prices far exceeds the theoretical value.

[0045] Taking market fluctuations as an example, the steps to obtain a typical confidence interval are as follows: Collect historical data related to market fluctuations in the past period from the database of the financial trading system, including various data of the above-mentioned typical characteristic information; Clean the collected data, remove outliers and missing values, and perform preprocessing operations such as standardization or normalization to ensure the quality and consistency of the data; Calculate statistics such as the mean and standard deviation of each typical characteristic information based on the preprocessed data; Preset a confidence level according to actual needs and risk preferences, such as the commonly used 95% or 99%; Calculate the confidence interval of each typical characteristic information according to the selected confidence level and the corresponding statistical distribution (such as the normal distribution). Taking trading price as an example, assuming it follows a normal distribution, at a 95% confidence level, the mean is 0 and the standard deviation is 1. This means we need to find two points, and the area between these two points accounts for 95% of the total area. Since the normal distribution is symmetric, the distances of these two points from the mean are the same. Starting from the mean, the area within approximately 1.96 standard deviations extended to both the left and right sides is about 95%. Then the expression for the typical confidence interval is , represents the mean of the trading price, represents the standard deviation of the trading price.

[0046] By retrieving the typical feature information of abnormal types of financial computer information in the database and comparing it with the relevant feature information monitored in real time, it is possible to accurately determine whether there is a specific abnormal type of financial computer information, improve the accuracy of judging abnormal situations in financial transactions, and help detect potential risks in a timely manner; using a data-driven method to make judgments based on the typical feature set and confidence interval reduces the interference of human factors, makes the decision-making more scientific and objective, and enhances the reliability and stability of the information security management method.

[0047] Specifically, the specific steps of S6 include: presenting the generated secondary financial transaction application page to the user and providing "agree to authorize" and "reject to authorize" exchange buttons. When the user selects "reject to authorize", the security approval fails, a risk warning prompt is sent to the user, and the user is marked as a risk. When the user selects "agree to authorize", relevant user verification data is obtained. The relevant verification data includes but is not limited to the asset information of other financial institutions, the business transaction details of upstream and downstream enterprises, and the user's transaction records. The relevant verification data is respectively retrieved and verified for relevant typical patterns. When there is relevant verification data that does not conform to the relevant typical patterns, the third verification is marked as unqualified and the security approval fails. When all the relevant verification data conform to the corresponding relevant typical patterns, the third verification is marked as qualified and the security approval is passed.

[0048] In this implementation plan, the asset information of other financial institutions refers to the various asset statuses that the user has in other financial institutions, such as deposits, wealth management products, stocks, bonds, etc. The acquisition method is through user authorization, and the financial trading system exchanges data with other financial institutions to obtain it. The quantification method is: quantifying different types of assets according to the market value or book value. For example, deposits are calculated based on the actual amount, and stocks are calculated based on the current stock price and the number of shares held.

[0049] The business transaction details of upstream and downstream enterprises are specifically the transaction details between upstream and downstream enterprises that have business dealings with the user, including transaction amount, transaction time, traded goods or services, etc. The acquisition method is to extract from the enterprise's business system or relevant database, provided that the financial trading system has the right to access this data. The quantification method is: taking the transaction amount as the main quantification index, and at the same time, the transaction frequency, transaction time interval, etc. can also be quantified. For example, it is expressed by the number of transactions per month, the average number of days between each transaction, etc.

[0050] The user's transaction records are all financial transaction records of the user within a certain period, including transaction amount, transaction time, transaction counterparty, etc. The acquisition method is to obtain from the transaction record database of the financial trading system itself. The quantification method is: based on the transaction amount and the number of transaction records, such as calculating the total transaction amount, average transaction amount, and change rate of the number of transaction records within a certain period.

[0051] The specific logical steps for retrieving and validating relevant typical patterns for relevant verification data are as follows: Analyze historical data and business experience to determine the typical patterns of various types of relevant verification data. For example, for the asset information of other financial institutions, the typical pattern is that the asset distribution conforms to a certain industry average level, or the increase or decrease range of assets within a certain period is within a reasonable range; perform preprocessing operations such as cleaning and transformation on the obtained relevant verification data to make it conform to the format and requirements of the typical pattern. For example, classify and summarize the asset information by different categories, and organize the transaction flow data according to the time series; extract key features from the preprocessed data, such as the total amount of assets, the proportion of various types of assets, the peak and valley values of the transaction flow, etc.; compare the extracted features with the features of the typical pattern, and calculate the similarity or difference degree. Specifically, distance measurement methods such as Euclidean distance and Manhattan distance can be used to measure the difference between the actual data and the typical pattern; judge whether it conforms to the typical pattern according to the set threshold. If the difference degree is less than the threshold, it is considered to conform to the typical pattern, otherwise, it is considered not to conform.

[0052] Taking the asset information of other financial institutions as an example, the example of retrieving and validating relevant typical patterns is as follows: Assume that the typical pattern is that in the assets of other financial institutions of users in a certain industry, the deposit proportion is about 50% - 70%, the wealth management product proportion is about 20% - 30%, the proportion of equity assets such as stocks and bonds is about 10% - 20%, and the total amount of assets has increased or decreased by no more than 20% in the past year. First, obtain the asset information data of other financial institutions of the user. After preprocessing, obtain the actual proportion of various types of assets of the user and the change situation of the total amount of assets; then extract key features, such as the current deposit proportion is 60%, the wealth management product proportion is 25%, the equity asset proportion is 15%, and the total amount of assets has increased by 15% in the past year; compare these features with the typical pattern, and calculate the difference degree between each feature and the corresponding range of the typical pattern. For example, the difference degree of the deposit proportion is 0, the difference degree of the wealth management product proportion is 0, the difference degree of the equity asset proportion is 0, and the difference degree of the increase in the total amount of assets is 0.25. Assume that the set comprehensive difference degree threshold is 0.3. Since the weighted average value of the difference degrees of each feature (assuming the weights of each feature are the same, and the weighted average difference degree is 0.0625) is less than the threshold, it is considered that the asset information of other financial institutions of this user conforms to the relevant typical pattern.

[0053] By obtaining more-dimensional relevant verification data of users and performing typical pattern retrieval and validation, the transaction security can be evaluated more comprehensively and the risk can be reduced; targeted verification of verification data from different sources helps to accurately judge whether there are abnormalities in the transaction and avoid misjudgment or missed judgment; provide a clear authorization selection interface to let users clearly understand the operation consequences, and at the same time mark the risk for users who refuse authorization to guide users to actively cooperate with the security verification.

[0054] Please refer to Figure 2 , a computer information security management system based on big data, which applies the above-mentioned computer information security management method based on big data, including: a data acquisition module for real-time collecting computer storage data of financial transaction applications based on multiple data sources of a financial transaction system, where the computer storage data of financial transaction applications includes basic transaction information and information of both parties to the transaction; a risk identification module for using a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then marking key transaction attention objects based on the risk identification results; a first verification module for performing multi-factor authentication on the key transaction attention objects, and then performing a first verification on the security of the key transaction attention objects based on the multi-factor authentication results, and identifying and marking abnormal computer information conditions; a retrieval module for extracting abnormal features for the marked abnormal computer information conditions, and then comparing the abnormal ratio coefficients of the abnormal features with the reference ratio coefficients of various abnormal patterns stored to identify and mark the financial computer information abnormal type with the highest matching degree; a second verification module for obtaining relevant feature information of the marked financial computer information abnormal type, and then performing a second verification on the relevant feature information of the marked financial computer information abnormal type to determine whether the marked financial computer information abnormal type exists; a third verification module for, when the marked financial computer information abnormal type does not exist, displaying a secondary financial transaction application page to the user, obtaining the user's authorization for obtaining relevant verification data, and then obtaining relevant verification data from the corresponding data sources according to the authorization results, and then performing a third verification on the relevant verification data; an approval management module for determining whether to grant security approval based on the third verification results. If the security approval is passed, it triggers a manual inspection requirement, obtains the specific reasons for the abnormalities marked by the manual inspection, creates an abnormal information label for the specific reasons for the abnormalities. If the security approval is not passed, it sends a warning prompt to the user.

[0055] In summary, the present application has at least the following effects: By collecting the computer storage data of financial transaction applications in real time, it is possible to ensure the immediate monitoring of computer information during the financial transaction process and promptly discover potential computer information security risks; using a risk prediction model for risk identification can mark in advance the transactions that may have risks, thus effectively preventing the occurrence of fraud and illegal transactions; multi-factor authentication increases the security of computer information during the transaction process and ensures the authenticity of the identities of both parties to the transaction through multiple verification means; further refining and verifying the abnormal computer information situation improves the accuracy and efficiency of abnormal identification by comparing abnormal features and abnormal patterns; for the abnormal types of financial computer information that are not identified, further verification is carried out by obtaining user authorization and relevant verification data to ensure the accuracy and reasonableness of the decision-making; for the specific reasons for the abnormalities confirmed by manual inspection, abnormal information tags can be created to provide valuable references for future risk prediction and abnormal identification.

[0056] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods and systems. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0057] The present invention is described with reference to the flowcharts and structural diagrams of methods and systems according to the embodiments of the present invention. It should be understood that each process and module combination in the flowcharts and structural diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and structures Figure 1 one module or multiple modules.

[0058] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one process or multiple processes and structures Figure 1 one module or multiple modules.

[0059] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to generate a computer-implemented process, thereby providing instructions for implementing the steps in the process Figure 1 a process or processes and architectures Figure 1 steps for specifying the functions specified in one or more modules.

[0060] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0061] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A computer information security management method based on big data, characterized in that, It includes the following steps: S1. Real-time collect the computer storage data of financial transaction applications based on multiple data sources of the financial transaction system. The computer storage data of the financial transaction applications includes basic transaction information and information of both parties to the transaction; S2. Use a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then mark key transaction attention objects based on the risk identification results; S3. Conduct multi-factor authentication on the key transaction attention objects, and then conduct a first verification on the security of the key transaction attention objects based on the multi-factor authentication results, and identify and mark abnormal computer information conditions; S4. For the marked abnormal computer information conditions, extract abnormal features, and then compare and retrieve the abnormal proportion coefficient of the abnormal features with the reference proportion coefficients of various abnormal patterns stored, and identify and mark the financial computer information abnormal type with the highest matching degree; S5. For the marked financial computer information abnormal type, obtain the relevant feature information of the financial computer information abnormal type, and then conduct a second verification on the relevant feature information of the financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; S6. When there is no such financial computer information abnormal type, display a secondary financial transaction application page to the user, obtain the user's authorization for obtaining relevant verification data, and then obtain relevant verification data from the corresponding data sources according to the authorization results, and then conduct a third verification on the relevant verification data; S7. Determine whether to grant security approval based on the third verification result. If the security approval is passed, trigger a manual inspection requirement, obtain the specific reasons for the abnormalities marked by the manual inspection, create an abnormal information label for the specific reasons for the abnormalities. If the security approval is not passed, send a warning prompt to the user.

2. The computer information security management method based on big data according to claim 1, characterized in that, The specific steps of S2 include: input the computer storage data of the financial transaction applications monitored in real time into the risk prediction model, output a risk probability value, and then compare the risk probability value with a risk probability threshold. The financial transaction applications with a risk probability value greater than or equal to the risk probability threshold are marked as key transaction attention objects.

3. A computer information security management method based on big data according to claim 1, characterized in that, The specific first verification includes: use a convolutional neural network and a support vector machine to output the authentication results of each multi-factor authentication, and then sum the authentication results of each multi-factor authentication to obtain a first verification score. Compare the first verification score with a first verification score threshold. When the first verification score is greater than or equal to the first verification score threshold, it is marked as an abnormal computer information condition.

4. A computer information security management method based on big data according to claim 1, characterized in that, The specific steps of S4 include: obtain the abnormal proportion coefficient of the marked abnormal computer information condition and the reference proportion coefficients of various abnormal patterns, and then respectively take the absolute difference between the abnormal proportion coefficient and the reference proportion coefficients of various abnormal patterns, and mark the one with the smallest absolute difference as the financial computer information abnormal type with the highest matching degree.

5. A computer information security management method based on big data according to claim 4, characterized in that, The obtaining of the abnormal proportion coefficient of the marked abnormal computer information condition and the reference proportion coefficients of various abnormal patterns specifically includes: conduct quantization processing on the abnormal features, and then input the abnormal features for training based on logistic regression, and output the abnormal proportion coefficient; Extract the stored feature information of various abnormal patterns, and respectively use the feature information of various abnormal patterns as training inputs based on logistic regression, and output the reference proportional coefficients of various abnormal patterns.

6. The computer information security management method based on big data according to claim 1, characterized in that, The specific steps of S5 include: According to the marked abnormal types of financial computer information, retrieve the typical feature information of the abnormal types of financial computer information, and then obtain the typical confidence interval of the abnormal types of financial computer information; Use the relevant feature information of the abnormal type of financial computer information to compare with the typical confidence interval. When the relevant feature information of the abnormal type of financial computer information conforms to the typical confidence interval of the abnormal type of financial computer information, it is determined that there is the abnormal type of financial computer information, the second verification is qualified, and the security approval is passed. Otherwise, it is determined that there is no such abnormal type of financial computer information.

7. A computer information security management method based on big data according to claim 1, characterized in that, The specific steps of S6 include: When the user refuses authorization, the security approval fails, a risk warning prompt is sent to the user, and the user is marked as a risk. When the user agrees to authorize, obtain the user's relevant verification data, and respectively conduct retrieval verification of relevant typical patterns on the relevant verification data. When there is relevant verification data that does not conform to the relevant typical pattern, mark that the third verification is unqualified. Otherwise, the security approval is passed.

8. A computer information security management system based on big data, which applies the computer information security management method based on big data described in any one of claims 1-7, is characterized in that, It includes: A data acquisition module, which is used to collect the financial transaction application computer storage data in real time based on multiple data sources of the financial transaction system. The financial transaction application computer storage data includes transaction basic information and transaction party information; A risk identification module, which is used to identify risks for the financial transaction application computer storage data by using a risk prediction model, and then mark key transaction attention objects based on the risk identification results; A first verification module, which is used to conduct multi-factor authentication on the key transaction attention objects, and then conduct a first verification on the security of the key transaction attention objects based on the multi-factor authentication results, and identify and mark the abnormal computer information status; A retrieval module, which is used to extract abnormal features for the marked abnormal computer information status, and then compare the abnormal proportional coefficients of the abnormal features with the reference proportional coefficients of various stored abnormal patterns, and identify and mark the abnormal type of financial computer information with the highest matching degree; A second verification module, which is used to obtain the relevant feature information of the marked abnormal type of financial computer information, and then conduct a second verification on the relevant feature information of the abnormal type of financial computer information to determine whether there is the abnormal type of financial computer information; A third verification module, which is used to display a secondary financial transaction application page to the user when there is no such abnormal type of financial computer information, obtain the user's authorization for obtaining relevant verification data, and then obtain relevant verification data from the corresponding data source according to the authorization result, and then conduct a third verification on the relevant verification data; An approval management module, which is used to determine whether to pass the security approval based on the third verification result. If the security approval is passed, trigger a manual inspection requirement, obtain the specific reasons for the abnormalities marked by the manual inspection, create an abnormal information label for the specific reasons for the abnormalities. If the security approval fails, send a warning prompt to the user.

Citation Information

Patent Citations

  • Digital wallet management system and method

    CN117114677A

  • Financial data security management system and method thereof

    CN119848882A