Risk control method, risk processing system, device, server and storage medium
By using risk control network models and anomaly analysis technology on e-commerce platforms, the data flow of user request business is processed automatically, solving the problem of the poor effectiveness of traditional risk control methods and achieving more efficient and accurate risk control.
Patent Information
- Application Number
- CN202111391685.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-19
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2041-11-19
AI Technical Summary
Traditional e-commerce platforms have poor risk control methods and are unable to effectively address the security risks of e-commerce platforms.
By acquiring the pending data stream of user request business, inputting it into the risk control network model for risk quantification, and combining anomaly analysis and preset risk control rules, the system automatically acquires business control information and executes corresponding processing.
Automated risk control has been achieved, which has improved the effectiveness of risk control, avoided omissions and miscontrols caused by manual control, and improved the accuracy and timeliness of risk control.
Smart Images

Figure CN114240060B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of risk control of e-commerce, and in particular to a risk control method, a risk processing system, a device, a server and a storage medium. BACKGROUND
[0002] With the rapid development of science and technology, traditional business industry is gradually changing from offline entity business to online electronic business. Although electronic business has the advantage of making transactions more convenient, it lacks the ability to control risks artificially. Security problems are becoming more and more serious with the increasing business scale, and security incidents are also emerging in an endless stream.
[0003] In the traditional technology, in order to deal with the above risks, the e-commerce platform usually adopts one or more of the following countermeasures to realize risk control: (1) constantly adjusting the business process, updating the business process that has been cracked by black production; (2) introducing some black production databases of third parties to intercept the black production that has been identified according to the database; (3) introducing a risk control rule engine to make the business rules changeable and not easy to be cracked by black production; (4) introducing a risk control model to distinguish between black production and ordinary customers, obtain a risk score and a risk label. However, using the traditional risk control method to realize business risk control will have the problem of poor risk control effect. SUMMARY
[0004] Therefore, it is necessary to provide a risk control method, a risk processing system, a device, a server and a storage medium to solve the above technical problems.
[0005] A risk control method, the method comprising:
[0006] obtaining a to-be-processed data stream of a user request business;
[0007] inputting the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, and performing abnormal analysis on the to-be-processed data stream to obtain a second risk quantification result;
[0008] obtaining business control information through the first risk quantification result, the second risk quantification result and a preset risk control rule;
[0009] performing corresponding processing on the user request business according to the business control information.
[0010] In one embodiment, the method further comprises:
[0011] determining a comprehensive risk quantification result through the first risk quantification result, a first weight, the second risk quantification result and a second weight;
[0012] The business control information is obtained by the comprehensive risk quantification result and the preset risk control rule.
[0013] In one of the embodiments, the abnormality analysis includes at least two of parameter verification, fingerprint comparison, cross comparison, and correlation analysis.
[0014] In one of the embodiments, the preset risk control rule includes a preset risk quantification threshold, and the business control information is obtained by the comprehensive risk quantification result and the preset risk control rule, including:
[0015] If the comprehensive risk quantification result is greater than the preset risk quantification threshold, the business control result is output as first prompt information; the first prompt information is used to prompt the user of relevant information that the user request has been intercepted.
[0016] In one of the embodiments, the business control information is obtained by the comprehensive risk quantification result and the preset risk control rule, including:
[0017] The preset risk control rule is monitored;
[0018] If the preset risk control rule is updated, the business control information is obtained by the comprehensive risk quantification result and the updated preset risk control rule.
[0019] In one of the embodiments, the method further includes:
[0020] The business transaction data intercepted by the risk control in a preset time is obtained;
[0021] If the business transaction data meets a preset condition, second prompt information is output, and the second prompt information is used to prompt the user whether to modify the preset risk control rule.
[0022] In one of the embodiments, the method further includes:
[0023] The initial risk control network model is trained by a data stream training set to obtain the risk control network model; the data stream training set includes data streams corresponding to different user requests for different services.
[0024] A risk processing system, the system includes: a micro-service cluster, data and storage, and a basic service middleware, wherein the micro-service cluster includes a risk control core service, a data real-time analysis module, and a risk control model service, and the basic service middleware includes a message queue.
[0025] The risk control core service is configured to obtain a to-be-processed data stream of a user request service and send the to-be-processed data stream to the message queue;
[0026] The message queue is configured to send the received to-be-processed data stream to the data real-time analysis module and the risk control model service respectively;
[0027] The risk control model service is configured to input the to-be-processed data stream into a risk control network model, obtain a first risk quantification result, and send the first risk quantification result to the data real-time analysis module;
[0028] The data real-time analysis module is configured to perform abnormality analysis on the to-be-processed data stream, obtain a second risk quantification result, obtain service control information through the first risk quantification result, the second risk quantification result, and a preset risk control rule, and send the service control information to the risk control core service;
[0029] The risk control core service is further configured to perform corresponding processing on the user request service according to the service control information.
[0030] In one of the embodiments, the data real-time analysis module is specifically configured to determine a comprehensive risk quantification result through the first risk quantification result, a first weight, the second risk quantification result, and a second weight, and obtain the service control information through the comprehensive risk quantification result and the preset risk control rule.
[0031] In one of the embodiments, the micro-service cluster further includes a risk control model management terminal service and a risk control rule engine service;
[0032] The risk control model management terminal service is configured to configure the risk control network model, send the risk control network model to the risk control model service, and control running of the risk control network model in the risk control model service;
[0033] The risk control rule engine service is configured to configure the preset risk control rule and update the preset risk control rule to obtain an updated preset risk control rule.
[0034] A risk control device, the device comprising:
[0035] A data stream acquisition module configured to obtain a to-be-processed data stream of a user request service;
[0036] A model processing module configured to input the to-be-processed data stream into a risk control network model, obtain a first risk quantification result, and perform abnormality analysis on the to-be-processed data stream to obtain a second risk quantification result;
[0037] The control information obtaining module is configured to obtain service control information by the first risk quantization result, the second risk quantization result, and a preset risk control rule.
[0038] The request service processing module is configured to perform corresponding processing on the user request service according to the service control information.
[0039] A server comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0040] Obtain a to-be-processed data stream of a user request service;
[0041] Input the to-be-processed data stream into a risk control network model to obtain a first risk quantization result, and perform abnormality analysis on the to-be-processed data stream to obtain a second risk quantization result;
[0042] Obtain service control information by the first risk quantization result, the second risk quantization result, and a preset risk control rule;
[0043] Perform corresponding processing on the user request service according to the service control information.
[0044] A storage medium stores a computer program, and the computer program is executed by a processor to implement the following steps:
[0045] Obtain a to-be-processed data stream of a user request service;
[0046] Input the to-be-processed data stream into a risk control network model to obtain a first risk quantization result, and perform abnormality analysis on the to-be-processed data stream to obtain a second risk quantization result;
[0047] Obtain service control information by the first risk quantization result, the second risk quantization result, and a preset risk control rule;
[0048] Perform corresponding processing on the user request service according to the service control information.
[0049] The risk control method, the risk processing system, the device, the server and the storage medium can obtain a to-be-processed data stream of a user's requested service, input the to-be-processed data stream into a risk control network model to obtain a first risk quantization result, perform abnormality analysis on the to-be-processed data stream to obtain a second risk quantization result, obtain service control information through the first risk quantization result, the second risk quantization result and a preset risk control rule, and perform corresponding processing on the user's requested service according to the service control information. The method can automatically control the risk of the user's requested service through a computer process, and does not need human intervention in the control process, thereby improving the effect of risk control. BRIEF DESCRIPTION OF DRAWINGS
[0050] Figure 1 An application system structure diagram of the risk control method in one embodiment;
[0051] Figure 2 A flowchart of the risk control method in one embodiment;
[0052] Figure 3 A flowchart of a method for obtaining service control information in one embodiment;
[0053] Figure 4 A flowchart of a specific method for obtaining service control information in another embodiment;
[0054] Figure 5 A flowchart of a specific method for obtaining abnormal output prompt information of service transaction data in another embodiment;
[0055] Figure 6 A specific structure diagram of the risk processing system in one embodiment;
[0056] Figure 7 A structure block diagram of the risk control device in one embodiment;
[0057] Figure 8 An internal structure diagram of the server in one embodiment. DETAILED DESCRIPTION
[0058] In order to make the objects, technical solutions and advantages of the present application clearer, further detailed description will be given to the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.
[0059] The risk control method provided by the present application can be applied to Figure 1The illustrated risk processing system includes a microservice cluster, data and storage, and basic service middleware, and the microservice cluster, data and storage, and basic service middleware communicate through interfaces.
[0060] In one embodiment, as Figure 2 illustrated, a risk control method is provided, which is applied to the risk processing system in Figure 1 for example, and includes the following steps:
[0061] S100, obtaining a to-be-processed data stream of a user request service.
[0062] Specifically, the user request service can be a mall service. The user can open an e-commerce mall on the client, and then input a mall service request for different goods on the e-commerce mall. The risk control core service receives the mall service request and responds to the mall service request to obtain the risk control data stream corresponding to the mall service request. The risk control data stream can be a part of the data stream corresponding to the mall service request. Further, the risk control core service can send a risk control request and a risk control data stream to the risk processing system to allow the risk processing system to perform risk control processing on the risk data stream. The to-be-processed data stream can be a risk control data stream. The goods can be domestic goods or overseas goods. The user request can be any request for accessing the e-commerce mall, such as a registration request, an order request, a coupon request, a browsing request, a payment request, a return request, a reservation request, a delivery reminder request, etc. The user request service can be a business client corresponding to these user requests. In the registration scenario, the user needs to register a real identity, so a corresponding registration request needs to be input, and it can also be a registration request in other business scenarios. The client can be various personal computers, notebook computers, smartphones, tablet computers, and other electronic devices that can log in to the e-commerce mall. The e-commerce mall can be Taobao, Jingdong, Amazon, Pinduoduo, etc. The input method of the user request can be mouse triggering, voice input, touch screen touch input, etc.
[0063] It can be understood that when the user logs in to the e-commerce platform on the client side, the risk processing system can receive the login data of the user, and combine the login data and the business data stream into a Java object to obtain a to-be-processed data stream. The login data can be fingerprint data of the user, and can also be other identity data. For example, if the user request is a order request, the business data stream can be a combination of order number, user name, user mobile phone number, order time, order amount, product number, coupon discount amount, and / or delivery address, etc. corresponding to the successful order request; the business data stream corresponding to the coupon request can be a combination of coupon number, coupon time, coupon quantity, and / or discount amount, etc. Since the data types contained in the business data streams corresponding to different user requests are different, after obtaining the business data streams corresponding to different business scenarios, the business data stream can be first converted into a unified type of data stream, that is, all data types under different business scenarios are included, the data types not under the current business scenario can be set to null, and then the login data and the converted business data stream are combined into a Java object to obtain a to-be-processed data stream.
[0064] S200, inputting the to-be-processed data stream into the risk control network model to obtain a first risk quantification result, and performing abnormal analysis on the to-be-processed data stream to obtain a second risk quantification result.
[0065] Specifically, the above risk control network model can be a pre-trained deep learning network model, which can be a convolutional neural network model, a recurrent neural network model, an adversarial neural network model, etc., and can also be a combination of multiple neural network models. The first risk quantification result output by the risk control network model can be a risk score, which can be equal to any value between 0 and 1. The above abnormal analysis can be understood as a data analysis and processing process, which can be abnormal data extraction and processing, risk type detection processing, etc., and can also be a combination of multiple processes. The second risk quantification result can also be a risk score, which can be equal to any value between 0% and a capped value. The first risk quantification result and the second risk quantification result can be stored in the risk library. The capped value can be determined by how many risks in the risk library are triggered by the to-be-processed data stream, that is, the scores corresponding to the triggered risks are added together.
[0066] S300, obtaining business control information through the first risk quantification result, the second risk quantification result, and a preset risk control rule.
[0067] Specifically, the risk processing system can perform mapping operation on the first risk quantification result, the second risk quantification result and the preset risk control rule to map the second risk quantification result to a range of 0 to 1, and obtain the service control information. The mapping operation can be a combination of four arithmetic operations, exponential operation, logarithmic operation, etc. The service control information can be information related to whether a service can continue to be executed.
[0068] S400, performing corresponding processing on the user requested service according to the service control information.
[0069] Specifically, the risk processing system can control the user requested service to continue to be executed or control the user requested service to be intercepted according to the service control information. The interception processing can be understood as rejecting the user requested service to continue to be executed.
[0070] In the above risk control method, the risk processing system can obtain the to-be-processed data stream of the user requested service, input the to-be-processed data stream into the risk control network model to obtain the first risk quantification result, perform abnormal analysis on the to-be-processed data stream to obtain the second risk quantification result, obtain the service control information through the first risk quantification result, the second risk quantification result and the preset risk control rule, and perform corresponding processing on the user requested service according to the service control information. The method can automatically control the risk of the user requested service through a computer process, and does not need human intervention in the control process, thereby improving the effect of risk control. At the same time, the method is executed by a machine, which can avoid the situation of missed control or mistaken control when controlled by a human, thereby improving the accuracy of risk control and improving the timeliness of risk control.
[0071] As one of the embodiments, as shown in Figure 3 The step of obtaining the service control information through the first risk quantification result, the second risk quantification result and the preset risk control rule in S300 can be implemented by the following steps:
[0072] S310, determining a comprehensive risk quantification result through the first risk quantification result, the first weight, the second risk quantification result and the second weight.
[0073] Specifically, the risk processing system can perform a weighted summation of the first risk quantification result, the first weight, the second risk quantification result, and the second weight to determine the comprehensive risk quantification result. Before the weighted summation, the second risk quantification result can be mapped to a value between 0 and 1. Then, the mapped result of the first risk quantification result, the first weight, the second risk quantification result, and the second weight are weighted summated to determine the comprehensive risk quantification result. The first weight can be the weight coefficient assigned by the risk processing system to the first risk quantification result, and the second weight can be the weight coefficient assigned by the risk processing system to the second risk quantification result. If the first risk quantification result is represented by A, the first weight by a, the second risk quantification result by B, and the second weight by b, then the comprehensive risk quantification result can be equal to A*a + B*b. The sum of the first weight and the second weight equals 1.
[0074] S320. Obtain business control information by combining comprehensive risk quantification results and preset risk control rules.
[0075] Understandably, a risk processing system can obtain business control information by performing calculations based on comprehensive risk quantification results and preset risk control rules. These calculations can include arithmetic operations, exponential operations, logarithmic operations, and combinations thereof.
[0076] The aforementioned risk control method can determine a comprehensive risk quantification result by using the first risk quantification result, the first weight, the second risk quantification result, and the second weight. By combining the comprehensive risk quantification result with preset risk control rules, business control information can be obtained. This method can obtain business control information through machine execution, and further process user request business accordingly using the business control information. This avoids omissions or miscontrols that occur during manual control, improves the accuracy of risk control, and also enhances the timeliness of risk control.
[0077] As one embodiment, the above-mentioned anomaly analysis includes at least two of the following: parameter verification, fingerprint comparison, cross-comparison, and correlation analysis.
[0078] Specifically, the risk processing system can perform at least two of the following analyses on the data stream to be processed: parameter verification, fingerprint comparison, cross-comparison, and correlation analysis, to obtain a second risk quantification result.
[0079] It can be understood that the above parameter verification is a basic verification, which can verify whether the key attribute information such as IP address, geographic location, client physical address and the like exists in the to-be-processed data stream. The above fingerprint comparison can be whether the user equipment fingerprint data is consistent with the fingerprint data pre-stored in the risk library. If not, the second risk quantification result will increase. The above user equipment fingerprint data can be a unique identifier of the user equipment. The above cross comparison can judge the difference degree between the to-be-processed data stream and the pre-stored service data stream in the risk library. The greater the difference degree, the greater the second risk quantification result. The above association analysis can judge whether different to-be-processed data streams at the same time, the same IP address or the same geographic location have a high aggregation relationship. If so, it is likely to be a gang, and the second risk quantification result will also increase. In the embodiment, the to-be-processed data stream must be subjected to parameter verification and fingerprint comparison analysis, and cross comparison and association analysis can be flexibly analyzed according to different business scenarios.
[0080] It can be understood that through the abnormality analysis, it can be determined whether the current user has the conditions of browsing robots, script robots, proxy IP, browser forgery, user equipment fingerprint abnormality, simulator, code debugging (such as JS debugging), cookie loss, client ID loss, client ID forgery, client information fraud, client basic information abnormality and the like. The risk processing system can pre-configure corresponding risk scores for these states. Finally, the risk scores corresponding to all states are added according to the abnormality analysis result to obtain the second risk quantification result.
[0081] The above risk control method can perform abnormality analysis on the to-be-processed data stream to obtain the second risk quantification result, and further perform corresponding processing on the user request service through the second risk quantification result. The method can automatically control the risk of the user request service through the computer process, and does not need human participation in the control process, thereby improving the effect of risk control.
[0082] As one of the embodiments, the preset risk control rule includes a preset risk quantification threshold. In the step S320, the business control information is obtained by comprehensively quantifying the risk and the preset risk control rule. Specifically, if the comprehensive risk quantification result is greater than the preset risk quantification threshold, the business control result is output as the first prompt information. The first prompt information is used to prompt the related information that the user request has been intercepted.
[0083] Specifically, the risk processing system can determine whether the overall risk quantification result exceeds a preset risk quantification threshold. If it does, the system can output a primary warning message to inform the user that their current request has been blocked due to risk. This message can be presented as a view, text, or even a voice announcement. The overall risk quantification result exceeding the preset risk quantification threshold can be a preset risk control rule. The information related to the blocked user request can include network congestion, high activity volume, or requests to try again later.
[0084] Meanwhile, if the risk processing system determines that the overall risk quantification result is less than or equal to the preset risk quantification threshold, the risk processing system will not respond. In other words, the response will time out without outputting any prompts. This result indicates to the user that the current user request does not pose a risk and can continue execution. The overall risk quantification result can also be called the overall risk score.
[0085] The risk handling system is triggered during the business process. Taking a coupon redemption scenario as an example, after a user clicks to redeem a coupon, they wait for the risk handling system to output a comprehensive risk score, which is then compared to a set interception threshold. Assuming the comprehensive risk score is 0.83 and the interception threshold is 0.7, the comprehensive risk score exceeds the threshold, the coupon is not issued to the user, and a "Promotion is too popular" message is displayed. If the risk control response times out, the user's request is considered approved by default. A comprehensive risk score greater than 0.7 represents a preset risk control rule used to determine whether risk control passes. 0.7 is the interception threshold configured in the risk control management service. If the interception rate is too high, this threshold can be lowered to 0.55. In this case, a comprehensive risk score greater than 0.55 represents an updated preset risk control rule. Alternatively, if a single preset risk control rule is too simple, multiple preset risk control rules can be combined to form different new rules. For example, user requests can be blocked by a combination of four rules: a comprehensive risk score greater than 0.55, a coupon number equal to 20210023231533, a redemption time greater than 10:00, and a redemption time less than 11:00.
[0086] The aforementioned risk control method can obtain prompts by combining the results of comprehensive risk quantification and preset risk control rules, so as to promptly remind users of the current execution status of user requests, improve user experience, and at the same time increase the number of visits to the e-commerce platform and increase e-commerce revenue.
[0087] As one example, such as Figure 4 As shown, the step in S320 above, which obtains business control information by combining the comprehensive risk quantification results and preset risk control rules, may include:
[0088] S321, listen to the preset risk control rule.
[0089] Specifically, the risk processing system can listen to the preset risk control rule in real time. The number of preset risk control rules can be greater than or equal to 2. The preset risk control rules can be stored in the risk library. The risk processing system is configured with a Flink message queue, and the Flink Job is used to manage and schedule the execution task of the Flink message queue. A broadcast stream BroadcastStream is set in the Flink Job, and the preset risk control rule is listened to through the BroadcastStream.
[0090] S322, if the preset risk control rule is updated, the business control information is obtained by combining the comprehensive risk quantification result and the updated preset risk control rule.
[0091] Specifically, when the risk processing system listens to the update of the preset risk control rule, it can judge the size relationship of the preset risk quantification threshold in the comprehensive risk quantification result and the updated preset risk control rule, and output the business control information according to the size relationship.
[0092] The above risk control method can listen to the preset risk control rule in real time, and if it is determined that the preset risk control rule is updated, the risk control processing can be realized through the updated preset risk control rule, so as to improve the accuracy of risk control and improve the risk control effect.
[0093] As one of the embodiments, as shown in Figure 5 The above risk control method can further include:
[0094] S500, obtaining the business transaction data blocked by the risk control in a preset time.
[0095] Specifically, the above preset time can be 1 minute, 2 minutes, 5 minutes, etc. However, the time cannot be set too long, and setting the preset time too long may be not conducive to the income of the electronic mall. In this embodiment, the risk processing system can periodically obtain the total number of business transactions corresponding to each business blocked by the risk control in a preset time, that is, the corresponding total number of transactions is obtained every preset time.
[0096] S600, if the business transaction data meets the preset condition, outputting a second prompt information, the second prompt information is used to prompt the user whether to modify the preset risk control rule.
[0097] It can be understood that the risk processing system can determine whether the obtained business transaction data meets the preset condition. If it is determined that the business transaction data meets the preset condition, a second prompt information is outputted to prompt the user that the ratio of being intercepted by the risk control in the current preset time is too high or too low, so that the user considers whether to modify the preset risk control rule to obtain an optimal interception ratio. Whether to modify the preset risk control rule needs to be determined according to the user's will.
[0098] It can be understood that the above-mentioned preset condition can be that the total number of transactions intercepted by the risk control in the preset time is continuously greater than a first preset total transaction threshold or continuously less than a second preset total transaction threshold, and the total number of transactions intercepted by the risk control in the preset time is continuously higher than a first preset percentage of all transaction quantities or continuously higher than a second preset percentage of all transaction quantities. The first preset total transaction threshold and the second preset total transaction threshold can be different and can be set to any value. The first preset percentage and the second preset percentage can also be different and can be set to any percentage. In the embodiment, the first preset total transaction threshold can be 500 or 600, the second preset total transaction threshold can be 5 or 3, the first preset percentage can be set to 10%, and the second preset percentage can be set to 0.5%. The total number of transactions intercepted by the risk control in the preset time is continuously greater than the first preset total transaction threshold, the total number of transactions intercepted by the risk control in the preset time is continuously less than the second preset total transaction threshold, the total number of transactions intercepted by the risk control in the preset time is continuously higher than the first preset percentage of all transaction quantities, and the total number of transactions intercepted by the risk control in the preset time is continuously higher than the second preset percentage of all transaction quantities can be referred to as a preset risk control rule.
[0099] The above-mentioned risk control method can output a prompt information when it is determined that the business transaction data intercepted by the risk control meets the preset condition, to prompt that the current preset risk control rule setting is not good, and remind the user whether to modify the preset risk control rule, so that the user can modify the preset risk control rule in time, and improve the accuracy and risk control effect of risk control.
[0100] As one of the embodiments, before performing the steps in S200, the above-mentioned risk control method can further include: training an initial risk control network model by a data stream training set to obtain a risk control network model; the data stream training set includes data streams corresponding to different user requests for different services.
[0101] Specifically, the risk processing system can train the initial risk control network model through the data stream training set to obtain the risk control network model. This process can be performed before S200, or can be performed before S100, and the execution sequence is not limited in this embodiment. Optionally, the initial risk control network model can be a convolutional neural network model, a recurrent neural network model, an adversarial neural network model, etc., or a combination of multiple neural networks. Optionally, the data stream training set can be a data set obtained by combining data streams corresponding to different user requests for different services. The data stream training set can be pre-stored in the risk library.
[0102] The step of training the initial risk control network model through the data stream training set to obtain the risk control network model can include the following steps: inputting the data stream training set into the initial risk control network model to obtain risk prediction data, calculating the prediction error value between the risk prediction data and the standard risk data through a loss function, updating the initial network parameters in the initial risk control network model according to the prediction error value, and iteratively performing the above training steps until the prediction error value meets the preset error threshold or the number of iterations reaches the preset iteration number threshold, thereby obtaining the risk control network model.
[0103] It should be noted that before the network model training, the network parameters of the initial risk control network model can be initialized, and then the risk processing system can input the data stream training set into the initial risk control network model to obtain the risk prediction data.
[0104] It can be understood that the risk processing system can calculate the prediction error value between the risk prediction data and the standard risk data through the preset loss function to determine whether the prediction error value is within the convergence condition of the end of the iterative training. Optionally, the standard risk data can be actual risk data corresponding to different user requests for different services. Optionally, the preset loss function can be a 0-1 loss function, an absolute value loss function, a log loss function, a square loss function, an exponential loss function, a Hinge loss function, etc., as long as the loss function can ensure good performance of the trained network model, and the execution sequence is not limited in this embodiment.
[0105] It can also be understood that the risk processing system can update the initial network parameters in the initial risk control network model according to the prediction error value through back propagation, and after the update, continue to perform the above step S301 until the prediction error value meets the preset error threshold or the number of iterations reaches the preset iteration threshold, to obtain the risk control network model. Optionally, the preset error threshold can be understood as a measurable convergence condition for ending the network model training; when the prediction error value is less than or equal to the preset error threshold, it can be determined that the current network parameters are the optimal network parameters, and the current initial risk control network model is taken as the risk control network model. At the same time, the preset iteration number can be understood as a measurable convergence condition for ending the network model training; when the number of iterations is greater than or equal to the preset iteration threshold during the network model training process, it can be determined that the current network parameters are the optimal network parameters, and the current initial risk control network model is taken as the risk control network model.
[0106] In the above risk control method, the risk control network model can be obtained by training the initial risk control network model, so as to realize risk control through the risk control network model, improve the speed of risk control, and also improve the accuracy of risk control.
[0107] For the convenience of those skilled in the art, the risk control method provided by the present disclosure is introduced taking the risk processing system as an example, and specifically, the method comprises:
[0108] (1) obtaining a to-be-processed data stream of a user requesting a service;
[0109] (2) training the initial risk control network model through a data stream training set to obtain a risk control network model; the data stream training set includes data streams corresponding to different users requesting different services.
[0110] (3) inputting the to-be-processed data stream into the risk control network model to obtain a first risk quantification result, and performing at least two of parameter verification, fingerprint comparison, cross comparison, and correlation analysis on the to-be-processed data stream to obtain a second risk quantification result.
[0111] (4) determining a comprehensive risk quantification result through the first risk quantification result, a first weight, the second risk quantification result, and a second weight.
[0112] (5) the preset risk control rule includes a preset risk quantification threshold, if the comprehensive risk quantification result is greater than the preset risk quantification threshold, a service control result is output as a first prompt information; the first prompt information is used to prompt the user that the user request has been intercepted; wherein, the preset risk control rule is monitored, if the preset risk control rule is updated, the service control information is obtained through the comprehensive risk quantification result and the updated preset risk control rule.
[0113] (6) obtaining the business transaction data intercepted by the risk control within a preset time;
[0114] (7) if the business transaction data meets a preset condition, outputting second prompt information, the second prompt information being used to prompt whether the user modifies the preset risk control rule.
[0115] The execution processes of (1) to (7) above can refer to the description of the above embodiments for details, and have similar implementation principles and technical effects, which will not be described here.
[0116] Referring back to Figure 1 , Figure 1 The embodiment provides a structural diagram of a risk processing system; the risk processing system comprises a micro-service cluster, data and storage, and a basic service middleware, wherein the micro-service cluster comprises a risk control core service, a data real-time analysis module, and a risk control model service, and the basic service middleware comprises a message queue;
[0117] The risk control core service is configured to obtain a to-be-processed data stream of a user's requested business, and send the to-be-processed data stream to the message queue;
[0118] The message queue is configured to send the received to-be-processed data stream to the data real-time analysis module and the risk control model service respectively;
[0119] The risk control model service is configured to input the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, and send the first risk quantification result to the data real-time analysis module;
[0120] The data real-time analysis module is configured to perform abnormality analysis on the to-be-processed data stream to obtain a second risk quantification result, obtain business control information through the first risk quantification result, the second risk quantification result, and a preset risk control rule, and send the business control information to the risk control core service;
[0121] The risk control core service is further configured to perform corresponding processing on the user's requested business according to the business control information.
[0122] Specifically, the risk processing system can further include a mall business process microservice group. The risk processing system can obtain a to-be-processed data stream of a user request business through a risk control core service in the microservice cluster. A user can open an e-commerce mall on a client, and then input a user request on the e-commerce mall for different goods. After receiving the user request, the risk processing system responds to the user request to obtain a business data stream corresponding to the user request business, and sends the business data stream to the mall business process microservice group. The mall business process microservice group can include a plurality of different business process services. Each business process service can receive a business data stream corresponding to a user request business. Each business process service can receive a business data stream corresponding to one kind of user request business. Different business process services can be configured according to different business functions. Each business process microservice can be an independent microservice. For example, a commodity microservice can display commodity details and store details, an order microservice can implement order submission, order viewing, and order deletion, a payment microservice can support all payment and refund businesses of the mall, a coupon microservice can query, receive, and use coupons, a user microservice can implement login, registration, and real-name verification, a recharge microservice can implement mobile phone and video website recharge, a public microservice can implement homepage display, advertisement display, and video display, and a search microservice can support all searches and recommendations in the mall. The above-mentioned goods can be domestic goods or overseas goods. A user request can be any request of a user accessing the e-commerce mall. The user request can be a registration request, an order request, a coupon request, a browsing request, a payment request, a return request, a reservation request, and a delivery reminder request. A user request business can be a business client corresponding to these user requests.
[0123] It can be understood that when the user logs in to the e-commerce platform on the client side, the risk processing system can receive the login data of the user, send the login data to the risk core service, and at the same time, the business process service also sends the business data stream to the risk core service. The risk core service combines the login data and the business data stream into a Java object to obtain a to-be-processed data stream. The login data can be fingerprint data of the user, and can also be other identity identification data. For example, if the user request is a order request, the business data stream can be a combination of order number, user name, user mobile phone number, order time, order amount, product number, coupon discount amount and / or delivery address and the like corresponding to the successful order request; the business data stream corresponding to the coupon request can be a combination of coupon number, coupon time, coupon quantity and / or discount amount and the like. Since the data types contained in the business data stream corresponding to different user requests are different, after the risk core service receives the business data stream corresponding to different business scenarios, it can first convert the business data stream into a unified type of data stream, that is, all data types under different business scenarios are included, and the data type not under the current business scenario can be set to null, and then combine the login data and the converted business data stream into a Java object to obtain a to-be-processed data stream. Further, the risk core service sends the to-be-processed data stream to the message queue in the basic service middleware in the risk processing system, so as to asynchronously distribute multiple to-be-processed data streams to the data real-time analysis module and the risk model service through the message queue, and asynchronously process the multiple to-be-processed data streams. Among them, the risk processing system can be configured with Flink, pulsar, cannal and the like message queue. The Flink message queue can not only store the data stream, but also be a kind of real-time computing engine.
[0124] It can also be understood that the risk model service is used to input the to-be-processed data stream into the risk network model to obtain a first risk quantification result, and send the first risk quantification result to the data real-time analysis module. The above-mentioned risk network model can be a pre-trained deep learning network model, which can be a convolutional neural network model, a recurrent neural network model, an adversarial neural network model and the like, and can also be a combination of multiple neural network models. The first risk quantification result output by the risk network model can be a risk score, and the first risk quantification result can be equal to any value between the interval 0 and 1.
[0125] Meanwhile, the data real-time analysis module can perform operation processing on the first risk quantification result, the second risk quantification result, and the preset risk control rule, obtain service control information, and send the service control information to the risk control core service. The operation processing can be four arithmetic operations, exponential operation, logarithmic operation, or a combination of these operations. The service control information can be information related to whether a service can continue to be executed. The abnormality analysis can be understood as a data analysis process, which can be abnormal data extraction processing, risk type detection processing, or a combination of multiple processes. The second risk quantification result can also be a risk score, which can be any value between 0% and a capped value.
[0126] In addition, the risk control core service can control the user request service to continue execution or control the user request service to be intercepted according to the service control information. The interception processing can be understood as rejecting the user request service to continue execution. Meanwhile, the preset risk control rule can be stored in the data and storage in the risk processing system, which can be configured with a MySql database, a Redis database, an ES database, an anti-fraud database, a file database, and the like. In this embodiment, the anti-fraud database can be referred to as a risk library. The Mysql database is mainly used to store commodity information, store information, user information, daily order information, coupon information, payment flow information, coupon record, mall basic configuration information, risk control basic rule information, and other infrequently changed data. The Redis database is mainly used to store user login tokens, seckill scene commodity inventory, coupon inventory in the coupon scene, and other information frequently queried in the main process of the mall. The ES database is mainly used to store search hot words and commodity, store name, and other word libraries. The anti-fraud database can be a risk library that records various risk data and blacklisted users of the risk processing system. The file database can be a reserved database for expansion. In this embodiment, the risk library can be an anti-fraud database.
[0127] In addition to the message queue, the basic service middleware can also include a registration center and a configuration center, log management, service governance, and monitoring alarm. In addition, the basic service middleware can also include other functional modules. In this embodiment, Nacos can be used as the service registration center and the configuration center. The monitoring alarm module can output not only the prompt information obtained in this embodiment, but also the prompt information obtained by other processing methods.
[0128] The embodiment can also use Nginx as a reverse proxy server, configure an Nginx cluster, and the Nginx cluster can be located in the gateway proxy layer. The configuration information includes: configuring permission control, configuring a load balancing strategy, and configuring log recording, to ensure the high availability of the risk processing system, and at the same time have load balancing capability, reduce the pressure of each server, and improve data throughput. The risk processing system also introduces Skywalking as an application performance management tool of the system, realizes the function of tracking distributed links, so that the development and operation personnel understand the behavior of the risk processing system and analyze performance problems. The risk processing system realizes online diagnosis of Java applications through the deployment of the Arthas console, which is convenient for development and operation personnel to locate online problems at the first time. Prometheus+Garafana is used as a monitoring tool of the risk processing system to build a distributed monitoring platform with functions of log analysis, kubernetes cluster state tracking and JVM running condition analysis. Different modules in the above microservice cluster can be called through Open Feign, and Open Feign is used to protect, enhance and control access to API services. The above risk processing system can control the microservice cluster through the Sentinel flow control system, and the flow control rules can be visualized configured through the Sentinel console, and the integration of Nacos realizes the persistence of the flow control rules.
[0129] The above risk processing system can obtain a to-be-processed data stream of a user request service, input the to-be-processed data stream into a risk control network model, obtain a first risk quantification result, and perform abnormal analysis on the to-be-processed data stream to obtain a second risk quantification result. The business control information is obtained through the first risk quantification result, the second risk quantification result and the preset risk control rule, and the corresponding processing is performed on the user request service according to the business control information. The system can automatically control the risk of the user request service and does not need manual participation in the control process, thereby improving the effect of risk control. At the same time, the system can also avoid the situation of missing control or miscontrol when manually controlling, so as to improve the accuracy of risk control and improve the timeliness of risk control.
[0130] As one of the embodiments, the above data real-time analysis module is specifically configured to determine a comprehensive risk quantification result through the first risk quantification result, the first weight, the second risk quantification result and the second weight, and obtain the business control information through the comprehensive risk quantification result and the preset risk control rule.
[0131] Specifically, the data real-time analysis module in the risk processing system can perform weighted summation processing on the first risk quantification result, the first weight, the second risk quantification result, and the second weight, determine a comprehensive risk quantification result, and perform operation processing on the comprehensive risk quantification result and the preset risk control rule to obtain the business control information. The first weight can be a weight coefficient configured by the risk processing system for the first risk quantification result, and the second weight can be a weight coefficient configured by the risk processing system for the second risk quantification result. If the first risk quantification result is represented by A, the first weight is represented by a, the second risk quantification result is represented by B, and the second weight is represented by b, then the comprehensive risk quantification result can be equal to A*a+B*b. The operation processing can be four arithmetic operations, exponential operation, logarithmic operation, or a combination of these operations.
[0132] The risk processing system described above can determine a comprehensive risk quantification result through the first risk quantification result, the first weight, the second risk quantification result, and the second weight, and obtain business control information through the comprehensive risk quantification result and the preset risk control rule. This system can obtain business control information and further process user request services accordingly through the business control information, avoiding the situation of missed control or incorrect control during manual control, improving the accuracy of risk control, and also improving the timeliness of risk control.
[0133] As one of the embodiments, as shown in Figure 6 The micro-service cluster further includes a risk control model management terminal service and a risk control rule engine service.
[0134] The risk control model management terminal service is configured to configure a risk control network model and send the risk control network model to the risk control model service to control the operation of the risk control network model in the risk control model service.
[0135] The risk control rule engine service is configured to configure a preset risk control rule and update the preset risk control rule to obtain an updated preset risk control rule.
[0136] Specifically, the risk processing system can perform network model training on an initial risk control network model through a data stream training set through the risk control model management terminal service in the micro-service cluster to obtain a risk control network model, and send the obtained risk control network model to the risk control model service. The risk control model management terminal service can also control the operation of the risk control network model in the risk control model service. The data stream training set includes data streams corresponding to different user requests for different services. The initial risk control network model can be a convolutional neural network model, a recurrent neural network model, an adversarial neural network model, or a combination of multiple neural networks. Optionally, the data stream training set can be a data set obtained by combining data streams corresponding to different user requests for different services.
[0137] Understandably, the risk processing system can configure preset risk control rules through the risk control rule engine service in the microservice cluster, and update the preset risk control rules to obtain the updated preset risk control rules.
[0138] The aforementioned risk management system can avoid omissions or miscontrols that occur during manual control, thereby improving the accuracy and timeliness of risk control.
[0139] Further, see also Figure 6 The risk management system may also include a presentation layer, an application programming interface (API) layer, and a runtime environment layer.
[0140] Specifically, the presentation layer may include one or more clients, one or more business management terminals, display devices, a risk control management terminal, and a risk control model management terminal. The clients are used by users to log in to the e-commerce platform; the business management terminals are used by merchants and administrators of the platform, and both the clients and terminals can be electronic devices; the display devices are electronic devices with screens, used to display the real-time operational status of the entire risk processing system; both the risk control management terminal and the risk control model management terminal are electronic control devices. The risk control management terminal can send requests to the risk control management service to manage the risk control database and configure preset risk control rules. The risk control model management terminal can manage the risk control network block model, and can send requests to the risk control model management terminal to adjust the network parameters of the risk control network block model, control the operation of the risk control network block model, and view the operational status of the risk control network block model, etc. In addition, the display devices can also display the prompts output by the risk processing system in the form of visual charts and other formats.
[0141] For example, a user whose order is blocked by the risk handling system can be dealt with according to certain rules. If a user is blocked more than 5 times when placing an order, the user will be automatically added to the blacklist stored in the risk database, and the risk handling system will block any further ordering operations from that user. If, due to certain special circumstances, the risk handling system misjudges a user and keeps blocking them, severely hindering the user's normal experience, the user can be removed from the blacklist stored in the risk database and added to the whitelist stored in the risk database through the risk control management terminal. Users on the whitelist will not be blocked, meaning the risk handling system will not be invoked. The aforementioned number of blocking attempts is also a preset risk control rule. Different preset risk control rules can be combined into higher-level risk control rules. The combination and deletion of different preset risk control rules can also be processed by sending corresponding requests to the risk control management terminal service through the risk control management terminal.
[0142] It can be understood that the risk control core service in the risk processing system can obtain the business transaction data intercepted by the risk control within the preset time and send it to the pulsar message queue, and the pulsar message queue can also input the business transaction data stored therein to the Flink message queue for storage. The pulsar message queue can send the business transaction data to the data real-time analysis module, and the data real-time analysis module judges whether the obtained business transaction data meets the preset condition. If it is determined that the business transaction data meets the preset condition, a second prompt information is output to prompt the user that the ratio of the business transaction data intercepted by the risk control within the preset time is too high or too low, and the user considers whether to modify the preset risk control rule to obtain an optimal interception ratio. The above-mentioned preset condition can be that the total number of transactions intercepted by the risk control within the preset time is continuously greater than a first preset transaction total threshold or continuously less than a second preset transaction total threshold, and the total number of transactions intercepted by the risk control within the preset time is continuously greater than a first preset percentage of all transaction quantities or continuously greater than a second preset percentage of all transaction quantities. The first preset transaction total threshold and the second preset transaction total threshold can be different and can be set to any value, and the first preset percentage and the second preset percentage can also be different and can be set to any percentage. In this embodiment, the first preset transaction total threshold can be 500 or 600, the second preset transaction total threshold can be 5 or 3, the first preset percentage can be set to 10%, and the second preset percentage can be set to 0.5%. The second prompt information can be output through a display device. In the risk processing process, the preset risk control rule can be automatically matched when it is used, and the matching process is automatically completed by Flink-CEP, wherein the data structure in the preset risk control rule is consistent with the structure of the data stream to be processed. The preset risk control rule can also be stored in the MySQL database.
[0143] In addition, the Flink message queue in the risk processing system, and the Flink message queue sets a broadcast stream BroadcastStream in the Flink Job, listens to the preset risk control rule through the BroadcastStream, determines whether the preset risk control rule is updated, and the BroadcastStream can be assigned with the ability to access data and storage. The Flink message queue can dynamically load the updated preset risk control rule into the Flink-CEP, that is, the updated preset risk control rule is parsed into a pattern structure body that can be recognized by the Flink-CEP, and the Flink message queue converts the newly generated pattern structure body into an NFA and replaces the original NFA before updating the preset risk control rule. In this way, the updated preset risk control rule can be used for matching in the risk processing process.
[0144] The API layer is provided with a micro-service gateway, which can include an API gateway (i.e., API Gateway) and a business & authentication gateway. The micro-service gateway can be built with Spring Cloud Gateway, which completes matching, filtering and routing operations of request traffic through Route, Predicate and filter. The micro-service gateway is used for communication between modules in the risk processing system. The above-mentioned running environment layer can include several host computers.
[0145] The above-mentioned risk processing system can avoid the situation of missing control or miscontrol when manually controlled, improve the accuracy of risk control, and also improve the timeliness of risk control.
[0146] It should be understood that, although Figures 2-5 The steps in the flowchart are shown in sequence according to the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order limitation for the execution of these steps, and these steps can be executed in other orders. Moreover, Figures 2-5 At least part of the steps in the flowchart can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or steps or stages in other steps.
[0147] In one embodiment, as shown in Figure 7 A risk control apparatus is provided, comprising: a data stream acquisition module 11, a model processing module 12, a control information acquisition module 13 and a request service processing module 14, wherein:
[0148] The data stream acquisition module 11 is configured to acquire a to-be-processed data stream of a user request service;
[0149] The model processing module 12 is configured to input the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, and perform abnormal analysis on the to-be-processed data stream to obtain a second risk quantification result;
[0150] The control information acquisition module 13 is configured to acquire service control information through the first risk quantification result, the second risk quantification result and a preset risk control rule;
[0151] The request service processing module 14 is configured to perform corresponding processing on the user request service according to the service control information.
[0152] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be repeated here.
[0153] In one of the embodiments, the model processing module 12 comprises a quantitative result determination unit and a control information acquisition unit, wherein:
[0154] The quantitative result determination unit is configured to determine a comprehensive risk quantitative result based on the first risk quantitative result, the first weight, the second risk quantitative result, and the second weight.
[0155] The control information acquisition unit is configured to acquire the service control information based on the comprehensive risk quantitative result and a preset risk control rule.
[0156] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be repeated here.
[0157] In one of the embodiments, the anomaly analysis comprises at least two of parameter verification, fingerprint comparison, cross comparison, and correlation analysis.
[0158] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be repeated here.
[0159] In one of the embodiments, the preset risk control rule comprises a preset risk quantitative threshold, and the control information acquisition unit is specifically configured to output the service control result as first prompt information when the comprehensive risk quantitative result is greater than the preset risk quantitative threshold; the first prompt information is used to prompt the user about the related information that the user request has been intercepted.
[0160] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be repeated here.
[0161] In one of the embodiments, the control information acquisition unit comprises a monitoring subunit and a control information acquisition subunit, wherein:
[0162] The monitoring subunit is configured to monitor the preset risk control rule.
[0163] The control information acquisition subunit is configured to acquire the service control information based on the comprehensive risk quantitative result and the updated preset risk control rule when the preset risk control rule exists.
[0164] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be repeated here.
[0165] In one of the embodiments, the risk control apparatus further comprises a transaction data acquisition module and a prompt information output module, wherein:
[0166] The transaction data acquisition module is configured to acquire the business transaction data intercepted by the risk control within a preset time.
[0167] The prompt information output module is configured to output second prompt information when the business transaction data meets the preset condition, and the second prompt information is used to prompt the user whether to modify the preset risk control rule.
[0168] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be described herein again.
[0169] In one of the embodiments, the risk control apparatus further comprises a model training module, wherein:
[0170] The model training module is configured to perform network model training on the initial risk control network model through a data stream training set to obtain the risk control network model, and the data stream training set comprises data streams corresponding to different user requests for different businesses.
[0171] The risk control apparatus provided in the embodiment can execute the method embodiments, and has similar implementation principles and technical effects, which will not be described herein again.
[0172] The specific limitations of the risk control apparatus can be referred to the limitations of the risk control method in the foregoing, which will not be described herein again. The modules in the risk control apparatus can be all or partially realized by software, hardware and combinations thereof. The modules can be embedded in or independent of the processor in the risk processing system in the form of hardware, or stored in the memory in the risk processing system in the form of software, so as to be called and executed by the processor to perform the operations corresponding to the modules.
[0173] In one embodiment, a server is provided, which can be a server, and an internal structure diagram thereof can be as shown in Figure 8 The server comprises a processor, a memory and a network interface connected through a system bus. The processor of the server is configured to provide computing and control capabilities. The memory of the server comprises a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium. The database of the server is configured to store business data streams corresponding to user requests for businesses. The network interface of the server is configured to communicate with external terminals through network connection. The computer program is executed by the processor to implement a risk control method.
[0174] Those skilled in the art can understand that, Figure 8The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the risk processing system to which the scheme of the present application is applied. The specific risk processing system can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0175] In one embodiment, a server is provided, comprising a memory and a processor, the memory storing a computer program, and the processor implementing the following steps when executing the computer program:
[0176] Obtaining a to-be-processed data stream of a user requesting a service;
[0177] Inputting the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, and performing abnormality analysis on the to-be-processed data stream to obtain a second risk quantification result;
[0178] Obtaining service control information through the first risk quantification result, the second risk quantification result, and a preset risk control rule;
[0179] Performing corresponding processing on the user requesting the service according to the service control information.
[0180] In one embodiment, a storage medium is provided, storing a computer program, and the computer program is executed by a processor to implement the following steps:
[0181] Obtaining a to-be-processed data stream of a user requesting a service;
[0182] Inputting the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, and performing abnormality analysis on the to-be-processed data stream to obtain a second risk quantification result;
[0183] Obtaining service control information through the first risk quantification result, the second risk quantification result, and a preset risk control rule;
[0184] Performing corresponding processing on the user requesting the service according to the service control information.
[0185] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when the computer program is executed, the processes of the above-mentioned embodiments of the methods can be included. Any reference to memory, storage, database or other medium used in each embodiment provided by the present application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0186] Any combination of the technical features of the above embodiments can be made. In order to make the description simple, all possible combinations of each technical feature in the above embodiments are not described, however, as long as the combination of the technical features does not exist, it should be considered as the scope of the present application.
[0187] The above embodiments only express several implementation manners of the present application, and the description is more specific and detailed, but it should not be understood as a limitation on the scope of the patent. It should be pointed out that for those skilled in the art, without departing from the concept of the present application, some modifications and improvements can be made, which are all within the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A risk control method, characterized by, The method comprises: obtaining a to-be-processed data stream of a user request service; inputting the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, the first risk quantification result being a risk score, the first risk quantification result being equal to any value between intervals 0 and 1; and performing at least two kinds of analysis on the to-be-processed data stream, including parameter verification, fingerprint comparison, cross comparison and correlation analysis, to obtain a second risk quantification result; the parameter verification is to verify key attribute information in the to-be-processed data stream, the key attribute information including an IP address, a geographic location and a client physical address; the cross comparison is to judge a difference degree between the to-be-processed data stream and a service data stream pre-stored in a risk library; the correlation analysis is to judge whether different to-be-processed data streams at the same time, the same IP address or the same geographic location have a highly aggregated relationship; obtaining service control information through the first risk quantification result, the second risk quantification result and a preset risk control rule; performing corresponding processing on the user request service according to the service control information; Before the step of obtaining service control information through the first risk quantification result, the second risk quantification result and a preset risk control rule, the method further comprises: mapping the second risk quantification result to between 0 and 1; The step of obtaining service control information through the first risk quantification result, the second risk quantification result and a preset risk control rule comprises: determining a comprehensive risk quantification result through the first risk quantification result, a first weight, the second risk quantification result and a second weight; and obtaining the service control information through the comprehensive risk quantification result and the preset risk control rule.
2. The method of claim 1, wherein, The preset risk control rule includes a preset risk quantification threshold, and the step of obtaining the service control information through the comprehensive risk quantification result and the preset risk control rule comprises: if the comprehensive risk quantification result is greater than the preset risk quantification threshold, outputting a service control result as first prompt information; the first prompt information is used to prompt the user that the user request has been intercepted.
3. The method of claim 1, wherein, The step of obtaining the service control information through the comprehensive risk quantification result and the preset risk control rule comprises: monitoring the preset risk control rule; if the preset risk control rule is updated, obtaining the service control information through the comprehensive risk quantification result and the updated preset risk control rule.
4. The method of claim 1, wherein, The method further comprises: obtaining service transaction data intercepted by risk control in a preset time; if the service transaction data meets a preset condition, outputting second prompt information, the second prompt information being used to prompt the user whether to modify the preset risk control rule.
5. The method according to claim 1 or 4, characterized in that, The method further comprises: training an initial risk control network model through a data stream training set to obtain the risk control network model; the data stream training set includes data streams corresponding to different user requests for different services.
6. A risk processing system, characterized by The system comprises a micro-service cluster, data and storage, and basic service middleware, wherein the micro-service cluster comprises a risk control core service, a data real-time analysis module, and a risk control model service, and the basic service middleware comprises a message queue; The risk control core service is configured to obtain a to-be-processed data stream of a user's requested service and send the to-be-processed data stream to the message queue; The message queue is configured to send the received to-be-processed data stream to the data real-time analysis module and the risk control model service respectively; The risk control model service is configured to input the to-be-processed data stream into a risk control network model to obtain a first risk quantification result, which is a risk score, and send the first risk quantification result to the data real-time analysis module; The data real-time analysis module is configured to perform at least two kinds of analysis, including parameter verification, fingerprint comparison, cross comparison, and correlation analysis, on the to-be-processed data stream to obtain a second risk quantification result, The first risk quantification result, the second risk quantification result, and a preset risk control rule are used to obtain service control information, and the service control information is sent to the risk control core service; the parameter verification is to verify key attribute information in the to-be-processed data stream, the key attribute information includes an IP address, a geographic location, and a client physical address; the cross comparison is to determine the difference between the to-be-processed data stream and a pre-stored service data stream in a risk library; the correlation analysis is to determine whether different to-be-processed data streams at the same time, the same IP address, or the same geographic location have a high aggregation relationship; The risk control core service is further configured to perform corresponding processing on the user's requested service according to the service control information; Before the first risk quantification result, the second risk quantification result, and the preset risk control rule are used to obtain the service control information, the following steps are further included: The second risk quantification result is mapped to between 0 and 1; The first risk quantification result, the second risk quantification result, and the preset risk control rule are used to obtain the service control information, including: A comprehensive risk quantification result is determined by the first risk quantification result, a first weight, the second risk quantification result, and a second weight; the service control information is obtained by the comprehensive risk quantification result and the preset risk control rule.
7. The system of claim 6, wherein, The micro-service cluster further comprises a risk control model management terminal service and a risk control rule engine service; The risk control model management terminal service is configured to configure the risk control network model and send the risk control network model to the risk control model service to control the operation of the risk control network model in the risk control model service; The risk control rule engine service is configured to configure the preset risk control rule and update the preset risk control rule to obtain an updated preset risk control rule.
8. A risk control apparatus, characterized by, The apparatus comprises: A data stream acquisition module configured to obtain a to-be-processed data stream of a user's requested service; The model processing module is configured to input the to-be-processed data stream into the risk control network model to obtain a first risk quantization result, the first risk quantization result being a risk score, the first risk quantization result being equal to any value between 0 and 1, and performing at least two of parameter verification, fingerprint comparison, cross comparison and correlation analysis on the to-be-processed data stream to obtain a second risk quantization result; the parameter verification is verification of key attribute information in the to-be-processed data stream, the key attribute information including an IP address, a geographic location and a client physical address; the cross comparison is judgment of a difference degree between the to-be-processed data stream and a service data stream pre-stored in a risk library; and the correlation analysis is judgment of whether different to-be-processed data streams at the same time, the same IP address or the same geographic location have a highly aggregated relationship; The control information obtaining module is configured to obtain service control information by using the first risk quantization result, the second risk quantization result and a preset risk control rule. Before the control information obtaining module obtains the service control information by using the first risk quantization result, the second risk quantization result and the preset risk control rule, the method further includes: Mapping the second risk quantization result to a value between 0 and 1. The control information obtaining module obtains the service control information by using the first risk quantization result, the second risk quantization result and the preset risk control rule, including: Determining a comprehensive risk quantization result by using the first risk quantization result, a first weight, the second risk quantization result and a second weight, and obtaining the service control information by using the comprehensive risk quantization result and the preset risk control rule. The request service processing module is configured to perform corresponding processing on the user request service according to the service control information.
9. A server comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor executes the computer program to implement the steps of the method in any one of claims 1-5.
10. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method in any one of claims 1-5.
Citation Information
Patent Citations
Business risk assessment method and device, and risk control system
CN107067157A
Risk control rule control method, device and equipment and storage medium
CN110490481A
Business risk control method and device, electronic equipment and storage medium
CN113361838A