Monitoring Method, Device, Equipment, Medium and Program Product for High-Risk Services
By identifying high-frequency and sensitive transaction links, the method addresses the challenge of accurately monitoring and testing high-risk business processes in complex financial systems, enhancing testing efficiency and coverage.
Patent Information
- Application Number
- CN202210690717.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-17
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-06-17
AI Technical Summary
In the financial field, the testing difficulties of the host and platform dual-core systems have been greatly improved, and it is difficult for testers to accurately control key test objects, resulting in frequent missed test problems.
By obtaining the correlation between the calling frequency of the transaction link and the key data table, identifying high-frequency and sensitive transaction links, determining the risk level weight of high-risk services, generating a monitoring list, and performing automated monitoring.
It realizes automated identification and accurate monitoring of high-risk services, solves the problems of inadequate testing and inaccurate risk control, and improves test coverage and efficiency.
Smart Images

Figure CN115063214B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of testing technologies and can be applied to the financial field or other fields. Specifically, it relates to a monitoring method, device, electronic device, storage medium, and program product for high-risk services. Background Art
[0002] Currently, in the financial field, services originally running on the mainframe are gradually transferred to self-developed platforms. To ensure the stable operation of the system, testing is required during system updates. However, at the present stage, the scale and complexity of the "mainframe + platform" dual-core system are beyond imagination, the testing difficulties have increased significantly, and it is difficult for testers to accurately control the testing focus during the testing process, and it is easy to miss the testing of key testing objects, with worrying consequences. Summary of the Invention
[0003] In view of the above problems, the present disclosure provides a monitoring method, device, electronic device, storage medium, and program product for high-risk services.
[0004] According to a first aspect of the present disclosure, there is provided a monitoring method for high-risk services, which includes:
[0005] Obtain the first call frequency of at least one transaction link;
[0006] Extract the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links;
[0007] Extract the transaction links associated with the key data of the key data table to obtain sensitive transaction links;
[0008] Determine high-risk services and the risk level weights of the high-risk services at least based on the high-frequency transaction links and the sensitive transaction links;
[0009] Generate a high-risk service monitoring list according to the high-risk services and the risk level weights of the high-risk services.
[0010] According to an embodiment of the present disclosure, the monitoring method further includes;
[0011] Obtain the second call frequency of at least one service;
[0012] Extract the services whose second call frequency meets the second preset condition to obtain high-frequency services;
[0013] The determining high-risk services and the risk level weights of the high-risk services at least based on the high-frequency transaction links and the sensitive transaction links includes:
[0014] Determine high-risk services and the risk level weights of the high-risk services based on the high-frequency services, the high-frequency trading links, and the sensitive trading links.
[0015] According to an embodiment of the present disclosure, the determining of the high-risk services and the risk level weights of the high-risk services based on the high-frequency services, the high-frequency trading links, and the sensitive trading links includes:
[0016] Extract services related to at least one of the high-frequency services, the high-frequency trading links, and the high-risk trading links to obtain the high-risk services;
[0017] When the high-risk services are related to at least two of the high-frequency services, the high-frequency trading links, and the high-risk trading links, determine the risk level weight of the high-risk services as the first risk level weight;
[0018] When the high-risk services are related to one of the high-frequency services, the high-frequency trading links, and the high-risk trading links, determine the risk level weight of the high-risk services as the second risk level weight;
[0019] The first risk level weight is higher than the second risk level weight.
[0020] According to an embodiment of the present disclosure, the extracting of the trading links associated with the key data of the key data table to obtain the sensitive trading links includes:
[0021] Obtain a preset target service;
[0022] Extract the services called by the target service to obtain the first service;
[0023] Determine the key data table according to the data tables involved in the key changes of the first service, where the key data in the key data table includes the data involved in the key changes of the target service;
[0024] Extract the SQL statements related to the key data;
[0025] Determine the sensitive trading links according to the logic in the extracted SQL statements;
[0026] According to an embodiment of the present disclosure, the extracting of the trading links associated with the key data of the key data table to obtain the sensitive trading links includes:
[0027] Obtain a preset target data table;
[0028] Determine the key data table according to the target data table, where the key data in the key data table includes the preset data that has changed in the target data table;
[0029] Extract the service that calls the key data to obtain a second service;
[0030] Determine the sensitive transaction link according to the extracted second service.
[0031] According to an embodiment of the present disclosure, the key data includes at least one of account-related data and confidential data.
[0032] According to an embodiment of the present disclosure, the monitoring method further includes:
[0033] Obtain supplementary monitoring information of all transaction links;
[0034] When the supplementary monitoring information of at least one transaction link meets the third preset condition, update the high-risk business monitoring list according to the business involved in the transaction link.
[0035] According to an embodiment of the present disclosure, when the supplementary monitoring information of at least one transaction link meets the third preset condition, updating the high-risk business monitoring list according to the business involved in the transaction link includes:
[0036] When the supplementary monitoring information of the transaction link in the high-risk business meets the third preset condition, increase the risk level weight of the high-risk business.
[0037] According to an embodiment of the present disclosure, the supplementary monitoring information includes the length information and complexity information of the transaction link, and the timeout information of each level of service in the transaction link.
[0038] According to an embodiment of the present disclosure, the monitoring method further includes:
[0039] When the version is updated, obtain the changed content;
[0040] Determine whether there is a newly added large table access according to the changed content;
[0041] When there is the newly added large table access, update the high-risk business monitoring list according to the business involved in the newly added large table access.
[0042] According to an embodiment of the present disclosure, the monitoring method further includes:
[0043] Establish a search association between the high-risk business and the high-frequency transaction link and / or sensitive transaction link it involves, and perform visual display.
[0044] According to an embodiment of the present disclosure, the monitoring method further includes:
[0045] According to the similarity algorithm, compare the currently identified high-risk services with the high-risk service monitoring list generated last time;
[0046] According to the comparison result, determine the risk level weight for the currently identified high-risk services.
[0047] The second aspect of the present disclosure provides a monitoring device for high-risk services, which includes:
[0048] An acquisition module, configured to acquire the first call frequency of at least one transaction link;
[0049] A first extraction module, configured to extract the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links;
[0050] A second extraction module, configured to extract the transaction links associated with the key data of the key data table to obtain sensitive transaction links;
[0051] A first processing module, configured to determine high-risk services and the risk level weights of the high-risk services at least based on the high-frequency transaction links and the sensitive transaction links;
[0052] A second processing module, configured to generate a high-risk service monitoring list according to the high-risk services and the risk level weights of the high-risk services.
[0053] The third aspect of the present disclosure provides an electronic device, including: one or more processors; a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the above-mentioned monitoring method for high-risk services.
[0054] The fourth aspect of the present disclosure further provides a computer-readable storage medium, on which executable instructions are stored, and when the instructions are executed by a processor, the processor is caused to execute the above-mentioned monitoring method for high-risk services.
[0055] The fifth aspect of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the above-mentioned monitoring method for high-risk services is implemented.
[0056] The above one or more embodiments have the following advantages or beneficial effects:
[0057] By adopting the monitoring method for high-risk services according to the embodiments of the present disclosure, high-risk services can be determined based on high-frequency trading links and sensitive trading links, thereby realizing the automatic identification of high-risk services with accurate and efficient identification effects. After determining the high-risk services, the trading links invoked by the high-risk services and the services invoked by the trading links can be monitored to a corresponding degree according to the risk level weights of the high-risk services. In this way, during testing, testers can focus on the test content related to high-risk services according to the monitoring objects, so that the test process can center on the key points of the testing work, solving the problems of incomplete testing and inaccurate risk control in the traditional test scheme. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Through the following description of the embodiments of the present disclosure with reference to the drawings, the above content and other objects, features and advantages of the present disclosure will become clearer. In the drawings:
[0059] Figure 1 Schematically shows an application scenario diagram of a monitoring method, device, electronic device, storage medium and program product for high-risk services according to an embodiment of the present disclosure;
[0060] Figure 2 Schematically shows one of the flowcharts of the monitoring method for high-risk services according to an embodiment of the present disclosure;
[0061] Figure 3 Schematically shows another flowchart of the monitoring method for high-risk services according to an embodiment of the present disclosure;
[0062] Figure 4 Schematically shows the flowchart of determining a sensitive trading link through a forward identification algorithm according to an embodiment of the present disclosure;
[0063] Figure 5 Schematically shows the flowchart of determining a sensitive trading link through a reverse identification algorithm according to an embodiment of the present disclosure;
[0064] Figure 6 Schematically shows a third flowchart of the monitoring method for high-risk services according to an embodiment of the present disclosure;
[0065] Figure 7 Schematically shows a fourth flowchart of the monitoring method for high-risk services according to an embodiment of the present disclosure;
[0066] Figure 8 Schematically shows the structural block diagram of a monitoring device for high-risk services according to an embodiment of the present disclosure;
[0067] Figure 9 Schematically shows the block diagram of an electronic device suitable for implementing the monitoring method for high-risk services according to an embodiment of the present disclosure. Detailed Implementation Modes
[0068] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.
[0069] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0070] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0071] In the case of using expressions such as "at least one of A, B, and C", generally, it should be interpreted according to the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0072] It should be noted that the monitoring method, device, electronic device, storage medium, and program product for high-risk services provided by the present disclosure relate to the field of testing technologies. The monitoring method, device, electronic device, storage medium, and program product for high-risk services provided by the embodiments of the present disclosure can be applied to the financial field or any field other than the financial field. For example, the monitoring method, device, electronic device, storage medium, and program product for high-risk services provided by the embodiments of the present disclosure can be applied to testing services in the financial field. The present disclosure does not limit the application fields of the monitoring method, device, electronic device, storage medium, and program product for high-risk services.
[0073] In the technical solution of the present disclosure, the processing of the collection, storage, use, processing, transmission, provision, disclosure, and application, etc. of the user's personal information involved all comply with the provisions of relevant laws and regulations, take necessary confidentiality measures, and do not violate public order and good customs.
[0074] Currently, a single business function calls multiple services to achieve a business function. The multiple services called by a single business can form the transaction link of that business. Since different businesses call different services, and the same service is called by multiple businesses, the entire transaction link is intricate, and the occupancy rates of each transaction link and even each service vary. Coupled with uncertainties such as loopholes in the program transformation process, table structures, and data volumes, situations of business transaction timeouts or error reports often occur. To strictly control risks, the embodiments of the present disclosure provide a monitoring method for high-risk businesses, which can identify and monitor high-risk businesses. Among them, the monitoring method for high-risk businesses in the embodiments of the present disclosure includes: obtaining the first call frequency of at least one transaction link; extracting the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links; extracting the transaction links associated with the key data of the key data table to obtain sensitive transaction links; determining high-risk businesses and the risk level weights of high-risk businesses at least based on the high-frequency transaction links and sensitive transaction links; generating a high-risk business monitoring list according to the high-risk businesses and the risk level weights of high-risk businesses.
[0075] By using the monitoring method for high-risk businesses in the embodiments of the present disclosure, high-risk businesses can be determined based on high-frequency transaction links and sensitive transaction links, thereby realizing the automated identification of high-risk businesses, and the identification effect is accurate and efficient. After determining the high-risk businesses, the transaction links called by the high-risk businesses and the services called by the transaction links can be monitored to a corresponding extent according to the risk level weights of the high-risk businesses. In this way, during testing, testers can focus on the test content related to high-risk businesses according to the monitoring objects, so that the test process can focus on the key points of the test work, and solve the problems of incomplete testing and inaccurate risk control in the traditional test scheme.
[0076] Figure 1 Schematically shows an application scenario diagram of a monitoring method, device, electronic device, storage medium, and program product for high-risk businesses according to an embodiment of the present disclosure. As Figure 1 shown, the application scenario 100 according to this embodiment may include terminal devices 101, 102, 103, a network 104, and a server 105. The network 104 is used to provide a medium for communication links between the terminal devices 101, 102, 103 and the server 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0077] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0078] Terminal devices 101, 102, and 103 can be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop computers, desktop computers, and so on.
[0079] Server 105 can be a server that provides various services, such as a background management server that supports the websites browsed by users using terminal devices 101, 102, and 103 (for example only). The background management server can analyze and process data such as received user requests, and feedback the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0080] It should be noted that the monitoring method for high-risk services provided by the embodiments of the present disclosure can generally be executed by server 105. Correspondingly, the monitoring device for high-risk services provided by the embodiments of the present disclosure can generally be set in server 105. The monitoring method for high-risk services provided by the embodiments of the present disclosure can also be executed by a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105. Correspondingly, the monitoring device for high-risk services provided by the embodiments of the present disclosure can also be set in a server or a server cluster different from server 105 and capable of communicating with terminal devices 101, 102, 103 and / or server 105.
[0081] It should be understood that Figure 1 the numbers of terminal devices, networks, and servers in
[0082] are merely illustrative. According to the implementation requirements, there can be any number of terminal devices, networks, and servers. Figure 1 Based on the Figures 2 to 7 scenario described below, the monitoring method for high-risk services of the public embodiments will be described in detail through
[0083] Figure 2 One of the flowcharts of the monitoring method for high-risk services according to the embodiments of the present disclosure is schematically shown, as Figure 2 shown. The monitoring method for high-risk services of this embodiment includes steps S210 to S250.
[0084] It should be noted that although Figure 2The steps in [figure] are displayed in sequence according to the instructions of the arrows. However, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the figure may include multiple sub-steps or multiple stages. These sub-steps or stages do not necessarily need to be completed at the same time, but can be executed at different times. Their execution order does not necessarily need to be sequential, but can be executed alternately or in turns with at least a part of other steps or sub-steps or stages of other steps.
[0085] In step S210, obtain the first call frequency of at least one transaction link.
[0086] In the embodiments of the present disclosure, a transaction link may refer to a link composed of services required to implement a service. For example, for a transfer service, the transaction link may include a withdrawal service and a deposit service, etc. The first call frequency may refer to the call volume of the transaction link within a preset time period.
[0087] In step S220, extract the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links.
[0088] In the embodiments of the present disclosure, the transaction links may be sorted according to the call volume from high to low, and the top N transaction links may be selected therefrom to obtain high-frequency transaction links. Where N is a positive integer. For example, N may be set to 100.
[0089] In step S230, extract the transaction links associated with the key data of the key data table to obtain sensitive transaction links.
[0090] In the embodiments of the present disclosure, the key table data may include the data tables called by the preset target services, or may include the preset target data tables. Among them, the target services may include relatively sensitive services, such as account-related services and confidential services, etc. The target data tables may include the data tables involving relatively sensitive data, and relatively sensitive data such as account-related data and confidential data, etc. The key data may include the data that has changed in the data table. For example, for account-related services, the key data may include the transfer amount and the received amount, etc.
[0091] In step S240, determine the high-risk services and the risk level weights of the high-risk services based on at least the high-frequency transaction links and the sensitive transaction links.
[0092] In the embodiments of the present disclosure, the high-risk services may include high-frequency services and sensitive services.
[0093] Exemplarily, high-frequency services can be determined based on the high-frequency trading link. For example, when a service invokes the high-frequency trading link, this service can be considered a high-frequency service.
[0094] Exemplarily, sensitive services can be determined based on the sensitive trading link. For example, when a service invokes the sensitive trading link, this service can be considered a sensitive service.
[0095] In step S250, a high-risk service monitoring list is generated based on the high-risk services and the risk level weights of the high-risk services.
[0096] In the embodiments of the present disclosure, the risk level weights of high-risk services can be determined according to the trading links invoked by the high-risk services. For example, when the trading link invoked by a high-risk service is a high-frequency trading link, the risk level weight of the high-risk service can be determined to be a lower level. When the trading link invoked by a high-risk service is a high-frequency trading link and a sensitive trading link, the risk level weight of the high-risk service can be determined to be a higher level.
[0097] By using the high-risk service monitoring method of the embodiments of the present disclosure, high-risk services can be determined based on the high-frequency trading link and the sensitive trading link, thereby realizing the automatic identification of high-risk services, and the identification effect is accurate and efficient. After determining the high-risk services, according to the risk level weights of the high-risk services, the trading links invoked by the high-risk services and the services invoked by these trading links can be monitored to a corresponding degree. In this way, during testing, testers can focus on the test content related to high-risk services according to the monitoring objects, so that the test process can focus on the test work, and solve the problems of incomplete testing and inaccurate risk control in the traditional test scheme.
[0098] The following combines Figures 2 to 7 , and further illustrates the high-risk service monitoring method of the embodiments of the present disclosure.
[0099] The overall system architecture of the high-risk service monitoring method of the embodiments of the present disclosure is as follows, divided into four layers: A business scenario layer, B service layer, C technical support layer, and D data foundation layer. The business scenario layer includes specific services, including payment, deposit, remittance, etc. The service layer includes the main functions of the embodiments of the present disclosure: 1. Automatic identification of high-risk services; 2. Full-link intelligent analysis and monitoring; 3. Docking of trading links and business assets. The technical support layer includes the specific technologies, algorithms, and IT frameworks for supporting the three major functional blocks of the service layer. The data foundation layer includes the final storage locations of all services, businesses, and data, including Mysql, hosts, and Oracel, etc.
[0100] The following first illustrates the automatic identification of high-risk services in the embodiments of the present disclosure.
[0101] Figure 3 Schematically shows the second flowchart of the monitoring method for high-risk services according to an embodiment of the present disclosure. As Figure 3 shown, in some specific embodiments, the monitoring method further includes step S310 and step S320.
[0102] In step S310, obtain the second call frequency of at least one service.
[0103] In the embodiment of the present disclosure, the second call frequency may refer to the call volume of a service within a preset time period.
[0104] In step S320, extract the services whose second call frequency meets the second preset condition to obtain high-frequency services.
[0105] In the embodiment of the present disclosure, the services may be sorted according to the call volume from high to low, and the first M services may be selected therefrom to obtain high-frequency services. Where M is a positive integer. For example, M may be set to 100.
[0106] In some specific embodiments, step S240 includes step S241.
[0107] In step S241, determine the high-risk services and the risk level weights of the high-risk services according to the high-frequency services, high-frequency trading links, and sensitive trading links.
[0108] For example, for a service, when the trading link it calls is a high-frequency trading link, it can be determined that the service is a high-risk service; for another example, when one of the services in the trading link it calls is a high-frequency service, it can also be determined that the service is a high-risk service, and so on. Details are not listed one by one here.
[0109] In some specific embodiments, step S241 includes step S241.
[0110] In step S2411, extract the services that involve at least one of the high-frequency services, high-frequency trading links, and high-risk trading links to obtain high-risk services.
[0111] In the embodiment of the present disclosure, when a high-risk service involves at least two of the high-frequency services, high-frequency trading links, and high-risk trading links, determine the risk level weight of the high-risk service as the first risk level weight. When a high-risk service involves only one of the high-frequency services, high-frequency trading links, and high-risk trading links, determine the risk level weight of the high-risk service as the second risk level weight. Wherein, the first risk level weight is higher than the second risk level weight.
[0112] In the embodiments of the present disclosure, the risk level weights may include the risk level weights of high-risk services themselves, may also include the risk level weights of transaction links in high-risk services, and may further include the risk level weights of each service in the transaction links.
[0113] For example, when the risk level weight is the first risk level weight, the risk level weights of the high-risk service itself, the transaction link in the high-risk service, and each service in the transaction link are all the first risk level weight.
[0114] Optionally, in the embodiments of the present disclosure, the services invoked in the sensitive transaction link may also be determined as sensitive services. In this way, for a service, when one of the services in the invoked transaction link is a sensitive service, it can also be determined that the service is a high-risk service.
[0115] For example, for the transfer service, the invoked deposit service (withdrawal service) is both a high-frequency service, and at the same time, since the deposit service (withdrawal service) involves accounts, the deposit service (withdrawal service) is also a sensitive service. At this time, it can be determined that the risk level weight of the transfer service is the first risk level weight, where the risk level weight of the deposit service (withdrawal service) can also be the first risk level weight.
[0116] In some specific embodiments, in step S230, the sensitive transaction link may be identified through a forward identification algorithm and a reverse identification algorithm. The forward identification algorithm may mine potential sensitive transaction links through known sensitive services (i.e., the target services mentioned below), and the reverse identification algorithm may mine potential sensitive transaction links through known relatively important data tables (i.e., the target data tables mentioned below).
[0117] First, the forward identification algorithm will be described below. Figure 4 Schematically shows a flowchart for determining a sensitive transaction link according to an embodiment of the present disclosure. As Figure 4 shown, in some specific embodiments, step S230 includes steps S231 to S235.
[0118] In step S231, a preset target service is obtained.
[0119] In the embodiments of the present disclosure, the preset target services may include account-related services, confidential services, etc.
[0120] In step S232, the services invoked by the target service are extracted to obtain the first service.
[0121] In the embodiments of the present disclosure, all the services invoked by the target service may be obtained to obtain the first service.
[0122] In step S233, determine a key data table according to the data tables involved in the key changes of the first service, where the key data in the key data table includes the data involved in the key changes of the first service.
[0123] In the embodiments of the present disclosure, the key changes may include, for example, account-related changes or secrecy-related changes. In some specific embodiments, the key data includes at least one of account-related data and secrecy-related data.
[0124] For example, if the key data includes account-related data, the key changes may include adding, modifying, and deleting the account-related data, etc.
[0125] In step S234, extract the SQL statements involving the key data.
[0126] In step S235, determine the sensitive transaction link according to the logic in the extracted SQL statements.
[0127] In the embodiments of the present disclosure, through the SQL statements involving the key data, the logic of the key data changes can be obtained, so that all services associated with the changes of the key data can be found, and then the complete transaction link can be obtained. For example, when it is found that a modification to the account-related data is a withdrawal service, it can be analyzed through the SQL statements whether there is a corresponding deposit service. When there is a deposit service, it can be shown that the transaction link associated with the key data is a transfer transaction link. When there is no deposit service, it can be shown that the transaction link associated with the key data is a deposit transaction link.
[0128] Next, the reverse identification algorithm will be described. Figure 5 Schematically shows a flowchart of determining the sensitive transaction link through the reverse identification algorithm according to the embodiments of the present disclosure, as Figure 5 shown. In some specific embodiments, step S230 includes steps S236 to S239.
[0129] In step S236, obtain a preset target data table.
[0130] In the embodiments of the present disclosure, the target data table may include known relatively important data tables, such as account-related data tables and secrecy-related data tables, etc.
[0131] In step S237, determine a key data table according to the target data table, where the key data in the key data table includes the preset data that has changed in the target data table.
[0132] In the embodiments of the present disclosure, the target data table can be used as the key data table. The preset data may include the account-related data and secrecy-related data described above, etc. The key data may include the preset data that has changed such as addition, modification, and deletion.
[0133] In step S238, extract the service that invokes the key data to obtain the second service.
[0134] In step S239, determine the sensitive transaction link according to the extracted second service.
[0135] In the embodiment of the present disclosure, the transaction link that invokes the second service can be obtained, so as to obtain the sensitive transaction link.
[0136] Next, the full-link intelligent analysis and monitoring in the embodiment of the present disclosure will be described.
[0137] Figure 6 Schematically shows the third flowchart of the monitoring method for high-risk services according to the embodiment of the present disclosure. As Figure 6 shown, in some specific embodiments, the monitoring method further includes step S410 and step S420.
[0138] In step S410, obtain the supplementary monitoring information of all transaction links.
[0139] In some specific embodiments, the supplementary monitoring information includes the length information and complexity information of the transaction link, and the timeout information of each level of service in the transaction link.
[0140] In step S420, when the supplementary monitoring information of at least one transaction link meets the third preset condition, update the high-risk service monitoring list according to the service involved in this transaction link. Otherwise, end step S420.
[0141] In the embodiment of the present disclosure, the third preset condition can be determined according to actual needs. For example, by monitoring the number of nodes, services, and queries in the transaction link, when the above parameters exceed a certain threshold (which can be customized by the user), it can be determined that the third preset condition is met, so as to be able to screen out longer transaction links and / or transaction links with higher complexity.
[0142] For another example, for the services on the transaction link, the principle of decreasing service timeout should be followed, that is, the timeout time of the next-level service should be less than that of the previous-level service. Through the third preset condition, the transaction links that violate this principle can be screened out.
[0143] In the embodiment of the present disclosure, all transaction links can be monitored. When any transaction link meets the third preset condition, it can be added as a new high-risk service to the high-risk service monitoring list for monitoring, so as to improve the comprehensiveness of high-risk service identification.
[0144] In some specific embodiments, step S420 includes step S421.
[0145] In step S421, when the supplementary monitoring information of the transaction link in the high-risk business meets the third preset condition, the risk level weight of the high-risk business is increased, thereby correcting the risk level weight of the high-risk business. Otherwise, step S421 ends.
[0146] Figure 7 FIG. 4 schematically shows a fourth flowchart of the monitoring method for high-risk business according to an embodiment of the present disclosure, as Figure 7 shown. In some specific embodiments, the monitoring method further includes step S510 and step S530.
[0147] In step S510, when the version is updated, the changed content is obtained.
[0148] In step S520, it is determined whether there is a newly added large access table according to the changed content.
[0149] In the embodiment of the present disclosure, the large table may refer to a data table in which the access volume meets a preset value. When the version is updated, by comparing the old and new versions, the changed jobs are listed, and the data tables involved are marked according to the jobs. When the access times of a single transaction link with modification content to this table reach the preset times, for example, more than one million, it is determined that this table is a newly added large access table.
[0150] In step S530, when there is a newly added large access table, the high-risk business monitoring list is updated according to the business involving the newly added large access table.
[0151] In the embodiment of the present disclosure, the services, transaction links, etc. that call the newly added large access table can be obtained, and then the businesses that call these services and transaction links can be obtained and added as new high-risk businesses to the high-risk business monitoring list.
[0152] Optionally, when the transaction link in the existing high-risk business accesses the newly added large access table, the risk level weight of the high-risk business can be increased, thereby correcting the risk level weight of the high-risk business.
[0153] Next, the docking of the transaction link and the business assets in the embodiment of the present disclosure will be described.
[0154] In some specific embodiments, the monitoring method further includes step S610.
[0155] In step S610, the high-risk business is associated with its involved high-frequency transaction links and / or sensitive transaction links for search and visually displayed.
[0156] In the embodiments of the present disclosure, high-risk services can be managed at the granularity of transaction links for operations such as addition, deletion, modification, and query. Optionally, a maintenance application product line and a person in charge can be configured for each transaction link or high-risk service. Optionally, applications, business functions, service sources, service call relationships, version transformations can be registered and accumulated with the maintainable product line and test person in charge to form a front-end visualization interface for subsequent test asset precipitation, improving the registration quality of IT architectures and business scenarios, and enhancing asset quality.
[0157] For example, for account-related services, using the above forward / backward recognition algorithms, key data, modification time, version transformation content, applications, called services, and transaction links in the key data tables of account-related services can be retrieved, and then this information can be integrated and registered with account-related services, test person in charge, and business person in charge for front-end display and asset accumulation.
[0158] Through the above asset integration, the high-risk services retrieved by the system can be front-end displayed and asset accumulated to achieve the docking of transaction links and services. Relevant business testers or technical personnel can search for transaction links or high-risk services to retrieve relevant information such as corresponding applications, test / business person in charge, transaction time, version transformation time, and corresponding table names, and then predict the production transformation risk situation and clarify the test focus in advance.
[0159] In some specific embodiments, the monitoring method further includes step S710 and step S720.
[0160] In step S710, according to the similarity algorithm, the currently determined high-risk service is compared with the high-risk service monitoring list generated last time.
[0161] In step S720, according to the comparison result, a risk level weight is determined for the currently determined high-risk service.
[0162] In the embodiments of the present disclosure, through the following similarity algorithm, using the transaction link, the currently determined high-risk service is compared with a high-risk service in the high-risk service monitoring list generated last time.
[0163] For example, when the number of nodes in the transaction links of two services is the same, the service names in the transaction links are different (the number of unmatched service names supports customization), and the SQL information is the same, it is considered that the two transaction links are similar, and the currently determined high-risk service already exists in the high-risk service monitoring list generated last time.
[0164] For another example, when the number of nodes in the transaction links of two services is the same, the service names are the same, and the SQL in the services is different, it can also be considered that the two transaction links are similar, and the currently determined high-risk service already exists in the high-risk service monitoring list generated last time.
[0165] By adopting the monitoring method for high-risk services according to the embodiments of the present disclosure, not only can the automated identification of high-risk services be achieved, but also the intelligent analysis and prevention and control of the entire transaction link and the accurate docking of the transaction link with the service can be realized. Therefore, it is beneficial to improve the accuracy and efficiency of testing. On the one hand, the comprehensiveness of test coverage is improved, and the situation of missed testing is avoided. On the other hand, the performance problems of the entire transaction link (such as timeouts described above) can be monitored, the transaction error information and the illegal transaction link can be located, the test efficiency is improved, and the problems and deficiencies of the existing test methods are made up for.
[0166] Based on the above monitoring method for high-risk services, the present disclosure also provides a monitoring device for high-risk services. The following will be combined with Figure 8 to describe this device in detail.
[0167] Figure 8 The structural block diagram of the monitoring device for high-risk services according to the embodiments of the present disclosure is schematically shown.
[0168] As Figure 8 shown, the monitoring device 800 for high-risk services in this embodiment includes an acquisition module 810, a first extraction module 820, a second extraction module 830, a first processing module 840, and a second processing module 850.
[0169] The acquisition module 810 is used to acquire the first call frequency of at least one transaction link. In one embodiment, the acquisition module 810 can be used to execute step S210 described above, which will not be elaborated here.
[0170] The first extraction module 820 is used to extract the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links. In one embodiment, the first extraction module 820 can be used to execute step S220 described above, which will not be elaborated here.
[0171] The second extraction module 830 is used to extract the transaction links associated with the key data of the key data table to obtain sensitive transaction links. In one embodiment, the second extraction module 830 can be used to execute step S230 described above, which will not be elaborated here.
[0172] The first processing module 840 is used to determine the high-risk services and the risk level weights of the high-risk services at least according to the high-frequency transaction links and the sensitive transaction links. In one embodiment, the first processing module 840 can be used to execute step S240 described above, which will not be elaborated here.
[0173] The second processing module 850 is used to generate a monitoring list for high-risk services according to the high-risk services and the risk level weights of the high-risk services. In one embodiment, the second processing module 850 may be used to execute the step S250 described above, which will not be elaborated here.
[0174] By using the monitoring method for high-risk services according to the embodiments of the present disclosure, high-risk services can be determined based on high-frequency trading links and sensitive trading links, thereby realizing the automatic identification of high-risk services, and the identification effect is accurate and efficient. After determining the high-risk services, the trading links called by the high-risk services and the services called by the trading links can be monitored to a corresponding degree according to the risk level weights of the high-risk services. In this way, during testing, testers can focus on the test content related to high-risk services according to the monitoring objects, so that the test process can focus on the key points of the test work, and solve the problems of incomplete testing and inaccurate risk control in the traditional test scheme.
[0175] According to the embodiments of the present disclosure, any multiple modules among the acquisition module 810, the first extraction module 820, the second extraction module 830, the first processing module 840, and the second processing module 850 can be combined and implemented in one module, or any one of them can be split into multiple modules. Or, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to the embodiments of the present disclosure, at least one of the acquisition module 810, the first extraction module 820, the second extraction module 830, the first processing module 840, and the second processing module 850 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented by any other reasonable way of integrating or packaging circuits, etc., in hardware or firmware, or implemented in any one of the three implementation manners of software, hardware, and firmware, or in any appropriate combination of several of them. Or, at least one of the acquisition module 810, the first extraction module 820, the second extraction module 830, the first processing module 840, and the second processing module 850 can be at least partially implemented as a computer program module, and when the computer program module runs, it can execute the corresponding functions.
[0176] In some specific embodiments, the monitoring device further includes a third processing module, which is used to execute the following steps:
[0177] Obtain the second call frequency of at least one service;
[0178] Extract the services whose second call frequency meets the second preset condition to obtain high-frequency services;
[0179] Determine the high-risk services and the risk-level weights of the high-risk services based on at least the high-frequency trading link and the sensitive trading link, including:
[0180] Determine the high-risk services and the risk-level weights of the high-risk services according to the high-frequency services, the high-frequency trading link, and the sensitive trading link.
[0181] In some specific embodiments, the second extraction module 830 is specifically configured to perform the following steps:
[0182] Obtain a preset target service;
[0183] Extract the services called by the target service to obtain the first service;
[0184] Determine the critical data tables according to the data tables involved in the critical changes of the first service, where the critical data in the critical data tables includes the data involved in the critical changes of the target service;
[0185] Extract the SQL statements involving the critical data;
[0186] Determine the sensitive trading link according to the logic in the extracted SQL statements;
[0187] In some specific embodiments, the second extraction module 830 is further specifically configured to perform the following steps:
[0188] Obtain a preset target data table;
[0189] Determine the critical data tables according to the target data table, where the critical data in the critical data tables includes the preset data that has changed in the target data table;
[0190] Extract the services that call the critical data to obtain the second service;
[0191] Determine the sensitive trading link according to the extracted second service.
[0192] In some specific embodiments, the critical data includes at least one of account-related data and confidential data.
[0193] In some specific embodiments, the first processing module 840 is specifically configured to perform the following steps:
[0194] Extract the services that involve at least one of the high-frequency services, the high-frequency trading link, and the high-risk trading link to obtain the high-risk services;
[0195] When the high-risk service involves at least two of the high-frequency services, the high-frequency trading link, and the high-risk trading link, determine the risk-level weight of the high-risk service as the first risk-level weight;
[0196] When a high-risk service involves one of high-frequency services, high-frequency trading links, and high-risk trading links, determine that the risk level weight of the high-risk service is the second risk level weight;
[0197] The first risk level weight is higher than the second risk level weight.
[0198] In some specific embodiments, the monitoring device further includes a fourth processing module for performing the following steps:
[0199] Obtain supplementary monitoring information for all trading links;
[0200] When the supplementary monitoring information of at least one trading link meets the third preset condition, update the high-risk service monitoring list according to the service involved in the trading link.
[0201] In some specific embodiments, the fourth processing module is specifically used for performing the following steps:
[0202] When the supplementary monitoring information of the trading link in the high-risk service meets the second preset condition, increase the risk level weight of the high-risk service.
[0203] In some specific embodiments, the supplementary monitoring information includes the length information and complexity information of the trading link, and the timeout information of each level of service in the trading link.
[0204] In some specific embodiments, the monitoring device further includes a fifth processing module for performing the following steps:
[0205] The monitoring method further includes:
[0206] When the version is updated, obtain the changed content;
[0207] Determine whether there is a newly added access to a large table according to the changed content;
[0208] When there is a newly added access to a large table, update the high-risk service monitoring list according to the service involved in the newly added access to the large table.
[0209] In some specific embodiments, the monitoring device further includes a sixth processing module for performing the following steps:
[0210] Establish a search association between the high-risk service and the high-frequency trading link and / or sensitive trading link it involves, and perform visual display.
[0211] In some specific embodiments, the monitoring device further includes a seventh processing module for performing the following steps:
[0212] According to the similarity algorithm, compare the currently determined high-risk services with the high-risk service monitoring list generated last time;
[0213] Determine the risk level weight for the currently identified high-risk services according to the comparison result.
[0214] By using the monitoring method for high-risk services according to the embodiments of the present disclosure, not only can the automatic identification of high-risk services be achieved, but also the intelligent analysis and prevention and control of the entire transaction link, the accurate docking of the transaction link and the service, etc. can be realized. Therefore, it is beneficial to improve the accuracy and efficiency of testing. On the one hand, it improves the comprehensiveness of test coverage and avoids the situation of missed testing. On the other hand, it can monitor the performance problems of the entire transaction link (such as timeouts mentioned above), locate transaction error information and illegal transaction links, improve the test efficiency, and make up for the problems and deficiencies of the existing test methods.
[0215] Figure 9 A block diagram of an electronic device suitable for implementing the monitoring method for high-risk services according to the embodiments of the present disclosure is schematically shown.
[0216] As Figure 9 shown, the electronic device 900 according to the embodiments of the present disclosure includes a processor 901, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 902 or the program loaded from the storage section 908 into the random access memory (RAM) 903. The processor 901 may include, for example, a general microprocessor (such as a CPU), an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (such as an application specific integrated circuit (ASIC)), etc. The processor 901 may also include on-board memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to the embodiments of the present disclosure.
[0217] In the RAM 903, various programs and data required for the operation of the electronic device 900 are stored. The processor 901, the ROM 902, and the RAM 903 are connected to each other through a bus 904. The processor 901 performs various operations of the method flow according to the embodiments of the present disclosure by executing the programs in the ROM 902 and / or the RAM 903. It should be noted that the program may also be stored in one or more memories other than the ROM 902 and the RAM 903. The processor 901 may also perform various operations of the method flow according to the embodiments of the present disclosure by executing the programs stored in the one or more memories.
[0218] According to an embodiment of the present disclosure, the electronic device 900 may further include an input / output (I / O) interface 905, and the input / output (I / O) interface 905 is also connected to the bus 904. The electronic device 900 may further include one or more of the following components connected to the I / O interface 905: an input portion 906 including a keyboard, a mouse, etc.; an output portion 907 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage portion 908 including a hard disk, etc.; and a communication portion 909 including a network interface card such as a LAN card, a modem, etc. The communication portion 909 performs communication processing via a network such as the Internet. The drive 910 is also connected to the I / O interface 905 as needed. A removable medium 911, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 910 as needed, so that a computer program read therefrom can be installed into the storage portion 908 as needed.
[0219] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable storage medium carries one or more programs, and when the one or more programs are executed, the method according to the embodiments of the present disclosure is implemented.
[0220] According to an embodiment of the present disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, for example, it may include but is not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or combined with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, the computer-readable storage medium may include the above-described ROM 902 and / or RAM 903 and / or one or more memories other than ROM 902 and RAM 903.
[0221] An embodiment of the present disclosure further includes a computer program product, which includes a computer program, and the computer program includes program codes for executing the method shown in the flowchart. When the computer program product runs on a computer system, the program codes are used to cause the computer system to implement the monitoring method for high-risk services provided by the embodiments of the present disclosure.
[0222] When the computer program is executed by the processor 901, the above functions defined in the system / apparatus of the embodiments of the present disclosure are executed. According to the embodiments of the present disclosure, the above-described systems, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0223] In one embodiment, the computer program can rely on tangible storage media such as optical storage devices, magnetic storage devices, etc. In another embodiment, the computer program can also be transmitted and distributed in the form of signals on a network medium, and be downloaded and installed through the communication part 909, and / or be installed from the removable medium 911. The program code included in the computer program can be transmitted by any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0224] In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 909, and / or be installed from the removable medium 911. When the computer program is executed by the processor 901, the above functions defined in the system of the embodiments of the present disclosure are executed. According to the embodiments of the present disclosure, the above-described systems, devices, apparatuses, modules, units, etc. can be implemented by computer program modules.
[0225] According to the embodiments of the present disclosure, the program code for executing the computer program provided by the embodiments of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computing programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include but are not limited to, such as Java, C++, python, the "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).
[0226] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0227] Those skilled in the art will appreciate that the features recited in the various embodiments and / or claims of the present disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0228] The embodiments of the present disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although the embodiments have been described separately above, this does not mean that the measures in each embodiment cannot be used advantageously in combination. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art can make various substitutions and modifications, and all such substitutions and modifications should fall within the scope of the present disclosure.
Claims
1. A monitoring method for high-risk services, characterized in that, Including: Obtain the first call frequency of at least one transaction link; Extract the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links; Extract the transaction links associated with the key data of the key data table to obtain sensitive transaction links; Determine high-risk services and the risk level weights of the high-risk services based on at least the high-frequency transaction links and the sensitive transaction links; Generate a high-risk service monitoring list according to the high-risk services and the risk level weights of the high-risk services; The determining of high-risk services and the risk level weights of the high-risk services based on at least the high-frequency transaction links and the sensitive transaction links includes: Determine high-risk services and the risk level weights of the high-risk services based on high-frequency services, the high-frequency transaction links, and the sensitive transaction links; The determining of high-risk services and the risk level weights of the high-risk services based on high-frequency services, the high-frequency transaction links, and the sensitive transaction links includes: Extract the services involved in at least one of the high-frequency services, the high-frequency transaction links, and high-risk transaction links to obtain the high-risk services; When the high-risk service involves at least two of the high-frequency services, the high-frequency transaction links, and the high-risk transaction links, determine that the risk level weight of the high-risk service is the first risk level weight; When the high-risk service involves one of the high-frequency services, the high-frequency transaction links, and the high-risk transaction links, determine that the risk level weight of the high-risk service is the second risk level weight; The first risk level weight is higher than the second risk level weight.
2. The monitoring method according to claim 1, characterized in that, The monitoring method further includes; Obtain the second call frequency of at least one service; Extract the services whose second call frequency meets the second preset condition to obtain the high-frequency services.
3. The monitoring method according to claim 1, wherein The extracting of the transaction links associated with the key data of the key data table to obtain sensitive transaction links includes: Obtain a preset target service; Extract the services called by the target service to obtain the first service; Determine the key data table according to the data tables involved in the key changes of the first service; wherein, the key data in the key data table includes the data involved in the key changes of the target service; Extract the SQL statements involving the key data; Determine the sensitive transaction links according to the logic in the extracted SQL statements.
4. The monitoring method according to claim 1, wherein The extracting of the transaction links associated with the key data of the key data table to obtain sensitive transaction links includes: Obtain a preset target data table; Determine the key data table according to the target data table, wherein the key data in the key data table includes the preset data that has changed in the target data table; Extract the services that call the key data to obtain the second service; Determine the sensitive transaction links according to the extracted second service.
5. The monitoring method according to claim 1, characterized in that, The key data includes at least one of account-related data and confidential data.
6. The monitoring method according to claim 1, wherein The monitoring method further includes: Obtain the supplementary monitoring information of all transaction links; When the supplementary monitoring information of at least one transaction link meets the third preset condition, update the high-risk business monitoring list according to the business related to this transaction link.
7. The monitoring method according to claim 6, characterized in that The step of updating the high-risk business monitoring list according to the business related to the transaction link when the supplementary monitoring information of at least one transaction link meets the third preset condition includes: When the supplementary monitoring information of the transaction link in the high-risk business meets the third preset condition, increase the risk level weight of the high-risk business.
8. The monitoring method according to claim 6, characterized in that, The supplementary monitoring information includes the length information and complexity information of the transaction link, and the timeout information of each level of service in the transaction link.
9. The monitoring method according to claim 1, characterized in that The monitoring method further includes: When the version is updated, obtain the changed content; Determine whether there is a newly added large access table according to the changed content; When there is the newly added large access table, update the high-risk business monitoring list according to the business related to the newly added large access table.
10. The monitoring method according to claim 1, wherein, The monitoring method further includes: Establish a search association between the high-risk business and the high-frequency transaction link and / or sensitive transaction link it involves, and perform visual display.
11. The monitoring method according to claim 1, characterized in that The monitoring method further includes: According to the similarity algorithm, compare the currently determined high-risk business with the high-risk business monitoring list generated last time; According to the comparison result, determine the risk level weight for the currently determined high-risk business.
12. A monitoring device for high-risk operations, characterized in that, It includes: An acquisition module, configured to acquire the first call frequency of at least one transaction link; A first extraction module, configured to extract the transaction links whose first call frequency meets the first preset condition to obtain high-frequency transaction links; A second extraction module, configured to extract the transaction links associated with the key data of the key data table to obtain sensitive transaction links; A first processing module, configured to determine high-risk businesses and the risk level weights of the high-risk businesses at least according to the high-frequency transaction links and the sensitive transaction links; A second processing module, configured to generate a high-risk business monitoring list according to the high-risk businesses and the risk level weights of the high-risk businesses; The third processing module, configured to determine high-risk businesses and the risk level weights of the high-risk businesses at least according to the high-frequency transaction links and the sensitive transaction links, includes: determining high-risk businesses and the risk level weights of the high-risk businesses according to high-frequency services, the high-frequency transaction links and the sensitive transaction links; The first processing module is further configured to extract the businesses involving at least one of the high-frequency services, the high-frequency transaction links and high-risk transaction links to obtain the high-risk businesses; when the high-risk business involves at least two of the high-frequency services, the high-frequency transaction links and the high-risk transaction links, determine that the risk level weight of the high-risk business is the first risk level weight; when the high-risk business involves one of the high-frequency services, the high-frequency transaction links and the high-risk transaction links, determine that the risk level weight of the high-risk business is the second risk level weight; the first risk level weight is higher than the second risk level weight.
13. An electronic device, characterized in that, It includes: One or more processors; A storage device, configured to store one or more programs, Wherein, when the one or more programs are executed by the one or more processors, the one or more processors are caused to execute the monitoring method for high-risk services according to any one of claims 1 to 11.
14. A computer-readable storage medium, characterized in that, Stored thereon are executable instructions which, when executed by a processor, cause the processor to execute the monitoring method for high-risk services according to any one of claims 1 to 11.
15. A computer program product, characterized in that, It includes a computer program which, when executed by a processor, implements the monitoring method for high-risk services according to any one of claims 1 to 11.
Citation Information
Patent Citations
Risk data monitoring method and device
CN110458396A
Risk management and control data processing method and risk early warning rule preposed data monitoring method
CN112613789A