A computer network security transaction optimization system
By designing a multi-modular computer network security transaction optimization system, the shortcomings of the existing technology in defending against complex attacks and ensuring transaction efficiency are solved, and the full monitoring and optimization of the transaction process is achieved, which significantly improves the system's security and transaction processing efficiency.
Patent Information
- Application Number
- CN202510156873.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-02-13
AI Technical Summary
The existing network security technology and transaction optimization systems have shortcomings in defending against complex attacks and ensuring transaction efficiency. They lack comprehensive integrated solutions. The traditional protection mechanism is lagging behind and cannot detect and deal with complex attack patterns in real time.
A computer network security transaction optimization system is designed, including an identity authentication authorization module, a transaction request processing module, a security monitoring and protection module, a transaction intelligent optimization module and a transaction audit management module. The system achieves comprehensive monitoring and optimization of the transaction process through multi-level authentication, real-time network traffic monitoring, intelligent transaction scheduling and detailed transaction auditing.
It significantly improves identity authentication and defense capabilities during the transaction process, ensures the confidentiality and integrity of transaction data, improves the system's anti-attack ability and transaction processing efficiency, reduces the occurrence of wrong transactions and illegal transactions, and enhances the monitoring and compliance guarantee of transaction behavior.
Smart Images

Figure CN119624457B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network transaction security, and particularly to a computer network security transaction optimization system. Background Art
[0002] Although existing network security technologies and transaction optimization systems can prevent some common attacks and violations to a certain extent, most of them focus on a certain aspect, such as identity authentication or transaction data encryption, lacking an all-round integrated solution.
[0003] Moreover, with the continuous upgrading of network attack means, traditional protection mechanisms often have a lag and cannot detect and respond to complex attack patterns in real time.
[0004] In addition, existing transaction optimization solutions often ignore intelligent scheduling and traffic management during the transaction process, unable to ensure the high-efficiency processing ability of the system when the transaction volume surges, and prone to transaction delays or system crashes. Summary of the Invention
[0005] The purpose of the present invention is to provide a computer network security transaction optimization system to solve the problems raised in the above background art.
[0006] To achieve the above purpose, the present invention provides the following technical solution: A computer network security transaction optimization system, comprising:
[0007] An identity authentication and authorization module, for:
[0008] Verifying the identities of both parties to the transaction through multiple authentication methods, generating digital certificates for users with successful verification, and performing authorization management on the transaction operation scope according to the user's permission level;
[0009] A transaction request processing module, for:
[0010] Receiving and processing transaction requests from the user side, collaborating with the identity authentication and authorization module, judging whether the transaction request is compliant according to the content and identity permissions of the user request, encrypting sensitive information in the transaction, and checking the rationality of the transaction instruction through amount verification and account status verification;
[0011] A security monitoring and protection module, for:
[0012] Real-time monitoring of network traffic during the transaction process and identifying attack behaviors, analyzing transaction behavior patterns and identifying abnormal transaction requests, encrypting data transmission during the transaction process, and combining with the transaction request processing module to block malicious requests in real time;
[0013] A transaction intelligent optimization module, for:
[0014] According to the distribution of transaction flow, cooperate with the transaction request processing module to dynamically adjust the processing nodes of transaction requests and the transaction data transmission path, and automatically execute transaction rules based on transaction logic;
[0015] The transaction audit management module is used for:
[0016] Audit all transaction processes, record transaction information, identify and mark suspicious transactions;
[0017] The transaction report analysis module is used for:
[0018] Statistically display transaction data through charts, conduct risk assessment on transaction data, cooperate with the transaction audit management module and generate a transaction report, where the transaction report includes all transaction records, risk assessment, and analysis of abnormal behaviors.
[0019] Furthermore, the identity authentication and authorization module includes:
[0020] The multi-factor authentication unit is used for:
[0021] When a user initiates a transaction, conduct multi-factor authentication on the user's identity through password, dynamic token, and facial recognition verification methods;
[0022] Analyze the user's historical behavior patterns during the multi-factor authentication process, where the historical behavior patterns include typing speed and transaction habits. When abnormal behavior is detected, trigger additional verification, and the additional verification includes requiring the input of answers to additional security questions;
[0023] If both the multi-factor authentication and additional verification steps are passed, it is regarded as successful identity authentication;
[0024] After passing the verification, generate a digital certificate according to the user's permission level and conduct permission authorization management;
[0025] The permission authorization management unit is used for:
[0026] According to the user's identity authentication result and the preset permission policy, dynamically allocate the user's transaction permissions and generate a digital certificate, and check the user's permissions when the user initiates a transaction request.
[0027] Furthermore, the transaction request processing module includes:
[0028] The transaction request inspection unit is used for:
[0029] Receive transaction requests from the user terminal, extract the key information in the transaction requests, where the key information includes transaction amount, transaction type, transaction account, and payee information, and conduct compliance checks on the request content;
[0030] Check the status of the account initiating the transaction to ensure that the account is active and there are no abnormal situations such as freezing or restrictions;
[0031] According to the preset transaction amount rules, the system verifies the transaction amount;
[0032] Based on the preset transaction rules and laws and regulations, verify whether the transaction request meets the compliance requirements;
[0033] If the transaction request passes all the verification rule checks, mark the transaction request as a legal request and continue the processing; otherwise, reject the transaction and feedback an error message;
[0034] The information encryption protection unit is used for:
[0035] Identify all sensitive information in the transaction request and mark it as data to be encrypted. The sensitive information includes account information, transaction amount, and user identity;
[0036] Use a combination of symmetric encryption and asymmetric encryption to encrypt the data to be encrypted;
[0037] During the transaction process, perform integrity verification on the encrypted data.
[0038] Furthermore, the security monitoring and protection module includes:
[0039] The network monitoring and identification unit is used for:
[0040] By real-time monitoring of network traffic, capture the data packets in the transaction request, and analyze the source, destination, size, frequency, and protocol characteristics of the data packets. By analyzing the source IP address, request frequency, and pattern of the network traffic, identify and detect potential attack behaviors. When the system detects potential attack behaviors, trigger the protection mechanism and temporarily restrict and intercept requests from the attack source IP;
[0041] The transaction behavior analysis unit is used for:
[0042] By analyzing the user's historical transaction data, establish a behavior model for each user. The behavior model includes transaction amount, transaction frequency, transaction time, transaction type, and payee characteristics, and extract the normal transaction behavior pattern of the user based on the behavior model;
[0043] When the user initiates a transaction, real-time analyze the current transaction behavior characteristics and compare them with the user's normal transaction behavior pattern;
[0044] If there are significant differences between the current transaction behavior characteristics and the user's normal transaction behavior pattern, mark the current transaction as an abnormal transaction. The significant differences include abnormally large transactions, frequent small transactions, and transaction times that do not match the user's normal transaction behavior pattern.
[0045] Furthermore, the security monitoring and protection module further includes:
[0046] An anomaly detection unit, configured to:
[0047] When the transaction behavior analysis unit detects an abnormal transaction behavior, automatically trigger a protection mechanism, where the protection mechanism includes restricting the transaction amount, requiring the user to perform additional identity verification, freezing the account, and suspending the transaction;
[0048] Simultaneously send an alarm message to the security administrator;
[0049] Record the abnormal transaction data marked as an abnormal transaction and send it to the transaction audit management module.
[0050] Furthermore, the transaction intelligent optimization module includes:
[0051] A transaction request scheduling unit, configured to:
[0052] Real-time monitor the workload data and current transaction flow data of each processing node, and collect the response time, processing capacity, and resource occupancy information of each node;
[0053] When a new transaction request arrives, based on the current transaction flow data, allocate the transaction request among multiple available nodes, and when it is detected that the load of a processing node exceeds the set threshold, automatically allocate the new transaction request to the node with a low load;
[0054] In the case of an increase in the transaction request volume and unstable network conditions, automatically enable the standby processing node and dynamically adjust the configuration of the node.
[0055] Furthermore, the node resource anomaly monitoring module is configured to:
[0056] Real-time monitor the node resource occupancy information corresponding to each unit time, where the node resource occupancy information includes the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate;
[0057] Obtain the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate according to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to each unit time;
[0058] Among them, the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate are obtained through the following formula:
[0059]
[0060] Among them, P represents the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate; n represents the number of unit time periods experienced by the processing node during operation, and the unit time is 1 s; X i represents the values of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to the i-th unit time; X maxi represents the maximum value of the values of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate that have occurred up to the i-th unit time; X bi represents the standard deviation of the values of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to the i-th unit time; X maxbi represents the standard deviation of the maximum value of the values of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate that have occurred up to the i-th unit time;
[0061] Compare the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate with their respective preset change degree coefficient thresholds;
[0062] When any one of the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate exceeds its respective preset change degree coefficient threshold, determine whether there is resource utilization abnormality in the processing node using the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate.
[0063] Further, the determination of whether there is resource utilization abnormality in the processing node using the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate includes:
[0064] When any one of the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate exceeds its respective preset change degree coefficient threshold, retrieve the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to each unit time;
[0065] Obtain a resource abnormality determination coefficient using the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to each unit time;
[0066] Among them, the resource abnormality determination coefficient is obtained through the following formula:
[0067]
[0068] Among them, Z represents the resource abnormality determination coefficient; n represents the number of unit time periods experienced by the processing node during operation, and the unit time is 1 s; X ci represents the CPU occupancy rate corresponding to the i-th unit time; X ni represents the memory occupancy rate corresponding to the i-th unit time; X tirepresents the communication bandwidth occupancy rate corresponding to the i-th unit time; X cfi represents the maximum value of the change range of the CPU occupancy rate corresponding to the i-th unit time; X nfi represents the maximum value of the change range of the memory occupancy rate corresponding to the i-th unit time; X tfi represents the maximum value of the change range of the communication bandwidth occupancy rate corresponding to the i-th unit time; T ci represents the time interval between the CPU occupancy rate corresponding to the i-th unit time and the maximum value of the CPU occupancy rate; T ni represents the time interval between the memory occupancy rate corresponding to the i-th unit time and the maximum value of the memory occupancy rate; T ti represents the time interval between the communication bandwidth occupancy rate corresponding to the i-th unit time and the maximum value of the communication bandwidth occupancy rate; P ci 、P ni and P ti respectively represent the change degree coefficients of the CPU occupancy rate, the memory occupancy rate, and the communication bandwidth occupancy rate in the i-th unit time
[0069] Compare the resource anomaly determination coefficient with a preset determination coefficient;
[0070] When the resource anomaly determination coefficient exceeds the preset determination coefficient, it is determined that the node has an abnormal resource utilization state, and a resource utilization anomaly alarm is issued.
[0071] Furthermore, the transaction intelligent optimization module includes:
[0072] A transaction path adjustment unit, used for:
[0073] When receiving a transaction request, evaluate the transmission requirements of the transaction data according to the transaction type, amount, and location factors of the two parties to the transaction. Among them, for sensitive transactions, select a high-security transmission path; for normal transactions, optimize the transmission path according to the delay requirements; for critical transactions and high-risk transactions, transmit data simultaneously between multiple secure paths;
[0074] Real-time monitor the health status and transmission quality of the network link, determine whether there is network congestion, bandwidth limitation, and malicious attack risk in the current network. When the quality of the transmission path deteriorates or is attacked, automatically switch the transmission path.
[0075] Furthermore, the transaction audit management module includes:
[0076] A data record storage unit, used for:
[0077] Record and store the key transaction information during the transaction process, where the key transaction information includes transaction time, transaction amount, identities of both parties to the transaction, transaction status, transaction type, and transaction account;
[0078] A transaction behavior auditing unit, configured to:
[0079] Establish a transaction behavior auditing rule library according to industry regulations, organizational internal policies, and historical transaction data. The transaction behavior auditing rule library includes rules such as abnormal transaction amount, large - amount transaction frequency, inconsistent transaction time with habits, and mutated transaction pattern;
[0080] Audit the transaction based on the set rules in the transaction behavior auditing rule library. If the transaction behavior violates the preset rules, mark the transaction as an abnormal transaction;
[0081] When an abnormal transaction is identified, mark the current transaction as a suspicious transaction and archive the suspicious transaction information of the suspicious transaction. The suspicious transaction information includes transaction time, amount, involved accounts, and abnormal behavior characteristics.
[0082] Compared with the prior art, the beneficial effects of the present invention are:
[0083] 1. Through the close cooperation of the identity authentication and authorization module and the security monitoring and protection module, the present invention establishes a multi - level security protection system, greatly improving the identity authentication and defense capabilities during the transaction process. By using multiple identity authentication methods, it ensures the authenticity and legality of the identities of both parties to the transaction. By analyzing the historical behavior patterns of users, when abnormal behavior is detected, it will automatically trigger additional security verification, reducing the risk of illegal intrusion. It monitors the transaction network traffic in real - time, deeply analyzes the data packets in the transaction requests, identifies potential attack behaviors, and takes immediate response measures when abnormalities are found. Through the multi - dimensional security protection system, it effectively prevents security threats such as identity theft, fraud, and cyber - attacks, protecting the asset security of both parties to the transaction.
[0084] 2. The present invention strictly checks the content, amount, account status, etc. of transaction requests to ensure that each transaction complies with compliance requirements, thereby minimizing the occurrence of incorrect and illegal transactions. Through the encryption protection of sensitive information, while ensuring transaction security, the system guarantees that the privacy of users is not disclosed. Through the transaction request scheduling unit, the system monitors the load conditions of each processing node in real time and intelligently distributes transaction requests to idle nodes according to changes in transaction traffic, thus avoiding the generation of system bottlenecks, improving the speed and stability of transaction processing. When the transaction request volume increases significantly or the network environment becomes unstable, standby nodes are automatically enabled and the transaction path is dynamically adjusted to ensure the efficient completion of transactions, effectively improving the flexibility and response ability of the system, and is particularly suitable for operation in scenarios with increased financial transaction volume or complex network environments.
[0085] 3. The present invention records all key transaction information and establishes an audit rule library for transaction behaviors based on industry regulations and enterprise policies to monitor and review transaction behaviors in real time. Any transaction that violates the audit rules will be marked as a suspicious transaction, and the suspicious information will be automatically archived for further review and analysis later. Through the aggregation and statistical analysis of all transaction data, a detailed risk assessment report is generated to help financial institutions, regulatory authorities, or enterprise managers deeply understand the risks and potential threats in the transaction process, enhancing the monitoring of improper transaction behaviors and providing strong support for compliance inspections, ensuring the legality and fairness of the transaction environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0086] Figure 1 It is a schematic diagram of the modules of the computer network security transaction optimization system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0087] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0088] Please refer to Figure 1 , the present invention provides the following technical solutions:
[0089] A computer network security transaction optimization system, comprising:
[0090] An identity authentication and authorization module, used for:
[0091] Verifying the identities of both parties to the transaction through multiple authentication methods, generating digital certificates for users with successful verification, and performing authorization management on the transaction operation scope according to the user's permission level;
[0092] A transaction request processing module, configured to:
[0093] Receive and process transaction requests from the client, cooperate with the authentication and authorization module, determine whether the transaction requests are compliant according to the content and identity permissions of the user requests, encrypt sensitive information in the transactions, and check the rationality of the transaction instructions through amount verification and account status verification;
[0094] A security monitoring and protection module, configured to:
[0095] Monitor network traffic in real time during the transaction process and identify attack behaviors, analyze transaction behavior patterns and identify abnormal transaction requests, encrypt data transmission during the transaction process, and combine with the transaction request processing module to block malicious requests in real time;
[0096] A transaction intelligent optimization module, configured to:
[0097] According to the distribution of transaction traffic, cooperate with the transaction request processing module to dynamically adjust the processing nodes of transaction requests and the transaction data transmission paths, and automatically execute transaction rules based on transaction logic;
[0098] A transaction audit and management module, configured to:
[0099] Audit all transaction processes and record transaction information, identify and mark suspicious transactions;
[0100] A transaction report analysis module, configured to:
[0101] Statistically display transaction data through charts, conduct risk assessments on transaction data, cooperate with the transaction audit and management module and generate transaction reports, and the transaction reports include all transaction records, risk assessments, and abnormal behavior analyses.
[0102] In the above embodiments, multi-level security verification of transactions is performed through the authentication and authorization module and the security monitoring and protection module to avoid security risks such as identity theft, fraud, and malicious attacks. Sensitive data is encrypted during the transaction process to ensure the confidentiality and integrity of transaction data. The processing nodes and data transmission paths are dynamically adjusted to effectively allocate resources in a high-concurrency environment, ensuring the efficiency and stability of transactions. Through intelligent scheduling and path adjustment, the transaction process and system response time are optimized, improving the overall transaction performance.
[0103] In the above embodiments, by analyzing transaction behaviors and network traffic in real time, abnormal transactions can be detected in a timely manner, triggering a protection mechanism to reduce potential risks. By accurately identifying risk behaviors in transactions, the system can quickly respond and prevent financial fraud, money laundering and other behaviors. The traceable records of all transaction processes provide detailed transaction data reports, facilitating risk assessment and compliance inspections by auditors and providing strong evidence for post-event accountability.
[0104] The identity authentication and authorization module includes:
[0105] The multi-factor authentication unit is used for:
[0106] When a user initiates a transaction, multi-factor authentication of the user's identity is performed through password, dynamic token, and facial recognition verification methods;
[0107] During the multi-factor authentication process, the historical behavior patterns of the user are analyzed, and the historical behavior patterns include typing speed and transaction habits. When abnormal behavior is detected, additional verification is triggered, and the additional verification includes requiring the input of answers to additional security questions;
[0108] If both the multi-factor authentication and the additional verification steps pass, the identity authentication is considered successful;
[0109] After passing the verification, a digital certificate is generated according to the user's permission level, and permission authorization management is performed;
[0110] The permission authorization management unit is used for:
[0111] According to the user's identity authentication result and the preset permission policy, the user's transaction permissions are dynamically allocated and a digital certificate is generated. When the user initiates a transaction request, the user's permissions are checked.
[0112] In the above embodiments, through the multi-factor authentication unit, the system can increase the security of identity authentication through multi-factor verification methods such as password, dynamic token, and facial recognition, preventing identity impersonation and theft. The analysis of behavior patterns further enhances the accuracy and intelligence of identity authentication. Especially when identifying abnormal behavior, additional verification measures can be triggered in a timely manner, greatly improving the system's ability to prevent complex attacks and abnormal behaviors. By dynamically adjusting the user's transaction operation scope according to the user's permission level, problems such as unauthorized behavior and abuse of permissions are avoided. By real-time verifying the user's identity authentication result and permission settings, the system ensures that only authorized users can perform specific transaction operations, effectively preventing internal personnel or external attackers from abusing permissions for illegal transactions.
[0113] The transaction request processing module includes:
[0114] The transaction request inspection unit is used for:
[0115] Receive a transaction request from the client, extract the key information in the transaction request, where the key information includes the transaction amount, transaction type, transaction account, and payee information, and perform compliance checks on the request content;
[0116] Check the status of the account initiating the transaction to ensure that the account is active and there are no abnormal situations such as freezing or restrictions;
[0117] According to the preset transaction amount rules, the system verifies the transaction amount;
[0118] Based on the preset transaction rules and laws and regulations, verify whether the transaction request meets the compliance requirements;
[0119] If the transaction request passes all the verification rule checks, mark the transaction request as a legal request and continue processing; otherwise, reject the transaction and feedback an error message;
[0120] An information encryption protection unit, which is used for:
[0121] Identify all sensitive information in the transaction request and mark it as data to be encrypted, where the sensitive information includes account information, transaction amount, and user identity;
[0122] Use a combination of symmetric encryption and asymmetric encryption to encrypt the data to be encrypted;
[0123] During the transaction process, perform integrity verification on the encrypted data.
[0124] In the above embodiment, through the transaction request inspection unit, the key information of the transaction is checked for legality and compliance to ensure that each transaction meets the regulatory requirements and the preset transaction rules, automatically verify whether the transaction amount meets the user's transaction amount rules, prevent the occurrence of abnormal large - amount transactions, effectively prevent illegal transactions of frozen or restricted accounts, perform strict encryption processing on the sensitive data in the transaction request, use a combination of symmetric encryption and asymmetric encryption to ensure that the transaction data is not intercepted, tampered with, or leaked during the transmission process, and at the same time perform data integrity verification during the transaction process, further ensuring the reliability of the transaction, effectively reducing the transaction risks caused by human errors or malicious attacks, ensuring the security of the transaction data and the compliance of the transaction process, and improving the user's trust in the system.
[0125] A security monitoring and protection module, including:
[0126] A network monitoring and identification unit, which is used for:
[0127] By monitoring network traffic in real time, capturing data packets in transaction requests, and analyzing the source, target, size, frequency, and protocol characteristics of the data packets, and by analyzing the source IP address, request frequency, and pattern of the network traffic, potential attack behaviors are identified and detected. When the system detects potential attack behaviors, the protection mechanism is triggered and requests from the attacking source IP are temporarily restricted and intercepted;
[0128] A transaction behavior analysis unit, configured to:
[0129] By analyzing the historical transaction data of users, a behavior model for each user is established. The behavior model includes transaction amount, transaction frequency, transaction time, transaction type, and payee characteristics, and the normal transaction behavior pattern of the user is extracted based on the behavior model;
[0130] When a user initiates a transaction, the current transaction behavior characteristics are analyzed in real time and compared with the normal transaction behavior pattern of the user;
[0131] If there are significant differences between the current transaction behavior characteristics and the normal transaction behavior pattern of the user, the current transaction is marked as an abnormal transaction. The significant differences include abnormally large transactions, frequent small transactions, and transaction times that do not match the normal transaction behavior pattern of the user;
[0132] An anomaly detection unit, configured to:
[0133] When the transaction behavior analysis unit detects abnormal transaction behaviors, the protection mechanism is automatically triggered. The protection mechanism includes restricting the transaction amount, requiring the user to perform additional identity verification, freezing the account, and suspending the transaction;
[0134] At the same time, an alarm message is sent to the security administrator;
[0135] Record the abnormal transaction data marked as abnormal transactions and send it to the transaction audit management module.
[0136] In the above embodiments, through network security monitoring and real-time protection functions, various attack behaviors can be identified and addressed. By analyzing characteristics such as network traffic, the source and target of data packets, and frequency, potential attack behaviors can be detected in real time, and possible attack sources can be identified by analyzing traffic patterns. Unsafe requests can be intercepted and restricted in a timely manner, effectively preventing the impact of network attacks such as DoS attacks and DDoS attacks. By analyzing the historical transaction data of users and establishing a behavior model, the normal transaction patterns of users can be accurately identified, and abnormal transactions can be discovered in a timely manner. When the transaction behavior of a user is abnormal, the system automatically marks the transaction as an abnormal transaction, triggering a protection mechanism, reducing the risks of fraud, money laundering, and other illegal transactions. When the system detects abnormal behaviors, restriction measures can be triggered in real time, such as freezing accounts and suspending transactions, and the abnormal transaction information can be reported to the security administrator in a timely manner. Through multi-level security protection means, the anti-attack ability of the transaction system is effectively improved, and the risk of financial fraud is reduced.
[0137] The transaction intelligent optimization module includes:
[0138] The transaction request scheduling unit is used for:
[0139] Monitor the workload data and current transaction traffic data of each processing node in real time, and collect the response time, processing capacity, and resource occupancy information of each node;
[0140] When a new transaction request arrives, based on the current transaction traffic data, allocate the transaction request among multiple available nodes. When it is detected that the load of a processing node exceeds the set threshold, automatically allocate the new transaction request to the node with a low load;
[0141] In the case of an increase in transaction requests and unstable network conditions, automatically enable standby processing nodes and dynamically adjust the configuration of the nodes;
[0142] The transaction path adjustment unit is used for:
[0143] When receiving a transaction request, evaluate the transmission requirements of the transaction data according to factors such as transaction type, amount, and the locations of the two parties to the transaction. Among them, for sensitive transactions, select a transmission path with high security; for normal transactions, optimize the transmission path according to the delay requirements; for critical transactions and high-risk transactions, transmit data simultaneously between multiple secure paths;
[0144] Monitor the health status and transmission quality of the network link in real time, judge whether there are congestion, bandwidth limitations, and malicious attack risks in the current network. When the quality of the transmission path deteriorates or is attacked, automatically switch the transmission path.
[0145] In the above embodiments, by dynamically adjusting the transaction flow, the load of processing nodes, and the transmission path, the processing efficiency of transactions and the resource allocation of the system are optimized. By real-time monitoring the workloads of each processing node, transaction requests can be intelligently allocated to nodes with lower loads, avoiding transaction delays and system crashes caused by node overload. When the transaction request volume surges, the system can automatically enable standby nodes to ensure that transaction requests are efficiently processed. According to the type, amount, and risk level of transactions, an appropriate transmission path is dynamically selected. For sensitive transactions, a high-security transmission channel is preferentially selected to ensure data security; for normal transactions, the path is optimized according to the latency requirements to ensure transaction efficiency. If the transmission path is attacked or the quality deteriorates, the system can quickly switch paths to ensure reliable data transmission. By intelligently optimizing the transaction flow and resources, the processing efficiency of transactions and the security of transaction data transmission are improved.
[0146] Specifically, the node resource anomaly monitoring module is used for:
[0147] Real-time monitoring of the node resource occupancy information corresponding to each unit time, where the node resource occupancy information includes CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate;
[0148] Obtaining the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate according to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to each unit time;
[0149] Among them, the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate are obtained through the following formula:
[0150]
[0151] Among them, P represents the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate; n represents the number of unit times experienced by the processing node during operation, and the unit time is 1s; X i represents the value of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to the i-th unit time; X maxi represents the maximum value of the values of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate that have occurred up to the i-th unit time; X bi represents the standard deviation of the value of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to the i-th unit time; X maxbi represents the standard deviation of the maximum value of the values of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate that have occurred up to the i-th unit time;
[0152] Compare the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate with their corresponding preset change degree coefficient thresholds respectively;
[0153] When any one of the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate exceeds its corresponding preset change degree coefficient threshold, determine whether there is abnormal resource utilization in the processing node by using the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate.
[0154] The technical effects of the above technical solution are as follows: By real-time monitoring the node resource occupancy information (CPU occupancy rate, memory occupancy rate, communication bandwidth occupancy rate) per unit time (such as per second), the system can quickly capture the dynamic changes in resource usage. This real-time monitoring mechanism helps to timely discover and handle potential resource utilization problems, ensuring the stable operation of the system or application. By introducing the change degree coefficient P, this solution can quantify the changes in the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate over different unit times. This coefficient not only considers the absolute values of resource occupancy (such as Xi and Xmaxi), but also incorporates the volatility of the values (such as Xbi and Xmaxbi), thus providing a more comprehensive and accurate assessment of the resource utilization change trend. By comparing the calculated change degree coefficient with the preset threshold, this solution can intelligently determine whether there is abnormal resource utilization in the processing node. When the change degree coefficient of any resource exceeds its corresponding threshold, the system can trigger an alarm or take other countermeasures, thus effectively avoiding problems such as resource overload and performance degradation. By real-time monitoring resource occupancy and intelligently detecting anomalies, this solution helps to timely discover and handle potential system bottlenecks or fault points. This not only improves the stability and reliability of the system, but also reduces the risks of system crashes or data loss caused by improper resource utilization. In the long run, this solution also helps to optimize the resource configuration and scheduling. By analyzing the historical resource occupancy data, the system can more accurately predict future resource requirements, thus reasonably allocate resources, improve resource utilization rate, and reduce operating costs.
[0155] In summary, through means such as real-time monitoring, precise evaluation, and intelligent anomaly detection, this technical solution effectively improves the stability, reliability, and resource utilization efficiency of the system, providing strong support for building a high-performance and highly available information system.
[0156] Specifically, the determination of whether there is abnormal resource utilization in the processing node by using the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate includes:
[0157] When any one of the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate exceeds its corresponding preset change degree coefficient threshold, retrieve the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to each unit time;
[0158] Use the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to each unit time to obtain a resource anomaly determination coefficient;
[0159] Among them, the resource anomaly determination coefficient is obtained through the following formula:
[0160]
[0161] Among them, Z represents the resource anomaly determination coefficient; n represents the number of unit times experienced by the processing node during operation, and the unit time is 1s; X ci represents the CPU occupancy rate corresponding to the i-th unit time; X ni represents the memory occupancy rate corresponding to the i-th unit time; X ti represents the communication bandwidth occupancy rate corresponding to the i-th unit time; X cfi represents the maximum change amplitude of the CPU occupancy rate corresponding to the i-th unit time; X nfi represents the maximum change amplitude of the memory occupancy rate corresponding to the i-th unit time; X tfi represents the maximum change amplitude of the communication bandwidth occupancy rate corresponding to the i-th unit time; T ci represents the time interval between the CPU occupancy rate corresponding to the i-th unit time and the maximum CPU occupancy rate; T ni represents the time interval between the memory occupancy rate corresponding to the i-th unit time and the maximum memory occupancy rate; T ti represents the time interval between the communication bandwidth occupancy rate corresponding to the i-th unit time and the maximum communication bandwidth occupancy rate; P ci 、P ni and P ti respectively represent the change degree coefficient of the CPU occupancy rate, the change degree coefficient of the memory occupancy rate, and the change degree coefficient of the communication bandwidth occupancy rate of the i-th unit time
[0162] Compare the resource anomaly determination coefficient with a preset determination coefficient;
[0163] When the resource anomaly determination coefficient exceeds the preset determination coefficient, it is determined that the node has a resource utilization anomaly state and a resource utilization anomaly alarm is issued.
[0164] The technical effects of the above technical solution are as follows: By comprehensively considering the change degrees of CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate, as well as the time intervals between them and their respective maximum values, the resource anomaly determination coefficient Z is introduced to comprehensively evaluate the resource utilization status of the processing node. This comprehensive determination method can more accurately reflect the overall resource utilization of the node than a single indicator, helping to detect potential resource utilization anomalies in a timely manner. By calculating the resource occupancy rate per unit time and the maximum value of its change amplitude, and combining with the time interval from the maximum value, this solution can more precisely capture the abnormal fluctuations of resource utilization. This detailed analysis method reduces the possibilities of false alarms and missed alarms, improving the accuracy of anomaly detection. Once the resource anomaly determination coefficient Z exceeds the preset determination coefficient, the system can immediately trigger an alarm mechanism to notify relevant personnel for handling. This real-time response ability helps to quickly resolve resource utilization anomalies, prevent problems from deteriorating further, and ensure the stability and reliability of the system. Through real-time monitoring and anomaly detection, this solution provides strong data support for resource management and scheduling. The system can dynamically adjust resource allocation according to the resource utilization situation, optimize resource utilization rate, reduce operating costs, and improve system performance. This solution reduces the workload of operation and maintenance personnel by automatically detecting resource utilization anomalies, improving the maintainability of the system. Operation and maintenance personnel can focus more on handling alarm events without frequently manually checking the system status.
[0165] In summary, through aspects such as comprehensively determining the resource utilization status, improving the accuracy of anomaly detection, implementing real-time response and alarm mechanisms, optimizing resource management and scheduling, and enhancing system maintainability, the above technical solution provides a comprehensive and effective solution for the resource utilization management of the processing node. This not only helps to improve the stability and reliability of the system, but also optimizes the resource utilization rate, reduces operating costs, and improves the overall system performance.
[0166] The transaction audit management module includes:
[0167] The data record storage unit is used for:
[0168] recording and storing the key transaction information during the transaction process, where the key transaction information includes transaction time, transaction amount, identities of both parties to the transaction, transaction status, transaction type, and transaction account;
[0169] The transaction behavior audit unit is used for:
[0170] establishing a transaction behavior audit rule library according to industry regulations, organizational internal policies, and historical transaction data, where the transaction behavior audit rule library includes rules for abnormal transaction amounts, high-frequency large transactions, inconsistent transaction time with habits, and sudden changes in transaction patterns;
[0171] The transactions are audited based on the set rules in the transaction behavior audit rule library. If a transaction behavior violates the preset rules, the transaction is marked as an abnormal transaction;
[0172] When an abnormal transaction is identified, the current transaction is marked as a suspicious transaction, and the suspicious transaction information of the suspicious transaction is archived. The suspicious transaction information includes the transaction time, amount, involved accounts, and abnormal behavior characteristics.
[0173] In the above embodiment, traceable transaction auditing is performed through the transaction audit management module, ensuring the legality and compliance of each transaction, detailed recording of all transaction data, and storing it in a secure database to ensure the integrity, immutability, and long-term preservation of transaction records, facilitating future auditing and investigation. By establishing a transaction behavior rule library and performing real-time auditing of transaction behaviors, abnormal transactions can be identified and marked in a timely manner. For transactions that violate the regulations, they are automatically marked as suspicious transactions and archived, facilitating subsequent tracking and investigation. Through flexible audit rules, the supervision and monitoring capabilities of transaction behaviors are effectively improved, providing strong compliance guarantees for the system and accurate data support for financial supervision and risk assessment.
[0174] The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and should be covered by the protection scope of the present invention.
Claims
1. A computer network security transaction optimization system, characterized in that: include: Authentication and authorization modules for: Verify the identities of both parties to the transaction through multiple authentication methods, generate digital certificates for successfully verified users, and authorize and manage the scope of transaction operations based on the user's authority level; Transaction request processing module, used to: Receive and process transaction requests from the user, collaborate with the identity authentication and authorization module, determine whether the transaction request is compliant based on the content and identity authority of the user's request, encrypt sensitive information in the transaction, and check the rationality of the transaction instruction through amount verification and account status verification; Security monitoring and protection module, used for: Monitor network traffic in real time during the transaction process and identify attack behaviors, analyze transaction behavior patterns and identify abnormal transaction requests, encrypt data transmission during the transaction process, and combine with the transaction request processing module to block malicious requests in real time; Trading intelligent optimization module, used for: According to the distribution of transaction traffic, it cooperates with the transaction request processing module to dynamically adjust the processing nodes of transaction requests and the transaction data transmission path, and automatically executes transaction rules based on transaction logic; Transaction audit management module, used for: Audit all transaction processes and record transaction information, identify and mark suspicious transactions; Transaction report analysis module for: Statistic and display transaction data through charts, conduct risk assessment on transaction data, and collaborate with the transaction audit management module to generate transaction reports, which include all transaction records, risk assessment and abnormal behavior analysis; Among them, the transaction intelligent optimization module includes: Node resource anomaly monitoring module, used for: Real-time monitoring of node resource occupancy information corresponding to each unit time, wherein the node resource occupancy information includes CPU occupancy, memory occupancy and communication bandwidth occupancy; According to the CPU occupancy rate, memory occupancy rate and communication bandwidth occupancy rate corresponding to each unit time, the change degree coefficients corresponding to the CPU occupancy rate, the memory occupancy rate and the communication bandwidth occupancy rate are obtained; Compare the change degree coefficients corresponding to the CPU occupancy rate, memory occupancy rate and communication bandwidth occupancy rate with their corresponding preset change degree coefficient thresholds respectively; When any one of the change degree coefficients corresponding to the CPU occupancy rate, the memory occupancy rate and the communication bandwidth occupancy rate exceeds its corresponding preset change degree coefficient threshold, the CPU occupancy rate, the memory occupancy rate and the communication bandwidth occupancy rate are used to determine whether there is a resource utilization abnormality in the processing node; When any one of the variation coefficients corresponding to the CPU occupancy rate, the memory occupancy rate and the communication bandwidth occupancy rate exceeds the corresponding preset variation coefficient threshold, the CPU occupancy rate, the memory occupancy rate and the communication bandwidth occupancy rate corresponding to each unit time are retrieved; The resource anomaly determination coefficient is obtained by using the CPU occupancy rate, memory occupancy rate and communication bandwidth occupancy rate corresponding to each unit time; Comparing the resource anomaly determination coefficient with a preset determination coefficient; When the resource anomaly determination coefficient exceeds a preset determination coefficient, it is determined that the node is in a resource utilization anomaly state, and a resource utilization anomaly alarm is issued.
2. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The identity authentication and authorization module comprises: Multi-factor authentication unit for: When a user initiates a transaction, the user's identity is verified through multiple authentication methods, including password, dynamic token, and facial recognition. Analyze the user's historical behavior patterns during the multi-factor authentication process, including typing speed and transaction habits, and trigger additional authentication when abnormal behavior is detected, including requiring the input of additional security question answers; If both the multi-factor authentication and the additional authentication steps are passed, the identity verification is considered successful; After verification, a digital certificate is generated according to the user's authority level, and authority authorization management is performed; The permission authorization management unit is used to: Based on the user's identity authentication results and preset permission policies, the user's transaction permissions are dynamically allocated and a digital certificate is generated. When the user initiates a transaction request, the user's permissions are checked.
3. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The transaction request processing module includes: The transaction request checking unit is used to: Receive a transaction request from a user, extract key information from the transaction request, including transaction amount, transaction type, transaction account, and payee information, and perform compliance checks on the request content; Check the status of the account initiating the transaction to ensure that the account is active and has no abnormal freezing or restrictions; Verify the transaction amount according to the preset transaction limit rules; Verify whether the transaction request meets compliance requirements based on preset transaction rules and laws and regulations; If the transaction request meets all the verification rule checks, the transaction request will be marked as a legal request and continue to be processed. Otherwise, the transaction will be rejected and an error message will be fed back; Information encryption protection unit, used for: Identify and mark all sensitive information in the transaction request as data to be encrypted, including account information, transaction amount, and user identity; Encrypt the data to be encrypted using a combination of symmetric encryption and asymmetric encryption; During the transaction process, the encrypted data is checked for integrity.
4. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The security monitoring and protection module includes: Network monitoring and identification unit, used for: By monitoring network traffic in real time, capturing data packets in transaction requests, and analyzing the source, destination, size, frequency, and protocol characteristics of the data packets, the system can identify and detect potential attack behaviors by analyzing the source IP address, request frequency, and pattern of network traffic. When the system detects potential attack behaviors, it triggers the protection mechanism and temporarily restricts and intercepts requests from the attack source IP. Transaction Behavior Analysis Unit, used to: By analyzing the user's historical transaction data, a behavior model for each user is established, wherein the behavior model includes transaction amount, transaction frequency, transaction time, transaction type, and characteristics of the payee, and the user's normal transaction behavior pattern is extracted based on the behavior model; When a user initiates a transaction, the current transaction behavior characteristics are analyzed in real time and compared with the user's normal transaction behavior pattern; If the current transaction behavior characteristics are significantly different from the user's normal transaction behavior pattern, the current transaction will be marked as an abnormal transaction. The significant differences include abnormally large transactions, frequent small transactions, and transaction times that are inconsistent with the user's normal transaction behavior pattern.
5. A computer network security transaction optimization system as claimed in claim 4, characterized in that: The security monitoring and protection module further includes: Anomaly detection unit, used to: When the transaction behavior analysis unit detects abnormal transaction behavior, a protection mechanism is automatically triggered, which includes limiting the transaction amount, requiring users to perform additional identity verification, freezing accounts, and suspending transactions; At the same time, an alarm message is sent to the security administrator; Record abnormal transaction data marked as abnormal transactions and send them to the transaction audit management module.
6. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The transaction intelligent optimization module includes: The transaction request scheduling unit is used to: Monitor the workload data and current transaction flow data of each processing node in real time, and collect the response time, processing capacity, and resource usage information of each node; When a new transaction request arrives, it distributes the transaction request among multiple available nodes based on the current transaction flow data. When it is detected that the load of the processing node exceeds the set threshold, the new transaction request is automatically allocated to the node with low load; When the volume of transaction requests increases and the network condition becomes unstable, backup processing nodes are automatically enabled and node configurations are dynamically adjusted.
7. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The variation coefficients corresponding to the CPU occupancy rate, memory occupancy rate and communication bandwidth occupancy rate are obtained by the following formula: Where P represents the coefficient of variation of CPU occupancy, memory occupancy and communication bandwidth occupancy; n represents the number of unit time experienced by the processing node, and the unit time is 1s; X i represents the value of CPU occupancy, memory occupancy and communication bandwidth occupancy corresponding to the i-th unit time; X maxi represents the maximum value of CPU occupancy, memory occupancy and communication bandwidth occupancy at the i-th unit time; X bi represents the standard deviation of the CPU occupancy rate, memory occupancy rate, and communication bandwidth occupancy rate corresponding to the i-th unit time; X maxbi It represents the standard deviation of the maximum values of CPU utilization, memory utilization, and communication bandwidth utilization that occur in the i-th unit time.
8. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The resource anomaly determination coefficient is obtained by the following formula: Where Z represents the resource anomaly determination coefficient; n represents the number of unit times experienced by the processing node, and the unit time is 1s; X ci Indicates the CPU occupancy rate corresponding to the i-th unit time; X ni represents the memory usage corresponding to the i-th unit time; X ti represents the communication bandwidth occupancy rate corresponding to the i-th unit time; X cfi Indicates the maximum change of CPU usage corresponding to the i-th unit time; X nfi Indicates the maximum change of memory usage rate corresponding to the i-th unit time; X tfi represents the maximum change amplitude of the communication bandwidth occupancy rate corresponding to the i-th unit time; T ci represents the time interval between the CPU usage rate corresponding to the i-th unit time and the maximum CPU usage rate; T ni represents the time interval between the memory usage rate corresponding to the i-th unit time and the maximum memory usage rate; T ti represents the time interval between the communication bandwidth occupancy rate corresponding to the i-th unit time and the maximum communication bandwidth occupancy rate; P ci , P ni and P ti They respectively represent the coefficient of change of CPU occupancy, memory occupancy and communication bandwidth occupancy in the ith unit time.
9. A computer network security transaction optimization system as claimed in claim 6, characterized in that: The transaction intelligent optimization module includes: The transaction path adjustment unit is used to: When receiving a transaction request, the transmission requirements of the transaction data are evaluated based on the transaction type, amount, and location of the two parties. For sensitive transactions, a highly secure transmission path is selected. For normal transactions, the transmission path is optimized based on the latency requirements. For critical and high-risk transactions, data is transmitted simultaneously through multiple secure paths. Monitor the health status and transmission quality of network links in real time to determine whether the current network is congested, bandwidth limited, or subject to malicious attack risks. Automatically switch transmission paths when the quality of the transmission path degrades or is attacked.
10. A computer network security transaction optimization system as claimed in claim 1, characterized in that: The transaction audit management module includes: Data logging storage unit for: Record and store key transaction information during the transaction process, including transaction time, transaction amount, identities of both parties to the transaction, transaction status, transaction type, and transaction account; Transaction behavior audit unit, used to: Establish a transaction behavior audit rule base based on industry regulations, internal organizational policies, and historical transaction data. The transaction behavior audit rule base includes rules for abnormal transaction amounts, large transaction frequencies, transaction times that are inconsistent with habits, and transaction pattern mutations; Audit transactions based on the set rules in the transaction behavior audit rule base. If the transaction behavior violates the preset rules, the transaction will be marked as an abnormal transaction. When an abnormal transaction is identified, the current transaction is marked as a suspicious transaction, and the suspicious transaction information of the suspicious transaction is archived. The suspicious transaction information includes the transaction time, amount, accounts involved, and abnormal behavior characteristics.
Citation Information
Patent Citations
Big data acquisition and processing method and system based on Internet of Things
CN118573733A
Financial transaction security verification system and method based on block chain
CN118733281A
Internet data security protection method and system based on intelligent algorithm
CN119272339A
Intelligent risk control system and method for cross-border e-commerce digitization
CN119398479A