Methods, devices, electronic equipment and storage media for identifying anomalies in business approval

By constructing a feature matrix and anomaly detection model for business approval processes, abnormal behavior of multiple accounts jointly circumventing the separation of duties is identified, solving the problem that existing technologies cannot detect multiple accounts jointly circumventing the separation of duties, and achieving efficient abnormal approval identification and information security assurance.

CN116451157BActive Publication Date: 2025-10-31CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210010112.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-06
Publication Date
2025-10-31
Estimated Expiration
2042-01-06

AI Technical Summary

Technical Problem

Existing office systems are unable to effectively detect abnormal behavior in which multiple accounts collude to circumvent separation of duties controls and audits. Furthermore, existing models involve large computational loads and cannot share data from different scenarios, resulting in a lack of supervision over business approval processes and potential information security risks.

Method used

By acquiring multiple audit combinations in the business approval process, a first feature matrix at the business approver level and a second feature matrix at the joint level are constructed. A first anomaly detection model is built using local anomaly factors and isolated forest anomaly detection algorithms. Combined with a multi-level logistic regression model, abnormal application approval combinations are identified, reducing computational load and improving accuracy.

Benefits of technology

It enables the effective identification of abnormal behaviors by multiple accounts jointly circumventing the separation of duties control, reduces the amount of computation, improves the accuracy of approval relationships and the applicability of the model, and enhances information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116451157B_ABST
    Figure CN116451157B_ABST
Patent Text Reader

Abstract

To address the issue of multiple accounts jointly circumventing separation of duties control, this invention provides a method, apparatus, electronic device, and storage medium for anomaly identification in business approval processes. The method includes: acquiring multiple audit combinations from the system to be identified within a set time period; obtaining a first feature matrix at the business approver level and a second feature matrix at the joint level based on each first audit indicator and each second audit indicator in the multiple audit combinations; constructing a first anomaly detection model based on each first mapping pair in the first feature matrix; constructing a second anomaly detection model based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver; and identifying whether the second feature matrix contains anomaly application approval combinations based on the second anomaly detection model. The anomaly identification method provided by this invention can solve the problem of multiple accounts jointly circumventing separation of duties control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to an anomaly identification method, apparatus, electronic device, and storage medium for business approval. Background Technology

[0002] With the development of information technology, various office systems have been gradually improved, greatly facilitating people's work and improving work efficiency. To ensure information security and standardize the supervision and approval mechanisms in business approval processes, the construction of office systems often requires the separation of duties. For example, a business approval process may require two or more handlers; the applicant cannot be their own approver (reviewer); and lower-level employees cannot act as approvers for higher-level employees. Current office system construction and auditing processes mainly achieve the separation of roles or permissions for the same account, avoiding incompatible roles or permissions that could lead to non-standard operations or a lack of supervision in business approval processes. In other words, current proposals for separation of duties control and auditing primarily focus on pre-emptive control or post-event auditing of individual user roles and permissions. Summary of the Invention

[0003] In view of this, embodiments of the present invention provide a method, apparatus, electronic device and storage medium for identifying anomalies in business approval, which can detect multiple accounts jointly circumventing the separation of duties control, thereby avoiding abnormal approval behavior by multiple accounts.

[0004] To achieve the above objectives, the technical solution of the present invention is implemented as follows:

[0005] On one hand, embodiments of the present invention provide an anomaly identification method for business approval, the anomaly identification method comprising:

[0006] Obtain multiple audit combinations from the system to be identified within a set time period; each audit combination includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver;

[0007] Based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations, a first feature matrix at the business approver level and a second feature matrix at the joint level are obtained; the joint level is the level at which the business applicant and the business approver are combined; the first feature matrix includes each first mapping pair; the first mapping pair is composed of the business approver and the corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes each second mapping pair; the second mapping pair is composed of the business application approval combination and the corresponding second behavioral indicator in the multiple audit combinations.

[0008] A first anomaly detection model is constructed based on each first mapping pair in the first feature matrix;

[0009] When the first business approver contained in the first feature matrix is ​​identified as an abnormal business approver based on the first anomaly detection model, a second anomaly detection model is constructed based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver.

[0010] The second anomaly detection model is used to identify whether the second feature matrix contains anomaly application approval combinations.

[0011] On the other hand, embodiments of the present invention provide an anomaly identification device for business approval, the anomaly identification device comprising: an acquisition unit, a obtaining unit, a first construction unit, a second construction unit, and an identification unit, wherein;

[0012] The acquisition unit is used to acquire multiple audit combinations of the system to be identified within a set time period; each audit combination includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver;

[0013] The obtaining unit is configured to obtain a first feature matrix at the business approver level and a second feature matrix at the joint level based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations; the joint level is the level at which the business applicant and the business approver are combined; the first feature matrix includes each first mapping pair; the first mapping pair is composed of the business approver and the corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes each second mapping pair; the second mapping pair is composed of the business application approval combination and the corresponding second behavioral indicator in the multiple audit combinations.

[0014] The first construction unit is used to construct a first anomaly detection model based on each first mapping pair in the first feature matrix;

[0015] The second construction unit is used to construct a second anomaly detection model based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver when the first business approver in the first feature matrix is ​​identified as an abnormal business approver based on the first anomaly detection model.

[0016] The identification unit is used to identify whether the second feature matrix contains an abnormal application approval combination based on the second anomaly detection model.

[0017] Thirdly, embodiments of the present invention also provide a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of any of the methods described above.

[0018] Fourthly, embodiments of the present invention also provide an electronic device, the electronic device comprising: a processor and a memory for storing a computer program capable of running on the processor, wherein, when the processor is used to run the computer program, it performs the steps of any of the methods described above.

[0019] This invention provides a method, apparatus, electronic device, and storage medium for identifying anomalies in business approval processes. The anomaly identification method includes: acquiring multiple audit combinations of a system to be identified within a set time period; each audit combination includes a first audit indicator related to a business applicant and a second audit indicator related to a business approver; obtaining a first feature matrix at the business approver level and a second feature matrix at a joint level based on each of the first and second audit indicators in the multiple audit combinations; the joint level being the level combining the business applicant and the business approver; the first feature matrix includes first mapping pairs; each first mapping pair consists of a business approver and a corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes second mapping pairs, each second mapping pair consists of a business application approval combination and a corresponding second behavioral indicator in the multiple audit combinations; constructing a first anomaly detection model based on each of the first mapping pairs in the first feature matrix; when the first anomaly detection model identifies a first business approver included in the first feature matrix as an abnormal business approver, constructing a second anomaly detection model based on each of the second mapping pairs in the second feature matrix and the first mapping pair corresponding to the first business approver; and identifying whether the second feature matrix contains an abnormal application approval combination based on the second anomaly detection model. The business approval anomaly identification method and apparatus provided in this invention obtains a first feature matrix at the business approver level and a second feature matrix at the joint level in the audit portfolio, and constructs a first anomaly detection model and a second anomaly detection model, thereby enabling the detection of multiple accounts jointly circumventing the separation of duties control, and thus avoiding abnormal approval behavior of multiple accounts jointly. Attached Figure Description

[0020] Figure 1 A schematic diagram of a business approval process for an anomaly identification method in business approval provided by an embodiment of the present invention. Figure 1 ;

[0021] Figure 2 A schematic diagram of a business approval process for an anomaly identification method in business approval provided by an embodiment of the present invention. Figure 2 ;

[0022] Figure 3 A schematic diagram of the structure of an anomaly identification device for business approval provided in an embodiment of the present invention;

[0023] Figure 4This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the specific technical solutions of the invention will be further described in detail below with reference to the accompanying drawings of the embodiments of the present invention. The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the present invention.

[0025] Currently, with the development of information technology, various office systems have been gradually improved, greatly facilitating people's work and improving work efficiency. To ensure information security and standardize the supervision and approval mechanisms in business approval processes, the construction of information systems often requires the separation of duties. For example, a business approval process may require two or more handlers; the applicant cannot be their own approver (reviewer); and lower-level employees cannot act as approvers for higher-level employees. Existing system construction and auditing processes primarily achieve the separation of roles or permissions for the same account, avoiding the possibility of the same account having incompatible roles or permissions, which could lead to non-standard operations or a lack of supervision in business approval processes.

[0026] However, current proposals for separation of duties control and auditing mainly focus on pre-emptive control or post-emptive auditing of individual user roles and permissions. For example, patent application CN201811376825.8, "Dynamic Access Control Method for Internal Attacks," discloses a dynamic access control framework for internal attacks, belonging to the field of information security access control technology. This framework includes: submitting access requests; calculating user-enabled roles; calculating role-enabled permissions; selecting enabled roles; reducing candidate enabled roles; calculating risk values; using an environment model to assess the satisfiability of environmental constraints in the access control policy; dynamically adjusting user permissions to prevent unauthorized access; and then, based on policy constraints and risk analysis, restricting the scope of permissions for legitimate users to avoid internal attacks by malicious users. This invention achieves triple control over access requests by analyzing environmental information, policy constraints, and access risks, enabling timely prevention of illegal and malicious access behaviors, more effectively protecting network resources, and ensuring the safe and efficient operation of the system. For example, the patent application CN201910971219.9, entitled "A Method and System for Auditing User Account Abuse Based on Network Security Device Log Data," provides a method and system for auditing user account abuse based on network security device log data. The steps are: 1) extracting features from data such as network security device user logs; 2) preprocessing and analyzing the features to obtain the relationships between features and between features and user behavior; 3) constructing a classifier model based on the One Class Support Vector Machine (OCSVM) algorithm according to the user features; 4) judging user behavior features according to the classifier model to discover whether there is a risk of user account abuse. The user account abuse auditing method and system disclosed in this patent based on network security device log data has a simple structure and low computational complexity, which can effectively reduce the computational resource overhead of behavior analysis in user logs. It only requires data automatically recorded by network security devices, which has the advantage of practical application. It provides a modeling analysis method for user personal account behavior features and makes a decision-making judgment on whether there is a risk of user account abuse.

[0027] Based on the two patents mentioned above, it can be seen that existing auditing methods have the following drawbacks:

[0028] 1. Existing technologies mainly target the separation of duties for the same account's roles or permissions for system control. Post-event audits also start from the behavioral characteristics of a single user and cannot detect behaviors that use multiple accounts to circumvent the separation of duties control.

[0029] 2. Without combining business approval process data, relying solely on log data results in a large computational load during the feature extraction stage, which can only be achieved by relying on a big data environment.

[0030] 3. Existing anomaly audit models do not build differentiated models for the different positions or roles of each account; or they directly build models for accounts with different responsibilities or positions in different scenarios. Although this improves the accuracy of the models, the development and maintenance workload of building customized models is large, and data from different scenarios cannot be shared.

[0031] To address the aforementioned issues, it has been found that effectively identifying, through technical means, abnormal behaviors in the business approval process of information systems, where the same individual uses two or more accounts with incompatible permissions to circumvent separation of duties controls, is crucial for standardizing business approval processes and ensuring information security. Therefore, this invention proposes a method and apparatus for auditing and detecting multiple accounts jointly circumventing separation of duties controls by combining business approval process data and business operation logs. Based on this, this invention proposes an anomaly identification method for business approvals. This method combines business data and log data to analyze the behavioral characteristics of different accounts upstream and downstream in the same business approval process, and audits to detect abnormal behaviors of two or more accounts jointly circumventing separation of duties controls. First, by exploring the behavioral characteristics between accounts with approval relationships, auditing and detecting abnormal behaviors of multiple accounts jointly circumventing separation of duties can identify violations by business approvers outside the system's control scope who do not strictly perform their duties according to management regulations. Second, by mining the approval relationships between accounts based on business data, the computational load is reduced and the accuracy of approval relationships is improved. Finally, for different business approvers, a multi-level Logistic Regression model is constructed for differentiated behavioral auditing, which is more targeted, improves the accuracy of results, and reduces the workload of building customized audit models for different scenarios.

[0032] The abnormal business approval method provided by the embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0033] like Figure 1 As shown, this diagram illustrates a business approval process using an anomaly identification method for business approval provided by an embodiment of the present invention. Figure 1 The anomaly identification method may include the following steps:

[0034] S101: Obtain multiple audit combinations of the system to be identified within a set time period; each audit combination includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver.

[0035] It should be noted that the system to be identified here can be various office systems. The set time can be set to within one month, one day, one week, etc., depending on the actual situation.

[0036] In some embodiments, obtaining multiple audit combinations of the system to be identified within a set time period may include:

[0037] The first key basic information within the set time period is obtained from the business database of the system to be identified; the first key basic information is related to the business approval process.

[0038] The second key basic information within the set time period is obtained from the log database of the system to be identified; the second key basic information is also related to the business approval process.

[0039] Based on the first key basic information and the second key basic information, multiple audit combinations of the system to be identified are obtained within the set time period.

[0040] It should be noted that the business database stores each business approval process. The business approval process is stored in the business database using data such as a business approval process identifier ID, the applicant account, the approver account, the application time, and the approval time for each approval stage. Based on this, in some embodiments, obtaining the first key basic information within the set time period from the business database of the system to be identified may include: using the business approval process identifier ID as the primary key, extracting the first key basic information starting from the time-based business approval process. This first key basic information includes, but is not limited to, the business approval process identifier ID, processing time, and processing account. The processing time includes the application time corresponding to the applicant account and the approval time corresponding to the approver account; the processing account includes both the applicant account and the approver account.

[0041] For example, in a complete business approval process from the issuance of a bill of lading to its termination, the steps include: A->B->C. A completes the application for a bill of lading; B first approves A's operation in step 1 and submits the approval process to C; C further reviews the application based on step 1 and performs step 2 approval, at which point the approval process ends. This business approval process includes two steps. Therefore, the first key information extracted from this business approval process can include: the business approval process identifier ID1, the applicant (A) in step 1, the approver (B) in step 1, the application time (i.e., A's processing time) in step 1, and the approval time (i.e., B's processing time) in step 1; and the business approval process ID1, the applicant (B) in step 2, the approver (C) in step 2, the application time (i.e., B's processing time) in step 2, and the approval time (i.e., C's processing time) in step 2. It should be noted that for a business approval process that includes multiple approval stages, each stage includes both a business applicant and a business approver. In other words, for a business approval process that includes multiple approval stages, the business applicant in some stages may be the business approver in other stages. That is to say, whether someone is a business applicant or a business approver depends on their role in that particular approval stage.

[0042] In some embodiments, obtaining the second key basic information within the set time period from the log database of the system to be identified may include: obtaining the second key basic information from the log database using the set time as a filtering condition. The second key basic information includes, but is not limited to, operation account, operation time, IP address, and operation business approval process ID. The operation account includes the business approver account and the business applicant account; the operation time is synonymous with the aforementioned processing time, only with different names in different databases. The operation business approval process ID is also the aforementioned business approval process identifier ID, only with different names in different databases.

[0043] In some embodiments, obtaining multiple audit combinations of the system to be identified within a set time period based on the first key basic information and the second key basic information includes:

[0044] The first key basic information includes one or more business application approval combinations; each business application approval combination represents an application approval relationship, which may include: business approval process identifier, business applicant account, business application time, business approver account, and business approval time;

[0045] Based on the second key basic information, the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account are determined for each of the business application approval combinations;

[0046] Based on each of the business application approval combinations and the business application address and business approval address corresponding to each of the business application approval combinations, multiple audit combinations of the system to be identified are obtained within the set time period;

[0047] Each of the multiple audit portfolios includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver; the first audit indicator includes the business applicant's account, business application time, and business application address; the second audit indicator includes the business approver's account, business approval time, and business approval address.

[0048] It should be noted that determining the one or more business application approval combinations included in the first key basic information means analyzing the application approval relationship from each business approval process. For example, in a business approval process from the submission of a bill of lading to the termination of the business approval process, the approval path of this business approval process is A->B->C. That is, A completes the application bill of lading, B first approves A's operation in step 1 and then submits the business approval process to C. C further reviews and approves in step 2 based on step 1, and the business approval process ends. Two application approval combinations can be extracted from this business approval process, namely: [Business approval process ID, step 1 business applicant (A), step 1 business approver (B), step 1 application time (i.e., A's processing time), step 1 approval time (i.e., B's processing time)], [Business approval process ID, step 2 business applicant (B), step 2 business approver (C), step 2 application time (i.e., B's processing time), step 2 approval time (i.e., C's processing time)].

[0049] After obtaining the business application approval combination included in each business approval process, the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account are determined for each business application approval combination based on the second key basic information. In some embodiments, the step of determining the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account for each business application approval combination based on the second key basic information may include: using the business approval process identifier, the business applicant account, the business application time, the business approver account, and the business approval time as keywords to associate them in the second key basic information, so as to obtain the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account in each application approval combination.

[0050] That is, using the business approval process ID, the account logged into the system to be identified, and the business processing time as the primary keys, the log database is backfilled to form the application IP address and approval IP address in each application approval relationship corresponding to the business approval process ID. Finally, based on each business application approval combination and the business application address and business approval address corresponding to each application approval combination, multiple audit combinations of the system to be identified within the set time period are obtained. Each audit combination includes: business applicant, business approver, business application time, business approval time, business application address (e.g., the IP address of the business applicant account logging into the system to be identified), and business approval address (e.g., the IP address of the business approver logging into the system to be identified), as shown in Table 1 below:

[0051] Table 1 Data Structure Table of Audit Portfolio

[0052]

[0053]

[0054] S102: Based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations, obtain a first feature matrix at the business approver level and a second feature matrix at the joint level; the joint level is the level at which the business applicant and the business approver are combined; the first feature matrix includes each first mapping pair; the first mapping pair is composed of the business approver and the corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes each second mapping pair, the second mapping pair is composed of the business application approval combination and the corresponding second behavioral indicator in the multiple audit combinations.

[0055] In some embodiments, obtaining a first feature matrix at the business approver level and a second feature matrix at the joint level based on each of the first audit indicators and each of the second audit indicators in the plurality of audit combinations may include:

[0056] Based on the first audit indicator and the second audit indicator in the same audit group among the multiple audit groups, determine the time interval between the business application time and the business approval time in the same audit group; and determine the address similarity between the business application address and the business approval address in the same audit group;

[0057] Determine the time interval and the address similarity for each of the same audit portfolios among the plurality of audit portfolios;

[0058] A first feature matrix for the business approver level is obtained based on each of the time intervals, each of the address similarities, and the combination of one or more business application approvals.

[0059] The first feature matrix is ​​a two-dimensional matrix composed of each first mapping pair, wherein the first dimension of the first mapping pair represents the business approver; and the second dimension of the first mapping pair represents the first behavioral indicator.

[0060] In some embodiments, obtaining a joint-level second feature matrix based on each of the first audit metrics and each of the second audit metrics in the plurality of audit portfolios may include:

[0061] Based on the first audit indicator and the second audit indicator in the same audit group among the multiple audit groups, determine the time interval between the business application time and the business approval time in the same audit group; and determine the address similarity between the business application address and the business approval address in the same audit group;

[0062] Determine the time interval and the address similarity for each of the same audit portfolios among the plurality of audit portfolios;

[0063] The second feature matrix of the joint hierarchy is obtained based on each of the time intervals and each of the address similarities.

[0064] The second feature matrix is ​​a three-dimensional matrix composed of each second mapping pair; the first dimension of the second mapping pair represents the business approver; the second dimension of the second mapping pair represents the business applicant; and the third dimension of the second mapping pair represents the second behavioral indicator.

[0065] What is being expressed here is that, based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations, a first feature matrix at the business approver level and a second feature matrix at the joint level are calculated. The specific calculation steps are as follows:

[0066] First, based on the data structure of Table 1 for each audit combination, calculate the interval t between the business approval time and the business application time in the k-th business approval process between business approver i and business applicant j. ijk This refers to the difference between the business approval time and the business application time, expressed in seconds; it is also a metric for determining whether the IP address used for the business application is the same as the IP address used for the business approval.

[0067] If business approver i completes n business approvals for business applicant j within the set time period, then a time interval sequence t between business approver i and business applicant j is formed.ij =[t ij1 , ij2 ,…, ijn IP address similarity index sequence r ij =[r ij1 ,r ij2 ,…,r ijn .

[0068] Based on the foregoing calculations, the calculation of the second feature matrix at the joint level can include: based on the time interval sequence t of the aforementioned business applicant, business approver, and business approval process. ij IP address similarity index sequence r ij Calculate the average time interval x between the combination of business approver i and business applicant j. ij1 Standard deviation of time interval x ij2 IP address similarity x ij3 =∑rijk / n. The parameters for the aforementioned calculation are the second behavioral indicators of this joint level. After the calculation of these second behavioral indicators, for each business approver, there is a set of business applicants. The number of elements in each set is the number of business applicants. Each business applicant-business approver combination has 3 second behavioral indicators. This ultimately forms a 3-dimensional feature matrix X, also known as the second feature matrix. The first dimension represents the business approver, the second dimension represents the business applicant, and the third dimension represents the specific indicator. The specific indicator is the second behavioral indicator corresponding to each business application-approval combination, which is the aforementioned IP address similarity, average time interval, and standard deviation of time interval. The business applicant, business approver, and corresponding second behavioral indicator form a second mapping pair. The second feature matrix contains each second mapping pair.

[0069] For the calculation of the first feature matrix at the business approver level, on the one hand, it is directly based on each second mapping pair in the second feature matrix of the business applicant-business approver combination level (joint level), and aggregated with the business approver as the main body to obtain the average time interval y of the business approver. i1 Standard deviation of time interval y i2 Average IP address similarity y i3 IP address similarity standard deviation y i4 On the other hand, based on the aforementioned multiple audit portfolios, the average daily online hours y for each business approver are calculated. i5 Number of IP addresses used (y) i6 Number of business applicants y i7 .

[0070] Wherein, the average time interval y i1The average time interval [x] for all combinations of business applicants within the authority of the i-th business approver. i11 x i21 , ..., x in1 The average value; the standard deviation of the time interval y. i2 The average time interval [x] for all combinations of business applicants within the authority of the i-th business approver. i11 x i21 , ..., x in1 The standard deviation of the average IP address similarity is y. i3 The IP address similarity [x] between the business applicants corresponding to the i-th business approver. i13 x i23 , ..., x in3 The average value of IP address similarity; standard deviation of IP address similarity y i4 The IP address similarity [x] between the business applicants corresponding to the i-th business approver. i13 x i23 , ..., x in3 The standard deviation of ].

[0071] Daily average online hours data y i5 The average number of non-repeating hours per day for business approval processes within the i-th business approver's cycle; the number of IP addresses used, y. i6 y represents the number of unique IP addresses used by the i-th business approver within the business cycle; y represents the number of business applicants. i7 Let represent the number of business applicants corresponding to the i-th business approver.

[0072] This ultimately results in a 2D feature matrix Y, also known as the first feature matrix. The first dimension represents the business approver, and the second dimension represents the specific indicators for that level. These specific indicators can refer to the first behavioral indicator corresponding to each business approver; the first behavioral indicator includes the aforementioned average time interval y for the business approvers. i1 Standard deviation of time interval y i2 Average IP address similarity y i3 IP address similarity standard deviation y i4 ; and the average daily online hours of business approvers y i5 Number of IP addresses used (y) i6 Number of business applicants y i7 .

[0073] It should be noted that the calculation of the first feature matrix at the business approver level and the second feature matrix at the joint level can be performed simultaneously or separately. In other words, the statement that the calculation of the first feature matrix at the business approver level is related to the second feature matrix at the joint level is only for the purpose of saving calculation time. In fact, the two can be calculated separately.

[0074] S103: Construct a first anomaly detection model based on each of the first mapping pairs in the first feature matrix.

[0075] It should be noted that, based on the foregoing description, each first mapping pair can be a coordinate system consisting of the business approver and its corresponding first feature row. Thus, in some embodiments, constructing a first anomaly detection model based on each first mapping pair in the first feature matrix may include:

[0076] The first anomaly detection model is constructed based on each of the first mapping pairs using a specific testing algorithm, wherein the specific testing algorithm is local anomaly factor anomaly detection and / or isolated forest anomaly detection.

[0077] It should be noted that the description here refers to the construction of the first anomaly detection model using commonly used anomaly detection algorithms such as Local Outlier Factor (LOF) anomaly detection and / or Isolation Forest (iForest) anomaly detection.

[0078] After obtaining the first anomaly detection model, in some embodiments, the method further includes: when the second business approver contained in the first feature matrix is ​​identified as a normal business approver based on the first anomaly detection model, the business approval process is terminated.

[0079] In other words, based on the first anomaly detection model, it is determined whether the first behavioral indicator corresponding to the business approver in the first feature matrix is ​​abnormal. If there is no anomaly, the business approver is determined to be a normal business approver, and the account they possess is also a normal approval account. If there is an anomaly, the business approver is determined to be an abnormal business approver, and the account they possess is also an abnormal approval account. That is, if the first anomaly detection model identifies the business approver as not an abnormal behavior subject, then the approval account is identified as normal, and the business approval process ends; if the first anomaly detection model identifies the business approver as an abnormal behavior subject, then a multi-level Logistic regression model is constructed by combining partial data from the first feature matrix at the business approver level and data from the second feature matrix at the business applicant business approver combination level (joint level) to further identify whether each business applicant business approver combination belongs to an abnormal combination.

[0080] S104: When the first business approver contained in the first feature matrix is ​​identified as an abnormal business approver based on the first anomaly detection model, a second anomaly detection model is constructed based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver.

[0081] S105: Based on the second anomaly detection model, identify whether the second feature matrix contains anomaly application approval combinations.

[0082] In some embodiments, the second anomaly detection model is a multilevel logistic regression model, wherein the first layer of the multilevel logistic regression model is constructed based on each of the second mapping pairs; the second layer of the multilevel logistic regression model is constructed based on the first mapping pair corresponding to the first business approver; and the first layer is influenced by the second layer.

[0083] In some embodiments, the method further includes:

[0084] When the second feature matrix contains abnormal application approval combinations, the abnormal application approval combinations and normal application approval combinations contained in the second feature matrix are obtained;

[0085] The abnormal type corresponding to the first business approver is identified based on the abnormal application approval combination, the normal application approval combination, and the first mapping pair corresponding to the first business approver.

[0086] It should be noted that the Logistic regression model is mainly applied to data with a hierarchical structure, such as the first behavioral indicator at the level of business approvers and the second behavioral indicator at the level of business applicant-business approver combinations. The results at the lower level (whether there is abnormal behavior in each business applicant-business approver combination) are affected by the indicators at the higher level (behavioral characteristics of different business approvers, such as online hours and total number of IP addresses) and the lower level (behavioral characteristics of each business applicant-business approver combination). Furthermore, different business applicant-business approver combinations belong to different business approvers.

[0087] This multilevel logistic regression model incorporates variable information and random errors at different levels, improving the model's accuracy.

[0088] The settings for the multilevel logistic regression model are as follows:

[0089] First-level formula:

[0090] Where pij represents the probability that the actions of the i-th business approver and the j-th business applicant under their authority constitute a joint attempt to circumvent separation of duties, and x ij1 x is the first behavioral characteristic of the combination of business applicant i and business approver j—the average time interval. ij2 The second behavioral characteristic of the combination of business applicant i and business approver j—the standard deviation of the time interval, x ij3 The third behavioral characteristic of the combination of business applicant i and business approver j is IP address similarity. These three characteristics are all low-level indicators.

[0091] Second-level formula:

[0092] β 0i =γ 00 +γ 01 y i5 +γ 02 y i6 +γ 03 y i7 +μ 0i (2)

[0093] β 1i =γ 10 +γ 11 y i5 +γ 12 y i6 +γ 13 y i7 +μ 1i (3)

[0094] β 2i =γ 20 +γ 21 y i5 +γ 22 y i6 +γ 23 y i7 +μ 2i (4)

[0095] β 3i =γ 30 +γ 31 y i5 +γ 32 y i6 +γ 33 y i7 +μ 3i (5)

[0096] Where y i5 (Average daily online hours of business approver i), y i6 (Number of IP addresses used by business approver i), y i7(The number of business applicants under the authority of business approver i) is a high-level variable with unit i.

[0097] In a multilevel logistic regression model, the traditional fixed intercept and fixed slope of the first level are replaced with random intercepts and random slopes of the first level. Corresponding to the random coefficients of the first level are several second-level equations, in which the random regression coefficients of the first level become the dependent variable.

[0098] Here, the multilevel logistic regression model is estimated in two steps: First, the first-level regression operation is performed in each lower-level observation unit (i.e., the combination of business applicant and business approver). That is, the same regression model (Formula 1) is run n times for n business approvers, generating n sets of regression coefficients, forming n datasets of first-level intercepts and slopes. Second, the first-level random regression coefficients are treated as higher-level variables (y...). i5 y i6 y i7 The function of ) generates a second-level equation or macroscopic model (Formulas 2-5). The application of this multi-level logistic regression model replaces the fixed effects model in the conventional logistic regression with a random effects model, and the fitting results show that the behavioral characteristics of each business approver have different impacts on abnormal results. This process takes into account the differences in the actual situation of each business approver.

[0099] In this embodiment of the invention, after fitting with a multi-level Logistic regression model, each business applicant's business approver combination is identified as a normal combination (there is no behavior of jointly using multiple accounts to circumvent the separation of duties control) and an abnormal combination (there is behavior of jointly using multiple accounts to circumvent the separation of duties control).

[0100] Furthermore, after obtaining the abnormal application approval combinations and normal application approval combinations contained in the second feature matrix based on the multi-level logistic regression model, in some embodiments, the abnormal type corresponding to the first business approver is identified based on the abnormal application approval combinations, the normal application approval combinations, and the first mapping pair corresponding to the first business approver. Specifically, if a business approver has an abnormal combination with 50% or more of its business applicants, the final abnormal type of the account corresponding to the first approver is "approval account shared"; if a business approver has an abnormal combination with less than 50% of its business applicants, the final abnormal type of the account corresponding to the first approver is "approval account publicly disclosed to some business applicants"; if a business approver and all business applicants within its authority belong to a normal combination, the final type of the account corresponding to the first approver is "normal approval account".

[0101] In some embodiments, the anomaly identification method further includes: feeding back the anomaly combination to the anomaly business applicant business approver combination collection submodule, updating the tag library, enriching the model tag library, and continuously improving the accuracy of the audit model.

[0102] In some embodiments, the anomaly identification method further includes: determining a processing operation for the first business approver based on the anomaly type corresponding to the first business approver, wherein the processing operation includes at least one of the following: reminder, account lockout.

[0103] In other words, this describes the different handling methods for abnormal approval accounts detected by the audit model module, depending on the scenario. For all abnormal approval accounts (shared approval accounts, audit accounts disclosed to some business applicants), a notification message is sent to the owner of the business approver account, informing them that handing over the account to business applicants for self-approval is a violation, thus preventing subsequent related violations from the root (i.e., a reminder); if the abnormal type of the business approver account in the most recent period is shared approval account, then the business approver account is also locked, and the account cannot perform business approvals during the locking period (i.e., account lock).

[0104] In some embodiments, the anomaly identification method further includes:

[0105] Obtain multiple combinations of abnormal application approvals within the specified time period;

[0106] The cumulative number of times the same abnormal application approval combination is recorded;

[0107] When the number of times exceeds a set threshold, the business approval application of the applicant in the same abnormal application approval group is blocked until the business approver in the same abnormal application approval group submits the relevant materials that meet the requirements, and then the business approval for the applicant in the same abnormal application approval group continues.

[0108] This describes a scenario where, if the most recent anomaly of the approver's account is that the approval account has been publicly disclosed to some business applicants, and a specific account combination (i.e., the same abnormal application approval combination) has more than 3 anomaly flags within the last 10 periods (multiple set time periods) (one embodiment of a set threshold), then the business applications of applicants within that abnormal account combination will be blocked. The approver must provide relevant materials to unlock the blocking before the business approval process can continue. If the most recent anomaly of the approver's account is that the approval account has been publicly disclosed to some business applicants, and a specific account combination has less than or equal to 3 anomaly flags within the last six months, then the subsequent operations of that abnormal account combination will be closely monitored. If, during the subsequent application approval process of a discovered abnormal account combination, abnormal IP address similarity or time intervals occur, the approval operation of that approval account for the current business application of the applicant account within the account combination will be directly rejected from the system management level, technically preventing one person from using multiple accounts to circumvent the separation of duties.

[0109] The anomaly identification method for business approval provided in this embodiment of the invention obtains a first feature matrix at the level of business approvers and a second feature matrix at the level of collaboration in the audit portfolio, and constructs a first anomaly detection model and a second anomaly detection model, thereby enabling the detection of multiple accounts jointly circumventing the separation of duties control, and thus avoiding abnormal approval behavior of multiple accounts jointly.

[0110] To understand the present invention, as Figure 2 As shown, it illustrates a business approval process for another business audit anomaly identification method provided by an embodiment of the present invention. Figure 2 .

[0111] exist Figure 2 In this document, the anomaly identification method for business auditing is divided into the following modules: a data acquisition module, a feature calculation module, an audit model module, and an anomaly handling module. Specifically, the data acquisition module extracts key basic data from the business database and the operation log database; the feature calculation module integrates business approval process data and operation log data to calculate behavioral characteristics at two levels, specifically for the combination of business applicant and business approver, and for the two main entities, the business approver; the audit model module, based on the feature data generated by the feature calculation module, first constructs an anomaly detection model at the business approver level, and then further constructs a multi-level Logistic regression model for the low-level behavioral characteristics of the abnormal business approver, outputting the abnormal business applicant and business approver account combination; and the anomaly handling module primarily handles the discovered abnormal business approver accounts.

[0112] How do each module work? Specifically, the data acquisition module extracts key basic data information from both the business database and the log database. The key basic data information extracted from the business database includes, but is not limited to, business approval process ID, processing time, and processing account. Using the business approval process ID as a clue, it analyzes the approval relationships between accounts during each business approval process, extracting information such as the business approval process ID, applicant, approver, application time, and approval time. For example, in a business approval process from submitting a request for approval to its termination, the path is A->B->C. That is, A completes the application for a request for approval; B first approves A's operation at stage 1 and then submits the business approval process to C; C further reviews and approves at stage 2 based on stage 1, and the business approval process ends. In this business approval process, two application approval combinations can be extracted, namely: [Business Approval Process ID, Step 1 Business Applicant (A), Step 1 Business Approver (B), Step 1 Application Time (i.e., A's Processing Time), Step 1 Approval Time (i.e., B's Processing Time)], [Business Approval Process ID, Step 2 Business Applicant (B), Step 2 Business Approver (C), Step 2 Application Time (i.e., B's Processing Time), Step 2 Approval Time (i.e., C's Processing Time)].

[0113] Key information extracted from the log database includes, but is not limited to, the operation account, operation time, IP address, and operation business approval process ID.

[0114] Based on information from the business database and log database, the application IP address and approval IP address are generated for each application-approval relationship corresponding to the business approval process ID, using the business approval process ID, account, and time as the primary keys. The final output preprocessed data structure includes: business applicant, business approver, application time, approval time, application IP address, and approval IP address, as detailed in Table 1 above.

[0115] In summary, the data acquisition module first extracts application and approval relationships from the business database, and then associates them with relevant information in the log database. Compared with traditional log auditing, which explores application and approval relationships based on operation sequences from massive log data, this reduces the amount of computation and improves the accuracy of the approval relationship extraction results.

[0116] The main function of the feature calculation module is to calculate the first behavioral indicators of the business applicant's business approver combination level and the business approver level based on the output results of the data acquisition module, according to a specified period (the default is 1 month, which can be configured according to business needs, such as 1 day, 1 week, etc.).

[0117] First, based on the output results Table 1 of the data acquisition module, calculate the interval t between the approval time and the application time in the k-th business approval process between business approver i and business applicant j. ijk This refers to the difference between the approval time and the application time, expressed in seconds; it is a metric for determining whether the applied IP address and the approved IP address are the same.

[0118] If business approver i completes n business approvals for business applicant j within the set time period, then a time interval sequence t between business approver i and business applicant j is formed. ij =[t ij1 , t ij2 , ..., t ijn ] and IP address similarity index sequence r ij =[r ij1 r ij2 ,...,r ijn ].

[0119] 1. Calculation of the hierarchical characteristic matrix of the business applicant and business approver combination.

[0120] Based on the time interval sequence t of the above-mentioned business applicant, business approver, and business approval process. ij IP address similarity index sequence r ij Calculate the average time interval x between the combination of business approver i and business applicant j. ij1 Standard deviation of time interval x ij2 IP address similarity x ij3 =∑rijk / n.

[0121] After the feature calculation at this level is completed, for each business approver, there is a set of business applicants. The number of elements in each set is the number of business applicants. Each business applicant-business approver combination has 3 feature indicators. Finally, a 3-dimensional feature matrix X is formed, where the first dimension represents the business approver, the second dimension represents the business applicant, and the third dimension represents the specific indicator (i.e., the second behavior indicator).

[0122] 2. Calculation of the hierarchical feature matrix of business approvers

[0123] The characteristics of the business approver hierarchy are, on the one hand, directly based on the characteristics of the business applicant-business approver combination hierarchy, and on the other hand, aggregated with business approvers as the main body to obtain the average time interval y of business approvers. i1 Standard deviation of time interval y i2 Average IP address similarity y i3 IP address similarity standard deviation y i4On the other hand, based on the output of the data acquisition module, the average daily online hours y of each business approver are calculated. i5 Small number of IP addresses used y i6 Number of business applicants y i7 .

[0124] Wherein, the average time interval y i1 The average time interval [x] for all combinations of business applicants within the authority of the i-th business approver. i11 x i21 , ..., x in1 The average value; the standard deviation of the time interval y. i2 The average time interval [x] for all combinations of business applicants within the authority of the i-th business approver. i11 x i21 , ..., x in1 The standard deviation of the average IP address similarity is y. i3 The IP address similarity [x] between the business applicants corresponding to the i-th business approver. i13 x i23 , ..., x in3 The average value of IP address similarity; standard deviation of IP address similarity y i4 The IP address similarity [x] between the business applicants corresponding to the i-th business approver. i13 x i23 , ..., x in3 The standard deviation of ].

[0125] Daily average online hours data y i5 The average number of non-repeating hours per day for business approval processes within the i-th business approver's cycle; the number of IP addresses used, y. i6 y represents the number of unique IP addresses used by the i-th business approver within the business cycle; y represents the number of business applicants. i7 Let represent the number of business applicants corresponding to the i-th business approver.

[0126] The final result is a 2D feature matrix Y, where the first dimension represents the business approver and the second dimension represents the specific indicators at that level (i.e., the first behavior indicators).

[0127] The main function of the audit model module is to construct analytical models based on the indicators output by the feature calculation module, namely, the business approver level (high level) and the business applicant-business approver combination level (low level). Finally, it identifies abnormal business approver accounts and further classifies the abnormality into the following types: approval account sharing abnormality (i.e., the business approver discloses the approval account to 50% or more of the business applicants within its authority to complete the business approval themselves) and approval account disclosure abnormality (the approval account is delegated to less than 50% of the business applicants within its authority to complete the relevant business approval work on its behalf).

[0128] First, based on the feature matrix Y at the business approver level output by the feature calculation module, an anomaly detection model is constructed. This model explores the fusion of commonly used anomaly detection algorithms such as LOF and Iforest based on actual data, adjusting the weights and parameters of the fusion algorithm according to the actual data scenario. Based on the anomaly detection model, it determines whether the overall behavioral characteristics of the business approver are abnormal. If the anomaly detection model identifies the business approver as not being an abnormal entity, then the approval account is considered normal, and the business approval process ends. If the anomaly detection model identifies the business approver as being an abnormal entity, then a multi-level Logistic regression model is constructed by combining some features at the business approver level and the features at the business applicant's business approver combination level to identify whether each business applicant's business approver combination belongs to an abnormal combination.

[0129] Multilevel logistic regression models are mainly applied to data with hierarchical structures, such as the first behavioral indicator at the level of business approvers and the second behavioral indicator at the level of business applicant-business approver combinations output by the feature calculation module. The results at the lower level (whether there is abnormal behavior in each business applicant-business approver combination) are affected by the indicators at the higher level (behavioral characteristics of different business approvers, such as online hours and total number of IP addresses) and the lower level (behavioral characteristics of each business applicant-business approver combination). Furthermore, different business applicant-business approver combinations belong to different business approvers.

[0130] This multilevel logistic regression model incorporates variable information and random errors at different levels, improving the model's accuracy.

[0131] The specifications of the multilevel logistic regression model are as follows:

[0132] First-level formula:

[0133] Where pij represents the probability that the actions of the i-th business approver and the j-th business applicant under their authority constitute a joint attempt to circumvent separation of duties, and x ij1x is the first behavioral characteristic of the combination of business applicant i and business approver j—the average time interval. ij2 The second behavioral characteristic of the combination of business applicant i and business approver j—the standard deviation of the time interval, x ij3 The third behavioral characteristic of the combination of business applicant i and business approver j is IP address similarity. These three characteristics are all low-level indicators.

[0134] Second-level formula:

[0135] β 0i =γ 00 +γ 01 y i5 +γ 02 y i6 +y 03 y i7 +μ 0i (2)

[0136] β 1i =γ 10 +γ 11 y i5 +γ 12 y i6 +γ 13 y i7 +μ 1i (3)

[0137] β 2i =γ 20 +γ 21 y i5 +γ 22 y i6 +γ 23 y i7 +μ 2i (4)

[0138] β 3i =γ 30 +γ 31 y i5 +γ 32 y i6 +γ 33 y i7 +μ 3i (5)

[0139] Where y i5 (Average daily online hours of business approver i), y i6 (Number of IP addresses used by business approver i), y i7 (The number of business applicants under the authority of business approver i) is a high-level variable with unit i.

[0140] In a multilevel logistic regression model, the traditional fixed intercept and fixed slope of the first level are replaced with random intercepts and random slopes of the first level. Corresponding to the random coefficients of the first level are several second-level equations, in which the random regression coefficients of the first level become the dependent variable.

[0141] The multilevel logistic regression model is estimated in two steps: First, a first-level regression operation is performed for each lower-level observation unit (i.e., the combination of business applicant and business approver). That is, the same regression model (Formula 1) is run n times for n business approvers, generating n sets of regression coefficients, forming n datasets of first-level intercepts and slopes. Second, the first-level random regression coefficients are treated as higher-level variables (y...). i5 y i6 y i7 The function generates the second-level equation or macroscopic model (Formula 2-Formula 5).

[0142] The application of the multilevel logistic regression model replaces the fixed effects model in the conventional logistic regression with a random effects model. The fitting results show that the behavioral characteristics of each business approver have different impacts on abnormal results. This process takes into account the differences in the actual situation of each business approver.

[0143] By fitting the multi-level logistic regression model, each business applicant's business approver combination is identified as a normal combination (there is no behavior of jointly using multiple accounts to circumvent the separation of duties control) and an abnormal combination (there is behavior of jointly using multiple accounts to circumvent the separation of duties control). The abnormal combination is fed back to the abnormal business applicant's business approver combination collection submodule to update the tag library, enrich the model tag library, and continuously improve the accuracy of the audit model.

[0144] For the classification results of the multi-level logistic regression model over multiple periods, the cumulative number of anomaly identifications N for each abnormal account combination is calculated.

[0145] Furthermore, if a business approver has an abnormal combination with 50% or more of the business applicants, the final abnormal type of the approval account is shared approval account; if a business approver has an abnormal combination with less than 50% of the business applicants, the final abnormal type of the approval account is that the approval account is disclosed to some business applicants; if a business approver and all business applicants within their authority are in a normal combination, the final type of the approval account is a normal approval account.

[0146] The audit model module combines an anomaly detection model and a multi-level model to perform anomaly audits. First, the anomaly detection model determines whether there are anomalies in the behavioral characteristics of business approvers at the higher level. Based on this, a unified multi-level logistic regression model is constructed for each combination of applicant business approvers, and differentiated based on the high-level behavioral characteristics of the approvers within that combination. The fusion of the anomaly detection model and the multi-level logistic regression model reduces the overall computational load of the audit model while improving the accuracy of the results. It also outputs anomaly results at both the business approver and applicant business approver combination levels, enriching the levels of audit results.

[0147] The main function of the exception handling module is to handle abnormal approval accounts discovered by the audit model module in different ways depending on the scenario.

[0148] For all abnormal approval accounts (approval accounts shared, audit accounts disclosed to some business applicants), a notification message is sent to the owner of the business approver account to inform them that handing over the account to the business applicant for self-approval is a violation, so as to eliminate subsequent related violations from the root of the problem.

[0149] If the recent abnormality type of a business approver's account is "shared approval account", then the business approver's account will be locked, and the account will be unable to conduct business approvals during the lock period.

[0150] If the most recent abnormality type of the business approver's account is that the approval account has been disclosed to some business applicants, and the number of abnormal identifications of a specific account combination is greater than 3 in the past 10 periods, then the business applications of the business applicants in the abnormal account combination of the business approver will be blocked. Only after the business approver provides relevant materials to unlock the account can the business approval process continue for that applicant.

[0151] If the recent abnormality type of the business approver's account is that the approval account has been disclosed to some business applicants, and the number of abnormal identifications of a specific account combination in the past six months is less than or equal to 3, then the subsequent operations of the abnormal account combination will be closely monitored. If the IP address similarity or time interval abnormality occurs in the subsequent application approval process of the discovered abnormal account combination, the approval operation of the approval account for the application account in the account combination will be rejected directly from the system management level, so as to technically prevent the violation of one person using multiple accounts to circumvent the separation of duties.

[0152] In summary, the anomaly identification and approval process for this business review can combine the aforementioned modules to achieve the function of identifying and handling business issues arising from multiple accounts jointly circumventing the separation of duties control. Specifically:

[0153] First, the data collection model extracts basic data from the business database and log database within a certain period (default is 1 month, which can be configured according to business needs, such as 1 day, 1 week, etc.) (that is, within the set time period).

[0154] Then, based on the output of the data acquisition module, the feature calculation module is used to calculate the high-level and low-level behavioral indicators.

[0155] Next, based on the output of the feature calculation module, the audit model module is used to fit the high-level anomaly detection model and the multi-level Logistic classification model respectively, and output the abnormal account combinations.

[0156] Finally, based on the abnormal account combinations identified by the audit model module, the abnormal handling module is used to notify the business approvers, informing them that handing over accounts to business applicants for self-approval is a violation, thus preventing subsequent violations from the root. On the other hand, different handling methods are adopted according to different abnormal types of business approvers' accounts and the number of abnormal identifications of account combinations.

[0157] This invention extracts basic data from business databases and log databases, constructs behavioral feature models at the business applicant and business approver levels respectively, and then integrates them with an anomaly detection model and a multi-level logistic regression model to accurately identify violations of business processes by using multiple accounts to circumvent the separation of duties control. Finally, the anomaly handling model completes the closed-loop management of the model results.

[0158] Existing related patents primarily target the identification and control of incompatible permissions or unauthorized operations by a single account, failing to detect and control the use of multiple accounts to circumvent separation of duties controls, even if the actions appear compliant in form but are not in practice. Furthermore, the models developed for single-account permission and behavior control and auditing do not differentiate between account types or require customized models for different scenarios, increasing development and maintenance costs. In contrast, the technical advantages of this application are mainly reflected in the following aspects: 1. It proposes an auditing method and apparatus for identifying the use of multiple accounts to circumvent separation of duties controls, even if the actions appear compliant in form but are not in practice. 2. By combining business database mining of application approval relationships, it improves the accuracy and efficiency of approval relationship identification compared to conventional log anomaly auditing. 3. It constructs two levels of behavioral features and builds a multi-level Logistic regression model based on these features. This allows for the simultaneous use of all data to build differentiated audit models for different business approvers. It can also fit differentiated audit models based on high-level behavioral characteristics, making the models more targeted and improving the accuracy of audit results. 4. By integrating high-level anomaly detection models and multi-level classification models to audit abnormal behavior, the overall computational load of the audit model is reduced while further improving the accuracy of audit results. 5. Audit results are notified to the account owner. Simultaneously, different account application approval process blocking mechanisms are implemented based on different anomaly types and account combinations with varying numbers of anomalies by the business approver, achieving closed-loop management of audit results and a proactive mechanism to prevent abnormal behavior.

[0159] Based on the same inventive concept, such as Figure 3 As shown, this embodiment of the invention also provides an anomaly identification device for business approval. The anomaly identification device 30 includes: an acquisition unit 301, an obtaining unit 302, a first construction unit 303, a second construction unit 304, and an identification unit 305, wherein;

[0160] The acquisition unit 301 is used to acquire multiple audit combinations of the system to be identified within a set time period; each audit combination includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver;

[0161] The obtaining unit 302 is used to obtain a first feature matrix at the business approver level and a second feature matrix at the joint level based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations; the joint level is the level at which the business applicant and the business approver are combined; the first feature matrix includes each first mapping pair; the first mapping pair is composed of the business approver and the corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes each second mapping pair; the second mapping pair is composed of the business application approval combination and the corresponding second behavioral indicator in the multiple audit combinations.

[0162] The first construction unit 303 constructs a first anomaly detection model based on each first mapping pair in the first feature matrix;

[0163] The second construction unit 304 is used to construct a second anomaly detection model based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver when the first business approver in the first feature matrix is ​​identified as an abnormal business approver based on the first anomaly detection model.

[0164] The identification unit 305 is used to identify whether the second feature matrix contains an abnormal application approval combination based on the second anomaly detection model.

[0165] In some embodiments, the acquisition unit includes a first acquisition subunit, a second acquisition subunit, and a third acquisition subunit, wherein;

[0166] The first acquisition subunit is used to acquire first key basic information within a set time period from the business database of the system to be identified; the first key basic information is related to the business approval process;

[0167] The second acquisition subunit is used to acquire second key basic information within the set time period from the log database of the system to be identified; the second key basic information is also related to the business approval process;

[0168] The third acquisition subunit is used to acquire multiple audit combinations of the system to be identified within the set time period based on the first key basic information and the second key basic information.

[0169] In some embodiments, the third acquisition subunit is specifically configured to: determine one or more business application approval combinations included in the first key basic information; each business application approval combination represents an application approval relationship, including: business approval process identifier, business applicant account, business application time, business approver account, and business approval time; determine the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account for each business application approval combination based on the second key basic information; acquire multiple audit combinations of the system to be identified within the set time period based on each business application approval combination and the business application address and business approval address corresponding to each application approval combination; wherein, each audit combination in the multiple audit combinations includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver; the first audit indicator includes the business applicant account, business application time, and business application address; the second audit indicator includes the business approver account, business approval time, and business approval address.

[0170] The third acquisition unit is further specifically used to: associate the business approval process identifier, the business applicant account, the business application time, the business approver account, and the business approval time with the second key basic information to obtain the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account in each application approval combination.

[0171] In some embodiments, the obtaining unit is specifically configured to: determine the time interval between the business application time and the business approval time contained in the same audit group based on the first audit indicator and the second audit indicator in the same audit group among the plurality of audit groups; and determine the address similarity between the business application address and the business approval address contained in the same audit group; determine the time interval and the address similarity corresponding to each of the same audit groups among the plurality of audit groups; and obtain a first feature matrix of the business approver level based on each time interval, each address similarity and the one or more business application approval groups.

[0172] The obtaining unit is specifically used for: determining the time interval between the business application time and the business approval time contained in the same audit group based on the first audit indicator and the second audit indicator in the same audit group among the multiple audit groups; determining the address similarity between the business application address and the business approval address contained in the same audit group; determining the time interval and the address similarity corresponding to each of the same audit groups among the multiple audit groups; and obtaining the second feature matrix of the joint level based on each time interval and each address similarity.

[0173] In some embodiments, the first feature matrix is ​​a two-dimensional matrix composed of each first mapping pair, wherein the first dimension of the first mapping pair represents the business approver; and the second dimension of the first mapping pair represents the first behavioral indicator.

[0174] The second feature matrix is ​​a three-dimensional matrix composed of each second mapping pair; wherein, the first dimension of the second mapping pair represents the business approver; the second dimension of the second mapping pair represents the business applicant; and the third dimension of the second mapping pair represents the second behavioral indicator.

[0175] In some embodiments, the first construction unit is specifically used to: construct the first anomaly detection model based on each of the first mapping pairs using a specific testing algorithm, wherein the specific testing algorithm is local anomaly factor anomaly detection and / or isolated forest anomaly detection.

[0176] In some embodiments, the second anomaly detection model is a multilevel logistic regression model, wherein the first layer of the multilevel logistic regression model is constructed based on each of the second mapping pairs; the second layer of the multilevel logistic regression model is constructed based on the first mapping pair corresponding to the first business approver; and the first layer is influenced by the second layer.

[0177] In some embodiments, the anomaly identification device further includes: a termination unit, configured to identify the termination of the business approval process when the second business approver included in the first feature matrix is ​​identified as a normal business approver based on the first anomaly detection model.

[0178] In some embodiments, the anomaly identification device further includes: a classification unit, configured to, when the second feature matrix contains an abnormal application approval combination, obtain the abnormal application approval combination and the normal application approval combination contained in the second feature matrix; and identify the anomaly type corresponding to the first business approver based on the abnormal application approval combination, the normal application approval combination and the first mapping pair corresponding to the first business approver.

[0179] In some embodiments, the anomaly identification device further includes a determining unit, configured to determine a processing operation for the first business approver based on the anomaly type corresponding to the first business approver, wherein the processing operation includes at least one of the following: reminder, account lockout.

[0180] In some embodiments, the anomaly identification device further includes an accumulation unit for acquiring multiple combinations of the abnormal application approvals within the set time period;

[0181] The cumulative number of times the same abnormal application approval combination is recorded;

[0182] When the number of times exceeds a set threshold, the business approval application of the applicant in the same abnormal application approval group is blocked until the business approver in the same abnormal application approval group submits the relevant materials that meet the requirements, and then the business approval for the applicant in the same abnormal application approval group continues.

[0183] The anomaly identification device for business approval provided in this embodiment of the invention belongs to the same inventive concept as the aforementioned anomaly identification method. The aforementioned description of the anomaly identification method also applies here and will not be repeated here.

[0184] This invention also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the steps of the above-described method embodiments. The aforementioned readable storage medium includes various media capable of storing program code, such as mobile storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0185] This invention also provides an electronic device, comprising: a processor and a memory for storing a computer program capable of running on the processor, wherein when the processor runs the computer program, it executes the steps of the method embodiments described above stored in the memory.

[0186] Figure 4 This is a schematic diagram of a hardware structure of a message processing device according to an embodiment of the present invention. The electronic device 40 includes at least one processor 401 and a memory 402. Optionally, the electronic device 40 may further include at least one communication interface 403. The various components in the electronic device 40 are coupled together through a bus system 404. It can be understood that the bus system 404 is used to realize the connection and communication between these components. In addition to a data bus, the bus system 404 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in... Figure 4 The general designated all buses as Bus System 404.

[0187] It is understood that memory 402 can be volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); magnetic surface memory can be disk storage or magnetic tape storage. Volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memory 402 described in this embodiment of the invention is intended to include, but is not limited to, these and any other suitable types of memory.

[0188] In this embodiment of the invention, the memory 402 is used to store various types of data to support the operation of the electronic device 40. Examples of such data include: any computer program for operation on the electronic device 40, such as a process for obtaining a first feature matrix at the business approver level and a second feature matrix at the joint level based on each of the first audit indicators and each of the second audit indicators in the plurality of audit combinations, etc., and a program implementing the method of this embodiment of the invention may be included in the memory 402.

[0189] The methods disclosed in the above embodiments of the present invention can be applied to processor 401, or implemented by processor 401. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. A general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present invention can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in memory. The processor reads information from the memory and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0190] In an exemplary embodiment, the electronic device 40 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the methods described above.

[0191] In the several embodiments provided by this invention, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed may be through some interfaces, and the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms. The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units; some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs. In addition, all functional units in the various embodiments of this invention can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0192] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A method for anomaly identification in business approval, characterized in that, The anomaly detection method includes: Obtain multiple audit combinations from the system to be identified within a set time period; each audit combination includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver; Based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations, a first feature matrix at the business approver level and a second feature matrix at the joint level are obtained; the joint level is the level at which the business applicant and the business approver are combined; the first feature matrix includes each first mapping pair; the first mapping pair is composed of the business approver and the corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes each second mapping pair; the second mapping pair is composed of the business application approval combination and the corresponding second behavioral indicator in the multiple audit combinations. A first anomaly detection model is constructed based on each first mapping pair in the first feature matrix; When the first business approver contained in the first feature matrix is ​​identified as an abnormal business approver based on the first anomaly detection model, a second anomaly detection model is constructed based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver. The second anomaly detection model is used to identify whether the second feature matrix contains anomaly application approval combinations.

2. The anomaly identification method according to claim 1, characterized in that, The acquisition of multiple audit combinations of the system to be identified within a set time period includes: The first key basic information within the set time period is obtained from the business database of the system to be identified; the first key basic information is related to the business approval process. The second key basic information within the set time period is obtained from the log database of the system to be identified; the second key basic information is also related to the business approval process. Based on the first key basic information and the second key basic information, multiple audit combinations of the system to be identified are obtained within the set time period.

3. The anomaly identification method according to claim 2, characterized in that, The process of obtaining multiple audit combinations of the system to be identified within the set time period based on the first key basic information and the second key basic information includes: The first key basic information includes one or more business application approval combinations; each business application approval combination represents an application approval relationship, including: business approval process identifier, business applicant account, business application time, business approver account, and business approval time; Based on the second key basic information, the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account are determined for each of the business application approval combinations; Based on each of the business application approval combinations and the business application address and business approval address corresponding to each of the business application approval combinations, multiple audit combinations of the system to be identified are obtained within the set time period; Each of the multiple audit portfolios includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver; the first audit indicator includes the business applicant's account, business application time, and business application address; the second audit indicator includes the business approver's account, business approval time, and business approval address.

4. The anomaly identification method according to claim 3, characterized in that, The step of determining the business application address corresponding to the business applicant's account and the business approval address corresponding to the business approver's account for each business application approval combination based on the second key basic information includes: Using the business approval process identifier, the business applicant account, the business application time, the business approver account, and the business approval time as keywords, the second key basic information is associated to obtain the business application address corresponding to the business applicant account and the business approval address corresponding to the business approver account in each application approval combination.

5. The anomaly identification method according to claim 3, characterized in that, The method of obtaining a first feature matrix at the business approver level based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations includes: Based on the first audit indicator and the second audit indicator in the same audit group among the multiple audit groups, determine the time interval between the business application time and the business approval time in the same audit group; and determine the address similarity between the business application address and the business approval address in the same audit group; Determine the time interval and the address similarity for each of the same audit portfolios among the plurality of audit portfolios; A first feature matrix for the business approver level is obtained based on each of the time intervals, each of the address similarities, and the combination of one or more business application approvals.

6. The anomaly identification method according to claim 5, characterized in that, A second feature matrix at the joint level is obtained based on each of the first audit indicators and each of the second audit indicators in the multiple audit portfolios, including: Based on the first audit indicator and the second audit indicator in the same audit group among the multiple audit groups, determine the time interval between the business application time and the business approval time in the same audit group; and determine the address similarity between the business application address and the business approval address in the same audit group; Determine the time interval and the address similarity for each of the same audit portfolios among the plurality of audit portfolios; The second feature matrix of the joint hierarchy is obtained based on each of the time intervals and each of the address similarities.

7. The anomaly identification method according to claim 5, characterized in that, The first feature matrix is ​​a two-dimensional matrix composed of each first mapping pair, wherein the first dimension of the first mapping pair represents the business approver; and the second dimension of the first mapping pair represents the first behavioral indicator. The second feature matrix is ​​a three-dimensional matrix composed of each second mapping pair; wherein, the first dimension of the second mapping pair represents the business approver; the second dimension of the second mapping pair represents the business applicant; and the third dimension of the second mapping pair represents the second behavioral indicator.

8. The anomaly identification method according to claim 5, characterized in that, The construction of the first anomaly detection model based on each first mapping pair in the first feature matrix includes: The first anomaly detection model is constructed based on each of the first mapping pairs using a specific testing algorithm, wherein the specific testing algorithm is local anomaly factor anomaly detection and / or isolated forest anomaly detection.

9. The anomaly identification method according to claim 8, characterized in that, The second anomaly detection model is a multilevel logistic regression model, wherein the first layer of the multilevel logistic regression model is constructed based on each of the second mapping pairs; the second layer of the multilevel logistic regression model is constructed based on the first mapping pair corresponding to the first business approver; and the first layer is affected by the second layer.

10. The anomaly identification method according to claim 1, characterized in that, The method further includes: when the second business approver contained in the first feature matrix is ​​identified as a normal business approver based on the first anomaly detection model, the business approval process is terminated.

11. The method according to claim 1, characterized in that, The method further includes: When the second feature matrix contains abnormal application approval combinations, the abnormal application approval combinations and normal application approval combinations contained in the second feature matrix are obtained; The abnormal type corresponding to the first business approver is identified based on the abnormal application approval combination, the normal application approval combination, and the first mapping pair corresponding to the first business approver.

12. The anomaly identification method according to claim 11, characterized in that, The anomaly identification method further includes: determining the processing operation for the first business approver based on the anomaly type corresponding to the first business approver, wherein the processing operation includes at least one of the following: reminder, account lockout.

13. The anomaly identification method according to claim 12, characterized in that, The anomaly identification method further includes: Obtain multiple combinations of abnormal application approvals within the specified time period; The cumulative number of times the same abnormal application approval combination is recorded; When the number of times exceeds a set threshold, the business approval application of the applicant in the same abnormal application approval group is blocked until the business approver in the same abnormal application approval group submits the relevant materials that meet the requirements, and then the business approval for the applicant in the same abnormal application approval group continues.

14. An anomaly detection device for business approval, characterized in that, The anomaly identification device includes: an acquisition unit, a obtaining unit, a first construction unit, a second construction unit, and an identification unit, wherein; The acquisition unit is used to acquire multiple audit combinations of the system to be identified within a set time period; each audit combination includes a first audit indicator related to the business applicant and a second audit indicator related to the business approver; The obtaining unit is configured to obtain a first feature matrix at the business approver level and a second feature matrix at the joint level based on each of the first audit indicators and each of the second audit indicators in the multiple audit combinations; the joint level is the level at which the business applicant and the business approver are combined; the first feature matrix includes each first mapping pair; the first mapping pair is composed of the business approver and the corresponding first behavioral indicator in the multiple audit combinations; the second feature matrix includes each second mapping pair; the second mapping pair is composed of the business application approval combination and the corresponding second behavioral indicator in the multiple audit combinations. The first construction unit is used to construct a first anomaly detection model based on each first mapping pair in the first feature matrix; The second construction unit is used to construct a second anomaly detection model based on each second mapping pair in the second feature matrix and the first mapping pair corresponding to the first business approver when the first business approver in the first feature matrix is ​​identified as an abnormal business approver based on the first anomaly detection model. The identification unit is used to identify whether the second feature matrix contains an abnormal application approval combination based on the second anomaly detection model.

15. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 13.

16. An electronic device, characterized in that, The electronic device includes: a processor and a memory for storing a computer program capable of running on the processor, wherein, when the processor runs the computer program, it performs the steps of the method according to any one of claims 1 to 13.

Citation Information

Patent Citations

  • Dynamic access control methods for internal attacks

    CN109495474B

  • User account abuse auditing method and system based on log data of network security equipment

    CN110765087A

  • Multi-modal label recommendation model construction method and device of multi-level attention mechanism

    CN111461174A

  • Federal learning auditing device, system, and method

    CN113723623A