Method and system for evaluating business message risk level by integrating multiple evaluation strategies

By integrating multiple evaluation strategies and using integrative calculations and database adjustments, the problem of inconsistent evaluation results in the existing technology is solved, and the accuracy and interpretability of risk levels are improved, which is suitable for real-time risk monitoring and processing.

CN114580815BActive Publication Date: 2025-07-11ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202011399585.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-02
Publication Date
2025-07-11
Estimated Expiration
2040-12-02

AI Technical Summary

Technical Problem

In the existing risk identification system, multiple evaluation strategies cannot be unified, resulting in the evaluation results being incomparable and interpretable, and it is difficult to balance between accuracy and recall.

Method used

By integrating multiple evaluation strategies, the default risk level of the evaluation strategy is adjusted using the inclusion operation and the established fact database, and risk level evaluation is carried out in combination with the relevant parameters of the business message to achieve the unity and accuracy of the risk level.

Benefits of technology

It improves the accuracy and comparability of risk level assessment, reduces computational complexity, is suitable for real-time risk monitoring, and promptly handles potential risks through alert mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114580815B_ABST
    Figure CN114580815B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a method and a system for evaluating the risk level of a service message by integrating evaluation strategies in an evaluation strategy set. The method includes: receiving a service message; obtaining one or more associated parameters according to the service message, where the one or more parameters at least include the source of the service message, the destination of the service message, and the occurrence time of the service message; for each evaluation strategy in the evaluation strategy set, matching one or more of the one or more parameters with the evaluation strategy to determine the risk level of the service message under the evaluation strategy; and integrating the obtained risk levels of the service message under the various evaluation strategies in the evaluation strategy set to obtain the integrated risk level of the service message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a method and system for evaluating the risk level of business messages by integrating multiple evaluation strategies. Background Art

[0002] In various fields of risk control, including harassment, fraud, theft, etc., there are many risk identification strategies, and generally, multiple evaluation strategies are used to evaluate the same risk level. These multiple evaluation strategies are mainly based on unsupervised algorithms, and identify, control, and intercept risk events from different perspectives. However, these different evaluation strategies cannot be unified, and their evaluation results are not comparable and interpretable. At the same time, these evaluation strategies generally need to balance accuracy and recall, so that the effects of risk identification vary.

[0003] The present disclosure is made in view of and not limited to the above defects of the existing systems. Summary of the Invention

[0004] To this end, from a statistical perspective and in combination with established factual information, the present disclosure proposes a method and system for evaluating the risk level of business messages by integrating multiple evaluation strategies, so as to unify different evaluation strategies, making the risk level evaluation results interpretable and with higher accuracy.

[0005] According to a first aspect of the present disclosure, there is provided a method for evaluating the risk level of a business message by integrating evaluation strategies in an evaluation strategy set, the method comprising: receiving a business message; obtaining one or more associated parameters according to the business message, the one or more parameters at least including the source of the business message, the destination of the business message, and the occurrence time of the business message; for each evaluation strategy in the evaluation strategy set, matching one or more of the one or more parameters with the evaluation strategy to determine the risk level of the business message under the evaluation strategy; and integrating the obtained risk levels of the business message under the various evaluation strategies in the evaluation strategy set to obtain the integrated risk level of the business message.

[0006] According to an embodiment, obtaining one or more parameters includes parsing the business message to obtain one or more parameters included in the business message, and consulting a database based on the parsed parameters to obtain further parameters.

[0007] According to another embodiment, the business message is a telephone call message, and the one or more obtained parameters include at least one of the following: the originating telephone number of the telephone call, the originating time, the geographical location of the originator of the telephone call message, the called telephone number, the identity and / or geographical location of the called party.

[0008] According to another embodiment, the service message is a transaction message, and the one or more parameters obtained include at least one of the following: the remittance account, the receiving account, the transaction time, the transaction location, and / or the transaction amount of the transaction message, the owner of the receiving account, the geographical location of the receiving account, the common transaction location and / or common transaction time of the remittance account, and the common counterparty account of the remittance account.

[0009] According to another embodiment, the method further includes fusing the risk levels under various evaluation strategies through the following product operation: where s is the fused risk level of the service message, p i is the risk level of the service message under the i-th strategy in the evaluation strategy set, and N is the number of evaluation strategies in the evaluation strategy set.

[0010] According to another embodiment, the method further includes using the established fact database to adjust the default risk levels of the evaluation strategies in the evaluation strategy set.

[0011] According to another embodiment, the adjustment is performed according to the following formula: where N is the number of evaluation strategies in the evaluation strategy set, m is the number of service messages in the established fact database; q i represents the initial default risk level of the i-th evaluation strategy in the evaluation strategy set; α i represents the weight coefficient of the i-th evaluation strategy in the evaluation strategy set; b j represents the service message in the established fact database; C i represents the set of service messages that hit the i-th evaluation strategy in the evaluation strategy set; and δ(b j ∈C i ) is an indicator function, which takes the value of 1 when the established fact service message belongs to the set of service messages that hit the i-th evaluation strategy in the evaluation strategy set, and 0 otherwise.

[0012] According to another embodiment, the method further includes determining whether the fused risk level of the service message exceeds a predetermined threshold, and if so, sending an alarm message.

[0013] According to another embodiment, the method further includes receiving feedback on the alarm message, the feedback including whether the service message actually has a risk, and using the feedback to adjust the default risk levels of the evaluation strategies.

[0014] According to a second aspect of the present disclosure, there is provided a system for evaluating the risk level of a service message by using an evaluation strategy in an integrated evaluation strategy set. The system includes: an evaluation engine; and a service server, wherein the evaluation engine is configured to: receive a service message; obtain one or more associated parameters according to the service message, the one or more parameters at least including the source of the service message, the destination of the service message, and the occurrence time of the service message; for each evaluation strategy in the evaluation strategy set, match one or more of the one or more parameters with the evaluation strategy to determine the risk level of the service message under the evaluation strategy; integrate the obtained risk levels of the service message under the various evaluation strategies in the evaluation strategy set to obtain the integrated risk level of the service message; and forward the service message to the service server when the integrated risk level does not exceed a predetermined threshold; and wherein the service server is configured to receive the service message forwarded from the evaluation engine for processing.

[0015] According to an embodiment, the system further includes a consulting server, wherein the evaluation engine is further configured to parse the service message to obtain one or more parameters included in the service message, and issue a consulting request to the consulting database based on the parsed parameters to obtain further parameters.

[0016] According to another embodiment, the evaluation engine is further configured to integrate the risk levels under the various evaluation strategies through the following product operation: where s is the integrated risk level of the service message, p i is the risk level of the service message under the i-th strategy in the evaluation strategy set, and N is the number of evaluation strategies in the evaluation strategy set.

[0017] According to still another embodiment, the evaluation engine is further configured to use a known fact database to adjust the default risk level of the evaluation strategies in the evaluation strategy set.

[0018] According to still another embodiment, the adjustment is performed according to the following formula: where N is the number of evaluation strategies in the evaluation strategy set, m is the number of service messages in the known fact database; q i represents the initial default risk level of the i-th evaluation strategy in the evaluation strategy set; α i represents the weight coefficient of the i-th evaluation strategy in the evaluation strategy set; b j represents the service message in the known fact database; C i represents the set of service messages that hit the i-th evaluation strategy in the evaluation strategy set; and δ(b j ∈C i) is an indicator function, which takes the value of 1 when the given factual service message belongs to the set of service messages of the i-th evaluation policy in the hit evaluation policy set, and 0 otherwise.

[0019] According to a third aspect of the present disclosure, there is provided a system for evaluating the risk level of service messages by integrating evaluation policies in an evaluation policy set. The system includes: a processor; and a memory arranged to store computer-executable instructions, which when executed cause the processor to execute the method according to the first aspect of the present disclosure.

[0020] Aspects generally include methods, apparatuses, systems, computer program products, and processing systems substantially as described herein with reference to the figures and as illustrated by the figures.

[0021] The foregoing has outlined rather broadly the features and technical advantages of examples in accordance with the present disclosure so that the detailed description that follows may be better understood. Additional features and advantages will be described hereinafter. The disclosed concepts and specific examples may be readily used as a basis for modifying or designing other structures for carrying out the same purposes as the present disclosure. Such equivalent constructions do not depart from the scope of the appended claims. The characteristics of the concepts disclosed herein, both as to their organization and operation methods, as well as the associated advantages, will be better understood by considering the following description in conjunction with the accompanying figures. Each figure is provided for purposes of illustration and description, and does not define a limitation on the claims. Description of the Drawings

[0022] To understand in detail the manner in which the features described above are used, the content briefly outlined above may be described in more detail with reference to the aspects, some of which are illustrated in the figures. However, it should be noted that the figures only illustrate some typical aspects of the present disclosure and should not be considered as limiting its scope, since the description may permit other equally effective aspects. The same reference numerals in different figures may identify the same or similar elements.

[0023] Figure 1 is a flowchart of an exemplary method for evaluating the risk level of service messages by integrating multiple evaluation policies according to an embodiment of the present disclosure;

[0024] Figure 2 is a block diagram of an exemplary system for evaluating the risk level of service messages by integrating multiple evaluation policies according to an embodiment of the present disclosure;

[0025] Figure 3 is an exemplary timing diagram for evaluating the risk level of service messages by integrating multiple evaluation policies according to an embodiment of the present disclosure; and

[0026] Figure 4FIG. 0 is a schematic block diagram of another exemplary system that fuses multiple evaluation strategies to evaluate the risk level of business messages according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0027] The detailed description set forth below in connection with the appended drawings is intended as a description of various configurations and is not intended to represent the only configurations in which the concepts described herein may be practiced. The detailed description includes specific details for the purpose of providing a thorough understanding of various concepts. It will be apparent, however, to one of ordinary skill in the art that these concepts may be practiced without these specific details.

[0028] In various fields of risk control, including harassment, fraud, theft, etc., there are many risk identification strategies, and generally there will be a situation where multiple evaluation strategies evaluate the same risk level. These multiple evaluation strategies are mainly based on unsupervised algorithms to identify, control, and intercept risk events from different perspectives.

[0029] For example, when determining whether a business message such as a phone call or an email has a harassment or fraud risk, the following evaluation strategies can be adopted: 1) If the calls initiated by the originator of the phone call are generally short calls (e.g., the proportion of calls ending within 10 seconds reaches 99%), then there is an 80% probability that the business message is a harassment or fraud call, that is, the risk level of the business message is 80%; 2) If the originator of the phone call frequently makes calls to infrequently contacted contacts, then there is a 70% probability that the business message is a harassment or fraud call. In these examples, 80%, 70%, etc. are the default risk levels of the corresponding evaluation strategies, which are generally given by the average level of all business messages.

[0030] It can be seen that the accuracy of the above exemplary evaluation strategies themselves is not easy to measure (e.g., their default risk levels are not completely reliable), and there is no unified measurement standard between different evaluation strategies. For this reason, the present disclosure proposes a method and system for fusing multiple evaluation strategies to evaluate the risk level of business messages, so that a unified evaluation result can be obtained, thereby improving the accuracy and comparability of the evaluation results.

[0031] Reference is now made to Figure 1 , which shows a flowchart of a method 100 for fusing multiple evaluation strategies to evaluate the risk level of business messages.

[0032] At block 102, method 100 may include receiving a business message.

[0033] In an example of the present disclosure, the service message may be a telephone call message, a short message, a social network message, an email, a transaction message (such as a money transfer, a payment), etc. In an embodiment of the present disclosure, receiving the service message may be intercepted by conventional interception means (e.g., intercepted in real time), such as intercepted by a telecommunications service provider, a mail service provider, or a social network service provider.

[0034] In block 104, method 100 may include obtaining one or more parameters associated with the service message for evaluation. In an embodiment, the one or more parameters at least include the source of the service message, the destination of the service message, the occurrence time of the service message, and so on.

[0035] In an embodiment of the present disclosure, method 100 may parse the service message to obtain one or more parameters included in the service message. For example, in the example where the service message is a telephone call, the service message may be parsed to obtain parameters such as the calling party's phone number, the call initiation time, the geographical location of the caller of the telephone call message, the called phone number, and so on. In a further embodiment, method 100 may then consult various databases based on the parsed parameters related to the service message. For example, continuing with the above example, method 100 may consult the harassing call database based on the obtained calling party's phone number of the telephone call to determine whether the phone number is stored in the database; or may consult the database of the telecommunications service provider based on the called phone number to determine the identity information and / or geographical location of the called party, and so on. All these obtained parameters can be used to evaluate the risk level of the service message.

[0036] In another example where the service message is a money transfer transaction message, the service message may be parsed to obtain parameters such as the remittance account, the receiving account, the transaction amount, the transaction time, the transaction location, and so on. In a further embodiment, method 100 may then consult the financial institution database based on the obtained remittance account and receiving account to determine the owner of the account, the geographical location of the receiving account, the common transaction locations and / or common transaction times of the remittance account, the common counterparty accounts of the remittance account, and so on. All these obtained parameters can also be used to evaluate the risk level of the transaction message.

[0037] Subsequently, at block 106, method 100 may include, for each evaluation policy in the evaluation policy set, matching one or more of the obtained parameters with the evaluation policy to determine the risk level of the service message under the evaluation policy. It can be understood that the evaluation policy uses one or more parameters related to the service message to make a risk judgment. Therefore, the above matching may include first determining which parameters each evaluation policy needs to use, then finding these parameters from the obtained parameters, and further determining whether the values of the found parameters fall within the value range specified by the evaluation policy. For example, if the value of the corresponding parameter of the service message falls within the value range of the parameter and / or parameter combination specified by the evaluation policy, it can be determined that the service message has a risk under the evaluation policy, and its risk level is the default risk level of the evaluation policy. It can be understood that the default risk level of an effective evaluation policy is greater than 0.5 and less than 1.

[0038] For example, in the example described above for a telephone call, the evaluation policies can be used to determine the risk level of the telephone call (e.g., fraud risk level or harassment risk level, etc.). For example, the first evaluation policy in the evaluation policy set can determine the harassment risk level of the current telephone call based on the historical call duration of the telephone call initiator: if the calls initiated by the telephone call initiator are generally short calls (e.g., 99% of the calls end within 10 seconds), then there is an 80% probability that the current telephone call is a harassing call, that is, the risk level of the current telephone call is 80%. 2) The second evaluation policy in the evaluation policy set can determine the harassment risk level of the current telephone call based on the callee of the historical calls of the telephone call initiator: if the telephone call initiator frequently makes calls to infrequently used contacts, then there is a 70% probability that the current telephone call is a harassing call. Those skilled in the art can understand that the evaluation policy set may also include any other suitable evaluation policies for evaluating the harassment risk level based on any parameter and / or parameter combination of the telephone call. In the above example, 80%, 70%, etc. are the default risk levels of the corresponding evaluation policies, which are generally given by the average level of all telephone calls.

[0039] Continuing with the above example, if the originator of the currently received phone call hits the above first evaluation strategy, that is, the calls initiated by the originator of this phone call are indeed generally short calls, then it can be determined that the risk level of this phone call under the first evaluation strategy is 80%; otherwise, it can be determined that the risk level of this phone call under the first evaluation strategy is 0%. Additionally, if the originator and the recipient of the currently received phone call hit the above second evaluation strategy, that is, the recipient of this phone call is an infrequently used contact of the originator of this phone call, and the originator of this phone call frequently initiates such calls, then it can be determined that the risk level of this phone call under the second evaluation strategy is 70%; otherwise, it can be determined that the risk level of this phone call under the second evaluation strategy is 0%. Those skilled in the art can understand that other evaluation strategies in the evaluation strategy set can be used to make evaluations using appropriate parameters and / or parameter combinations of the current phone call.

[0040] In another example, as described above for transaction messages, various evaluation strategies can be used to determine the risk level of a transaction message (e.g., fraud risk level, theft risk level, etc.). For example, the first evaluation strategy in the evaluation strategy set can be based on whether the receiving account of the transaction message is a frequently used counterparty account of the sending account and the transaction amount is large, then the theft risk level of this transaction message is 70%, that is, there is a 70% probability that this transaction message is a theft; 2) the second evaluation strategy in the evaluation strategy set can be based on the frequently used transaction location of this transaction message to determine the risk level of the current transaction message: if the transaction location of this transaction message is not the frequently used transaction location of the sending account, then the theft risk level of this transaction message is 60%. Those skilled in the art can understand that the evaluation strategy set can also include any other appropriate evaluation strategies for evaluating the theft risk level based on any parameters and / or parameter combinations of the transaction message. In the above example, 70%, 60%, etc. are the default risk levels of the corresponding evaluation strategies, which are generally given by the average level of all transaction messages.

[0041] Continuing with the above example, if the receiving account and amount of the currently received transaction message match the first evaluation strategy above, that is, the receiving account of the transaction message is not the common counterparty account of the remitting account and the transaction amount is large, it can be determined that the theft risk level of the transaction message under the first evaluation strategy is 70%; otherwise, it can be determined that the risk level of the transaction message under the first evaluation strategy is 0%. Additionally, if the transaction location (i.e., the remitting location) of the currently received transaction message matches the second evaluation strategy above, that is, the remitting location of the transaction message is not the common remitting location of the remitting account, it can be determined that the theft risk level of the transaction message under the second evaluation strategy is 60%; otherwise, it can be determined that the theft risk level of the transaction message under the second evaluation strategy is 0%. In yet another embodiment, as yet another evaluation strategy, for the location of the remitting account, if the transaction time of the transaction message is 2 am and it is not the common transaction time of the account, then the transaction message has a theft risk, for example, the risk level can generally be 90%. Furthermore, in another embodiment, as another evaluation strategy, the age of the remitting account owner (e.g., over 60 years old) can be considered to have a high risk of being deceived and stolen.

[0042] Those skilled in the art can understand that any suitable parameters and / or combinations of parameters of the current transaction message can be used to make an evaluation for other evaluation strategies in the evaluation strategy set. For example, parameters such as the number of transaction accounts owned by the receiving account owner, transaction location, transaction amount, transaction frequency, common transaction address, transaction occurrence time, etc. can all be used to evaluate the risk level of the transaction message.

[0043] In block 108, method 100 may include fusing the risk levels of the obtained service message under the various evaluation strategies in the evaluation strategy set to obtain the fused risk level of the service message.

[0044] In one embodiment, the risk levels under the various evaluation strategies can be fused through the following product operation:

[0045]

[0046] where s is the fused risk level of the service message, p i is the risk level of the service message under the i-th strategy in the evaluation strategy set, and N is the number of evaluation strategies in the evaluation strategy set. Thus, it can be seen that the obtained fused risk level unifies all the evaluation strategies in the evaluation strategy set, making its accuracy higher, and the results are comparable and interpretable. Additionally, calculating the fused risk level in the above manner can save computing power and can calculate the fused risk level faster. For example, it can be calculated by directly adding in the logarithmic domain, thereby making it possible to quickly calculate s, which is more suitable for real-time risk monitoring.

[0047] However, those skilled in the art will understand that the risk levels under various evaluation strategies can also be integrated in any other suitable way, such as by taking a weighted average of the risk levels of the various evaluation strategies, and so on.

[0048] It can be understood that existing evaluation strategies require a large number of positive and negative samples for training, and then the trained evaluation strategies can be applied. However, in another preferred embodiment of the present disclosure, method 100 may further include using a known facts database to adjust the default risk levels of the evaluation strategies in the evaluation strategy set. In this embodiment, the business messages included in the known facts database are established facts, that is, the business messages either have a 100% risk or a 0% risk. In this embodiment, method 100 may include determining whether the business messages in the known facts database match the evaluation strategies in the evaluation strategy set (i.e., the evaluation strategy determines that the business message has a risk), and adjusting the default risk level of the evaluation strategy based on this determination. Thus, even if there are only a small number of business messages in the known facts database, the various evaluation strategies can be improved very well, so that a large number of positive and negative business message samples are not required for training.

[0049] For example, if a business message with a 100% risk level in the known facts database is determined by an evaluation strategy to have a risk, it means that the evaluation strategy correctly determines the business message with a risk, and thus the default risk level of the evaluation strategy can be increased. On the contrary, if a business message with a 0% risk level in the known facts database is determined by an evaluation strategy to have a risk, it means that the evaluation strategy does not correctly determine the business message, and thus the default risk level of the evaluation strategy can be decreased. In this embodiment, it can be understood that the increase in the default risk level of the evaluation strategy should not make the default risk level of the evaluation strategy greater than 1, that is, 100%. In addition, if the decrease in the default risk level of the evaluation strategy makes it lower than 50%, it proves that the evaluation strategy is inefficient or even ineffective. Therefore, in this case, the evaluation strategy can be removed from the evaluation strategy set.

[0050] In yet another embodiment of the present disclosure, the default risk level of the evaluation strategy can be adjusted according to the following formula:

[0051]

[0052] where N is the number of evaluation strategies in the evaluation strategy set, and m is the number of business messages in the known facts database;

[0053] q i represents the initial default risk level of the i-th evaluation strategy in the evaluation strategy set;

[0054] α iDenotes the weight coefficient of the i-th evaluation strategy in the evaluation strategy set;

[0055] b j Denotes the business message in the established fact database;

[0056] C i Denotes the set of business messages that hit the i-th evaluation strategy in the evaluation strategy set; and

[0057] δ(b j ∈C i ) is an indicator function, which takes the value of 1 when the established fact business message belongs to the set of business messages of the i-th evaluation strategy in the hit evaluation strategy set, and 0 otherwise.

[0058] In yet another embodiment of the present disclosure, method 100 may optionally further include, at block 110, determining whether the fused risk level of the business message exceeds a predetermined threshold (e.g., 95%, 99%, etc.). And if the fused risk level exceeds the predetermined threshold, an alert message may be issued to notify the potentially affected user, system administrator, and / or other regulatory parties to handle this business message. In a further embodiment, as a supplement or replacement to the alert message, method 100 may further include blocking further processing of the business message. For example, if the business message is a transfer transaction, the transfer may be blocked and the corresponding remitter and relevant financial institutions, etc. may be notified.

[0059] Continuing with this example, method 100 may optionally further include, at block 112, receiving feedback from the user on the alert message. For example, after receiving the alert message, the user may determine that the business message is indeed risky and provide this determination as feedback. After receiving this feedback, method 100 may adjust the default risk levels of the evaluation strategies with this business message as an established fact (i.e., 100% risk level), as described above in connection with the established fact database.

[0060] Figure 2 Illustrates a block diagram of an exemplary system 200 for fusing multiple evaluation strategies to evaluate the risk level of a business message according to an embodiment of the present disclosure.

[0061] As shown, system 200 may include one or more user terminals 202 used by users, an evaluation engine 204, a business server 206, and a consultation database 208, all of which are interconnected through a communication infrastructure such as the Internet 210.

[0062] In one embodiment, a user may use their user terminal 202 to issue a business message for the business server 206 to process. The evaluation engine 204 may receive (e.g., intercept) the business message and evaluate the risk level of the business message, for example, using reference Figure 1The described method 100. If the risk level of the service message does not exceed a predetermined threshold, the evaluation engine 204 may forward the service message to the service server 206 for further processing; otherwise, if the risk level of the service message exceeds the predetermined threshold, the evaluation engine 204 may issue an alert message and / or notify the service server 206 to abort processing the service message.

[0063] Those skilled in the art will appreciate that there may be multiple user terminals, such as Figure 2 as indicated by the ellipsis 203 in. In addition, although the evaluation engine 204, the service server 206, and the consultation database 208 are shown separately in Figure 2 this is only a logical division, so any two or all of them may be located in one place. For example, the service server 206 may include the evaluation engine 204.

[0064] The following combines Figure 3 and refers to Figure 2 to describe an exemplary timing diagram 300 for evaluating the risk level of a service message by integrating multiple evaluation strategies according to an embodiment of the present disclosure.

[0065] As shown in the figure, a user may use a user terminal 301 (e.g., Figure 2 the user terminal 202 of ) to issue a service message. For example, a user may use their smartphone to make a phone call, issue a transfer request through an application on the smartphone and / or an ATM machine, etc.

[0066] The evaluation engine 303 (e.g., Figure 2 the evaluation engine 204 of ) may receive a service message from the user terminal 301 and parse the service message to obtain one or more associated parameters, as Figure 3 shown. In one embodiment, the evaluation engine 303 may also issue a consultation request to the consultation database 307 to obtain more parameters related to the service message. For example, in the example where the service message is a phone call, the evaluation engine 303 may parse the service message to obtain parameters such as the phone number of the caller of the phone call, the call time, the phone number of the called party, etc. The evaluation engine 303 may then consult the harassing call database based on the obtained phone number of the caller of the phone call to determine whether the phone number is stored in the database; or may consult the database of the telecommunications service provider based on the phone number of the called party to determine the identity information of the called party, etc. In another example where the service message is a transfer transaction message, the evaluation engine 303 may parse the service message to obtain parameters such as the remittance account, the receiving account, the transaction amount, etc. of the transaction. The evaluation engine 303 may then consult the database of the financial institution based on the obtained remittance account and receiving account to determine the owner of the account, etc.

[0067] The consultation database 307 can then transmit the response to the consultation request (including the parameters requested by the consultation request) back to the evaluation engine 303.

[0068] The evaluation engine 303 can then determine the risk level of the service message. For example, this determination can be made according to the method 100 described in the reference Figure 1 to make this determination.

[0069] Thereafter, the evaluation engine 303 can determine whether the risk level of the service message exceeds a predetermined threshold. If it is determined that the risk level exceeds the predetermined threshold, an alarm is issued and / or the processing of the service message is aborted. For example, the evaluation engine 303 can issue an alarm to the service server 305, or to the user of the user terminal 301, the device of the regulatory agency ( Figure 3 not shown in the figure), etc. In addition, aborting the processing of the service message can include the evaluation engine 303 notifying the service server 305 of the evaluation result of the risk level, so that the service server 305 no longer processes the service message. In a further embodiment, the service server 305 can also notify the user terminal 301 of the decision not to process the service message and the reason, so that the user can obtain an alarm.

[0070] On the contrary, if the risk level does not exceed the predetermined threshold, the evaluation engine 303 can forward the service message to the service server 305 for processing. The service server 305 can continue to process the service message and send the processing result back to the user terminal 301.

[0071] Figure 4 is a schematic block diagram of another exemplary system 400 for evaluating the risk level of a service message by integrating multiple evaluation strategies according to an embodiment of the present disclosure. As shown in the figure, the system 400 includes a processor 405 and a memory 410. The memory 410 stores computer-executable instructions that can be executed by the processor 405 to implement the corresponding methods and processes described above in conjunction with Figures 1 - 3 description.

[0072] The above specific embodiments include references to the accompanying drawings, which form part of the specific embodiments. The accompanying drawings illustrate specific embodiments that can be practiced by way of illustration. These embodiments are also referred to herein as "examples". Such examples can include elements other than those shown or described. However, examples including the elements shown or described are also contemplated. In addition, examples using any combination or arrangement of the elements shown or described, or referring to the specific examples (or one or more aspects thereof) shown or described herein, or referring to other examples (or one or more aspects thereof) shown or described herein are also contemplated.

[0073] In the appended claims, the terms "comprising" and "including" are open-ended, meaning that a system, apparatus, article, or process that includes elements other than those recited after such terms in a claim is still considered to fall within the scope of that claim. Further, in the appended claims, the terms "first," "second," "third," and the like are used merely as labels and are not intended to indicate a numerical order of their objects.

[0074] Also, the order of the operations recited in this specification is exemplary. In alternative embodiments, the operations may be performed in a different order than shown in the figures, and the operations may be combined into a single operation or split into more operations.

[0075] The above description is intended to be illustrative, not restrictive. For example, the above-described examples (or one or more aspects thereof) may be used in conjunction with other embodiments. Other embodiments may be used, for example, by one of ordinary skill in the art after reviewing the above description. The abstract allows the reader to quickly ascertain the nature of the technical disclosure. The abstract is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Further, in the above Detailed Description, various features may be grouped together to streamline the disclosure. However, the claims may not recite every feature disclosed herein because an embodiment may represent a subset of the features. Further, an embodiment may include fewer features than those disclosed in a particular example. Accordingly, the appended claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment. The scope of the embodiments disclosed herein should be determined with reference to the appended claims and the full scope of equivalents to which such claims are entitled.

Claims

1. A method for evaluating the risk level of a service message by integrating evaluation strategies in an evaluation strategy set, the method comprising: Receiving a service message; Obtaining one or more associated parameters according to the service message, the one or more parameters at least including the source of the service message, the destination of the service message, and the occurrence time of the service message; For each evaluation strategy in the evaluation strategy set, matching one or more of the one or more parameters with the evaluation strategy to determine the risk level of the service message under the evaluation strategy; And Integrating the obtained risk levels of the service message under the various evaluation strategies in the evaluation strategy set to obtain the integrated risk level of the service message, including integrating the risk levels under the various evaluation strategies through the following product operation: where s is the fused risk level of the service message, and p i is the risk level of the service message under the i-th policy in the evaluation policy set, and N is the number of evaluation policies in the evaluation policy set The method further includes using a known fact database to adjust the default risk level of the evaluation strategies in the evaluation strategy set, wherein the adjustment is performed according to the following formula: where N is the number of evaluation strategies in the evaluation strategy set, and m is the number of service messages in the known fact database; q i represents the initial default risk level of the i-th evaluation strategy in the evaluation strategy set; α i represents the weight coefficient of the i-th evaluation strategy in the evaluation strategy set; b j Represents a business message in the established fact database; C i represents a set of service messages for the i-th evaluation policy in the hit evaluation policy set; and δ(b j ∈C i ) is an indicator function that takes the value 1 when the established fact business message belongs to the business message set of the i-th evaluation policy in the hit evaluation policy set, and 0 otherwise.

2. The method according to claim 1, wherein Obtaining one or more parameters includes parsing the service message to obtain one or more parameters included in the service message, and consulting a database based on the parsed parameters to obtain further parameters.

3. The method according to claim 2, wherein The service message is a telephone call message, and the one or more obtained parameters include at least one of the following: the originating telephone number of the telephone call, the originating time, the geographical location of the originator of the telephone call message, the called telephone number, the identity and / or geographical location of the called party.

4. The method according to claim 2, wherein The service message is a transaction message, and the one or more obtained parameters include at least one of the following: the remittance account of the transaction message, the receiving account, the transaction time, the transaction location, and / or the transaction amount, the owner of the receiving account, the geographical location of the receiving account, the common transaction location and / or common transaction time of the remittance account, the common counterparty account of the remittance account.

5. The method according to claim 1, wherein It further includes determining whether the integrated risk level of the service message exceeds a predetermined threshold, and if so, sending an alarm message.

6. The method according to claim 5, characterized in that, It further includes receiving feedback on the alarm message, the feedback including whether the service message actually has a risk, and using the feedback to adjust the default risk levels of the various evaluation strategies.

7. A system for evaluating the risk level of a service message by integrating evaluation strategies in an evaluation strategy set, the system comprising: An evaluation engine; And A service server, wherein the evaluation engine is configured to: Receive a service message; Obtain one or more associated parameters according to the service message, the one or more parameters at least including the source of the service message, the destination of the service message, and the occurrence time of the service message; For each evaluation strategy in the evaluation strategy set, matching one or more of the one or more parameters with the evaluation strategy to determine the risk level of the service message under the evaluation strategy; Fusing the risk levels of the service message under the various evaluation policies in the evaluation policy set to obtain the fused risk level of the service message; and Forwarding the service message to the service server when the fused risk level does not exceed a predetermined threshold; and wherein the service server is configured to receive the service message forwarded from the evaluation engine for processing, wherein the evaluation engine is further configured to fuse the risk levels under the various evaluation policies through the following product operation: where s is the fused risk level of the service message, p i is the risk level of the service message under the i-th policy in the evaluation policy set, and N is the number of evaluation policies in the evaluation policy set. and wherein the evaluation engine is further configured to use the established fact database to adjust the default risk level of the evaluation policies in the evaluation policy set, and the adjustment is performed according to the following formula: where N is the number of evaluation policies in the evaluation policy set, and m is the number of service messages in the established fact database; q i represents the initial default risk level of the i-th evaluation strategy in the evaluation strategy set; α i represents the weight coefficient of the i-th evaluation strategy in the evaluation strategy set; b j Represents a business message in the established fact database; C i represents a set of service messages for the i-th evaluation strategy in the hit evaluation strategy set; and δ(b j ∈C i ) is an indicator function that takes the value of 1 when the established fact business message belongs to the business message set of the i-th evaluation policy in the hit evaluation policy set, and 0 otherwise.

8. The system according to claim 7, wherein further comprising a consulting server, wherein the evaluation engine is further configured to parse the service message to obtain one or more parameters included in the service message, and issue a consulting request to the consulting database based on the parsed parameters to obtain further parameters.

9. A system for fusing evaluation policies in an evaluation policy set to evaluate the risk level of a service message, the system comprising: a processor; and a memory arranged to store computer-executable instructions, the executable instructions when executed causing the processor to perform the method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Business risk assessment method and device, and risk control system

    CN107067157A