Risk management and control system and method based on knowledge graph

Through a risk management system based on knowledge graphs, risk propagation paths and data are linked in real time, multi-dimensional risk entropy values ​​are calculated, and risk management strategies are dynamically adjusted. This solves the problems of low manual analysis efficiency, difficult data integration, lack of real-time and predictive capabilities in existing technologies, and achieves efficient and accurate risk identification and early warning.

CN120632674APending Publication Date: 2025-09-12BEIJING TESTOR TECH
View PDF 0 Cites 9 Cited by

Patent Information

Application Number
CN202510697173.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-09-12

Smart Images

  • Figure CN120632674A_ABST
    Figure CN120632674A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of risk management, and provides a risk management and control system and method based on a knowledge graph, and the method comprises the steps: configuring a risk grading management and control mechanism in advance, and determining a management and control channel to which multi-source heterogeneous data belongs; acquiring propagation path characteristics through the control channel, and determining a target dynamic knowledge graph based on the propagation path characteristics; and according to the target dynamic knowledge graph, calculating a multi-dimensional risk entropy value based on propagation path characteristics, comparing the multi-dimensional risk entropy value with a reference risk entropy value of each level in a risk hierarchical management and control mechanism, and determining a risk level and a risk management and control strategy corresponding to the risk level. A dynamic knowledge graph is combined with a management and control channel, so that a conventional knowledge graph also has an effect of reflecting dynamic risk evolution. In risk management and control, through combination of a multi-dimensional risk entropy value and a dynamic knowledge graph, strong association between risk grading and a grading mechanism is realized, a management and control strategy is directly matched with dynamic evolution characteristics, and risk data and diffusion are prevented and controlled.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of risk management and control, and in particular to a risk management system and method based on knowledge graphs. Background Art

[0002] In existing technologies, risk data is often scattered across heterogeneous data sources such as business systems, IoT devices, and external public opinion. Data formats vary, and semantic associations are missing. This results in risk analysis relying on manual cleaning and integration, which is inefficient and prone to errors. For example, it is difficult to directly link the real-time operational data of industrial control systems with the business data of enterprise ERP systems. Traditional ETL (Extract, Transform, Load) technology suffers from latency and resource consumption issues when processing large-scale, time-sensitive data. Furthermore, differences in data security levels and permission management further exacerbate the difficulty of cross-system data integration, causing risk analysis to often miss key related information due to data fragmentation.

[0003] Traditional risk management strategies are often based on pre-set rules or expert experience, making them difficult to dynamically adjust to real-time risks. For example, the activation conditions of emergency response plans often rely on fixed thresholds, making them unable to adapt to the nonlinear evolution of risk events.

[0004] Furthermore, the lack of a mechanism to track and optimize policy execution results prevents the accumulation and reuse of successful historical strategies. For example, firefighting rescue plans that rely solely on historical cases may be unable to cope with the complexity of new disaster scenarios. This static policy system perpetuates a passive response mode for risk management, making it difficult to achieve proactive defense and continuous optimization.

[0005] Problems with traditional technical solutions:

[0006] (1) Excessive manual intervention and strong subjectivity. Existing risk management often relies on manual analysis and empirical judgment, which makes it difficult to cope with massive data and complex risk scenarios.

[0007] (2) Inefficient data integration and utilization. Existing risk management methods typically rely on dispersed, unstructured data, which is often stored in multiple different systems and databases, making data integration difficult. In addition, due to the lack of effective data analysis tools, companies find it difficult to extract valuable information from massive amounts of data, which in turn affects the accuracy and efficiency of risk identification and management.

[0008] (3) Lack of real-time and dynamic nature. Existing risk management methods usually only conduct risk assessments at specific time points or when an event occurs, lacking real-time monitoring and dynamic adjustment of risks. This makes it difficult for companies to respond quickly when risks occur, and they miss the best opportunity to respond to risks.

[0009] (4) Lack of prediction and early warning capabilities. Existing risk management methods mainly focus on historical data and current conditions, and lack the ability to predict and warn of future risks. This makes it difficult for companies to formulate risk response strategies in advance, reduce the possibility of risk occurrence, or mitigate risk losses.

[0010] Application Contents

[0011] This application proposes a risk management and control system and method based on a knowledge graph. By combining a dynamic knowledge graph with a control channel, the risk propagation path, the identification and collection of risk data, and the knowledge graph are linked in real time, so that conventional knowledge graphs can also reflect the dynamic evolution of risks. In risk management, by combining multi-dimensional risk entropy values ​​with dynamic knowledge graphs, risk assessment is expanded from the loss of the event itself to the risk of uncertainty in the process of risk data propagation, achieving a strong correlation between risk grading and grading mechanisms, so that the management and control strategy directly matches the dynamic evolution characteristics of the risk, rather than just targeting a single risk event itself.

[0012] On the first aspect, this application proposes a risk management method based on knowledge graph, including.

[0013] Pre-configure risk classification and control mechanisms to determine the control channels for multi-source heterogeneous data;

[0014] Propagation path features are collected through control channels to determine a target dynamic knowledge graph based on the propagation path features; the target dynamic knowledge graph includes the path features of the risk event path nodes and the event features of the risk event content;

[0015] According to the target dynamic knowledge graph, the multi-dimensional risk entropy value based on the propagation path characteristics is calculated, and the multi-dimensional risk entropy value is compared with the benchmark risk entropy value of each level in the risk grading control mechanism to determine the risk level and the risk control strategy corresponding to the risk level.

[0016] This application classifies business data and collects independent features through different management and control channels after classification to form a dynamic knowledge graph, and then calculates multi-dimensional risk entropy values; it not only solves the risk analysis of data instances of business data, but also can identify the risks of business data in uncertain propagation paths, reflecting the possible consequences of events and the possibility of propagation and diffusion of business data in uncertain propagation paths, as well as the corresponding risk levels, and generates corresponding processing strategies.

[0017] In combination with the first aspect, the collection of propagation path characteristics through the control channel further includes:

[0018] Determining, based on the propagation path characteristics, environmental parameters representing the service scenario type and the operating status parameters, and a first propagation path weight corresponding to the environmental parameters;

[0019] Dynamically adjust the weight of the first propagation path to obtain a comprehensive risk evaluation value calculated and output by the risk entropy value aggregation engine, which characterizes the characteristic spatiotemporal attributes of the propagation path.

[0020] This application calculates the risk entropy value of the propagation path characteristics and fits the weight distribution with the propagation path characteristics, so that in the case of uncertain propagation and diffusion, the risk results that may be caused by the risk data represented by the propagation path characteristics can be determined.

[0021] In combination with the first aspect, a path feature probe is deployed in the control channel, and the path feature probe is configured with a rule template for feature capture;

[0022] When the path feature probe detects propagation path features, it automatically matches the feature capture rule template based on the attribute labels of the path endpoint nodes to capture dynamic path features. Dynamic path features include: path propagation rate, path stability coefficient, and cross-domain connection strength.

[0023] According to the dynamic path characteristics, a cycle manager of the propagation path characteristics is established. When a dynamic path characteristic is a set path characteristic, the characteristic data archiving is triggered and a propagation path evolution trend analysis report is generated.

[0024] This application uses path feature probes to collect data representing path propagation characteristics in business data. Combined with rule templates, it prevents feature omissions. When all captured are dynamic path features, cycle management is performed. The cycle management and the time attributes of dynamic path features are coordinated. While performing real-time calculations, the propagation path features can also be used to determine the trend of business data, identify high-risk data in advance, and avoid post-response.

[0025] In combination with the first aspect, the calculation of the multi-dimensional risk entropy value based on the propagation path characteristics according to the target dynamic knowledge graph also includes:

[0026] Based on the target dynamic knowledge graph, a dynamic adjustment model for the baseline risk entropy value is constructed; wherein the dynamic adjustment model associates the business scenario knowledge base with the historical risk event library;

[0027] When the dynamic adjustment model detects structural changes in the business model or detects repeated outbreaks of similar risk events, the baseline entropy value recalibration process is initiated:

[0028] Extract the key path features of the current business topology, compare the distribution deviation of historical data in the same scenario, dynamically adjust the sliding window of the model configuration through the benchmark risk entropy value, dynamically correct the baseline entropy value boundaries of each level, and output the hierarchical threshold update parameters with confidence intervals to update the target dynamic knowledge graph.

[0029] In this application, by dynamically adjusting the model, the risk entropy value boundary error caused by data distribution deviation is automatically triggered, and then corrected through a sliding window with a confidence interval. While updating the dynamic knowledge graph, the risk analysis results are more accurate and can be displayed visually, with different risk levels displayed separately.

[0030] Combined with the first aspect, the target dynamic knowledge graph is also used to generate a three-dimensional dynamic model of risk propagation, including:

[0031] The propagation path characteristics are mapped into the radial expansion parameters of the connecting pipes, the baseline risk entropy value is converted into the node volume parameter, and the event characteristics are encoded into the surface texture features;

[0032] Generate multi-scale risk nodes of topological structure in the visualization interface according to radial expansion parameters, node volume parameters and surface texture characteristics;

[0033] When a separation instruction is received, the multi-scale risk nodes are separated into node clusters of specific risk levels, forming a spatiotemporal propagation heat map of the associated paths.

[0034] This application divides the topological structure of the target knowledge graph in the visualization interface. When receiving separation instructions, different risk nodes can be divided according to risk levels and displayed in the form of a spatiotemporal propagation heat map.

[0035] In combination with the first aspect, a cross-domain association detector is deployed in the target dynamic knowledge graph. When it is detected that the risk event path node is connected to more than two business domains at the same time, the cross-domain path is determined and the association risk analysis of the cross-domain path is initiated;

[0036] The domain path association risk analysis includes:

[0037] Extract the protocol conversion characteristics, data format conversion loss rate, and permission mapping consistency indicators of the cross-domain path to determine the cross-domain connection strength;

[0038] The risk transmission probability is calculated based on the cross-domain connection strength, a cross-domain risk thermal link is generated, and an early warning is issued in the form of pulse flashing in the visual interface.

[0039] This application uses cross-domain detectors to actively predict the risks that may exist when connecting to different business domains. When displaying risks, it issues an alarm through the user's visual perception angle of pulse flashing.

[0040] In combination with the first aspect, the multi-dimensional risk entropy value is compared with the benchmark risk entropy value of each level in the risk classification and control mechanism to determine the risk level, which also includes:

[0041] Create a historical trajectory analysis channel for risk entropy values ​​to obtain the risk entropy value change sequence of propagation path characteristics within a continuous time window;

[0042] Identify abnormal fluctuation patterns through characteristic waveform matching algorithms and compare the current entropy change curve with the precursor waveforms of historical high-risk events for similarity;

[0043] When the similarity exceeds the warning threshold, the probability of accelerated risk diffusion is calculated to mark the potential outbreak path and the vulnerability index of the associated nodes in the target dynamic knowledge graph.

[0044] This application predicts high-risk events by analyzing the precursor waveforms in high-risk events, prevents the lag and blindness of risk warnings, and conducts targeted prevention and control through the annotation information in the target dynamic knowledge graph.

[0045] In conjunction with the first aspect, the steps for generating the risk management and control strategy are:

[0046] Obtain the comparison results of the benchmark risk entropy value comparison and construct a risk control strategy knowledge graph based on the comparison deviation; the risk control strategy knowledge graph includes strategy quantitative values, which include strategy type, implementation cost, and historical success rate;

[0047] Once the risk level is determined, multi-constraint strategy screening is initiated to screen candidates from the risk management strategy knowledge graph and determine candidate strategies that meet the current available resource list and business continuity requirements;

[0048] Calculate the topological coverage matching degree, resource consumption cost-effectiveness, and side effect impact coefficient of each candidate strategy and the target risk point.

[0049] Output a set of policy options sorted by comprehensive utility, and mark the expected effective time window of each policy item.

[0050] This application constructs a risk management strategy knowledge graph for strategy screening, which can match strategies with resources when selecting strategies, make the effective time predictable, and sort the comprehensive utility.

[0051] In conjunction with the first aspect, the risk management strategy is also used to:

[0052] According to the risk management strategy, establish a strategy execution effect tracking channel and collect target dynamic knowledge graph status change data after the strategy is implemented;

[0053] Based on the target dynamic knowledge graph state change data, the differential feature extraction engine compares the expected risk reduction curve with the actual change trajectory to identify the characteristic pattern of strategy failure;

[0054] The strategy failure feature pattern is input into the strategy knowledge graph reinforcement learning module to generate strategy rule correction parameters and update the strategy matching weight coefficient, forming an online self-evolution mechanism of the strategy library.

[0055] This application can achieve the comparison of difference features through the changes in the target dynamic knowledge graph, thereby realizing real-time online update of the strategy library.

[0056] Secondly, this application proposes a risk management system based on knowledge graph, including:

[0057] Hierarchical control module: used to pre-configure the risk hierarchical control mechanism and determine the control channels for the ownership of multi-source heterogeneous data;

[0058] Graph configuration module: used to collect propagation path features through control channels and determine the target dynamic knowledge graph based on the propagation path features; the target dynamic knowledge graph includes the path features of the risk event path nodes and the event features of the risk event content;

[0059] Risk management and control module: used to calculate the multi-dimensional risk entropy value based on the characteristics of the propagation path according to the target dynamic knowledge graph, and compare the multi-dimensional risk entropy value with the benchmark risk entropy value of each level in the risk classification and control mechanism to determine the risk level and the risk management strategy corresponding to the risk level.

[0060] Other features and advantages of the present application will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.

[0061] The technical solution of the present application is further described in detail below through the accompanying drawings and examples. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] The accompanying drawings are used to provide a further understanding of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the accompanying drawings:

[0063] Figure 1 This is a schematic diagram of a scenario for multi-source heterogeneous data risk management in an embodiment of the present application;

[0064] Figure 2 This is a schematic diagram of the composition of a traditional multi-source heterogeneous data risk management and control platform;

[0065] Figure 3 This is a flow chart of a risk management method based on knowledge graph in an embodiment of the present application;

[0066] Figure 4 This is a scenario implementation diagram for calculating the comprehensive risk assessment value in an embodiment of the present application;

[0067] Figure 5 This is a schematic diagram of the execution scenario of the path feature probe in an embodiment of the present application;

[0068] Figure 6 A UML diagram for updating the target dynamic knowledge graph in the embodiment of the present application;

[0069] Figure 7 A schematic diagram of a scene of a three-dimensional dynamic model of a target dynamic knowledge graph in an embodiment of the present application;

[0070] Figure 8 This is a schematic diagram of a cross-domain risk analysis scenario in an embodiment of the present application;

[0071] Figure 9 Schematic diagram of the labeling process of the target dynamic knowledge graph in an embodiment of the present application;

[0072] Figure 10 This is a schematic diagram of a scenario in which policy options are output in an embodiment of the present application;

[0073] Figure 11 This is a process flow chart of the online self-evolution mechanism of the policy library in the embodiment of the present application;

[0074] Figure 12 This is a system structure diagram of a risk management system based on a knowledge graph in an embodiment of the present application. DETAILED DESCRIPTION

[0075] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application and are not used to limit the present application.

[0076] As many companies build data centers, they will collect and analyze multi-source heterogeneous data based on the company's business classification, achieve comprehensive security management, and detect and process risk data.

[0077] like Figure 1As shown in the figure, the traditional risk management and control platform for multi-source heterogeneous data includes user devices and the risk management and control platform. User devices include users' mobile phones, personal computers, Internet of Things devices, data processing equipment, vehicle-mounted equipment and other intelligent terminal devices. User devices are the data source of multi-source heterogeneous data and the data source for generating data. Multi-source heterogeneous data includes the company's business data, Internet of Things data, database data and log data. Business data is any business data uploaded by company employees and business data related to their job positions.

[0078] Risk management platforms are divided into cloud-based and local risk management platforms. The local risk management platform connects to data sources for multi-source heterogeneous data and performs preliminary processing of multi-source data through a constructed knowledge graph. It first performs data preprocessing, cleansing, and storage and backup. Then, based on the pre-built knowledge graph, it integrates multi-source data, configures high-speed transmission network equipment, identifies risk data, and builds index information for risk data. The cloud-based risk management platform is primarily used for risk assessment. It utilizes a cloud-based distributed computing cluster and dedicated analysis servers to perform risk assessments, determine the risk data present in multi-source heterogeneous data, and identify risk levels and trends. After communication warning processing, data analysis and processing are performed, and disposition measures are output through external access interfaces.

[0079] As the number of business branches increases, more and more data needs to be processed. When issuing risk data disposal measures based on the above solutions, static knowledge graphs are mostly based on preset rules or expert experience, which makes it difficult to adjust according to real-time risks and identify risk data. Moreover, risk data often faces the problem of diffusion and massive data, which is difficult to process on a large scale, and is likely to cause greater risks.

[0080] When identifying data risks in knowledge graphs, multi-source data integration is often required. However, due to factors such as the different paths and storage areas of massive amounts of data, valuable information cannot be quickly extracted during the processing of massive business data, and the identification of risk data may result in errors or anomalies.

[0081] Moreover, knowledge graphs are often static data identification. When integrating multi-source data through pre-stored risk databases and event case libraries, risk characteristics, risk data content and risk data paths are determined through risk comparison identification. These data are then transmitted to the cloud-based risk management and control platform for risk assessment. Through the processed data, combined with the rule cases at the data layer, the risk level is identified and the corresponding management and control strategy is generated. Finally, during the early warning, the implementation of management and control measures is achieved through manual intervention. Therefore, the efficiency is very low, and it is impossible to provide early warning of risks. It is also easily affected by subjective judgment.

[0082] In response to the above problems, this application proposes a risk management method based on knowledge graph. By classifying business data and collecting independent features through different management channels after classification, a dynamic knowledge graph is formed, and then multi-dimensional risk entropy values ​​are calculated. It not only solves the risk analysis of data instances of business data, but also can identify the risks of business data in uncertain propagation paths, reflecting the possible consequences of events and the possibility of propagation and diffusion caused by business data in uncertain propagation paths, as well as the corresponding risk levels, and generates corresponding processing strategies.

[0083] In response to the above problems, this application firstly adapts the data processing path of the risk management platform based on the existing business status of the enterprise and the risk management method of this application, such as Figure 2 FIG. 1 shows a schematic diagram of a multi-source heterogeneous risk management scenario, including user equipment and data processing equipment.

[0084] Data processing equipment can be cloud servers, network servers, local application servers, management servers and edge computing terminals, etc., which have data processing capabilities. Data processing equipment receives multi-source heterogeneous data through a management and control channel, that is, a specially set interactive interface, and then performs feature screening and entropy calculation through processors and memories to conduct risk management and control. Figure 1 The traditional multi-source heterogeneous data risk management and control platform shown in the figure, in terms of data preprocessing, this application sets a data management and control channel through data processing equipment. Compared with data preprocessing, the data management and control channel can divide different types of data and isolate data to prevent computing resource pressure in the comprehensive processing scenario of massive data. It can also realize data risk grading. The realization of different types of data division and data isolation is only a non-essential but adaptable conventional capability to realize data risk grading; then, through the first service cluster, through the rule probe engine, the propagation path of business data is identified. The business data in this application includes IoT device data, business system data, log system data and database data. Through the propagation path, this application builds a target dynamic knowledge graph, which is different from Figure 1The traditional multi-source heterogeneous data risk management and control platform shown is mainly a pre-configured static knowledge graph. In terms of risk data processing, the present application is more capable of analyzing and calculating diffusion risks and calculating diffusion and propagation trend risks. Traditional technologies are mostly static risk identification, which are trigger-type, patrol-type or intrusive risk monitoring, and have poor ability to segment risk data and calculate the intrusive risk trend of risk data. In addition, the present application sets up a second service cluster, which can combine business scenarios and historical risk events to perform multi-dimensional risk entropy value calculations on the propagation path characteristics of risk data, thereby achieving the positioning and level control of risk data, and eliminating the propagation of risk data on the propagation path, thereby preventing subsequent risks, rather than only discovering risk data to process risk data. The specific implementation process of the present application based on the above scenario is as follows. The implementation method of the present application example is described in detail below with reference to the accompanying drawings.

[0085] Example 1:

[0086] See Figure 3 , is a risk management method based on knowledge graph provided in the embodiment of the present application, such as Figure 3 As shown, in step 100, the present application pre-configures a risk classification control mechanism to determine the control channel for the ownership of multi-source heterogeneous data;

[0087] The risk grading and control mechanism establishes high, medium and low risk thresholds by pre-establishing risk level classification standards. Different risk thresholds will be classified according to the classification method of multi-source heterogeneous data. Different types of data, data of different business types, data from different sources and data of different formats will be classified for risk, so as to achieve the distinction of load data, and can directly perform preliminary risk classification based on data type, data business type, data source and data format. At this time, the risk classification of multi-source heterogeneous data is only a risk classification pre-determined based on preset data attributes. The risk grading and control mechanism is related to the dynamic knowledge graph. In the process of continuous collection of propagation path characteristics and risk detection, the risk grading method or rules of the graded control method can be updated in real time.

[0088] The control channel is based on risk classification, and multi-source heterogeneous data with different risk levels is transmitted through a separate control channel to achieve data isolation. At the same time, it also isolates risks accordingly. During the classification process, the risk classification control mechanism determines the data elements, labels, or semantics of the multi-source heterogeneous data, etc., which serve as the trigger mechanism for the mapping rules. It determines the mapping rules between multi-source heterogeneous data and the control channel, achieving accurate data partitioning and risk pre-division.

[0089] In step 101, the present application collects propagation path features through the control channel and determines a target dynamic knowledge graph based on the propagation path; wherein the target dynamic knowledge graph includes the path features of the risk event path nodes and the event features of the risk event content;

[0090] During the collection of propagation path characteristics, the control channel will identify the propagation path characteristics of the data transmitted in each control channel based on graph traversal or time series analysis, such as propagation path nodes, node density, propagation rate, path length and propagation area authority, as well as the event characteristics corresponding to the propagation data, namely business content, loss value, etc.; then, through the event characteristics, it can be determined whether the data is risk data, and then the propagation path characteristics of the risk data can be determined, thereby constructing a dynamically updated knowledge graph, which can reflect the diffusion trend and risk level of risk data in real time, and solve the problem that static knowledge graphs cannot reflect the results of risk evolution.

[0091] In step 103, based on the target dynamic knowledge graph, a multi-dimensional risk entropy value based on the characteristics of the propagation path is calculated. The multi-dimensional risk entropy value is compared with the baseline risk entropy value of each level in the risk classification and control mechanism to determine the risk level and the corresponding risk control strategy. In combination with the calculation of the multi-dimensional risk entropy value, the loss of the event itself in the risk assessment is extended to the uncertainty loss of the event propagation process. Therefore, the more complex the event path, the higher the entropy value and the higher the risk level, the higher the assessment accuracy.

[0092] Based on the target dynamic knowledge graph, the uncertainty of the propagation rate and diffusion trend in the propagation path characteristics, as well as the uncertainty of the loss value corresponding to the event characteristics, can be determined. This allows for the determination of multi-dimensional risk entropy values, specifically including path entropy and event entropy. In step 100, the risk grading and control mechanism determines the specific risk level by comparing the baseline entropy values ​​of different data types, and outputs a corresponding risk control strategy. The propagation path characteristics include the uncertainty of the propagation rate. For example, the more propagation paths there are for risk data, the higher the uncertainty, and the higher the entropy value corresponding to the propagation rate. The event entropy value, on the other hand, reflects the uncertainty of the event's consequences; the greater the loss value, the higher the corresponding baseline entropy value. The risk control strategy is a preset strategy invoked based on the risk level. The risk control strategy is correlated with the event content. For example, for high risk, the risk control strategy is to block the propagation path; for medium risk, the risk control strategy is to set a risk isolation point. Because the baseline entropy value has a preset grading mechanism, when the risk control strategy is to block the transmission path, event isolation can also be achieved, directly matching the comprehensive dynamic evolution, rather than targeting a single event to solve the problem of identifying low-risk events with "high loss value but simple transmission path" or high-risk events with "low loss value but complex transmission path".

[0093] Example 2:

[0094] like Figure 4 As shown, in the control channel of the present application, during the process of collecting propagation path characteristics, a comprehensive risk assessment of the propagation path characteristics can also be performed; in its specific implementation, there is an interactive interface between the control channel and the cache service cluster and the database cluster, and the service cluster is deployed with a business perception module 200, an operation status detection module 201, a storage server 202, a weight calculation engine 203, a risk entropy aggregation server 204 and a time synchronization device 205 through the interactive interface.

[0095] By using the mapping relationship between environmental parameters and weights stored in the storage server 202, after determining the propagation path characteristics, the business scenario information, such as the scenario label, can be determined in the business perception module 200 through the propagation path characteristics. The operation status detection module 201 obtains the log collection device and the data processing device CPU during data transmission, the utilization rate of these devices, and the real-time parameters corresponding to the network delay. The environmental parameters are determined based on the business scenario information and the motion status parameters. After determining the mapping relationship between the environmental parameters and the weights, for example, whether the weights are positively correlated / negatively correlated with the environmental risks, the weights are automatically assigned to generate the first propagation path weights.

[0096] Then, the weight of the first propagation path is calculated by the weight calculation engine 203, specifically through the path features or event features in the target dynamic knowledge graph. The path features represent the uncertainty of parameters such as the propagation rate or diffusion range, and the event features are the uncertainty of the risk degree and risk loss caused by the risk data, thereby triggering the weight adjustment rule to adjust the first propagation path weight. The risk entropy value aggregation server 204 combines the real-time location of the assessment event and the risk data. After revising the weight, it determines the comprehensive evaluation value based on the weight multiplied by the path entropy value and the weight multiplied by the event entropy value.

[0097] For example, by combining environmental parameters with dynamic weighting adjustments, weight distribution can be tailored to real-time business conditions, preventing a single risk assessment value system. The spatiotemporal attributes of the comprehensive risk assessment, combined with the event dimensions corresponding to environmental parameters, not only reflect real-time risks but also enable real-time location of risk data during transmission.

[0098] When weights are adjusted dynamically, the corresponding real-time updates of environmental parameters match the changes in path characteristics of the dynamic knowledge graph. This can track the evolution trend of risk data in different scenarios and predict the direction of risk diffusion and transmission. This solves the problem of disconnection between risk assessment and actual business scenarios. It does not rely on manual experience to adjust the evaluation dimensions, but automatically adapts based on business scenarios, operating status, and spatiotemporal attributes to achieve multi-dimensional risk assessment.

[0099] Example 3:

[0100] like Figure 5 As shown, the control channel of this application deploys path feature probes to capture path features, specifically:

[0101] After the multi-source heterogeneous data of this application is classified through the risk classification control mechanism, it is deployed through path feature probes in the control channel. During the deployment process, feature probes are deployed at key nodes such as the business domain boundaries and data interaction hubs of the control channel. Feature probes include network traffic features, edge computing nodes, etc., which are mainly used to identify the propagation path of risk data and determine the propagation path characteristics. Each probe has built-in capture rule templates such as high-concurrency path templates or cross-departmental learning path templates, which are mainly used to capture propagation path characteristics. The template database 300 defines rule templates based on historical propagation path characteristics, such as path patterns in high-concurrency scenarios. For example: Rule template A: The path endpoint label contains attack or infected data propagation nodes. By obtaining the propagation rate and the stability coefficient of the node, it is determined whether it is a propagation path feature. When there is risk data in the control channel, the rule template is loaded through the rule template library and the probe rules are configured. The number and location of the deployed path rule probes are automatically adapted based on the actual risk data according to different data types and different transmission capture volumes of the data control channel.

[0102] When the path probe of the present application detects new propagation path features, it will automatically capture the new path propagation features and extract the attribute labels of the path endpoint nodes. For example, the dynamic path features include: path propagation rate, path stability coefficient, and cross-domain connection strength; the path feature probe identifies the new propagation path through traffic monitoring, knowledge graph traversal and other means, and matches the nearest label in the rule template library through the semantic similarity algorithm to realize the collection of dynamic path features.

[0103] Based on the path propagation rate, path stability coefficient, cross-domain connection strength, which reflect the speed and rate of risk data diffusion, the stability of the diffusion path in historical similar transmission behaviors, and the interaction frequency across business domains, a cycle manager 301 is constructed to set trigger conditions.

[0104] For example, trigger conditions include: the path propagation rate is greater than the preset infection characteristic threshold, indicating a possible infection risk; the path stability frequency is lower than the preset stability frequency, etc. If the conditions are met, the feature data will be migrated from the in-memory database to cold storage, and an evolution trend report will be generated through time series analysis. The event sequence model is conventionally used to analyze and archive data.

[0105] This application combines the multi-location coverage of path feature probes with automatic template matching based on node labels to achieve unmanned automatic collection of dynamic features of multi-channel and multi-type paths. This solves the problem that static knowledge graphs in the existing technology use matching to identify features, which can only identify risk features but cannot analyze the diffusion situation. Through the cycle manager 301, according to the set feature regulations, in coordination with the event attributes of dynamic features, it can predict risk diffusion and analyze diffusion trends. Identifying high-risk and low-risk paths in advance can also limit cross-domain connections in advance.

[0106] Example 4:

[0107] like Figure 6 As shown, the target dynamic knowledge graph constructed by this application will be updated in real time before calculating the multi-dimensional risk entropy value.

[0108] This application builds a dynamic adjustment model that can dynamically adjust the baseline risk entropy value based on the real-time data of the target dynamic knowledge graph, namely the entity data, relationship data and attribute data of the propagation path characteristics; wherein, the dynamic adjustment model associates the business scenario knowledge base with the historical risk event library; the business scenario data mainly includes the risk characteristics of the scenario, and the historical risk event library is a database of risk events that have existed in history, including the entropy value distribution corresponding to each event. For details, please refer to Figure 6 Business scenario knowledge base and real-time risk event database.

[0109] This application dynamically adjusts the model to monitor business model data such as business process changes in real time, as well as the outbreak of similar or similar events in risk events, and initiates the recalculation and correction process of the baseline entropy value based on pre-set trigger conditions.

[0110] Extract the critical path features of the current business topology from the target dynamic knowledge graph. These features characterize the state and properties of the propagation path. Alternatively, the propagation path features can be directly used as key features. Based on the distribution of path features for the same historical scenario, the degree of deviation is calculated to assess the difference between the current risk characteristics and historical scenarios. When extracting critical path features, graph traversal algorithms (such as breadth-first search) can be used to identify the critical paths in the business topology.

[0111] Finally, by dynamically adjusting the sliding window of the model configuration, the boundaries of the baseline entropy values ​​at each level are dynamically corrected based on recent data. For example, the high-risk baseline value is adjusted from 80 to 85, and the confidence interval is calculated, such as the 95% confidence interval [82,88]. Finally, the updated parameters are output to update the target dynamic knowledge graph. The updated parameters can modify the risk level label of the node, etc.

[0112] The dynamic adjustment model of the associated business scenarios and historical events of this application will automatically trigger changes in business models or the same risk events, so that the baseline entropy value is dynamically updated with the business environment to prevent the static baseline value from becoming invalid. Through the deviation analysis of the key path characteristics, coordinated with the dynamic correction of recent data under the sliding window, the baseline value is adjusted not based on a single abnormal point, preventing erroneous adjustments due to accidental events. The confidence information output by the confidence interval is combined with the deviation analysis to provide a quantifiable confidence value for the risk management strategy, judge the effectiveness of the results, and also combine the target dynamic knowledge graph with the latest benchmark value to achieve synchronous analysis, solving the problem of the disconnection between the baseline entropy value and the business environment, and through dynamic adjustment of the model, automatic triggering, data distribution deviation analysis and sliding window correction with confidence intervals, the baseline value adjustment is adaptive, scientific and explainable, and the dynamic evolution of the risk model is achieved by updating the knowledge graph.

[0113] Example 5:

[0114] See Figure 7 When visualizing, this application can realize the classification analysis of risk data. The target dynamic knowledge graph is also used to generate a three-dimensional dynamic model of risk propagation. In specific operations:

[0115] The propagation path features, baseline risk entropy values, and event features in the target dynamic knowledge graph are mapped to the geometric properties of the three-dimensional model. Specifically, the entropy calculation results of the propagation path features in the target dynamic knowledge graph, such as the propagation rate, path nodes, and risk entropy values, are combined with information such as the event type and loss value of the event features, and mapped to the geometric properties of the three-dimensional model:

[0116] The radial scaling parameter is used to characterize the dynamic characteristics of the propagation path. For example, the faster the propagation rate, the greater the bandwidth of the connected control pipe, and the greater the amount of data that can be transmitted.

[0117] The node volume parameter is used to characterize the risk level of the node. The higher the risk entropy value, the larger the node volume;

[0118] The surface texture feature is used to characterize the type or degree of harm of an event. For example, a data leakage event is marked as a red striped texture.

[0119] Based on the mapped parameters, multi-scale risk nodes are generated in the visualization interface, and a global view is generated to display simplified nodes and a local view is generated to display detailed textures; the display accuracy of the nodes is dynamically adjusted through the level of detail (LOD) technology to achieve different levels of scaling. Specifically, based on the radial scaling parameters, node volume parameters and surface texture characteristics, a multi-scale risk node with a topological structure is generated in the visualization interface; the multi-scale risk node corresponds to a multi-scale model, and a 3D model of different accuracy is created for each risk node. According to the user's scaling, the LOD level of the node can be dynamically switched, and the topological relationship of the target dynamic knowledge graph layouts the topological structure of the multi-scale node in the visualization interface, including a tree structure and a grid structure.

[0120] If a user action is received, and the user action is a separation instruction, the multi-scale risk nodes are separated into node clusters of specific risk levels, forming a spatiotemporal propagation heat map of the associated paths. In other words, the multi-scale risk nodes are separated into different clusters based on risk level labels (such as "high / medium / low risk"), and the spatiotemporal propagation heat map is superimposed on the associated paths. The time dimension of the spatiotemporal propagation heat map is represented by a color gradient, and the spatial dimension is represented by brightness, thus visualizing the risk.

[0121] Exemplary:

[0122] Time dimension: Use color gradient (red → near term, blue → long term) to represent the temporal distribution of risk transmission;

[0123] Spatial dimension: brightness (high brightness → concentrated risk) is used to represent the distribution of risk in different areas;

[0124] This application combines pipeline expansion, node volume, and texture three-dimensional parameters with multi-scale presentation to achieve intuitive display of risk characteristics corresponding to the propagation path through three-dimensional spatial attributes. For example: the volume of high-entropy nodes expands, and the pipeline of the fast-propagating path is thickened, preventing the problems of low information density and vague feature expression in the existing two-dimensional display interface; through the combination of separation instructions and multi-scale nodes, users can quickly focus on nodes with specific risk levels. For example, after separating high-risk clusters, their associated paths can be analyzed separately to avoid information overlap and tedious screening in the two-dimensional map. The collaboration of spatiotemporal heat maps and dynamic models can intuitively display the evolution process of risks in events and space, and realize risk tracing.

[0125] That is, this application solves the problems of intuitiveness (three-dimensional attributes), analysis efficiency (interactive separation), and spatiotemporal tracing (thermal map) of risk communication visualization. Through the mapping of three-dimensional parameters and risk characteristics, the association of multi-scale rendering and risk level, and the combination of interactive separation and spatiotemporal heat, visualization can not only display information, but also serve as a risk analysis tool to quickly locate high-risk nodes by separating clusters.

[0126] Example 6:

[0127] See Figure 8 A cross-domain association detector 600 is deployed in the target dynamic knowledge graph. When it is detected that a risk event path node is connected to two or more business domains at the same time, the cross-domain path is determined and the association risk analysis of the cross-domain path is initiated. The present application deploys detectors at key nodes of the target dynamic knowledge graph, such as business domain boundaries and data exchange hubs, to monitor the business domain connection status of the risk event path node in real time. When the cross-domain association detector 600 detects that a risk event path node is connected to two or more business domains at the same time, for example, the production domain and the financial domain are detected at the same time, the association risk analysis process is automatically triggered to conduct an in-depth risk assessment of the cross-domain path.

[0128] During implementation, the risk analysis of cross-domain paths includes:

[0129] First, the cross-domain path's protocol conversion characteristics, data format conversion loss rate, and permission mapping consistency index are extracted to determine the strength of the cross-domain connection. The protocol conversion characteristics characterize the type of communication protocol used in the cross-domain path and the number of conversions. The data format conversion loss rate characterizes the proportion of information lost due to format conversion during cross-domain transmission. The permission mapping consistency index measures the degree of matching between the permission lists of the nodes before and after the cross-domain connection. By weighting the protocol conversion characteristics, data loss rate, and permission consistency, the cross-domain connection strength is calculated, quantifying the risk association degree of the cross-domain path. For example, the higher the strength, the greater the likelihood of risk transmission.

[0130] Based on the strength of cross-domain connections, the probability of risk transmission is calculated, and a cross-domain risk thermal link is generated, which is then displayed as a pulsed warning in the visualization interface. Finally, through machine learning models or statistical methods, the cross-domain connection strength is mapped to the risk transmission probability, quantifying the likelihood that cross-domain paths will lead to risk diffusion. In the visualization interface, cross-domain paths are rendered as thermal links (color gradients represent transmission probability), and pulsed flashes (frequency is positively correlated with probability) are used to enhance the visual cues of high-risk links, achieving dynamic risk warning.

[0131] The cross-domain detector of this application identifies cross-domain nodes and combines them with information such as protocols, data, and permissions extracted from multiple indicators. It assesses cross-domain risks from multiple dimensions based on parameters such as connection existence, interaction quality, and permission compliance. For example, frequent protocol conversion may lead to vulnerabilities, high data loss may lead to loss of key information, and inconsistent permissions may lead to unauthorized access. While identifying cross-domain connections, risks can also be assessed.

[0132] The connection strength calculation based on multi-indicator weighting and the probability model are coordinated to transform cross-domain risks from qualitative descriptions to quantitative probabilities. Risk management can clearly define priorities and give priority to high-probability links.

[0133] The dynamic visual stimulation of the pulse flash warning is combined with probability calculation and quantitative risk level, so that high-risk links can quickly attract users' attention through high-frequency flashing, avoiding neglecting key issues.

[0134] Example 7:

[0135] See Figure 9 This application compares the multi-dimensional risk entropy value with the benchmark risk entropy value of each level in the risk classification and control mechanism. In the process of determining the risk level, the potential diffusion path and node vulnerability of the risk data will be marked on the target knowledge graph.

[0136] Step 700: This application first creates a risk entropy historical trajectory analysis channel to obtain the risk entropy value change sequence of the propagation path characteristics within a continuous time window, that is, to create an independent analysis channel in the target dynamic knowledge graph, and extract the risk entropy value change sequence corresponding to the propagation path characteristics according to the time window, and the sequence bit is N; the channel creates network security, business processes or business scenarios of suspicious risk types, divides independent channels to avoid data confusion, and the window can extract entropy value data at continuous time points, filter out anomalies, and generate a change sequence of effective entropy values.

[0137] Step 701: This application identifies abnormal fluctuation patterns through a characteristic waveform matching algorithm, and compares the current entropy value change curve with the precursor waveform of historical high-risk events for similarity, that is, extracts key waveform features from the entropy value change sequence, including the rising rate and fluctuation frequency, and performs similarity comparison with the precursor waveform of historical high-risk events to identify abnormal fluctuation patterns. During waveform extraction, the entropy value sequence is standardized (normalized to the [0,1] interval) to extract features such as peaks, valleys, and slopes; the precursor waveform is the waveform of the corresponding precursor event of the same type of event in the historical risk event library. In similarity calculation, the dynamic time warping (DTW) algorithm is used to measure the shape matching degree between the current curve and the historical waveform.

[0138] Step 702: When the similarity exceeds the warning threshold, the probability of accelerated risk diffusion is calculated to annotate the potential outbreak path and the vulnerability index of the associated nodes in the target dynamic knowledge graph. If the similarity between the current entropy change curve and the historical precursor waveform exceeds the warning threshold, the probability of accelerated risk diffusion is calculated using a machine learning model to quantify the likelihood of risk evolution. Based on the topological structure of the target dynamic knowledge graph, high-probability propagation paths starting from the current high-risk node are identified and annotated as "potential outbreak paths" in the knowledge graph. The vulnerability index of the associated nodes on the potential outbreak path is calculated to quantify the degree to which the nodes are susceptible to risk and annotate them in the knowledge graph. The vulnerability index is calculated as follows: 0.5 × failure rate + 0.3 × connectivity + 0.2 × authority level, with 0.5, 0.3, and 0.2 representing the weights of the corresponding parameters.

[0139] This application can achieve early warning through continuous event sequence and waveform matching, and can achieve accurate risk management instead of comprehensive defense through diffusion probability prediction and potential path labeling. It can achieve risk tracing through waveform similarity and precursor waveform processing.

[0140] Example 8:

[0141] See Figure 10 ,In the process of generating the risk management and control strategy of this application, the specific steps are as follows:

[0142] This application constructs a structured policy knowledge graph based on the deviation between the current entropy value and the baseline value (i.e., the result of the comparison of the baseline risk entropy value). The nodes contain policy quantitative values, which include: policy type, implementation cost, historical success rate, and the mapping relationship between the comparison deviation and the policy. For example, high deviation scenarios are associated with strong blocking policies. After the risk level is determined, based on the current available resources and business continuity requirements, candidate policies that meet all constraints are screened from the policy knowledge graph. When screening candidate policies, traverse the policy knowledge graph to screen policies that meet both resource constraints and business continuity constraints, and perform multi-dimensional quantitative evaluations on the candidate policies to calculate the following three coefficients:

[0143] Topology coverage matching degree: the ratio of the number of risk paths covered by the strategy to the total number of paths to the target risk point;

[0144] Cost-effectiveness of resource consumption: the ratio of historical success rate to implementation cost;

[0145] Side Effect Impact Coefficient: Quantifies the negative impact of a policy on the business.

[0146] Finally, based on the comprehensive utility calculated by the multi-dimensional coefficient, candidate strategies are sorted from high to low by comprehensive utility, and the expected effective time window of each strategy is marked. For example, the effective time of strategy A is 10 to 15 minutes. This application combines the mapping of the risk level associated with the deviation with the strategy and multi-constraint screening to prevent the mismatch between strategy and risk requirements. Based on the synergy of multi-dimensional coefficient calculation and strategy quantification, it prevents the strategy effect from being a subjective judgment rather than a quantitative result. Finally, through the time window annotation, users are provided with clear execution priority and time reference.

[0147] Example 9:

[0148] See Figure 11 , this application is in the process of automatic evolution of the policy library:

[0149] After the strategy is implemented in step 900, an independent tracking channel is created for each executed risk control strategy in step 901. Then, in step 902, state change data of the target dynamic knowledge graph after the strategy implementation is collected. This state change data includes changes in risk entropy, path propagation rate, and event feature updates. Then, through the differential feature extraction engine in step 903, combined with the expected risk reduction curve in step 910 and the actual change trajectory in step 911, step 904 is executed to identify the characteristic pattern of strategy failure.

[0150] Specifically, risk management strategies include blocking and isolation measures, and risk scenarios include data leakage and system failure. State change events are captured in real time through agents such as hook functions deployed on knowledge graph nodes. Based on entropy curves, the actual risk reduction trajectory is extracted from the collected state change data and compared with the expected reduction curve preset before policy implementation. The differential feature extraction engine identifies failure modes.

[0151] Specifically, the expected extinction target, pre-implemented before the policy is implemented, is obtained from the policy knowledge graph, and the actual entropy change sequence after the policy is implemented is extracted from the time series database. In step 905, the identified failure mode is input into the reinforcement learning module of the policy knowledge graph. In step 906, model training is performed to generate policy rule correction parameters. In step 907, the policy matching weight coefficient is updated, achieving online self-evolution of the policy library in step 908. Finally, the policy library update completion result is obtained in step 909.

[0152] This application's state change data and difference comparisons can address the issue of ambiguous effect evaluation and achieve data quantification of results. By integrating failure pattern recognition with state change data, defects can be accurately analyzed. Finally, based on reinforcement learning and failure analysis, the treatment strategy can be dynamically optimized. This addresses the issues of unquantifiable policy effects, unclear failure causes, and rigid policy libraries.

[0153] Example 10:

[0154] This application also proposes a risk management system based on knowledge graph, such as Figure 12 As shown, it includes a hierarchical management and control module 1011, a graph configuration module 1012, and a risk management and control module 1013.

[0155] The hierarchical management and control module 1011 is used to pre-configure the risk hierarchical management and control mechanism and determine the management and control channels for the ownership of multi-source heterogeneous data; the risk hierarchical management and control mechanism sets high, medium and low risk thresholds by pre-establishing risk level classification standards. The risk thresholds of different levels will be divided according to the classification method of multi-source heterogeneous data. Different types of data, data of different business types, data from different sources, and data of different formats will be divided into risks to achieve the distinction of load data, and the preliminary risk classification can be directly performed according to the data type, data business type, data source and data format. At this time, the risk classification of multi-source heterogeneous data is only a risk classification pre-determined based on preset data attributes. The risk classification management mechanism is related to the dynamic knowledge graph. In the process of continuous collection of propagation path characteristics and risk detection, the risk classification method or rules of the hierarchical management method can be updated in real time.

[0156] The control channel is based on risk classification, and multi-source heterogeneous data with different risk levels is transmitted through a separate control channel to achieve data isolation. At the same time, it also isolates risks accordingly. During the classification process, the risk classification control mechanism determines the data elements, labels, or semantics of the multi-source heterogeneous data, etc., which serve as the trigger mechanism for the mapping rules. It determines the mapping rules between multi-source heterogeneous data and the control channel, achieving accurate data partitioning and risk pre-division.

[0157] The graph configuration module 1012 collects propagation path features through the control channel and determines a target dynamic knowledge graph based on the propagation path; wherein the target dynamic knowledge graph includes the path features of the risk event path nodes and the event features of the risk event content;

[0158] During the collection of propagation path characteristics, the control channel will identify the propagation path characteristics of the data transmitted in each control channel based on graph traversal or time series analysis, such as propagation path nodes, node density, propagation rate, path length and propagation area authority, as well as event characteristics, business content, loss value, etc. corresponding to the propagation data; then, through the event characteristics, it can be determined whether the data is risk data, and then the propagation path characteristics of the risk data can be determined, thereby constructing a dynamically updated knowledge graph, which can reflect the diffusion trend and risk level of risk data in real time, and solve the problem that static knowledge graphs cannot reflect the results of risk evolution.

[0159] Risk management and control module 1013 calculates a multi-dimensional risk entropy value based on the characteristics of the propagation path based on the target dynamic knowledge graph. It then compares the multi-dimensional risk entropy value with the baseline risk entropy value for each level in the risk grading and control mechanism to determine the risk level and the corresponding risk management strategy. By combining the calculation of the multi-dimensional risk entropy value and expanding the risk assessment from the event itself to the uncertainty loss during the event propagation process, the more complex the event path, the higher the entropy value, and the higher the risk level, the higher the assessment accuracy.

[0160] Based on the target dynamic knowledge graph, the uncertainty of the propagation rate and diffusion trend in the propagation path characteristics, as well as the uncertainty of the loss value corresponding to the event characteristics, can be determined. This allows for the determination of multi-dimensional risk entropy values, specifically including path entropy and event entropy. In step 100, the risk grading and control mechanism determines the specific risk level by comparing the baseline entropy values ​​of different data types, and outputs a corresponding risk control strategy. The propagation path characteristics include the uncertainty of the propagation rate. For example, the more propagation paths there are for risk data, the higher the uncertainty, and the higher the entropy value corresponding to the propagation rate. The event entropy value, on the other hand, reflects the uncertainty of the event's consequences; the greater the loss value, the higher the corresponding baseline entropy value. The risk control strategy is a preset strategy invoked based on the risk level. The risk control strategy is correlated with the event content. For example, for high risk, the risk control strategy is to block the propagation path; for medium risk, the risk control strategy is to set a risk isolation point. Because the baseline entropy value has a preset grading mechanism, when the risk control strategy is to block the transmission path, event isolation can also be achieved, directly matching the comprehensive dynamic evolution, rather than targeting a single event to solve the problem of identifying low-risk events with "high loss value but simple transmission path" or high-risk events with "low loss value but complex transmission path".

[0161] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A risk management method based on knowledge graph, characterized in that: include: Pre-configure risk classification and control mechanisms to determine the control channels for multi-source heterogeneous data; Propagation path features are collected through control channels to determine a target dynamic knowledge graph based on the propagation path features; the target dynamic knowledge graph includes the path features of the risk event path nodes and the event features of the risk event content; According to the target dynamic knowledge graph, the multi-dimensional risk entropy value based on the propagation path characteristics is calculated, and the multi-dimensional risk entropy value is compared with the benchmark risk entropy value of each level in the risk grading control mechanism to determine the risk level and the risk control strategy corresponding to the risk level.

2. A risk management method based on knowledge graph according to claim 1, characterized in that: The collecting of propagation path characteristics through the control channel further includes: Determining, based on the propagation path characteristics, environmental parameters representing the service scenario type and the operating status parameters, and a first propagation path weight corresponding to the environmental parameters; Dynamically adjust the weight of the first propagation path to obtain a comprehensive risk evaluation value calculated and output by the risk entropy value aggregation engine, which characterizes the characteristic spatiotemporal attributes of the propagation path.

3. A risk management method based on knowledge graph according to claim 1, characterized in that: Path feature probes are deployed in the control channel, and the path feature probes are configured with rule templates for feature capture; When the path feature probe detects propagation path features, it automatically matches the feature capture rule template based on the attribute labels of the path endpoint nodes to capture dynamic path features. Dynamic path features include: path propagation rate, path stability coefficient, and cross-domain connection strength. According to the dynamic path characteristics, a cycle manager of the propagation path characteristics is established. When a dynamic path characteristic is a set path characteristic, the characteristic data archiving is triggered and a propagation path evolution trend analysis report is generated.

4. A risk management method based on knowledge graph according to claim 1, characterized in that: The step of calculating the multi-dimensional risk entropy value based on the propagation path characteristics according to the target dynamic knowledge graph further includes: Based on the target dynamic knowledge graph, a dynamic adjustment model for the baseline risk entropy value is constructed; wherein the dynamic adjustment model associates the business scenario knowledge base with the historical risk event library; When the dynamic adjustment model detects structural changes in the business model or detects repeated outbreaks of similar risk events, the baseline entropy value recalibration process is initiated: Extract the key path features of the current business topology, compare the distribution deviation of historical data in the same scenario, dynamically adjust the sliding window of the model configuration through the benchmark risk entropy value, dynamically correct the baseline entropy value boundaries of each level, and output the hierarchical threshold update parameters with confidence intervals to update the target dynamic knowledge graph.

5. A risk management method based on knowledge graph according to claim 4, characterized in that: The target dynamic knowledge graph is also used to generate a three-dimensional dynamic model of risk propagation, including: The propagation path characteristics are mapped into the radial expansion parameters of the connecting pipes, the baseline risk entropy value is converted into the node volume parameter, and the event characteristics are encoded into the surface texture features; Generate multi-scale risk nodes of topological structure in the visualization interface according to radial expansion parameters, node volume parameters and surface texture characteristics; When a separation instruction is received, the multi-scale risk nodes are separated into node clusters of specific risk levels, forming a spatiotemporal propagation heat map of the associated paths.

6. A risk management method based on knowledge graph according to claim 1, characterized in that: A cross-domain association detector is deployed in the target dynamic knowledge graph. When it is detected that a risk event path node is connected to two or more business domains at the same time, a cross-domain path is determined and an association risk analysis of the cross-domain path is initiated; The domain path association risk analysis includes: Extract the protocol conversion characteristics, data format conversion loss rate, and permission mapping consistency indicators of the cross-domain path to determine the cross-domain connection strength; The risk transmission probability is calculated based on the cross-domain connection strength, a cross-domain risk thermal link is generated, and an early warning is issued in the form of pulse flashing in the visual interface.

7. A risk management method based on knowledge graph according to claim 1, characterized in that: The comparison of the multi-dimensional risk entropy value with the benchmark risk entropy value of each level in the risk classification control mechanism to determine the risk level also includes: Create a historical trajectory analysis channel for risk entropy values ​​to obtain the risk entropy value change sequence of propagation path characteristics within a continuous time window; Identify abnormal fluctuation patterns through characteristic waveform matching algorithms and compare the current entropy change curve with the precursor waveforms of historical high-risk events for similarity; When the similarity exceeds the warning threshold, the probability of accelerated risk diffusion is calculated to mark the potential outbreak path and the vulnerability index of the associated nodes in the target dynamic knowledge graph.

8. A risk management method based on knowledge graph according to claim 1, characterized in that: The steps for generating the risk management strategy are: Obtain the comparison results of the benchmark risk entropy value comparison and construct a risk control strategy knowledge graph based on the comparison deviation; the risk control strategy knowledge graph includes strategy quantitative values, which include strategy type, implementation cost, and historical success rate; Once the risk level is determined, multi-constraint strategy screening is initiated to screen candidates from the risk management strategy knowledge graph and determine candidate strategies that meet the current available resource list and business continuity requirements; Calculate the topological coverage matching degree, resource consumption cost-effectiveness, and side effect impact coefficient of each candidate strategy and the target risk point, output a set of strategy options sorted by comprehensive utility, and mark the expected effective time window of each strategy item.

9. A risk management method based on knowledge graph according to claim 1, characterized in that: The risk management strategy is also used to: According to the risk management strategy, establish a strategy execution effect tracking channel and collect target dynamic knowledge graph status change data after the strategy is implemented; Based on the target dynamic knowledge graph state change data, the differential feature extraction engine compares the expected risk reduction curve with the actual change trajectory to identify the characteristic pattern of strategy failure; The strategy failure feature pattern is input into the strategy knowledge graph reinforcement learning module to generate strategy rule correction parameters and update the strategy matching weight coefficient, forming an online self-evolution mechanism of the strategy library.

10. A risk management system based on knowledge graph, characterized in that: include: Hierarchical control module: used to pre-configure the risk hierarchical control mechanism and determine the control channels for the ownership of multi-source heterogeneous data; Graph configuration module: used to collect propagation path features through control channels and determine the target dynamic knowledge graph based on the propagation path features; the target dynamic knowledge graph includes the path features of the risk event path nodes and the event features of the risk event content; Risk management and control module: used to calculate the multi-dimensional risk entropy value based on the characteristics of the propagation path according to the target dynamic knowledge graph, and compare the multi-dimensional risk entropy value with the benchmark risk entropy value of each level in the risk classification and control mechanism to determine the risk level and the risk management strategy corresponding to the risk level.

Citation Information

Cited By

  • Construction risk assessment and early warning method and system applied to water conservancy project

    CN120851632A

  • Underground pipe gallery three-dimensional risk positioning method and device fused with multi-point sensing

    CN121236329A

  • Teaching programming system and teaching recommendation method based on large language model assistance

    CN121352045A

  • Teaching programming system and teaching recommendation method based on large language model assistance

    CN121352045B

  • Intelligent cargo supervision data analysis processing method and system based on big data

    CN121352251A