Operational risk acquisition method, system, electronic device and storage medium
By processing and analyzing the operating system log information and using neural network models to identify operational risks, the problem that operational risk prevention and control in the existing technology is mainly post-event prevention and control, and accurate identification and early warning of operational risks are achieved, and economic losses are reduced.
Patent Information
- Application Number
- CN202110587891.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-27
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2041-05-27
AI Technical Summary
In the prior art, operational risk prevention and control is mainly post-event prevention and control, and it is difficult to effectively arrange and intercept before and during losses, resulting in huge economic losses caused by operational risks.
By obtaining the operating system's log information, converting it into multiple tuple data, semantic analysis is performed to obtain emotional information, and inputting this data into the neural network model to identify operational risks and provide early warnings.
It realizes accurate identification and early warning of operational risks, effectively reduces economic losses caused by operational risks, and improves the foresight and accuracy of risk prevention and control.
Smart Images

Figure CN113191137B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of operational risk prevention and control management of financial institutions, and specifically to an operational risk acquisition method, system, electronic device and storage medium. Background Art
[0002] In recent years, major cases in the financial sector have occurred frequently, and a series of cases caused by operational risks have caused huge losses to commercial banks. The current method of operational risk prevention and control is mainly post-event prevention and control. In order to reduce the losses caused by operational risks, effective control and interception must be carried out before and during the occurrence of losses. The key to pre-event control and interception is to accurately identify operational risks. Therefore, how to fully and accurately obtain the risk information inside the operational event has become an urgent problem to be solved. Summary of the invention
[0003] In order to solve the problems existing in the prior art, the embodiments of the present disclosure provide an operational risk acquisition method, system, electronic device and storage medium, which are intended to accurately identify existing operational risks, and warn operators after identification, so as to effectively reduce the economic losses caused by operational risks.
[0004] The first aspect of the present disclosure provides a method for obtaining operational risks, including: obtaining log information of an operating system; converting the log information into multiple tuple data; for each tuple data, performing semantic analysis based on at least one tuple data in the tuple data to obtain sentiment information of the tuple data; inputting the multiple tuple data and the sentiment information they carry into a neural network model to obtain risk information of each tuple data.
[0005] Furthermore, for each tuple data, semantic analysis is performed based on at least one piece of data in the tuple data to obtain emotional information of the tuple data, including: using an emotional dictionary, performing semantic analysis based on at least one piece of data in the tuple data, determining the text with emotion in each tuple data, and obtaining the emotional information of the tuple data.
[0006] Furthermore, the multiple tuple data and the emotional information they carry are input into a neural network model to obtain risk information of each tuple data, including: preprocessing the multiple tuple data and the emotional information they carry to obtain a vector matrix set of the multiple tuple data; inputting the vector matrix set into a classifier of the neural network model for classification training to obtain risk information of each tuple data.
[0007] Furthermore, the log information is converted into multiple tuple data, including: segmenting and formatting the log information to obtain multiple tuple data, wherein each tuple data includes 6-tuple data, and the 6-tuple data is the time of the user operation event, the relevant user number, event information, event cost, event occurrence probability and event level.
[0008] Furthermore, before the multiple tuple data and the emotional information they carry are input into the neural network model, the method includes: obtaining a training data set, wherein the training data set is a labeled data set; and training the neural network model using the labeled data set to obtain the trained neural network model.
[0009] Furthermore, the risk information of the plurality of tuple data includes at least: a risk score value of each tuple data, the number of positive and negative samples in the plurality of tuple data, and the ratio of positive and negative samples.
[0010] Furthermore, the classifier is a Naive Bayesian classifier, a logistic regression classifier, or a SVM three-class classifier.
[0011] The second aspect of the present disclosure provides an operational risk acquisition system, including: a log information acquisition module, used to obtain log information of an operating system; a data conversion module, used to convert the log information into multiple tuple data; a data semantic analysis module, used to perform semantic analysis on each tuple data based on at least one tuple data in the tuple data to obtain emotional information of the tuple data; a risk information acquisition module, used to input multiple tuple data and the emotional information they carry into a neural network model to obtain risk information for each tuple data.
[0012] Furthermore, the data semantic analysis module is used to perform semantic analysis on each tuple data according to at least one piece of data in the tuple data to obtain sentiment information of the tuple data, including: using a sentiment dictionary to perform semantic analysis on at least one piece of data in the tuple data to determine the text with sentiment in each tuple data to obtain sentiment information of the tuple data.
[0013] Furthermore, the risk information acquisition module is used to input the multiple tuple data and the emotional information they carry into the neural network model to obtain the risk information of each tuple data, including: preprocessing the multiple tuple data and the emotional information they carry to obtain a vector matrix set of the multiple tuple data; inputting the vector matrix set into the classifier of the neural network model for classification training to obtain the risk information of each tuple data.
[0014] Furthermore, the data conversion module is used to convert the log information into multiple tuple data, including: segmenting and formatting the log information to obtain multiple tuple data, wherein each tuple data includes 6 tuple data, and the 6 tuple data is the time of the user operation event, the relevant user number, event information, event cost, event occurrence probability and event level.
[0015] Furthermore, the risk information of the plurality of tuple data includes at least: a risk score value of each tuple data, the number of positive and negative samples in the plurality of tuple data, and the ratio of positive and negative samples.
[0016] The third aspect of the present disclosure provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the operational risk acquisition method provided by the first aspect of the present disclosure is implemented.
[0017] The fourth aspect of the present disclosure provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the operational risk acquisition method provided by the first aspect of the present disclosure is implemented.
[0018] The present disclosure provides an operational risk acquisition method, system, electronic device and storage medium, which finds risk records in operations through data mining, providing a basis for early identification of subsequent risks. The method provided by the present disclosure mines data from a large number of log records, with more diverse samples, so that the identification results are closer to reality and the identification is more accurate, realizing intelligent identification of operational risks and saving labor costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] For a more complete understanding of the present disclosure and its advantages, reference will now be made to the following description taken in conjunction with the accompanying drawings, in which:
[0020] Figure 1 A schematic diagram showing an application scenario of the method for obtaining operational risk according to an embodiment of the present disclosure;
[0021] Figure 2 A flowchart of a method for obtaining operational risk according to an embodiment of the present disclosure is schematically shown;
[0022] Figure 3 A flowchart of obtaining risk information of each tuple data according to an embodiment of the present disclosure is schematically shown;
[0023] Figure 4 A block diagram of a login system according to an embodiment of the present disclosure is schematically shown;
[0024] Figure 5 A block diagram of a risk information acquisition module according to an embodiment of the present disclosure is schematically shown;
[0025] Figure 6 A block diagram of an electronic device suitable for implementing the method described above according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present disclosure. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0027] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise", "include", etc. used herein indicate the existence of the features, steps, operations and / or components, but do not exclude the existence or addition of one or more other features, steps, operations or components.
[0028] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification, and should not be interpreted in an idealized or overly rigid manner.
[0029] In the case of using expressions such as "at least one of A, B, and C, etc.", it should generally be interpreted in accordance with the meaning of the expression generally understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.). In the case of using expressions such as "at least one of A, B, or C, etc.", it should generally be interpreted in accordance with the meaning of the expression generally understood by those skilled in the art (for example, "a system having at least one of A, B, or C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0030] Some block diagrams and / or flow charts are shown in the accompanying drawings. It should be understood that some boxes or combinations thereof in the block diagrams and / or flow charts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that these instructions can create a device for implementing the functions / operations described in these block diagrams and / or flow charts when executed by the processor. The technology of the present disclosure can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). In addition, the technology of the present disclosure can take the form of a computer program product on a computer-readable storage medium storing instructions, which can be used by an instruction execution system or used in conjunction with an instruction execution system.
[0031] The embodiment of the present disclosure provides a method for obtaining operational risks, including: obtaining log information of an operating system; converting the log information into multiple tuple data; for each tuple data, performing semantic analysis based on at least one tuple data in the tuple data to obtain emotional information of the tuple data; inputting the multiple tuple data and the emotional information they carry into a neural network model to obtain risk information of each tuple data.
[0032] According to the embodiments of the present disclosure, by mining risk records in operations from a large number of log records, marking the operational risks existing in user operation behaviors and generating corresponding risk information, a data basis is provided for early identification of subsequent risks, which can play a role in effective control and interception before and during the occurrence of losses.
[0033] Figure 1 The exemplary system architecture 100 that can be applied to the operational risk acquisition method according to an embodiment of the present disclosure is schematically shown. It should be noted that: Figure 1 What is shown is merely an example of a system architecture to which the embodiments of the present disclosure can be applied, in order to help those skilled in the art understand the technical content of the present disclosure, but it does not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.
[0034] like Figure 1 As shown, the system architecture 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104 and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0035] Users can use terminal devices 101, 102, 103 to interact with server 105 through network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, 103, such as various software programming systems, software testing systems, web browser applications, mobile banking applications, instant messaging tools, email clients, social platform software, etc. (only as examples).
[0036] The terminal devices 101 , 102 , and 103 may be various electronic devices having a display screen and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, and desktop computers.
[0037] The server 105 may be a server that provides various services, such as a background management server (only an example) that provides support for the application system used by the user using the terminal devices 101, 102, 103. The background management server may analyze and process the received user requests, etc., and feed back the processing results (such as the results of the operation risk analysis, etc.) to the terminal device.
[0038] It should be noted that the operational risk acquisition method provided in the embodiment of the present disclosure can be executed by the server 105. Accordingly, the operational risk acquisition system provided in the embodiment of the present disclosure can be deployed in the server 105. The operational risk acquisition method provided in the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Accordingly, the operational risk acquisition system provided in the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the terminal devices 101, 102, 103 and / or the server 105. Of course, in some embodiments, the operational risk acquisition system provided in the embodiment of the present disclosure can also be deployed in a user terminal device, that is, the operational risk acquisition can also be executed by the user terminal device.
[0039] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is only for illustration. Any number of terminal devices, networks and servers may be provided according to implementation requirements.
[0040] Figure 2 The flowchart of the method for obtaining operational risk according to an embodiment of the present disclosure is schematically shown. Figure 2 As shown, the method includes: steps S201 to S204.
[0041] In operation S201, log information of an operating system is obtained.
[0042] According to an embodiment of the present disclosure, the operational risk acquisition can be applied to electronic devices, which may include but are not limited to server 105, server clusters, etc. Various application systems can be installed in the server, such as: mobile banking system, financial system, etc., and the server stores log files generated when users operate various application systems, and the log files record information about user operation behaviors.
[0043] In the embodiments of the present disclosure, log files can be stored on the server in file formats such as .txt and .log. Each log information in the log file is the corresponding information when the user performs an operation, including but not limited to user number information, operation time, event content, classification level of the time, etc. Among them, a transaction performed by a user involves multiple operation behaviors, which will generate and store corresponding multiple log information. In an embodiment of the present disclosure, the relevant personnel information involved in the same transaction is integrated into a metadata. For example, each metadata can be {"code":"00001","data":"[{"2021-04-06",["000111A","000112A","000113A"],"Transfer counterparty risk","00001","00001","A"}]","msg":""}, the relevant objects in the exemplary metadata are "000111A","000112A","000113A", indicating that there are three related transaction objects involved in the transaction, and the time of the transaction is "2021-04-06", wherein the information about the transaction is stored in the remarks information of "Transfer counterparty risk".
[0044] It should be noted that the metadata of a transaction generated according to multiple log information in the log file in the embodiment of the present disclosure is only an exemplary description and does not constitute a limitation of the embodiment of the present disclosure.
[0045] In operation S202 , the log information is converted into a plurality of tuple data.
[0046] In the embodiment of the present disclosure, the acquired log information is converted into multiple tuple data by using preset rules, wherein the preset rules include but are not limited to word segmentation and formatting processing rules. Specifically, the log information is segmented and formatted to obtain multiple tuple data, wherein each tuple data includes 6 tuple data, which are the time (T) of the user operation event, the relevant user number (W), the event information (C), the event cost (P), the event occurrence probability (R) and the event level (G). The time T of the user operation event refers to the time point when the risk event occurs; the relevant user number W refers to the risk-related person, including the customer number and the employee number, and the employee refers to the staff who processes the transaction as passed or rejected; the event information C refers to the content of the operation event, including information such as the process and situation of the event; the event cost P represents the cost of the event, that is, the loss or impact caused, which can be quantified as a specific numerical value of financial loss or punishment, etc.; the event occurrence probability R represents the frequency of such events within a certain period of time, which is obtained by calculation; the event level G is the risk event level corresponding to the event, which is the internal assessment level.
[0047] Continuing with the above embodiment, if the metadata is formatted, the time of the corresponding user operation event is converted to "time": "2021-04-06", the relevant user number is converted to "who": ["000111A", "000112A", "000113A"], the event information is converted to "content": "Transfer counterparty risk-high-risk account", the event cost is converted to "price": "00001", and the event occurrence probability is converted to "ra te″:″00001″, the event level is converted to ″grade″:″A″, that is, the 6-tuple data generated according to the metadata is {″time″:″2021-04-06″, ″who″:[″000111A″, ″000112A″, ″000113A″], ″content″:″Transfer counterparty risk-high-risk account″, ″price″:″00001″, ″rate″:″00001″, ″grade″:″A″}.
[0048] It should be noted that the event level G can be classified and identified by letters A, B, C..., and the severity order can be arranged from high to low, or in increasing order. Among them, user accounts with higher levels are the objects of subsequent intensive prevention and control. The embodiments of the present disclosure do not limit the parameter setting method for each tuple in the 6-tuple data.
[0049] In operation S203, for each tuple data, semantic analysis is performed according to at least one piece of data in the tuple data to obtain sentiment information of the tuple data.
[0050] In the embodiment of the present disclosure, each tuple data includes at least 6 tuple data, wherein the event information C includes multiple notes of the event, and each note information includes text with different emotions. By performing semantic analysis based on the event information C, event cost P and event occurrence probability R in the tuple data, the emotional information of the tuple data can be obtained.
[0051] Specifically, a sentiment dictionary is used to perform semantic analysis based on at least one piece of data in the tuple data, to determine the text with sentiment in each tuple data, and to obtain the sentiment information of the tuple data.
[0052] In the embodiments of the present disclosure, the Emotion Dictionary provided by HowNet is used as the basic emotional dictionary. Some texts without emotional colors are deleted according to actual usage, and the text is pre-processed such as word segmentation and stop word processing. Then, the emotional dictionary constructed in advance is used to perform string matching on the text to mine positive and negative information. Among them, the emotional dictionary contains four parts: positive word dictionary, negative word dictionary, negative word dictionary, and degree adverb dictionary. The emotional tendency (SO) of Chinese words is defined as positive and negative attitudes, and the two indicators of polarity (Po) and intensity (I) are mainly used for emotion calculation. The value of polarity Po in the embodiments of the present disclosure only involves three types: positive, negative, and neutral (irrelevant). Intensity I is an extension of the polarity division, representing the strength of the polarity tendency. The emotional polarity of words is defined as follows:
[0053] S(word)=(Po,)Po={-1, 0, 1} / ={0, 0.5,}
[0054] Among them, Po takes the value "-1" to represent negativity, the value "0" to represent neutrality or irrelevant, and the value "1" to represent positivity. For / : the larger the number, the greater the intensity. When P = 0, S (word) does not have an I value. In the embodiment of the present disclosure, the above embodiment is used. The result of sentiment analysis of the event information C, event cost P, and event occurrence probability R of the tuple data exemplified in the above embodiment is a negative sample.
[0055] In operation S204, the plurality of tuple data and the sentiment information they carry are input into a neural network model to obtain risk information of each tuple data.
[0056] In the embodiments of the present disclosure, since there is no absolutely real data to refer to in the text, manual annotation is required first. Assuming that the tendency of 10,000 data items needs to be annotated, the sample data is shown in Table 1 below:
[0057] Table 1 Operation behavior and score mapping table
[0058] operate score Transfer account (high risk) -1 Source Account (High Risk) -1 Normal transfer 0
[0059] Among them, it is assumed that 20% of the 10,000 data, that is, 2,000 data, are manually labeled as a training data set, and then the labeled data set is input into the neural network model to be trained for model training. Specifically, before the multiple tuple data and the emotional information they carry are input into the neural network model, it includes: obtaining a training data set, wherein the training data set is a labeled data set, and using the labeled data set to train the neural network model to obtain a trained neural network model.
[0060] According to the embodiments of the present disclosure, Figure 3 As shown in the figure, multiple tuple data and the sentiment information they carry are input into the neural network model to obtain the risk information of each tuple data, including:
[0061] In operation S301, the plurality of tuple data and the emotional information they carry are preprocessed to obtain a vector matrix set of the plurality of tuple data.
[0062] In operation S302, the vector matrix set is input into a classifier of a neural network model for classification training to obtain risk information of each tuple data.
[0063] In the embodiments of the present disclosure, the neural network model network adopts a convolutional neural network (CNN), and its structure mainly includes five layers. The first layer is an embedding layer (input layer), which inputs Word2vec word vectors, the second layer is a convolution layer, and the convolution layer has multiple convolution kernels and feature maps. The third layer is a pooling layer, and the last fully connected layer is used for outputting the results using a softmax layer or dropout. There are convolution kernels of different sizes in the convolution layer, so tensors of different shapes will be generated after convolution, and the results need to be merged. In addition, the convolution operation uses narrow convolution, and the convolution output result is processed by max-pooling and the value with the largest score is selected as the output result.
[0064] Specifically, the classifier of the neural network model can adopt a Naive Bayesian classifier or a logistic regression classifier or a SVM three-class classifier or other classifiers. The risk information of the multiple tuple data processed by the classifier includes at least: the risk score value of each tuple data, the number of positive and negative samples in the multiple tuple data, the ratio of positive and negative samples, and risk classification accuracy, evaluation indicators and other information, wherein the number of positive and negative samples in the multiple tuple data refers to the number of positive samples and negative samples. For example, among 8000 sample data, the number of positive samples obtained according to the risk information is 5600, and the number of negative samples is 1600, then the ratio of positive and negative samples is 20% and 70% respectively. It should be noted that the sample data value and the number of positive and negative samples are only exemplary descriptions, and they do not constitute a limitation of the embodiments of the present disclosure.
[0065] According to the risk score value of each tuple data, the risk value of the corresponding user operation can be known, and then the risk generated when the user performs the relevant operation can be judged, and the probability of its occurrence can be judged. According to the number of positive and negative samples and the ratio of positive and negative samples in the tuple data within a certain period of time, the probability of occurrence of some types of risky behaviors and the more concentrated time period can be predicted, which plays a data basis role in the monitoring and risk prevention and control of subsequent related user operations. In addition, the method provided by the present disclosure is deployed at the corresponding interface of the application system, and the risk information of the user's operation behavior can be obtained in real time, and then the operation time can be intercepted according to the risk value to reduce unnecessary accidental losses.
[0066] It should be noted that in the above-mentioned embodiments, the data parameter settings and numerical values are only exemplary descriptions, and do not mean that they cannot be other parameter settings and values in other embodiments, and the present disclosure does not limit this.
[0067] Figure 4 A block diagram of an operational risk acquisition system according to an embodiment of the present disclosure is schematically shown.
[0068] like Figure 4 As shown, the operational risk acquisition system 400 includes: a log information acquisition module 410, a data conversion module 420, a data semantic analysis module 430 and a risk information acquisition module 440. The system 400 can be used to implement reference Figure 2 The operational risk capture approach described.
[0069] The log information acquisition module 410 is used to acquire the log information of the operating system. According to an embodiment of the present disclosure, the log information acquisition module 410 can be used to execute the above reference Figure 2 The described step S201 will not be repeated here.
[0070] The data conversion module 420 is used to convert the log information into a plurality of tuple data. According to an embodiment of the present disclosure, the data conversion module 420 can be used to perform the above reference Figure 2 The described step S202 will not be repeated here.
[0071] The data semantic analysis module 430 is used to perform semantic analysis on each tuple data according to at least one tuple data in the tuple data to obtain the sentiment information of the tuple data. According to an embodiment of the present disclosure, the data semantic analysis module 430 can be used to perform the above reference Figure 2 The described step S203 will not be repeated here.
[0072] The risk information acquisition module 440 is used to input the plurality of tuple data and the sentiment information they carry into the neural network model to obtain the risk information of each tuple data. According to an embodiment of the present disclosure, the risk information acquisition module 440 can be used to execute the above reference Figure 2 The described step S204 will not be repeated here.
[0073] In an embodiment of the present disclosure, the data conversion module 420 is used to convert the log information into multiple tuple data, including: performing word segmentation and formatting processing on the log information to obtain multiple tuple data, wherein each tuple data includes 6 tuple data, which are the time of the user operation event, the relevant user number, event information, event cost, event occurrence probability and event level.
[0074] In an embodiment of the present disclosure, the data semantic analysis module 430 is used to perform semantic analysis on each tuple data according to at least one piece of data in the tuple data to obtain sentiment information of the tuple data, including: using a sentiment dictionary to perform semantic analysis on at least one piece of data in the tuple data to determine the text with sentiment in each tuple data to obtain sentiment information of the tuple data.
[0075] like Figure 5 As shown, the risk information acquisition module 440 is used to input the multiple tuple data and the sentiment information they carry into the neural network model to obtain the risk information of each tuple data, specifically including:
[0076] The vector matrix generation module 4401 is used to pre-process the multiple tuple data and the emotional information they carry to obtain a vector matrix set of the multiple tuple data. According to an embodiment of the present disclosure, the vector matrix generation module 4401 can be used to perform the above reference Figure 3 The described step S301 will not be repeated here.
[0077] The data training module 4402 is used to input the vector matrix set into the classifier of the neural network model for classification training to obtain the risk information of each tuple data. According to the embodiment of the present disclosure, the data training module 4402 can be used to perform the above reference Figure 3 The described step S302 will not be repeated here.
[0078] According to the embodiments of the present invention, any one or more of the modules, submodules, units, and subunits, or at least part of the functions of any one of them can be implemented in one module. According to the embodiments of the present invention, any one or more of the modules, submodules, units, and subunits can be split into multiple modules for implementation. According to the embodiments of the present invention, any one or more of the modules, submodules, units, and subunits can be at least partially implemented as hardware circuits, such as field programmable gate arrays (FPGAs), programmable logic arrays (PLAs), systems on chips, systems on substrates, systems on packages, application specific integrated circuits (ASICs), or can be implemented by hardware or firmware in any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in any appropriate combination of any of them. Alternatively, according to the embodiments of the present invention, one or more of the modules, submodules, units, and subunits can be at least partially implemented as computer program modules, and when the computer program modules are run, the corresponding functions can be performed.
[0079] For example, any multiple of the log information acquisition module 410, the data conversion module 420, the data semantic analysis module 430, and the risk information acquisition module 440 can be combined in one module for implementation, or any one of the modules can be split into multiple modules. Alternatively, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present disclosure, at least one of the log information acquisition module 410, the data conversion module 420, the data semantic analysis module 430, and the risk information acquisition module 440 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by hardware or firmware such as any other reasonable way of integrating or packaging the circuit, or implemented in any one of the three implementation methods of software, hardware, and firmware, or in an appropriate combination of any of them. Alternatively, at least one of the log information acquisition module 410, the data conversion module 420, the data semantic analysis module 430 and the risk information acquisition module 440 may be at least partially implemented as a computer program module, and when the computer program module is executed, the corresponding function may be executed.
[0080] The operational risk acquisition method and system provided by the present disclosure can be used in the financial field or other fields. It should be noted that the operational risk acquisition method and system provided by the present disclosure can be used in the financial field, such as logging into various business systems in the financial field, and can also be used in fields other than the financial field. The application field of the operational risk acquisition method and system provided by the present disclosure is not limited.
[0081] Figure 6 A block diagram of an electronic device suitable for implementing the method described above according to an embodiment of the present disclosure is schematically shown. Figure 6 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0082] like Figure 6 As shown, the electronic device 600 described in this embodiment includes: a processor 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage part 808 into a random access memory (RAM) 603. The processor 601 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), and the like. The processor 601 may also include an onboard memory for caching purposes. The processor 601 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0083] In RAM 603, various programs and data required for the operation of system 600 are stored. Processor 601, ROM 602 and RAM 603 are connected to each other through bus 604. Processor 601 performs various operations of the method flow according to the embodiment of the present disclosure by executing the program in ROM 602 and / or RAM 603. It should be noted that the program can also be stored in one or more memories other than ROM 602 and RAM 603. Processor 601 can also perform various operations of the method flow according to the embodiment of the present disclosure by executing the program stored in the one or more memories.
[0084] According to an embodiment of the present disclosure, the electronic device 600 may further include an input / output (I / O) interface 605, which is also connected to the bus 604. The system 800 may further include one or more of the following components connected to the I / O interface 605: an input portion 606 including a keyboard, a mouse, etc.; an output portion 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 608 including a hard disk, etc.; and a communication portion 609 including a network interface card such as a LAN card, a modem, etc. The communication portion 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as needed, so that a computer program read therefrom is installed into the storage portion 608 as needed.
[0085] According to an embodiment of the present disclosure, the method flow according to an embodiment of the present disclosure can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program contains a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 609, and / or installed from the removable medium 611. When the computer program is executed by the processor 601, the above-mentioned functions defined in the system of the embodiment of the present disclosure are executed. According to an embodiment of the present disclosure, the system, equipment, device, module, unit, etc. described above can be implemented by a computer program module.
[0086] The embodiment of the present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiment; or may exist independently without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the above one or more programs are executed, the method for obtaining operational risk according to the embodiment of the present disclosure is implemented.
[0087] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In an embodiment of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program, which may be used by or in combination with an instruction execution system, an apparatus or a device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the ROM 602 and / or RAM 603 described above and / or one or more memories other than ROM 602 and RAM 603.
[0088] It should be noted that the functional modules in the various embodiments of the present invention can be integrated into a processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The above-mentioned integrated modules can be implemented in the form of hardware or in the form of software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product.
[0089] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a module, a program segment, or a part of a code, and the above-mentioned module, program segment, or a part of a code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flow chart, and the combination of the boxes in the block diagram or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0090] It will be appreciated by those skilled in the art that the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways, even if such combinations and / or combinations are not explicitly described in the present disclosure. In particular, the features described in the various embodiments and / or claims of the present disclosure may be combined and / or combined in a variety of ways without departing from the spirit and teachings of the present disclosure. All of these combinations and / or combinations fall within the scope of the present disclosure.
[0091] Although the present disclosure has been shown and described with reference to specific exemplary embodiments of the present disclosure, it should be understood by those skilled in the art that various changes in form and details may be made to the present disclosure without departing from the spirit and scope of the present disclosure as defined by the appended claims and their equivalents. Therefore, the scope of the present disclosure should not be limited to the above-mentioned embodiments, but should be determined not only by the appended claims, but also by the equivalents of the appended claims.
Claims
1. A method for obtaining operational risk, characterized in that: include: Get the log information of the operating system; Convert the log information into multiple tuple data; For each tuple data, semantic analysis is performed according to at least one piece of data in the tuple data to obtain sentiment information of the tuple data; Inputting the plurality of tuple data and the sentiment information they carry into a neural network model to obtain risk information of each tuple data; The step of performing semantic analysis on each tuple data according to at least one tuple data in the tuple data to obtain sentiment information of the tuple data includes: Using a sentiment dictionary, performing semantic analysis based on at least one piece of data in the tuple data, determining text with sentiment in each piece of tuple data, and obtaining sentiment information of the tuple data; The step of inputting the plurality of tuple data and the sentiment information they carry into a neural network model to obtain risk information of each tuple data includes: Preprocessing the plurality of tuple data and the emotional information they carry to obtain a vector matrix set of the plurality of tuple data; Inputting the vector matrix set into the classifier of the neural network model for classification training to obtain risk information of each tuple data; The risk information of the plurality of tuple data includes at least: a risk score value of each tuple data, the number of positive and negative samples in the plurality of tuple data, and the ratio of positive and negative samples.
2. The operational risk acquisition method according to claim 1, characterized in that: The converting the log information into a plurality of tuple data includes: The log information is segmented and formatted to obtain multiple tuple data, wherein each tuple data includes 6-tuple data, and the 6-tuple data is the time of the user operation event, the relevant user number, event information, event cost, event occurrence probability and event level.
3. The operational risk acquisition method according to claim 1, characterized in that: Before inputting the plurality of tuple data and the sentiment information they carry into the neural network model, the method includes: Acquire a training data set, wherein the training data set is a labeled data set; The neural network model is trained using the labeled data set to obtain the trained neural network model.
4. The operational risk acquisition method according to claim 1, characterized in that: The classifier is a NaiveBayesian classifier, a logistic regression classifier or a SVM three-category classifier.
5. An operational risk acquisition system, characterized in that: include: A log information acquisition module is used to obtain log information of the operating system; A data conversion module, used for converting the log information into a plurality of tuple data; A data semantic analysis module is used to perform semantic analysis on each tuple data according to at least one piece of data in the tuple data to obtain sentiment information of the tuple data; The step of performing semantic analysis on each tuple data according to at least one tuple data in the tuple data to obtain sentiment information of the tuple data includes: Using a sentiment dictionary, performing semantic analysis based on at least one piece of data in the tuple data, determining text with sentiment in each piece of tuple data, and obtaining sentiment information of the tuple data; A risk information acquisition module, used to input the plurality of tuple data and the sentiment information they carry into a neural network model to obtain risk information of each tuple data; The step of inputting the plurality of tuple data and the sentiment information they carry into a neural network model to obtain risk information of each tuple data includes: Preprocessing the plurality of tuple data and the emotional information they carry to obtain a vector matrix set of the plurality of tuple data; Inputting the vector matrix set into the classifier of the neural network model for classification training to obtain risk information of each tuple data; The risk information of the plurality of tuple data includes at least: a risk score value of each tuple data, the number of positive and negative samples in the plurality of tuple data, and the ratio of positive and negative samples.
6. The operational risk acquisition system according to claim 5, characterized in that: The data conversion module is used to convert the log information into a plurality of tuple data, including: The log information is segmented and formatted to obtain multiple tuple data, wherein each tuple data includes 6-tuple data, and the 6-tuple data is the time of the user operation event, the relevant user number, event information, event cost, event occurrence probability and event level.
7. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the operational risk acquisition method as described in any one of claims 1 to 4 is implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the operational risk acquisition method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Method and device for determining risk operation event
CN111125042A
Internal threat analysis method and system based on anomaly detection and sentiment analysis
CN112637108A