Service provider network health monitoring method, computer device and storage medium

By establishing a risk event database and constructing a risk matrix and calculating the health of work numbers, the problems of lag and one-sidedness in risk identification at telecom operators' outlets are solved, refined management and automated disposal of risks are achieved, and the possibility of risk events is reduced.

CN120672123APending Publication Date: 2025-09-19CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510765083.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing technologies make it difficult to fine-tune the risks faced by telecom operators' outlets during business operations, especially the lag in post-audits, the one-sidedness of single event verification, the avoidance of behaviors at the edge of monitoring thresholds, and insufficient risk quantification, resulting in incomplete risk identification and handling.

Method used

Establish a risk event database for operator outlets, construct a risk matrix, determine event weight coefficients, obtain event factors for target work numbers, calculate work number health, and implement systematic and automated risk monitoring and disposal through computer devices.

Benefits of technology

It has achieved refined management of risks at telecom operators' outlets, audited potential risks in advance, reduced the possibility of risk events, and improved management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120672123A_ABST
    Figure CN120672123A_ABST
Patent Text Reader

Abstract

The invention discloses an operator network health monitoring method, a computer device and a storage medium, which can obtain the health degree of a job number and quantitatively represent the potential risk of a target job number in the aspect of a plurality of possible risk events. According to the job number health degree, pre-auditing of a plurality of risk events can be carried out on the target job number, the overall situation of the risk can be comprehensively captured and evaluated, risk disposal can be carried out before a new risk event actually occurs, and the possibility of actual occurrence of the risk event and actual loss caused by actual occurrence are reduced; the health degree information accurate to the job number can be obtained, so that fine management of risks by telecom operator enterprises can be realized; the method is easy to implement through a management system which is uniformly operated by a telecom operator, so that systematic and automatic risk monitoring disposal is realized, the workload of manual checking is reduced, and the risk management efficiency of a telecom operator enterprise is improved. The method is widely applied to the technical field of operation data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of operation data processing, and in particular to an operator network health monitoring method, a computer device and a storage medium. Background Art

[0002] Telecom operators typically have multiple branches, providing services to users in different locations. Each branch typically has multiple staff members. In the course of their daily work, these staff members may intentionally or negligently engage in non-compliant behavior, resulting in damage to the interests of the staff member, the branch, the operator as a whole, or the operator's users, or even illegal consequences. Therefore, the staff members in the branch and the business operations of the branch as a whole are directly related to the operator's service quality and business operational efficiency. It is necessary to monitor and identify risks in the business operations of the branch so that timely investigations can be carried out to safeguard the legitimate interests of all parties.

[0003] However, traditional telecom operators' risk management approaches often focus on post-event audits, often examining individual incidents. This approach not only lags behind the actual occurrence of risks but also makes it difficult to fully capture and assess the overall risk landscape. The large number and widespread distribution of operator outlets complicates risk monitoring and management, increasing the likelihood that a risk outbreak could lead to actual profit damage. In short, existing technologies struggle to precisely address the risks faced by telecom operator outlets during business operations. Summary of the Invention

[0004] In view of the technical problems existing in current risk management technologies of telecom operators, such as the difficulty in finely handling risks faced during business operations, the purpose of the present invention is to provide an operator network health monitoring method, computer device and storage medium.

[0005] In one aspect, an embodiment of the present invention includes a method for monitoring the health of an operator's network, the method comprising the following steps:

[0006] Establishing a risk event database for an operator's network; the risk event database includes at least one risk event;

[0007] Determine the frequency level and damage level corresponding to each of the risk events;

[0008] Constructing a risk matrix based on each of the risk events; wherein one dimension of the risk matrix corresponds to the frequency level and another dimension corresponds to the degree of damage;

[0009] Determining a weight coefficient for each event based on the risk matrix; the event weight coefficient represents the weight of the risk event corresponding to the specific frequency level and the damage degree;

[0010] Obtaining various event factors of a target employee number in an operator's network; the event factors represent the historical behavior of the target employee number in relation to the risk event;

[0011] The job number health of the target job number is determined based on each of the event weight coefficients and each of the event factors.

[0012] Furthermore, the establishment of a risk event database for operator outlets includes:

[0013] Obtaining business data of all employee numbers of the operator's outlets;

[0014] Taking a single risk event as the scanning target, scan each of the business data;

[0015] The risk event database is established based on the risk events scanned.

[0016] Furthermore, determining the weight coefficient of each event according to the risk matrix includes:

[0017] Obtaining information entropy of each frequency level to obtain frequency information entropy;

[0018] Obtaining information entropy of each damage degree to obtain damage information entropy;

[0019] Determining a frequency weight coefficient and a damage weight coefficient according to the frequency information entropy and the damage information entropy;

[0020] For any of the risk events, the frequency level and the damage degree corresponding to the risk event are weighted and summed according to the frequency weight coefficient and the damage weight coefficient to obtain the event weight coefficient corresponding to the risk event.

[0021] Furthermore, the event factors of the target employee number in the operator's network are obtained, including:

[0022] For any of the risk events, obtain the number of violations and time distribution dispersion of the target employee number in the risk event;

[0023] Constructing a judgment matrix of the number of violations and the time distribution dispersion by using the hierarchical analysis method;

[0024] Determining, according to the judgment matrix, a first weight coefficient corresponding to the number of violations and a second weight coefficient corresponding to the time distribution dispersion;

[0025] Obtaining the maximum number of violations in history of the operator's network point, and normalizing the number of violations according to the maximum number of violations in history;

[0026] Obtaining the maximum value of the time distribution standard deviations corresponding to the same risk event for all employee numbers in the operator's outlets, obtaining the maximum standard deviation, and normalizing the time distribution dispersion according to the maximum standard deviation;

[0027] According to the first weight coefficient and the second weight coefficient, a weighted sum is performed on the normalized number of violations and the normalized time distribution dispersion to obtain the event factor corresponding to the target work number in the risk event.

[0028] Furthermore, determining the job number health of the target job number based on each of the event weight coefficients and each of the event factors includes:

[0029] According to the weight coefficients of the events, the event factors are weighted and summed to obtain the job number health of the target job number.

[0030] Furthermore, the operator network health monitoring method further includes:

[0031] Obtain the employee number health corresponding to all employee numbers of the operator's outlets;

[0032] Perform global normalization based on the health of each work number to obtain a normalized score corresponding to each work number;

[0033] Determine risk job numbers among all job numbers based on the normalized scores;

[0034] Provide graded warnings for the risky work numbers.

[0035] Furthermore, the operator network health monitoring method further includes:

[0036] Obtain the employee number health corresponding to all employee numbers of the operator's outlets;

[0037] Performing Z-Score normalization on the health of each work number to obtain multiple normalized scores;

[0038] The average value of each of the standardized scores is obtained to obtain the network health level corresponding to the operator network.

[0039] Furthermore, the operator network health monitoring method further includes:

[0040] Visually displaying the work number health and the network health;

[0041] Providing risk warning based on the health of the work number and the health of the outlet;

[0042] Generate and push warning information based on the results of risk warning;

[0043] Based on the results of the risk warning, the freezing of work numbers and the clearing of permissions process will be executed.

[0044] On the other hand, an embodiment of the present invention also includes a computer device including a memory and a processor, wherein the memory is used to store at least one program, and the processor is used to load at least one program to execute the operator network health monitoring method in the embodiment.

[0045] On the other hand, an embodiment of the present invention further includes a computer-readable storage medium storing a program executable by a processor. When the program is executed by the processor, it is used to execute the operator network health monitoring method in the embodiment.

[0046] The beneficial effects of the present invention are: the operator branch health monitoring method, computer device and computer-readable storage medium in the embodiment can obtain the work number health of any target work number of any operator branch. The work number health integrates the information of multiple risk events and the behavioral information of the target work number, and can quantitatively represent the potential risk of the target work number in multiple possible risk events; based on the work number health, the target work number can be audited in advance for multiple risk events, which is conducive to comprehensively capturing and evaluating the overall situation of risks, and is conducive to risk disposal before new risk events actually occur, reducing the possibility of actual occurrence of risk events and the actual losses caused by actual occurrence; health information accurate to the work number can be obtained, which is conducive to the realization of refined risk management of telecommunications operators; it is easy to be executed through a management system uniformly operated by telecommunications operators, thereby realizing systematic and automated risk monitoring and disposal, reducing the workload of manual verification, and improving the risk management efficiency of telecommunications operators. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 Schematic diagram of the steps of the operator network health monitoring method in the embodiment;

[0048] Figure 2 Schematic diagram of a system to which the operator network health monitoring method can be applied in an embodiment;

[0049] Figure 3 A schematic diagram of the principle of constructing a risk matrix in an embodiment;

[0050] Figure 4 This is a schematic diagram of the principle of dynamic monitoring and early warning based on health status in the embodiment;

[0051] Figure 5This is a schematic diagram of an RPA digital intelligence machine simulating manual operations to log into an operator's rights management system and automatically executing the freezing of work numbers and clearing of rights in an embodiment.

[0052] Figure 6 This is a schematic diagram of the process of performing a fuse by an RPA digital intelligence machine in an embodiment;

[0053] Figure 7 This is a schematic diagram of the CPC configuration center platform operation interface in the embodiment;

[0054] Figure 8 This is a schematic diagram of a fixed template import file during the RPA digital intelligence machine execution of a work number freeze and fuse in an embodiment;

[0055] Figure 9 This is a schematic diagram of the BSS 3.0 backend management portal operation interface during the RPA digital intelligence machine processing process in the embodiment;

[0056] Figure 10 This is a schematic diagram of a fixed template import file used by the RPA digital intelligence machine to freeze and disconnect work numbers and positions in the embodiment;

[0057] Figure 11 This is a schematic diagram of a fixed template import file used by the RPA digital intelligence machine to execute a sales product freeze and fuse process in an embodiment;

[0058] Figure 12 Schematic diagram of the structure of the operator network health monitoring system in the embodiment. DETAILED DESCRIPTION

[0059] Explanation of terms:

[0060] Risk Matrix: Also known as the Risk Matrix, it is a tool used to assess and visualize different risk events. It helps organizations or individuals identify, analyze, and prioritize risks by combining the likelihood of a risk occurring with the potential consequences if the risk occurs.

[0061] Entropy Weight Method (EWM): It is an objective weighting method based on information theory. It is used to determine the weight of each evaluation indicator in multi-index decision-making analysis. Its core idea is to use the concept of information entropy to measure the amount of information and the degree of dispersion of each evaluation indicator, so as to determine their importance in the comprehensive evaluation. The smaller the information entropy value of an indicator, the greater the variability of the indicator and the more information it provides. Therefore, its weight should also be greater.

[0062] Indicator factors: These are the specific measurement criteria or variables used to evaluate the performance of an object or solution. These factors can be quantitative or qualitative, and together they form an evaluation system to comprehensively measure the performance, status, or impact of the thing being evaluated.

[0063] Health: It is a quantitative indicator that measures the degree to which an individual or system is in a certain aspect. This concept can be applied to different fields, such as personal health, organizational management, battery performance, etc.

[0064] Current telecom operators' risk management technologies are limited by the lag of post-audits, the one-sidedness of single-event verification, the avoidance of behaviors at the edge of monitoring thresholds, and insufficient risk quantification. This makes it difficult to detect and address risk events that exist in the business operations of individual operator outlets, especially those that occur frequently but cause relatively little damage. These limitations include:

[0065] Post-audit lag: Traditional risk identification relies primarily on post-audit, which involves checking and handling risk events after they occur. This approach fails to provide early warning of potential risks, leading companies to take action only after risks have already caused losses, making it difficult to effectively prevent losses.

[0066] The one-sidedness of single-event verification: Traditional risk identification methods typically only examine individual events, ignoring the interrelationships and holistic nature of risk events. This makes it difficult for companies to fully grasp the overall risk landscape and develop effective risk response strategies.

[0067] Avoiding behaviors near monitoring thresholds: In practice, some branch employees may adopt strategies to evade detection. For example, when a certain employee approaches a monitoring threshold, they may cease further action and have someone else continue the process, thereby evading detection. This behavior not only undermines the effectiveness of the monitoring system but can also lead to the accumulation and subsequent outbreak of risks.

[0068] Insufficient risk quantification: Risk frequency and damage severity are two closely linked dimensions. However, existing technologies fail to comprehensively consider the correlation between risk frequency and damage severity, leading to, for example, mismatched priorities for handling high-incidence, low-damage incidents, significant waste of human resources, or outright neglect of such risks.

[0069] Based on the above principles, in this embodiment, a method for monitoring the health of an operator's network is provided. Figure 1 As shown, the operator network health monitoring method includes the following steps:

[0070] S1. Establish a risk event database for operator outlets;

[0071] S2. Determine the frequency level and damage level corresponding to each risk event;

[0072] S3. Construct a risk matrix based on each risk event;

[0073] S4. Determine the weight coefficients for each event based on the risk matrix; the event weight coefficients represent the weights of risk events corresponding to specific frequency levels and damage levels;

[0074] S5. Obtain the event factors of the target employee number in the operator's network; the event factors represent the historical behavior of the target employee number in risk events;

[0075] S6. Determine the job number health of the target job number based on the weight coefficient of each event and each event factor.

[0076] In this embodiment, a computer device may be used to execute each step of the operator network health monitoring method, including steps S1-S6. The computer device that executes the operator network health monitoring method may be a computer device operated by a telecommunications operator, or a computer device operated by an institution commissioned by the telecommunications operator.

[0077] In this embodiment, the operator network health monitoring method can be applied to Figure 2 In the system shown. Figure 2 Telecom operators have multiple branches, which can be self-operated business halls, authorized stores, or authorized individuals. Each branch has one or more employee numbers, each of which corresponds to a staff member, self-service kiosk, or AI-based virtual service agent. Telecom operators can use a unified management system to manage these branches and employee numbers.

[0078] In this embodiment, unless otherwise specified, the operator network point may refer to a specific network point of a telecommunications operator, and the target employee number may refer to a specific employee number of the operator network point.

[0079] In step S1, a risk event database for operator branches can be established in the telecom operator's database. This database is used to store actual risk events that have occurred at operator branches. These risk events can be business operations performed by the operator branch as a whole or by individual employees, which pose risks due to, for example, non-compliance with relevant regulations. Risk events may have already occurred, resulting in actual losses, or they may not have caused actual losses but have become potential risks.

[0080] The risk event library established in step S1 can be dynamically updated. For example, whenever a new risk event is detected, the new risk event is stored in the risk event library. If the relevant business operation specifications are modified, resulting in a change in the risk event judgment criteria, so that the previous risk event is no longer a risk event, then such previous risk event can be deleted from the risk event library.

[0081] In this embodiment, a risk event library may be established for each operator's network point, and an example in which a plurality of risk events are stored in the risk event library is used for description.

[0082] In step S2, for each risk event in the risk event database, its frequency level can be determined based on the number of times the risk event has occurred over a certain period of time. The damage level of the risk event can be determined based on the actual losses caused by the risk event (if the risk event has already occurred and caused actual losses) or the losses that would be caused by a hypothetical risk event as assessed by the model. That is, for a specific risk event, its corresponding frequency level and damage level are both fixed values, where the frequency level represents the likelihood of the risk event occurring, and the damage level represents the amount of damage that would be caused if the risk event occurred.

[0083] When there are multiple risk events in the risk event database, the frequency levels of each risk event are generally not exactly the same, but rather are distributed as different values ​​along the frequency level axis. Similarly, the damage levels of each risk event are generally not exactly the same, but rather are distributed as different values ​​along the damage level axis. Therefore, step S3 can be performed to construct a risk matrix using the frequency level of each distributed value of each risk event as one dimension and the damage level of each distributed value of each risk event as another dimension.

[0084] The risk matrix constructed in step S3 includes multiple elements (also called cells), each of which corresponds to a specific frequency level value and damage degree value, that is, corresponds to one or more specific risk events with such frequency level and damage degree values.

[0085] In step S4, a corresponding event weight coefficient can be determined for each element in the risk matrix. Since each element in the risk matrix corresponds to a risk event with a specific frequency level and damage level, determining the event weight coefficient in step S4 allows each risk event in the risk event library obtained in step S1 to be assigned a corresponding weight based on its corresponding frequency level and damage level.

[0086] For example, by executing step S4, risk event 1 may be assigned an event weight coefficient of 1, risk event 2 may be assigned an event weight coefficient of 2, risk event 3 may be assigned an event weight coefficient of 3, and so on.

[0087] In step S5, a specific employee ID within the operator's network that requires investigation can be identified as the target employee ID. For this target employee ID, its historical behavior with respect to each risk event can be examined to obtain the event factor corresponding to each risk event. The event factor represents the target employee ID's historical behavior with respect to the corresponding risk event. Specifically, it can indicate information such as whether the target employee ID has experienced the corresponding risk event and the time distribution of the corresponding risk event.

[0088] For example, by executing step S5, it is possible to determine event factor 1 corresponding to risk event 1, event factor 2 corresponding to risk event 2, event factor 3 corresponding to risk event 3, and so on for the target employee number.

[0089] By executing steps S1-S5, for the target work number, each risk event has a corresponding event weight coefficient and event factor. For example, risk event 1 corresponds to event weight coefficient 1 and event factor 1, risk event 2 corresponds to event weight coefficient 2 and event factor 2, risk event 3 corresponds to event weight coefficient 3 and event factor 3... That is, by executing steps S1-S5, information such as the possibility of occurrence of each risk event and the possible size of damage can be obtained, as well as information such as the possibility of each risk event occurring in the target work number. Therefore, step S6 can be executed to calculate the work number health of the target work number based on the event weight coefficients and event factors corresponding to the target work number.

[0090] Specifically, the event weight coefficient can be used as the weight of the event factors corresponding to the same risk event. The weighted sum of these event factors is then used as the target employee's employee health score. This score integrates information about the target employee's behavior and the potential harm of risk events caused by their behavior. It comprehensively assesses the target employee's risk against multiple objectively existing risk events.

[0091] By executing steps S1-S6, the work number health of any target work number in any operator's outlet can be obtained. The work number health integrates the information of multiple risk events and the behavioral information of the target work number, and can quantitatively represent the potential risks of the target work number in multiple possible risk events; based on the work number health obtained by executing steps S1-S6, the target work number can be audited in advance for multiple risk events, which is conducive to comprehensively capturing and evaluating the overall risk situation, and is conducive to risk disposal before new risk events actually occur, reducing the possibility of actual occurrence of risk events and the actual losses caused by actual occurrence; steps S1-S6 can obtain health information accurate to the work number, which is conducive to the realization of refined risk management of telecom operators; steps S1-S6 are easy to execute through the management system uniformly operated by telecom operators, thereby realizing systematic and automated risk monitoring and disposal, reducing the workload of manual verification, and improving the risk management efficiency of telecom operators.

[0092] The following provides a more specific embodiment of the operator network health monitoring method.

[0093] In this embodiment, when executing step S1, that is, the step of establishing a risk event database of an operator's network, the following steps may be specifically performed:

[0094] S101. Obtain business data of all employee numbers at the operator's outlets;

[0095] S102. Scan each business data using a single risk event as the scanning target;

[0096] S103. Establish a risk event database based on the scanned risk events.

[0097] The principles of steps S101-S103 are as follows: Figure 3 shown.

[0098] Reference Figure 3 During step S101, the telecom operator's business system can retrieve the business data for all employee numbers at the operator's outlets over the past period of time. The "full employee numbers" refers to all employee numbers at the operator's outlets, and the business data refers to the data generated by employees during business operations, including employee operation logs, business acceptance records, communication records with users, user reviews, and other data. The time period for the retrieved business data can be determined based on the specific circumstances of the telecom operator, for example, six months.

[0099] Reference Figure 3During step S102, the business data may be judged for risk events in accordance with relevant laws, regulations, or corporate rules. Specifically, risk events include a surge in daily query volume, high-frequency queries, queries during non-working hours, employee ID lending, trading of customer information, unusual outbound calls, replacement of old with new, non-compliant real-name registration, and illegal lifting of restrictions.

[0100] When executing step S102, a single risk event is used as the scanning target, that is, every single risk event in all business data needs to be scanned. For example, if the risk event "daily query volume surge" is scanned in one business data, and the risk event "daily query volume surge" is also scanned in another business data, then it can be identified as two risk events, or the cumulative occurrence of the risk event "daily query volume surge" is 2 times.

[0101] When executing step S102, in addition to scanning the information on whether a single risk event occurs, the specific information of the single risk event, such as its type and the actual loss caused, such as the amount of damage, may also be scanned.

[0102] Reference Figure 3 , execute step S103 to store all the risk events scanned, thereby establishing a risk event library.

[0103] In this embodiment, the content of the risk event library established by executing steps S101 to S103 is shown in Table 1.

[0104] Table 1 Risk event database

[0105]

[0106]

[0107] In step S2, the frequency level and damage degree corresponding to each risk event in the risk event library can be determined according to the content of the risk event library shown in Table 1.

[0108] For example, we can set the scoring rules shown in Table 2 to classify risk events such as daily query volume surges, high-frequency queries, and non-working hours queries into frequency levels such as L1 and L2, based on the range of average damage amounts. L1 represents the lowest frequency level, and L5 represents the highest.

[0109] Table 2 Scoring rules for frequency levels

[0110] Occurrence range Frequency level ≤10 L1 11-50 L2 51-100 L3 101-200 L4 >200 L5

[0111] For example, the scoring rules shown in Table 3 can be set to categorize risk events such as daily query volume surges, high-frequency queries, and non-working hours queries into damage levels of S1, S2, and so on, based on the range of occurrences. S1 represents the lowest damage level, and S5 represents the highest damage level.

[0112] Table 3 Scoring rules for damage degree

[0113] Average damage amount (10,000 yuan) Extent of damage ≤1 S1 2-5 S2 5-20 S3 21-50 S4 >50 S5

[0114] In step S2, by executing the scoring rules shown in Table 2 and Table 3, the frequency level and damage degree corresponding to each risk event can be obtained, as shown in Table 4.

[0115] Table 4 Frequency levels and damage levels corresponding to risk events

[0116]

[0117]

[0118] Referring to Table 4, each type of risk event has a certain frequency level and damage level. For example, the frequency level of a risk event such as a surge in daily query volume is L4, and the damage level is S1.

[0119] Next, step S3 may be executed to construct a risk matrix based on the risk events shown in Table 4 and their corresponding frequency levels and damage degrees.

[0120] Referring to Table 4, when there are multiple risk events in the risk event database, the frequency levels of these risk events are distributed within the range of L1-L5, and the damage levels of these risk events are distributed within the range of S1-S5. Therefore, we can construct the risk matrix shown in Table 5(a) with the frequency level as one dimension (horizontal axis) and the damage score as the other dimension (vertical axis).

[0121] Table 5(a) Risk matrix without event weight coefficients

[0122] Damage Score\Frequency Level L1=1 L2=2 L3=3 L4=4 L5=5 S1=1 S2=2 S3=3 S4=4 S5=5

[0123] Referring to Table 5(a), the horizontal axis (columns) of the risk matrix can take values ​​such as L1, L2, L3, L4, and L5, and the vertical axis (rows) can take values ​​such as S1, S2, S3, S4, and S5. Each specific pair of damage score and frequency level identifies a specific element (cell) in the risk matrix. In Table 5(a), the elements of the newly constructed risk matrix are not assigned event weight coefficients.

[0124] For the risk matrix shown in Table 5(a) that does not have event weight coefficients assigned to it, event weight coefficients can be assigned through the product method. Specifically, according to the formula

[0125] W ij =L i ·S j

[0126] Calculate the event weight coefficient of each element in the risk matrix, where W ij Indicates the event weight coefficient corresponding to the element in column i and column i in the risk matrix, L i Indicates the frequency level value corresponding to this element, S j The risk matrix that assigns event weight coefficients by the product method is shown in Table 5(b).

[0127] Table 5(b) Risk matrix of event weight coefficients assigned by product method

[0128]

[0129]

[0130] For the risk matrix shown in Table 5(a) that does not assign event weight coefficients, event weight coefficients can be assigned through the method of customizing fixed weight coefficients based on expert experience. Specifically, according to the formula

[0131] W ij =α·L i +β·S j

[0132] Calculate the event weight coefficient of each element in the risk matrix, where W ij Indicates the event weight coefficient corresponding to the element in column i and column i in the risk matrix, L i Indicates the frequency level value corresponding to this element, S j Indicates the damage score corresponding to this element. Both α and β are fixed values. For example, if α=β=0.5, the formula used becomes

[0133] W ij =0.5·L i +0.5·S j

[0134] The risk matrix of event weight coefficients assigned by the method of customizing fixed weight coefficients based on expert experience is shown in Table 5(c).

[0135] Table 5(c) Risk matrix of event weight coefficients assigned by expert experience customized fixed weight coefficient method

[0136] Damage Score\Frequency Level L1=1 L2=2 L3=3 L4=4 L5=5 S1=1 1 1.5 2 2.5 3 S2=2 1.5 2 2.5 3 3.5 S3=3 2 2.5 3 3.5 4 S4=4 2.5 3 3.5 4 4.5 S5=5 3 3.5 4 4.5 5

[0137] While both the product method and the expert experience-based fixed weight coefficient method can assign event weight coefficients to the risk matrix, both methods rely heavily on subjective factors and are difficult to dynamically adapt to changes in risk patterns. In this embodiment, the entropy weight method can be used to determine the event weight coefficients corresponding to each element in the risk matrix based on the data shown in Table 4.

[0138] Specifically, the formula used in the entropy weight method is also

[0139] W ij =α·L i +β·S j

[0140] However, α and β are not fixed values, but dynamic adjustment coefficients to be determined. Based on the frequency level and damage degree corresponding to the risk events shown in Table 4, when executing step S4, that is, determining the weight coefficient of each event according to the risk matrix, the following steps can be performed:

[0141] S401. Obtain information entropy of each frequency level as frequency information entropy;

[0142] S402. Obtain information entropy of each damage degree as damage information entropy;

[0143] S403. Determine the frequency weight coefficient and the damage weight coefficient according to the frequency information entropy and the damage information entropy;

[0144] S404. For any risk event, the frequency level and damage degree corresponding to the risk event are weighted and summed according to the frequency weight coefficient and the damage weight coefficient to obtain the event weight coefficient corresponding to the risk event.

[0145] The principles of steps S401-S404 are as follows: Figure 3 shown.

[0146] Before executing steps S401-S404, each frequency level and each damage degree in Table 4 may be normalized. For example, for each frequency level in Table 4 ( Indicates the frequency level of the nth row in Table 4, for example, when n=1 ), through the formula

[0147]

[0148] Normalize, where means summing up all the frequency levels of each row in Table 4, yes The normalized result of is the normalized result of the frequency level in the nth row in Table 4.

[0149] Similarly, for each frequency level in Table 4 ( Indicates the damage level of row n in Table 4, for example, when n=1 ), through the formula

[0150]

[0151] Normalize, where It means to sum up all the damage levels of each row in Table 4. yes The normalized result of is also the normalized result of the damage degree in the nth row in Table 4.

[0152] In step S401, the information entropy of each frequency level after normalization in Table 4 is calculated using the following formula:

[0153]

[0154] Where N is the total number of rows in Table 4, E L It is the information entropy of each frequency level, that is, the frequency information entropy.

[0155] Similarly, in step S402, the information entropy of each damage degree after normalization in Table 4 is calculated using the following formula:

[0156]

[0157] E S It is the information entropy of each damage degree, that is, the damage information entropy.

[0158] In step S403, the frequency information entropy E calculated in step S402 is used. L and damage information entropy E S , determine the frequency weight coefficient (i.e. α in the entropy weight method formula) and the damage weight coefficient (i.e. β in the entropy weight method formula).

[0159] Specifically, according to the formula

[0160]

[0161] To calculate the frequency weight coefficient α and the damage weight coefficient β. Let E be E L and E S , we can get

[0162]

[0163] In this embodiment, according to the data shown in Table 4, the above formula of the entropy weight method can be used to calculate α=0.44 and β=0.56, so the formula used in the entropy weight method is specifically

[0164] W ij =0.44·L i +0.56·S j

[0165] Since the specific data such as the frequency level and damage degree in Table 4 can be updated by time period (for example, monthly) through the sliding window method, the frequency weight coefficient α and damage weight coefficient β calculated by the entropy weight method selected in steps S401-S403 can also be updated by time period, thereby achieving automatic optimization based on recent risk data.

[0166] In this embodiment, the frequency weight coefficient α and the damage weight coefficient β can also be adjusted in real time based on expert experience and business objectives to balance long-term risk accumulation (high frequency, low loss) and short-term significant losses (low frequency, high loss). For example, if the proportion of high-frequency, low-loss events has increased recently, the telecom operator's risk control department may recommend increasing α from 0.44 to 0.5; if significant loss events have occurred frequently recently, the telecom operator's operations department may recommend increasing β from 0.56 to 0.65.

[0167] By combining expert experience and business objectives to adjust the frequency weight coefficient α and the damage weight coefficient β in real time, we can not only focus on high-risk events, but also on low-damage but high-incidence risk events, thereby expanding the coverage of various types of risk events and ensuring the comprehensiveness of risk event monitoring and disposal.

[0168] After executing steps S401-S403 to determine the specific values ​​of the frequency weight coefficient α and the damage weight coefficient β (for example, α = 0.44, β = 0.56), execute step S404. For any risk event, its corresponding frequency level can be determined according to Table 4 as L i , the corresponding damage level is S j , according to the formula

[0169] W ij =0.44·L i +0.56·S j

[0170] For frequency level L i and damage level S j Perform weighted summation to obtain the event weight coefficient W corresponding to this risk event ij .

[0171] For example, for the risk event “high frequency query” in Table 4, its corresponding frequency level and damage degree can be determined to be L3=3 and S1=1 respectively. Therefore, according to the formula

[0172] W 31 =0.44·L3+0.56·S1=0.44·3+0.56·1=1.88

[0173] The calculated event weight coefficient of the risk event "high frequency query" is W 31 =1.88.

[0174] For example, for the risk event "abnormal outbound call" in Table 4, its corresponding frequency level and damage degree can be determined to be L2=2 and S3=3 respectively. Therefore, according to the formula

[0175] W 23 =0.44·L2+0.56·S3=0.44·2+0.56·3=2.56

[0176] The calculated event weight coefficient of the risk event "abnormal outbound call" is W 23 =2.56.

[0177] For example, for the risk event "buying and selling customer information" in Table 4, its corresponding frequency level and damage degree can be determined to be L1=1 and S4=4 respectively. Therefore, according to the formula

[0178] W 14 =0.44·L1+0.56·S4=0.44·1+0.56·4=2.68

[0179] The calculated event weight coefficient of the risk event "buying and selling customer information" is W 14 =2.68.

[0180] Execute the event weight coefficient W obtained in step S404 ij The event weight coefficient corresponding to the element in the i-th column in the risk matrix to be obtained in step S4.

[0181] In this embodiment, when executing step S5, that is, the step of obtaining the event factors of the target employee number in the operator's network, the following steps may be specifically performed:

[0182] S501. For any risk event, obtain the number of violations and time distribution dispersion of the target employee number in the risk event;

[0183] S502. Construct a judgment matrix of the number of violations and the time distribution dispersion through the analytic hierarchy process;

[0184] S503. Determine, based on the judgment matrix, a first weight coefficient corresponding to the number of violations and a second weight coefficient corresponding to the time distribution dispersion;

[0185] S504. Get the operator's network point's historical maximum number of violations, and normalize the number of violations based on the historical maximum number of violations;

[0186] S505. Obtain the maximum value of the standard deviation of the time distribution of all employee numbers of the operator's outlets corresponding to the same risk event, obtain the maximum standard deviation, and normalize the time distribution dispersion according to the maximum standard deviation;

[0187] S506. Perform a weighted summation of the normalized number of violations and the normalized time distribution dispersion based on the first weight coefficient and the second weight coefficient to obtain the event factor corresponding to the target employee number in the risk event.

[0188] In step S501, taking risk event m as an example, the number of violations of the target employee number in risk event m is obtained. and time distribution dispersion Among them, the number of violations Indicates the total number of risk events m that occurred in the target employee number in the past period of time, and the time distribution dispersion It can be calculated based on the time distribution array of risk event m occurring in the target employee number within the past period of time (indicating the number of times risk event m occurs at each specific moment).

[0189] The number of violations obtained in step S501 and time distribution dispersion They can be collectively referred to as the indicator factors of the target employee number in the risk event m.

[0190] In step S502, the number of violations can be constructed by AHP. and time distribution dispersion Specifically, the number of violations can be determined according to the 1-9 scaling method shown in Table 6. and time distribution dispersion the relative importance of .

[0191] Table 6 1-9 scaling method

[0192] scale meaning 1 Indicators A and B are equally important 3 Indicator A is slightly more important than B 5 Indicator A is significantly more important than indicator B 7 Indicator A is more important than B 9 Indicator A is extremely more important than B 2,4,6,8 midpoint between adjacent scales

[0193] In this embodiment, the number of violations is set Time distribution dispersion Slightly important, which corresponds to scale 3 in Table 6, thus constructing the judgment matrix shown in Table 7.

[0194] Table 7 Number of violations and time distribution dispersion Judgment matrix

[0195] index Number of violations Time distribution dispersion Number of violations 1 3 Time distribution dispersion 1 / 3 1

[0196] In step S503, the weight is calculated after normalization according to the column where the number of violations in the judgment matrix shown in Table 7, so as to obtain the number of violations The corresponding first weight coefficient γ is normalized according to the column where the time distribution dispersion in the judgment matrix shown in Table 7 and then the weight is calculated to obtain the time distribution dispersion The corresponding second weight coefficient δ. In this embodiment, the first weight coefficient γ and the second weight coefficient δ can be collectively referred to as the impact factor of the target employee number on the risk event m, γ = 0.75, δ = 0.25.

[0197] In this embodiment, after executing step S503, step S506 can be directly executed to calculate the number of violations according to the first weight coefficient γ and the second weight coefficient δ. Time distribution dispersion Perform weighted summation to obtain the event factor corresponding to the risk event m Right now

[0198]

[0199] In this embodiment, before executing step S506, steps S504-S505 can be executed to respectively count the number of violations. Time distribution dispersion Perform normalization.

[0200] In step S504, taking the risk event m as "high frequency query" as an example, by executing step S501, the occurrence of the target employee number in the risk event m, i.e., high frequency query, is obtained as shown in Table 8.

[0201] Table 8 Occurrence of target employee number in risk event m, i.e. high-frequency query

[0202]

[0203]

[0204] According to Table 8, the number of violations of the target employee number in risk event m, i.e., high-frequency query, is 3+5+2+4+1+4=19. By executing step S504, the historical maximum number of violations of the operator's outlets (the maximum number of violations of all employee numbers in risk event m in the same time period) is 50 times. Then, the number of violations is normalized according to the historical maximum number of violations, that is, according to the formula

[0205]

[0206] Calculate the normalized number of violations Right now

[0207] In step S505, according to Table 8, the time distribution array of the target employee number in risk event m, i.e., high-frequency query, is [3, 5, 2, 4, 1, 4]. The corresponding standard deviation can be calculated as In step S505, based on the same method, the time distribution arrays of other employee numbers of the operator's outlets in risk event m, i.e., high-frequency queries, are obtained respectively. The time distribution standard deviations corresponding to these time distribution arrays are calculated respectively, and the maximum value is taken to obtain the maximum standard deviation. Assuming that the maximum standard deviation is 5, the standard deviation of the target employee number in risk event m can be divided by the maximum standard deviation to obtain the normalized time distribution dispersion. Right now

[0208]

[0209] Normalized distribution dispersion The meaning is:

[0210] Low dispersion ( Close to 0): The target employee's illegal behaviors, i.e., risk events m, are concentrated in a few time periods (e.g., surprise operations), possibly indicating an attempt to evade monitoring.

[0211] High Discreteness ( Close to 1): The target employee's violation behavior, i.e., the risk event m, is dispersed, which may be an isolated event or a long-term test threshold.

[0212] In this embodiment, steps S504-S505 are executed to count the number of violations. and distribution dispersion Normalization not only maps them to the [0,1] interval for easy calculation, but also effectively identifies easily overlooked violations of the target work number based on the size of the normalized value, such as sudden violations, long-term violations, and other marginal behaviors.

[0213] For example, if the normalization is not performed in steps S504-S505, if the target employee performs borderline behaviors such as sudden illegal operations or long-term illegal behavior trials, it may be difficult to determine the distribution dispersion. In the case of performing normalization in steps S504-S505, it is easy to identify these edge behaviors based on the relative size of the distribution. The close relationship with 0 or 1 can be used to determine the possible existence of these edge behaviors.

[0214] After executing steps S504-S505, the normalized number of violations is obtained. and the normalized time distribution dispersion Then, execute step S506, according to the formula

[0215]

[0216] Calculate the event factor corresponding to the target employee number on the risk event m In this embodiment, since γ=0.75 and δ=0.25 are determined when executing step S503, the specific formula is:

[0217]

[0218] According to this formula, the event factor corresponding to the target employee number in the risk event "high frequency query" can be calculated as:

[0219] F 高频查询 =0.75×0.38+0.25×0.294=0.3585

[0220] The event factor corresponding to the target employee number in the risk event "abnormal outbound call" is

[0221] F 异常外呼 =0.75×0.56+0.25×0.420=0.525

[0222] After executing steps S501-S506, step S6 can be executed to determine the target employee health according to the event weight coefficient and each event factor. When executing step S6, the event factors can be weighted and summed according to the event weight coefficient to obtain the target employee health. Specifically, according to the formula

[0223]

[0224] Calculate the target job number's job number health H 目标工号 .in, is the event factor of all risk events involved in the target job number, and Multiplied W ij Represents the event weight coefficient corresponding to risk event m.

[0225] For example, if the target employee number only involves the risk event "high frequency query" (the corresponding event weight coefficient is 1.88, the corresponding event factor is 0.3585) and "abnormal outbound call" (the corresponding event weight coefficient is 2.56, the corresponding event factor is 0.525) and does not involve other risk events, then the target job number's job number health is

[0226] H 目标工号 =1.88×0.3585+2.56×0.525=2.018

[0227] In this embodiment, in addition to executing steps S1 to S5, the following steps may also be executed:

[0228] S7. Obtain the employee health status of all employee numbers at the operator's outlets;

[0229] S8. Perform global normalization based on the health of each work number to obtain a normalized score corresponding to each work number;

[0230] S9. Determine risky job numbers from the full set of job numbers based on the normalized scores;

[0231] S10. Issue graded warnings for risky work numbers.

[0232] In the embodiment of steps S1-S5, the calculation of the job health H of a specific target job is described. 目标工号 Since the target employee number is selected arbitrarily, the employee number health H corresponding to any employee number in the operator's network can be calculated based on the same principle in step S7. 工号 .

[0233] In step S8, first obtain the minimum value H according to the health of the work numbers corresponding to all the work numbers min and the maximum value H max For any of the full number of employee numbers in the operator's network, the corresponding employee number health H 工号 , according to the formula

[0234] H 归一化 =(H max -H min ) / (H 工号 -H min )

[0235] Calculate its normalized score H 归一化 .

[0236] In step S9, the normalized score H of each job number is traversed. 归一化 , determine the risky job numbers among all the job numbers. The higher the normalized score, the greater the risk of the job number. Specifically, you can set the following hierarchical warning rules:

[0237] Red Light (H 归一化 ≥0.8): Immediately freeze the employee number and revoke the position and acceptance authority;

[0238] Yellow light (0.5≤H 归一化<0.8): Send a warning SMS to the administrator;

[0239] Green light (H 归一化 <0.5): Normal monitoring, with reports generated at regular intervals (e.g., weekly).

[0240] In step S10, according to the hierarchical warning rules set in step S9, each work number is judged as a risky work number (for example, a red light or a yellow light) or a non-risky work number (for example, a green light), and a corresponding warning is issued for the risky work number.

[0241] In this embodiment, on the basis of executing steps S1-S5 or S1-S10, the following steps may also be executed:

[0242] S11. Perform Z-Score normalization on the health of each work number to obtain multiple normalized scores;

[0243] S12. Obtain the average value of each standardized score to obtain the network health level corresponding to the operator's network.

[0244] In step S11, the health of all work numbers obtained in step S7 can be called. For a specific work number, the health of the work number H 工号 , can be obtained by formula

[0245] Z 工号 =(H 工号 -μ) / σ

[0246] Perform Z-Score standardization to obtain the standardized score Z corresponding to this specific work number 工号 , where μ is the mean of the health of all job numbers, and σ is the standard deviation of the health of all job numbers.

[0247] By performing Z-Score standardization, the scale differences in the health of different work numbers can be eliminated.

[0248] In step S12, the standardized scores of each job number are traversed Calculate their average

[0249]

[0250] As the network health degree of the operator's network, H 网点 Among them, the health of the outlets H 网点 The larger it is, the lower the overall risk of the operator's outlets.

[0251] By executing steps S11-S12, the work number health of each work number in the operator's network can be normalized and aggregated to generate the network health, which represents the overall health of the operator's network.

[0252] In this embodiment, on the basis of executing steps S1-S5, S1-S10, or S1-S12, the following steps may also be executed:

[0253] S13. Visualize the health of work numbers and outlets;

[0254] S14. Issue risk warnings based on the health of work numbers and outlets;

[0255] S15. Generate and push warning information based on the risk warning results;

[0256] S16. Based on the results of the risk warning, execute the freezing work number and clearing authority process.

[0257] The process of steps S13-S16 is as follows: Figure 4 In this embodiment, a dynamic monitoring platform and a real-time early warning device can be deployed to execute steps S13-S16 to perform dynamic monitoring and early warning.

[0258] In step S13, a visual dashboard can be used to develop a real-time monitoring interface: use Echarts or Tableau to build a dynamic dashboard to display the following visual information:

[0259] (1) Worker ID health (worker ID level): health trend chart, list of top 10 high-risk work IDs;

[0260] (2) Network health (network level): For multiple operator networks, execute steps S1-S12 to obtain the network health of each operator network. Based on the network health of each network and the location of the operator network, generate a geographical distribution heat map and health ranking changes.

[0261] In step S14, the following hierarchical warning rules may be set:

[0262] Red light (high risk): H 网点 ≥0.8;

[0263] Yellow light (medium risk): 0.5 ≤ H 网点 <0.8;

[0264] Green light (low risk): H 网点 <0.5.

[0265] Thus the health of the outlets H 网点 Perform risk warning, and call the risk warning result of the work number in step S9 to generate a comprehensive health report of the operator's network.

[0266] In step S15, refer to Figure 4, according to the result of the risk warning in step S14, generate and push warning information. Specifically, run the real-time warning device (integrated with SMS interface), when the risk work number or the health degree of the branch H 网点 When the yellow light threshold is reached or above, the operator's own SMS API interface is called and a request is sent through the HTTPS protocol; an SMS template is designed, including content fields: work ID, branch code, risk level, violation event type, recommended measures, and jump link (risk control platform details page).

[0267] For example, when the risky work number reaches the yellow light threshold or above, the real-time warning device can be run to push the following warning information:

[0268] [Branch ID Health Risk Control Alert] Employee ID A1001's health level is 0.82 (red), assigned to branch xxxx. It is suspected of overclocking (15 times) and abnormal outbound calls (18 times). Action: User ID permissions will be frozen. Please monitor closely. Details: http: / / xxx.xxx.

[0269] In step S16, refer to Figure 4 According to the result of the risk warning in step S14, the freezing work number and clearing authority process are executed.

[0270] Specifically, when executing step S16, you can run RPA digital machine processing (automated authority management): when the work number and branch health reaches the red light level, call the database process, and synchronously generate a high-risk work number authority information table (including work number ID, position, acceptance authority, disposal instructions, etc.), and then create an RPA robot through UiPath or Automation Anywhere, and pass in the work number ID, authority and disposal instructions, such as Figure 5 As shown, the system simulates manual operation to log in to the operator's authority management system (BSS background system, CPC configuration system), automatically executes the process of freezing work numbers and clearing permissions, generates records and synchronizes them to the risk control platform.

[0271] Among them, the process of RPA digital intelligent machine executing circuit breaking is as follows Figure 6 shown.

[0272] (1)Reference Figure 6 and Figure 7 The specific process of the machine executing the freezing and breaking of the work number includes:

[0273] The RPA digital intelligence machine captures the target data of red-light-level branch employee numbers from the risk control platform, then logs in to the backend CPC configuration portal center platform, and performs "batch modification" through the "System Management -> Organization Employees -> System User Management" path. After uploading the target data table, the system automatically fuses the high-risk employee numbers.

[0274] (2)Reference Figure 6 、 Figure 8 and Figure 9 The specific process of the machine executing the freezing and breaking of the work number position includes:

[0275] The RPA digital intelligence machine captures the target data of the red-light-level branch employee numbers from the risk control platform, logs in to the BSS 3.0 backend management portal, and uses the "Public Management -> Organization, Employee Number and Authority Management -> Employee Number Management" path to "batch import positions" and import files according to fixed templates. Upon submission, the corresponding position will be retrieved and the employee number will be linked.

[0276] (3)Reference Figure 6 、 Figure 10 and Figure 11 The specific process of the machine executing the freezing and breaking of the work number sales product includes:

[0277] The RPA digital intelligence machine captures the target data of the red-light-level outlets' employee numbers from the risk control platform, logs in to the BSS 3.0 backend management portal, and goes through "Public Management -> Organization, Employee Number and Authority Management -> Package Batch Authorization"; after "Loading the Target EXCEL" and importing the file according to the fixed template, click "Start Batch Update" and submit to reclaim the corresponding sales product acceptance authority under the employee number.

[0278] By executing steps S13-S16, it is possible to access the SMS warning interface and automated handling process, set up a real-time monitoring dashboard and API interface for business system calls, and thus embed the health score into the risk control platform.

[0279] In summary, the operator network health monitoring method in this embodiment can achieve the following technical effects:

[0280] (1) Pre-emptive risk warning: By dynamically monitoring the health of work numbers, potential risks can be identified in advance to avoid the lag of post-audit.

[0281] (2) Comprehensive coverage of risk types: not only focusing on high-risk events, but also monitoring low-damage but high-incidence risks to ensure comprehensive risk identification.

[0282] (3) Prevent evasive behavior: Through real-time monitoring and dynamic analysis, identify and prevent evasive behavior of branch work numbers at the edge of the monitoring threshold to ensure the integrity of risk monitoring.

[0283] (4) Improve management efficiency: Through systematic and automated monitoring and disposal methods, reduce the workload of manual verification and improve risk management efficiency.

[0284] A computer program that executes the operator network health monitoring method in this embodiment can be written and written into a computer device or storage medium. When the computer program is read out and run, the operator network health monitoring method in this embodiment is executed, thereby achieving the same technical effect as the operator network health monitoring method in the embodiment.

[0285] In this embodiment, you can run Figure 12 The operator network health monitoring system shown executes the operator network health monitoring method. Figure 12 , the operator's network health monitoring system includes:

[0286] (1) Data collection module: collects the operation data and violation records of the branch employee number in real time, specifically executing step S1;

[0287] (2) Risk Assessment Module: Based on the risk matrix and scoring system, the violation event is assessed, specifically by executing steps S2-S3;

[0288] (3) Health calculation module: Calculate the health of the work number through entropy weight method, index factor algorithm and weighted average calculation, specifically executing steps S4-S6;

[0289] (4) Normalization processing module: normalizes the health of all work numbers under the outlet and outputs the normalized results. Specifically, steps S11-S12 can be executed;

[0290] (5) Dynamic monitoring and early warning module: real-time monitoring of the health of outlets and work numbers, issuing early warnings for high-risk work numbers and outlets, specifically executing steps S13-S15;

[0291] (6) Intervention and disposal module: Automatically recover and clean up the permissions of entities that trigger high risks, specifically by executing step S16.

[0292] The operator network health monitoring system and the operator network health monitoring method have the same technical effects, including:

[0293] 1. By setting up a dynamic risk matrix and entropy weight adjustment mechanism in the risk assessment module, the risk weight coefficient can be automatically optimized according to real-time violation data, thereby dynamically adapting to the evolution of risk patterns to improve the accuracy and timeliness of risk assessment, and effectively respond to complex and changeable work number violations.

[0294] 2. Introducing the indicator factor algorithm and frequency dispersion analysis into the health calculation module can capture low-frequency but periodic threshold violation behaviors (such as edge operations), play a role in identifying potential risk avoidance, thereby providing early warning of hidden risks and preventing the escalation of risks from quantitative change to qualitative change.

[0295] 3. A hierarchical alarm trigger mechanism is set up in the dynamic monitoring and early warning module, which can send yellow and red light warnings in real time based on the deviation of the work number health from the baseline, and conduct in-process risk intervention, thereby shortening the risk response time and avoiding business losses caused by the expansion of violations.

[0296] 4. By standardizing and aggregating the health of employee numbers within outlets through the normalization processing module, data deviations between outlets of different sizes can be eliminated, thereby unifying assessment standards and accurately locating high-risk outlets, thereby assisting managers in formulating differentiated risk control strategies.

[0297] 5. Integrating the RPA digital machine automated permission recovery function into the intervention and disposal module can automatically freeze the permissions of high-risk work numbers when a red light warning is issued, thereby replacing manual operations, achieving the effect of quickly blocking the spread of risks, and realizing closed-loop management and efficiency improvement of risk disposal.

[0298] 6. Through the collaborative design of dynamic modeling, edge behavior analysis, real-time graded warnings, and automated disposal, we have solved the problems of static risk weights, difficulty in identifying hidden violations, and delayed manual responses in traditional methods, and achieved an intelligent transformation of operator work number risk management from passive response to active prevention and control.

[0299] It should be noted that, unless otherwise specified, when a feature is referred to as being "fixed" or "connected" to another feature, it may be directly fixed or connected to the other feature, or it may be indirectly fixed or connected to the other feature. In addition, the descriptions of up, down, left, right, etc. used in this disclosure are only relative to the relative positional relationship of the components of the present disclosure in the accompanying drawings. The singular forms of "a" and "the" used in this disclosure are also intended to include the plural forms, unless the context clearly indicates otherwise. In addition, unless otherwise defined, all technical and scientific terms used in this embodiment have the same meaning as those generally understood by those skilled in the art. The terms used in the specification of this embodiment are only for describing specific embodiments and are not intended to limit the present invention. The term "and / or" used in this embodiment includes any combination of one or more related listed items.

[0300] It should be understood that, although the present disclosure may adopt the term first, second, third etc. to describe various elements, these elements should not be limited to these terms.These terms are only used to distinguish the elements of the same type from each other.For example, without departing from the scope of the present disclosure, the first element may also be referred to as the second element, and similarly, the second element may also be referred to as the first element.The use of any and all examples or exemplary language ("for example", "such as" etc.) provided by the present embodiment is only intended to better illustrate embodiments of the present invention, and unless otherwise required, the scope of the present invention will not be limited.

[0301] It should be appreciated that embodiments of the present invention can be implemented or practiced by computer hardware, a combination of hardware and software, or by computer instructions stored in a non-transitory computer-readable memory. The methods can be implemented in a computer program using standard programming techniques - including a non-transitory computer-readable storage medium configured with a computer program, wherein the storage medium so configured causes the computer to operate in a specific and predefined manner - according to the methods and figures described in the specific embodiments. Each program can be implemented in a high-level procedural or object-oriented programming language to communicate with the computer system. However, if desired, the program can be implemented in assembly or machine language. In any case, the language can be a compiled or interpreted language. In addition, the program can be run on a programmed application-specific integrated circuit for this purpose.

[0302] In addition, the operations of the process described in this embodiment may be performed in any suitable order, unless otherwise indicated in this embodiment or otherwise clearly contradicted by the context. The process described in this embodiment (or variations and / or combinations thereof) may be performed under the control of one or more computer systems configured with executable instructions, and may be implemented as a code (e.g., executable instructions, one or more computer programs, or one or more applications) executed on one or more processors, by hardware or a combination thereof. A computer program includes a plurality of instructions that may be executed by one or more processors.

[0303] Furthermore, the method can be implemented in any type of computing platform that is operably connected to a suitable computer, including but not limited to a personal computer, a minicomputer, a mainframe, a workstation, a network or distributed computing environment, a separate or integrated computer platform, or in communication with a charged particle tool or other imaging device, etc. Various aspects of the present invention can be implemented as machine-readable code stored on a non-transitory storage medium or device, whether removable or integrated into a computing platform, such as a hard disk, an optical read and / or write storage medium, RAM, ROM, etc., so that it can be read by a programmable computer, and when the storage medium or device is read by the computer, it can be used to configure and operate the computer to perform the process described herein. In addition, the machine-readable code, or portions thereof, can be transmitted over a wired or wireless network. When such media includes instructions or programs that implement the above steps in conjunction with a microprocessor or other data processor, the invention of this embodiment includes these and other different types of non-transitory computer-readable storage media. When programmed according to the methods and techniques of the present invention, the present invention also includes the computer itself.

[0304] The computer program can be applied to input data to perform the functions of the present embodiment, thereby converting the input data to generate output data that is stored in a non-volatile memory. The output information can also be applied to one or more output devices such as a display. In a preferred embodiment of the present invention, the converted data represents a physical and tangible object, including a specific visual depiction of the physical and tangible object produced on the display.

[0305] The above are merely preferred embodiments of the present invention. The present invention is not limited to the aforementioned embodiments. As long as the technical effects of the present invention are achieved by the same means, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention. Within the scope of protection of the present invention, various modifications and variations of the technical solutions and / or implementation methods may be made.

Claims

1. A method for monitoring the health of an operator's network, characterized in that: The operator network health monitoring method includes: Establishing a risk event database for an operator's network; the risk event database includes at least one risk event; Determine the frequency level and damage level corresponding to each of the risk events; Constructing a risk matrix based on each of the risk events; wherein one dimension of the risk matrix corresponds to the frequency level and another dimension corresponds to the degree of damage; Determining a weight coefficient for each event based on the risk matrix; the event weight coefficient represents the weight of the risk event corresponding to the specific frequency level and the damage degree; Obtaining various event factors of a target employee number in an operator's network; the event factors represent the historical behavior of the target employee number in relation to the risk event; The job number health of the target job number is determined based on each of the event weight coefficients and each of the event factors.

2. The operator network health monitoring method according to claim 1, characterized in that: The establishment of a risk event database for operator outlets includes: Obtaining business data of all employee numbers of the operator's outlets; Taking a single risk event as the scanning target, scan each of the business data; The risk event database is established based on the risk events scanned.

3. The operator network health monitoring method according to claim 1, characterized in that: Determining the weight coefficient of each event according to the risk matrix includes: Obtaining information entropy of each frequency level as frequency information entropy; Obtaining information entropy of each damage degree as damage information entropy; Determining a frequency weight coefficient and a damage weight coefficient according to the frequency information entropy and the damage information entropy; For any of the risk events, the frequency level and the damage degree corresponding to the risk event are weighted and summed according to the frequency weight coefficient and the damage weight coefficient to obtain the event weight coefficient corresponding to the risk event.

4. The operator network health monitoring method according to claim 1, characterized in that: The event factors for obtaining the target employee number in the operator's network include: For any of the risk events, obtain the number of violations and time distribution dispersion of the target employee number in the risk event; Constructing a judgment matrix of the number of violations and the time distribution dispersion by using the hierarchical analysis method; Determining, according to the judgment matrix, a first weight coefficient corresponding to the number of violations and a second weight coefficient corresponding to the time distribution dispersion; Obtaining the maximum number of violations in history of the operator's network point, and normalizing the number of violations according to the maximum number of violations in history; Obtaining the maximum value of the time distribution standard deviations corresponding to the same risk event for all employee numbers in the operator's outlets, obtaining the maximum standard deviation, and normalizing the time distribution dispersion according to the maximum standard deviation; According to the first weight coefficient and the second weight coefficient, a weighted sum is performed on the normalized number of violations and the normalized time distribution dispersion to obtain the event factor corresponding to the target work number in the risk event.

5. The operator network health monitoring method according to claim 1, characterized in that: Determining the job number health of the target job number based on each of the event weight coefficients and each of the event factors includes: According to the weight coefficients of the events, the event factors are weighted and summed to obtain the job number health of the target job number.

6. The operator network health monitoring method according to any one of claims 1 to 5, characterized in that: The operator network health monitoring method further includes: Obtain the employee number health corresponding to all employee numbers of the operator's outlets; Perform global normalization based on the health of each work number to obtain a normalized score corresponding to each work number; Determine risk job numbers among all job numbers based on the normalized scores; Provide graded warnings for the risky work numbers.

7. The operator network health monitoring method according to any one of claims 1 to 5, characterized in that: The operator network health monitoring method further includes: Obtain the employee number health corresponding to all employee numbers of the operator's outlets; Performing Z-Score normalization on the health of each work number to obtain multiple normalized scores; The average value of each of the standardized scores is obtained to obtain the network health level corresponding to the operator network.

8. The operator network health monitoring method according to claim 7, characterized in that: The operator network health monitoring method further includes: Visually displaying the work number health and the network health; Providing risk warning based on the health of the work number and the health of the outlet; Generate and push warning information based on the results of risk warning; Based on the results of the risk warning, the freezing of work numbers and the clearing of permissions process will be executed.

9. A computer device, characterized in that: The system comprises a memory and a processor, wherein the memory is used to store at least one program, and the processor is used to load at least one program to execute the operator network health monitoring method according to any one of claims 1 to 8.

10. A computer-readable storage medium storing a program executable by a processor, characterized in that: The program executable by the processor is used to execute the operator network health monitoring method described in any one of claims 1 to 8 when executed by the processor.