Audit processing method and device of ledger data and server

By automatically generating ledger data and performing automatic auditing, the problem of low auditing efficiency of ledger data has been solved, realizing an efficient and automated auditing process, and improving auditing efficiency and problem detection rate.

CN115859949BActive Publication Date: 2026-07-21CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2022-12-01
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In existing technologies, the auditing efficiency of ledger data is low, the management efficiency is low, the timeliness is insufficient, the accuracy is not enough, the traceability is poor, and the manual inspection method is also inefficient.

Method used

By receiving audit instructions, the system generates ledger data according to preset ledger generation rules, performs content and form audits using preset audit rules, generates audit result information, automatically generates ledger data, and performs automatic audits, thereby improving the level of audit automation.

Benefits of technology

It improved the efficiency of auditing ledger data, saved labor costs, increased the problem detection rate, and solved the problem of low audit efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115859949B_ABST
    Figure CN115859949B_ABST
Patent Text Reader

Abstract

The application provides an auditing processing method and device of ledger data and a server, relates to data processing technology, and the method comprises the following steps: receiving an auditing instruction, the auditing instruction comprising a plurality of to-be-audited data source identifiers. According to the auditing instruction, to-be-audited data in a data source corresponding to each to-be-audited data source identifier is acquired. According to preset ledger generation rule information, ledger data corresponding to to-be-audited data in a data source corresponding to each to-be-audited data source identifier is generated respectively. According to preset auditing rule information, the ledger data corresponding to each to-be-audited data is audited, auditing result information is obtained, and the auditing result information is displayed to complete the auditing process; the auditing rule information comprises content auditing rule information and / or form auditing rule information. The method of the application improves the automation level of generating ledger data and auditing ledger data, improves the auditing efficiency of ledger data, and solves the problem of low auditing efficiency of ledger data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to data processing technology, and more particularly to a method, apparatus and server for auditing and processing ledger data. Background Technology

[0002] Currently, in the process of enterprise operation, it is necessary to convert various data generated into ledger data for recording and storage.

[0003] In existing technologies, the data is usually recorded manually offline, with the ledger data stored in document form on the computer of the person recording it, and then manually checked for errors.

[0004] However, in the existing technology, since the ledger data is stored in document form on the computer of the recorder and is manually checked for errors, this manual entry method is inefficient, lacks timeliness, accuracy, and traceability, and the manual checking method is also inefficient. Summary of the Invention

[0005] This application provides a method, apparatus, and server for auditing ledger data, in order to solve the technical problem of low auditing efficiency of ledger data.

[0006] Firstly, this application provides a method for auditing and processing ledger data, including:

[0007] Receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited;

[0008] According to the audit instruction, obtain the audit data in the data source corresponding to each audit data source identifier;

[0009] Based on the preset ledger generation rules, ledger data corresponding to the data to be audited in each data source is generated; wherein, the ledger generation rules are used to indicate the ledger generation steps.

[0010] According to the preset audit rules, the ledger data corresponding to the data to be audited in each of the data sources is audited to obtain audit result information, and the audit result information is displayed to complete the audit process; wherein, the audit rules include content audit rules and / or form audit rules.

[0011] Further, the auditing process is performed on the ledger data corresponding to the data to be audited in each of the data sources according to the preset auditing rules, to obtain auditing result information, including:

[0012] Determine the audit time in the preset audit rule information;

[0013] If it is determined that the current time is equal to the audit time, then according to the content audit rule information in the preset audit rule information, the ledger data corresponding to the data to be audited in each of the data sources is subjected to content audit processing to obtain the first result information.

[0014] According to the formal audit rule information in the preset audit rule information, the ledger data corresponding to the data to be audited in each of the data sources is subjected to formal audit processing to obtain the second result information;

[0015] The first result information and the second result information are determined to be audit result information.

[0016] Further, the step of performing content auditing processing on the ledger data corresponding to the data to be audited in each of the data sources according to the preset auditing rule information, to obtain first result information, includes:

[0017] Determine the data source type of the ledger data corresponding to the auditable data in each of the aforementioned data sources;

[0018] Based on the preset mapping relationship between data source types and content audit rule information, the content audit rule information corresponding to the data source type is determined from the preset audit rule information.

[0019] Based on the content audit rules information corresponding to the data source type, the ledger data corresponding to the data to be audited in each data source is subjected to content audit processing to obtain the first result information.

[0020] Further, the step of generating ledger data corresponding to the auditable data in each data source according to preset ledger generation rules includes:

[0021] Generate a ledger template corresponding to the auditable data in each data source; wherein, the ledger template includes ledger template structure information and logical relationship information between each ledger template;

[0022] Based on the ledger template structure information and the logical relationship information between each ledger template, determine the ledger structure for each piece of data to be audited;

[0023] Based on the preset ledger generation rules, each piece of data to be audited is stored in the corresponding ledger structure to generate ledger data corresponding to each piece of data to be audited.

[0024] Furthermore, the method also includes:

[0025] Based on the audit results, a prompt message is generated; wherein, the prompt message is used to indicate errors in the ledger data;

[0026] Receive a revision instruction for revising the error information and obtain the revised ledger data.

[0027] Furthermore, the method also includes:

[0028] If it is determined that the revised ledger data has been obtained, then obtain the new data to be audited;

[0029] The abnormal behavior event data in the new audit data is determined according to the preset anomaly prediction model; wherein, the anomaly prediction model is trained based on the abnormal behavior event data and the normal behavior event data;

[0030] If it is determined that the abnormal behavior event data does not match the revised ledger data, an alarm will be issued for the abnormal behavior event data.

[0031] If the abnormal behavior event data is determined to match the revised ledger data, then the abnormal behavior event data is determined to be false alarm data, the cause of the false alarm is determined, and the abnormal prediction model is updated according to the cause of the false alarm.

[0032] Furthermore, the data to be audited includes any one or more of the following:

[0033] Execution data, log data, specification documents, and databases of the target application system and network infrastructure.

[0034] Secondly, this application provides an auditing and processing device for ledger data, comprising:

[0035] A receiving unit is used to receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited;

[0036] The first acquisition unit is used to acquire the data to be audited in the data source corresponding to each data source identifier to be audited according to the audit instruction.

[0037] The first generation unit is used to generate ledger data corresponding to the auditable data in each data source according to the preset ledger generation rule information; wherein, the ledger generation rule information is used to indicate the ledger generation steps.

[0038] An audit unit is used to audit the ledger data corresponding to the data to be audited in each of the data sources according to preset audit rules information, and to obtain audit result information; wherein, the audit rules information includes content audit rules information and / or form audit rules information.

[0039] The display unit is used to display the audit result information to complete the audit process.

[0040] Furthermore, the audit unit includes:

[0041] The first determining module is used to determine the audit time in the preset audit rule information;

[0042] The first audit module is used to perform content audit processing on the ledger data corresponding to the data to be audited in each of the data sources according to the content audit rule information in the preset audit rule information if the current time is determined to be equal to the audit time, so as to obtain the first result information.

[0043] The second audit module is used to perform formal audit processing on the ledger data corresponding to the data to be audited in each of the data sources according to the formal audit rule information in the preset audit rule information, and to obtain the second result information.

[0044] The second determining module is used to determine that the first result information and the second result information are audit result information.

[0045] Furthermore, the first audit module includes:

[0046] The first determining submodule is used to determine the data source type of the ledger data corresponding to the audit data in each of the data sources;

[0047] The second determining submodule is used to determine the content audit rule information corresponding to the data source type in the content audit rule information of the preset audit rule information based on the mapping relationship between the preset data source type and the content audit rule information.

[0048] The audit submodule is used to perform content audit processing on the ledger data corresponding to the data to be audited in each of the data sources according to the content audit rule information corresponding to the data source type, and obtain the first result information.

[0049] Further, the first generation unit includes:

[0050] The first generation module is used to generate a ledger template corresponding to the auditable data in each data source; wherein, the ledger template includes ledger template structure information and logical relationship information between each ledger template;

[0051] The third determining module is used to determine the ledger structure of each piece of data to be audited based on the ledger template structure information and the logical relationship information between each ledger template.

[0052] The second generation module is used to store each piece of data to be audited into the corresponding ledger structure according to the preset ledger generation rules, and generate ledger data corresponding to each piece of data to be audited.

[0053] Furthermore, the device also includes:

[0054] The second generation unit is used to generate prompt information based on the audit results; wherein the prompt information is used to indicate errors in the ledger data.

[0055] The revision unit is used to receive revision instructions for revising the error information and to obtain the revised ledger data.

[0056] Furthermore, the device also includes:

[0057] The second acquisition unit is used to acquire new audit data if it is determined that the revised ledger data has been acquired.

[0058] The first determining unit is used to determine new abnormal behavior event data in the data to be audited based on a preset anomaly prediction model; wherein the anomaly prediction model is trained based on abnormal behavior event data and normal behavior event data.

[0059] An alarm unit is used to issue an alarm prompt for the abnormal behavior event data if it is determined that the abnormal behavior event data does not match the revised ledger data.

[0060] The second determining unit is configured to determine that the abnormal behavior event data is false alarm data if it is determined that the abnormal behavior event data matches the revised ledger data, determine the cause of the false alarm of the abnormal behavior event data, and update the abnormal prediction model according to the cause of the false alarm.

[0061] Furthermore, the data to be audited includes any one or more of the following:

[0062] Execution data, log data, specification documents, and databases of the target application system and network infrastructure.

[0063] Thirdly, this application provides a server, including a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the computer program to implement the method described in the first aspect.

[0064] Fourthly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the first aspect.

[0065] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0066] This application provides a method, apparatus, and server for auditing ledger data. The method receives audit instructions, each including multiple data source identifiers to be audited. It retrieves the data to be audited from the data source corresponding to each identifier according to the audit instructions. Based on preset ledger generation rules, it generates ledger data corresponding to the data to be audited in each data source; the ledger generation rules indicate the ledger generation steps. Based on the preset audit rules, it performs audit processing on the ledger data corresponding to the data to be audited in each data source, obtaining and displaying the audit results to complete the audit processing; the audit rules include content audit rules and / or format audit rules. In this solution, multiple data source identifiers to be audited are determined according to the audit instructions. From the data sources corresponding to these identifiers, the data to be audited is retrieved from each data source according to the audit instructions. Based on the ledger generation steps indicated by the ledger generation rules, ledger data corresponding to the data to be audited in each data source is automatically generated. Then, based on the content audit rules in the preset audit rules information, the ledger data corresponding to the data to be audited in each data source is subjected to content audit processing, and / or, based on the formal audit rules in the preset audit rules information, the ledger data corresponding to the data to be audited in each data source is subjected to formal audit processing, obtaining audit result information, and displaying the audit result information, thus completing the audit processing. Therefore, after automatically generating ledger data according to the ledger generation rules information, performing content audit and compliance audit on the ledger data to obtain audit result information can determine whether the ledger data is accurate. Compared with manual auditing, this application does not rely on the experience of audit personnel, improves the automation level of generating and auditing ledger data, saves labor costs, increases the problem detection rate of ledger data, and thus improves the audit efficiency of ledger data, solving the technical problem of low audit efficiency of ledger data. Attached Figure Description

[0067] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0068] Figure 1 A flowchart illustrating a method for auditing ledger data provided in this application embodiment;

[0069] Figure 2 A flowchart illustrating another method for auditing ledger data provided in this application embodiment;

[0070] Figure 3 A flowchart illustrating another method for auditing ledger data provided in this application embodiment;

[0071] Figure 4 A flowchart illustrating another method for auditing ledger data provided in this application embodiment;

[0072] Figure 5 A flowchart illustrating another method for auditing ledger data provided in this application embodiment;

[0073] Figure 6 A flowchart illustrating another method for auditing ledger data provided in this application embodiment;

[0074] Figure 7 This is a schematic diagram of another method for auditing ledger data provided in the embodiments of this application;

[0075] Figure 8 A schematic diagram of the structure of a ledger data auditing and processing device provided in an embodiment of this application;

[0076] Figure 9 A schematic diagram of another ledger data auditing and processing device provided in this application embodiment;

[0077] Figure 10 This is a schematic diagram of the structure of a server provided in an embodiment of this application.

[0078] The accompanying drawings have illustrated specific embodiments of this disclosure, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concepts of this disclosure to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0079] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure.

[0080] In one example, during the operation of a business, various data generated need to be converted into ledger data for recording and storage. Currently, this is typically done manually offline, with the ledger data stored in document form on the computers of the recorders, and manually checked for errors. However, this manual data entry method is inefficient, lacks timeliness, accuracy, and traceability, and the manual checking process is also inefficient.

[0081] This application provides a method, apparatus, and server for auditing and processing ledger data, which aims to solve the above-mentioned technical problems in the prior art.

[0082] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0083] Figure 1 A flowchart illustrating a method for auditing ledger data provided in this application embodiment is shown below. Figure 1 As shown, the method includes:

[0084] Step 101: Receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited.

[0085] For example, the execution entity in this embodiment can be a server. First, the server receives an audit instruction, which includes multiple data source identifiers to be audited. The data sources corresponding to the data source identifiers to be audited include application systems that are pre-included in management, execution data of network infrastructure (such as data asset lists, classification and grading lists, etc.), log data, specification documents, and databases, etc.

[0086] Step 102: Obtain the data to be audited from the data source corresponding to each data source identifier to be audited according to the audit instruction.

[0087] For example, in each data source corresponding to the data source identifier to be audited, the server obtains the data to be audited in each data source according to the audit instruction. Figure 2 A flowchart illustrating another method for auditing ledger data provided in this application embodiment is shown below. Figure 2 As shown, the system includes: a ledger data center, an audit center, an anomaly correlation analysis center, a traffic monitoring system, a data asset management system, and an operational behavior audit system. The ledger data center handles key processes such as ledger template customization, ledger data processing, and automatic ledger data generation, automatically forming ledger data. The audit center audits the data to be audited and identifies erroneous data. The anomaly correlation analysis center predicts abnormal behavior events in application systems. The traffic monitoring system acquires standard process execution data from various application systems. The data asset management system collects auditable data from various application systems. The operational behavior audit system acquires abnormal log data, abnormal employee operation data, abnormal permission data, and other abnormal behavior event data. Auditable data includes execution data from application systems and network infrastructure (such as data asset lists, classification and grading lists), log data, specification documents, and databases.

[0088] Step 103: Generate ledger data corresponding to the auditable data in each data source according to the preset ledger generation rule information; wherein, the ledger generation rule information is used to indicate the ledger generation steps.

[0089] For example, the ledger generation rule information is used to indicate the steps for generating the ledger. The server can automatically generate ledger data corresponding to the data to be audited in each data source according to the ledger generation steps.

[0090] For example, Figure 3 A flowchart illustrating another method for auditing ledger data provided in this application embodiment is shown below. Figure 3 As shown, the server includes a ledger data center, which is responsible for automatically generating ledger data. The ledger data center mainly includes: a system configuration unit, a data acquisition unit, a data processing unit, a ledger template customization unit, a ledger generation rule customization unit, and a ledger data automatic generation unit. The generation process of the ledger data center is shown below:

[0091] (1) In the system configuration unit, the application systems, network infrastructure and data sources included in the management are registered, and information such as IP and port is recorded, and connectivity tests are conducted.

[0092] (2) Read system configuration information in the data acquisition unit, collect data from data sources such as application systems, network infrastructure and management specifications, and databases to obtain multiple sets of data to be audited.

[0093] (3) Customize the ledger template according to the requirements of data security laws, regulations, technical standards and specifications, and relevant management documents of the enterprise. Design the structure of the ledger template and the logical relationship table between each ledger in the form of a graphical interface in the blank template, or import the ledger structure designed in Excel or database into the blank template to complete the customization of the ledger template and logical relationship information, and save the generated structure data and logical data of the ledger template to the database.

[0094] (4) Based on the customized ledger template, complete the design of ledger generation rule information in the ledger generation rule customization unit to obtain ledger generation rule information.

[0095] (5) The collected data to be audited is sent to the data processing unit for data filtering, cleaning, standardization and other processes to unify the data formats of different systems and process the data according to the ledger generation rules to convert the data to be audited into a data format that can be recognized by the ledger data automatic generation unit.

[0096] (6) In the automatic ledger data generation unit, the system reads and parses the ledger structure data and logical data stored in the database to generate the ledger structure. Based on the ledger generation rules, it automatically extracts the data for each ledger item corresponding to the ledger template and fills the data into the corresponding ledger structure to obtain complete ledger data. When displaying the ledger data, it supports various display methods such as ledger data layering, display by managed application systems, and production systems (i.e., traffic monitoring systems, data asset management systems, and operational behavior auditing systems).

[0097] Step 104: Based on the preset audit rules, perform audit processing on the ledger data corresponding to the data to be audited in each data source, obtain audit result information, and display the audit result information to complete the audit processing; wherein, the audit rules information includes content audit rules information and / or form audit rules information.

[0098] For example, the audit rule information includes pre-stored content audit rule information and / or formal audit rule information. Based on the preset audit rule information, the server can perform content audit and formal audit on the generated ledger data. Content audit is used to determine the content of the ledger data, while formal audit is used to determine whether the ledger data is compliant. For content audit of the ledger data, the server collects traffic data from the traffic monitoring system, parses and processes the traffic data to obtain the standard process execution data of the application system. Based on the pre-set content audit rule information, the ledger data to be audited is compared with the standard process execution data to determine the accuracy of the ledger data content to be audited. For compliance auditing of ledger data, Optical Character Recognition (OCR) and Natural Language Processing (NLP) technologies are used to identify and decompose data security-related laws, regulations, technical standards, and enterprise management specifications. Based on the decomposed management specifications, compliance formal audit rules are set to determine whether the ledger data to be audited meets the formal audit rules. If it is determined that the ledger data to be audited does not meet the formal audit rules, a prompt message is issued to indicate the problematic ledger data after auditing. Finally, modification instructions are received to obtain the revised ledger data.

[0099] In this embodiment, an audit instruction is received, wherein the audit instruction includes multiple data source identifiers to be audited. The audit data to be audited is obtained from the data source corresponding to each audit data source identifier according to the audit instruction. Ledger data corresponding to the audit data in each data source is generated according to preset ledger generation rules; wherein the ledger generation rules indicate the ledger generation steps. Audit processing is performed on the ledger data corresponding to the audit data in each data source according to the preset audit rules, and the audit result information is obtained and displayed to complete the audit processing; wherein the audit rules include content audit rules and / or form audit rules. In this solution, multiple data source identifiers to be audited are determined according to the audit instruction. From the data sources corresponding to the multiple audit data source identifiers, the audit data in each data source is obtained according to the audit instruction. Ledger data corresponding to the audit data in each data source is automatically generated according to the ledger generation rules indicated by the ledger generation rules. Then, based on the content audit rules in the preset audit rules information, the ledger data corresponding to the data to be audited in each data source is subjected to content audit processing, and / or, based on the formal audit rules in the preset audit rules information, the ledger data corresponding to the data to be audited in each data source is subjected to formal audit processing, obtaining audit result information, and displaying the audit result information, thus completing the audit processing. Therefore, after automatically generating ledger data according to the ledger generation rules information, performing content audit and compliance audit on the ledger data to obtain audit result information can determine whether the ledger data is accurate. Compared with manual auditing, this application does not rely on the experience of audit personnel, improves the automation level of generating and auditing ledger data, saves labor costs, increases the problem detection rate of ledger data, and thus improves the audit efficiency of ledger data, solving the technical problem of low audit efficiency of ledger data.

[0100] Figure 4 A flowchart illustrating another method for auditing ledger data provided in this application embodiment is shown below. Figure 4 As shown, the method includes:

[0101] Step 201: Receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited.

[0102] For example, this step can be referred to Figure 1 Step 101 in the text will not be repeated here.

[0103] Step 202: Obtain the data to be audited from the data source corresponding to each data source identifier to be audited according to the audit instruction.

[0104] In one example, the data to be audited includes any one or more of the following: target application system, execution data of network infrastructure, log data, specification documents, and databases.

[0105] For example, this step can be referred to Figure 1 Step 102 in the text will not be repeated here.

[0106] Step 203: Generate a ledger template corresponding to the data to be audited in each data source; wherein, the ledger template includes ledger template structure information and logical relationship information between each ledger template.

[0107] For example, the ledger template is customized according to data security-related laws and regulations, technical standards and specifications, and relevant enterprise management documents. The structure of the ledger template and the logical relationship table between each ledger are designed in a graphical interface within a blank template, or the ledger structure designed in Excel or a database is imported into the blank template to complete the customization of the ledger template and logical relationship information. The generated structure data and logical relationship data of the ledger template are then saved to the database.

[0108] Step 204: Determine the ledger structure for each piece of data to be audited based on the ledger template structure information and the logical relationship information between each ledger template.

[0109] For example, the server designs the ledger generation rule information in the ledger generation rule customization unit based on the customized ledger template, thus obtaining the ledger generation rule information. The collected data to be audited is sent to the data processing unit for data filtering, cleaning, and standardization processes to unify the data formats of different application systems. The data is then processed according to the ledger generation rule information, transforming the data to be audited into a data format recognizable by the automatic ledger data generation unit. Then, in the automatic ledger data generation unit, the system reads and parses the ledger structure data and logical data stored in the database to generate the ledger structure.

[0110] Step 205: According to the preset ledger generation rules, store each piece of data to be audited into the corresponding ledger structure to generate ledger data corresponding to each piece of data to be audited.

[0111] For example, the server automatically extracts the auditable data corresponding to the ledger template according to the preset ledger generation rule information. The auditable data includes the ledger item data corresponding to each ledger template, and fills each ledger item data into the corresponding ledger structure to obtain complete ledger data corresponding to each auditable data.

[0112] Step 206: Determine the audit time in the preset audit rule information.

[0113] For example, the pre-set audit time in the preset audit rule information is determined, wherein the time interval of the audit time can be minutes, hours, months, days, or years, etc.

[0114] Step 207: If the current time is determined to be equal to the audit time, then according to the content audit rule information in the preset audit rule information, perform content audit processing on the ledger data corresponding to the data to be audited in each data source to obtain the first result information.

[0115] In one example, step 207 includes: determining the data source type of the ledger data corresponding to the data to be audited in each data source; determining the content audit rule information corresponding to the data source type in the content audit rule information of the preset audit rule information according to the mapping relationship between the preset data source type and the content audit rule information; and performing content audit processing on the ledger data corresponding to the data to be audited in each data source according to the content audit rule information corresponding to the data source type to obtain the first result information.

[0116] For example, the server obtains the current time in real time and compares it with the audit time. If the current time equals the audit time, the server determines the data source type of the ledger data corresponding to the data to be audited in each data source. Based on the preset mapping relationship between data source types and content audit rule information, the server determines the content audit rule information corresponding to the data source type from the preset content audit rule information. Finally, based on the content audit rule information corresponding to the data source type, the server performs content audit processing on the ledger data corresponding to the data to be audited in each data source to obtain the first result information.

[0117] For example, Figure 5 A flowchart illustrating another method for auditing ledger data provided in this application embodiment is shown below. Figure 5 As shown, the audit center includes: a traffic data processing unit, a content audit unit, content audit rules, and a ledger revision unit. The content audit module of the audit center is primarily responsible for auditing the accuracy of the internal logic of the ledger data generated by the ledger data center, automatically auditing the accuracy of the ledger data. The audit process of the audit center is as follows:

[0118] (1) Read the ledger data in the ledger data center, convert the ledger data into a preset format that the content audit unit can recognize, and send it to the content audit unit;

[0119] (2) Set content audit rules information based on the content of the ledger data to be audited. The ledger content can refer to the ledger type, which includes execution data of network infrastructure (such as data asset list, classification and grading list, etc.) or log data, etc. The content audit rules information includes traffic data summary rules, data audit execution time rules, etc. The traffic data summary rules include rules used to determine the content of the ledger data or rules to determine whether the ledger data is compliant. Send the content audit rules information to the content audit unit.

[0120] (3) In the traffic data processing unit, based on the ledger data to be audited, the server collects relevant traffic data from the traffic monitoring system, parses the traffic data, and restores the execution process to obtain standard process execution data. According to the pre-set content audit rules, the standard process execution data undergoes preprocessing processes such as data filtering, cleaning, and format conversion to convert the standard process execution data into a preset format that the content audit unit can recognize, and then sends the processed standard process execution data to the content audit unit.

[0121] (4) The content audit unit uses multi-threading to perform audit operations. Multi-threading is used to classify the data information of the standard process execution data to obtain the standard process execution data corresponding to each data source type. The classified standard process execution data is sent to different interfaces to perform audit operations, thereby improving the efficiency of audit operations.

[0122] (5) Generate first result information, send the erroneous ledger information in the ledger data to the ledger data revision unit to revise the ledger data, and send the revised ledger data to the ledger data center for ledger update.

[0123] Step 208: Based on the formal audit rules in the preset audit rules information, perform formal audit processing on the ledger data corresponding to the data to be audited in each data source to obtain the second result information.

[0124] For example, based on the formal audit rules information in the preset audit rules information, the server performs formal audit processing on the ledger data corresponding to the data to be audited in each data source, and obtains the second result information.

[0125] For example, Figure 6 A flowchart illustrating another method for auditing ledger data provided in this application embodiment is shown below. Figure 6 As shown, the compliance audit module of the audit center is mainly responsible for conducting compliance audits on the ledger data generated by the ledger data center to determine whether the ledger data meets management requirements. The specific audit process of the compliance audit module is as follows:

[0126] (1) Read the ledger data in the ledger data center, convert the ledger data into a preset format that the compliance audit unit can recognize, and send it to the compliance audit unit;

[0127] (2) Set up formal audit rules information according to management specifications and send them to the compliance audit unit.

[0128] (3) In the compliance audit unit, the formal audit rule information is parsed, the ledger data to be audited is audited, and it is determined whether the existing ledger data meets the formal audit rule information.

[0129] (4) Generate second result information, send the ledger data that does not meet the formal audit rules to the ledger data revision unit to revise the ledger data, and send the revised ledger data to the ledger data center for ledger update.

[0130] Step 209: Determine the first result information and the second result information as audit result information, and display the audit result information.

[0131] For example, the server determines the first result information and the second result information as audit result information and displays the audit result information.

[0132] Step 210: Generate prompt information based on the audit results; the prompt information is used to indicate errors in the ledger data.

[0133] For example, the server can generate a prompt message based on the audit results. The prompt message is used to indicate errors in the ledger data so as to remind the user to make corrections in a timely manner.

[0134] Step 211: Receive the revision instruction for revising the error information and obtain the revised ledger data.

[0135] For example, the server receives a revision instruction for revising error information, and in response to the revision instruction, obtains the revised ledger data. The revised ledger data is the correct and standard ledger data, which can be used for subsequent anomaly correlation analysis.

[0136] Step 212: If it is determined that the revised ledger data has been obtained, then obtain the new data to be audited.

[0137] For example, if the server determines that it has obtained the revised ledger data, it can continue to obtain new data to be audited. For instance, it can continuously obtain new data to be audited in real time from the managed application systems that are subject to audit.

[0138] Step 213: Determine the abnormal behavior event data in the new audit data according to the preset anomaly prediction model; wherein, the anomaly prediction model is trained based on the abnormal behavior event data and the normal behavior event data.

[0139] For example, since the anomaly prediction model is trained based on abnormal behavior event data and normal behavior event data, the anomaly prediction model can directly output abnormal behavior event data from the new audit data according to the prediction strategy in the anomaly prediction model.

[0140] Step 214: If it is determined that the abnormal behavior event data does not match the revised ledger data, then issue an alarm for the abnormal behavior event data.

[0141] For example, the server compares the abnormal behavior event data with the revised ledger data. If it is determined that the abnormal behavior event data does not match the revised ledger data, an alarm is issued for the abnormal behavior event data.

[0142] For example, Figure 7 This is a schematic diagram of another method for auditing ledger data provided in the embodiments of this application, such as... Figure 7 As shown, the Anomaly Correlation Analysis Center comprises a data acquisition unit, a correlation analysis unit, and a source tracing analysis unit. The center receives revised ledger data from the ledger data center and collects data from the data acquisition unit, including abnormal access behaviors of external interfaces from the traffic monitoring system, abnormal data lifecycle behaviors from the data asset management system, and abnormal access behaviors of the production and maintenance area from the operation behavior audit system. This unit performs data cleaning and standardization processes to unify the data format. Then, a correlation analysis model is built based on artificial intelligence technology. Using AI technologies (such as machine learning and deep learning), the correlation analysis unit performs correlation analysis between the processed abnormal behavior event data and the revised ledger data, automatically verifying the authenticity of the abnormal behavior event data. For genuine abnormal behavior event data, alerts are issued and source tracing analysis is performed. Based on the revised ledger data, the corresponding terminal or account is located, assisting data security management personnel in quickly handling abnormal behavior event data.

[0143] Step 215: If the abnormal behavior event data is determined to be consistent with the revised ledger data, then the abnormal behavior event data is determined to be false alarm data. The cause of the false alarm of the abnormal behavior event data is determined, and the abnormal prediction model is updated according to the cause of the false alarm.

[0144] For example, if it is determined that the abnormal behavior event data matches the revised ledger data, it is determined to be a false alarm. For the false alarm abnormal behavior event data, the cause of the false alarm is analyzed, and the anomaly prediction strategy of the production system (i.e., traffic monitoring system, data asset management system, and operation behavior audit system) for the false alarm abnormal behavior event data is optimized to continuously enrich and improve the integrity and maturity of data security construction.

[0145] In this embodiment, an audit instruction is received, wherein the audit instruction includes multiple data source identifiers to be audited. The audit data to be audited in the data source corresponding to each data source identifier is obtained according to the audit instruction. A ledger template corresponding to the audit data in each data source is generated; wherein the ledger template includes ledger template structure information and logical relationship information between each ledger template. The ledger structure for each data to be audited is determined based on the ledger template structure information and the logical relationship information between each ledger template. Each data to be audited is stored in the corresponding ledger structure according to preset ledger generation rules, generating ledger data corresponding to each data to be audited. The audit time in the preset audit rules is determined. If the current time is equal to the audit time, the content audit rules in the preset audit rules are used to perform content audit processing on the ledger data corresponding to the data to be audited in each data source, obtaining first result information. The formal audit rules in the preset audit rules are used to perform formal audit processing on the ledger data corresponding to the data to be audited in each data source, obtaining second result information. The system identifies the first and second result information as audit result information and displays them. Based on the audit result information, it generates a prompt message indicating errors in the ledger data. It receives a revision instruction to correct the errors and retrieves the revised ledger data. If the revised ledger data has been retrieved, new data to be audited is acquired. Anomaly prediction data is identified in the new data to be audited based on a pre-set anomaly prediction model trained on both abnormal and normal behavior event data. If the abnormal behavior event data does not match the revised ledger data, an alarm is issued. If the abnormal behavior event data matches the revised ledger data, it is determined to be a false alarm; the cause of the false alarm is identified, and the anomaly prediction model is updated based on the cause. Therefore, after automatically generating ledger data based on the ledger generation rules, content and compliance audits are performed on the ledger data to obtain audit results. This allows for the determination of the accuracy of the ledger data. Compared to manual audits, this application eliminates the need to rely on the experience of audit personnel, improving the automation level of ledger data generation and auditing, saving labor costs, increasing the problem detection rate of ledger data, and thus improving the audit efficiency of ledger data, solving the technical problem of low audit efficiency. Furthermore, it can identify abnormal behavior event data and perform correlation analysis between abnormal behavior event data and revised ledger data to quickly determine the authenticity of abnormal behavior event data, improving the timeliness of audits, rapidly intercepting abnormal data, effectively improving the data security index, and reducing losses caused by abnormal data.

[0146] Figure 8This is a schematic diagram of the structure of a ledger data auditing and processing device provided in an embodiment of this application, as shown below. Figure 8 As shown, the device includes:

[0147] The receiving unit 31 is used to receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited.

[0148] The first acquisition unit 32 is used to acquire the data to be audited in the data source corresponding to each data source identifier to be audited according to the audit instruction.

[0149] The first generation unit 33 is used to generate ledger data corresponding to the auditable data in each data source according to the preset ledger generation rule information; wherein, the ledger generation rule information is used to indicate the ledger generation steps.

[0150] Audit unit 34 is used to audit the ledger data corresponding to the data to be audited in each data source according to the preset audit rule information, and obtain audit result information; wherein, the audit rule information includes content audit rule information and / or form audit rule information.

[0151] Display unit 35 is used to display audit result information to complete the audit process.

[0152] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.

[0153] Figure 9 This is a schematic diagram of the structure of another ledger data auditing and processing device provided in an embodiment of this application. Figure 8 Based on the illustrated embodiments, as Figure 9 As shown, audit unit 34 includes:

[0154] The first determining module 341 is used to determine the audit time in the preset audit rule information.

[0155] The first audit module 342 is used to perform content audit processing on the ledger data corresponding to the data to be audited in each data source according to the content audit rule information in the preset audit rule information if the current time is determined to be equal to the audit time, so as to obtain the first result information.

[0156] The second audit module 343 is used to perform formal audit processing on the ledger data corresponding to the data to be audited in each data source according to the formal audit rule information in the preset audit rule information, and obtain the second result information.

[0157] The second determining module 344 is used to determine that the first result information and the second result information are audit result information.

[0158] In one example, the first audit module 342 includes:

[0159] The first determining submodule 3421 is used to determine the data source type of the ledger data corresponding to the audit data in each data source.

[0160] The second determining submodule 3422 is used to determine the content audit rule information corresponding to the data source type from the content audit rule information of the preset audit rule information, based on the preset mapping relationship between the data source type and the content audit rule information.

[0161] The audit submodule 3423 is used to perform content audit processing on the ledger data corresponding to the data to be audited in each data source according to the content audit rule information corresponding to the data source type, and obtain the first result information.

[0162] In one example, the first generating unit 33 includes:

[0163] The first generation module 331 is used to generate a ledger template corresponding to the audit data in each data source; wherein, the ledger template includes ledger template structure information and logical relationship information between each ledger template.

[0164] The third determining module 332 is used to determine the ledger structure of each piece of data to be audited based on the ledger template structure information and the logical relationship information between each ledger template.

[0165] The second generation module 333 is used to store each piece of data to be audited into the corresponding ledger structure according to the preset ledger generation rules information, and generate ledger data corresponding to each piece of data to be audited.

[0166] In one example, the device also includes:

[0167] The second generation unit 41 is used to generate prompt information based on the audit results; wherein the prompt information is used to indicate the error information in the ledger data.

[0168] The revision unit 42 is used to receive revision instructions for revising error information and to obtain the revised ledger data.

[0169] In one example, the device also includes:

[0170] The second acquisition unit 43 is used to acquire new audit data if it is determined that the revised ledger data has been acquired.

[0171] The first determining unit 44 is used to determine abnormal behavior event data in the new audit data according to a preset anomaly prediction model; wherein, the anomaly prediction model is trained based on abnormal behavior event data and normal behavior event data.

[0172] Alarm unit 45 is used to issue an alarm prompt for abnormal behavior event data if it is determined that the abnormal behavior event data does not match the revised ledger data.

[0173] The second determining unit 46 is used to determine that the abnormal behavior event data is false alarm data if the abnormal behavior event data matches the revised ledger data, determine the cause of the false alarm of the abnormal behavior event data, and update the abnormal prediction model according to the cause of the false alarm.

[0174] In one example, the data to be audited includes any one or more of the following:

[0175] Execution data, log data, specification documents, and databases of the target application system and network infrastructure.

[0176] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.

[0177] Figure 10 This application provides a schematic diagram of the structure of a server, as shown in the embodiment of the present application. Figure 10 As shown, the server includes: memory 51 and processor 52.

[0178] The memory 51 stores a computer program that can run on the processor 52.

[0179] The processor 52 is configured to perform the methods provided in the embodiments described above.

[0180] The server also includes a receiver 53 and a transmitter 54. The receiver 53 is used to receive instructions and data sent by external devices, and the transmitter 54 is used to send instructions and data to external devices.

[0181] This application also provides a non-transitory computer-readable storage medium, which, when the instructions in the storage medium are executed by the server's processor, enables the server to perform the methods provided in the above embodiments.

[0182] This application also provides a computer program product, which includes: a computer program stored in a readable storage medium, at least one processor of the server can read the computer program from the readable storage medium, and the at least one processor executes the computer program to cause the server to perform the solution provided in any of the above embodiments.

[0183] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0184] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A method for auditing and processing ledger data, characterized in that, include: Receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited; According to the audit instruction, obtain the audit data in the data source corresponding to each audit data source identifier; Based on the preset ledger generation rules, ledger data corresponding to the data to be audited in each data source is generated; wherein, the ledger generation rules are used to indicate the ledger generation steps. According to the preset audit rules, the ledger data corresponding to the data to be audited in each of the data sources is audited to obtain audit result information, and the audit result information is displayed to complete the audit process; wherein, the audit rules include content audit rules and / or form audit rules. The method further includes: Based on the audit results, a prompt message is generated; wherein, the prompt message is used to indicate errors in the ledger data; Receive a revision instruction for revising the error information, and obtain the revised ledger data; If it is determined that the revised ledger data has been obtained, then obtain the new data to be audited; The abnormal behavior event data in the new audit data is determined according to the preset anomaly prediction model; wherein, the anomaly prediction model is trained based on the abnormal behavior event data and the normal behavior event data; If it is determined that the abnormal behavior event data does not match the revised ledger data, an alarm will be issued for the abnormal behavior event data. If the abnormal behavior event data is determined to match the revised ledger data, then the abnormal behavior event data is determined to be false alarm data, the cause of the false alarm is determined, and the abnormal prediction model is updated according to the cause of the false alarm.

2. The method according to claim 1, characterized in that, The audit process involves performing auditing on the ledger data corresponding to the data to be audited in each of the data sources, based on preset auditing rules, to obtain auditing result information, including: Determine the audit time in the preset audit rule information; If it is determined that the current time is equal to the audit time, then according to the content audit rule information in the preset audit rule information, the ledger data corresponding to the data to be audited in each of the data sources is subjected to content audit processing to obtain the first result information. According to the formal audit rule information in the preset audit rule information, the ledger data corresponding to the data to be audited in each of the data sources is subjected to formal audit processing to obtain the second result information; The first result information and the second result information are determined to be audit result information.

3. The method according to claim 2, characterized in that, The first step involves performing content auditing processing on the ledger data corresponding to the data to be audited in each of the data sources, based on the content auditing rules information in the preset auditing rules information, to obtain first result information, including: Determine the data source type of the ledger data corresponding to the auditable data in each of the aforementioned data sources; Based on the preset mapping relationship between data source types and content audit rule information, the content audit rule information corresponding to the data source type is determined from the preset audit rule information. Based on the content audit rules information corresponding to the data source type, the ledger data corresponding to the data to be audited in each data source is subjected to content audit processing to obtain the first result information.

4. The method according to claim 1, characterized in that, The step of generating ledger data corresponding to the auditable data in each data source according to preset ledger generation rules includes: Generate a ledger template corresponding to the auditable data in each data source; wherein, the ledger template includes ledger template structure information and logical relationship information between each ledger template; Based on the ledger template structure information and the logical relationship information between each ledger template, determine the ledger structure for each piece of data to be audited; Based on the preset ledger generation rules, each piece of data to be audited is stored in the corresponding ledger structure to generate ledger data corresponding to each piece of data to be audited.

5. The method according to any one of claims 1-4, characterized in that, The data to be audited includes any one or more of the following: Execution data, log data, specification documents, and databases of the target application system and network infrastructure.

6. A device for auditing and processing ledger data, characterized in that, include: A receiving unit is used to receive audit instructions, wherein the audit instructions include multiple data source identifiers to be audited; The first acquisition unit is used to acquire the data to be audited in the data source corresponding to each data source identifier to be audited according to the audit instruction. The first generation unit is used to generate ledger data corresponding to the auditable data in each data source according to the preset ledger generation rule information; wherein, the ledger generation rule information is used to indicate the ledger generation steps. An audit unit is used to audit the ledger data corresponding to the data to be audited in each of the data sources according to preset audit rules information, and to obtain audit result information; wherein, the audit rules information includes content audit rules information and / or form audit rules information. The display unit is used to display the audit result information to complete the audit process; The second generation unit is used to generate prompt information based on the audit results; wherein the prompt information is used to indicate errors in the ledger data. The revision unit is used to receive a revision instruction for revising the error information and to obtain the revised ledger data; The second acquisition unit is used to acquire new audit data if it is determined that the revised ledger data has been acquired. The first determining unit is used to determine new abnormal behavior event data in the data to be audited based on a preset anomaly prediction model; wherein the anomaly prediction model is trained based on abnormal behavior event data and normal behavior event data. An alarm unit is used to issue an alarm prompt for the abnormal behavior event data if it is determined that the abnormal behavior event data does not match the revised ledger data. The second determining unit is configured to determine that the abnormal behavior event data is false alarm data if it is determined that the abnormal behavior event data matches the revised ledger data, determine the cause of the false alarm of the abnormal behavior event data, and update the abnormal prediction model according to the cause of the false alarm.

7. The apparatus according to claim 6, characterized in that, The audit unit includes: The first determining module is used to determine the audit time in the preset audit rule information; The first audit module is used to perform content audit processing on the ledger data corresponding to the data to be audited in each of the data sources according to the content audit rule information in the preset audit rule information if the current time is determined to be equal to the audit time, so as to obtain the first result information. The second audit module is used to perform formal audit processing on the ledger data corresponding to the data to be audited in each of the data sources according to the formal audit rule information in the preset audit rule information, and to obtain the second result information. The second determining module is used to determine that the first result information and the second result information are audit result information.

8. The apparatus according to claim 7, characterized in that, The first audit module includes: The first determining submodule is used to determine the data source type of the ledger data corresponding to the audit data in each of the data sources; The second determining submodule is used to determine the content audit rule information corresponding to the data source type in the content audit rule information of the preset audit rule information based on the mapping relationship between the preset data source type and the content audit rule information. The audit submodule is used to perform content audit processing on the ledger data corresponding to the data to be audited in each of the data sources according to the content audit rule information corresponding to the data source type, and obtain the first result information.

9. The apparatus according to claim 6, characterized in that, The first generation unit includes: The first generation module is used to generate a ledger template corresponding to the auditable data in each data source; wherein, the ledger template includes ledger template structure information and logical relationship information between each ledger template; The third determining module is used to determine the ledger structure of each piece of data to be audited based on the ledger template structure information and the logical relationship information between each ledger template. The second generation module is used to store each piece of data to be audited into the corresponding ledger structure according to the preset ledger generation rules, and generate ledger data corresponding to each piece of data to be audited.

10. The apparatus according to any one of claims 6-9, characterized in that, The data to be audited includes any one or more of the following: Execution data, log data, specification documents, and databases of the target application system and network infrastructure.

11. A server, characterized in that, The method includes a memory and a processor, wherein the memory stores a computer program that can run on the processor, and the processor executes the computer program to implement the method of any one of claims 1-5.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-5.

13. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, is used to implement the method of any one of claims 1-5.