A risk control rule updating method and device, electronic equipment and readable storage medium
By receiving risk control decision data to calculate support, screening abnormal user behavior elements and automatically updating risk control rules, the problem of poor timeliness of manual updates is solved, efficient and automated risk control rule updates are achieved, and the needs of high-frequency confrontation with black industries are met.
Patent Information
- Application Number
- CN202211576276.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-08
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-12-08
AI Technical Summary
In existing technologies, manual updates of risk control rules are time-sensitive and cannot meet the needs of high-frequency combat against illegal activities.
By receiving risk control decision data, calculating the support of user behavior elements, filtering out abnormal user behavior element information with support higher than the threshold, automatically updating risk control rules, generating new risk control rules and automatically taking effect.
It realizes efficient and automatic updating of risk control rules, improves update efficiency, meets the needs of high-frequency confrontation with black industries, and achieves the effect of dynamic attack and defense.
Smart Images

Figure CN115883231B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information processing, in particular to a risk control rule updating method, a risk control rule updating device, an electronic device and a computer readable storage medium. BACKGROUND
[0002] The existence of the network black industry brings risks to the Internet security. In order to cope with the risks brought by the black industry, many enterprises will build a risk control system, use the risk control system to analyze and decide the risk of the business request, and further build a risk radar to detect the abnormal data of the business request decision data of the risk control system decision, and alarm after detecting the abnormal data.
[0003] In order to improve the accuracy of the risk control system decision, it is necessary to continuously improve the rules in the risk control system. In the prior art, for these alarms, the risk control operation personnel analyzes the business request decision data in the alarm information to obtain abnormal user behavior information, and uses the abnormal user behavior information to newly build rules in the risk control system. However, it takes a long time to improve the rules in the risk control system by manual work, and the overall timeliness is poor, which is difficult to meet the needs of high-frequency confrontation with black production. SUMMARY
[0004] The embodiments of the present application provide a risk control rule updating method, device, electronic device and readable storage medium to solve the problem of poor timeliness of manual updating of risk control rules.
[0005] In the first aspect of the present application, a risk control rule updating method is first provided, applied to a risk control rule management center, comprising:
[0006] Receiving risk control decision data; the risk control decision data is obtained by the risk radar for abnormal detection of the first business request decision data of the risk control system; the first business request decision data is obtained by the risk control system for evaluating the risk level of the business request;
[0007] Determine the proportion of the occurrence times of each user behavior element in the total occurrence times of all user behavior elements in the risk control decision data to obtain the support degree of each user behavior element;
[0008] From the risk control decision data, filter the user behavior elements with a support degree higher than a preset support degree threshold to obtain abnormal user behavior element information of the risk control decision data;
[0009] Update the risk control rules by using the abnormal user behavior element information of the risk control decision data, so that the risk control system detects the risk of the business request by using the risk control rules.
[0010] Optionally, user behavior elements with a support degree higher than a preset support degree threshold are filtered from the risk control decision data, to obtain abnormal user behavior element information of the risk control decision data, including:
[0011] User behavior elements with a support degree higher than the support degree threshold are filtered from the risk control decision data, to obtain a high-frequency user behavior element set;
[0012] Each high-frequency user behavior element in the high-frequency user behavior element set is taken as a node in the frequent pattern tree, to obtain a frequent pattern tree; the frequent pattern tree includes a root node; the root node is a node that does not contain a high-frequency user behavior element;
[0013] All prefix paths of the frequent pattern tree are obtained; the prefix path includes all high-frequency user behavior elements between each high-frequency user behavior element node and the root node;
[0014] Prefix paths with a high-frequency user behavior element item number equal to a preset item number and a high-frequency user behavior element support degree higher than the support degree threshold are filtered, to obtain a target prefix path;
[0015] High-frequency user behavior elements in the target prefix path are taken as abnormal user behavior element information.
[0016] Optionally, the step of updating a risk control rule by using the abnormal user behavior element information of the risk control decision data includes:
[0017] A new risk control rule is generated by using the abnormal user behavior element information of the risk control decision data and a preset rule structure; the rule structure is a preset conditional statement; the conditional statement includes a condition part and an operation part, the operation part is a risk score adjustment amount for different abnormal user behavior element information, and the condition part is a judgment statement lacking the abnormal user behavior element information;
[0018] A risk control scene corresponding to the new risk control rule is determined;
[0019] A to-be-updated risk control rule set corresponding to the risk control scene is determined;
[0020] The new risk control rule is updated to the to-be-updated risk control rule set, to obtain a new risk control rule set.
[0021] Optionally, the method further includes:
[0022] At least one second service request decision data is received; the second service request decision data is obtained from a risk control data warehouse according to the abnormal user behavior element information;
[0023] extract user identity information from the second business request decision data according to a preset extraction rule, to obtain abnormal user identity information;
[0024] update the risk control rule by using the abnormal user identity information.
[0025] Optionally, the abnormal user behavior element information includes abnormal materials, abnormal environment, and abnormal account.
[0026] Optionally, the risk control decision data is obtained by the risk radar from the risk control data warehouse according to a preset task, the risk radar extracts first business request decision data corresponding to the preset task, and the risk radar screens business request decision data deviating from a normal data amount from the first business request decision data.
[0027] In a second aspect of the embodiment of the present application, a risk control decision data generation method is further provided, applied to a risk assessment system, the risk assessment system including a risk control system, a risk control data warehouse, a risk radar, and a risk control rule management center, and including:
[0028] The risk control system uploads business request decision data to the risk control data warehouse, the business request decision data being obtained by the risk control system by using a risk control rule to judge a risk level of a business request, and the business request decision data including first business request decision data.
[0029] The risk radar acquires the first business request decision data corresponding to a preset task from the risk control data warehouse according to the preset task.
[0030] The risk radar detects whether the first business request decision data is abnormal.
[0031] If the first business request decision data is abnormal, the risk radar takes the first business request decision data as risk control decision data, and sends the risk control decision data to the risk control rule management center.
[0032] The risk control rule management center is configured to generate a new risk control rule based on the risk control decision data, and update the new risk control rule to the risk control system.
[0033] In still another aspect of the embodiment of the present application, a risk control rule updating device is further provided, applied to a risk control rule management center, and including:
[0034] A first receiving module is configured to receive risk control decision data, the risk control decision data being obtained by the risk radar by performing abnormality detection on first business request decision data of the risk control system, and the first business request decision data being obtained by the risk control system by evaluating a risk level of a business request.
[0035] The support degree determination module is configured to determine a proportion of a number of occurrences of each user behavior element in the risk control decision data in a total number of occurrences of all user behavior elements, to obtain a support degree of the each user behavior element;
[0036] The abnormal user behavior element information determination module is configured to filter, from the risk control decision data, user behavior elements with a support degree higher than a preset support degree threshold, to obtain abnormal user behavior element information of the risk control decision data;
[0037] The first updating module is configured to update a risk control rule by using the abnormal user behavior element information of the risk control decision data, so that the risk control system detects a risk of a business request by using the risk control rule.
[0038] Optionally, the abnormal user behavior element information determination module comprises:
[0039] The high-frequency user behavior element set determination submodule is configured to filter, from the risk control decision data, user behavior elements with a support degree higher than the support degree threshold, to obtain a high-frequency user behavior element set.
[0040] The frequent pattern tree construction submodule is configured to take each high-frequency user behavior element in the high-frequency user behavior element set as a node in the frequent pattern tree, to obtain a frequent pattern tree; the frequent pattern tree comprises a root node; the root node is a node that does not contain a high-frequency user behavior element.
[0041] The acquisition submodule is configured to acquire all prefix paths of the frequent pattern tree; the prefix path comprises all high-frequency user behavior elements between each high-frequency user behavior element node and the root node.
[0042] The filtering submodule is configured to filter a prefix path with a same number of high-frequency user behavior element items as a preset number of items and with a support degree of a high-frequency user behavior element higher than the support degree threshold, to obtain a target prefix path.
[0043] The abnormal user behavior element information determination submodule is configured to take high-frequency user behavior elements in the target prefix path as abnormal user behavior element information.
[0044] Optionally, the first updating module comprises:
[0045] The generation submodule is configured to generate a new risk control rule by using the abnormal user behavior element information of the risk control decision data and a preset rule structure; the rule structure is a preset conditional statement; the conditional statement comprises a condition part and an operation part; the operation part is an adjustment of a risk score amount for different abnormal user behavior element information; and the condition part is a judgment statement that lacks the abnormal user behavior element information.
[0046] The risk control scene determination sub-module is configured to determine a risk control scene corresponding to the new risk control rule.
[0047] The to-be-updated risk control rule set determination sub-module is configured to determine a to-be-updated risk control rule set corresponding to the risk control scene.
[0048] The new risk control rule set determination sub-module is configured to update the new risk control rule to the to-be-updated risk control rule set to obtain a new risk control rule set.
[0049] Optionally, the device further comprises:
[0050] The second receiving module is configured to receive at least one piece of second service request decision data, which is obtained from the risk control data warehouse according to the abnormal user behavior element information.
[0051] The extraction module is configured to extract user identity information from the second service request decision data according to a preset extraction rule to obtain abnormal user identity information.
[0052] The second updating module is configured to update the risk control rule by using the abnormal user identity information.
[0053] Optionally, the abnormal user behavior element information includes abnormal materials, abnormal environment, and abnormal account.
[0054] Optionally, the risk control decision data is obtained by the risk radar from the risk control data warehouse according to a preset task, filtering service request decision data deviating from a normal data amount from first service request decision data corresponding to the preset task.
[0055] In another aspect of the embodiment of the present application, a risk control decision data generation device is also provided, which is applied to a risk assessment system, the risk assessment system comprising a risk control system, a risk control data warehouse, a risk radar, and a risk control rule management center, and comprising:
[0056] The uploading module is configured to upload, by the risk control system, service request decision data to the risk control data warehouse, wherein the service request decision data is obtained by the risk control system by using a risk control rule to judge a risk level of a service request, and the service request decision data comprises first service request decision data.
[0057] The first service request decision data acquisition module is configured to acquire, by the risk radar, the first service request decision data corresponding to a preset task from the risk control data warehouse according to the preset task.
[0058] The abnormality detection module is configured to detect, by the risk radar, whether the first service request decision data is abnormal.
[0059] The risk control decision data determination module is configured to, if the first business request decision data is abnormal, take the first business request decision data as risk control decision data, and send the risk control decision data to the risk control rule management center.
[0060] The risk control rule management center is configured to generate new risk control rules based on the risk control decision data, and update the new risk control rules to the risk control system.
[0061] In another aspect of the present application, an electronic device is provided, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus.
[0062] The memory is configured to store a computer program.
[0063] The processor is configured to execute the program stored in the memory, so as to implement the risk control rule updating method and the risk control decision data generation method as described in the embodiments of the present application.
[0064] In another aspect of the present application, a computer readable storage medium is provided, which stores a computer program, wherein the program is executed by a processor to implement the risk control rule updating method and the risk control decision data generation method as described in the embodiments of the present application.
[0065] The risk control rule updating method provided by the embodiments of the present application can obtain the support degree of each user behavior element by receiving risk control decision data and determining the proportion of the occurrence times of each user behavior element in the total occurrence times of all user behavior elements, can filter the user behavior elements with a support degree higher than a preset support degree threshold from the risk control decision data to obtain abnormal user behavior element information of the risk control decision data, and then can update the risk control rules by using the abnormal user behavior element information of the risk control decision data, so as to automatically update the risk control rules, improve the updating efficiency of the risk control rules, and automatically mine and extract the abnormal user behavior element information based on the risk control decision data, automatically generate new risk control rules by using the abnormal user behavior element information, and automatically update the new risk control rules to take effect online, so that the overall process can be completed within minutes, the updated risk control rules have high real-time performance, the demand for high-frequency confrontation with black production can be met, and the effect of dynamic attack and defense is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0066] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed in the embodiments or the prior art description will be briefly introduced below.
[0067] Figure 1 A system structure block diagram of a service request decision and risk control rule update provided in the present application;
[0068] Figure 2 A step flow chart of a risk control rule update method provided in the embodiment of the present application;
[0069] Figure 3 A step flow chart of another risk control rule update method provided in the embodiment of the present application;
[0070] Figure 4 A step flow chart of a risk control decision data generation method provided in the present application;
[0071] Figure 5 A structure block diagram of a risk control rule update device provided in the embodiment of the present application;
[0072] Figure 6 A structure block diagram of a risk control decision data generation device provided in the embodiment of the present application;
[0073] Figure 7 A schematic diagram of a computer readable storage medium provided in the embodiment of the present application. DETAILED DESCRIPTION
[0074] The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings in the embodiments of the present application.
[0075] The criminal methods of black production will present common performance in the data layer, so the common analysis of the data can be used to determine the abnormal user behavior elements, and then the abnormal user behavior elements are used to update the risk control rules.
[0076] Therefore, in order to solve the problem that the timeliness of manual updating of the risk control rule is poor, and the real-time performance of the risk control rule is insufficient to resist the high frequency of black production, in the embodiment of the application, after receiving the risk control decision data, the number of occurrences of the risk control decision data can be counted, the proportion of the number of occurrences of each user behavior element in the risk control decision data in the total number of occurrences of all user behavior elements can be calculated, the support degree of each user behavior element can be obtained, and further, the user behavior element with a support degree higher than a preset support degree threshold can be filtered from the risk control decision data to obtain the abnormal user behavior element information of the risk control decision data. After the abnormal user behavior element information is determined, the abnormal user behavior element information can be used to update the risk control rule, so that the risk control rule can be automatically updated, the updating efficiency of the risk control rule can be improved, and the abnormal user behavior element information can be mined and extracted based on the risk control decision data in an automatic manner, the new risk control rule can be automatically generated based on the abnormal user behavior element information, and the new risk control rule can be automatically updated to take effect online, so that the overall process can be completed within minutes, the updated risk control rule has high real-time performance, the demand for resisting the high frequency of black production can be met, and the effect of dynamic attack and defense is achieved.
[0077] Reference Figure 1 A system structure block diagram of business request decision and risk control rule updating in the application is shown.
[0078] In the application, the risk control system 101, the risk control data warehouse 102, the risk radar 103 and the risk control rule management center 104 can be provided.
[0079] When a user initiates a business request, in order to evaluate the risk of the business request, the business system can call the risk control system to evaluate the risk of the business request.
[0080] The risk control system 101 can determine the corresponding risk control scene of the business request by using the scene routing module after receiving the business request of the business system, can call the risk control rule set corresponding to the risk control scene by using the rule engine module, and run the risk control rule in the risk control rule set to obtain the risk score of the business request. Then, the decision module can determine the corresponding risk level according to the risk score. The risk control system can return the risk evaluation result to the business system after determining the risk level, and upload the business request decision data to the risk control data warehouse for storage.
[0081] The risk control data warehouse 102 can receive and store the business request decision data uploaded by the risk control system.
[0082] Based on the current risk control rules of the risk control system, the risk assessment made by the risk control system on the business request may be correct or may have assessment errors, so further abnormality detection can be performed on the business request decision data to filter out abnormal business request decision data, and the abnormal decision data is used to update the risk control rules of the risk control system, thereby optimizing the risk assessment capability of the risk control system.
[0083] The risk radar 103 can be used for abnormality detection on the business request decision data. Specifically, the risk radar can extract first business request decision data from the risk control data warehouse according to a task set by the risk control operator, and perform abnormality detection on the first business request decision data to obtain risk control decision data. After obtaining the risk control decision data, the risk control decision data can be sent to the risk control rule management center.
[0084] The risk control rule management center 104, after receiving the risk control decision data sent by the risk radar, can perform commonality analysis on the risk control decision data, find abnormal user behavior element information of the risk control decision data, and extract abnormal user identity information from the risk control decision data, so as to update the risk control rules by using the abnormal user behavior element information and the abnormal user identity information, and realize optimization of the risk control system.
[0085] Referring to Figure 2 , a step flowchart of a risk control rule updating method provided in an embodiment of the present application is shown, which can specifically include the following steps:
[0086] Step 201, receiving risk control decision data;
[0087] In the embodiment of the present application, in order to update the risk control rules, a risk control rule management center can be set, as shown in Figure 1 The risk control rule management center can communicate with the risk control system and the risk radar, so that the risk control rule management center can obtain the risk control decision data from the risk radar and update the risk control rules in the risk control system in real time.
[0088] Specifically, as shown in Figure 1 , when the risk radar performs an abnormality detection task, the risk radar can extract first business request decision data corresponding to the task from the risk control data warehouse, perform abnormality detection on the first business request decision data, and if abnormal business request decision data is detected, the abnormal business request decision data can be taken as risk control decision data and sent to the risk control rule center, so that the risk control rule management center can receive at least one piece of risk control decision data. Since the risk radar can usually detect multiple pieces of abnormal business request decision data, the risk control decision data received by the risk control rule management center can usually be multiple pieces, and then the risk control rule management center can perform commonality analysis on the multiple pieces of risk control decision data to update the risk control rules by using the abnormal user behavior elements determined by the commonality analysis.
[0089] The business request decision data in the risk control data warehouse can be a log of risk assessment of the business request by the risk control system, that is, the first business request decision data can be a risk assessment log of the business request, which can include, for example, a business request, a business request decision process record, a business request risk assessment result, and the like.
[0090] In step 202, the proportion of the occurrence times of each user behavior element in the total occurrence times of all user behavior elements in the risk control decision data is determined to obtain the support degree of each user behavior element.
[0091] The risk control decision data is abnormal business request decision data, and therefore the risk control decision data can include a business request, a business request decision process record, and a business request risk assessment result. The business request can carry user behavior elements such as a user account, a mobile phone number, a nickname, an age, a gender, a user IP address, an access terminal type, an automated tool, and an application.
[0092] Since the obtained multiple pieces of risk control decision data are abnormal business request decision data screened out through abnormality detection, the abnormal business request decision data can have the same or similar abnormal points, that is, the abnormal user behavior information of the abnormal business request decision data can be the same or similar, that is, the common performance of the user's abnormal behavior in the data layer can be that the user behavior elements have a high occurrence frequency. Therefore, the frequently occurring user behavior elements can be screened from the user behavior elements of the multiple pieces of risk control decision data to obtain abnormal user behavior element information.
[0093] Specifically, the support degree can be used to represent the frequency of occurrence of each user behavior element. The support degree is the proportion of the occurrence times of each user behavior element in the total occurrence times of all user behavior elements. The risk control rule management center can first calculate the support degree of each user behavior element, and then determine whether the user behavior element is an abnormal user behavior element through the support degree of each user behavior element.
[0094] Specifically, the risk control decision data can carry parameters representing user behavior elements, so that the risk control rule management center can parse the risk control decision data to obtain the parameters representing user behavior elements after receiving the risk control decision data, refer to a preset user behavior element parameter table, match the parameters representing user behavior elements with the preset user behavior element parameters, determine which user behavior elements the parameters representing user behavior elements carried by the risk control decision data correspond to, and find all user behavior elements included in the risk control decision data. Then, the risk control rule management center can calculate the number of occurrences of each user behavior element, count the total number of occurrences of all user behavior elements, calculate the proportion of the number of occurrences of each user behavior element in the total number of occurrences of all user behavior elements, and obtain the support degree of each user behavior element.
[0095] Step 203: filtering user behavior elements with a support degree higher than a preset support threshold from the risk control decision data to obtain abnormal user behavior element information of the risk control decision data;
[0096] Generally, the determination of abnormal user behavior elements is directly to take the user behavior element with the highest support degree in all user behavior elements as the abnormal user behavior element information. However, in the present application, the abnormal user behavior element information can be a single user behavior element or a combination of at least two user behavior elements. Therefore, in the present application, a support threshold corresponding to a relatively high frequency of occurrence can be set, and the user behavior elements with a support degree higher than the support threshold are filtered out from all user behavior elements. Then, these filtered user behavior elements are taken as a new user behavior element set, and the support degree of the user behavior elements is calculated based on the new user behavior element set. Then, another new user behavior element set is filtered out by using the support threshold. After at least two rounds of screening, when the user behavior element set obtained in the last round of screening is completely the same as the user behavior element set obtained in the penultimate round of screening, and the support degree of each user behavior element in the user behavior element set is higher than the support threshold, the screening is stopped, and the user behavior elements in the user behavior element set obtained in the last round of screening are taken as the user behavior element information.
[0097] As a specific example, in the case of a single user behavior element, the abnormal user behavior element information can be a user account, a user mobile phone number, a user network IP address, etc. In the case of a combination of at least two user behavior elements, the abnormal user behavior element information can be an overseas mobile phone number + an Android APP, an overseas mobile phone number + a domestic address, a network IP address + an automated tool, an overseas mobile phone number + an Android APP + an automated tool, etc.
[0098] In a specific application, different business scenarios, the number of occurrences required for identifying different user behavior elements as abnormal is different, so different support threshold values can be set for different business scenarios, for example, for login scenario business requests, if all user accounts are logged in 1000 times within 1 minute, and there are more than 10 user accounts logged in more than 10 times, it can be considered that the user account logged in more than 10 times is an abnormal user behavior element, and the support threshold value can be set to 10 / 1000=0.01; for search scenario business requests, if all user accounts are searched 100000 times within 1 minute, and there are more than 10000 user accounts searched more than 10000 times, it can be considered that the user account searched more than 10000 times is an abnormal user behavior element, and the support threshold value can be set to 10000 / 100000=0.1; Therefore, in a specific application, the risk control operation personnel can preset the support threshold value of each business scenario according to the actual demand.
[0099] After counting the number of occurrences of each user behavior element, the user behavior elements can be screened, first, the user behavior elements corresponding to the business scenarios can be determined according to the keywords such as login, search, payment, and amount, after determining the business scenarios, the support threshold value of the business scenario to which the user behavior element belongs can be determined. After determining the support threshold value, the user behavior elements with a support higher than the support threshold value in the risk control decision data can be screened out to obtain the abnormal user behavior element information of the risk control decision data, and then the abnormal user behavior elements can be used to update the risk control rules.
[0100] Step 204, updating the risk control rules by using the abnormal user behavior element information of the risk control decision data, so that the risk control system detects the risk of the business request by using the risk control rules.
[0101] After determining the abnormal user behavior element information of the risk control decision data, the risk control rule management center can directly update the risk control rules by using the abnormal user behavior element information, so that it is not necessary to manually create new risk control rules, and the automatic updating of the risk control rules greatly reduces the time required for updating the risk control rules, and improves the updating efficiency of the risk control rules.
[0102] The risk control rule updating method provided by the embodiment of the application can obtain the support degree of each user behavior element by receiving the risk control decision data and determining the proportion of the occurrence times of each user behavior element in the total occurrence times of all user behavior elements in the risk control decision data, can filter the user behavior elements with a support degree higher than a preset support degree threshold from the risk control decision data to obtain the abnormal user behavior element information of the risk control decision data, and then can update the risk control rule by using the abnormal user behavior element information of the risk control decision data, so that the risk control rule can be automatically updated, the updating efficiency of the risk control rule is improved, the abnormal user behavior element information is automatically mined and extracted based on the risk control decision data, the new risk control rule is automatically generated by using the abnormal user behavior element information, and the new risk control rule is automatically updated to take effect online, so that the overall process can be completed within minutes, the updated risk control rule has high real-time performance, the demand for high-frequency confrontation with black production can be met, and the effect of dynamic attack and defense is achieved.
[0103] Referring to Figure 3 , a step flowchart of another risk control rule updating method provided in the embodiment of the application is shown, which can specifically include the following steps:
[0104] Step 301, receiving risk control decision data;
[0105] In an embodiment of the application, the risk control decision data is obtained by the risk radar querying and extracting the first business request decision data corresponding to a preset task from the risk control data warehouse according to the preset task, and filtering the business request decision data deviating from the normal data amount in the first business request decision data corresponding to the preset task.
[0106] In order to optimize the risk control system, the abnormal business request decision data can be used to improve the risk control rule of the risk control system, so the business request decision data obtained by the risk control system can be first detected for abnormalities to filter the abnormal business request decision data.
[0107] In the embodiment of the application, the risk control decision data can be obtained by the risk radar detecting the first business request decision data of the risk control system for abnormalities, wherein at least one task can be preset in the risk radar, and the risk radar can execute the preset task according to a preset period.
[0108] Specifically, as Figure 1 shown, when the risk radar executes the preset task, the risk radar can query the first business request decision data corresponding to the preset task from the risk control data warehouse and extract the first business request decision data, so as to further detect the first business request decision data for abnormalities.
[0109] Generally, the data volume of the user's business request data can have a relatively stable fluctuation range, so the data volume of the first business request decision data should also be maintained within a stable fluctuation range. When the data volume of the first business request decision data exceeds or is lower than the stable fluctuation range, it can be considered that the first business request decision data is abnormal, so after the first business request decision data is extracted, the risk radar can filter out the business request decision data deviating from the normal data volume in the first business request decision data to obtain the risk control decision data.
[0110] Specifically, the risk radar can filter out the business request decision data deviating from the normal data volume from the first business request decision data using a preset abnormality detection rule or a preset abnormality detection algorithm, take the business request decision data deviating from the normal data volume as the risk control decision data, and send the risk control decision data to the risk control rule management center, so that the risk control rule management center can perform commonality analysis on the risk control decision data to update the risk control rules, thereby improving the ability of the risk control system to assess the risk of business requests.
[0111] As an example, the preset abnormality detection rule can be that: for a certain business, the average number of business requests per minute is x, if the number of business requests in a certain period of time suddenly increases or decreases, it can be considered that the business requests in the period of time are risky, and thus it can be determined whether the data volume of the first business request decision data corresponding to the business requests in the period of time is 100 times x or 1 / 100 of x.
[0112] As an example, the preset abnormality detection algorithm can be a statistical-based abnormality detection algorithm, a density-based abnormality detection algorithm, a time series abnormality detection algorithm, etc.
[0113] In actual application, after the risk radar performs abnormality detection on the first business request decision data to obtain the risk control decision data, the risk radar can generate an alarm information carrying the risk control decision data, and send the alarm information to the risk control rule management center. The risk control operators can analyze the alarm information in the risk control rule management center to determine whether the risk control decision data belongs to false alarm or valid alarm. If the alarm belongs to false alarm, the alarm will be marked as a non-risk case, and if the alarm belongs to valid alarm, the alarm will be marked as a risk case, and a risk case file will be created and the risk control decision data determined as valid alarm will be written into the risk case file.
[0114] Step 302, determining the proportion of the occurrence times of each user behavior element in the risk control decision data in the total occurrence times of all user behavior elements to obtain the support degree of each user behavior element;
[0115] Step 303: screening, from the risk control decision data, a user behavior element with a support degree higher than a preset support degree threshold, to obtain abnormal user behavior element information of the risk control decision data;
[0116] In an embodiment of the present application, screening, from the risk control decision data, a user behavior element with a support degree higher than a preset support degree threshold, to obtain abnormal user behavior element information of the risk control decision data, comprises:
[0117] S11: screening, from the risk control decision data, a user behavior element with a support degree higher than the support degree threshold, to obtain a high-frequency user behavior element set;
[0118] S12: taking each high-frequency user behavior element in the high-frequency user behavior element set as a node in the frequent pattern tree, to obtain a frequent pattern tree; the frequent pattern tree comprises a root node; the root node is a node without containing a high-frequency user behavior element;
[0119] S13: obtaining all prefix paths of the frequent pattern tree; the prefix path comprises all high-frequency user behavior elements between each high-frequency user behavior element node and the root node;
[0120] S14: screening a prefix path with a high-frequency user behavior element item number same as a preset item number and a support degree of a high-frequency user behavior element higher than the support degree threshold, to obtain a target prefix path;
[0121] S15: taking a high-frequency user behavior element in the target prefix path as abnormal user behavior element information.
[0122] In order to obtain abnormal user behavior element information, after calculating the support degree of each user behavior element, a first round of screening can be performed to screen out a user behavior element with a support degree higher than a support degree threshold in the risk control decision data, to obtain a high-frequency user behavior element set, and then a high-frequency user behavior element in the high-frequency user behavior element set can be used to construct a frequent pattern tree.
[0123] For the construction of the frequent pattern tree, specifically:
[0124] (1) a root node of the frequent pattern tree is first created, and the root node of the frequent pattern tree is a node without containing a high-frequency user behavior element.
[0125] (2) after the root node is created, the high-frequency user behavior elements in the high-frequency user behavior element set can be sequentially linked to the root node in descending order of occurrence number, to obtain the frequent pattern tree.
[0126] Then, taking each high-frequency user behavior element node on the frequent pattern tree as a starting point and the root node as a terminal point, all prefix paths on the frequent pattern tree are obtained, the prefix paths including all high-frequency user behavior elements between the high-frequency user behavior element node and the root node. Moreover, the high-frequency user behavior elements in each prefix path that are lower than the support threshold are removed, and the high-frequency user behavior elements remaining in each prefix path after the removal are taken as a new user behavior element set, to obtain at least one first user behavior element set.
[0127] Further, the conditional pattern tree of each new user behavior element set is constructed by using the same method as that of constructing the frequent pattern tree, and the prefix paths of each conditional pattern tree are obtained, and the user behavior elements in the prefix paths of each conditional pattern tree are screened again according to the support threshold, to obtain at least one second user behavior element set.
[0128] Finally, if the number of high-frequency user behavior elements in the second user behavior element set is the same as the preset number of items, and the support of each high-frequency user behavior element is higher than the support threshold, the high-frequency user behavior elements in the second behavior element set can be taken as the abnormal user behavior element information. If the number of high-frequency user behavior elements in the second user behavior element set is different from the preset number of items, and / or the support of each high-frequency user behavior element is lower than or equal to the support threshold, the conditional pattern tree construction and the screening of the high-frequency user behavior elements in the prefix paths of the conditional pattern tree are continuously performed for at least one round, until the user behavior element set obtained by the Nth round of screening meets the condition that the number of high-frequency user behavior elements is the same as the preset number of items, and the support of each high-frequency user behavior element is higher than the support threshold, the screening is stopped, and the high-frequency user behavior elements in the user behavior element set obtained by the Nth round of screening are taken as the user behavior element information.
[0129] In an embodiment of the present application, the abnormal user behavior element information includes abnormal materials, abnormal environments, and abnormal accounts.
[0130] The abnormal materials can be articles or materials used by black production for criminal activities, and can include automated tools, cheating APPs, virtual mobile numbers, temporary email addresses, etc.; the abnormal environments can include that the network IP where the user terminal is located does not belong to the preset network IP, and / or the location where the user terminal is located does not belong to the preset location; and the abnormal accounts can be accounts that have been determined to be abnormal accounts in other risk control scenarios.
[0131] In step 304, a new risk control rule is generated by using the abnormal user behavior element information of the risk control decision data and a preset rule structure.
[0132] After determining the abnormal user behavior element information of the risk control decision data, the abnormal user behavior element information can be added to the preset rule structure to obtain a new risk control rule, which can be used to update the risk control rule in the risk control system.
[0133] Specifically, the rule structure can be a pre-set conditional statement, which can include a condition part and an operation part. The condition part can be a judgment statement lacking the abnormal user behavior element information, and the operation part can be an adjustment of the risk score amount for different abnormal user behavior element information. Thus, the risk control rule management center can add the abnormal user behavior element information to the condition part to form a new conditional statement, i.e., a new risk control rule.
[0134] The preset rule structure can be set by risk control operators according to actual conditions, such as "if A is included, the risk score amount is increased by 10 points", "if the login frequency of B within a preset time meets a preset frequency, the risk score amount is increased by 10 points", "if the user's mobile phone number C is an overseas number and the user's IP address D is a domestic address, the risk score amount is increased by 20 points", "if an automated tool M is used, the risk score amount is increased by 20 points", and the like.
[0135] Step 305, determining a risk control scene corresponding to the new risk control rule;
[0136] After obtaining the new risk control rule, the new risk control rule can be used to find the risk control scene corresponding to the new risk control rule from the preset risk control scenes, so as to update the new risk control rule to the correct risk control scene, so that the subsequent risk control system can select the corresponding risk control rule according to the risk control scene.
[0137] The risk control scene can include a login scene, a search scene, a payment scene, and the like.
[0138] Specifically, the risk control rule management center can pre-store preset keywords corresponding to each business scene, so as to match the login, search, payment, and amount keywords in the risk control rule with the preset keywords. If the keywords in the risk control rule match the preset keywords, it can be determined that the risk control rule belongs to the business scene corresponding to the preset keywords.
[0139] As an example, when the new risk control rule is "if the login frequency of B within a preset time meets a preset frequency, the risk score amount is increased by 10 points", the corresponding risk control scene is the login scene; when the new risk control rule is "if the search frequency of D within a preset time exceeds a preset frequency, the risk score amount is increased by 10 points", the corresponding risk control scene is the search scene; when the new risk control rule is "if the payment amount R is lower than a preset amount, the risk score amount is increased by 10 points", the corresponding risk control scene is the payment scene.
[0140] Step 306, determining a to-be-updated risk control rule set corresponding to the risk control scene;
[0141] After determining the risk control scene corresponding to the new risk control rule, the to-be-updated risk control rule set corresponding to the risk control scene can be found from the rule set in the risk control system, so that the new risk control rule is added to the correct risk control rule set.
[0142] Step 307, updating the new risk control rule to the to-be-updated risk control rule set to obtain a new risk control rule set.
[0143] After determining the to-be-updated risk control rule set, the new risk control rule can be written into the to-be-updated risk control rule set, so that the risk control rule can be automatically updated without manual new risk control rule, and the updating efficiency of the risk control rule is improved.
[0144] In an embodiment of the present application, the method further comprises:
[0145] S21, receiving at least one second business request decision data;
[0146] The risk control decision data received by the risk control rule management center is part of the business request decision data filtered out by the risk radar from the risk control data warehouse based on the preset task, and this part of the business request decision data includes abnormal user behavior information. Other business request decision data not filtered out from the risk control data warehouse may also include the same abnormal user behavior element information, so after determining the abnormal user behavior element information, the risk control rule management center can use SQL query, HIVE query and other query methods to query all business request decision data including the abnormal user behavior element information in the risk control data warehouse, to obtain second business request decision data. The second business request decision data includes business request decision data filtered out by the risk radar for the preset task and other business request decision data not filtered out by the risk radar, so that all business request decision data including abnormal user behavior element information can be found out, so as to optimize the risk assessment capability of the risk control system according to these abnormal business request decision data.
[0147] S22, extracting user identity information from the second business request decision data according to a preset extraction rule to obtain abnormal user identity information;
[0148] The risk control system can assess the risk level of the business request by judging whether the user is an abnormal user, so after all abnormal business request decision data is found out, the user identity information in these abnormal business request decision data can be extracted for assessing the risk level of the business request.
[0149] Specifically, the second business request decision data carries parameters corresponding to user identity information, and after receiving the second business request decision data, the risk control rule management center can identify the parameters carried by the second business request decision data, determine the corresponding user identity information according to the parameters, extract the user identity information, and obtain abnormal user identity information.
[0150] S23, updating the risk control rule by using the abnormal user identity information.
[0151] After obtaining the abnormal user identity information, the abnormal user identity information can be added to a preset rule structure to obtain new risk control rules, and the new risk control rules can be updated to the to-be-updated risk control rule set to obtain a new risk control rule set, thereby realizing updating of the risk control rule.
[0152] Specifically, the rule structure can be a pre-set conditional statement, the operation part of the conditional statement can be an adjustment of a risk score amount for the abnormal user identity information, and the condition part can be a judgment statement lacking the abnormal user identity information, so that the risk control rule management center can add the abnormal user identity information to the condition part to form a new conditional statement, that is, a new risk control rule.
[0153] The risk control rule updating method provided by the embodiment of the application can query all business request decision data having abnormal user behavior element information in the risk control data warehouse according to the abnormal user behavior element information, extract user identity information in the abnormal business request decision data, and then update the risk control rule by using the abnormal user identity information, so that the risk control system can evaluate the risk level of the business request by judging whether the user belongs to an abnormal user, thereby realizing automatic updating of the risk control rule by using complete abnormal user identity information and improving the accuracy of risk evaluation of the risk control system.
[0154] Reference Figure 4 Fig. 2 shows a step flowchart of the risk control decision data generation method provided in the embodiment of the application, which can specifically include the following steps:
[0155] Step 401, the risk control system uploads the business request decision data to the risk control data warehouse;
[0156] In the embodiment of the application, a risk evaluation system can be provided, which can include a risk control system, a risk control data warehouse, a risk radar, and a risk control rule management center. In order to evaluate the risk of a business request, the business system can call the risk control system when receiving the business request, which can be used to evaluate the risk level of the business request. Specifically, after the business system calls the risk control system, the business request can be sent to the risk control system, so that the risk control system can evaluate the risk level of the business request.
[0157] The business request can carry parameters representing the risk control scene, so that the risk control system can search for the risk control scene corresponding to the business request by using the parameters representing the risk control scene carried by the business request after receiving the business request. After determining the risk control scene corresponding to the business request, the risk control system can retrieve a risk control rule set corresponding to the risk control scene according to the risk control scene. The risk control rule set can include at least one risk control rule, so that the risk control system can use the risk control rules in the risk control rule set to evaluate the risk level of the business request.
[0158] After retrieving the risk control rule set, the risk control system can run the risk control rules in the risk control rule set to obtain a risk score of the business request, and then determine the risk level of the business request according to a preset corresponding relationship between the risk score and the risk level, so as to obtain the risk level of the business request.
[0159] After completing the risk level evaluation, the risk control system can upload the business request decision data to the risk control data warehouse for storage. The business request decision data can include the business request, the rule snapshot, the risk level of the business request, and the like. The rule snapshot can be the running and output conditions of each rule in the process of the risk control system making a decision on the business request. After receiving and storing the business request decision data uploaded by the risk control system, the risk control data warehouse can store all the business request decision data evaluated by the risk control system.
[0160] Step 402, the risk radar obtains the first business request decision data corresponding to the preset task from the risk control data warehouse according to the preset task;
[0161] Based on the current risk control rules of the risk control system, the risk evaluation made by the risk control system on the business request can be correct or can have evaluation errors, so further abnormality detection can be performed on the business request decision data to filter out abnormal business request decision data, and the abnormal decision data is used to update the risk control rules of the risk control system, so as to optimize the risk evaluation capability of the risk control system.
[0162] In the embodiments of the present application, the risk radar can be used to detect the abnormality of the business request decision data. Specifically, the risk radar can store preset tasks, and the preset tasks can be used to collect and detect whether the business request decision data in a certain time period is abnormal. Therefore, the risk radar can obtain the first business request decision data corresponding to the preset task from the risk control data warehouse according to the preset task.
[0163] Step 403, the risk radar detects whether the first business request decision data is abnormal;
[0164] After obtaining the first business request decision data from the risk control data warehouse, the risk radar can detect whether the first business request decision data is abnormal. The amount of user business request data can have a relatively stable fluctuation range, so the amount of first business request decision data should also be kept within a stable fluctuation range. When the amount of first business request decision data exceeds or is lower than the stable fluctuation range, it can be considered that the first business request decision data is abnormal. Therefore, the risk radar can determine whether the first business request decision data is abnormal by judging whether the amount of first business request decision data deviates from the normal data amount.
[0165] In step 404, if the first business request decision data is abnormal, the risk radar sends the first business request decision data as risk control decision data to the risk control rule management center, and the risk control rule management center generates new risk control rules based on the risk control decision data and updates the new risk control rules to the risk control system.
[0166] The risk radar determines whether the amount of first business request decision data deviates from the normal data amount, determines the business request decision data deviating from the normal data amount as abnormal business request decision data, filters out these abnormal business request decision data as risk control decision data, and sends them to the risk control rule management center. Therefore, the risk control rule management center can perform commonality analysis on these risk control decision data to generate new risk control rules, and update the new risk control rules to the risk control system, thereby improving the ability of the risk control system to evaluate the risk of business requests.
[0167] The risk control decision data generation method provided by the embodiment of the application uploads the business request decision data obtained by the risk control system in evaluating the risk level of business requests to the risk control data warehouse, and predefines an abnormality detection task in the risk radar. The risk radar can obtain first business request decision data corresponding to the predefined task from the risk control data warehouse according to the predefined task, and then perform abnormality detection on the first business request decision data to obtain risk control decision data and send it to the risk control rule management center. Therefore, it can filter out abnormal business request decision data, and the risk control rule management center can update the rules of the risk control system based on the abnormal business request decision data, thereby improving the ability of the risk control system to evaluate the risk of business requests.
[0168] It should be noted that, for the method embodiment, in order to simply describe, it is expressed as a series of action combinations, but those skilled in the art should know that the embodiment of the application is not limited by the order of the described actions, because according to the embodiment of the application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily necessary for the embodiment of the application.
[0169] Referring to Figure 5 , a structural block diagram of a risk control rule updating device provided in an embodiment of the present application is shown, and specifically can include the following modules:
[0170] The first receiving module 501 is configured to receive risk control decision data; the risk control decision data is obtained by the risk radar performing anomaly detection on first service request decision data of the risk control system; the first service request decision data is obtained by the risk control system evaluating the risk level of a service request;
[0171] The support degree determination module 502 is configured to determine the proportion of the occurrence frequency of each user behavior element in the risk control decision data in the total occurrence frequency of all user behavior elements, to obtain the support degree of each user behavior element;
[0172] The abnormal user behavior element information determination module 503 is configured to filter user behavior elements with a support degree higher than a preset support degree threshold from the risk control decision data, to obtain abnormal user behavior element information of the risk control decision data;
[0173] The first updating module 504 is configured to update the risk control rule by using the abnormal user behavior element information of the risk control decision data, so that the risk control system detects the risk of a service request by using the risk control rule.
[0174] Optionally, the abnormal user behavior element information determination module includes:
[0175] The high-frequency user behavior element set determination sub-module is configured to filter user behavior elements with a support degree higher than the support degree threshold from the risk control decision data, to obtain a high-frequency user behavior element set;
[0176] The frequent pattern tree construction sub-module is configured to take each high-frequency user behavior element in the high-frequency user behavior element set as a node in the frequent pattern tree, to obtain a frequent pattern tree; the frequent pattern tree includes a root node; the root node is a node that does not contain a high-frequency user behavior element;
[0177] The acquisition sub-module is configured to acquire all prefix paths of the frequent pattern tree; the prefix path includes all high-frequency user behavior elements between each high-frequency user behavior element node and the root node;
[0178] The filtering sub-module is configured to filter prefix paths with the same number of high-frequency user behavior element items as a preset number of items and with a support degree of a high-frequency user behavior element higher than the support degree threshold, to obtain a target prefix path;
[0179] The abnormal user behavior element information determination submodule is configured to determine high-frequency user behavior elements in the target prefix path as abnormal user behavior element information.
[0180] Optionally, the first updating module comprises:
[0181] The generation submodule is configured to generate a new risk control rule by using the abnormal user behavior element information of the risk control decision data and a preset rule structure; the rule structure is a preset conditional statement; the conditional statement comprises a condition part and an operation part; the operation part is an adjustment of a risk score amount for different abnormal user behavior element information; and the condition part is a judgment statement for lack of the abnormal user behavior element information.
[0182] The risk control scene determination submodule is configured to determine a risk control scene corresponding to the new risk control rule.
[0183] The to-be-updated risk control rule set determination submodule is configured to determine a to-be-updated risk control rule set corresponding to the risk control scene.
[0184] The new risk control rule set determination submodule is configured to update the new risk control rule to the to-be-updated risk control rule set to obtain a new risk control rule set.
[0185] Optionally, the device further comprises:
[0186] The second receiving module is configured to receive at least one second service request decision data; the second service request decision data is obtained by querying the risk control data warehouse according to the abnormal user behavior element information.
[0187] The extraction module is configured to extract user identity information from the second service request decision data according to a preset extraction rule to obtain abnormal user identity information.
[0188] The second updating module is configured to update a risk control rule by using the abnormal user identity information.
[0189] Optionally, the abnormal user behavior element information comprises abnormal materials, abnormal environments and abnormal accounts.
[0190] Optionally, the risk control decision data is obtained by the risk radar from the risk control data warehouse according to a preset task, by querying and extracting first service request decision data corresponding to the preset task, and by screening service request decision data deviating from normal data from the first service request decision data corresponding to the preset task.
[0191] In another aspect of the embodiment of the present application, a risk control decision data generation device is also provided, which is applied to a risk assessment system, the risk assessment system comprising a risk control system, a risk control data warehouse, a risk radar and a risk control rule management center, and comprising:
[0192] an uploading module, configured to upload, by the risk control system, business request decision data to the risk control data warehouse; the business request decision data is obtained by the risk control system by using a risk control rule to judge a risk level of a business request; and the business request decision data comprises first business request decision data;
[0193] a first business request decision data acquisition module, configured to acquire, by the risk radar, the first business request decision data corresponding to a preset task from the risk control data warehouse according to the preset task;
[0194] an anomaly detection module, configured to detect, by the risk radar, whether the first business request decision data is abnormal;
[0195] a risk control decision data determination module, configured to, if the first business request decision data is abnormal, determine, by the risk radar, the first business request decision data as risk control decision data, and send the risk control decision data to the risk control rule management center;
[0196] the risk control rule management center is configured to generate a new risk control rule based on the risk control decision data, and update the new risk control rule to the risk control system.
[0197] Referring to Figure 6 , a structural block diagram of a risk control decision data generation device provided in an embodiment of the present application is shown, which can specifically include the following modules:
[0198] an uploading module 601, configured to upload, by the risk control system, business request decision data to the risk control data warehouse; the business request decision data is obtained by the risk control system by using a risk control rule to judge a risk level of a business request; and the business request decision data comprises first business request decision data;
[0199] a first business request decision data acquisition module 602, configured to acquire, by the risk radar, the first business request decision data corresponding to a preset task from the risk control data warehouse according to the preset task;
[0200] an anomaly detection module 603, configured to detect, by the risk radar, whether the first business request decision data is abnormal;
[0201] a risk control decision data determination module 604, configured to, if the first business request decision data is abnormal, determine, by the risk radar, the first business request decision data as risk control decision data, and send the risk control decision data to the risk control rule management center; the risk control rule management center is configured to generate a new risk control rule based on the risk control decision data, and update the new risk control rule to the risk control system.
[0202] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts are described in the part of the method embodiment.
[0203] In addition, the embodiment of the present application further provides an electronic device, such as Figure 7 As shown in the figure, the electronic device comprises a processor 701, a communication interface 702, a memory 703 and a communication bus 704, wherein the processor 701, the communication interface 702 and the memory 703 complete mutual communication through the communication bus 704,
[0204] The memory 703 is used for storing a computer program.
[0205] The processor 701 is used for executing the program stored in the memory 703, so as to realize the risk control rule updating method and the risk control decision data generating method of the embodiment of the present application.
[0206] The communication bus mentioned above can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or only one type of bus.
[0207] The communication interface is used for communication between the terminal and other devices.
[0208] The memory can comprise a random access memory (RAM) and can also comprise a non-volatile memory, for example at least one disk memory. Optionally, the memory can also be at least one storage device located away from the aforementioned processor.
[0209] The processor described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; or can be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
[0210] In another embodiment provided by the present application, a computer readable storage medium is provided, and the computer readable storage medium stores instructions, which, when executed on a computer, cause the computer to perform the risk control rule updating method and the risk control decision data generating method in any of the above embodiments.
[0211] In another embodiment provided by the present application, a computer program product is provided, and the computer program product includes instructions, which, when executed on a computer, cause the computer to perform the risk control rule updating method and the risk control decision data generating method in any of the above embodiments.
[0212] In the above embodiments, the implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented by using software, the implementation can be in a form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the implementation produces the flow or function described in the embodiments of the present application entirely or partially. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transferred from one website site, computer, server or data center to another website site, computer, server or data center through a wired (for example, coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (for example, infrared, wireless, microwave, etc.) manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. that includes one or more available media sets. The available medium can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, DVD), or a semiconductor medium (for example, solid state disk (SSD)), etc.
[0213] It is to be noted that, as used in this specification and the appended claims, the singular forms "a," "an" and "the" include plural referents unless the context clearly dictates otherwise. Thus, for example, reference to "a component" can include a combination of two or more components, and the term "an element" can include comparable reference to a plurality of elements. Also, as used in this specification and the appended claims, the term "or" as used in the context of "A / B" or "A / B / C" means any of the possibilities; for example, "A or B" means "A or B or both".
[0214] Each of the embodiments in the specification is described in a relevant manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the description of the method embodiments.
[0215] The above only describes the preferred embodiments of the present application, and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A risk control rule updating method, characterized in that: Applied to the risk control rule management center, the method includes: Receiving risk control decision data; the risk control decision data is obtained by the risk radar performing anomaly detection on first business request decision data of the risk control system; the first business request decision data is obtained by the risk control system evaluating the risk level of the business request; Determine the proportion of the number of occurrences of each user behavior element in the risk control decision data to the total number of occurrences of all user behavior elements, and obtain the support level of each user behavior element; Filtering user behavior elements whose support is higher than a preset support threshold from the risk control decision data to obtain abnormal user behavior element information of the risk control decision data, including: filtering user behavior elements whose support is higher than the support threshold from the risk control decision data to obtain a high-frequency user behavior element set; constructing a frequent pattern tree based on the high-frequency user behavior elements in the high-frequency user behavior element set; the frequent pattern tree includes a root node; the root node is a node that does not contain high-frequency user behavior elements; obtaining all prefix paths of the frequent pattern tree; the prefix path includes all high-frequency user behavior elements between each high-frequency user behavior element node and the root node; filtering prefix paths whose number of high-frequency user behavior element items is the same as the preset number of items and whose support of the high-frequency user behavior elements is higher than the support threshold to obtain a target prefix path; using the high-frequency user behavior elements in the target prefix path as abnormal user behavior element information; The abnormal user behavior element information of the risk control decision data is used to update the risk control rules, so that the risk control system uses the risk control rules to detect the risks of business requests.
2. The method according to claim 1, characterized in that The step of updating the risk control rules using the abnormal user behavior element information of the risk control decision data includes: Generate a new risk control rule using the abnormal user behavior element information of the risk control decision data and a preset rule structure; the rule structure is a preset conditional statement; the conditional statement includes a condition part and an operation part, the operation part is to adjust the risk score according to different abnormal user behavior element information, and the condition part is a judgment statement in the absence of the abnormal user behavior element information; Determine the risk control scenario corresponding to the new risk control rule; Determine a set of risk control rules to be updated corresponding to the risk control scenario; The new risk control rule is updated to the set of risk control rules to be updated to obtain a new set of risk control rules.
3. The method according to claim 1, characterized in that The method further comprises: receiving at least one second business request decision data; the second business request decision data is obtained by querying from the risk control data warehouse according to the abnormal user behavior element information; extracting user identity information from the second service request decision data according to a preset extraction rule to obtain abnormal user identity information; The risk control rules are updated using the abnormal user identity information.
4. The method according to any one of claims 1 to 3, characterized in that The abnormal user behavior element information includes abnormal materials, abnormal environment, and abnormal account number.
5. The method according to claim 1, characterized in that The risk control decision data is obtained by the risk radar querying and extracting the first business request decision data corresponding to the preset task from the risk control data warehouse according to the preset task, and screening the business request decision data that deviates from the normal data volume in the first business request decision data corresponding to the preset task.
6. A method for generating risk control decision data, characterized in that: Applied to the risk assessment system, which includes a risk control system, a risk control data warehouse, a risk radar, and a risk control rule management center, including: The risk control system uploads the business request decision data to the risk control data warehouse; the business request decision data is obtained by the risk control system using risk control rules to determine the risk level of the business request; the business request decision data includes first business request decision data; The risk radar obtains the first business request decision data corresponding to the preset task from the risk control data warehouse according to the preset task; The risk radar detects whether the first business request decision data is abnormal; If the first business request decision data is abnormal, the risk radar uses the first business request decision data as risk control decision data and sends the risk control decision data to the risk control rule management center; The risk control rule management center is used to generate new risk control rules based on the risk control decision data and update the new risk control rules to the risk control system, which includes: screening user behavior elements whose support is higher than the support threshold from the risk control decision data to obtain a high-frequency user behavior element set; constructing a frequent pattern tree based on the high-frequency user behavior elements in the high-frequency user behavior element set; the frequent pattern tree includes a root node; the root node is a node that does not contain high-frequency user behavior elements; obtaining all prefix paths of the frequent pattern tree; the prefix path includes all high-frequency user behavior elements between each high-frequency user behavior element node and the root node; screening prefix paths whose number of high-frequency user behavior elements is the same as the preset number of items and whose support is higher than the support threshold to obtain a target prefix path; using the high-frequency user behavior elements in the target prefix path as abnormal user behavior element information, and using the abnormal user behavior element information of the risk control decision data to update the risk control rules.
7. A risk control rule updating device, characterized in that: Applied to the risk control rule management center, the device includes: A first receiving module is configured to receive risk control decision data; the risk control decision data is obtained by a risk radar performing anomaly detection on first business request decision data of a risk control system; the first business request decision data is obtained by the risk control system evaluating the risk level of a business request; A support determination module is used to determine the proportion of the number of occurrences of each user behavior element in the risk control decision data to the total number of occurrences of all user behavior elements, and obtain the support of each user behavior element; An abnormal user behavior element information determination module is used to filter user behavior elements whose support is higher than a preset support threshold from the risk control decision data to obtain abnormal user behavior element information of the risk control decision data, including: filtering user behavior elements whose support is higher than the support threshold from the risk control decision data to obtain a high-frequency user behavior element set; constructing a frequent pattern tree based on the high-frequency user behavior elements in the high-frequency user behavior element set; the frequent pattern tree includes a root node; the root node is a node that does not contain high-frequency user behavior elements; obtaining all prefix paths of the frequent pattern tree; the prefix path includes all high-frequency user behavior elements between each high-frequency user behavior element node and the root node; filtering prefix paths whose number of high-frequency user behavior element items is the same as the preset number of items and whose support is higher than the support threshold to obtain a target prefix path; and using the high-frequency user behavior elements in the target prefix path as abnormal user behavior element information; The first updating module is used to update the risk control rules using the abnormal user behavior element information of the risk control decision data, so that the risk control system uses the risk control rules to detect the risks of business requests.
8. An electronic device, characterized in that: comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; The memory is used to store computer programs; The processor is used to implement the risk control rule updating method and risk control decision data generating method described in any one of claims 1 to 7 when executing the program stored in the memory.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the risk control rule updating method and the risk control decision data generating method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Risk prevention and control strategy updating method and device
CN110428137A
Maximalσ-Frequent Subtree Extraction of XML data bybinary code
KR1020050112229A
Method and device for determining high-risk user
WO2019196549A1