Account identification method, device, equipment and computer storage medium

By acquiring and matching employees' multi-dimensional parameter information, identifying and monitoring the transaction behaviors of accounts they control, the problem of employees' illegal operations in the banking industry is solved, the accurate identification of employee accounts and monitoring of abnormal transactions are achieved, and the occurrence of malicious incidents is reduced.

CN114663097BActive Publication Date: 2025-09-19CHINA CONSTRUCTION BANK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210302628.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-25
Publication Date
2025-09-19
Estimated Expiration
2042-03-25

AI Technical Summary

Technical Problem

In the banking industry, there is a phenomenon where employees conduct illegal operations by controlling multiple accounts of other people, resulting in frequent malicious business incidents. How to accurately identify accounts controlled by employees and monitor their transaction behavior has become an urgent problem that needs to be solved.

Method used

By obtaining multi-dimensional parameter information of the target employees, including basic information, transaction information, device information and location information, matching is performed using the preset control account model, the control degree score is calculated, the target account is identified, and account behavior is monitored through the transaction monitoring model to output abnormal alarm information.

Benefits of technology

It achieves accurate identification of employee-controlled accounts and monitoring of transaction behaviors, effectively reducing the probability of malicious business incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114663097B_ABST
    Figure CN114663097B_ABST
Patent Text Reader

Abstract

The present application discloses an account identification method, apparatus, device and computer storage medium, and relates to the field of computer technology. The method comprises: obtaining N-dimensional parameter information of a target employee, wherein the N-dimensional parameter information comprises at least one of basic information, transaction information, device information and location information, and N is a positive integer; matching the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively, and obtaining P control degree scores corresponding to the target parameter information, and P is a positive integer; determining, based on the P control degree scores, the control account corresponding to the target employee and the target parameter information in the target account set, wherein the target account set comprises P accounts corresponding to the P reference target parameter information. According to an embodiment of the present application, it is possible to accurately identify and monitor the accounts controlled by employees, thereby effectively reducing the probability of malicious business events.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an account identification method, apparatus, device, and computer storage medium. Background Art

[0002] At present, there has been a phenomenon in the banking industry where commercial bank employees have taken control of multiple accounts of other people to conduct a series of illegal and risky operations.

[0003] Based on this, how to accurately identify employee-controlled accounts and monitor abnormal transaction behaviors of the identified controlled accounts has become one of the urgent issues to be solved in the development of the banking industry at this stage. Summary of the Invention

[0004] The embodiments of the present application provide an account identification method, apparatus, device, and computer storage medium that can accurately identify and monitor accounts controlled by employees, thereby effectively reducing the probability of malicious business incidents.

[0005] In a first aspect, an embodiment of the present application provides an account identification method, the account identification method comprising:

[0006] Obtaining N-dimensional parameter information of the target employee, where the N-dimensional parameter information includes at least one of basic information, transaction information, device information, and location information, where N is a positive integer;

[0007] Match the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information, where P is a positive integer;

[0008] According to the P control degree scores, the control account corresponding to the target employee and the target parameter information in the target account set is determined, wherein the target account set includes P accounts corresponding one-to-one to the P reference target parameter information.

[0009] In some possible implementations, the target parameter information in the N-dimensional parameter information is matched with P reference target parameter information to obtain P control degree scores corresponding to the target parameter information, including:

[0010] Determine the preset control account model corresponding to the target parameter information based on the dimension to which the target parameter information belongs;

[0011] Through the preset control account model, the target parameter information in the N-dimensional parameter information is matched with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information; wherein, the preset control account model is constructed based on P reference target parameter information.

[0012] In some possible implementations, after determining, in the target account set, the control account corresponding to the target employee and the target parameter information based on the P control degree scores, the account identification method further includes:

[0013] Obtain the account transaction behavior characteristics of the target user's Q controlled accounts, where Q controlled accounts include the target employee's controlled accounts corresponding to each parameter information in the N-dimensional parameter information, where Q is a positive integer;

[0014] The account transaction behavior characteristics of the Q control accounts are respectively output to the target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts; if there is at least one monitoring result among the Q monitoring results indicating that the account transaction behavior characteristics are abnormal, a transaction abnormality alarm information is output.

[0015] In some possible implementations, before inputting the account transaction behavior characteristics of the Q control accounts into the target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts, the following steps are included:

[0016] Obtain target transaction flow data;

[0017] Extracting transaction feature variables from target transaction flow data, where the transaction feature variables include at least one of a basic transaction indicator, a loan and consumption indicator, a cash transaction indicator, and a corporate transaction indicator;

[0018] Based on transaction characteristic variables, a target control account transaction monitoring model is constructed.

[0019] In some possible implementations, a target control account transaction monitoring model is constructed based on transaction characteristic variables, including:

[0020] Determining, based on the transaction characteristic variables, the transaction characteristic variables for each group in the employee identity attribute grouping set; the employee identity attribute grouping set is obtained based on identity attribute parameters of each employee; the identity attribute parameters include at least one of the employee's region, organization, position, age, and salary level;

[0021] Based on the transaction characteristic variables of each group, a control account transaction monitoring model for each group is constructed;

[0022] The target control account transaction monitoring model is any control account transaction monitoring model under each group.

[0023] In some possible implementations, the account transaction behavior characteristics of the Q control accounts are respectively output to the target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts, further comprising:

[0024] Get the identity attribute parameters of the target employee;

[0025] Based on the identity attribute parameters of the target employee, determining the group to which the target employee belongs in the employee identity attribute group set;

[0026] Determine the target control account transaction monitoring model corresponding to the target employee's group based on the target employee's group;

[0027] The account transaction behavior characteristics of the Q control accounts are respectively input into the target control account transaction monitoring model corresponding to the group to which the target employee belongs, and Q monitoring results corresponding to the Q control accounts are obtained.

[0028] In some possible implementations, the account identification method further includes:

[0029] Build a monitoring model for abnormal scenarios of control accounts based on historical abnormal scenario data;

[0030] Based on the control account abnormal scenario monitoring model, detect whether the transaction scenarios of the target user's Q control accounts are abnormal;

[0031] When it is detected that any of the Q control accounts has an abnormal transaction scenario, an abnormal transaction scenario alarm message is output.

[0032] In some possible implementations, the device information includes commonly used device information of the target employee. Before obtaining the N-dimensional parameter information of the target employee, the account identification method further includes:

[0033] Obtain login trace data of each employee's electronic device;

[0034] Based on the electronic device login trace data of each employee, derive at least one characteristic parameter of usage frequency, usage percentage, and number of users;

[0035] Establish a model of commonly used equipment by employees based on at least one characteristic parameter among frequency of use, percentage of use, and number of users;

[0036] Based on the employee's commonly used device model, the target employee's commonly used device information is determined according to the target employee's electronic device login trace data.

[0037] In some possible implementations, the location information includes the target employee's frequently used location information. Before obtaining the target employee's N-dimensional parameter information, the account identification method further includes:

[0038] Based on the electronic device login trace data of each employee, derive at least one characteristic parameter of location login frequency, login proportion, and number of location logins;

[0039] Establish a model of employees' frequently used locations based on at least one characteristic parameter of location login frequency, login proportion, and number of location logins;

[0040] Determine the target employees' frequently used location information based on the employee frequently used location model.

[0041] In a second aspect, an embodiment of the present application provides an account identification device, the account identification device comprising:

[0042] A first acquisition module is configured to acquire N-dimensional parameter information of a target employee, where the N-dimensional parameter information includes at least one of basic information, transaction information, device information, and location information, where N is a positive integer;

[0043] A first matching module is used to match the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information, where P is a positive integer;

[0044] The identification module is used to determine the control account corresponding to the target employee and the target parameter information in the target account set based on the P control degree scores, wherein the target account set includes P accounts corresponding to the P reference target parameter information.

[0045] In a third aspect, an embodiment of the present application provides an account identification device, the account identification device comprising:

[0046] a processor and a memory storing computer program instructions;

[0047] When the processor executes the computer program instructions, it implements the account identification method provided in any one of the above-mentioned embodiments of the present application.

[0048] In a fourth aspect, an embodiment of the present application provides a computer storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, an account identification method as provided in any one of the above embodiments of the present application is implemented.

[0049] In a fifth aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes an account identification method as provided in any one of the above-mentioned embodiments of the present application.

[0050] The account identification method, device, equipment and computer storage medium of the embodiment of the present application can obtain multi-dimensional parameter information of the target employee, and then match the parameter information under any dimension with multiple reference target parameter information to obtain multiple control degree scores. In this way, the control account corresponding to the target employee and the target parameter information can be identified based on the multiple control degree scores and the target account set. The account identification method, device, equipment and computer storage medium provided by the present application can identify the control account of the employee in combination with the multi-dimensional parameter information, so as to subsequently monitor and alert the transaction behavior and transaction scenarios of the employee's control account. In this way, the improper behavior of employees can be accurately monitored, thereby effectively reducing the probability of malicious business incidents. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0052] Figure 1 This is a flowchart of an account identification method provided by an embodiment of the present application;

[0053] Figure 2 is a structural diagram of an account identification device provided by another embodiment of the present application;

[0054] Figure 3 This is a structural diagram of an account identification device provided in another embodiment of the present application. DETAILED DESCRIPTION

[0055] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0056] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.

[0057] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application comply with the relevant provisions of national laws and regulations.

[0058] In the embodiment of the present application, the employee's controlled account can be interpreted as an account that is not an employee's real-name account, but is actually controlled and used by the employee.

[0059] As described in the background technology section, with the development of the information age, various commercial organizations have gradually seen employees using other people's identity information to generate their own controlled accounts in order to obtain improper benefits. In this way, employees control multiple other people's accounts and conduct abnormal transactions, which further leads to a series of malicious business incidents such as employees misappropriating customer funds.

[0060] The inventors of this application realized that if a series of technical measures are to be taken to curb the occurrence of the above-mentioned adverse events, then how to accurately identify the control accounts of employees of enterprises or institutions is the core key point in solving the above-mentioned problems.

[0061] In order to solve the problems of the prior art, the embodiments of the present application provide an account identification method, apparatus, device, storage medium and computer program product. It should be noted that the embodiments provided in this application are not intended to limit the scope of the disclosure of this application.

[0062] The following first introduces the account identification method provided in the embodiment of the present application.

[0063] It should be understood that the application scenarios of the account identification method can be, but are not limited to, commercial banks, financial institutions, and other corporate institutions involved in account operation activities.

[0064] For ease of understanding, the following application embodiment mainly takes a commercial bank as an example to elaborate on an account identification method provided by this application.

[0065] Figure 1The following is a flow chart of an account identification method provided by an embodiment of the present application. The account identification method is applied to an electronic device, which may include a server or a terminal. Figure 1 As shown, the account identification method includes the following steps:

[0066] S110 , obtaining N-dimensional parameter information of the target employee, where the N-dimensional parameter information includes at least one of basic information, transaction information, device information, and location information, where N is a positive integer.

[0067] S120 , matching the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively, to obtain P control degree scores corresponding to the target parameter information, where P is a positive integer.

[0068] S130 , determining, based on the P control degree scores, the control account corresponding to the target employee and the target parameter information in the target account set, wherein the target account set includes P accounts corresponding one-to-one to the P reference target parameter information.

[0069] The account identification method of the embodiment of the present application can obtain multiple control degree scores by obtaining multi-dimensional parameter information of the target employee and then matching the parameter information under any dimension with multiple reference target parameter information. In this way, the control account corresponding to the target employee and the target parameter information can be identified based on the multiple control degree scores and the target account set. An account identification method provided by the present application can identify the employee's control account in combination with multi-dimensional parameter information, so as to subsequently monitor and alert the transaction behavior and transaction scenarios of the employee's control account. In this way, the improper behavior of employees can be accurately monitored, thereby effectively reducing the probability of malicious business incidents.

[0070] The specific implementation methods of the above steps are introduced below.

[0071] In S110 , during specific implementation, N-dimensional parameter information of the target employee can be efficiently obtained through big data technology. The N-dimensional parameter information can include at least one of basic information, transaction information, device information, and location information.

[0072] In an embodiment of the present application, the target employee may be an employee of a commercial bank, and the basic information of the target employee may include but is not limited to at least one of human resources information, personal loan information, credit card information, employee channel information, private customer channel information, customer number, identity information, contact person information, contact information and address information.

[0073] The transaction information of the target employee may be the bank transaction flow information of the employee.

[0074] In some embodiments, the device information may include the target employee's frequently used device information, such as the target employee's frequently used mobile phone and computer device information. Furthermore, in order to effectively filter out the target user's frequently used device information to improve the accuracy of subsequent data applications, before obtaining the target employee's N-dimensional parameter information, the account identification method may further include:

[0075] Obtain login trace data of each employee's electronic device;

[0076] Based on the electronic device login trace data of each employee, derive at least one characteristic parameter of usage frequency, usage percentage, and number of users;

[0077] Establish a model of commonly used equipment by employees based on at least one characteristic parameter among frequency of use, percentage of use, and number of users;

[0078] Based on the employee's commonly used device model, the target employee's commonly used device information is determined according to the target employee's electronic device login trace data.

[0079] In specific implementation, when the target employee is an employee of a commercial bank, the electronic device login trace data of each employee mentioned above can be: the device login traces left by each employee in the commercial bank's mobile banking, online banking and other electronic channels.

[0080] Based on this, at least one characteristic parameter among the frequency of use, usage percentage, and number of users is constructed through the electronic device login trace data of the above-mentioned employees and the corresponding feature-derived technical means. Furthermore, a model of employees' commonly used equipment is established based on the constructed characteristic parameters.

[0081] In this way, by establishing an employee commonly used device model containing rules with complex judgment conditions, interference data can be eliminated, thereby obtaining accurate and effective commonly used device information of the target employees and improving the data quality of the commonly used device information obtained.

[0082] In some embodiments, the location information may include the target employee's frequently used location information, such as the target employee's frequently used latitude and longitude, IP address, and other location information. Similarly, to effectively filter out the target user's frequently used location information to improve the accuracy of subsequent data applications, before obtaining the target employee's N-dimensional parameter information, the account identification method may further include:

[0083] Based on the electronic device login trace data of each employee, derive at least one characteristic parameter of location login frequency, login proportion, and number of location logins;

[0084] Establish a model of employees' frequently used locations based on at least one characteristic parameter among location login frequency, login proportion, and number of location logins;

[0085] Determine the target employees' frequently used location information based on the employee frequently used location model.

[0086] In an embodiment of the present application, by establishing an employee common location model containing rules with complex judgment conditions, interference data can be eliminated, thereby obtaining accurate and effective common location information of the target employees, thereby improving the quality of the obtained parameter information.

[0087] In S120 , during specific implementation, the target parameter information in the N-dimensional parameter information may be matched with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information.

[0088] It should be noted that the target parameter information can be any dimension parameter information in the above-mentioned N-dimensional parameter information. For example, the target parameter information can be the basic information of the target employee. In this case, the above-mentioned P reference target information can correspond to the basic information of P customers owned by the commercial bank.

[0089] In an embodiment, by matching the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively, the degree of matching between the target parameter information and each reference target parameter information in the P reference target parameter information can be calculated respectively. For example, the similarity between the target parameter information and the P reference target parameter information can be calculated by methods such as Euclidean distance and Manhattan distance, so that P control degree scores corresponding to the target parameter information can be generated.

[0090] In some embodiments, considering the complexity and diversity of employee parameter information, in order to obtain a more accurate control degree score, the target parameter information in the N-dimensional parameter information is matched with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information, which may include:

[0091] Determine the preset control account model corresponding to the target parameter information based on the dimension to which the target parameter information belongs;

[0092] Through the preset control account model, the target parameter information in the N-dimensional parameter information is matched with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information; wherein, the preset control account model can be constructed based on P reference target parameter information.

[0093] It should be noted that for any dimension of the above-mentioned N-dimensional parameter information, there may be a corresponding preset control account model under that dimension.

[0094] Among them, the preset control account model can be pre-built based on P reference target parameter information.

[0095] During specific implementation, the dimension to which the target parameter information belongs can be determined by judging whether the target parameter information is basic information, transaction information, device information, or location information.

[0096] The preset control account model corresponding to the target parameter information can be pre-constructed based on P reference target parameter information. As an example, when the target parameter information is basic information, the corresponding P reference target parameter information is P basic customer information. Data processing such as feature extraction and quantification is performed on the P basic customer information to construct the preset control account model.

[0097] In one implementation, the preset control account model is periodically run to match the target parameter information in the N-dimensional parameter information with the P reference target parameter information, thereby outputting P control degree scores using the preset control account model. It should be noted that there should be a one-to-one correspondence between the P target parameter information and the P control degree scores.

[0098] It should be noted that the control degree score can be used to indicate the degree of similarity between the target parameter information of the target employee and the target parameter information of a reference customer. For example, when the target parameter information is the basic information of the target employee, the control degree score can indicate the degree of similarity between the basic information of the target employee and the basic information of a reference customer.

[0099] In S130 , during specific implementation, the control account corresponding to the target employee and the target parameter information may be determined from a target account set including P accounts corresponding to the P reference target parameter information according to the P control degree scores.

[0100] For example, P control degree scores may be compared with preset thresholds respectively. When a control degree score is detected to be higher than the preset threshold, it may be considered that the target parameter information of the target employee is highly similar to a certain customer reference target parameter information. At this time, the account corresponding to the control degree score is identified as the control account corresponding to the above-mentioned target employee and target parameter information.

[0101] In this way, by detecting and judging the P control degree scores respectively, the control account corresponding to the target employee and the target parameter information can be determined. Considering the actual situation, the number of the control accounts determined above can be at least one or zero.

[0102] In some embodiments, in order to monitor transaction behavior of identified control accounts to further improve employee management effectiveness, after determining the control accounts corresponding to the target employee and target parameter information in the target account set based on the P control degree scores, the account identification method may further include:

[0103] Obtain account transaction behavior characteristics of Q controlled accounts of the target user. The Q controlled accounts may include the control accounts of the target employee corresponding to each parameter information in the N-dimensional parameter information, where Q is a positive integer.

[0104] Input the account transaction behavior characteristics of the Q control accounts into the target control account transaction monitoring model respectively, and obtain Q monitoring results corresponding to the Q control accounts one by one;

[0105] When at least one monitoring result among the Q monitoring results indicates that the account transaction behavior characteristics are abnormal, a transaction abnormality alarm message is output.

[0106] Specifically, the Q control accounts may be control accounts in multiple dimensions obtained after performing the control account identification process on each dimension of the N-dimensional parameter information of the target employee.

[0107] Based on the identified Q controlled accounts of the target user, in specific implementations, corresponding big data technologies can be used to obtain the account transaction behavior characteristics corresponding to each of the Q controlled accounts. Based on this, the account transaction behavior characteristics of the Q controlled accounts are respectively input into the target controlled account transaction monitoring model, thereby obtaining Q monitoring results output by the target controlled account transaction monitoring model, corresponding one-to-one to the Q controlled accounts.

[0108] In this manner, the Q monitoring results can be individually tested, and if at least one of the Q monitoring results indicates abnormal account transaction behavior characteristics, a transaction anomaly alert message can be output. For example, the monitoring results can be represented by specific score information, and the Q monitoring results can be individually compared with a preset abnormality score threshold. If a monitoring result score exceeds the preset abnormality threshold, a transaction anomaly alert message can be output.

[0109] In an embodiment, the transaction abnormality alarm information may include at least one of specific transaction abnormality control account information and transaction abnormality monitoring results. The output form of the transaction abnormality alarm information may include but is not limited to SMS notification, email notification or voice broadcast alarm.

[0110] It should be noted that the above-mentioned target control account transaction monitoring model can be constructed based on common sense or actual transaction behavior regulations, or it can be constructed based on data information associated with account transaction activities. This application does not impose specific restrictions on this.

[0111] In some embodiments, considering the complexity of the parameter information involved, in order to more accurately monitor the identified control accounts, before inputting the account transaction behavior characteristics of the Q control accounts into the target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts, the account identification method may include:

[0112] Obtain target transaction flow data;

[0113] Extracting transaction feature variables from target transaction flow data, where the transaction feature variables may include at least one of a basic transaction indicator, a loan and consumption indicator, a cash transaction indicator, and a corporate transaction indicator;

[0114] Based on transaction characteristic variables, a target control account transaction monitoring model is constructed.

[0115] Specifically, the target transaction flow data may be obtained based on big data technology. For example, when the target employees are employees of a commercial bank, the target transaction flow data may be the commercial bank transaction flow data.

[0116] The above-mentioned basic transaction indicators may include but are not limited to at least one of the transaction amount, number of transactions, loan-to-credit ratio, and proportion of transactions during abnormal time.

[0117] The above-mentioned borrowing and consumption indicators may include but are not limited to at least one of credit card consumption amount, third-party consumption amount, loan amount and annual income.

[0118] The above cash transaction indicators may include but are not limited to at least one of the deposit and withdrawal ratio, deposit and withdrawal times, deposit and withdrawal amount, large-value cash withdrawal and out-of-town deposit.

[0119] The above-mentioned corporate transaction indicators may include but are not limited to at least one of the proportion of corporate transactions with the same institution, the proportion of corporate transactions in different locations, the amount of corporate transactions, and the number of corporate transactions.

[0120] In a specific implementation, for example, commercial bank transaction flow data can be used as target transaction flow data. Transaction feature variables are extracted and quantified based on the commercial bank transaction flow data. A target controlled account transaction monitoring model is then constructed based on the extracted transaction feature variables. This target controlled account transaction monitoring model can be used to effectively monitor the transaction behavior characteristics of the controlled account, thereby reducing the probability of serious commercial accidents.

[0121] In some implementations, considering the differences among employees, in order to establish a more reasonable and accurate controlled account transaction detection model, a target controlled account transaction monitoring model is constructed based on transaction characteristic variables, which may include:

[0122] Determining, based on the transaction characteristic variables, the transaction characteristic variables for each group in the employee identity attribute grouping set; the employee identity attribute grouping set may be obtained based on identity attribute parameters of each employee; the identity attribute parameters may include at least one of the employee's region, organization, position, age, and salary level;

[0123] Based on the transaction characteristic variables of each group, a control account transaction monitoring model for each group is constructed;

[0124] The target control account transaction monitoring model may be any control account transaction monitoring model under each group.

[0125] Specifically, by rationally grouping the identity attribute parameters of the aforementioned employees and determining the distribution of the aforementioned transaction characteristic variables within each group, a control account transaction monitoring model corresponding to each group can be constructed based on the transaction characteristic variables within each group.

[0126] In some embodiments, in order to more reasonably and accurately detect the transaction behavior of employee-controlled accounts, the account transaction behavior characteristics of the Q controlled accounts are respectively output to the target controlled account transaction monitoring model to obtain Q monitoring results corresponding to the Q controlled accounts. The following may also be included:

[0127] Get the identity attribute parameters of the target employee;

[0128] Based on the identity attribute parameters of the target employee, determining the group to which the target employee belongs in the employee identity attribute group set;

[0129] Determine the target control account transaction monitoring model corresponding to the target employee's group based on the target employee's group;

[0130] The account transaction behavior characteristics of the Q control accounts are respectively input into the target control account transaction monitoring model corresponding to the group to which the target employee belongs, and Q monitoring results corresponding to the Q control accounts are obtained.

[0131] In an embodiment, before monitoring the transaction behaviors of the Q controlled accounts of the target employee, the identity attribute parameters of the target employee may be obtained first, and the target employee may be grouped according to the identity attribute parameters.

[0132] In this way, after determining the group to which the target employee belongs, we can further determine the target control account transaction monitoring model corresponding to the group, and then monitor the Q control accounts through the determined target control account transaction monitoring model, and output Q monitoring results corresponding to the Q control accounts respectively.

[0133] The above embodiment groups and constructs the control account transaction monitoring model based on employee identity attribute parameters. In this way, it is possible to combine the differences and regularities among employees to achieve more reasonable monitoring of employee control account transaction behaviors.

[0134] In some embodiments, in order to further monitor the transaction scenarios of the control account, the account identification method may further include:

[0135] Build a monitoring model for abnormal scenarios of control accounts based on historical abnormal scenario data;

[0136] Based on the control account abnormal scenario monitoring model, detect whether the transaction scenarios of the target user's Q control accounts are abnormal;

[0137] When it is detected that any of the Q control accounts has an abnormal transaction scenario, an abnormal transaction scenario alarm message is output.

[0138] It should be noted that the source channels of the data information of the above-mentioned historical abnormal scenarios can be but are not limited to internal historical data of the enterprise organization, relevant transaction scenario regulations, etc., and this application does not impose any restrictions here.

[0139] Specifically, corresponding model rules can be designed based on the data information of the above-mentioned historical abnormal scenarios, thereby realizing the construction of a monitoring model for abnormal scenarios of control accounts.

[0140] During specific implementation, based on the control account abnormal scenario monitoring model constructed above, the transaction scenarios of the target user's Q control accounts are detected to see if they are abnormal. If it is detected that any of the Q control accounts has an abnormal transaction scenario, the transaction scenario abnormality alarm information is output.

[0141] For example, when the employee is an employee of a commercial bank, the above-mentioned abnormal transaction scenario may be an abnormal transaction scenario of collecting customer funds, which may be specifically manifested as: at least one controlled account of the target employee receives large-amount one-way transfers from multiple customers, and the direction of fund flow is similar; the above-mentioned abnormal transaction scenario may also be an abnormal transaction scenario of misappropriation of customer funds, which may be specifically manifested as: the target employee receives a transfer from a controlled account, and the login method before and after the transaction is similar.

[0142] The aforementioned abnormal transaction scenario can also involve an abnormal transaction scenario involving a customer, specifically, a situation where multiple control accounts of the target employee log into the same device within a short period of time. It is understood that due to the complexity and diversity of actual transaction scenarios, this application does not limit this specific abnormal transaction scenario.

[0143] In an embodiment, the transaction scene abnormality alarm information may include at least one of specific transaction scene abnormality control account information and abnormal transaction scene information. The output form of the transaction scene abnormality alarm information may include but is not limited to SMS notification, email notification or voice broadcast alarm, etc.

[0144] Based on the account identification method provided in the above embodiment, this application also provides an account identification device corresponding to the above account identification method. Figure 2 A detailed introduction to the account identification device is given.

[0145] Figure 2 A schematic structural diagram of an account identification device provided in yet another embodiment of the present application is shown. Figure 2 The account identification device 200 shown includes:

[0146] A first acquisition module 210 is configured to acquire N-dimensional parameter information of a target employee, where the N-dimensional parameter information includes at least one of basic information, transaction information, device information, and location information, where N is a positive integer;

[0147] The first matching module 220 is configured to match the target parameter information in the N-dimensional parameter information with P reference target parameter information to obtain P control degree scores corresponding to the target parameter information, where P is a positive integer;

[0148] The identification module 230 is used to determine the control account corresponding to the target employee and the target parameter information in the target account set according to the P control degree scores, wherein the target account set includes P accounts corresponding to the P reference target parameter information.

[0149] The account identification device of the embodiment of the present application can obtain multi-dimensional parameter information of the target employee through the corresponding functional module, and then match the parameter information under any dimension with multiple reference target parameter information to obtain multiple control degree scores. In this way, the control account corresponding to the target employee and the target parameter information can be identified based on multiple control degree scores and target account sets. An account identification method provided by the present application can identify the control account of an employee in combination with multi-dimensional parameter information, so as to subsequently monitor and alert the transaction behavior and transaction scenarios of the employee's control account. In this way, the improper behavior of employees can be accurately monitored, thereby effectively reducing the probability of malicious business incidents.

[0150] In some implementations, considering the complexity and diversity of employee parameter information, in order to obtain a more accurate control degree score, the first matching module 220 may specifically include:

[0151] The first determination submodule may be configured to determine a preset control account model corresponding to the target parameter information according to the dimension to which the target parameter information belongs;

[0152] The first sub-module is obtained, which matches the target parameter information in the N-dimensional parameter information with P reference target parameter information through the preset control account model to obtain P control degree scores corresponding to the target parameter information; wherein the preset control account model can be constructed based on P reference target parameter information.

[0153] In some embodiments, in order to monitor transaction behavior of identified control accounts to further improve employee management effectiveness, after determining the control accounts corresponding to the target employees and target parameter information in the target account set based on the P control degree scores, the account identification device 200 may further include:

[0154] The second acquisition module may be used to obtain account transaction behavior characteristics of Q controlled accounts of the target user, where the Q controlled accounts may include the control accounts of the target employee corresponding to each parameter information in the N-dimensional parameter information, and Q is a positive integer;

[0155] The first obtaining module can be used to input the account transaction behavior characteristics of Q control accounts into the target control account transaction monitoring model respectively, and obtain Q monitoring results corresponding to the Q control accounts;

[0156] The first output module may be configured to output transaction abnormality alarm information when at least one monitoring result among the Q monitoring results indicates that the account transaction behavior characteristics are abnormal.

[0157] In some embodiments, considering the complexity of the parameter information involved, in order to more accurately monitor the identified control accounts, before inputting the account transaction behavior characteristics of the Q control accounts into the target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts, the account identification device 200 may include:

[0158] The third acquisition module can be used to obtain target transaction flow data;

[0159] An extraction module may be used to extract transaction feature variables from target transaction flow data. The transaction feature variables may include at least one of basic transaction indicators, loan and consumption indicators, cash transaction indicators, and corporate transaction indicators.

[0160] The first building module can be used to build a target control account transaction monitoring model based on transaction characteristic variables.

[0161] In some implementations, in order to establish a more reasonable and accurate control account transaction detection model, taking into account the differences among employees, the first building module may include:

[0162] The second determination submodule may be configured to determine, based on the transaction characteristic variables, the transaction characteristic variables for each group in the employee identity attribute grouping set; the employee identity attribute grouping set may be obtained based on identity attribute parameters of each employee; the identity attribute parameters may include at least one of the employee's region, organization, position, age, and salary level;

[0163] The construction submodule can be used to construct a control account transaction monitoring model for each group based on the transaction characteristic variables of each group;

[0164] The target control account transaction monitoring model may be any control account transaction monitoring model under each group.

[0165] In some implementations, in order to more reasonably and accurately detect transaction behaviors of employee-controlled accounts, the first obtaining module may further specifically include:

[0166] The acquisition submodule can be used to obtain the identity attribute parameters of the target employee;

[0167] The second determination submodule may be used to determine the group to which the target employee belongs in the employee identity attribute group set based on the identity attribute parameters of the target employee;

[0168] The third determination submodule may be used to determine the target control account transaction monitoring model corresponding to the target employee's group according to the target employee's group;

[0169] The second obtaining submodule can be used to input the account transaction behavior characteristics of the Q control accounts into the target control account transaction monitoring model corresponding to the group to which the target employee belongs, and obtain Q monitoring results corresponding to the Q control accounts.

[0170] In some embodiments, in order to further monitor the transaction scenarios of the control account, the account identification device 200 may further include:

[0171] The second building module can be used to build a control account abnormal scenario monitoring model based on historical abnormal scenario data;

[0172] The detection module can be used to detect whether the transaction scenarios of the target user's Q controlled accounts are abnormal based on the control account abnormal scenario monitoring model;

[0173] The second output module can be used to output transaction scenario abnormality alarm information when it is detected that any control account transaction scenario among the Q control accounts is abnormal.

[0174] In some embodiments, in order to effectively filter out the target user's frequently used device information and thus improve the accuracy of subsequent data applications, the device information may include the target employee's frequently used device information. Before obtaining the target employee's N-dimensional parameter information, the account identification device 200 may further include:

[0175] The fourth acquisition module can be used to obtain the electronic device login trace data of each employee;

[0176] The first derivation module can be used to derive at least one characteristic parameter of usage frequency, usage percentage, and number of users based on the electronic device login trace data of each employee;

[0177] The first establishment module can be used to establish a model of employees' frequently used equipment based on at least one characteristic parameter of usage frequency, usage ratio, and number of users;

[0178] The first determination module can be used to determine the target employee's commonly used device information based on the employee's commonly used device model and the target employee's electronic device login trace data.

[0179] In some embodiments, in order to effectively filter out the target user's frequently used location information and thereby improve the accuracy of subsequent data applications, the location information may include the frequently used location information of the target employee. Before obtaining the target employee's N-dimensional parameter information, the account identification device 200 may further include:

[0180] The second derivation module can be used to derive at least one characteristic parameter of location login frequency, login proportion, and number of location logins based on the electronic device login trace data of each employee;

[0181] The second establishment module can be used to establish a frequently used location model of employees based on at least one characteristic parameter of location login frequency, login ratio, and number of location logins;

[0182] The second determining module may be used to determine the target employee's frequently used location information based on the employee frequently used location model.

[0183] Figure 3 This is a structural diagram of an account identification device provided in another embodiment of the present application.

[0184] The account identification device may include a processor 301 and a memory 302 storing computer program instructions.

[0185] Specifically, the processor 301 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0186] The memory 302 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 302 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 302 may include removable or non-removable (or fixed) media. Where appropriate, the memory 302 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 302 is a non-volatile solid-state memory.

[0187] The memory may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.

[0188] The processor 301 implements any one of the account identification methods in the above embodiments by reading and executing computer program instructions stored in the memory 302 .

[0189] In one example, the data account identification device may further include a communication interface 303 and a bus 310. Figure 3 As shown, the processor 301 , the memory 302 , and the communication interface 303 are connected via a bus 310 and communicate with each other.

[0190] The communication interface 303 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0191] Bus 310 includes hardware, software or both, and couples the components of the account identification device to each other. For example, and not limitation, the bus may include an accelerated graphics port (AGP) or other graphics bus, an enhanced industry standard architecture (EISA) bus, a front-side bus (FSB), a hypertransport (HT) interconnect, an industry standard architecture (ISA) bus, an infinite bandwidth interconnect, a low pin count (LPC) bus, a memory bus, a microchannel architecture (MCA) bus, a peripheral component interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a serial advanced technology attachment (SATA) bus, a video electronics standard association local (VLB) bus or other suitable bus or a combination of two or more of these. Where appropriate, bus 310 may include one or more buses. Although the present application describes and illustrates a specific bus, the present application considers any suitable bus or interconnect.

[0192] The account identification device executes the account identification method in the embodiment of the present application, thereby achieving Figure 1 Describes the account identification method.

[0193] In addition, in conjunction with the account identification method in the above embodiments, embodiments of the present application may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by a processor, any one of the account identification methods in the above embodiments is implemented.

[0194] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0195] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.

[0196] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0197] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or flowchart and the combination of the boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.

[0198] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. An account identification method, characterized in that: include: Obtaining N-dimensional parameter information of the target employee, where the N-dimensional parameter information includes at least one of basic information, transaction information, device information, and location information, where N is a positive integer; Matching the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information, where P is a positive integer; Determining, in a target account set, a control account of the target employee corresponding to the target parameter information based on the P control degree scores, wherein the target account set includes P accounts corresponding one-to-one to the P reference target parameter information; The step of matching the target parameter information in the N-dimensional parameter information with P reference target parameter information to obtain P control degree scores corresponding to the target parameter information includes: Determining a preset control account model corresponding to the target parameter information according to the dimension to which the target parameter information belongs; Matching the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively through the preset control account model to obtain P control degree scores corresponding to the target parameter information; Wherein, the preset control account model is constructed based on the P reference target parameter information; The step of determining, in a target account set, a control account corresponding to the target employee and the target parameter information based on the P control degree scores includes: By comparing the P control degree scores with a preset threshold value respectively, a control account corresponding to the target employee and the target parameter information in the target account set is determined, and the control degree score of the control account is higher than the preset threshold value.

2. The method according to claim 1, characterized in that After determining, in the target account set, the control account corresponding to the target employee and the target parameter information based on the P control degree scores, the method further includes: Obtaining account transaction behavior characteristics of Q controlled accounts of the target employee, where the Q controlled accounts include the controlled accounts of the target employee corresponding to each parameter information in the N-dimensional parameter information, where Q is a positive integer; Inputting the account transaction behavior characteristics of the Q control accounts into the target control account transaction monitoring model respectively, and obtaining Q monitoring results corresponding to the Q control accounts; When at least one monitoring result among the Q monitoring results indicates that the account transaction behavior characteristics are abnormal, transaction abnormality alarm information is output.

3. The method according to claim 2, characterized in that Before inputting the account transaction behavior features of the Q control accounts into the target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts, the method includes: Obtain target transaction flow data; Extracting transaction feature variables from the target transaction flow data, wherein the transaction feature variables include at least one of a basic transaction index, a loan and consumption index, a cash transaction index, and a corporate transaction index; Based on the transaction characteristic variables, the target control account transaction monitoring model is constructed.

4. The method according to claim 3, characterized in that The step of constructing the target control account transaction monitoring model based on the transaction characteristic variables includes: Determining, based on the transaction characteristic variables, transaction characteristic variables for each group in a set of employee identity attribute groups, wherein the set of employee identity attribute groups is obtained by dividing the employee identity attribute parameters based on the employee's region, organization, position, age, and salary level; Constructing a control account transaction monitoring model for each group based on the transaction characteristic variables for each group; The target control account transaction monitoring model is any control account transaction monitoring model under each group.

5. The method according to any one of claims 2 to 4, characterized in that The step of outputting the account transaction behavior features of the Q control accounts to a target control account transaction monitoring model to obtain Q monitoring results corresponding to the Q control accounts may further include: Obtaining identity attribute parameters of the target employee; Based on the identity attribute parameters of the target employee, determining the group to which the target employee belongs in the employee identity attribute group set; Determining, according to the group to which the target employee belongs, the target control account transaction monitoring model corresponding to the group to which the target employee belongs; The account transaction behavior features of the Q control accounts are respectively input into the target control account transaction monitoring model corresponding to the group to which the target employee belongs, and Q monitoring results corresponding to the Q control accounts are obtained.

6. The method according to any one of claims 1 to 4, characterized in that The method further comprises: Build a monitoring model for abnormal scenarios of control accounts based on historical abnormal scenario data; Detecting whether the transaction scenarios of the Q controlled accounts of the target employee are abnormal based on the controlled account abnormal scenario monitoring model; When it is detected that any of the Q control accounts has an abnormal transaction scenario, an abnormal transaction scenario alarm message is output.

7. The method according to claim 1, characterized in that The device information includes commonly used device information of the target employee. Before obtaining the N-dimensional parameter information of the target employee, the method further includes: Obtain login trace data of each employee's electronic device; Deriving at least one characteristic parameter of usage frequency, usage percentage, and number of users based on the electronic device login trace data of each employee; Establishing a model of employees' frequently used devices based on at least one characteristic parameter of the usage frequency, usage percentage, and number of users; Based on the employee's frequently used device model, the frequently used device information of the target employee is determined according to the electronic device login trace data of the target employee.

8. The method according to claim 7, characterized in that The location information includes the common location information of the target employee. Before obtaining the N-dimensional parameter information of the target employee, the method further includes: Based on the electronic device login trace data of each employee, deriving at least one characteristic parameter of location login frequency, login proportion, and number of location logins; Establishing a frequently used location model of employees based on at least one characteristic parameter of the location login frequency, login proportion, and number of location logins; The frequently used location information of the target employee is determined according to the frequently used location model of the employee.

9. An account identification device, characterized in that: The device comprises: A first acquisition module is configured to acquire N-dimensional parameter information of a target employee, wherein the N-dimensional parameter information includes at least one of basic information, transaction information, device information, and location information, where N is a positive integer; A first matching module is configured to match the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively to obtain P control degree scores corresponding to the target parameter information, where P is a positive integer; an identification module, configured to determine, in a target account set, a control account of the target employee corresponding to the target parameter information based on the P control degree scores, wherein the target account set includes P accounts corresponding one-to-one to the P reference target parameter information; The first matching module is specifically configured to: determine a preset control account model corresponding to the target parameter information according to the dimension to which the target parameter information belongs; Matching the target parameter information in the N-dimensional parameter information with P reference target parameter information respectively through the preset control account model to obtain P control degree scores corresponding to the target parameter information; Wherein, the preset control account model is constructed based on the P reference target parameter information; The identification module is specifically used to: determine the control account corresponding to the target employee and the target parameter information in the target account set by comparing the P control degree scores with the preset threshold respectively, and the control degree score of the control account is higher than the preset threshold.

10. An account identification device, characterized in that: The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the account identification method according to any one of claims 1 to 8 is implemented.

11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the account identification method according to any one of claims 1 to 8 is implemented.

12. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the account identification method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Account management method and device

    CN113065106A

  • Employee abnormal transaction behavior recognition method, apparatus and device, and storage medium

    CN113129058A