Big data transaction security management and control method

Through multi-dimensional risk assessment and dynamic control strategies, the problem of insufficient integration capabilities of multi-source heterogeneous data in big data transactions is solved, and the efficiency and accuracy of transaction security control is achieved.

CN120563239APending Publication Date: 2025-08-29深圳市企邦创新服务有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510952427.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

The existing technology has insufficient integration capabilities of multi-source heterogeneous data in big data transactions, making it difficult to conduct multi-dimensional analysis, and the management and control strategies lack dynamic adaptability, resulting in low transaction security management and control efficiency.

Method used

By collecting information of transaction subjects and environmental parameters, conducting multi-dimensional risk assessment, generating security level assessment coefficients, and generating dynamic management and control strategies based on this, including transaction blocking, real-time encryption and manual review, to build a real-time supervision and early warning system.

Benefits of technology

Accurate identification and dynamic adjustment of transaction risks have been achieved, and the efficiency and security of transaction security control have been improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120563239A_ABST
    Figure CN120563239A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of transaction security, in particular to a big data transaction security control method. The method comprises the following steps: acquiring basic information of a transaction subject, transaction data and environmental parameters, evaluating risks from subject, behavior and environmental dimensions to obtain corresponding risk indexes, integrating the risk indexes and security event influence degrees, obtaining security level evaluation coefficients, sorting and dividing security levels, generating corresponding management and control strategies based on the security levels, and performing management and control according to the management and control strategies. According to the method, hierarchical management and control of high-risk transaction blocking, medium-risk enhanced encryption, manual auditing and low-risk conventional monitoring are realized, meanwhile, a real-time early warning system is constructed through transaction data association analysis and multi-dimensional anomaly detection, and a management and control strategy is dynamically adjusted, so that the problems of risk identification lagging and management and control strategy extensive in transaction security are effectively solved, and the security of the transaction security is improved. And the transaction security evaluation precision and the response efficiency are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of transaction security technology, and in particular to a big data transaction security management and control method. Background Art

[0002] With the development of big data and information technology, transaction scale has seen explosive growth. As a core component of transaction risk management, transaction security control is also evolving. Existing technologies provide a quantitative basis for transaction security management by collecting basic transaction data and building risk assessment models. However, many problems still exist:

[0003] Existing technologies lack the ability to integrate multi-source heterogeneous data, making it difficult to effectively process complex data such as transaction subject information and environmental parameters, resulting in a single risk assessment dimension, a lack of multi-dimensional analysis of transaction environment risks, and an inability to identify complex risk scenarios; management and control strategies lack dynamic adaptability, adopt extensive management of transactions of different risk levels, and real-time monitoring relies on preset rules, making it difficult to adapt to dynamically changing transaction risks, resulting in low efficiency in transaction security management and control.

[0004] In order to solve the above-mentioned defects, a technical solution is now provided. Summary of the Invention

[0005] The purpose of the present invention is to solve the problem of low transaction security control and propose a big data transaction security control method.

[0006] The purpose of the present invention can be achieved through the following technical solutions:

[0007] A method for managing and controlling big data transaction security includes the following steps:

[0008] 101. Transaction data collection: The data collection unit collects basic enterprise information and transaction data of each transaction entity, and simultaneously obtains environmental parameters of the transaction data;

[0009] 102. Transaction Entity Risk Assessment: Conduct multi-dimensional risk assessments on each transaction entity through the risk assessment unit to obtain the transaction entity risk index, transaction behavior risk index, and environmental risk index;

[0010] 103. Security Level Assessment: By assessing the security level of each transaction, the multi-dimensional risk index is integrated into a unified security level assessment coefficient, and the transaction security level is ranked;

[0011] 104. Management and Control Strategy Generation: By comparing the security level assessment coefficient with the preset security level threshold, the security level of each transaction is determined and corresponding security management and control strategies are generated, including transaction blocking strategies, real-time encryption and manual review strategies, and regular monitoring strategies;

[0012] 105. Real-time supervision and early warning: Risk monitoring is carried out throughout the entire transaction life cycle through a multi-level processing approach.

[0013] As a further improvement of the present invention, the specific implementation process of the transaction subject risk index in step 102 includes:

[0014] Extract default events from the transaction subject's historical records, including overdue payment YQ, contract default WY and credit overdraft TZ; through formula W ij =b1·YQ+b2·WY+b3·TZ to obtain the historical default coefficient W ij , where b1, b2, and b3 are the weight factors affecting overdue payment, contract default, and credit overdraft;

[0015] Integrate multiple credit scores and use a weighted average algorithm to create a unified credit score X xj , and perform standardization so that X xj ∈[0,100];

[0016] Count the number of transactions of the trading subject in different time periods and construct the transaction frequency time series P ij ={P i,1 ,P i,2 ,...P i,j}; where i = 1, 2, 3, ..., n, represents the unique number bound to the transaction entity; j = 1, 2, 3, ..., m, represents the historical event cycle number;

[0017] The historical default coefficient W ij , Credit Score X ij and transaction frequency P ij , after normalization, enter the formula Get the transaction subject risk index R1, where Refers to the time decay coefficient; ω1, ω2, and ω3 are the influencing weight factors of historical default coefficient, credit score, and transaction frequency, respectively.

[0018] As a further improvement of the present invention, the specific implementation process of the transaction behavior risk index in step 102 includes:

[0019] Extract the transaction amount D of the i-th transaction data from real-time transaction data i , the previous transaction timestamp T 前 With the current transaction timestamp T 实 and transaction type L i , for T 前 With T 实 Calculate the transaction time difference ΔT i , after normalization, enter the formula Get outliers Among them, T0 is the normal trading interval benchmark;

[0020] At the same time, extract the transaction amount within the transaction subject cycle time and calculate the mean D z and standard deviation D x , after normalization, enter the formula Obtain the amount fluctuation value PD, map different transaction types to complexity scores based on the preset transaction type weight table, and obtain the transaction type complexity based on the table lookup mapping method

[0021] Outliers Amount fluctuation value PD and transaction type complexity After normalization, enter the formula The transaction risk assessment index R2 is obtained, where μ1, μ2, and μ3 are the influencing weight factors of outliers, amount fluctuations, and transaction type complexity, respectively.

[0022] As a further improvement of the present invention, the specific implementation process of the environmental risk index in step 102 includes:

[0023] The environmental risk index R3 is obtained by extracting the network security level WL, device anomaly rate YC and IP address anomaly degree DZ from the transaction environment data; after normalization processing, the formula R3 = λ1·WL+λ2·YC+λ3·DZ is substituted, where the device anomaly rate is obtained by extracting the characteristic identifier of the current transaction device through device fingerprint technology and matching it with the historical device library used by the transaction subject; the IP address anomaly degree is obtained by comparing the current transaction IP address with the historical IP address library of the transaction subject, calculating the address location anomaly degree and IP reputation, and combining them with the weighted formula; λ1, λ2, and λ3 are the influencing weight factors of the network security level, device anomaly rate, and IP address anomaly degree, respectively.

[0024] As a further improvement of the present invention, the specific implementation process of the security level evaluation coefficient in step 103 is as follows:

[0025] Extract the historical security event records of each transaction subject from the transaction data and obtain the current transaction time point Q 前 and historical security incident time point Q 历 , and calculate the time interval to get ΔQ; by formula The impact of security events R4 is obtained; where q is the total number of historical security events; S i Quantify the severity of the i-th historical security event, S i ∈[1,10]; is the time attenuation coefficient;

[0026] After normalizing the transaction subject risk index R1, transaction risk assessment index R2, environmental risk index R3 and security incident impact R4, they are inserted into the formula AQ=t1·R1+t2·R2+t3·R3+t4·R4 to obtain the security level assessment coefficient AQ; among them, t1, t2, t3, and t4 are the influence weight factors of the transaction subject risk index, transaction risk assessment index, environmental risk index and security incident impact, respectively.

[0027] As a further improvement of the present invention, the specific implementation process of the transaction blocking strategy in step 104 includes:

[0028] By comparing the security level assessment coefficient AQ with the preset security level threshold; dividing the risk level FX based on the comparison result;

[0029] When AQ is greater than the preset security level threshold, the security level is determined to be high risk and a transaction blocking strategy is generated, including:

[0030] Construct judgment functions based on transaction type, transaction status and transaction data characteristics

[0031] When the judgment function determines that the current transaction is at a critical moment, the current transaction process is immediately terminated, the transaction status is marked as pending review, and further execution of the transaction is prevented. Otherwise, the transaction process is frozen but the current status is retained. The transaction data is re-verified and the AQ is refreshed before re-judgment. Based on the result, the abort command is executed or the transaction is frozen and awaiting manual review.

[0032] As a further improvement of the present invention, the specific implementation process of the transaction blocking strategy in step 104 further includes:

[0033] Notify transaction subjects and security administrators in real time through multi-channel notifications, and use the formula PY=c1·FX+c2·D i + c3·SX + c4·YH to get the priority coefficient PY, PY = [1, 10], where SX is the timeliness requirement; YH is the user-preset notification priority; c1, c2, c3, and c4 are the risk level, transaction amount, timeliness requirement, and user-preset impact weight factors;

[0034] When SX≥7, notifications are primarily by phone and SMS, supplemented by email and in-app push notifications; when 4<SX<7, notifications are primarily by SMS and email; when SX≤3, in-app push notifications and email notifications are primarily;

[0035] When the user preset notification priority conflicts with the notification method determined by the priority coefficient, the formula U 最终 =YH×(1-K)+U 紧急 ×K calculates and determines the final notification method, where U紧急 The emergency notification channel preference value automatically assigned based on the risk level, K is the emergency coefficient;

[0036] Check the integrity of transaction data through digital signature verification and hash value comparison; perform secondary verification of user identity; analyze current transactions and historical user and group behaviors to identify abnormal transaction patterns; encrypt and store data from the entire transaction process to generate an electronic evidence package.

[0037] As a further improvement of the present invention, the specific implementation process of the real-time encryption and manual review strategy and the conventional monitoring strategy in step 104 includes:

[0038] When the AQ falls within the preset security level threshold, the security level is determined to be medium risk. A real-time encryption and manual review strategy is generated, including:

[0039] Upgrading the encryption algorithm for transaction data from standard strength to high strength through the encryption service interface, adding application-layer end-to-end encryption based on the transport layer TLS, and sending identity authentication requests to transaction entities. These requests are assigned to security administrators and processed through a dedicated console. Transaction limits are adjusted to 50% to 70% of normal levels, and processing is delayed by 3 to 5 minutes.

[0040] When AQ is less than the preset security level threshold, the security level is determined to be low risk and a regular monitoring strategy is generated, including:

[0041] Standard TLS transmission encryption and AES-128 storage encryption are applied to transaction data; automated audits are conducted based on preset rules and machine learning models, and any anomalies detected are marked and manually reviewed; after the transaction is completed, complete transaction details are recorded and stored in a structured database, and based on the Monte Carlo sampling algorithm, 5% of low-risk transactions are randomly selected for in-depth inspection.

[0042] As a further improvement of the present invention, the specific implementation process of risk control over the entire life cycle in step 105 includes:

[0043] The data processing unit performs structured decomposition on the original transaction data, divides it into basic fields, transaction subjects, environmental parameters and business fields according to the transaction agreement specifications, and after normalization processing based on the unified data model, screens important security monitoring fields and builds logical associations to form a transaction data association graph; the processed data is sent to the multi-dimensional anomaly inspection unit, which calculates the amount deviation based on the statistical model, identifies unconventional transaction time periods and IP location anomalies, and improves the confidence level of anomaly judgment through a weighted algorithm; the anomaly indicators are converted into standardized feature vectors and matched with preset patterns, and low-matching abnormal behaviors are marked and the pattern library is dynamically updated through reinforcement learning; the security level assessment coefficient is adjusted based on the anomaly detection and pattern matching results, and graded warning information is generated, which notifies and triggers corresponding management and control strategies in real time.

[0044] Compared with the prior art, the present invention has the following beneficial effects:

[0045] The present invention collects basic information of transaction subjects, transaction data and environmental parameters, evaluates risks from the dimensions of subjects, behaviors and environments, obtains corresponding risk indexes, integrates risk indexes with the impact of security events, obtains security level assessment coefficients and sorts and divides security levels, generates corresponding management and control strategies based on security levels, and implements hierarchical management and control of high-risk transactions blocking, medium-risk enhanced encryption and manual review, and low-risk routine monitoring. At the same time, a real-time early warning system is constructed through transaction data correlation analysis and multi-dimensional anomaly detection, and management and control strategies are dynamically adjusted, which effectively improves the accuracy and timeliness of risk identification, and significantly improves the efficiency of transaction security management and control and the security of the entire transaction process. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings;

[0047] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION

[0048] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0049] It should be understood that the terms “include” and “comprising” used in the specification and claims of the present disclosure indicate the presence of the described features, wholes, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or collections thereof.

[0050] It should also be understood that the terminology used in this disclosure is for the purpose of describing specific embodiments only and is not intended to limit the disclosure. As used in this disclosure and the claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise. It should also be further understood that the terms "and / implementing or" as used in this disclosure and the claims refer to any and all possible combinations of one or more of the associated listed items, including and including these combinations.

[0051] like Figure 1 As shown, a big data transaction security management and control method includes transaction data collection, transaction risk assessment, security level assessment, management and control strategy generation, and real-time supervision and early warning.

[0052] 101. Transaction Data Collection: The data collection unit collects basic corporate information and transaction data of each transaction entity. Basic information includes corporate information and credit records of the transaction entity, and transaction data includes transaction amount, transaction time, and transaction type. The data collection unit also acquires environmental parameters of the transaction data. Environmental parameters include transaction IP addresses, transaction initiating device identifiers, and network parameters.

[0053] 102. Transaction Entity Risk Assessment: A multi-dimensional risk assessment is conducted on each transaction entity through the risk assessment unit to obtain the transaction entity risk index, transaction behavior risk index, and environmental risk index. The specific process is as follows:

[0054] Z1, extract the default events of the i-th transaction subject in the j-th historical time period from the transaction subject history, the default events include overdue payment YQ, contract default WY and credit overdraft TZ; through formula W ij =b1·YQ+b2·WY+b3·TZ to calculate the historical default coefficient W ij , where b1, b2, and b3 are the weight factors affecting overdue payment, contract default, and credit overdraft;

[0055] By integrating multiple channels of credit scores and using a weighted average algorithm to synthesize a unified credit score X xj , multi-channel credit scoring includes financial institution scoring, third-party credit scoring and platform internal scoring; standardize the unified credit score to make the unified credit score X xj ∈[0,100];

[0056] By counting the number of transactions of the trading entities in different time periods, we can construct the transaction frequency time series P ij ={P i,1 ,P i,2 ,...P i,j}; where i = 1, 2, 3, ..., n, represents the transaction subject number, and each transaction subject is bound to a unique number; j = 1, 2, 3, ..., m, represents the historical event cycle number, and j = m represents the earliest cycle;

[0057] The historical default coefficient W ij , Credit Score X ij and transaction frequency P ij , after normalization, enter the formula Calculate the transaction subject risk index R1, where: Refers to the time decay coefficient; ω1, ω2, and ω3 are the weighting factors of historical default coefficient, credit score, and transaction frequency, respectively;

[0058] Z2. Extract the transaction amount D of the i-th transaction data from the real-time transaction data. i , the previous transaction timestamp T 前 With the current transaction timestamp T 实 and transaction type L i , by timestamping the previous transaction T 前 With the current transaction timestamp T 实 Calculate the transaction time difference ΔT i , and uniformly convert to hour units, normalize and enter the formula Calculate outliers Among them, T0 is the normal trading interval benchmark, which is set to 6 hours;

[0059] At the same time, extract the transaction amount within the transaction subject cycle time and calculate the mean D z and standard deviation D x , after normalization, enter the formula The amount fluctuation value PD is calculated, and different transaction types are mapped to complexity scores based on the preset transaction type weight table. The transaction type complexity is obtained based on the table lookup mapping method.

[0060] Outliers Amount fluctuation value PD and transaction type complexity After normalization, enter the formula The transaction risk assessment index R2 is calculated, where μ1, μ2, and μ3 are the weighting factors of outliers, amount fluctuations, and transaction type complexity, respectively.

[0061] Z3, by extracting the network security level WL, device anomaly rate YC, and IP address anomaly degree DZ from the transaction environment data; after normalization processing, substituting them into the formula R3 = λ1·WL+λ2·YC+λ3·DZ to calculate the environmental risk index R3, where the device anomaly rate is obtained by extracting the characteristic identifier of the current transaction device through device fingerprint technology and matching it with the current transaction subject's historical device library; the IP address anomaly degree is obtained by comparing the current transaction IP address with the transaction subject's historical IP address library, calculating the address location anomaly degree and IP reputation, and combining them with a weighted formula; λ1, λ2, and λ3 are the influencing weight factors of the network security level, device anomaly rate, and IP address anomaly degree, respectively;

[0062] 103. Security Level Assessment: By assessing the security level of each transaction, integrating the multi-dimensional risk index into a unified security level assessment coefficient, and ranking the transaction security levels, the specific implementation process includes:

[0063] Extract historical security event records of each transaction subject from the transaction data. Security event records include abnormal account login, data leakage and intrusion records; the record content includes event type, severity, occurrence time, impact range and processing results; at the same time, obtain the current transaction time point Q 前 and historical security incident time point Q 历 , and calculate the time interval to get ΔQ; by formula The impact of security events R4 is calculated; where q is the total number of historical security events; S i Quantify the severity of the i-th historical security event, S i ∈[1,10]; is the time attenuation coefficient;

[0064] The transaction subject risk index R1, transaction risk assessment index R2, environmental risk index R3, and security incident impact R4 are normalized and then inserted into the formula AQ = t1·R1+t2·R2+t3·R3+t4·R4 to calculate the security level assessment coefficient AQ; where t1, t2, t3, and t4 are the impact weight factors of the transaction subject risk index, transaction risk assessment index, environmental risk index, and security incident impact, respectively;

[0065] Arrange the security level assessment coefficients of each transaction in ascending order, divide the continuous security level assessment coefficients into discrete security levels based on cluster analysis, and construct a transaction security risk ranking table; the larger the security level assessment coefficient, the higher the security risk and the higher the control priority;

[0066] 104. Management and Control Strategy Generation: By comparing the security level assessment coefficient with the preset security level threshold, the security level of each transaction is determined and a corresponding security management and control strategy is generated. The specific implementation process is as follows:

[0067] 104-1. Compare the security level assessment coefficient AQ with the preset security level threshold; and divide the risk level FX based on the comparison result into high risk level, medium risk level and low risk level;

[0068] When the security level assessment coefficient is greater than the preset security level threshold range, the security level is determined to be high risk and a transaction blocking strategy is generated. The transaction blocking strategy includes: transaction critical moment judgment, multi-channel notification and security audit process;

[0069] 104-1.1. Judgment of critical transaction moments: Building a judgment function based on transaction type, transaction status, and transaction data characteristics Transaction status includes pending, in progress, and completed. Transaction data features include transaction amount, counterparty, and IP address. When the judgment function determines that the current transaction is at a critical moment, the current transaction process is immediately terminated, and the transaction status is marked as pending review, preventing further execution of the transaction. Critical moments include fund flow nodes, such as account balance deductions and fund escrow locks; state transition critical points, such as the transition of a contract from pending confirmation to being executed; and external system interaction points, such as blockchain transaction broadcasts.

[0070] If the judgment function determines that the current transaction is not at a critical moment, the transaction process is frozen but the current state is retained, waiting for further instructions, re-verifying the transaction data, and refreshing the security level assessment coefficient in real time. If the risk level is still high, it is again determined whether it is at a critical moment. If it is, the abort command is executed. If not, the current transaction is frozen and the current state is retained pending manual review by the security administrator.

[0071] 104-1.2, Multi-channel notification: Real-time notification of transaction subjects and security administrators through multi-channel notification methods, including phone, SMS, email and in-app push; through the formula PY = c1·FX + c2·D i The priority coefficient PY is calculated by adding c3·SX+c4·YH, where PY=[1,10], where SX is the timeliness requirement, determined by the risk level. High risk levels are handled immediately; medium risk levels are handled on the same day; and low risk levels are handled the next day. YH is the user-preset notification priority. c1, c2, c3, and c4 represent the risk level, transaction amount, timeliness requirement, and user-preset impact weight factors.

[0072] When SX≥7, notifications are primarily made by phone and SMS, supplemented by email and in-app notifications. Phone calls are made immediately, and if unanswered within 10 minutes, the call is redirected to a resent SMS. Emails and in-app notifications are sent simultaneously with detailed reports. When 4<SX<7, notifications are primarily made by SMS and email. If the SMS gateway receipt determines that the first SMS message is unread, it will be automatically resent after 5 minutes. An email will be sent one hour after the SMS notification is completed. When SX≤3, in-app notifications and email notifications are primarily used. In-app notifications are only displayed when the user opens the app, and emails combine similar low-risk notifications and send them together.

[0073] When the user's preset preference conflicts with the notification method determined by the priority coefficient, the formula U 最终 =YH×(1-K)+U 紧急 ×K is calculated and the final notification method is determined, where U 紧急 The emergency notification channel preference value is automatically assigned based on the risk level. K is the urgency coefficient. For high risk level, K = 0.7; for medium risk level, K = 0.3.

[0074] 104-1.3. Security Audit Process: Verify the transaction data integrity through digital signature verification; compare the hash value calculated from the transaction data stored at the initial stage with the hash value recalculated during the audit; perform secondary verification of user identity using methods such as biometric recognition and a one-time transaction password; analyze the current transaction against historical user and group behavior for multi-dimensional comparison to identify abnormal transaction patterns, including account theft, money laundering, and identity fraud; obtain and encrypt data from the entire transaction process to generate an electronic evidence package;

[0075] At the same time, a detailed risk report is generated, including risk factor analysis, abnormal behavior description, and control recommendations;

[0076] 104-2. When the security level assessment coefficient is within the preset security level threshold range, the security level is determined to be medium risk; a real-time encryption and manual review strategy is generated; the real-time encryption and manual review strategy includes:

[0077] The encryption service interface is used to upgrade the encryption algorithm for transaction data from standard strength to high strength, such as upgrading AES-128 to AES-256, while adding application-layer end-to-end encryption based on the transport layer TLS to form double encryption protection. The identity authentication service sends an authentication request to the transaction subject and pushes a dynamic password to the user's mobile device through a message queue based on the user's preset preferences, or initiates a biometric recognition process, requiring the user to complete an additional identity authentication step. At the same time, transaction information is pushed to the review workflow, assigned a priority based on transaction type, transaction amount, and risk level, and assigned to the security administrator based on a load balancing algorithm. The security administrator views transaction details, risk analysis, and historical transaction records through a dedicated console for manual judgment. The transaction parameter configuration is adjusted to reduce the transaction limit of the current transaction subject's account to 50% to 70% of the normal value, and a mechanism-based delay is embedded in the transaction processing process, delaying the standard processing time by 3 to 5 minutes. The security level assessment coefficient of the transaction is continuously analyzed during the delay period. An independent channel of communication is established with the transaction subject through the reserved contact information, and the transaction intention is verified by an automated voice system or a human customer.

[0078] 104-3. When the security level assessment coefficient is lower than the preset security level threshold range, the security level is determined to be a low risk level and a conventional monitoring strategy is generated. The conventional monitoring strategy includes:

[0079] Standard TLS transmission encryption and AES-128 storage encryption are applied to transaction data to establish a basic security barrier. Encryption keys are regularly rotated through the key management unit. Automated audits are conducted based on preset rules and machine learning models, with detected anomalies flagged and manually reviewed. After a transaction is completed, complete transaction details are recorded and stored in a structured database according to data classification strategies. Archiving tasks are performed within the cycle time, and expired data is compressed and migrated to cold storage. A fast retrieval index is also maintained. Based on the Monte Carlo sampling algorithm, 5% of low-risk transactions are randomly selected for in-depth inspections, covering data integrity, behavioral patterns, and correlation analysis.

[0080] 105. Real-time supervision and early warning: Risk monitoring is performed throughout the entire transaction life cycle through a multi-level processing approach. The specific implementation process is as follows:

[0081] The data processing unit performs structured processing, breaking down raw transaction data into basic fields, transaction subjects, environmental parameters, and business fields based on transaction protocol specifications. Based on a unified data model, transaction data from different sources and formats is standardized, with unified formats and coding standards. Important fields related to security monitoring are screened, including authentication fields, transaction data fields, and environmental parameter fields. Logical relationships between fields are then established to form a transaction data association graph.

[0082] Processed transaction data is transmitted to a multi-dimensional anomaly detection unit for analysis. The unit calculates the degree of deviation between transaction amounts and historical transaction amounts based on statistical models, dynamically adjusting thresholds to accommodate different industry characteristics. It identifies irregular transaction periods and analyzes the distribution and timing of transaction events. It also identifies location anomalies by analyzing IP address matching and comparing them with a risky IP database. When transactions simultaneously trigger anomaly indicators, a weighted algorithm is used to increase the confidence level of anomaly judgments.

[0083] The detected abnormal indicators are converted into standardized feature vectors and matched with the preset abnormal behavior patterns for similarity; abnormal behaviors with low matching degree with the abnormal behavior pattern library are marked, and autonomous learning and dynamic updating of the abnormal behavior pattern library are carried out based on the reinforcement learning mechanism;

[0084] Based on the results of multi-dimensional anomaly detection and abnormal behavior pattern similarity matching, the security level assessment coefficient is dynamically adjusted, graded warning information is generated, and the corresponding management and control strategies are updated; the warning information is notified to the transaction subjects and security administrators in real time through multiple channels, and the corresponding management and control strategies are triggered in real time.

[0085] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to specific embodiments. Obviously, many modifications and variations are possible based on the contents of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.

Claims

1. A method for security management and control of big data transactions, characterized in that: The following steps are involved:

101. Transaction data collection: The data collection unit collects basic enterprise information and transaction data of each transaction entity, and simultaneously obtains environmental parameters of the transaction data; 102. Transaction Entity Risk Assessment: Conduct multi-dimensional risk assessments on each transaction entity through the risk assessment unit to obtain the transaction entity risk index, transaction behavior risk index, and environmental risk index; 103. Security Level Assessment: By assessing the security level of each transaction, the multi-dimensional risk index is integrated into a unified security level assessment coefficient, and the transaction security level is ranked; 104. Management and Control Strategy Generation: By comparing the security level assessment coefficient with the preset security level threshold, the security level of each transaction is determined and corresponding security management and control strategies are generated, including transaction blocking strategies, real-time encryption and manual review strategies, and regular monitoring strategies; 105. Real-time supervision and early warning: Risk monitoring is carried out throughout the entire transaction life cycle through a multi-level processing approach.

2. A method for security management and control of big data transactions according to claim 1, characterized in that: The specific implementation process of the transaction subject risk index in step 102 includes: Extract default events from the transaction subject's historical records, including overdue payment YQ, contract default WY and credit overdraft TZ; through formula W ij =b1·YQ+b2·WY+b3·TZ to obtain the historical default coefficient W ij , where b1, b2, and b3 are the weight factors affecting overdue payment, contract default, and credit overdraft; Integrate multiple credit scores and use a weighted average algorithm to create a unified credit score X xj , and perform standardization so that X xj ∈[0,100]; Count the number of transactions of the trading subject in different time periods and construct the transaction frequency time series P ij ={P i,1 ,P i,2 ,...P i,j }; where i = 1, 2, 3, ..., n, represents the unique number bound to the transaction entity; j = 1, 2, 3, ..., m, represents the historical event cycle number; The historical default coefficient W ij , Credit Score X ij and transaction frequency P ij , after normalization, enter the formula Get the transaction subject risk index R1, where Refers to the time decay coefficient; ω1, ω2, and ω3 are the influencing weight factors of historical default coefficient, credit score, and transaction frequency, respectively.

3. A method for security management and control of big data transactions according to claim 2, characterized in that: The specific implementation process of the transaction behavior risk index in step 102 includes: Extract the transaction amount D of the i-th transaction data from real-time transaction data i , the previous transaction timestamp T 前 With the current transaction timestamp T 实 and transaction type L i , for T 前 With T 实 Calculate the transaction time difference ΔT i , after normalization, enter the formula Get outliers Among them, T0 is the normal trading interval benchmark; At the same time, extract the transaction amount within the transaction subject cycle time and calculate the mean D z and standard deviation D x , after normalization, enter the formula Obtain the amount fluctuation value PD, map different transaction types to complexity scores based on the preset transaction type weight table, and obtain the transaction type complexity based on the table lookup mapping method Outliers Amount fluctuation value PD and transaction type complexity After normalization, enter the formula The transaction risk assessment index R2 is obtained, where μ1, μ2, and μ3 are the influencing weight factors of outliers, amount fluctuations, and transaction type complexity, respectively.

4. A method for security management and control of big data transactions according to claim 3, characterized in that: The specific implementation process of the environmental risk index in step 102 includes: The environmental risk index R3 is obtained by extracting the network security level WL, device anomaly rate YC and IP address anomaly degree DZ from the transaction environment data; after normalization processing, the formula R3 = λ1·WL+λ2·YC+λ3·DZ is substituted, where the device anomaly rate is obtained by extracting the characteristic identifier of the current transaction device through device fingerprint technology and matching it with the historical device library used by the transaction subject; the IP address anomaly degree is obtained by comparing the current transaction IP address with the historical IP address library of the transaction subject, calculating the address location anomaly degree and IP reputation, and combining them with the weighted formula; λ1, λ2, and λ3 are the influencing weight factors of the network security level, device anomaly rate, and IP address anomaly degree, respectively.

5. A method for security management and control of big data transactions according to claim 1, characterized in that: The specific implementation process of the security level evaluation coefficient in step 103 is as follows: Extract the historical security event records of each transaction subject from the transaction data and obtain the current transaction time point Q 前 and historical security incident time point Q 历 , and calculate the time interval to get ΔQ; by formula The impact of security events R4 is obtained; where q is the total number of historical security events; S i Quantify the severity of the i-th historical security event, S i ∈[1,10]; is the time attenuation coefficient; After normalizing the transaction subject risk index R1, transaction risk assessment index R2, environmental risk index R3 and security incident impact R4, they are inserted into the formula AQ=t1·R1+t2·R2+t3·R3+t4·R4 to obtain the security level assessment coefficient AQ; among them, t1, t2, t3, and t4 are the influence weight factors of the transaction subject risk index, transaction risk assessment index, environmental risk index and security incident impact, respectively.

6. A method for security management and control of big data transactions according to claim 1, characterized in that: The specific implementation process of the transaction blocking strategy in step 104 includes: By comparing the security level assessment coefficient AQ with the preset security level threshold; dividing the risk level FX based on the comparison result; When AQ is greater than the preset security level threshold, the security level is determined to be high risk and a transaction blocking strategy is generated, including: Construct judgment functions based on transaction type, transaction status and transaction data characteristics When the judgment function determines that the current transaction is at a critical moment, the current transaction process is immediately terminated, the transaction status is marked as pending review, and further execution of the transaction is prevented. Otherwise, the transaction process is frozen but the current status is retained. The transaction data is re-verified and the AQ is refreshed before re-judgment. Based on the result, the abort command is executed or the transaction is frozen and awaiting manual review.

7. A method for security management and control of big data transactions according to claim 6, characterized in that: The specific implementation process of the transaction blocking strategy in step 104 further includes: Notify transaction subjects and security administrators in real time through multi-channel notifications, and use the formula PY=c1·FX+c2·D i + c3·SX + c4·YH to get the priority coefficient PY, PY = [1, 10], where SX is the timeliness requirement; YH is the user-preset notification priority; c1, c2, c3, and c4 are the risk level, transaction amount, timeliness requirement, and user-preset impact weight factors; When SX≥7, notifications are primarily by phone and SMS, supplemented by email and in-app push notifications; when 4<SX<7, notifications are primarily by SMS and email; when SX≤3, in-app push notifications and email notifications are primarily; When the user preset notification priority conflicts with the notification method determined by the priority coefficient, the formula U 最终 =YH×(1-K)+U 紧急 ×K calculates and determines the final notification method, where U 紧急 The emergency notification channel preference value automatically assigned based on the risk level, K is the emergency coefficient; Check the integrity of transaction data through digital signature verification and hash value comparison; perform secondary verification of user identity; analyze current transactions and historical user and group behaviors to identify abnormal transaction patterns; encrypt and store data from the entire transaction process to generate an electronic evidence package.

8. A method for controlling the security of big data transactions according to claim 7, characterized in that: The specific implementation process of the real-time encryption and manual review strategy and the conventional monitoring strategy in step 104 includes: When the AQ falls within the preset security level threshold, the security level is determined to be medium risk. A real-time encryption and manual review strategy is generated, including: Upgrading the encryption algorithm for transaction data from standard strength to high strength through the encryption service interface, adding application-layer end-to-end encryption based on the transport layer TLS, and sending identity authentication requests to transaction entities. These requests are assigned to security administrators and processed through a dedicated console. Transaction limits are adjusted to 50% to 70% of normal levels, and processing is delayed by 3 to 5 minutes. When AQ is less than the preset security level threshold, the security level is determined to be low risk and a regular monitoring strategy is generated, including: Standard TLS transmission encryption and AES-128 storage encryption are applied to transaction data; automated audits are conducted based on preset rules and machine learning models, and any anomalies detected are marked and manually reviewed; after the transaction is completed, complete transaction details are recorded and stored in a structured database, and based on the Monte Carlo sampling algorithm, 5% of low-risk transactions are randomly selected for in-depth inspection.

9. A method for security management and control of big data transactions according to claim 1, characterized in that: The specific implementation process of risk management and control throughout the entire life cycle in the 105 steps includes: The data processing unit performs structured decomposition on the original transaction data, divides it into basic fields, transaction subjects, environmental parameters and business fields according to the transaction agreement specifications, and after normalization processing based on the unified data model, screens important security monitoring fields and builds logical associations to form a transaction data association graph; the processed data is sent to the multi-dimensional anomaly inspection unit, which calculates the amount deviation based on the statistical model, identifies unconventional transaction time periods and IP location anomalies, and improves the confidence level of anomaly judgment through a weighted algorithm; the anomaly indicators are converted into standardized feature vectors and matched with preset patterns, and low-matching abnormal behaviors are marked and the pattern library is dynamically updated through reinforcement learning; the security level assessment coefficient is adjusted based on the anomaly detection and pattern matching results, and graded warning information is generated, which notifies and triggers corresponding management and control strategies in real time.

Citation Information

Cited By

  • A Method for Linking Risk Control and Hierarchical Disclosure in the Front-End of Commodity Trading

    CN122573159A