A financial risk warning method and system based on big data technology
Through real-time monitoring and dynamic analysis of financial user transaction behavior, combined with intelligent algorithms and risk assessment models, the problem of lack of flexibility and real-time nature of traditional financial risk warning methods is solved, and more efficient and accurate financial risk warning is achieved.
Patent Information
- Application Number
- CN202411827861.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-12-12
AI Technical Summary
Traditional financial risk warning methods are difficult to cope with the rapidly changing market environment and complex user behavior, and are prone to false alarms or missed alarms, and lack flexibility and real-time.
Through real-time monitoring, analysis and clustering of financial users' trading behaviors, potential risk characteristics are identified, combined with intelligent algorithms and risk assessment models for dynamic analysis, a transaction operation risk assessment model is built, transaction operation risks are evaluated in real time, and preventive measures are taken before risks occur.
It improves the accuracy of risk identification and can take preventive measures before risks occur, effectively reduce financial risks and improve the security and response capabilities of financial institutions.
Smart Images

Figure CN119624661B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of risk early warning, and particularly to a financial risk early warning method and system based on big data technology. Background Art
[0002] With the rapid development of the financial market and the diversification of financial transaction methods, the risks of financial transactions are increasing day by day. Especially in emerging fields such as Internet finance and online payment, the complexity and diversity of financial transaction behaviors have posed many challenges to traditional financial risk assessment and early warning methods. Traditional financial risk early warning methods usually rely on static rules and historical data analysis. These methods are difficult to cope with the rapidly changing market environment and complex user behaviors, and are prone to false alarms or missed alarms, lacking flexibility and real-time performance.
[0003] In recent years, with the continuous development of big data technology, the financial industry has gradually introduced risk analysis means based on big data. By deeply mining and analyzing the behavior data of financial users, potential risk factors can be identified for more accurate risk assessment and early warning. However, the application of existing big data technology in financial risk early warning still has certain limitations. For example, how to efficiently and accurately identify potential risks in user transaction behaviors, how to dynamically adjust the risk assessment model according to real-time data, and how to reduce manual intervention and improve the automation level of the system are still problems to be solved urgently.
[0004] Therefore, the present invention proposes a financial risk early warning method and system based on big data technology. By real-time monitoring, analyzing and clustering the transaction behaviors of financial users, potential risk characteristics are identified therefrom, and dynamic analysis is carried out in combination with intelligent algorithms and risk assessment models, in order to achieve more efficient and accurate financial risk early warning. This method can not only improve the accuracy of risk identification, but also take preventive measures before the occurrence of risks, thereby effectively reducing financial risks and enhancing the security and response capabilities of financial institutions. Summary of the Invention
[0005] In order to solve at least one of the above technical problems, the present invention proposes a financial risk early warning method and system based on big data technology.
[0006] In the first aspect of the present invention, a financial risk early warning method based on big data technology is provided, including:
[0007] Obtaining historical operation record data of a financial user according to a target financial server, and extracting historical operation path data of the financial user according to the historical operation record data;
[0008] Performing a clustering operation on the historical operation path data according to a clustering algorithm to obtain a clustering result of operation records;
[0009] Identify the transaction operation path characteristics of financial users under different transaction types based on the clustering results of the operation records;
[0010] Construct a transaction operation risk assessment model for financial users based on the transaction operation path characteristics, perform transaction operation path deviation analysis on the real-time transaction operation behavior of financial users according to the transaction operation risk assessment model, calculate the deviation degree of the real-time transaction operation behavior of financial users, and conduct transaction operation risk assessment according to the real-time transaction operation behavior deviation degree;
[0011] If the transaction operation risk is greater than the preset risk value, mark the financial user as a risk user, conduct a secondary confirmation of the transaction risk for the risk user, conduct a financial risk early warning according to the results of the secondary confirmation of the transaction risk, and construct a financial risk early warning strategy.
[0012] In this solution, obtaining the historical operation record data of financial users according to the target financial server and extracting the historical operation path data of financial users according to the historical operation record data are specifically as follows:
[0013] Obtain the historical operation record data of financial users according to the target financial server, and the historical operation record data includes browsing records, financial consultation records, and transaction records;
[0014] Sort the historical operation record data according to the time stamp, construct historical operation record time series data, and perform data segmentation on the historical operation record time series data according to the transaction record time points to obtain historical operation record data segments;
[0015] Construct an operation record directed graph from the historical operation record data segments, and extract the historical operation path data of financial users according to the operation record directed graph.
[0016] In this solution, clustering the historical operation path data according to the clustering algorithm to obtain the clustering results of the operation records is specifically as follows:
[0017] Set the clustering weights of each operation record in the historical operation path data, calculate the Euclidean distance between each pair of historical operation paths in the historical operation path data, and calculate the similarity between historical operation paths according to the Euclidean distance and the clustering weights;
[0018] Construct a similarity matrix according to the similarity, calculate the diagonal matrix of the similarity matrix, construct a Laplacian matrix according to the similarity matrix and the diagonal matrix, perform eigenvalue decomposition on the Laplacian matrix, and find the eigenvectors corresponding to the smallest k eigenvalues;
[0019] Construct a feature matrix based on the eigenvectors corresponding to the k eigenvalues, randomly select k data points from the feature matrix as the initial centroids, calculate the Euclidean distances from each data point in the feature matrix to each initial centroid, and assign each data point to the cluster where the nearest initial centroid is located;
[0020] Iteratively update the cluster centers and recalculate the updated Euclidean distances from each data to the updated cluster centers, and perform data point assignment according to the updated Euclidean distances until the cluster centers no longer change, obtaining the clustering result of the operation records.
[0021] In this solution, the identification of the trading operation path features of financial users under different trading types according to the clustering result of the operation records is specifically as follows:
[0022] Extract the trading types to which each clustering result belongs according to the clustering result of the operation records, and construct the trading operation paths of the trading types to which each clustering result belongs according to the clustering result of the operation records, obtaining the trading operation path features;
[0023] Repeatedly identify the trading operation path features, judge whether there are multiple trading operation path features for each trading type, mark the trading types with multiple trading operation path features, and extract the multiple trading operation path features of the marked trading types as the trading operation path features to be merged;
[0024] Calculate the proportion of the quantity of each trading operation path feature to be merged in the clustering result of the operation records according to the clustering result of the operation records, and use the trading operation path feature with the largest proportion of the quantity as the benchmark trading operation path feature, and the remaining trading operation path features to be merged are marked as candidate trading operation path features;
[0025] Preset the minimum support threshold for path feature merging, obtain the operation record elements included in the candidate trading operation path features, calculate the occurrence frequency of each operation record element in the trading operation path features to be merged, and evaluate the support of the operation record elements according to the occurrence frequency;
[0026] Compare the support of the operation record elements with the minimum support threshold, and mark the operation record elements whose support is greater than the minimum support threshold and are not included in the benchmark trading operation path feature as candidate frequent sub-features;
[0027] Based on the Apriori algorithm, perform hierarchical search on the trading operation path features to be merged, analyze the occurrence probability of the candidate frequent sub-features after each operation record in the benchmark trading operation path feature, and determine the insertion position of the candidate frequent sub-features in the benchmark trading operation path feature according to the occurrence probability;
[0028] Merge the reference transaction operation path feature and the candidate frequent sub - feature according to the insertion position to obtain the transaction operation path feature of the financial user under different transaction types.
[0029] In this solution, construct a transaction operation risk assessment model for financial users based on the transaction operation path feature, perform transaction operation path deviation analysis on the real - time transaction operation behavior of financial users according to the transaction operation risk assessment model, calculate the deviation degree of the real - time transaction operation behavior of financial users, and perform transaction operation risk assessment according to the real - time transaction operation behavior deviation degree. Specifically:
[0030] Construct operation state transition pairs for the transaction operation path feature based on the Markov chain, calculate the operation transition probability between operation state transition pairs according to the historical operation path data, and construct an operation state transition matrix according to the operation transition probability;
[0031] Construct a transaction operation risk assessment model for financial users according to the operation state transition matrix, and construct a data link channel between the transaction operation risk assessment model and the target financial server based on big data technology. The data link channel includes a data interface between the target financial server and the transaction operation risk assessment model and a data cleaning module;
[0032] Import the real - time transaction operation behavior data of financial users on the target financial server into the transaction operation risk assessment model according to the data link channel, calculate the operation state transition probability between adjacent operation behaviors in the real - time transaction operation behavior data, and calculate the comprehensive operation transition probability of the real - time transaction operation behavior data according to the operation state transition probability between adjacent operation behaviors;
[0033] Calculate the deviation degree between the real - time transaction operation behavior of the financial user and the transaction operation path feature according to the comprehensive operation transition probability of the real - time transaction operation behavior data, and perform risk assessment on the real - time transaction operation of the financial user based on the transaction operation risk assessment model according to the deviation degree to obtain the transaction operation risk assessment result.
[0034] In this solution, if the transaction operation risk is greater than the preset risk value, mark the financial user as a risk user, perform a secondary confirmation of the transaction risk on the risk user, perform financial risk early warning according to the result of the secondary confirmation of the transaction risk, and construct a financial risk early warning strategy. Specifically:
[0035] According to the transaction operation risk assessment result, if the transaction operation risk is greater than the preset risk value, mark the financial user as a risk user, and obtain the transaction change information of the risk user within a preset time period. The transaction change information includes changes in transaction frequency and transaction amount;
[0036] Comprehensively analyze the transaction change information and the transaction operation path characteristics, judge the change situation of the transaction change information to the transaction operation path characteristics, update the transaction operation path characteristics according to the change situation, and perform a secondary risk assessment on the real-time transaction operation behavior of the risk user based on the updated transaction operation path characteristics;
[0037] If the transaction operation risk of the secondary risk assessment is still greater than the preset risk value, compare the real-time transaction operation behavior data of the risk user with the transaction operation path characteristics, identify the missing operations in the real-time transaction operation behavior of the risk user, generate a warning message for the missing operations and perform a warning reminder operation on the risk user to obtain a user warning plan;
[0038] Obtain the transaction IP address information of the risk user and the credit rating information of the transaction object, determine the risk level of the risk user according to the transaction IP address information and the credit rating information of the transaction object, generate a warning message according to the risk level and perform a warning operation on the target financial institution to obtain an institution warning plan;
[0039] Construct a financial risk warning strategy according to the user warning plan and the institution warning plan.
[0040] The second aspect of the present invention also provides a financial risk warning system based on big data technology. The system includes: a memory and a processor. The memory includes a financial risk warning method program based on big data technology. When the financial risk warning method program based on big data technology is executed by the processor, the following steps are implemented:
[0041] Obtain the historical operation record data of the financial user according to the target financial server, and extract the historical operation path data of the financial user according to the historical operation record data;
[0042] Perform a clustering operation on the historical operation path data according to the clustering algorithm to obtain an operation record clustering result;
[0043] Identify the transaction operation path characteristics of the financial user under different transaction types according to the operation record clustering result;
[0044] Construct a transaction operation risk assessment model for the financial user according to the transaction operation path characteristics, perform a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculate the real-time transaction operation behavior deviation degree of the financial user, and perform a transaction operation risk assessment according to the real-time transaction operation behavior deviation degree;
[0045] If the trading operation risk is greater than the preset risk value, mark the financial user as a risk user, conduct a secondary confirmation of the trading risk for the risk user, and issue a financial risk warning according to the result of the secondary confirmation of the trading risk, and construct a financial risk warning strategy.
[0046] The present invention discloses a financial risk warning method and system based on big data technology, aiming to evaluate and warn risks in real time by analyzing the trading behaviors of financial users. The method includes: obtaining the historical operation records of financial users and extracting operation path data; using a clustering algorithm to cluster the historical operation path data to identify the operation path characteristics under different trading types; constructing a trading risk assessment model to analyze the deviation degree of real-time trading behaviors; evaluating risks according to the deviation degree, and if the risk exceeds the preset value, mark the user as a risk user and conduct a secondary confirmation; finally, trigger a risk warning mechanism and formulate a warning strategy. The system includes data collection, processing, evaluation, warning, and execution modules, which work together to achieve real-time monitoring and risk warning. The invention can accurately identify abnormal trading behaviors, improve the intelligence and automation levels of financial risk management, and has a wide application prospect in the financial field. Brief Description of the Drawings
[0047] Figure 1 Shows a flowchart of a financial risk warning method based on big data technology according to the present invention;
[0048] Figure 2 Shows a flowchart of extracting the historical operation path data of financial users according to the present invention;
[0049] Figure 3 Shows a flowchart of conducting trading operation risk assessment according to the present invention;
[0050] Figure 4 Shows a block diagram of a financial risk warning system based on big data technology according to the present invention. Detailed Embodiments
[0051] In order to more clearly understand the above objects, features, and advantages of the present invention, the present invention will be further described in detail below with reference to the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.
[0052] Many specific details are set forth in the following description in order to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0053] Figure 1 Shows a flowchart of a financial risk warning method based on big data technology according to the present invention.
[0054] As Figure 1 shown, the first aspect of the present invention provides a financial risk warning method based on big data technology, including:
[0055] S102, obtaining historical operation record data of a financial user according to a target financial server, and extracting historical operation path data of the financial user according to the historical operation record data;
[0056] S104, performing a clustering operation on the historical operation path data according to a clustering algorithm to obtain a clustering result of operation records;
[0057] S106, identifying transaction operation path characteristics of a financial user under different transaction types according to the clustering result of operation records;
[0058] S108, constructing a transaction operation risk assessment model according to the transaction operation path characteristics, performing a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculating the deviation degree of the real-time transaction operation behavior of the financial user, and performing a transaction operation risk assessment according to the deviation degree of the real-time transaction operation behavior;
[0059] S110, if the transaction operation risk is greater than a preset risk value, marking the financial user as a risk user, performing a secondary confirmation of the transaction risk on the risk user, performing a financial risk warning according to the result of the secondary confirmation of the transaction risk, and constructing a financial risk warning strategy.
[0060] It should be noted that by obtaining the historical operation record data of financial users (such as browsing records, transaction records, consultation records, etc.) from the target financial server, the trading behaviors and historical operation paths of users can be comprehensively understood. By extracting the historical operation path data of users, through the extraction of structured and unstructured data, the operation trajectories of users on the financial platform can be comprehensively reflected, forming high-quality input data. Applying a clustering algorithm to cluster the historical operation path data can automatically identify different patterns of users' trading behaviors. The clustering results classify similar trading behaviors into one category, which helps to simplify the complex trading behavior data into an easily analyzable category structure. This clustering process can reveal the typical operation paths of different users in different trading scenarios; by identifying the operation path characteristics of financial users under different trading types, the behavior habits and preferences of users in specific trading scenarios can be further analyzed. This identification process helps to reveal the normal trading patterns of users and provides benchmark data for subsequent risk analysis. If the behaviors of certain users deviate from the normal patterns, they will be detected in a timely manner; constructing a trading operation risk assessment model can combine the operation path characteristics of users with the risk assessment criteria of the financial industry to form a personalized risk prediction tool, monitor users' trading behaviors in real time, and conduct deviation analysis, which can detect the deviation between users' real-time operations and historical normal patterns. This deviation analysis is based on big data technology and machine learning algorithms, and can efficiently and accurately identify potential abnormal trading behaviors and discover possible risks in a timely manner; by calculating the deviation degree of real-time trading operation behaviors, the risk degree of users' operations can be accurately quantified. The deviation degree reflects the difference between users' current trading behaviors and the normal operation paths. The larger the deviation degree, the higher the risk of trading behaviors. When the risk of trading operations exceeds the set threshold, the user is marked as a "risk user" for secondary confirmation. After further verifying the authenticity of the trading risk through the secondary confirmation results, a financial risk warning can be effectively triggered. An automated risk warning mechanism is realized, and financial institutions can take necessary countermeasures (such as suspending trading, freezing accounts, etc.) in a timely manner according to the warning strategy to reduce possible financial losses.
[0061] Figure 2 The flowchart showing the extraction of the historical operation path data of financial users according to the present invention is shown.
[0062] According to an embodiment of the present invention, the obtaining of the historical operation record data of financial users from the target financial server and the extraction of the historical operation path data of financial users according to the historical operation record data are specifically as follows:
[0063] S202, obtaining the historical operation record data of financial users from the target financial server, where the historical operation record data includes browsing records, financial consultation records, and transaction records;
[0064] S204. Sort the historical operation record data according to the timestamp to construct historical operation record time series data, and perform data segmentation on the historical operation record time series data according to the transaction record time points to obtain historical operation record data segments;
[0065] S206. Construct an operation record directed graph from the historical operation record data segments, and extract the historical operation path data of the financial user according to the operation record directed graph.
[0066] It should be noted that sorting the operation record data according to the timestamp can reconstruct the real behavior path of the user and form logically clear time series data. Through the arrangement of the time dimension of the data, the sequence of the user's operations can be clearly presented. Splitting the sorted time series data according to the time points of the transaction records can group the relevant operations with the transaction as the core and form independent historical operation record data segments. This splitting method directly associates the user's operation behavior with the specific transaction behavior, improving the pertinence of the data; by converting the data segments into an operation record directed graph, the path and flow of the user's operations can be intuitively presented in a graph structure. The directed graph can describe the association relationship and its sequence between operation nodes (such as browsing, consulting, trading), revealing the operation logic of the user. The browsing record includes the browsing content and browsing duration; the financial consulting record includes the consulting time, consulting type, and consulting channel; the transaction record includes the transaction type, transaction time, transaction object, transaction method, and transaction amount. The data segmentation operation is to, after each transaction is completed by the financial user, split the operations between the current transaction record and the previous transaction record into operation record data segments. For example, if the user performs financial operations such as browsing financial information and conducting financial consultations within a preset time period after completing a transaction and then conducts a financial transaction, then the browsing of financial information, financial consultations, and financial transactions within the preset time period are split into the same operation record data segment. Each historical operation record data segment represents the operations performed before and after the transaction.
[0067] According to an embodiment of the present invention, the clustering operation is performed on the historical operation path data according to the clustering algorithm to obtain an operation record clustering result, specifically:
[0068] Set the clustering weight of each operation record in the historical operation path data, calculate the Euclidean distance between each pair of historical operation paths in the historical operation path data, and calculate the similarity between the historical operation paths according to the Euclidean distance and the clustering weight;
[0069] Construct a similarity matrix based on the said similarity, calculate the diagonal matrix of the similarity matrix, construct a Laplacian matrix based on the similarity matrix and the diagonal matrix, perform eigenvalue decomposition on the Laplacian matrix, and find the eigenvectors corresponding to the smallest k eigenvalues;
[0070] Construct a feature matrix based on the eigenvectors corresponding to the k eigenvalues, randomly select k data points from the feature matrix as the initial centroids, calculate the Euclidean distances from each data point in the feature matrix to each initial centroid, and assign each data point to the cluster where the nearest initial centroid is located;
[0071] Iteratively update the cluster centers and recalculate the updated Euclidean distances from each data to the updated cluster centers, and perform data point assignment according to the updated Euclidean distances until the cluster centers no longer change, to obtain the clustering result of operation records.
[0072] It should be noted that by setting a clustering weight for each operation record, the influence of each operation in the clustering process can be adjusted according to the importance or frequency of different operations. This enables the clustering result to more accurately reflect the actual characteristics of user behavior, while avoiding the excessive interference of a small number of unimportant operation records on the clustering result; by calculating the similarity between historical operation paths, constructing a similarity matrix and a Laplacian matrix, and performing eigenvalue decomposition on the Laplacian matrix, the potential structure of data can be identified in a high-dimensional space, helping to distinguish the internal differences of different user groups, avoiding the problems of over-clustering or misclassification that may occur in traditional clustering methods, and improving the accuracy of clustering; by randomly selecting initial centroids from the feature matrix and calculating the Euclidean distances from data points to each centroid, effective initial clustering assignment can be achieved. By iteratively updating the cluster centers and recalculating the Euclidean distances between data points and the updated cluster centers, the clustering result can be continuously optimized to ensure that each data point is assigned to the cluster that is most similar to it. As the cluster centers are gradually adjusted, the clustering result will gradually converge to the optimal state.
[0073] According to an embodiment of the present invention, the identifying the transaction operation path characteristics of financial users under different transaction types according to the clustering result of operation records is specifically as follows:
[0074] Extract the transaction type to which each clustering result belongs according to the clustering result of operation records, construct the transaction operation path of the transaction type to which each clustering result belongs according to the clustering result of operation records, and obtain the transaction operation path characteristics;
[0075] Perform repeated identification on the transaction operation path characteristics, judge whether there are multiple transaction operation path characteristics for each transaction type, mark the transaction types with multiple transaction operation path characteristics, and extract the multiple transaction operation path characteristics of the marked transaction types as the transaction operation path characteristics to be merged;
[0076] Calculate the proportion of the number of each operation path feature of the transactions to be merged in the clustering result of operation records, and take the operation path feature of the transaction to be merged with the largest proportion as the benchmark transaction operation path feature, and label the remaining operation path features of the transactions to be merged as candidate transaction operation path features;
[0077] Preset the minimum support threshold for path feature merging, obtain the operation record elements included in the candidate transaction operation path features, calculate the occurrence frequency of each operation record element in the operation path features of the transactions to be merged, and evaluate the support of the operation record element according to the occurrence frequency;
[0078] Compare the support of the operation record element with the minimum support threshold, and label the operation record element whose support is greater than the minimum support threshold and is not included in the benchmark transaction operation path feature as a candidate frequent sub-feature;
[0079] Based on the Apriori algorithm, perform hierarchical search on the operation path features of the transactions to be merged, analyze the occurrence probability of the candidate frequent sub-features after each operation record in the benchmark transaction operation path feature, and determine the insertion position of the candidate frequent sub-features in the benchmark transaction operation path feature according to the occurrence probability;
[0080] According to the insertion position, perform a merging operation on the benchmark transaction operation path feature and the candidate frequent sub-feature to obtain the transaction operation path features of financial users under different transaction types.
[0081] It should be noted that when financial users conduct transactions, their behaviors may exhibit multiple path characteristics. Especially when users conduct multiple transactions or involve multiple transaction types, the operation paths will show inconsistencies. For example, in different transaction types such as stock trading, fund purchase, and credit card repayment, the operation paths of users may vary significantly. By merging multiple transaction path characteristics, especially the method based on the merger of frequent sub-characteristics (such as the Apriori algorithm), the core characteristics of the transaction path can be retained and unnecessary diversity can be removed, so that the merged operation path characteristics can more comprehensively represent the risk pattern of this transaction type. By judging whether there are multiple transaction operation path characteristics for each transaction type and merging the transaction types with multiple path characteristics, the diverse behavior patterns of users under this transaction type can be captured more accurately. For example, some users may perform different types of operations at different times, or the behaviors of the same user may vary under multiple transaction types. By merging multiple path characteristics, the model can more comprehensively reflect the transaction characteristics of users, thereby enhancing the representativeness of the transaction operation path characteristics. If there are multiple path characteristics (such as high-frequency trading, low-frequency trading, etc.) under a certain transaction type, through merging, the system can extract the common parts in these paths and consider them uniformly, avoiding interference from excessive individual differences to risk assessment, so as to more accurately identify and evaluate risks. The support degree is used to measure the universality or occurrence frequency of a certain item set or rule in the entire dataset. The higher the support degree, the higher the occurrence frequency; the candidate frequent sub-characteristics refer to the sub-characteristics with potential frequent occurrence rules identified when merging multiple transaction operation path characteristics; the Apriori algorithm is an association rule learning algorithm; the transaction operation path characteristics refer to an operation mode or trajectory formed by users according to their historical transaction behaviors (such as purchase, transfer, consultation, etc.) during the financial transaction process. These modes reflect the behavior paths and preferences of users in different transaction types. By analyzing the historical operation data of financial users, these path characteristics can be extracted and used to analyze the risk status, behavior deviation, etc. of users.
[0082] Figure 3 Fig. shows the flowchart of the transaction operation risk assessment of the present invention.
[0083] According to an embodiment of the present invention, the transaction operation risk assessment model of financial users is constructed according to the transaction operation path characteristics, the transaction operation path deviation analysis is performed on the real-time transaction operation behavior of financial users according to the transaction operation risk assessment model, the deviation degree of the real-time transaction operation behavior of financial users is calculated, and the transaction operation risk assessment is performed according to the real-time transaction operation behavior deviation degree. Specifically:
[0084] S302. Based on the Markov chain, construct operation state transition pairs for the transaction operation path features, calculate the operation transition probabilities between the operation state transition pairs according to the historical operation path data, and construct an operation state transition matrix according to the operation transition probabilities;
[0085] S304. Construct a transaction operation risk assessment model for financial users according to the operation state transition matrix, and construct a data link channel between the transaction operation risk assessment model and the target financial server based on big data technology. The data link channel includes a data interface between the target financial server and the transaction operation risk assessment model and a data cleaning module;
[0086] S306. Import the real-time transaction operation behavior data of the financial users of the target financial server into the transaction operation risk assessment model according to the data link channel, calculate the operation state transition probabilities between adjacent operation behaviors in the real-time transaction operation behavior data, and calculate the comprehensive operation transition probability of the real-time transaction operation behavior data according to the operation state transition probabilities between the adjacent operation behaviors;
[0087] S308. Calculate the deviation between the real-time transaction operation behavior of the financial user and the transaction operation path features according to the comprehensive operation transition probability of the real-time transaction operation behavior data, and perform a risk assessment on the real-time transaction operation of the financial user based on the transaction operation risk assessment model according to the deviation to obtain a transaction operation risk assessment result.
[0088] It should be noted that by using a Markov chain to describe the state transition of the trading operation path, the time series characteristics of user behavior can be accurately captured. The Markov chain can infer the transition probability of each operation in the trading operation path characteristics of the user based on historical operation path data. Using the operation state transition matrix, a risk assessment model of financial user behavior can be constructed to accurately identify the normal behavior trajectory and deviation behavior of the user. By comparing the real-time trading operation behavior with the historical operation path characteristics, the deviation degree can be calculated to immediately discover whether the user's operation is inconsistent with their conventional behavior pattern. If it is found that the user's real-time operation deviates from the normal path, the system will promptly conduct a risk assessment and generate a warning. By combining big data technology and the real-time data link channel of the Markov chain, the risk assessment model can adaptively adjust in a changing market environment. By continuously monitoring the trading behavior data of the user, the model can be updated in a timely manner and the assessment results can be adjusted according to the new data, thereby improving the accuracy and timeliness of risk assessment. Through the comprehensive calculation of the operation state transition probability, a comprehensive risk score can be provided for each trading operation behavior, which not only considers the operation path characteristics of the user but also comprehensively considers the relative relationship between different operations. This multi-dimensional assessment can help financial institutions more comprehensively analyze whether there are abnormalities in the trading behavior of users. By comparing the real-time operation behavior of the user with the normal pattern of their historical trading operation path, potential risks can be quickly detected when the user exhibits unusual trading behavior. For example, if a user who has been operating stably for a long time suddenly shows high-frequency and large-amount transactions, the system will calculate the comprehensive probability of operation transfer and detect the deviation degree to promptly warn of the risk. The operation transfer probability refers to the probability that a financial user transfers from one operation state to another within a specific time interval. The real-time trading operation behavior data includes the real-time trading type of the financial user and the browsing record and financial consultation record data within a preset time period.
[0089] According to an embodiment of the present invention, if the trading operation risk is greater than a preset risk value, the financial user is marked as a risk user, and a secondary confirmation of the trading risk is performed on the risk user. According to the result of the secondary confirmation of the trading risk, a financial risk warning is issued, and a financial risk warning strategy is constructed, specifically as follows:
[0090] According to the trading operation risk assessment result, if the trading operation risk is greater than a preset risk value, the financial user is marked as a risk user, and the trading change information of the risk user within a preset time period is obtained. The trading change information includes the change in trading frequency and the change in trading amount.
[0091] Comprehensively analyze the transaction change information and the characteristics of the transaction operation path, judge the change of the transaction change information on the characteristics of the transaction operation path, update the characteristics of the transaction operation path according to the change situation, and conduct a secondary risk assessment on the real-time transaction operation behavior of the risk user based on the updated characteristics of the transaction operation path;
[0092] If the transaction operation risk of the secondary risk assessment is still greater than the preset risk value, compare the real-time transaction operation behavior data of the risk user with the characteristics of the transaction operation path, identify the missing operations in the real-time transaction operation behavior of the risk user, generate warning information for the missing operations to conduct a warning reminder operation on the risk user, and obtain a user warning plan;
[0093] Obtain the transaction IP address information of the risk user and the credit rating information of the transaction object, determine the risk level of the risk user according to the transaction IP address information and the credit rating information of the transaction object, generate warning information according to the risk level to conduct a warning operation on the target financial institution, and obtain an institution warning plan;
[0094] Construct a financial risk warning strategy according to the user warning plan and the institution warning plan.
[0095] It should be noted that through the analysis of the transaction operation risk assessment results, if the transaction operation risk of a financial user is greater than the preset risk value, the user can be immediately identified as a risk user. After being marked as a risk user, the system not only relies on the preliminary risk assessment results, but also dynamically monitors the change trend of the user's behavior by obtaining transaction change information such as the change of the user's transaction frequency and transaction amount. This method makes the risk assessment more flexible and real-time, can respond to the change of the user's behavior in a timely manner, and update the characteristics of the transaction operation path. Through this continuously updated dynamic assessment mechanism, the system can more accurately assess and predict the potential risks of users, reduce misjudgments, and further improve the accuracy and credibility of the behavior of risk users through the secondary risk assessment of the updated characteristics of the transaction operation path; after the secondary risk assessment, if the risk of the user still exceeds the preset threshold, the system can identify the missing operations by comparing the real-time transaction operation behavior of the user and the historical path characteristics. The missing operations may mean abnormal behavior of the user or potential fraud behavior, and this feature helps to identify those unreasonable or hidden risk behaviors. By generating warning information in a timely manner, the system can send a risk reminder to the financial institution or the user. By combining the user's transaction behavior with multi-dimensional data such as their IP information and the credit rating of the transaction object, the system can more comprehensively and accurately assess the risk level of the user. The transaction IP address information helps to identify whether there are abnormal operations of the user across regions or in high-risk areas, and the credit rating of the transaction object helps to judge whether the interaction between the user and high-risk customers increases the potential financial risks.
[0096] According to an embodiment of the present invention, it further includes:
[0097] Construct a network monitoring system for the target financial server, obtain the data transmission traffic of the target financial server in real time according to the network monitoring system, and construct network transmission data packets according to the data transmission traffic. The network transmission data packets include network traffic fluctuation data, repeated access data, and abnormal data packets;
[0098] Construct a network abnormal behavior detection model based on the isolation forest algorithm. According to the historical network abnormal behavior data of the target financial server, the historical network abnormal behavior data includes abnormal behavior types and network change characteristics of each abnormal behavior type. The abnormal behavior types include network faults, network attacks, malicious traffic, and data packet tampering. The network change characteristics include bandwidth utilization change characteristics, network delay characteristics, and packet loss rate characteristics;
[0099] Import the historical network abnormal behavior data into the network abnormal behavior detection model for training, and import the network transmission data packets into the trained network abnormal behavior detection model for network abnormal detection to obtain network abnormal detection results;
[0100] According to the network abnormal detection results, if the target financial server is maliciously attacked, lock the financial user account and restrict the trading behavior of the financial user;
[0101] If the target financial server has a network fault, obtain the real-time trading behavior data of the financial user and the historical trading behavior data under normal trading conditions, convert the real-time trading behavior data and historical trading behavior data into hash value data, and perform hash value verification on the hash value data to identify the data integrity of the real-time trading behavior;
[0102] According to the data integrity, judge the impact of different degrees of network faults on the data transmission integrity of the financial user's trading behavior. If the impact on data transmission integrity is greater than a preset value, construct a financial user trading behavior buffer. When the network fault degree of the target financial server is greater than the preset degree, import the real-time trading behavior data of the financial user into the financial user trading behavior buffer until the network fault degree is not greater than the preset degree and then transmit the real-time trading behavior data.
[0103] It should be noted that during the process of evaluating the financial transaction risks of financial users, the network status of the target financial server will also affect the financial transaction risks of financial users. For example, network attacks (such as DDoS attacks, malicious traffic attacks), network failures (such as bandwidth bottlenecks, packet loss, latency, etc.) or data packet tampering may cause the financial server to be unable to process user requests normally, and even cause financial data to be lost or tampered with, resulting in problems such as incorrect transaction records and account anomalies. Therefore, by constructing a network monitoring system for the target financial server, the data transmission traffic of the target financial server can be obtained in real time. These data include network traffic fluctuation data, repeated access data, and abnormal data packets. By analyzing these data, potential anomalies in the network, such as network attacks, malicious traffic, and repeated access, can be effectively identified. Based on the Isolation Forest algorithm, combined with historical network anomaly behavior data (such as network failures, network attacks, malicious traffic, etc.), a network anomaly behavior detection model is trained. The Isolation Forest is an unsupervised learning algorithm that can automatically identify abnormal patterns in data by establishing a tree-based classification model. The historical network anomaly behavior data includes network change characteristics of various abnormal behaviors, such as changes in bandwidth utilization, network latency characteristics, packet loss rate characteristics, etc. By importing the historical anomaly behavior data into the model for training, the model can identify abnormal data in real-time network transmission data packets, thereby realizing real-time monitoring and network anomaly detection. Once a network anomaly (such as a network attack, a network failure, etc.) is detected, the system will automatically take corresponding countermeasures. For example, when it is found that the target financial server is under a malicious attack, the system will automatically lock the financial user's account and restrict their trading behavior to prevent further risk expansion. For data transmission problems caused by network failures, the system will judge the integrity of the transaction behavior data according to the severity of the network failure. If the data integrity is greatly affected (such as severe packet loss, high latency, etc.), the system will construct a buffer for the financial user's transaction behavior. When the degree of the network failure exceeds a preset threshold, the system will temporarily store the real-time transaction behavior data of the user in the buffer and then perform data transmission after the network returns to normal. This ensures that transaction data is not lost on the one hand and avoids transaction data errors or anomalies caused by network failures on the other hand.
[0104] According to an embodiment of the present invention, it further includes:
[0105] Obtain the network traffic change information of the target financial server within a preset time period, and determine the transaction change amount of the financial user within the preset time period according to the network traffic change information;
[0106] Construct a prediction model for the transaction change amount of the financial user based on the LSTM algorithm, import the transaction change amount into the prediction model for the transaction change amount for training, and predict the transaction change amount within a future preset time period to obtain a prediction result of the transaction change amount;
[0107] Determine the concurrent transaction data volume within a future preset time period according to the predicted result of the transaction change volume, obtain the data processing performance information of the target financial server, and determine the data processing volume threshold for concurrent transactions according to the data processing performance information;
[0108] If the concurrent transaction data volume is greater than the data processing volume threshold, determine the transaction concurrent peak time period according to the predicted result of the transaction change volume, and adjust the bandwidth resources of the target financial server during the transaction concurrent peak time period to obtain a primary monitoring resource adjustment strategy;
[0109] Obtain the operation behavior data of financial users during the transaction concurrent peak time period, obtain the degree of risk impact of the operation behavior data on financial transactions, adjust the risk monitoring sensitivity of financial users during the transaction concurrent peak time period according to the degree of risk impact to obtain a secondary monitoring resource adjustment strategy, and adjust the financial risk monitoring resources during the transaction concurrent peak time period according to the primary monitoring resource adjustment strategy and the secondary monitoring resource adjustment strategy.
[0110] It should be noted that the LSTM algorithm is a long short-term memory network; using the LSTM algorithm to accurately predict the transaction change volume of financial users can identify transaction fluctuations within a future preset time period; based on the predicted result of the transaction change volume, the concurrent transaction data volume within a future high-concurrency time period can be accurately calculated; after determining the future concurrent transaction data volume, the data processing performance information of the target financial server can be obtained in real time, and the impact of the concurrent transaction data volume on the server performance can be reasonably predicted, so as to set a reasonable data processing volume threshold. When the concurrent transaction data volume exceeds this threshold, the system can automatically adjust the bandwidth resources of the target financial server to ensure that the server can operate stably under high-concurrency load. Through the accurate prediction of the transaction concurrent peak time period, the system can automatically perform pre-scheduling of monitoring resources. For example, the bandwidth can be increased, the storage can be optimized, the computing power can be improved, etc.; after predicting the transaction concurrent peak time period, the system will evaluate the degree of risk impact of the transaction based on the operation behavior data of financial users. By real-time monitoring of operation behavior data (such as abnormal transaction behaviors, abnormal fund flows, etc.), the system can evaluate the potential risks of these behaviors to transaction security under high-concurrency conditions, and automatically adjust the risk monitoring sensitivity during this time period. Automatically adjusting the sensitivity and resource allocation can effectively reduce the overload risk of the system and avoid monitoring failure caused by resource shortage. By optimizing resource allocation, the system can maintain efficient operation during high concurrency.
[0111] Figure 4 Fig. shows a block diagram of a financial risk early warning system based on big data technology according to the present invention.
[0112] In a second aspect of the present invention, there is also provided a financial risk warning system 4 based on big data technology. The system includes: a memory 41 and a processor 42. The memory includes a financial risk warning method program based on big data technology. When the financial risk warning method program based on big data technology is executed by the processor, the following steps are implemented:
[0113] Obtain the historical operation record data of the financial user according to the target financial server, and extract the historical operation path data of the financial user according to the historical operation record data;
[0114] Perform a clustering operation on the historical operation path data according to the clustering algorithm to obtain a clustering result of the operation records;
[0115] Identify the transaction operation path characteristics of the financial user under different transaction types according to the clustering result of the operation records;
[0116] Construct a transaction operation risk assessment model for the financial user according to the transaction operation path characteristics, perform a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculate the deviation degree of the real-time transaction operation behavior of the financial user, and perform a transaction operation risk assessment according to the deviation degree of the real-time transaction operation behavior;
[0117] If the transaction operation risk is greater than a preset risk value, mark the financial user as a risk user, perform a secondary confirmation of the transaction risk on the risk user, perform a financial risk warning according to the result of the secondary confirmation of the transaction risk, and construct a financial risk warning strategy.
[0118] The present invention discloses a financial risk warning method and system based on big data technology, aiming to evaluate and warn risks in real time by analyzing the transaction behavior of financial users. The method includes: obtaining the historical operation records of financial users and extracting operation path data; using a clustering algorithm to cluster the historical operation path data to identify operation path characteristics under different transaction types; constructing a transaction risk assessment model to analyze the deviation degree of real-time transaction behavior; evaluating risks according to the deviation degree, and if the risk exceeds a preset value, marking the user as a risk user and performing a secondary confirmation; finally triggering a risk warning mechanism and formulating a warning strategy. The system includes data acquisition, processing, evaluation, warning, and execution modules, which work together to achieve real-time monitoring and risk warning. The invention can accurately identify abnormal transaction behaviors, improve the intelligence and automation level of financial risk management, and has a wide application prospect in the financial field.
[0119] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed with each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be electrical, mechanical, or other forms.
[0120] The units described above as separate components may or may not be physically separated. The components shown as units may or may not be physical units. They can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0121] In addition, each functional unit in the embodiments of the present invention can be all integrated in a processing unit, or each unit can be separately used as a unit, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional units.
[0122] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments. The foregoing storage medium includes: removable storage devices, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks and other various media that can store program codes.
[0123] Alternatively, if the above-mentioned integrated units of the present invention are implemented in the form of software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in the embodiments of the present invention. The foregoing storage medium includes: removable storage devices, ROM, RAM, magnetic disks, or optical disks and other various media that can store program codes.
[0124] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims described.
Claims
1. A financial risk early warning method based on big data technology, characterized in that: The following steps are involved: Acquire historical operation record data of a financial user according to a target financial server, and extract historical operation path data of the financial user according to the historical operation record data; The historical operation path data is a path record that reflects the sequence and direction of different operation records of the user, extracted by constructing a directed graph of the operation records before and after each transaction of the user in chronological order; Performing a clustering operation on the historical operation path data according to a clustering algorithm to obtain an operation record clustering result; Identifying transaction operation path characteristics of financial users under different transaction types according to the operation record clustering results; constructing a transaction operation risk assessment model for the financial user according to the transaction operation path characteristics, performing a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculating the deviation degree of the real-time transaction operation behavior of the financial user, and performing a transaction operation risk assessment according to the real-time transaction operation behavior deviation degree; If the transaction operation risk is greater than the preset risk value, the financial user is marked as a risky user, and the transaction risk of the risky user is reconfirmed. According to the result of the reconfirmation of the transaction risk, a financial risk warning is issued to build a financial risk warning strategy; The step of constructing a transaction operation risk assessment model for a financial user according to the transaction operation path characteristics, performing a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculating the deviation degree of the real-time transaction operation behavior of the financial user, and performing a transaction operation risk assessment according to the real-time transaction operation behavior deviation degree is specifically as follows: constructing an operation state transfer pair for the transaction operation path features based on a Markov chain, calculating the operation transfer probability between the operation state transfer pairs according to the historical operation path data, and constructing an operation state transfer matrix according to the operation transfer probability; Constructing a transaction operation risk assessment model for financial users according to the operation state transfer matrix, and constructing a data link channel between the transaction operation risk assessment model and the target financial server based on big data technology, wherein the data link channel includes a data interface between the target financial server and the transaction operation risk assessment model, and a data cleaning module; Importing the real-time transaction operation behavior data of the financial user of the target financial service server into the transaction operation risk assessment model according to the data link channel, calculating the operation state transition probability between adjacent operation behaviors in the real-time transaction operation behavior data, and calculating the operation transition comprehensive probability of the real-time transaction operation behavior data according to the operation state transition probability between the adjacent operation behaviors; The deviation between the real-time transaction operation behavior of the financial user and the transaction operation path characteristics is calculated according to the comprehensive probability of operation transfer of the real-time transaction operation behavior data, and the real-time transaction operation of the financial user is risk assessed according to the deviation based on the transaction operation risk assessment model to obtain a transaction operation risk assessment result.
2. The financial risk early warning method based on big data technology according to claim 1 is characterized in that: The acquiring of the historical operation record data of the financial user according to the target financial server and the extraction of the historical operation path data of the financial user according to the historical operation record data are specifically: Acquire historical operation record data of a financial user according to a target financial server, wherein the historical operation record data includes browsing records, financial consultation records, and transaction records; Sorting the historical operation record data according to timestamps to construct historical operation record time series data, and segmenting the historical operation record time series data according to transaction record time points to obtain historical operation record data segments; The historical operation record data segments are used to construct an operation record directed graph, and the historical operation path data of the financial user is extracted according to the operation record directed graph.
3. The financial risk early warning method based on big data technology according to claim 1 is characterized in that: The clustering operation is performed on the historical operation path data according to the clustering algorithm to obtain the operation record clustering result, which is specifically: Setting a clustering weight for each operation record in the historical operation path data, calculating the Euclidean distance between each pair of historical operation paths in the historical operation path data, and calculating the similarity between the historical operation paths according to the Euclidean distance and the clustering weight; Constructing a similarity matrix according to the similarity, calculating a diagonal matrix of the similarity matrix, constructing a Laplace matrix according to the similarity matrix and the diagonal matrix, performing eigenvalue decomposition on the Laplace matrix, and finding eigenvectors corresponding to the smallest k eigenvalues; Constructing a feature matrix according to the eigenvectors corresponding to the k eigenvalues, randomly selecting k data points from the feature matrix as initial centroids, calculating the Euclidean distance from each data point in the feature matrix to each initial centroid, and assigning each data point to the cluster where the nearest initial centroid is located; Iteratively update the cluster center and recalculate the updated Euclidean distance from each data to the updated cluster center. Allocate data points according to the updated Euclidean distance until the cluster center no longer changes, and obtain the operation record clustering result.
4. The financial risk early warning method based on big data technology according to claim 1 is characterized in that: The identifying the transaction operation path characteristics of the financial user under different transaction types according to the operation record clustering result is specifically: Extracting the transaction type to which each clustering result belongs according to the operation record clustering results, constructing the transaction operation path of the transaction type to which each clustering result belongs according to the operation record clustering results, and obtaining the transaction operation path feature; Repeatedly identify the transaction operation path features, determine whether each transaction type has multiple transaction operation path features, mark the transaction type with multiple transaction operation path features, extract the multiple transaction operation path features of the marked transaction type and mark them as the transaction operation path features to be merged; Calculating the proportion of each transaction operation path feature to be merged in the operation record clustering result according to the operation record clustering result, taking the transaction operation path feature to be merged with the largest proportion as the benchmark transaction operation path feature, and marking the remaining transaction operation path features to be merged as candidate transaction operation path features; Preset a minimum support threshold for path feature merging, obtain the operation record elements included in the candidate transaction operation path features, calculate the frequency of occurrence of each operation record element in the transaction operation path features to be merged, and evaluate the support of the operation record element according to the frequency of occurrence; Comparing the support of the operation record element with the minimum support threshold, and marking the operation record element whose support is greater than the minimum support threshold and is not included in the benchmark transaction operation path feature as a candidate frequent sub-feature; Based on the Apriori algorithm, a hierarchical search is performed on the transaction operation path features to be merged, and the occurrence probability of the candidate frequent sub-features after each operation record in the benchmark transaction operation path features is analyzed, and the insertion position of the candidate frequent sub-features in the benchmark transaction operation path features is determined according to the occurrence probability; The benchmark transaction operation path feature and the candidate frequent sub-features are merged according to the insertion position to obtain the transaction operation path features of the financial user under different transaction types.
5. The financial risk early warning method based on big data technology according to claim 1 is characterized in that: If the transaction operation risk is greater than the preset risk value, the financial user is marked as a risky user, the transaction risk of the risky user is reconfirmed, and a financial risk warning is issued based on the transaction risk reconfirmation result, and a financial risk warning strategy is constructed, specifically: According to the transaction operation risk assessment result, if the transaction operation risk is greater than the preset risk value, the financial user is marked as a risky user, and the transaction change information of the risky user within a preset time period is obtained, and the transaction change information includes the change of transaction frequency and transaction amount; Comprehensively analyzing the transaction change information and the transaction operation path characteristics, determining the change of the transaction change information to the transaction operation path characteristics, updating the transaction operation path characteristics according to the change, and performing a secondary risk assessment on the real-time transaction operation behavior of the risky user according to the updated transaction operation path characteristics; If the transaction operation risk of the secondary risk assessment is still greater than the preset risk value, the real-time transaction operation behavior data of the risk user is compared with the transaction operation path characteristics to identify the missing operations of the risk user's real-time transaction operation behavior, and the missing operations are generated as warning information to perform warning reminder operations on the risk user to obtain a user warning plan; Acquire transaction IP address information of risky users and credit rating information of transaction objects, determine the risk level of risky users according to the transaction IP address information and credit rating information of transaction objects, generate warning information according to the risk level, perform warning operations on target financial institutions, and obtain institutional warning plans; A financial risk early warning strategy is constructed based on the user early warning plan and the institution early warning plan.
6. A financial risk early warning system based on big data technology, characterized in that: The financial risk early warning system based on big data technology includes a storage device and a processor. The storage device includes a financial risk early warning method program based on big data technology. When the financial risk early warning method program based on big data technology is executed by the processor, the following steps are implemented: Acquire historical operation record data of a financial user according to a target financial server, and extract historical operation path data of the financial user according to the historical operation record data; The historical operation path data is a path record that reflects the sequence and direction of different operation records of the user, extracted by constructing a directed graph of the operation records before and after each transaction of the user in chronological order; Performing a clustering operation on the historical operation path data according to a clustering algorithm to obtain an operation record clustering result; Identifying transaction operation path characteristics of financial users under different transaction types according to the operation record clustering results; constructing a transaction operation risk assessment model for the financial user according to the transaction operation path characteristics, performing a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculating the deviation degree of the real-time transaction operation behavior of the financial user, and performing a transaction operation risk assessment according to the real-time transaction operation behavior deviation degree; If the transaction operation risk is greater than the preset risk value, the financial user is marked as a risky user, and the transaction risk of the risky user is reconfirmed. According to the result of the reconfirmation of the transaction risk, a financial risk warning is issued to build a financial risk warning strategy; The step of constructing a transaction operation risk assessment model for a financial user according to the transaction operation path characteristics, performing a transaction operation path deviation analysis on the real-time transaction operation behavior of the financial user according to the transaction operation risk assessment model, calculating the deviation degree of the real-time transaction operation behavior of the financial user, and performing a transaction operation risk assessment according to the real-time transaction operation behavior deviation degree is specifically as follows: constructing an operation state transfer pair for the transaction operation path features based on a Markov chain, calculating the operation transfer probability between the operation state transfer pairs according to the historical operation path data, and constructing an operation state transfer matrix according to the operation transfer probability; Constructing a transaction operation risk assessment model for financial users according to the operation state transfer matrix, and constructing a data link channel between the transaction operation risk assessment model and the target financial server based on big data technology, wherein the data link channel includes a data interface between the target financial server and the transaction operation risk assessment model, and a data cleaning module; Importing the real-time transaction operation behavior data of the financial user of the target financial service server into the transaction operation risk assessment model according to the data link channel, calculating the operation state transition probability between adjacent operation behaviors in the real-time transaction operation behavior data, and calculating the operation transition comprehensive probability of the real-time transaction operation behavior data according to the operation state transition probability between the adjacent operation behaviors; The deviation between the real-time transaction operation behavior of the financial user and the transaction operation path characteristics is calculated according to the comprehensive probability of operation transfer of the real-time transaction operation behavior data, and the real-time transaction operation of the financial user is risk assessed according to the deviation based on the transaction operation risk assessment model to obtain a transaction operation risk assessment result.
Citation Information
Patent Citations
Transaction risk assessment method and device and electronic equipment
CN110046997A
Risk assessment method and device, computer storage medium and electronic equipment
CN118261695A