Abnormal transaction data recovery method, device and equipment and storage medium

By establishing and processing transaction data tables, and reconstructing them into a chain diagram in two-dimensional space, abnormal transaction data can be restored. This solves the system operation problems caused by data corruption, distortion, loss, and forgery in the transaction system, and ensures the stability of the transaction system and the interests of both parties in the transaction.

CN116416068BActive Publication Date: 2026-08-04GUANGDONG MINGLING DATA CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGDONG MINGLING DATA CO LTD
Filing Date
2023-05-04
Publication Date
2026-08-04

AI Technical Summary

Technical Problem

In large-scale trading systems, trading data may become disordered, distorted, lost, or forged due to system structure, signal interference, equipment failure, or other reasons. Existing processing methods can affect the normal operation of the trading system and cause losses.

Method used

By acquiring the target user's transaction data, a first data table is established, transaction indicators are determined and anomalies are handled, resulting in a second data table and abnormal transactions. A two-dimensional spatial reconstruction is then performed to form a chain diagram, and finally, data restoration is performed to recover the abnormal transaction data.

Benefits of technology

To ensure the normal operation of the trading system, protect the interests of both parties, and avoid misjudging normal transactions as abnormal transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116416068B_ABST
    Figure CN116416068B_ABST
Patent Text Reader

Abstract

The application discloses a method, device and equipment for recovering abnormal transaction data and a storage medium. The method comprises the following steps: obtaining transaction data of each transaction of a target user in a preset time period, establishing the transaction data of each transaction into a first data table, determining each transaction index in the first data table, and obtaining a second data table by performing data abnormality processing on the first data table according to each transaction index. Thus, the abnormal transaction in the first data table can be determined. However, the abnormal transaction is not determined as a false transaction or deleted data. Instead, the second data table and each abnormal transaction are reconstructed in a two-dimensional space to obtain a chain graph corresponding to the target user. Then, data of the chain graph is restored, so that the recovery of the abnormal transaction data is completed. The method can ensure normal operation of a transaction system and protect interests of both parties in a transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data recovery technology, specifically to a method, apparatus, device, and storage medium for recovering abnormal transaction data. Background Technology

[0002] In large-scale trading systems, due to system architecture, signal interference, equipment malfunctions, and other reasons, abnormal situations such as disordered, distorted, lost, or missed transaction data are inevitable. In extreme cases, even forged transaction data may occur. These abnormal transaction data can threaten the security and stability of the trading system. Existing methods include discarding abnormal transaction data as garbage, deleting the abnormal transaction as a failed transaction, or encrypting the abnormal transaction, thus affecting the normal trading process.

[0003] If a normal or genuine transaction is judged to be abnormal or a fake transaction, it will affect the normal operation of the transaction system and cause losses to the sender and receiver of the transaction and even the transaction system. Summary of the Invention

[0004] In view of this, this application provides a method, apparatus, device, and storage medium for recovering abnormal transaction data, which solves the problem that if a normal or genuine transaction is determined to be abnormal or a fake transaction, it will affect the normal operation of the transaction and cause losses to the sender and receiver of the transaction or even the transaction system.

[0005] To achieve the above objectives, the following solution is proposed:

[0006] Firstly, a method for recovering abnormal transaction data includes:

[0007] Obtain transaction data for each transaction made by the target user within a preset time period;

[0008] A first data table is established based on the transaction data of each transaction;

[0009] Each transaction indicator in the first data table is determined, and based on each transaction indicator, the first data table is processed to handle data anomalies, resulting in a second data table and each abnormal transaction.

[0010] The second data table and each abnormal transaction are reconstructed in two-dimensional space to obtain a chain diagram corresponding to the target user.

[0011] The chain diagram is then restored to recover the abnormal transaction data.

[0012] Preferably, the step of performing data anomaly processing on the first data table based on each of the transaction indicators to obtain a second data table and each abnormal transaction includes:

[0013] When the transaction indicator is a transaction count value, the continuity of each transaction is determined based on the transaction count value of each transaction.

[0014] If not, then determine each non-contiguous position in the first data table;

[0015] Obtain the discontinuity type corresponding to each of the discontinuous positions, and determine the abnormal transaction corresponding to each of the discontinuous positions based on the discontinuity type;

[0016] The first data table is updated based on the abnormal transactions to obtain the second data table.

[0017] Preferably, determining the abnormal transactions corresponding to each discontinuous position based on the discontinuity type includes:

[0018] For each non-continuous position, if the non-continuity type corresponding to the non-continuous position is missing, then obtain the previous transaction and the next transaction corresponding to the non-continuous position.

[0019] Determine the balance of the previous transaction and the balance of the next transaction corresponding to the non-contiguous position;

[0020] Obtain the transaction terminal corresponding to the target user at the non-contiguous location;

[0021] The abnormal transaction corresponding to the non-contiguous position is determined from the transaction terminal using the balance of the previous transaction and the balance of the next transaction corresponding to the non-contiguous position.

[0022] Preferably, determining the abnormal transactions corresponding to each discontinuous position based on the discontinuity type includes:

[0023] For each non-contiguous position, if the non-contiguous type corresponding to the non-contiguous position is a repeating type, then determine the repeating transactions corresponding to the non-contiguous position.

[0024] Determine the last transaction in each of the repeated transactions, and take the next transaction corresponding to the last transaction as the target transaction;

[0025] Obtain the transaction type code, transaction amount, and balance of the target transaction;

[0026] Based on the transaction type code, transaction amount, and balance of the target transaction, each pseudo transaction in each of the repeated transactions is determined;

[0027] Each of the aforementioned duplicate transactions, excluding the aforementioned fake transactions, will be classified as an abnormal transaction.

[0028] Preferably, it further includes:

[0029] If the transactions are consecutive, then obtain the transaction time of each transaction;

[0030] For each transaction, determine whether the transaction time of the current transaction is later than the transaction time of the previous transaction.

[0031] If not, the transaction will be classified as an abnormal transaction.

[0032] Preferably, it further includes:

[0033] If the transactions are consecutive, then for each transaction, obtain the current balance, transaction code, and transaction amount corresponding to that transaction;

[0034] Multiply the transaction code by the transaction amount to obtain the first transaction amount;

[0035] Subtracting the first transaction amount from the current balance corresponding to this transaction equals the second transaction amount;

[0036] Get the balance corresponding to the previous transaction of this transaction;

[0037] If the balance of the previous transaction is not equal to the amount of the second transaction, then the transaction will be considered an abnormal transaction.

[0038] Preferably, the step of reconstructing the second data table and each abnormal transaction in a two-dimensional space to obtain a chain graph corresponding to the target user includes:

[0039] Obtain the transaction sequence value and transaction time point of each of the aforementioned abnormal transactions and each transaction in the second data table;

[0040] A two-dimensional spatial coordinate system is established with the transaction sequence value as the vertical axis and the transaction time point as the horizontal axis.

[0041] Determine the coordinates of the first transaction and the last transaction in the second data table from the two-dimensional coordinate system. Connect the coordinates of the first transaction and the last transaction with a straight line to form a chain. At the same time, plot each of the abnormal transactions in the two-dimensional coordinate system to obtain a chain diagram.

[0042] Secondly, a device for recovering abnormal transaction data includes:

[0043] The transaction data acquisition module is used to acquire transaction data of each transaction made by the target user within a preset time period;

[0044] The first data table creation module is used to create a first data table based on each of the aforementioned transaction data.

[0045] The data anomaly module is used to determine the transaction indicators in the first data table, and to perform data anomaly processing on the first data table based on each transaction indicator to obtain the second data table and each abnormal transaction.

[0046] The reconstruction module is used to reconstruct the second data table and each abnormal transaction in two-dimensional space to obtain a chain diagram corresponding to the target user.

[0047] The data restoration module is used to restore the chain graph to recover abnormal transaction data.

[0048] Thirdly, a device for recovering abnormal transaction data, including a memory and a processor;

[0049] The memory is used to store programs;

[0050] The processor is configured to execute the program to implement the various steps of the abnormal transaction data recovery method as described in the first aspect.

[0051] Fourthly, a storage medium storing a computer program thereon, which, when executed by a processor, implements the steps of the method for recovering abnormal transaction data as described in the first aspect.

[0052] As can be seen from the above technical solution, this application obtains transaction data of each transaction made by the target user within a preset time period, establishes the transaction data of each transaction into a first data table, determines each transaction indicator in the first data table, and performs data anomaly processing on the first data table based on each transaction indicator to obtain a second data table. This allows the identification of abnormal transactions in the first data table. However, at this point, the abnormal transactions are not judged as fake transactions or deleted. Instead, the second data table and each abnormal transaction are reconstructed in two-dimensional space to obtain a chain graph corresponding to the target user. Then, the chain graph is restored to restore the data, thereby completing the recovery of abnormal transaction data. This method can ensure the normal operation of the transaction system and protect the interests of both parties in the transaction. Attached Figure Description

[0053] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0054] Figure 1 An optional flowchart of a method for recovering abnormal transaction data provided in an embodiment of this application;

[0055] Figure 2 A chain diagram provided for an embodiment of this application;

[0056] Figure 3 A schematic diagram of the structure of an abnormal transaction data recovery device provided in an embodiment of this application;

[0057] Figure 4 This is a schematic diagram of the structure of a device for recovering abnormal transaction data provided in an embodiment of this application. Detailed Implementation

[0058] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0059] In large-scale trading systems, due to system architecture, signal interference, equipment malfunctions, and other reasons, abnormal situations such as disordered, distorted, lost, or missed transaction data are inevitable. In extreme cases, even forged transaction data may occur, resulting in distorted, lost, and fake transaction data. These abnormal transaction data threaten the security and stability of the trading system. Current methods typically treat distorted transaction data as garbage and lost transaction data as bad debt. For fake transactions, various encryption methods are generally used to prevent their generation. To ensure data integrity, a checksum is added to each data entry; only data that passes the checksum is considered legitimate. However, this method has the drawback of being unable to distinguish between genuine fake transactions and transactions with data disordered due to signal interference, easily leading to encryption / decryption failures and genuine transactions being mistaken for "fake transactions."

[0060] If a normal or genuine transaction is judged to be abnormal or a fake transaction, it will affect the normal operation of the transaction system and cause losses to the sender and receiver of the transaction and even the transaction system.

[0061] This invention provides a method for recovering abnormal transaction data. This method can be applied to various computer terminals or smart terminals, and its execution entity can be the processor or server of the computer terminal or smart terminal. The method flowchart is shown below. Figure 1 As shown, it specifically includes:

[0062] S1: Obtain transaction data for each transaction made by the target user within a preset time period;

[0063] Specifically, there are multiple trading users in the trading system. If it is for a single user, then that user is the target user in this application. The preset time period can be one day or two days, etc. For the target user, the target user may make multiple transactions within the preset time period. The transaction data of each transaction may include: the time of the transaction, the sender and receiver of the transaction, the transaction number, the transaction amount, etc. This embodiment does not limit this.

[0064] S2: Establish a first data table based on the transaction data of each transaction;

[0065] After obtaining the transaction data of each transaction of the target user, the transaction data of each transaction can be integrated to establish the first data table.

[0066] Creating a primary data table makes it easier to analyze transaction data, thereby enabling efficient recovery of abnormal transaction data.

[0067] S3: Determine the transaction indicators in the first data table, and perform data anomaly processing on the first data table based on each transaction indicator to obtain the second data table and each abnormal transaction;

[0068] In the embodiments provided in this application, transaction indicators include, but are not limited to: transaction amount (deal_fee), balance (balance), card number (logic_card_no), user ID, SIM card number (sam_no), terminal number, transaction count (count), transaction time (deal_time), and transaction type code (deal_type_k). Each transaction indicator can be used to process the first data table accordingly. One transaction indicator can be selected to process the first data table, or multiple transaction indicators can be selected to process the first data table comprehensively.

[0069] Here's an example: Two transaction metrics are set: transaction count and transaction time. The transaction count can be understood as the order or sequence of transactions, such as the first transaction, second transaction, etc., of a target user within a preset time period. The first transaction's time must be earlier than the second transaction's. If a transaction exists in the first data table with a normal transaction time, but its transaction count is inconsistent with the counts of its predecessor and successor, this transaction can be considered an abnormal transaction and removed from the first data table, resulting in the second data table. The second data table no longer includes abnormal transactions.

[0070] S4: Reconstruct the second data table and each abnormal transaction in two-dimensional space to obtain a chain diagram corresponding to the target user;

[0071] Understandably, in this step, the second data table can be reconstructed in two dimensions to obtain the first image, and then each abnormal transaction can be drawn in the first image to obtain the chain diagram corresponding to the target user.

[0072] The purpose of this step is to link all transactions and each abnormal transaction in the second data table, thereby obtaining relatively complete and coherent transaction data.

[0073] S5: Perform data restoration on the chain diagram to complete the recovery of abnormal transaction data.

[0074] After reconstructing the second data table in two dimensions, one or more relatively continuous line segments or chains can be obtained. Each transaction data may restore one or more of the above line segments or chains in order to recover abnormal transaction data.

[0075] The method provided in this embodiment of the invention involves processing the first data table for data anomalies based on various transaction indicators to obtain a second data table and each abnormal transaction. The specific process is described below:

[0076] S31: When the transaction indicator is a transaction count value, determine whether the transactions are continuous based on the transaction count value of each transaction;

[0077] Trading indicators include various types, including trade counts, which indicate the order of trades. When the trading indicator is a trade count, the order of trades can be determined based on the trade count values ​​of each trade. An example is shown in Table 1 below:

[0078] Table 1

[0079]

[0080] Using Table 1 above as the first data table, it can be seen that the transaction count values ​​of each transaction in the first data table are continuous, and there is no break from 1 to 8.

[0081] S32: If not, then determine each non-contiguous position in the first data table;

[0082] In one example, the first data table is shown in Table 2 below:

[0083] Table 2

[0084]

[0085]

[0086] As can be seen, the transaction counts in the first data table are not consecutive, with a missing transaction count of 4. Therefore, the transaction that should have a transaction count of 4 in the table can be considered an abnormal transaction. The discontinuous position in the table is then the midpoint between transaction counts of 3 and 5.

[0087] S33: Obtain the discontinuity type corresponding to each of the discontinuous positions, and determine the abnormal transaction corresponding to each of the discontinuous positions according to the discontinuity type;

[0088] The types of discontinuity corresponding to discontinuous positions include various types, such as missing transactions in Table 2. Therefore, the abnormal transaction corresponding to that discontinuity position can be determined based on the type of discontinuity.

[0089] S34: Update the first data table based on the abnormal transaction to obtain the second data table.

[0090] After identifying abnormal transactions, the non-contiguous positions in the first data table can be updated based on the abnormal transactions to supplement the first data table; or the abnormal transactions in the first data table can be deleted to obtain the second data table.

[0091] Specifically, step S33 above, which involves determining the abnormal transactions corresponding to each discontinuous position based on the discontinuity type, may include:

[0092] S331: For each discontinuous position, if the discontinuity type corresponding to the discontinuous position is missing, then obtain the previous transaction and the next transaction corresponding to the discontinuous position; determine the balance of the previous transaction and the balance of the next transaction corresponding to the discontinuous position; obtain the transaction terminal corresponding to the target user at the discontinuous position; use the balance of the previous transaction and the balance of the next transaction corresponding to the discontinuous position to determine the abnormal transaction corresponding to the discontinuous position from the transaction terminal.

[0093] Specifically, continuing with the example above, as shown in Table 2, the discontinuity type corresponding to this discontinuous position is a missing type, meaning a transaction is missing between transaction count values ​​of 3 and 5. Therefore, the previous transaction is the transaction with a transaction count value of 3, and the next transaction is the transaction with a transaction count value of 5. We define the transaction with a transaction count value of 3 as transaction 3 and the transaction with a transaction count value of 5 as transaction 5. As shown in Table 2, the balance of transaction 3 is 46, and the balance of transaction 5 is 42. Next, we obtain the transaction terminal corresponding to the target user at the discontinuous position. Then, based on the balance of 46 for transaction 3 and the balance of 42 for transaction 5, we can determine the abnormal transaction from the transaction terminal.

[0094] S332: For each non-continuous position, if the non-continuity type corresponding to the non-continuous position is a repeating type, then determine each repeating transaction corresponding to the non-continuous position; determine the last transaction in each of the repeating transactions, and take the next transaction corresponding to the last transaction as the target transaction; obtain the transaction type code, transaction amount, and balance of the target transaction; determine each pseudo transaction in each of the repeating transactions based on the transaction type code, transaction amount, and balance of the target transaction; and treat the repeating transactions in each of the repeating transactions other than the pseudo transactions as abnormal transactions.

[0095] In one example, as shown in Table 3:

[0096] Table 3

[0097]

[0098] As shown in Table 3, a transaction with a transaction count of 3 appeared twice, but the two transactions were not the same. One transaction, with a transaction time of 2005-01-01 09:21:20, a transaction type code of 1, and a transaction amount of 50, was referred to as Transaction A. The other transaction, with a transaction time of 2005-01-01 09:31:20, a transaction type code of -1, and a transaction amount of 2, was referred to as Transaction B. It can be seen that Transaction A and Transaction B are duplicate transactions, and at least one of these two transactions is an abnormal transaction. Therefore, the next transaction after the last transaction (Transaction B), i.e., the transaction with a transaction count of 4, is taken as the target transaction. The target transaction has a transaction type code of -1, a transaction amount of 2, and a balance of 44. Therefore, Transaction A can be identified as a fake transaction, and Transaction B as an abnormal transaction.

[0099] In one embodiment provided in this application, after determining whether the transactions are consecutive in step S31, the method further includes:

[0100] If the transactions are consecutive, the transaction time of each transaction is obtained; for each transaction, it is determined whether the transaction time of the transaction is later than the transaction time of the previous transaction; if not, the transaction is regarded as an abnormal transaction.

[0101] In one example, as shown in Table 4:

[0102] Table 4

[0103]

[0104]

[0105] As shown in Table 4, the transaction with a transaction count of 5 was later than the transaction with a transaction count of 4. Therefore, the transaction with a transaction count of 5 can be identified as an abnormal transaction.

[0106] Optionally, if the transactions are consecutive, for each transaction, obtain the current balance, transaction code, and transaction amount corresponding to that transaction; multiply the transaction code by the transaction amount to obtain a first transaction amount; subtract the first transaction amount from the current balance corresponding to that transaction to obtain a second transaction amount; obtain the balance corresponding to the previous transaction; if the balance corresponding to the previous transaction is not equal to the second transaction amount, then that transaction is considered an abnormal transaction. Based on the current balance, transaction code, and transaction amount, abnormal transactions can be easily deduced. The following relationship exists between transactions: Current transaction's balance before the transaction = Previous transaction's balance = Current transaction's balance - Current transaction's transaction amount * Current transaction's transaction type code.

[0107] Specifically, the process of reconstructing the second data table and each abnormal transaction in two-dimensional space in step S4 to obtain the chain diagram corresponding to the target user is explained in detail below:

[0108] Obtain the transaction sequence value and transaction time point of each abnormal transaction and each transaction in the second data table; establish a two-dimensional spatial coordinate system with the transaction sequence value as the vertical axis and the transaction time point as the horizontal axis; determine the coordinate point corresponding to the first transaction and the coordinate point corresponding to the last transaction in the second data table from the two-dimensional spatial coordinate system, connect the coordinate point corresponding to the first transaction and the coordinate point corresponding to the last transaction with a straight line to form a chain, and simultaneously draw each abnormal transaction in the two-dimensional spatial coordinate system to obtain a chain diagram.

[0109] Optionally, if the second data table is Table 1 above, a chain or line segment with a starting point of (09:06:30, 1) and an ending point of (10:19:15, 8) can be drawn in a two-dimensional coordinate system; if the second data table is Table 2, two chains with a starting point of (09:06:30, 1) and an ending point of (09:31:20, 3) and a starting point of (09:56:10, 5) and an ending point of (10:01:30, 6) can be drawn in a two-dimensional coordinate system; if the second data table is Table 3, after determining that transaction A is a pseudo transaction, it is deleted from the first data table, and the resulting second data table is the same as Table 1. Therefore, a chain with a starting point of (09:06:30, 1) and an ending point of (10:19:15, 8) can also be drawn in a two-dimensional coordinate system.

[0110] If the second data table is as shown in Table 5 below:

[0111] Table 5

[0112]

[0113] If the second data table is as shown in Table 5, then two chains can be drawn in the two-dimensional coordinate system with the starting point (09:06:30, 1) and the ending point (09:42:30, 4) and the starting point (09:56:10, 1) and the ending point (10:19:15, 4).

[0114] If the second data table is as shown in Table 6 below:

[0115] Table 6

[0116]

[0117]

[0118] In Table 6, the balance relationship between transactions with a transaction count of 3 and transactions with a transaction count of 4 is not continuous. Therefore, two chains can be drawn in a two-dimensional coordinate system with the starting point (09:06:30, 1) and the ending point (09:31:20, 3) and the starting point (09:42:30, 4) and the ending point (10:19:15, 8).

[0119] Next, the abnormal transactions will be plotted in a two-dimensional coordinate system, such as... Figure 2 As shown, Figure 2The horizontal axis represents the transaction time (month / day), and the vertical axis represents the transaction count. The two straight lines with the starting point (1 / 1, 0) and ending point (8 / 3, 350) and the starting point (10 / 28, 450) and ending point (12 / 7, 550) in the graph correspond to the transactions in the second data table. The two straight lines with the starting point (4 / 18, 100) and ending point (6 / 22, 200) and the starting point (9 / 18, 50) and ending point (10 / 28, 100) correspond to abnormal transactions.

[0120] Next, based on the transaction time and transaction count, we can... Figure 2 The abnormal transaction with a starting point of (9 / 18, 50) and an ending point of (10 / 28, 100) is moved, or interpolation is used to try inserting the line corresponding to the abnormal transaction into the breakpoint to see if the transactions before and after the breakpoint can be connected. If they can be connected, a complete transaction chain can be formed, completing the recovery process of the abnormal transaction data; if they cannot be connected, the abnormal transaction is deleted. The abnormal transaction with a starting point of (4 / 18, 100) and an ending point of (6 / 22, 200) overlaps with the line with a starting point of (1 / 1, 0) and an ending point of (8 / 3, 350) in terms of transaction time, so this abnormal transaction can be deleted.

[0121] and Figure 1 Corresponding to the method described above, embodiments of the present invention also provide a device for recovering abnormal transaction data, used for... Figure 1 In a specific implementation of the method, the abnormal transaction data recovery device provided in this embodiment of the invention can be used in a computer terminal or various mobile devices, combined with Figure 3 The document introduces devices for recovering abnormal transaction data, such as... Figure 3 As shown, the device may include:

[0122] The transaction data acquisition module 10 is used to acquire transaction data of each transaction made by the target user within a preset time period.

[0123] The first data table creation module 20 is used to create a first data table based on each of the transaction data;

[0124] The data anomaly module 30 is used to determine the transaction indicators in the first data table, and to perform data anomaly processing on the first data table based on each transaction indicator to obtain a second data table and each abnormal transaction.

[0125] The reconstruction module 40 is used to reconstruct the second data table and each abnormal transaction in two-dimensional space to obtain a chain diagram corresponding to the target user.

[0126] The data restoration module 50 is used to restore the chain diagram to complete the recovery of abnormal transaction data.

[0127] As can be seen from the above technical solution, this application obtains transaction data of each transaction made by the target user within a preset time period, establishes the transaction data of each transaction into a first data table, determines each transaction indicator in the first data table, and performs data anomaly processing on the first data table based on each transaction indicator to obtain a second data table. This allows the identification of abnormal transactions in the first data table. However, at this point, the abnormal transactions are not judged as fake transactions or deleted. Instead, the second data table and each abnormal transaction are reconstructed in two-dimensional space to obtain a chain graph corresponding to the target user. Then, the chain graph is restored to restore the data, thereby completing the recovery of abnormal transaction data. This method can ensure the normal operation of the transaction system and protect the interests of both parties in the transaction.

[0128] In one example, the data anomaly module 30 may include:

[0129] The judgment module is used to determine whether the transactions are consecutive based on the transaction count value of each transaction when the transaction indicator is a transaction count value.

[0130] The non-continuous position determination module is used to determine each non-continuous position in the first data table if no;

[0131] An abnormal transaction determination module is used to obtain the discontinuity type corresponding to each of the discontinuous positions, and determine the abnormal transaction corresponding to each of the discontinuous positions according to the discontinuity type.

[0132] The update module is used to update the first data table based on the abnormal transactions to obtain a second data table.

[0133] In one example, the abnormal transaction determination module may include:

[0134] The module for obtaining previous and next transactions is used to obtain the previous and next transactions corresponding to each non-contiguous position if the non-contiguousness type corresponding to the non-contiguous position is missing.

[0135] The balance determination module is used to determine the balance of the previous transaction and the balance of the next transaction corresponding to the non-contiguous position.

[0136] A transaction terminal acquisition module is used to acquire the transaction terminal corresponding to the target user at the non-contiguous location;

[0137] The abnormal transaction first determination module is used to determine the abnormal transaction corresponding to the non-contiguous position from the transaction terminal by using the balance of the previous transaction and the balance of the next transaction corresponding to the non-contiguous position.

[0138] In one example, the abnormal transaction determination module may further include:

[0139] The duplicate transaction determination module is used to determine each duplicate transaction corresponding to each non-continuous position if the non-continuity type corresponding to the non-continuous position is a duplicate type.

[0140] The target transaction determination module is used to determine the last transaction in each of the repeated transactions and to take the next transaction corresponding to the last transaction as the target transaction.

[0141] The target transaction information acquisition module is used to acquire the transaction type code, transaction amount, and balance of the target transaction;

[0142] The fake transaction identification module is used to identify each fake transaction in each of the repeated transactions based on the transaction type code, transaction amount, and balance of the target transaction.

[0143] The second abnormal transaction determination module is used to identify duplicate transactions other than the pseudo transactions among the duplicate transactions as abnormal transactions.

[0144] In one example, the device may include:

[0145] The transaction time acquisition module is used to acquire the transaction time of each transaction if the transactions are consecutive.

[0146] The transaction time determination module is used to determine whether the transaction time of each transaction is later than the transaction time of the previous transaction.

[0147] The third module for determining abnormal transactions is used to classify a transaction as abnormal if no such condition is found.

[0148] In one example, the device may include:

[0149] The information acquisition module is used to acquire the current balance, transaction code, and transaction amount corresponding to each transaction if the transactions are consecutive.

[0150] The multiplication module is used to multiply the transaction code by the transaction amount to obtain the first transaction amount;

[0151] The subtraction module is used to subtract the first transaction amount from the current balance corresponding to the transaction, so that the result equals the second transaction amount;

[0152] The module for obtaining the balance of the previous transaction is used to obtain the balance corresponding to the previous transaction of this transaction;

[0153] The fourth abnormal transaction determination module is used to determine an abnormal transaction if the balance corresponding to the previous transaction is not equal to the second transaction amount.

[0154] In one example, the refactoring module 40 may include:

[0155] The transaction data acquisition module is used to acquire the transaction sequence value and transaction time point of each abnormal transaction and each transaction in the second data table.

[0156] A two-dimensional spatial coordinate system establishment module is used to establish a two-dimensional spatial coordinate system with the transaction sequence value as the vertical axis and the transaction time point as the horizontal axis.

[0157] The drawing module is used to determine the coordinate points corresponding to the first transaction and the last transaction in the second data table from the two-dimensional spatial coordinate system, connect the coordinate points corresponding to the first transaction and the last transaction with a straight line to form a chain, and simultaneously draw each of the abnormal transactions in the two-dimensional spatial coordinate system to obtain a chain diagram.

[0158] Furthermore, embodiments of this application provide a device for recovering abnormal transaction data. Optionally, Figure 4 The hardware structure block diagram of the abnormal transaction data recovery device is shown below. Figure 4 The hardware structure of the abnormal transaction data recovery device may include: at least one processor 01, at least one communication interface 02, at least one memory 03, and at least one communication bus 04.

[0159] In this embodiment, the number of processor 01, communication interface 02, memory 03 and communication bus 04 is at least one, and processor 01, communication interface 02 and memory 03 communicate with each other through communication bus 04.

[0160] Processor 01 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention.

[0161] Memory 03 may include high-speed RAM, and may also include non-volatile memory, such as at least one disk storage device.

[0162] The memory stores a program that the processor can call. The program is used to execute the following methods for recovering abnormal transaction data, including:

[0163] Obtain transaction data for each transaction made by the target user within a preset time period;

[0164] A first data table is established based on the transaction data of each transaction;

[0165] Each transaction indicator in the first data table is determined, and based on each transaction indicator, the first data table is processed to handle data anomalies, resulting in a second data table and each abnormal transaction.

[0166] The second data table and each abnormal transaction are reconstructed in two-dimensional space to obtain a chain diagram corresponding to the target user.

[0167] The chain diagram is then restored to recover the abnormal transaction data.

[0168] Optionally, the refined and extended functions of the program can be found in the description of the abnormal transaction data recovery method in the method embodiment.

[0169] This application embodiment also provides a storage medium that can store a program suitable for execution by a processor. When the program runs, it controls the device where the storage medium is located to execute the following method for recovering abnormal transaction data, including:

[0170] Obtain transaction data for each transaction made by the target user within a preset time period;

[0171] A first data table is established based on the transaction data of each transaction;

[0172] Each transaction indicator in the first data table is determined, and based on each transaction indicator, the first data table is processed to handle data anomalies, resulting in a second data table and each abnormal transaction.

[0173] The second data table and each abnormal transaction are reconstructed in two-dimensional space to obtain a chain diagram corresponding to the target user.

[0174] The chain diagram is then restored to recover the abnormal transaction data.

[0175] Specifically, the storage medium can be a computer-readable storage medium, which can be an electronic storage device such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM.

[0176] Optionally, the refined and extended functions of the program can be found in the description of the abnormal transaction data recovery method in the method embodiment.

[0177] Furthermore, the functional modules in the various embodiments of this disclosure can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part. If the function is implemented as a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a live streaming device, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this disclosure.

[0178] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0179] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0180] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for recovering abnormal transaction data, characterized in that, include: Obtain transaction data for each transaction made by the target user within a preset time period; A first data table is established based on the transaction data of each transaction; The process involves identifying various transaction indicators in the first data table and performing data anomaly processing on the first data table based on these indicators to obtain a second data table and each abnormal transaction. This includes: when the transaction indicator is a transaction count value, determining whether each transaction is continuous based on its transaction count value; if not, identifying each non-continuous position in the first data table; obtaining the non-continuity type corresponding to each non-continuity position and determining the abnormal transaction corresponding to each non-continuity position based on the non-continuity type; updating the first data table based on the abnormal transactions to obtain the second data table; the second data table does not include the abnormal transactions. The second data table and each abnormal transaction are reconstructed in two-dimensional space to obtain a chain diagram corresponding to the target user. This includes: obtaining the transaction sequence value and transaction time point of each abnormal transaction and each transaction in the second data table; establishing a two-dimensional spatial coordinate system with the transaction sequence value as the vertical axis and the transaction time point as the horizontal axis; determining the coordinate point corresponding to the first transaction and the coordinate point corresponding to the last transaction in the second data table from the two-dimensional spatial coordinate system, connecting the coordinate points corresponding to the first transaction and the last transaction with a straight line to form a chain, and simultaneously plotting each abnormal transaction in the two-dimensional spatial coordinate system to obtain a chain diagram; and restoring the chain diagram to complete the recovery of the abnormal transaction data.

2. The method according to claim 1, characterized in that, The step of determining the abnormal transactions corresponding to each discontinuous position based on the discontinuity type includes: For each non-continuous position, if the non-continuity type corresponding to the non-continuous position is missing, then obtain the previous transaction and the next transaction corresponding to the non-continuous position. Determine the balance of the previous transaction and the balance of the next transaction corresponding to the non-contiguous position; Obtain the transaction terminal corresponding to the target user at the non-contiguous location; The abnormal transaction corresponding to the non-contiguous position is determined from the transaction terminal using the balance of the previous transaction and the balance of the next transaction corresponding to the non-contiguous position.

3. The method according to claim 1, characterized in that, The step of determining the abnormal transactions corresponding to each discontinuous position based on the discontinuity type includes: For each non-contiguous position, if the non-contiguous type corresponding to the non-contiguous position is a repeating type, then determine the repeating transactions corresponding to the non-contiguous position. Determine the last transaction in each of the repeated transactions, and take the next transaction corresponding to the last transaction as the target transaction; Obtain the transaction type code, transaction amount, and balance of the target transaction; Based on the transaction type code, transaction amount, and balance of the target transaction, each pseudo transaction in each of the repeated transactions is determined; Each of the aforementioned duplicate transactions, excluding the aforementioned fake transactions, will be classified as an abnormal transaction.

4. The method according to claim 1, characterized in that, Also includes: If the transactions are consecutive, then obtain the transaction time of each transaction; For each transaction, determine whether the transaction time of the current transaction is later than the transaction time of the previous transaction. If not, the transaction will be classified as an abnormal transaction.

5. The method according to claim 1, characterized in that, Also includes: If the transactions are consecutive, then for each transaction, obtain the current balance, transaction code, and transaction amount corresponding to that transaction; Multiply the transaction code by the transaction amount to obtain the first transaction amount; Subtracting the first transaction amount from the current balance corresponding to this transaction equals the second transaction amount; Get the balance corresponding to the previous transaction of this transaction; If the balance of the previous transaction is not equal to the amount of the second transaction, then the transaction will be considered an abnormal transaction.

6. A device for recovering abnormal transaction data, characterized in that, include: The transaction data acquisition module is used to acquire transaction data of each transaction made by the target user within a preset time period; The first data table creation module is used to create a first data table based on each of the aforementioned transaction data. A data anomaly module is used to determine transaction indicators in the first data table and, based on each transaction indicator, perform data anomaly processing on the first data table to obtain a second data table and each abnormal transaction; including: when the transaction indicator is a transaction count value, determining whether each transaction is continuous based on the transaction count value of each transaction; if not, determining each non-continuous position in the first data table; obtaining the non-continuity type corresponding to each non-continuity position, and determining the abnormal transaction corresponding to each non-continuity position based on the non-continuity type; updating the first data table based on the abnormal transactions to obtain a second data table; the second data table does not include the abnormal transactions. The reconstruction module is used to reconstruct the second data table and each abnormal transaction in a two-dimensional space to obtain a chain diagram corresponding to the target user. This includes: obtaining the transaction sequence value and transaction time point of each abnormal transaction and each transaction in the second data table; establishing a two-dimensional coordinate system with the transaction sequence value as the vertical axis and the transaction time point as the horizontal axis; determining the coordinate points corresponding to the first transaction and the last transaction in the second data table from the two-dimensional coordinate system; connecting the coordinate points corresponding to the first transaction and the last transaction with a straight line to form a chain; and simultaneously plotting each abnormal transaction in the two-dimensional coordinate system to obtain the chain diagram. The data restoration module is used to restore the chain graph to recover abnormal transaction data.

7. A device for recovering abnormal transaction data, characterized in that, Including memory and processor; The memory is used to store programs; The processor is configured to execute the program to implement each step of the abnormal transaction data recovery method as described in any one of claims 1-5.

8. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method for recovering abnormal transaction data as described in any one of claims 1-5.