Traffic playback-based risk control policy configuration method and device, equipment and medium
By parsing and verifying risk control strategy configuration requests using a traffic replay-based method, the problem of low efficiency in risk control strategy configuration in existing technologies is solved, enabling timely and effective configuration of risk control strategies and improving system stability and risk management capabilities.
Patent Information
- Application Number
- CN202111528626.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-14
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2041-12-14
AI Technical Summary
Existing technologies have low efficiency in configuring risk control strategies, leading to increased system load, stability issues, and expanded risk exposure, making it impossible to detect and deploy risk rules in a timely manner.
By using a traffic replay-based method, the strategy configuration request is parsed to obtain characteristic indicator information. The event characteristic indicator information is then replayed and verified. The validity of the risk control configuration strategy is determined by comparing the verification rules. Finally, the verified strategy is configured to the data processing server.
It improves the efficiency of risk control strategy configuration, ensures timely and effective configuration of risk control strategies, and reduces system load and risk exposure.
Smart Images

Figure CN114186874B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data analysis, and belongs to the application scenario of intelligent configuration of risk control strategies based on traffic playback analysis in smart cities, and particularly relates to a risk control strategy configuration method and device based on traffic playback, equipment and medium. BACKGROUND
[0002] In order to control the risks of their own businesses, enterprises generally set risk control strategies to screen business flow data, so as to screen out risk business data and perform corresponding processing, so as to improve the risk control capability. However, the existing rule strategies are all specified according to the experience of managers, and are usually arranged and combined based on event characteristics and then put into production lines. Since the enterprise cannot accurately master the specific risk control rules that play a role in the rule strategy, that is, cannot efficiently screen the existing risk control rules to obtain effective risk control rules, it is difficult to easily offline any one risk control rule in the rule strategy, and the number of risk control rules accumulated on the production line is increasingly large, and the system load is heavy. Due to too many rules, the maintenance is poor, and the system response is not timely and even the system is stalled. Due to the stability problem of the system, the risk exposure is expanded. In addition, the existing technical method obtains event characteristics according to asset loss or customer complaint, and supplements new rule strategies for corresponding rule deployment, and cannot perceive the risk in the first time and deploy the rule strategy as soon as possible to control the risk. Due to the low efficiency of the risk control strategy configuration, the risk exposure time is too long, and the business risk of the enterprise is increased. Therefore, the existing technical method has the problem of low configuration efficiency when configuring the rule strategy. SUMMARY
[0003] The embodiments of the present application provide a risk control strategy configuration method and device based on traffic playback, equipment and medium, which aims to solve the problem of low configuration efficiency of the existing technical method when configuring the rule strategy.
[0004] In a first aspect, the embodiments of the present application provide a risk control strategy configuration method based on traffic playback, and the method comprises the following steps:
[0005] If a strategy configuration request is received, target event data corresponding to the strategy configuration request is obtained from a pre-stored historical event data table;
[0006] The risk control configuration strategy in the strategy configuration request is analyzed to obtain corresponding feature index item information therefrom;
[0007] According to the feature index item information, the target event data is index playback arranged to obtain event characteristic index information corresponding to the feature index item information;
[0008] According to the risk control configuration strategy, event feature index information corresponding to the target event data is verified by replaying, to obtain a replay result corresponding to the risk control configuration strategy;
[0009] According to preset comparison verification rules, the replay result is compared and verified, to obtain a comparison verification result of whether the replay result passes the verification;
[0010] If the comparison verification result is passed, the risk control configuration strategy is configured into a data processing server.
[0011] In a second aspect, an embodiment of the present application provides a risk control strategy configuration device based on traffic replay, which comprises:
[0012] A target event data acquisition unit is configured to, if a strategy configuration request is received, acquire target event data corresponding to the strategy configuration request from a pre-stored historical event data table;
[0013] A feature index item information acquisition unit is configured to analyze a risk control configuration strategy in the strategy configuration request to acquire corresponding feature index item information therefrom;
[0014] An event feature index information acquisition unit is configured to, according to the feature index item information, perform index replay arrangement on the target event data, to acquire event feature index information corresponding to the feature index item information;
[0015] A replay result acquisition unit is configured to, according to the risk control configuration strategy, verify event feature index information corresponding to the target event data by replaying, to acquire a replay result corresponding to the risk control configuration strategy;
[0016] A comparison verification result acquisition unit is configured to, according to preset comparison verification rules, compare and verify the replay result, to obtain a comparison verification result of whether the replay result passes the verification;
[0017] A strategy configuration unit is configured to, if the comparison verification result is passed, configure the risk control configuration strategy into a data processing server.
[0018] In a third aspect, an embodiment of the present application further provides a computer device, which comprises a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and the processor implements the risk control strategy configuration method based on traffic replay of the first aspect when executing the computer program.
[0019] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program, when executed by a processor, causes the processor to perform the method of configuring a risk control strategy based on traffic playback as described in the first aspect.
[0020] The embodiments of the present application provide a method, device and medium for configuring a risk control strategy based on traffic playback. Target event data corresponding to a received policy configuration request is obtained. Feature index item information is obtained by analyzing a risk control configuration strategy in the policy configuration request. Event feature index information is obtained by performing index playback on the target event data according to the feature index item information. A playback result is obtained by performing playback verification on the event feature index information according to the risk control configuration strategy, and further comparison verification is performed to obtain a comparison verification result. If the comparison verification result is passed, the risk control configuration strategy is configured in a data processing server. According to the above method, traffic data playback can be performed based on the risk control strategy before the risk control strategy is configured. The reliability of the risk control strategy is verified through the traffic data playback process. The configuration efficiency of the risk control strategy is greatly improved. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0022] Figure 1 A flowchart of the method for configuring a risk control strategy based on traffic playback provided by the embodiments of the present application is shown.
[0023] Figure 2 An application scenario diagram of the method for configuring a risk control strategy based on traffic playback provided by the embodiments of the present application is shown.
[0024] Figure 3 A sub-flowchart of the method for configuring a risk control strategy based on traffic playback provided by the embodiments of the present application is shown.
[0025] Figure 4 Another flowchart of the method for configuring a risk control strategy based on traffic playback provided by the embodiments of the present application is shown.
[0026] Figure 5 Another sub-flowchart of the method for configuring a risk control strategy based on traffic playback provided by the embodiments of the present application is shown.
[0027] Figure 6Another sub-process schematic diagram of the flow playback-based risk control policy configuration method provided by the embodiment of the present application is shown in FIG. 6;
[0028] Figure 7 Another sub-process schematic diagram of the flow playback-based risk control policy configuration method provided by the embodiment of the present application is shown in FIG. 6;
[0029] Figure 8 Another sub-process schematic diagram of the flow playback-based risk control policy configuration method provided by the embodiment of the present application is shown in FIG. 6;
[0030] Figure 9 A schematic block diagram of the flow playback-based risk control policy configuration apparatus provided by the embodiment of the present application is shown in FIG. 7.
[0031] Figure 10 A schematic block diagram of the computer device provided by the embodiment of the present application is shown in FIG. 8. DETAILED DESCRIPTION
[0032] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of the present application.
[0033] It should be understood that the terms "comprising" and "including" as used in the specification and the appended claims indicate the presence of the described features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0034] It should also be understood that the terms used in the present application specification are only for the purpose of describing particular embodiments and are not intended to limit the present application. As used in the present application specification and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly indicates otherwise.
[0035] It should be further understood that the term "and / or" as used in the present application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations thereof, and includes these combinations.
[0036] Please refer to Figure 1 and Figure 2 , Figure 1 A flow schematic diagram of the flow playback-based risk control policy configuration method provided by the embodiment of the present application is shown in FIG. 5. Figure 2An application scenario schematic diagram of the method for configuring a risk control strategy based on traffic playback provided by the embodiments of the present application is shown in FIG. 1. The method for configuring a risk control strategy based on traffic playback is applied in a user terminal 10, and is executed by an application software installed in the user terminal 10. A network connection is established between the user terminal 10 and a processing server 20 to realize transmission of data information. The user terminal 10 is a terminal device for executing the method for configuring a risk control strategy based on traffic playback to perform traffic playback-based analysis and intelligently configure a risk control strategy, such as a desktop computer, a notebook computer, a tablet computer, or a mobile phone, etc. The processing server 20 is a server end for processing traffic data to realize corresponding business handling, such as a server constructed by an enterprise or a government department. As shown in FIG. 1, the method comprises steps S110-S160. Figure 1
[0037] S110, if a policy configuration request is received, obtaining target event data corresponding to the policy configuration request from a pre-stored historical event data table.
[0038] If a policy configuration request is received, event data corresponding to the policy configuration request is obtained from a pre-stored historical event data table. The user can send a policy configuration request to the user terminal, and the user can be a risk control management personnel of an enterprise. The user terminal is configured with a historical event data table, which is a data table for storing event data information of the enterprise. The user terminal can integrate event data through a message queue, a library table synchronization, or a file upload mode. Each piece of event data is data information obtained by a corresponding record of a historical business event received by the enterprise from a client, such as a business handling request sent by a client to an enterprise server through a client. The policy configuration request is request information input by the user for configuring a risk control strategy.
[0039] In an embodiment, as shown in FIG. 1, step S110 comprises sub-steps S111 and S112. Figure 3
[0040] S111, generating a corresponding filtering condition according to data filtering information of the policy configuration request.
[0041] Specifically, the policy configuration request contains data filtering information, and a corresponding filtering condition can be generated based on the data filtering information. The data filtering information is information configured by the user for filtering event data.
[0042] For example, if the data filtering information is data within 3 years, the corresponding filtering condition can be generated according to the data filtering information: generation time = A time point to B time point, where B time point is the current time, and A time point is the time corresponding to 3 years ago from the current time. In addition, in addition to the configurable time filtering information, type filtering information and other filtering information can also be configured in the data filtering information.
[0043] S112, sequentially determine whether each event data in the historical event data table satisfies the filtering condition to obtain event data satisfying the filtering condition and determine as target event data.
[0044] Each event data in the historical event data table contains specific information such as generation time and event type, so the specific information in the event data can be used to sequentially determine whether it satisfies the filtering condition, and if it satisfies, the event data is determined as target event data.
[0045] S120, parse the risk control configuration strategy in the policy configuration request to obtain corresponding feature index item information therefrom.
[0046] The policy configuration request contains the risk control configuration strategy configured by the user, and the risk control configuration strategy can be parsed to obtain the feature index item information. Specifically, the risk control configuration strategy is composed of multiple risk control rules, each of which involves risk control verification on a data value corresponding to an index, or combined risk control verification on multiple data values corresponding to multiple indexes. The feature index item information can be obtained by obtaining the corresponding index information from each risk control rule included in the risk control configuration strategy. Each risk control rule is embodied as a program segment, and the content included in the program segment can be parsed to obtain the index information. First, specific punctuation symbols (such as (, ), <, >, etc.) in the program segment are filtered out, and the keywords in the remaining program content are split to obtain the independent keywords included therein, such as splitting based on the space between two keywords. According to the current running program, a corresponding program code set is obtained, which includes code keywords of a specific type of program, such as a java program code set that includes code keywords required for java programming, wherein the code keywords such as int, char, string represent basic meaning keywords, and a C++ program code set that includes code keywords required for C programming. Each independent keyword of the program segment is matched with the code keywords of the program code set, and the independent keywords matched with the program code set are deleted, and the remaining code content is the index information, which is usually a feature word defined by the program developer and distinguished from the code keywords, such as "user_post_AL001" and other feature words defined or synthesized by the program developer.
[0047] In an embodiment, as shown in Figure 4 S1201 is further included before S120.
[0048] S1201, updating the pre-stored historical risk control policy according to the rule update information in the policy configuration request to obtain a corresponding risk control configuration policy.
[0049] Specifically, if the risk control configuration policy is not included in the policy configuration request, the rule update information can be configured in the policy configuration request, and the historical risk control policy is pre-stored in the user terminal. The historical risk control policy is the policy information obtained by recording the previous risk control policy. The risk control rules contained in the historical risk control policy can be updated by the rule update information, thereby obtaining the risk control configuration policy. Specifically, the rule update information includes rule deletion information, rule addition information, and rule parameter adjustment information. The risk control rules corresponding to the rule screening information in the historical risk control policy can be deleted according to the rule deletion information. The risk control rules contained in the historical risk control policy can be updated by adding the newly added risk control rules generated according to the rule addition information. The risk control rules also include parameters such as indicators, thresholds, and range intervals. The parameters of the risk control rules in the historical risk control policy can be adjusted according to the parameter adjustment information. The historical risk control policy after the configuration update is used as the corresponding risk control configuration policy for subsequent processing.
[0050] S130, performing index playback arrangement on the target event data according to the feature index item information to obtain event feature index information corresponding to the feature index item information.
[0051] According to the feature index item information, the target event data is arranged by index playback to obtain event feature index information corresponding to the feature index item information. The target event data contains data values corresponding to multiple index items, and the index items contained in the feature index item information may not exist in the index items of the target event data. That is, the data values corresponding to part of the index items in the feature index item information cannot be directly obtained from the target event data, and part of the context information in the target event data needs to be expanded to obtain the data values. That is, the target event data can be arranged by index playback according to the index items contained in the feature index item information, thereby arranging the event feature index information corresponding to the feature index item information. The event feature index information contains complete data values corresponding to each index item contained in the feature index item information.
[0052] In an embodiment, as shown in Figure 5 S130 includes sub-steps S131, S132, S133, and S134.
[0053] S131, obtain the basic index information corresponding to each event data from the target event data; S132, obtain the corresponding dependent index from the feature index item information according to the basic index information.
[0054] Specifically, each index item in the target event data is taken as a basic index item, and the basic index information corresponding to each event data and all basic index items is obtained. Non-basic index items can be obtained from the feature index item information according to the basic index information and determined as corresponding dependent indexes.
[0055] S133, index playback is performed on the basic index information of each event data according to the dependent index to obtain the dependent index information corresponding to each event data.
[0056] The basic index information can be played back based on the generation time of the event data and the dependent index. The basic index information of the event data whose generation time is located in the corresponding time period can be obtained based on the corresponding limit condition of the dependent index, so as to reconstruct the dependent index information corresponding to the dependent index. The reconstruction process can be further processed based on the existing context data in the event data, and more index information can be derived based on the original basic index information.
[0057] For example, a dependent index is "transaction number of the same mobile phone in 30 days", and the corresponding limit condition is the event data of the same mobile phone and whose generation time is within 30 days. The basic index information of all event data in the target event data is played back according to the limit condition to obtain the event data satisfying the limit condition, and the dependent index information corresponding to the dependent index is obtained by sorting, and the corresponding dependent index information can be filled into all event data associated with the mobile phone.
[0058] In addition, before the index playback of the basic index information according to the dependent index, it can be judged whether the dependent index information corresponding to the dependent index is stored in the user terminal. If the corresponding dependent index information is stored, the known dependent index information can be filled back into the event data, so as to solve the problem of missing part of the dependent index information, and the remaining other dependent indexes adopt the index playback mode to obtain the corresponding dependent index information.
[0059] S134, integrate the basic index information and the dependent index information corresponding to each event data to obtain the event feature index information corresponding to the target event data.
[0060] Each event data can obtain a corresponding dependent index information, so the basic index information and the dependent index information corresponding to the same event data can be integrated to obtain the integrated information corresponding to each event data in the target event data as the event feature index information.
[0061] In an embodiment, as shown in Figure 6 S1331 is further included before S133.
[0062] S1331, generating time index information according to the generation time of each event data and adding it to the basic index information.
[0063] To facilitate the playback arrangement of event data based on the generation time of event data, corresponding time index information can be generated based on the generation time and added to the basic index information of each event data. Then, based on the basic index information of each time data, the basic index information of event data can be played back and arranged in a sliding time window manner. Specifically, the time index information of event data can be packed into the transaction context at the position where the basic index information of event data is first processed. When subsequent playback arrangement is performed, the time information is processed and the corresponding dependent index information is obtained through the sliding time window manner. The playback arrangement through the sliding time window manner can greatly improve the playback efficiency and improve the processing speed of the user terminal.
[0064] For example, there are 3 transactions (3 event data) occurring at 1st second, 3rd second and 7th second of the day, and there is a risk control rule that: if the number of transactions within 5 seconds is greater than or equal to 3, the abnormal high-frequency transaction will be intercepted. Because the system speed is very fast during playback, it is extremely possible to play back the 3 transactions occurring within 6 seconds within 1 second. If the usual transaction-by-transaction playback processing is performed, the user terminal will judge that 3 transactions are completed within 1 second, and the above risk control rule will be triggered incorrectly. To avoid the above problem of incorrect triggering, the usual processing method is to suspend and wait until the time window and the transaction occurrence are consistent, but this will cause the playback processing time to be equal to the time span of event data (for example, if the time span of event data is 3 years, the playback processing will take 3 years, which is obviously impossible in reality). By using the above technical method in the present case to generate time index information and using the sliding time window and the time index information of event data to play back and arrange the corresponding information of event data, the time index information is packed into the transaction context at the position where the transaction is first processed, that is, the time index information of the first transaction is used as the starting time of the time window. When the subsequent transactions are played back, the time window is directly calculated through the time index information (such as the time index information of the above 3 transactions) to include the event data within the sliding window (the sliding window is 5 seconds after the occurrence of the first transaction at this time) and accumulate the traffic, thereby greatly improving the efficiency of playing back and arranging the data.
[0065] S140, replay verification is performed on the event characteristic index information corresponding to the target event data according to the risk control configuration strategy to obtain a replay result corresponding to the risk control configuration strategy.
[0066] According to the risk control configuration strategy, the event index item information corresponding to the target event data is replayed to obtain a replay result corresponding to the risk control configuration strategy. According to the risk control rules contained in the risk control configuration strategy, the event characteristic index information corresponding to the target event data is replayed, and the event characteristic index information of each event data is verified by each risk control rule to verify whether each event data meets the risk control rule, so as to verify the replay result corresponding to the risk control configuration strategy. If a certain event data does not meet a certain risk control rule, the event data needs to be intercepted according to the risk control rule; otherwise, the event data is not intercepted, and the replay result contains the judgment information of whether each event data should be intercepted according to each risk control rule.
[0067] In an embodiment, as shown in Figure 7 Step S140 includes sub-steps S141, S142, S143, S144 and S145.
[0068] S141, the event characteristic index information of the target event data and the event data with the longest time interval is stored in the preset cache database.
[0069] First, the event characteristic index of the event data with the longest time interval in the target event data is obtained and stored in the cache database. The cache database is a database used for caching the event characteristic index information of the event data in the user terminal. Due to the mass data storage problem, the cold and hot backup technology is used, so that only hot data in a short time can be saved in the cache database (high-speed time sequence database or column list storage database). The data for a longer time is cold backed up in the form of a file. When needed, the form of processing while loading can be used, and in the process of index replay arrangement, the form of processing while loading can also be used.
[0070] For example, the time span of the event data in the target event data is 3 years, and the cache database can accommodate up to 3 months of hot data. Therefore, each group of event data corresponds to a time span of 1 month, and the event characteristic index information of three groups of event data with a time interval of 35 months, 34 months and 33 months is obtained and stored in the cache database.
[0071] S142, according to the risk control configuration strategy, the event characteristic index information of the event data with the longest time interval in the cache database is replayed to obtain corresponding verification information.
[0072] According to each risk control rule in the risk control configuration strategy, the event characteristic index information of the event data set with the longest time interval from the current time interval is verified, for example, the event characteristic index information of the event data set with 35 months from the current time interval is verified first.
[0073] S143, determining whether the target event data set has a next event data set; S144, if the target event data set has a next event data set, loading the event characteristic index information of the next event data set into the cache database, and returning to the step of verifying the event characteristic index information of the event data set with the longest time interval from the current time interval in the cache database according to the risk control configuration strategy to obtain corresponding verification information.
[0074] Determine whether the target event data set has a next event data set, for example, if the cache database stores the event characteristic index information of three event data sets with 35 months, 34 months and 33 months from the current time interval, determine whether the target event data set has an event data set with 32 months from the current time interval. If so, delete the data with 35 months from the current time interval in the cache database, load the event characteristic index information of the event data set with 32 months from the current time interval, and repeat the above step S142. At this time, the event characteristic index information of the event data set with 34 months from the current time interval in the cache database can be verified.
[0075] S145, if the target event data set does not have a next event data set, repeat the step of verifying the event characteristic index information of the event data set with the longest time interval from the current time interval in the cache database according to the risk control configuration strategy to obtain corresponding verification information until the event characteristic index information of each event data set in the cache database is verified.
[0076] If the target event data set does not have a next event data set, repeat the above step S142 until the event characteristic index information of each event data set in the cache database is verified.
[0077] S150, comparing the replay result according to the preset comparison verification rule to obtain a comparison verification result of whether the replay result passes the verification.
[0078] According to the preset comparison verification rule, the replay result is compared and verified to obtain a comparison verification result of whether the replay result passes the verification. The replay result includes verification information corresponding to each risk control rule in the risk control configuration strategy, so each risk control rule verification information can be compared and verified according to the comparison verification rule, thereby obtaining a comparison verification result of whether the replay result passes the verification.
[0079] In an embodiment, as shown in Figure 8 Step S150 includes sub-steps S151, S152 and S153.
[0080] S151, sample statistics is performed on the replay result according to the statistical items of the comparison verification rule and the sample label information of the event data in the target event data, to obtain sample statistical information corresponding to each risk control rule in the risk control configuration strategy.
[0081] Specifically, all or part of the event data in the target event data further contains sample label information, which is label information marking the sample type of the event data. The sample label information is a positive sample or a negative sample, and the sample label information of the event data can be added by artificial means. Based on the sample label information of the event data, sample statistics can be performed on the replay result to obtain sample statistical information corresponding to each risk control rule. Specifically, the event data intercepted by each risk control rule can be obtained, and the proportion of positive samples in all event data containing sample label information intercepted by each risk control rule can be determined to obtain the effectiveness of each risk control rule. The ratio of the proportion of event data intercepted by each risk control rule to the proportion of positive samples can be obtained to obtain the disturbance rate of each risk control rule. The sample statistical information corresponding to each risk control rule at least contains the effectiveness and the disturbance rate.
[0082] S152, the sample statistical information is calculated according to the comparison calculation formula in the comparison verification rule to obtain a comparison calculation value corresponding to each risk control rule.
[0083] According to the comparison calculation formula, the sample statistical information of each risk control rule is calculated respectively to obtain a comparison calculation value corresponding to each risk control rule. Specifically, the comparison calculation formula can be represented by formula (1):
[0084] D=a s1 +ln(s2) (1);
[0085] Wherein, s1 is the effectiveness in any sample statistical information, s2 is the disturbance rate in the same sample statistical information, and a is the coefficient value in the formula and a>1.
[0086] S153, it is judged whether each comparison calculation value is greater than the comparison threshold value in the comparison verification rule to obtain a comparison verification result of whether to pass the verification.
[0087] The comparison threshold value is further configured in the comparison verification rule. It can be judged whether each comparison calculation value is greater than the comparison threshold value. If they are all greater than the comparison threshold value, the comparison verification result of passing the verification is obtained. If they are not all greater than the comparison threshold value, the comparison verification result of not passing the verification is obtained. Through the comparison threshold value, it can be verified whether the risk control configuration strategy configured is in line with the expectation.
[0088] If the comparison verification result is not passed, the comparison verification result is fed back.
[0089] The user can view the comparison verification result through the user terminal, and filter the risk control rules configured in the risk control configuration strategy or adjust the parameters in the risk control rules according to the comparison verification result, so as to input the adjusted risk control configuration rules into the user terminal again for playback again.
[0090] S160, if the comparison verification result is passed, the risk control configuration strategy is configured into the data processing server.
[0091] If the comparison verification result is passed, the risk control configuration strategy is configured into the data processing server. If the comparison verification result is passed, the risk control configuration strategy is configured. Specifically, the data processing server is configured with a risk control module, the data processing server can receive a business handling request from the client and perform real-time data processing, the risk control module is a module for detecting the risk control of the business handling request, the risk control configuration strategy is configured into the risk control module of the processing server, that is, the risk control configuration strategy is put into production online, and then the data processing server can detect and intercept the business handling request based on the risk control configuration strategy configured in the risk control module, so as to ensure that the risk control module timely and effectively completes the configuration of the risk control configuration strategy.
[0092] The technical method in the application can be applied to the application scene of intelligent configuration of risk control strategy based on traffic playback analysis, thereby promoting the construction of smart city.
[0093] In the risk control strategy configuration method based on traffic playback provided in the embodiment of the application, target event data corresponding to the received strategy configuration request is obtained, the risk control configuration strategy in the strategy configuration request is analyzed to obtain feature index item information, the target event data is arranged according to the index playback to obtain corresponding event feature index information according to the feature index item information, the playback result is obtained by performing playback verification on the event feature index information according to the risk control configuration strategy, and further comparison verification is performed to obtain a comparison verification result. If the comparison verification result is passed, the risk control configuration strategy is configured into the data processing server. Through the above method, traffic data playback can be performed based on the risk control strategy before the risk control strategy is configured. The reliability of the risk control strategy is compared and verified through the playback process of the traffic data, and the configuration of the risk control strategy is timely and effectively completed according to the verification result, which greatly improves the configuration efficiency of the risk control strategy.
[0094] The embodiment of the present application also provides a flow playback-based risk control strategy configuration device, which can be configured in a user terminal and is used for executing any embodiment of the flow playback-based risk control strategy configuration method. Specifically, refer to Figure 9 , Figure 9 The flow playback-based risk control strategy configuration device provided by the embodiment of the present application is shown in a schematic block diagram.
[0095] As shown in Figure 9 , the flow playback-based risk control strategy configuration device 100 comprises a target event data acquisition unit 110, a feature index item information acquisition unit 120, an event feature index information acquisition unit 130, a playback result acquisition unit 140, a comparison verification result acquisition unit 150 and a strategy configuration unit 160.
[0096] The target event data acquisition unit 110 is used for acquiring target event data corresponding to a strategy configuration request from a pre-stored historical event data table if the strategy configuration request is received.
[0097] In a specific embodiment, the target event data acquisition unit 110 comprises a subunit: a screening condition generation unit, which is used for generating corresponding screening conditions according to data screening information of the strategy configuration request; and an event data screening unit, which is used for judging whether each event data in the historical event data table meets the screening conditions in sequence to acquire event data meeting the screening conditions and determine the event data as target event data.
[0098] The feature index item information acquisition unit 120 is used for analyzing a risk control configuration strategy in the strategy configuration request to acquire corresponding feature index item information therefrom.
[0099] In a specific embodiment, the flow playback-based risk control strategy configuration device 100 further comprises a subunit: a configuration update unit, which is used for performing configuration update on pre-stored historical risk control strategies according to rule update information in the strategy configuration request to acquire corresponding risk control configuration strategies.
[0100] The event feature index information acquisition unit 130 is used for performing index playback arrangement on the target event data according to the feature index item information to acquire event feature index information corresponding to the feature index item information.
[0101] In an embodiment, the event feature index information obtaining unit 130 comprises sub-units: a basic index information obtaining unit, configured to obtain basic index information corresponding to each event data from the target event data; a dependent index obtaining unit, configured to obtain dependent index corresponding to the feature index item information according to the basic index information; an index playback processing unit, configured to perform index playback on the basic index information of each event data according to the dependent index, to obtain dependent index information corresponding to each event data; and an index information integrating unit, configured to integrate the basic index information and the dependent index information corresponding to each event data, to obtain event feature index information corresponding to the target event data.
[0102] In an embodiment, the event feature index information obtaining unit 130 further comprises a time index information adding unit, configured to generate time index information corresponding to each event data according to the generation time of each event data and add the time index information to the basic index information.
[0103] The playback result obtaining unit 140 is configured to perform playback verification on the event feature index information corresponding to the target event data according to the risk control configuration strategy, to obtain a playback result corresponding to the risk control configuration strategy.
[0104] In an embodiment, the playback result obtaining unit 140 comprises sub-units: an information caching unit, configured to store event feature index information of a plurality of groups of event data with the longest time interval from the target event data to a preset cache database; a verification information obtaining unit, configured to perform playback verification on the event feature index information of a group of event data with the longest time interval from the cache database according to the risk control configuration strategy, to obtain corresponding verification information; a judging unit, configured to judge whether there is a next group of event data from the target event data; an information loading unit, configured to, if there is a next group of event data from the target event data, load event feature index information of the next group of event data to the cache database, and return to perform the step of performing playback verification on the event feature index information of a group of event data with the longest time interval from the cache database according to the risk control configuration strategy, to obtain corresponding verification information; and a return executing unit, configured to, if there is no next group of event data from the target event data, repeatedly perform the step of performing playback verification on the event feature index information of a group of event data with the longest time interval from the cache database according to the risk control configuration strategy, to obtain corresponding verification information, until the event feature index information of each group of event data in the cache database is completed.
[0105] The comparison verification result acquisition unit 150 is configured to perform comparison verification on the playback result according to a preset comparison verification rule to obtain a comparison verification result of whether the playback result passes the verification.
[0106] In an embodiment, the comparison verification result acquisition unit 150 comprises a sample statistical information acquisition unit configured to perform sample statistics on the playback result according to a statistical item of the comparison verification rule and sample label information of event data in the target event data to obtain sample statistical information corresponding to each risk control rule in the risk control configuration strategy; a comparison calculation value acquisition unit configured to calculate the sample statistical information according to a comparison calculation formula in the comparison verification rule to obtain a comparison calculation value corresponding to each risk control rule; and a verification result acquisition unit configured to determine whether each comparison calculation value is greater than a comparison threshold in the comparison verification rule to obtain a comparison verification result of whether the verification passes.
[0107] The strategy configuration unit 160 is configured to configure the risk control configuration strategy to a data processing server if the comparison verification result passes.
[0108] The risk control strategy configuration device based on traffic playback provided in the embodiments of the present application applies the above-mentioned risk control strategy configuration method based on traffic playback, obtains target event data corresponding to an accepted strategy configuration request, parses a risk control configuration strategy in the strategy configuration request to obtain feature index item information, performs index playback arrangement on the target event data according to the feature index item information to obtain corresponding event feature index information, performs playback verification on the event feature index information according to the risk control configuration strategy to obtain a playback result and further performs comparison verification to obtain a comparison verification result, and configures the risk control configuration strategy to a data processing server if the comparison verification result passes. Through the above-mentioned method, traffic data playback can be performed based on the risk control strategy before the risk control strategy configuration, the reliability of the risk control strategy is compared and verified through the traffic data playback process, and the configuration of the risk control strategy is completed in time and effectively according to the verification result, which greatly improves the configuration efficiency of the risk control strategy.
[0109] The above-mentioned risk control strategy configuration device based on traffic playback can be realized in the form of a computer program, which can run on a computer device as shown in Figure 10 .
[0110] Please refer to Figure 10 , Figure 10 is a schematic block diagram of a computer device provided in the embodiments of the present application. The computer device can be a user terminal for executing the risk control strategy configuration method based on traffic playback to realize intelligent configuration of the risk control strategy based on traffic playback analysis.
[0111] Please refer toFigure 10 The computer device 500 includes a processor 502, a memory, and a network interface 505 connected through a system bus 501, wherein the memory can include a storage medium 503 and an internal memory 504.
[0112] The storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032, when executed, can cause the processor 502 to perform the method for configuring a risk control strategy based on traffic playback, wherein the storage medium 503 can be a volatile storage medium or a non-volatile storage medium.
[0113] The processor 502 is configured to provide computing and control capabilities to support the operation of the entire computer device 500.
[0114] The internal memory 504 provides an environment for the execution of the computer program 5032 in the storage medium 503, and the computer program 5032, when executed by the processor 502, can cause the processor 502 to perform the method for configuring a risk control strategy based on traffic playback.
[0115] The network interface 505 is configured to perform network communication, such as providing transmission of data information, etc. Those skilled in the art can understand that Figure 10 The structure shown in FIG. 5 is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device 500 to which the scheme of the present application is applied. Specifically, the computer device 500 can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0116] The processor 502 is configured to run the computer program 5032 stored in the memory to implement the corresponding functions in the method for configuring a risk control strategy based on traffic playback described above.
[0117] Those skilled in the art can understand that Figure 10 The embodiments of the computer device shown in FIG. 5 do not constitute a limitation on the specific structure of the computer device. In other embodiments, the computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement. For example, in some embodiments, the computer device can only include a memory and a processor, and in such embodiments, the structure and functions of the memory and the processor are consistent with those of the embodiments shown in FIG. 5, and will not be described here. Figure 10
[0118] It should be understood that, in the embodiments of the present application, the processor 502 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.
[0119] In another embodiment of the present application, a computer readable storage medium is provided. The computer readable storage medium can be a volatile or non-volatile computer readable storage medium. The computer readable storage medium stores a computer program, wherein the computer program is executed by a processor to implement the steps included in the traffic playback-based risk control policy configuration method described above.
[0120] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the devices, apparatuses and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be described here. Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been described in a general manner in the foregoing description. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0121] In several embodiments provided by the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic, for example, the division of the units is merely logical function division, and actual implementation can have another division manner, or units with the same function can be combined into one unit, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can also be electrical, mechanical or other form of connection.
[0122] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one place, or they may be distributed to multiple network units. Part or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of the present application.
[0123] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0124] The integrated unit, if realized in the form of a software functional unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part of the prior art that contributes to the present application, or all or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a computer readable storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned computer readable storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a magnetic disk or an optical disk, and various program code storage media.
[0125] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for configuring risk control strategies based on traffic replay, characterized in that, The method is applied in a user terminal, wherein a network connection is established between the user terminal and a data processing server to realize the transmission of data information, and the method includes: If a policy configuration request is received, retrieve the target event data corresponding to the policy configuration request from the pre-stored historical event data table; Parsing the risk control configuration strategy in the strategy configuration request to obtain the corresponding feature indicator information includes: parsing the content of the program segment corresponding to each risk control rule in the risk control configuration strategy to obtain indicator information, and the indicator information corresponding to each risk control rule is the feature indicator information. The steps for obtaining the indicator information include: filtering out specific punctuation marks in the program segment; splitting the keywords in the remaining program content of the program segment to obtain the independent keywords contained therein; obtaining the corresponding program code set according to the currently running program; matching each independent keyword of the program segment with the code keywords of the program code set in turn; deleting the independent keywords that match the program code set; and the remaining code content is the corresponding indicator information. Based on the feature indicator information, the target event data is replayed and organized to obtain event feature indicator information corresponding to the feature indicator information. According to the risk control configuration strategy, the event feature index information corresponding to the target event data is replayed and verified to obtain the replay result corresponding to the risk control configuration strategy; The playback results are compared and verified according to preset comparison and verification rules to obtain a comparison and verification result indicating whether the playback results pass the verification. If the comparison and verification result is successful, the risk control configuration strategy will be configured in the data processing server.
2. The risk control strategy configuration method based on traffic replay according to claim 1, characterized in that, The step of retrieving the target event data corresponding to the policy configuration request from the pre-stored historical event data table includes: Generate corresponding filtering conditions based on the data filtering information requested in the strategy configuration request; The system sequentially determines whether each event data in the historical event data table meets the filtering conditions, thereby obtaining event data that meets the filtering conditions and identifying it as the target event data.
3. The risk control strategy configuration method based on traffic replay according to claim 1, characterized in that, Before parsing the risk control configuration strategy in the strategy configuration request to obtain the corresponding feature indicator information, the process also includes: The pre-stored historical risk control strategies are updated according to the rule update information in the strategy configuration request to obtain the corresponding risk control configuration strategy.
4. The risk control strategy configuration method based on traffic replay according to claim 1, characterized in that, The step of performing indicator replay and organization on the target event data based on the feature indicator item information to obtain event feature indicator information corresponding to the feature indicator item information includes: Obtain the basic indicator information corresponding to each event data from the target event data; Based on the basic indicator information, the corresponding dependent indicators are obtained from the feature indicator item information; Based on the dependency metrics, the basic metric information of each event data is replayed to obtain the dependency metric information corresponding to each event data. The basic indicator information and dependent indicator information corresponding to each event data are integrated to obtain the event feature indicator information corresponding to the target event data.
5. The risk control strategy configuration method based on traffic replay according to claim 4, characterized in that, Before performing indicator replay on the basic indicator information of each event data based on the dependency indicator to obtain the dependency indicator information corresponding to each event data, the method further includes: Based on the generation time of each event data, corresponding time indicator information is generated and added to the basic indicator information.
6. The risk control strategy configuration method based on traffic replay according to claim 1, characterized in that, The step of replaying and verifying the event feature index information corresponding to the target event data according to the risk control configuration strategy to obtain the replay result corresponding to the risk control configuration strategy includes: The event feature index information of the multiple sets of event data with the longest time interval between the target event data and the current data is obtained and stored in a preset cache database; Based on the risk control configuration strategy, the event characteristic index information of the set of event data with the longest time interval between the cache database and the current time is replayed and verified to obtain the corresponding verification information; Determine whether the target event data exists in the subsequent set of event data; If the target event data has a subsequent set of event data, the event feature index information of the subsequent set of event data is obtained and loaded into the cache database, and the step of replaying and verifying the event feature index information of the set of event data with the longest time interval between the cache database and the current data according to the risk control configuration strategy to obtain the corresponding verification information is returned. If the target event data does not have a subsequent set of event data, repeat the step of replaying and verifying the event feature index information of the set of event data with the longest time interval between the cache database and the current data according to the risk control configuration strategy to obtain the corresponding verification information until the event feature index information of each set of event data in the cache database has been replayed and verified.
7. The risk control strategy configuration method based on traffic replay according to claim 1, characterized in that, The step of comparing and verifying the playback result according to preset comparison and verification rules to obtain a comparison and verification result indicating whether the playback result passes verification includes: Based on the statistical items of the comparison and verification rules and the sample label information of the event data in the target event data, the playback results are statistically analyzed to obtain the sample statistical information corresponding to each risk control rule in the risk control configuration strategy. The statistical information of the sample is calculated according to the comparison calculation formula in the comparison verification rule to obtain the comparison calculation value corresponding to each risk control rule; Determine whether each of the calculated comparison values is greater than the comparison threshold in the comparison verification rule to obtain the comparison verification result of whether the verification is passed.
8. A risk control strategy configuration device based on traffic replay, characterized in that, The device is configured in a user terminal, and the user terminal establishes a network connection with a data processing server to realize the transmission of data information. The device includes: The target event data acquisition unit is used to acquire target event data corresponding to the policy configuration request from a pre-stored historical event data table if a policy configuration request is received. The feature indicator information acquisition unit is used to parse the risk control configuration strategy in the strategy configuration request to obtain the corresponding feature indicator information, including: parsing the content of the program segment corresponding to each risk control rule contained in the risk control configuration strategy to obtain indicator information, and the indicator information corresponding to each risk control rule is the feature indicator information. The steps for obtaining the indicator information include: filtering out specific punctuation marks in the program segment; splitting the keywords in the remaining program content of the program segment to obtain the independent keywords contained therein; obtaining the corresponding program code set according to the currently running program; matching each independent keyword of the program segment with the code keywords of the program code set in turn; deleting the independent keywords that match the program code set; and the remaining code content is the corresponding indicator information. An event feature indicator information acquisition unit is used to perform indicator playback and organization on the target event data according to the feature indicator item information, so as to obtain event feature indicator information corresponding to the feature indicator item information. The replay result acquisition unit is used to replay and verify the event feature indicator information corresponding to the target event data according to the risk control configuration strategy, so as to obtain the replay result corresponding to the risk control configuration strategy. The comparison verification result acquisition unit is used to compare and verify the playback result according to the preset comparison verification rules, and obtain the comparison verification result of whether the playback result passes the verification. The strategy configuration unit is used to configure the risk control configuration strategy to the data processing server if the comparison verification result is passed.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the risk control strategy configuration method based on traffic replay as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the risk control strategy configuration method based on traffic replay as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Anti-fraud system tuning production online method and device based on three engines
CN110349015A