Business transaction detection method and device, electronic equipment and storage medium
By leveraging big data and artificial intelligence technologies, we have established business rule models and user profile models to automatically identify and handle business anomalies. This addresses the shortcomings of anomaly detection in IT management systems, enabling timely warnings and risk avoidance, and improving system reliability and user satisfaction.
Patent Information
- Application Number
- CN202311862194.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-29
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2043-12-29
AI Technical Summary
In existing technologies, after the IT management system architecture is cloudified and microservice-based, the business anomaly detection lacks automated identification and proactive early warning capabilities, making it difficult to detect anomalies in a timely manner. In particular, it is difficult to detect large expense issues through TOPN numbers and business sampling methods, which can easily lead to user complaints and revenue losses.
By employing big data and artificial intelligence technologies, and establishing abnormal business rule models and user profile models, the normal fluctuation range of business data is identified, abnormality judgment indicators are generated, and automated detection and processing of business data are achieved, generating alarm notifications to remind operation and maintenance personnel.
The system has been able to automatically and intelligently identify abnormal business data, thus preventing the risk of major business anomalies from escalating and revenue losses from occurring in a timely manner. This has improved the system's fault tolerance and reliability, and enhanced the user experience.
Smart Images

Figure CN118827323B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of big data, and in particular to a business abnormality detection method and device, electronic equipment and storage medium. BACKGROUND
[0002] With the development of business, various IT management system architectures are clouded and micro-serviced, the networking architecture is increasingly complex, the business calls between various subsystem modules are increasingly complex, and the probability of business exceptions is gradually increasing. For business operation support systems, currently, the business exception situation is mainly checked in reverse after user business complaints, and there is no automatic checking and active early warning capability for business exceptions. At the same time, for system account problems, the current main method is to check the business rationality and accuracy by using TOPN numbers and business sampling, but it is difficult to find large fee problems by using the above method. SUMMARY
[0003] The present application aims to at least solve one of the technical problems in the related art to some extent.
[0004] To this end, a first object of the present application is to provide a business abnormality detection method to realize automatic identification and processing of abnormal business.
[0005] A second object of the present application is to provide a business abnormality detection device.
[0006] A third object of the present application is to provide an electronic device.
[0007] A fourth object of the present application is to provide a computer-readable storage medium.
[0008] A fifth object of the present application is to provide a computer program product.
[0009] To achieve the above objects, a business abnormality detection method according to an embodiment of the first aspect of the present application comprises:
[0010] Obtaining business data of an abnormality business scenario;
[0011] Performing abnormality detection on the business data based on an abnormality data rule model of the abnormality business scenario to generate business abnormality data; wherein the abnormality data rule model comprises an abnormality judgment rule for sequentially judging the business data based on a plurality of judgment indexes; and the plurality of judgment indexes comprise an abnormality judgment index;
[0012] Performing abnormality business processing based on the business abnormality data.
[0013] In some implementations, the method for generating an index value of the abnormality judgment index comprises:
[0014] acquire historical business data of the abnormal transaction business scenario;
[0015] form a user business portrait model based on the historical business data;
[0016] identify a normal fluctuation range of business data of a user based on the user business portrait model;
[0017] determine an index value of the abnormal transaction determination index based on the normal fluctuation range of business data of the user.
[0018] In some implementations, the forming a user business portrait model based on the historical business data comprises:
[0019] performing data cleaning on the historical business data to obtain standard historical business data;
[0020] obtaining user feature data based on the standard historical business data;
[0021] forming a user business portrait model based on the user feature data.
[0022] In some implementations, the identifying a normal fluctuation range of business data of a user based on the user business portrait model comprises:
[0023] forming a user business historical data fluctuation curve based on the historical business data;
[0024] identifying a normal fluctuation range of business data of a user based on the user business historical data fluctuation curve and the user business portrait model.
[0025] In some implementations, after the determining an index value of the abnormal transaction determination index, the method further comprises:
[0026] adjusting the index value of the abnormal transaction determination index based on a preset rule to obtain an adjusted index value of the abnormal transaction determination index.
[0027] In some implementations, the performing abnormal transaction detection on the business data based on the abnormal transaction business scenario abnormal transaction data rule model to generate business abnormal transaction data comprises:
[0028] acquiring an index value of the abnormal transaction determination index;
[0029] performing abnormal transaction detection on the business data based on the abnormal transaction judgment rule and the index value of the abnormal transaction determination index to generate business abnormal transaction data.
[0030] In some implementations, the performing abnormal transaction business processing based on the business abnormal transaction data comprises:
[0031] generate service change alarm request data based on the service change data;
[0032] generate an alarm notification based on the service change alarm request data;
[0033] push the alarm notification.
[0034] To achieve the above purpose, the second aspect of the embodiment of the application provides a service change detection device, comprising:
[0035] a data acquisition module configured to acquire service data of a change service scenario;
[0036] a change detection module configured to perform change detection on the service data based on a change data rule model of the change service scenario, and generate service change data; wherein the change data rule model comprises a change judgment rule for sequentially judging the service data based on a plurality of judgment indexes; and the plurality of judgment indexes comprise a change judgment index;
[0037] a change processing module configured to perform change service processing based on the service change data.
[0038] In some implementations, the device further comprises a user portrait module configured to:
[0039] acquire historical service data of the change service scenario;
[0040] form a user service portrait model based on the historical service data;
[0041] identify a normal fluctuation range of service data of a user based on the user service portrait model;
[0042] determine an index value of the change judgment index based on the normal fluctuation range of service data of the user.
[0043] In some implementations, when the user portrait module forms a user service portrait model based on the historical service data, it is configured to:
[0044] perform data cleaning on the historical service data to obtain standard historical service data;
[0045] obtain user feature data based on the standard historical service data;
[0046] form a user service portrait model based on the user feature data.
[0047] In some implementations, when the user portrait module identifies a normal fluctuation range of service data of a user based on the user service portrait model, it is configured to:
[0048] forming a user service history data fluctuation curve based on the historical service data;
[0049] identifying a normal fluctuation range of service data of the user based on the user service history data fluctuation curve and the user service portrait model.
[0050] In some implementations, the user portrait module is further configured to, after determining the index value of the abnormality determination index:
[0051] adjusting the index value of the abnormality determination index based on a preset rule to obtain an adjusted index value of the abnormality determination index.
[0052] In some implementations, the abnormality detection module is specifically configured to:
[0053] obtaining the index value of the abnormality determination index;
[0054] detecting the abnormality of the service data based on the abnormality determination rule and the index value of the abnormality determination index to generate service abnormality data.
[0055] In some implementations, the abnormality processing module is specifically configured to:
[0056] generating service abnormality alarm request data based on the service abnormality data;
[0057] generating an alarm notification based on the service abnormality alarm request data;
[0058] pushing the alarm notification.
[0059] To achieve the above purpose, the third aspect of the present application provides an electronic device, which comprises a processor and a memory connected with the processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method of the first aspect.
[0060] To achieve the above purpose, the fourth aspect of the present application provides a computer readable storage medium, which stores computer execution instructions; the computer execution instructions are executed by a processor to implement the method of the first aspect.
[0061] To achieve the above purpose, the fifth aspect of the present application provides a computer program product, which comprises a computer program; the computer program is executed by a processor to implement the method of the first aspect.
[0062] The business transaction detection method, device, electronic equipment and storage medium provided by the application detect the business data of each transaction business scene through the transaction data rule model of each transaction business scene, obtain a transaction detection result, realize the capability of automatically and intelligently identifying abnormal business data by the system, can effectively avoid the expansion of major business transaction risks and income loss, improve the fault tolerance and reliability of the system for abnormal business transaction scenes, improve the user experience perception, and play a role in reducing costs and increasing efficiency.
[0063] Additional aspects and advantages of the application will be set forth in part in the description that follows, and in part will become apparent to those skilled in the art upon examination of the following description and drawings. BRIEF DESCRIPTION OF DRAWINGS
[0064] The above and / or additional aspects and advantages of the application will become apparent and be readily appreciated from the following description, taken in conjunction with the accompanying drawings, in which:
[0065] Figure 1 A flowchart of a business transaction detection method provided by an embodiment of the application;
[0066] Figure 2 A flowchart of a business transaction detection method provided by an embodiment of the application;
[0067] Figure 3 A block diagram of a business transaction detection device provided by an embodiment of the application. DETAILED DESCRIPTION
[0068] The embodiments of the application are described in detail below, examples of which are shown in the accompanying drawings, in which the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below are exemplary and are intended to explain the application, and cannot be understood as limiting the application.
[0069] Terminology explanation:
[0070] Platform: refers to system architecture.
[0071] With the development of business, various IT management system architectures are clouded and micro-serviced, the networking architecture is becoming more and more complex, and the business calls between various subsystem modules are becoming more and more complex. Taking mobile NGBOSS (business operation support system) as an example, for similar daily production business (such as monthly settlement business, SP fee business, list checking, fee payment, etc.), it mainly relies on reverse checking of business abnormalities after user business complaints, and does not have the capability of automatic checking and active early warning of business abnormalities. For system debiting problems, the current system mainly checks the rationality and authenticity of business for number level, and usually adopts TOPN number and business sampling inspection to check the rationality and accuracy of business.
[0072] With the continuous online of mobile convergence billing system cloud / micro-service projects (clustered, X86, containerized, etc.), while the cloud system mostly uses micro-service framework, large-scale distributed cluster design, service process number rises exponentially, CHBN new business scenarios are continuously added, and the probability of business exceptions is gradually increasing. For example, the verification and analysis of business exceptions such as large bill and large recharge, the current system does not limit various account-related business handling, and in special scenarios, due to unclear needs, imprecise business rules, peripheral system failures or BOSS system internal exceptions, etc., the accuracy of system data is abnormal, causing billing, account debiting, reminder SMS and account clearing display abnormalities, affecting customer perception, and easily causing user upgrade complaints. Taking the current system account debiting problem as an example, the current network personal and group user combined account debiting, the TOPN and sampling inspection methods for number level verification are difficult to find large amount of cost problems, which is easy to cause user complaints and income loss.
[0073] To solve the above problems, the embodiments of the present application provide a business abnormality detection method and device, which uses big data, artificial intelligence, data mining and other technologies to analyze and process abnormality business scenario related data, realizes the automatic management and optimization of abnormality business, and enables system operation and maintenance personnel to analyze and warn in time until the problem is closed, avoiding the expansion of major business abnormality risks.
[0074] The business abnormality detection method, device and equipment of the embodiments of the present application are described below with reference to the accompanying drawings.
[0075] Figure 1 A flowchart of a business abnormality detection method provided by the embodiments of the present application.
[0076] It should be noted that the execution subject of the business abnormality detection method of the embodiments of the present application is the business abnormality detection device of the embodiments of the present application, which can be configured in an electronic device to enable the electronic device to perform the business abnormality detection function.
[0077] As shown in Figure 1 The business abnormality detection method includes the following steps:
[0078] Step 101, acquiring business data of abnormality business scenarios.
[0079] Based on each link of the billing account production main process, the business abnormality check points are sorted out, the abnormality business scenarios are determined for the business abnormality check points, and the business data of each abnormality business scenario is acquired.
[0080] Exemplarily, the transaction business scenarios mainly include daily production aspect and monthly billing aspect transaction business scenarios. The daily production aspect includes month-end transaction, SP information fee transaction, list transaction, and payment transaction. The monthly billing aspect includes billing transaction, rent fee transaction, arrears transaction, and communication fee transaction.
[0081] In the business running process, the business data of the transaction business scenarios is acquired by collecting the data of the transaction business scenarios. The data collection is performed according to the daily production and billing dimensions. The daily production data includes recharge, month-end, return fee, free resource, arrears, and list data. The month-end billing data includes billing, rent fee, and communication fee.
[0082] As an implementation manner, the business data of the transaction business scenarios, i.e., the related data of the user, is collected based on AIOPS (Artificial Intelligence for IT Operations).
[0083] In step 102, the business data is detected based on the transaction rule model of the transaction business scenario to generate transaction data. The transaction rule model includes a transaction judgment rule for sequentially judging the business data based on multiple judgment indexes. The multiple judgment indexes include a transaction judgment index.
[0084] It can be understood that different transaction rule models are established for different transaction business scenarios. The transaction judgment rule for detecting the transaction of the business data of the transaction business scenario is established through the transaction rule model. Whether the transaction occurs is determined based on the transaction judgment rule.
[0085] As an implementation manner, the business data is detected based on the transaction rule model of the transaction business scenario to generate transaction data. The transaction rule model includes a transaction judgment rule for sequentially judging the business data based on multiple judgment indexes. The multiple judgment indexes include a transaction judgment index.
[0086] The business data is detected based on the transaction judgment rule and the index value of the corresponding transaction judgment index. Once the business exception is found, the system can automatically trigger the corresponding response mechanism to generate the transaction business data, such as recharge, month-end, return fee, free resource, arrears, list, billing, and invoice. The transaction risk message is pushed for the transaction business data of the production, the alarm notification, the fault transfer, and the like. The production guarantee personnel is reminded to check the business accuracy to the closed loop. The historical alarm and transaction data query are supported.
[0087] As an implementation manner, the index value of the transaction determination index is obtained through the user transaction portrait model. For the user transaction portrait model, detailed description is made in the following embodiments.
[0088] Exemplarily, the transaction transaction rule model includes the following dimensions:
[0089] 1) Business type: for example, including fee return business, SP monthly business, SP on-demand business, and list cumulative account business;
[0090] 2) User type: including group users and individual users;
[0091] 3) User sub-type: including postpaid users, prepaid users, and no distinction;
[0092] 4) Index type: single amount, monthly summary amount, and comparison with last month fluctuation;
[0093] 5) Threshold unit type: amount, points, and no unit;
[0094] 6) State: valid and invalid;
[0095] 7) Transaction threshold (i.e. transaction determination index): the index value of the transaction determination index can be collected and analyzed according to the user historical data to form a user transaction portrait model, and the recommended transaction threshold value (adjustable by business personnel) is generated based on the user transaction portrait model;
[0096] 8) Transaction alarm receiving: the number of personnel receiving related alarm information when the transaction scene occurs can be set, and the abnormality is notified and processed in time.
[0097] In some embodiments, the transaction determination index can include but is not limited to the transaction threshold, the alarm threshold, and the fluctuation base value.
[0098] According to business rules and production specifications, the transaction determination rules in the transaction transaction rule model of each type of business are set.
[0099] The following takes the monthly settlement, fee deduction, cumulative account transaction, and recharge as examples to describe the transaction transaction rule model.
[0100] Example 1, the transaction transaction rule model of monthly settlement and fee deduction, see Table 1 below.
[0101] Table 1:
[0102]
[0103] Based on AIOPS, by collecting relevant data of users, including user type (personal, group), business type (monthly settlement, overdue charge supplement deduction), user sub-type (prepaid, postpaid), index type (single amount) and other information, a business abnormality rule model of monthly settlement and overdue charge supplement deduction is established. The business abnormality rule model includes abnormality judgment rules for judging whether monthly settlement and overdue charge supplement deduction have abnormality.
[0104] The abnormality judgment rules are as follows: based on data collection analysis and model creation, the judgment indexes related to the abnormality of monthly settlement and overdue charge supplement deduction of users are analyzed, including abnormality threshold, alarm threshold, threshold unit type and fluctuation base value (business personnel can customize the setting of judgment indexes according to the uniqueness of abnormality business scene).
[0105] The abnormality judgment rules are as follows: first, the user type (personal, group) is judged, and then whether the monthly settlement amount and the overdue charge supplement deduction amount of the user in the month are greater than the fluctuation base value is judged. If it is greater than the fluctuation base value, it is compared with the abnormality threshold / alarm threshold. If the amount is greater than the abnormality threshold and less than the alarm threshold, it indicates that the business has abnormality, and the related data needs to be pushed to the account production platform for review. If the amount is greater than the alarm threshold, it indicates that the business abnormality needs to be paid attention to, and the operation and maintenance personnel are informed through an alarm message, and the related abnormality data is pushed to the account production platform for review.
[0106] Example 2, the business abnormality rule model corresponding to the cumulative account business, see Table 2 below.
[0107] Table 2:
[0108]
[0109] Based on AIOPS, by collecting relevant data of users, including user type (personal, group), business type (cumulative account), user sub-type (prepaid, postpaid), index type (monthly total amount) and other information, a business abnormality rule model of cumulative account business is established. The business abnormality rule model includes abnormality judgment rules for judging whether the cumulative account amount has abnormality.
[0110] The abnormality judgment rules are as follows: based on data collection analysis and model creation, multiple judgment indexes related to the abnormality of cumulative account business of users are analyzed, including abnormality threshold, alarm threshold, threshold unit type and fluctuation base value (business personnel can customize the setting of judgment indexes according to the uniqueness of business scene).
[0111] The transaction judgment rule is: first, judging the user type (personal, group), second, judging whether the monthly cumulative account summary amount of the user is greater than the fluctuation base value, if greater than the fluctuation base value, comparing with the transaction threshold / alarm threshold, if the monthly summary amount is greater than the transaction threshold and less than the alarm threshold, it indicates that the business has a transaction, and the related data needs to be pushed to the account production platform for review; if the amount is greater than the alarm threshold, it indicates that the business transaction needs to be paid attention to, and the operation and maintenance personnel are notified through the alarm message, and the related transaction data is pushed to the account production platform for review.
[0112] Example 3, the business transaction rule model corresponding to the recharge business, see Table 3 below.
[0113] Table 3:
[0114]
[0115] Based on AIOPS, by collecting user related data, including user type (personal, group), business type (recharge), user sub-type (prepaid, postpaid), index type (single amount) and other information, the transaction data rule model of the recharge business is established. The transaction data rule model includes a transaction judgment rule for judging whether the recharge amount has a transaction.
[0116] The transaction judgment rule is: based on data collection and analysis and model creation, analyzing multiple judgment indexes related to user recharge business transactions, including transaction threshold, alarm threshold, threshold unit type, fluctuation base value (business personnel can customize the setting of the judgment index according to the unique characteristics of the business scene). The transaction judgment rule is: first, judging the user type (personal, group), second, judging whether the single recharge amount of the user is greater than the fluctuation base value, if greater than the fluctuation base value, comparing with the transaction threshold / alarm threshold, if the single recharge amount is greater than the transaction threshold and less than the alarm threshold, it indicates that the recharge business has a transaction, and the related transaction data needs to be pushed to the account production platform for review; if the recharge amount is greater than the alarm threshold, it indicates that the recharge business transaction needs to be paid attention to, and the operation and maintenance personnel are notified through the alarm message, and the related recharge transaction data is pushed to the account production platform for review.
[0117] As an implementation manner, based on AIOPS technology, data meeting the time range is filtered from the collected data source, for example, including monthly settlement, overdue charge deduction, cumulative account, recharge and other business data. According to the transaction business scene type, the filtered data is subjected to data cleaning and analysis processing, and whether the corresponding business data is within the transaction threshold range is calculated based on the transaction judgment rule in the business transaction rule model; if not within the range, generate business transaction data, and output the business transaction data according to the specified format, generate business transaction data file.
[0118] Step 103, based on the business transaction data, transaction business processing is performed.
[0119] As an implementation mode, the implementation mode of performing transaction business processing based on the business transaction data; comprising: generating business transaction alarm request data based on the business transaction data; generating alarm notification based on the business transaction alarm request data; pushing the alarm notification.
[0120] Therefore, after pushing the alarm notification, the operation and maintenance personnel can process the transaction business, including confirming the transaction and judging whether it is reasonable or not.
[0121] As an implementation mode, based on AIOPS technology, through business transaction alarm request processing algorithm, business transaction alarm request data is generated based on business transaction data.
[0122] In this embodiment, based on AIOPS technology, data deep analysis is performed on the generated business transaction data, and relevant business transaction data is pushed to the accounting production platform and the alarm platform. The transaction business data file is pushed to the accounting production platform, and the analysis result is visualized in the form of charts, reports and the like, so as to better convey the analysis result and insight, and at the same time, the business transaction alarm request data is pushed to the system maintenance personnel in the form of short message for timely follow-up processing. Based on the analysis and visualization result of the business transaction data, decision support is provided to help the operation and maintenance personnel better cope with the business transaction, formulate corresponding business processing strategy and plan, and judge whether the business transaction data is reasonable. Based on the formulated relevant business processing strategy, transaction business data processing is performed to judge whether it is reasonable or not, and system vulnerabilities and hidden dangers are identified in time.
[0123] For example, AIOPS generates short message notification (i.e. alarm message) for business transaction alarm request data of return fee business, monthly settlement business, recharge, two-level bill arrears transaction, list cumulative account business, account fee warehousing, bill payment business and other transaction business scenarios, i.e. the alarm message is pushed to the accounting production platform. AIOPS generates short message notification for business transaction alarm request data of accounting preferential business, fixed fee pre-out, fixed fee account, communication fee account business, i.e. the alarm message is pushed to the accounting production platform. AIOPS generates short message notification for business transaction alarm request data of balance points transaction, account processing, bill invoice, prepayment account business, and the alarm message is pushed to the accounting production platform.
[0124] In addition, AIOPS supports receiving and processing alarm messages, querying and exporting business change data from the accounting production platform, and modifying alarm messages (requiring support for generating processing log records), closing loops, and exporting (alarm information and processing logs). AIOPS provides a business change data table containing business change data and a business alarm data table containing business change alarm request data, with a visual query page.
[0125] Furthermore, by analyzing and modeling historical business data, we can predict potential business anomalies and take corresponding measures in advance to avoid business interruptions or failures.
[0126] This application embodiment can identify abnormal business data in the billing and accounting production process based on AIOPS.
[0127] The business anomaly detection method in this application detects anomalies in business data for each anomaly scenario using an anomaly data rule model, thus obtaining anomaly detection results. The anomaly data rule model includes anomaly judgment rules based on multiple judgment indicators to sequentially judge business data, enabling the system to automatically and intelligently identify abnormal business data. This effectively and promptly prevents the escalation of significant business anomaly risks and revenue losses. It improves the system's fault tolerance and reliability in abnormal business anomaly scenarios, enhances user experience, and achieves cost reduction and efficiency improvement.
[0128] To clearly illustrate how the anomaly detection index is obtained in this application, this embodiment provides another method for detecting business anomalies. Figure 2 This is a flowchart illustrating another service anomaly detection method provided in an embodiment of this application.
[0129] like Figure 2 As shown, the business anomaly detection method may include the following steps:
[0130] Step 201: Obtain historical business data for the abnormal business scenario.
[0131] To create a user business profile model, data collection is required, so that the user business profile model can be created based on the analysis and mining of the data.
[0132] Data collection refers to the collection of users' basic information, behavioral data, transaction data, etc., based on data mining techniques.
[0133] For example, the data collection includes collecting user-related data, including user type (personal, group), business type (rebate, on-demand, list, cumulative account), user sub-type (prepaid, postpaid), index type (single amount, monthly aggregate amount), comparison with previous month data fluctuations, user status information, etc.
[0134] Step 202, based on the historical business data, forming a user business portrait model.
[0135] As an implementation manner, based on the historical business data, forming a user business portrait model includes: performing data cleaning on the historical business data to obtain standard historical business data; obtaining user feature data based on the standard historical business data; and forming a user business portrait model based on the user feature data.
[0136] It can be understood that after completing the data collection, the collected data needs to be cleaned to remove duplicate data, abnormal data, etc., to ensure the accuracy and integrity of the data. After cleaning the data, data analysis is performed, and through data mining, machine learning and other technical means, the behavior characteristics, preferences, demands, consumption habits and other information of the user are mined to obtain user feature data. For example, consumption habits such as user consumption habits can include whether there is a large fluctuation in the amount of each business consumption, business subscription preferences, willingness to handle new businesses, etc. According to the results of data analysis, the user's information, behavior characteristics, preferences, demands, consumption habits and other user feature data are integrated to form a user business portrait model.
[0137] Step 203, based on the user business portrait model, identifying the normal fluctuation range of the user's business data.
[0138] As an implementation manner, based on the user business portrait model, identifying the normal fluctuation range of the user's business data includes: based on the historical business data, forming a user business historical data fluctuation curve; and based on the user business historical data fluctuation curve and the user business portrait model, identifying the normal fluctuation range of the user's business data.
[0139] This step is to apply the user business portrait model to the business, analyze the user's historical business data (such as rent, arrears, cumulative account, etc.), form a user business historical data fluctuation curve, and determine the index value range of the abnormal transaction judgment index (abnormal transaction threshold) of each abnormal transaction business scenario through the user business historical data fluctuation curve.
[0140] For example, a rent transaction threshold (the absolute value of the fluctuation of a personal fee item is greater than xx%, the absolute value of the fluctuation of a group fee item is greater than xx%); an arrears transaction threshold (the personal arrears is greater than xx yuan, the group arrears is greater than xx ten thousand yuan); a cumulative account transaction (the monthly cumulative account amount of a single fee item of a personal number is greater than xx yuan, the single fee item of a single number is greater than xx ten thousand yuan); a recharge transaction (the single recharge of a personal number is greater than xx yuan, the single recharge of a group user is greater than xx yuan).
[0141] Therefore, by analyzing and modeling the collected service data, a user service portrait model of the user is formed, and a normal fluctuation range trend of the user service is identified.
[0142] In step 204, based on the normal fluctuation range of the service data of the user, the index value of the transaction determination index is determined.
[0143] In some embodiments, the service fluctuation threshold is customizable, for example, a fluctuation of 20% up and down, that is, the index value of the transaction determination index can be obtained by customization.
[0144] In some embodiments, after determining the index value of the transaction determination index, the method further comprises: based on a preset rule, adjusting the index value of the transaction determination index to obtain an adjusted index value of the transaction determination index.
[0145] It can be understood that when the service data of the user appears data outside the user service portrait model, the abnormal situation of the service is actively identified and detected.
[0146] By implementing the present embodiment, the index value of the transaction determination index is determined through the user service portrait model. Thus, the automatic transaction detection of the service data based on the index value of the transaction determination index is realized, so as to realize the ability of the system to automatically and intelligently identify abnormal service data, which can timely and effectively avoid the expansion of major service transaction risks and income loss. The system improves the fault tolerance and reliability of the abnormal service transaction scene, improves the user experience perception, and plays a role in reducing costs and increasing efficiency.
[0147] In order to realize the above-mentioned embodiments, the present application also provides a service transaction detection device. Figure 3 A structural schematic diagram of a service transaction detection device provided by the present application is shown in FIG. 1. Figure 3 As shown in the figure, the service transaction detection device can include a data acquisition module 301, a transaction detection module 302, and a transaction processing module 303.
[0148] The data acquisition module 301 is configured to acquire service data of a transaction service scene.
[0149] The transaction detection module 302 is configured to perform transaction detection on the service data based on a transaction data rule model of the transaction service scenario, and generate transaction service data. The transaction data rule model includes a transaction judgment rule for sequentially judging the service data based on a plurality of judgment indexes. The plurality of judgment indexes include a transaction judgment index.
[0150] The transaction processing module 303 is configured to perform transaction service processing based on the transaction service data.
[0151] Further, in a possible implementation of the embodiment of the application, the apparatus further includes a user portrait module 304 configured to:
[0152] obtain historical service data of the transaction service scenario;
[0153] form a user service portrait model based on the historical service data;
[0154] identify a normal fluctuation range of service data of a user based on the user service portrait model;
[0155] determine an index value of the transaction judgment index based on the normal fluctuation range of service data of the user.
[0156] Further, in a possible implementation of the embodiment of the application, when the user portrait module 304 forms a user service portrait model based on the historical service data, the user portrait module 304 is configured to:
[0157] perform data cleaning on the historical service data to obtain standard historical service data;
[0158] obtain user feature data based on the standard historical service data;
[0159] form a user service portrait model based on the user feature data.
[0160] Further, in a possible implementation of the embodiment of the application, when the user portrait module 304 identifies a normal fluctuation range of service data of a user based on the user service portrait model, the user portrait module 304 is configured to:
[0161] form a user service historical data fluctuation curve based on the historical service data;
[0162] identify a normal fluctuation range of service data of a user based on the user service historical data fluctuation curve and the user service portrait model.
[0163] Further, in a possible implementation of the embodiment of the application, after the user portrait module 304 determines the index value of the transaction judgment index, the user portrait module 304 is further configured to:
[0164] Adjust the index value of the transaction judgment index based on a preset rule to obtain an adjusted index value of the transaction judgment index.
[0165] Further, in a possible implementation of the embodiment of the application, the transaction detection module 302 is specifically configured to:
[0166] Obtain the index value of the transaction judgment index.
[0167] Detect the transaction of the service data based on the transaction judgment rule and the index value of the transaction judgment index, and generate service transaction data.
[0168] Further, in a possible implementation of the embodiment of the application, the transaction processing module 303 is specifically configured to:
[0169] Generate service transaction alarm request data based on the service transaction data.
[0170] Generate an alarm notification based on the service transaction alarm request data.
[0171] Push the alarm notification.
[0172] It should be noted that the foregoing explanation and description of the service transaction detection method embodiment also apply to the service transaction detection device of this embodiment, which will not be described here.
[0173] The service transaction detection device of the embodiment of the application detects the service data of each transaction service scenario through the transaction data rule model of each transaction service scenario to obtain a transaction detection result. The transaction data rule model includes a transaction judgment rule for sequentially judging the service data based on multiple judgment indexes, which realizes the ability of the system to automatically and intelligently identify abnormal service data, can effectively avoid the expansion of major transaction risks and income loss, improves the fault tolerance and reliability of the system for abnormal transaction scenarios, improves the user experience perception, and plays a role in reducing costs and increasing efficiency.
[0174] To implement the above-mentioned embodiments, the application further provides an electronic device, comprising a processor and a memory connected with the processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method provided in the foregoing embodiments.
[0175] To implement the above-mentioned embodiments, the application further provides a computer readable storage medium, which stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the method provided in the foregoing embodiments.
[0176] To achieve the above-mentioned embodiments, the application further provides a computer program product comprising a computer program which, when executed by a processor, implements the method provided by the foregoing embodiments.
[0177] The collection, storage, use, processing, transmission, provision and disclosure of user personal information involved in the present application comply with relevant laws and regulations and do not violate public order and good customs.
[0178] It should be noted that the personal information from the user should be collected for legal and reasonable purposes, and should not be shared or sold outside these legal uses. In addition, such collection / sharing should be carried out after the user's informed consent is received, including but not limited to informing the user to read the user agreement / user notice before the user uses the function, and signing the agreement / authorization including authorization of relevant user information. In addition, any necessary steps should be taken to protect and secure access to such personal information data and ensure that other people with access to personal information data comply with their privacy policies and processes.
[0179] The present application is expected to provide embodiments in which the user can selectively prevent the use or access of personal information data. That is, the present disclosure is expected to provide hardware and / or software to prevent or block access to such personal information data. Once the personal information data is no longer needed, the risk is minimized by limiting data collection and deleting data. In addition, such personal information is de-identified, if applicable, to protect the privacy of the user.
[0180] In the foregoing embodiment description, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples. In addition, the person skilled in the art can combine and combine the different embodiments or examples described in the specification and the features of the different embodiments or examples, without contradiction.
[0181] In addition, the terms "first", "second" are only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features. Therefore, the features defined with "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, for example, two, three, etc., unless otherwise specifically limited.
[0182] Any processes or methods described in the flowcharts or otherwise described herein can be understood as representing modules, segments, or portions of code that include one or more executable instructions for implementing specific logical functions or steps in the processes. The scope of preferred embodiments of the present application encompasses other implementations in which the steps are performed in a different order, including substantially simultaneously, or in reverse order, according to the functions involved, as will be understood by those skilled in the art of the embodiments described herein.
[0183] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as a list of executable instructions for implementing the logic function, and can be embodied in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, processor- containing system, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions. For purposes of this specification, a "computer-readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the instruction execution system, apparatus, or device. The computer-readable medium can be a more specific example (non-exhaustive list) including the following: an electronic connection having one or more wires (electronic apparatus), a portable computer diskette (magnetic apparatus), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium can even be paper or other suitable medium on which the program can be printed, as the program can be electronically obtained, for example, by optically scanning the paper or other medium, then
[0184] It should be understood that portions of the present application can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in a memory and executed by a suitable instruction execution system. As in another embodiment, if implemented in hardware, any of the following technologies known in the art or their combinations can be used: discrete logic circuitry having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.
[0185] Those skilled in the art of the present technology can understand that all or part of the steps carried out by the above-mentioned embodiment method can be completed by programs instructing related hardware, and the programs can be stored in a computer readable storage medium. When the program is executed, it includes one of the steps of the method embodiment or a combination thereof.
[0186] In addition, each functional unit in each embodiment of the present application can be integrated into one processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.
[0187] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc. Although the embodiments of the present application have been shown and described above, it should be understood that the above-mentioned embodiments are exemplary and cannot be understood as limiting the present application, and those skilled in the art can make changes, modifications, replacements and variations to the above-mentioned embodiments within the scope of the present application.
Claims
1. A method for detecting a business transaction anomaly, the method comprising: The method comprises the following steps: obtaining business data of a transaction service scenario, wherein, based on each link of a billing and accounting production main process, business transaction checkpoints are sorted out, and for the business transaction checkpoints, transaction service scenarios are determined, and business data of each transaction service scenario is obtained; based on a transaction rule model of the transaction service scenario, transaction detection is performed on the business data, and transaction data is generated, comprising: obtaining an index value of a transaction determination index through a user business portrait model; based on a transaction judgment rule and the index value of the transaction determination index, transaction detection is performed on the business data, and transaction data is generated; wherein the transaction rule model comprises a transaction judgment rule for sequentially judging the business data based on multiple judgment indexes; the multiple judgment indexes comprise a transaction determination index, different transaction rule models are established for each transaction service scenario, a transaction judgment rule for transaction detection on the business data of the transaction service scenario is established through the transaction rule model, and whether the transaction occurs is determined based on the transaction judgment rule, the transaction rule model comprises the following dimensions: business type, user type, user sub-type, index type, threshold unit type, state, transaction threshold and transaction alarm receiving, and the transaction judgment rule in the transaction rule model of each type of business is set according to business rules and production specifications; based on the transaction data, transaction service processing is performed.
2. The method of claim 1, wherein, The method for generating the index value of the transaction determination index comprises: obtaining historical business data of the transaction service scenario; based on the historical business data, a user business portrait model is formed; based on the user business portrait model, a normal fluctuation range of the user's business data is identified; based on the normal fluctuation range of the user's business data, the index value of the transaction determination index is determined.
3. The method of claim 2, wherein, The method for forming the user business portrait model based on the historical business data comprises: performing data cleaning on the historical business data to obtain standard historical business data; based on the standard historical business data, user feature data is obtained; based on the user feature data, a user business portrait model is formed.
4. The method of claim 3, wherein, The method for identifying the normal fluctuation range of the user's business data based on the user business portrait model comprises: based on the historical business data, a user business historical data fluctuation curve graph is formed; based on the user business historical data fluctuation curve graph and the user business portrait model, the normal fluctuation range of the user's business data is identified.
5. The method of claim 2, wherein, After determining the index value of the transaction determination index, the method further comprises: based on a preset rule, the index value of the transaction determination index is adjusted to obtain an adjusted index value of the transaction determination index.
6. The method of claim 1, wherein, The method for performing transaction service processing based on the transaction data comprises: based on the transaction data, transaction alarm request data is generated; based on the transaction alarm request data, an alarm notification is generated; the alarm notification is pushed.
7. A transaction anomaly detection apparatus, characterized by comprising: The data acquisition module is configured to acquire business data of transaction scenarios. Based on each link of a main process of charging and accounting production, the business transaction checkpoints are sorted out, and the transaction scenarios are determined according to the business transaction checkpoints, and the business data of each transaction scenario is acquired. The transaction detection module is configured to perform transaction detection on the business data based on a business transaction rule model of the transaction scenarios, and generate business transaction data. The transaction detection is performed on the business data based on transaction judgment rules and index values of transaction judgment indexes, and the business transaction data is generated. The business transaction rule model includes transaction judgment rules for sequentially judging the business data based on multiple judgment indexes. The multiple judgment indexes include transaction judgment indexes. Different business transaction rule models are established for each transaction scenario. The transaction judgment rules for transaction detection on the business data of the transaction scenarios are established by the business transaction rule models. The transaction judgment rules are used to determine whether the transaction occurs. The business transaction rule model includes the following dimensions: business type, user type, user sub-type, index type, threshold unit type, state, transaction threshold, and transaction alarm receiving. The transaction judgment rules in the business transaction rule models of each type of business are set according to business rules and production specifications. The transaction processing module is configured to perform transaction business processing based on the business transaction data. The processor and the memory connected to the processor in communication are included.
8. An electronic device, comprising: The memory stores computer execution instructions. The processor executes the computer execution instructions stored in the memory to implement the method of any one of claims 1-6. The computer readable storage medium stores computer execution instructions. The computer execution instructions are executed by the processor to implement the method of any one of claims 1-6. 9. A computer-readable storage medium, characterized in that,
Citation Information
Patent Citations
Abnormal business data screening method for anti-money laundering system
CN107358360A
Abnormality detection method and device for service flow data, and electronic equipment
CN115935237A