Method and device for assessing financial data security risk
By screening financial data security risk indicators, using fuzzy hierarchical analysis method and entropy weight method to determine weights, and adopting fuzzy comprehensive evaluation method to calculate risk assessment values, the problem of strong subjectivity in manual assessment in existing technologies is solved, and accurate risk assessment and timely risk disposal are achieved.
Patent Information
- Application Number
- CN202510001353.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-02
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-01-02
AI Technical Summary
Existing financial data security risk assessment methods rely on manual assessment, which is highly subjective and inefficient. They fail to effectively identify risk factors unique to data flow, resulting in inaccurate assessment results.
The approximate ideal solution sorting method is used to screen financial data security risk indicators, the fuzzy analytic hierarchy process and entropy weight method are combined to determine the weights, the risk assessment value is calculated through the fuzzy comprehensive evaluation method, and a scientific risk assessment indicator system is constructed.
It achieves objective and accurate financial data security risk assessment, can timely discover and deal with data security risks, reduce subjective interference in expert decision-making, and improve assessment efficiency.
Smart Images

Figure CN119809834B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data security, and in particular, to a method and device for assessing financial data security risks. Background Art
[0002] With the rapid growth of the digital economy, data security risks are increasing, leading to a deepening level of harm. Data security incidents such as data leaks, data abuse, and data trafficking are occurring frequently and steadily, posing a serious threat to national security, social stability, the rights and interests of enterprises and organizations, and personal privacy. Effectively responding to the current severe data security situation, preventing and addressing data security issues arising from new scenarios, new technologies, and new business models in the financial industry, and ensuring the safe development and utilization of data elements have become key issues in contemporary social development.
[0003] Current data security risk assessment methods are mostly based on a simple transformation of information security risk assessment theory, ignoring the risk factors unique to data flow; and the assessment methods mainly rely on manual interviews, document reviews, compliance benchmarking, etc. The risk assessment results are often given by experts based on their professional experience, which are highly subjective and have low overall assessment efficiency. Summary of the Invention
[0004] In response to the above situation, the embodiments of the present application provide a financial data security risk assessment method and device, which aim to solve the above problems or at least partially solve the above problems.
[0005] In a first aspect, an embodiment of the present application provides a method for assessing financial data security risks, the method comprising: determining an initial risk indicator set, the initial risk indicator set including multiple risk indicators that affect financial data security; screening the initial risk indicator set based on an approximate ideal solution sorting method to determine a target risk indicator set, the target risk indicator set including n first-level risk indicators, and the n first-level risk indicators corresponding to n second-level risk indicator sets; determining an initial weight set of the target risk indicator set based on a fuzzy hierarchical analysis method, the weight set including a weight set of n first-level risk indicators and a weight set of each second-level risk indicator set; correcting the initial weight set of the target risk indicator set using the entropy weight of the target risk indicator set to obtain a target weight set of the target risk indicator set; calculating a fuzzy comprehensive evaluation result of the financial data security risk based on a fuzzy membership matrix of an evaluation factor set, a target weight set of the target risk indicator set, and an assignment matrix of a comment set; wherein the evaluation factor set includes factors that affect the financial data security risk assessment, and the comment set represents the assessment level of the financial data security risk.
[0006] In a second aspect, an embodiment of the present application also provides a financial data security risk assessment device, the device comprising: a determination module for determining an initial risk indicator set, the initial risk indicator set including multiple risk indicators that affect the security of financial data; a screening module for screening the initial risk indicator set based on an approximate ideal solution sorting method to determine a target risk indicator set, the target risk indicator set including n first-level risk indicators, and the n first-level risk indicators corresponding to n second-level risk indicator sets; the determination module is also used to determine an initial weight set of the target risk indicator set based on a fuzzy hierarchical analysis method, the weight set including the weight set of n first-level risk indicators and the weight set of each second-level risk indicator set; a correction module for correcting the initial weight set of the target risk indicator set using the entropy weight of the target risk indicator set to obtain a target weight set of the target risk indicator set; a calculation module for calculating a fuzzy comprehensive evaluation result of the financial data security risk based on the fuzzy membership matrix of the evaluation factor set, the target weight set of the target risk indicator set, and the assignment matrix of the comment set; wherein the evaluation factor set includes factors that affect the financial data security risk assessment, and the comment set represents the assessment level of the financial data security risk.
[0007] In a third aspect, an embodiment of the present application further provides an electronic device comprising: a processor; and a memory arranged to store computer-executable instructions, wherein the executable instructions, when executed, cause the processor to perform the steps of the first aspect described above.
[0008] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which stores one or more programs. When the one or more programs are executed by an electronic device including multiple applications, the electronic device performs the steps of the first aspect above.
[0009] At least one of the above-mentioned technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: preliminarily determining the financial data security risk assessment indicators, and in order to ensure the accuracy of the assessment indicators, using the approximate ideal solution sorting method to screen the financial data security risk assessment indicators, determine the target risk indicator set, and construct a financial data security risk assessment indicator system. Secondly, using the fuzzy hierarchical analysis method and the entropy weight method to assign weight values to the target risk indicator set, so as to reduce the subjective interference in the expert decision-making process. Finally, the risk assessment value is determined by the comprehensive fuzzy evaluation method. Compared with the subjective financial data security risk assessment results given by experts, the present application can conduct objective and accurate financial data security risk assessments and can timely discover and deal with data security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0011] Figure 1 A schematic diagram of a process for assessing financial data security risks provided by an embodiment of the present application is shown;
[0012] Figure 2 A schematic diagram showing the relative proximity of risk indicators provided by an embodiment of the present application;
[0013] Figure 3 A flowchart of a financial data security risk assessment method provided by another embodiment of the present application is shown;
[0014] Figure 4 A schematic diagram of the initial weights of the risk indicators provided in the embodiment of the present application is shown;
[0015] Figure 5 A schematic diagram of entropy weight provided in an embodiment of the present application is shown;
[0016] Figure 6 A schematic diagram of target weights provided in an embodiment of the present application is shown;
[0017] Figure 7 The structure diagram of the financial data security risk assessment device provided in an embodiment of the present application is shown;
[0018] Figure 8 A structural diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION
[0019] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0020] It should be noted that the terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that such usage is interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the term "including" and its variations are to be interpreted as open-ended terms meaning "including but not limited to."
[0021] As described in the background, with the rapid growth of the digital economy, data security risks are increasing day by day, leading to deepening harm, frequent data security incidents such as data leakage, data misuse, and data trafficking, and a continuously increasing trend, which poses a serious threat to national security, social stability, enterprise organizational interests, and personal privacy security. Effectively addressing the current serious data security situation, preventing and handling data security issues brought about by new scenarios, new technologies, and new forms in the financial industry, and ensuring the safe development and use of data elements have become one of the important issues in the current social development.
[0022] Financial data security is a key component of national and social security, and is also a fundamental guarantee for the development and utilization of financial data, occupying a core position in the process of data elementization. With the acceleration of financial digital transformation, the data security protection capabilities of financial institutions are facing higher challenges. In recent years, financial data security incidents have occurred frequently, and the security situation has become increasingly severe. On the one hand, the value of data is increasingly prominent, and hacking, malicious software, and other attacks and theft methods targeting data are constantly evolving, threatening financial data security. On the other hand, data application methods and scenarios continue to innovate, financial business processes and data flow links become increasingly complex, and the exposure of financial data security risks increases dramatically. At the current important stage of transformation and innovation development in the financial industry, financial institutions urgently need to build a perfect data security protection system to lay a solid foundation for financial digital development.
[0023] Conducting financial data security risk assessment can help financial institutions comprehensively grasp the data security situation, identify and solve security risks in a timely manner, and then target data security construction and system optimization, improve security protection and risk prevention and control levels, and reduce the frequency and loss of data security incidents. By conducting regular data security risk assessment, financial institutions can build a data security system that promotes construction, improvement, and continuous iteration and improvement.
[0024] The current data security risk assessment method is mainly based on the simple transformation of information security risk assessment theory, ignoring the unique risk factors of data flow. The assessment method mainly relies on manual interviews, document reviews, compliance benchmarking, etc., and the risk evaluation results are often given by experts based on their experience, which is highly subjective and has low overall assessment efficiency.
[0025] Based on this, the embodiment of the present application proposes a financial data security risk assessment method, preliminarily determines the data security risk assessment indicators, and in order to ensure the accuracy of the assessment indicators, uses the Technique for Order Preference by Similarity to Ideal Solution (TOPSIS) to screen the data security risk assessment indicators and determine the target risk indicator set to construct a data security risk assessment indicator system. Secondly, the target risk indicator set is assigned weights through the fuzzy hierarchical analysis method and the entropy weight method to reduce the subjective interference in the expert decision-making process. Finally, the risk assessment value is determined by the comprehensive fuzzy evaluation method, which can conduct an objective and accurate data security risk assessment, fully grasp the current data security management status and problems of the assessment object, and have good effectiveness, applicability and execution strength at the practical level.
[0026] The present application is described in detail below through specific embodiments.
[0027] Figure 1 The flowchart of the financial data security risk assessment method provided by the embodiment of the present application is shown. Figure 1 It can be seen that this application at least includes steps S101 to S105:
[0028] Step S101: Determine an initial risk indicator set.
[0029] Among them, the initial risk indicator set includes multiple risk indicators that affect the security of financial data.
[0030] Step S102: Based on the approximate ideal solution sorting method, the initial risk indicator set is screened to determine the target risk indicator set.
[0031] Among them, the target risk indicator set includes n first-level risk indicators, and n first-level risk indicators correspond to n second-level risk indicator sets.
[0032] That is, the target risk indicator set includes n first-level risk indicators, each first-level risk indicator includes a second-level risk indicator set, and each second-level risk indicator set includes multiple second-level risk indicators. For example, the target risk indicator set includes three first-level risk indicators: first-level risk indicator 1, first-level risk indicator 2, and first-level risk indicator 3. First-level risk indicator 1 includes second-level risk indicator 11 and second-level risk indicator 12, first-level risk indicator 2 includes second-level risk indicator 21, second-level risk indicator 22, and second-level risk indicator 23, and first-level risk indicator 3 includes second-level risk indicator 31 and second-level risk indicator 32.
[0033] Step S103: Determine the initial weight set of the target risk indicator set based on the fuzzy analytic hierarchy process.
[0034] The initial weight set includes the weight sets of n first-level risk indicators and the weight sets of each second-level risk indicator set. Specifically, the weight set of n first-level risk indicators includes the weights corresponding to the n first-level risk indicators, and the weight set of each second-level risk indicator set includes the weights corresponding to each second-level risk indicator.
[0035] Step S104: using the entropy weight of the target risk indicator set to modify the initial weight set of the target risk indicator set, to obtain the target weight set of the target risk indicator set.
[0036] Specifically, the entropy weight method is used to calculate the entropy weight of the first-level risk indicator set and the entropy weight of each second-level risk indicator set in the target risk indicator set. The entropy weight of each indicator set is used to correct the initial weight set of each indicator set to obtain the target weight set of each indicator set.
[0037] Step S105: Calculate the fuzzy comprehensive evaluation result of the financial data security risk based on the fuzzy membership matrix of the evaluation factor set, the target weight set of the target risk indicator set, and the assignment matrix of the comment set.
[0038] The assessment factor set includes factors that impact financial data security risks. In one embodiment, because the target risk indicator set includes multiple risk indicators that impact financial data security, the assessment factor set can be established based on the target risk indicator set. For example, the assessment factor set includes n first-level risk indicators, each of which includes multiple second-level risk indicators.
[0039] The comment set represents the assessment level of financial data security risk.
[0040] from Figure 1 As can be seen from the method shown, this application preliminarily determines the financial data security risk assessment indicators. In order to ensure the accuracy of the assessment indicators, the TOPSIS method is used to screen the financial data security risk assessment indicators and determine the target risk indicator set to construct a financial data security risk assessment indicator system. Secondly, the fuzzy hierarchical analysis method and entropy weight method are used to assign weights to the target risk indicator set to reduce the subjective interference in the expert decision-making process. Finally, the risk assessment value is determined by the comprehensive fuzzy evaluation method. Compared with the subjective data security risk assessment results given by experts, this application can conduct objective and accurate data security risk assessments and can timely discover and deal with data security risks.
[0041] In some embodiments of the present application, in the above step S101, data security risk indicator items are identified by analyzing and studying literature, cases, etc., and the data security risk indicator items are summarized to determine an initial risk indicator set.
[0042] Specifically, from the data security core concept, the keywords are screened from the literature database or literature website, and the related articles are obtained. Through the analysis of the related articles, the data security risk influencing factor literature can be obtained. For example, taking "financial data security" as the keyword, the influencing factors obtained by retrieval are shown in Table 1.
[0043] Table 1 Financial data security risk influencing factor literature statistics table
[0044]
[0045] Further, the financial data security risk index items are identified through case analysis. By analyzing the related data security cases, combined with the actual situation, the main influencing factors of financial data security risk are summarized.
[0046] For example, an employee obtained more than 2.9 million members (including 2.7 million family users and 173,000 enterprises and related contacts) of personal identifiable information in the database, involving name, date of birth, phone number, email and personal financial habits, etc. Event analysis shows that the data leakage is due to the lack of security awareness of employees, lack of data security training, and imperfect organization data security management system. Accordingly, the main elements of financial data security risk include personnel education and training and data security management system.
[0047] For another example, a company suffered a network attack, which highlighted the lack of network security protection, failure to promptly investigate security vulnerabilities, etc. Accordingly, the main elements of financial data security risk include network security protection, data security risk monitoring, and data leakage prevention.
[0048] For another example, a company was fined for not performing customer identity recognition obligations and infringing consumer rights. The penalties include failure to conduct effective identity verification on personal information subjects, illegal provision of personal information, etc. Accordingly, the main elements of financial data security risk include data quality control, legality and necessity, appropriateness of processing method, and data provision security.
[0049] Therefore, by analyzing the cases, the case analysis statistics table of financial data security risk influencing factors is obtained, for example, as shown in Table 2.
[0050] Table 2 Financial data security risk influencing factor case analysis statistics table
[0051]
[0052] Further, by summarizing and analyzing the data security influencing factors obtained based on literature analysis and the data security influencing factors obtained based on case analysis, the initial risk index set is obtained. For example, as shown in Table 3.
[0053] Table 3 Initial risk indicator set
[0054]
[0055]
[0056] Furthermore, by comprehensively evaluating the interrelationships between various indicators, the present embodiment summarizes the main risk categories for financial data security into seven areas: data asset management risk, data security management risk, network security risk, data security operation risk, data behavior security risk, data flow security risk, and data application security risk. Based on the initial risk indicator set shown in Table 3, the risk indicators in the initial risk indicator set are divided into the aforementioned risk categories. The initial risk indicator set now includes seven primary indicators, each of which includes multiple secondary indicators, for a total of 55 secondary indicators.
[0057] In the embodiments of the present application, by combing and analyzing relevant literature and cases, key risk indicators that affect the security of financial data can be identified in combination with actual situations.
[0058] In some embodiments of the present application, in step S102, the initial risk indicator set is screened using the TOPSIS method to determine a target risk indicator set. Specifically, the relative proximity of each risk indicator in the initial risk indicator set is calculated by determining the distance between each risk indicator and the positive ideal solution, as well as the distance between each risk indicator and the negative ideal solution. The initial risk indicator set is then screened based on the relative proximity of each risk indicator to obtain the target risk indicator set.
[0059] Specifically, we obtained expert ratings for each secondary risk indicator within the target risk indicator set. Using the Likert five-point scale as an example, ratings of 1, 2, 3, 4, and 5 represent a very small impact, a small impact, a moderate impact, a large impact, and a very large impact, respectively. The ratings for each indicator by the five experts are shown in Table 4.
[0060] Table 4 Financial Data Security Risk Index Score Table
[0061]
[0062]
[0063] Furthermore, a weighted normalized decision matrix D is constructed according to the score table shown in Table 3:
[0064]
[0065] Among them, d nm It represents the score of the mth expert on the nth risk indicator.
[0066] Furthermore, the weighted normalized decision matrix is normalized to obtain a normalized standard matrix Z.
[0067] Specifically, the matrix D is normalized based on the following formula:
[0068]
[0069] Among them, z ij represents the normalized score of the jth expert on the i-th risk indicator, d ij It represents the score of the j-th expert on the i-th risk indicator.
[0070] Furthermore, the positive ideal solution and the negative ideal solution are determined. The positive ideal solution is the optimal solution, that is, the maximum value in the expert score; the negative ideal solution is the worst solution, that is, the minimum value in the expert score. The calculation formulas for the positive and negative ideal solutions are as follows:
[0071]
[0072] Among them, z nm It represents the score of the mth expert on the nth risk indicator in the matrix D.
[0073] Furthermore, the distance between each risk indicator and the positive ideal solution and the distance between each risk indicator and the negative ideal solution are calculated.
[0074] In one embodiment, the distance between each risk indicator and the positive ideal solution and the distance between each solution and the negative ideal solution are calculated based on the following formula:
[0075]
[0076] in, represents the distance between the i-th risk indicator and the positive ideal solution, represents the distance between the i-th risk indicator and the negative ideal solution, represents the positive ideal solution of the j-th risk indicator, represents the negative ideal solution of the j-th risk indicator, z ij It represents the score of the j-th expert on the i-th risk indicator in the matrix D.
[0077] Furthermore, the relative closeness of n risk indicators to the ideal solution is calculated according to the following formula:
[0078]
[0079] Among them, Q i Indicates the relative proximity of the i-th risk indicator.
[0080] In this embodiment of the application, the threshold is set to 0.5, and the risk index with a relative closeness greater than 0.5 is regarded as the target risk index, and the other risk indicators are ignored. Figure 2 As shown, nine indicators had a proximity score below 0.5, including data asset catalog, important data catalog, update and maintenance procedures, employee background checks, personnel assessment and evaluation, complaint and reporting handling mechanism, appropriateness of handling methods, respect for social morality and ethics, and response to individual rights. Therefore, these nine indicators were removed, ultimately resulting in 46 target risk indicators. The resulting financial data security risk assessment indicator system (target risk indicator set) consists of seven primary indicators and 46 secondary indicators.
[0081] In an embodiment of the present application, the risk indicators obtained in step S101 are screened by the TOPSIS method, and some risk indicators with little impact are screened out to obtain a target risk indicator set, thereby forming a scientific, convenient, accurate, and actual financial data security risk assessment indicator system that conforms to the actual scenarios of financial institutions.
[0082] In some embodiments of the present application, when determining the initial indicator weight set of the target risk indicator set in step S103, the initial indicator weight set is determined using a fuzzy analytic hierarchy process. Specifically, a fuzzy judgment matrix of the target risk indicator set is determined, a consistency check is performed on the fuzzy judgment matrix of the target risk indicator set to generate a fuzzy consistency matrix of the target risk indicator set; and based on the fuzzy consistency matrix of the target risk indicator set, the initial indicator weight set of the target risk indicator set is calculated.
[0083] Specifically, in the embodiment of the present application, N experts compare the risk indicators of the same level with each other to obtain the fuzzy judgment matrix C = (c ij ) n×n , i, j∈(1,2,…,n), where n is the number of risk indicators at this level, c ij Indicates c i C j The relative importance of the value. Fuzzy matrix C = (c ij ) n×n Must satisfy 0≤c ij ≤1. If the fuzzy matrix C=(c ij ) n×n Satisfy c ij +c ji =1, then C is called a fuzzy complementary matrix. The fuzzy analytic hierarchy process marks the importance values obtained by comparing the indicators pairwise with 0.1-0.9, thus obtaining a fuzzy judgment matrix. The 0.1-0.9 scaling method is shown in Table 5:
[0084] Table 5 Relative importance scale of measurement levels
[0085]
[0086] Furthermore, the fuzzy consistency matrix is constructed: if the fuzzy complementary matrix C=(c ij ) n×n Satisfy c ij =c ik -c jk +0.5(i,j,k=1,2,…,n), then C is called a fuzzy consistent matrix. The matrix constructed using the 0.1-0.9 scaling method is usually a fuzzy complementary matrix. To correct the fuzzy complementary matrix to a fuzzy consistent matrix, we first need to use the formula Sum the fuzzy complementary matrix row by row and then transform it, as shown in formula a ij =(r i -r j ) / 2n+0.5, and finally construct the fuzzy consistent matrix A=(a ij ) n×n .
[0087] Furthermore, the initial indicator weights are calculated. For example, the weights of each indicator in the fuzzy consistency matrix are calculated using the least squares method:
[0088]
[0089] When α satisfies α≥(n-1) / 2, the larger the value of a, the smaller the difference in weight values, and vice versa, the difference in weight values is large; when a=(n-1) / 2, the difference in weight values is the largest. In order to ensure the objectivity of the indicator difference, the value of a is selected as α=(n-1) / 2 in this embodiment of the application.
[0090] In the embodiment of the present application, since the target risk indicator set includes primary risk indicators and secondary risk indicators, it is necessary to determine the fuzzy judgment matrix of the primary risk indicator set and each secondary risk indicator set in the embodiment of the present application, perform a consistency check on the fuzzy judgment matrix of the primary risk indicator set and the secondary risk indicator set, generate the fuzzy consistency matrix of the primary risk indicator set and the secondary risk indicator set, and then calculate the initial weights of the primary risk indicator set and each secondary risk indicator set based on the fuzzy consistency matrix of the primary risk indicator set and the secondary risk indicator set. Taking the above-mentioned target risk indicator set including 7 primary risk indicators and 46 secondary risk indicators as an example, it is necessary to determine the initial weight set of 1 primary risk indicator set and the initial weight set of 7 secondary risk indicator sets.
[0091] In the embodiment of the present application, the initial weights of the risk indicators are calculated by using the fuzzy analytic hierarchy process, thereby avoiding the subjectivity of direct weighting by experts and improving the accuracy of the weights.
[0092] In some embodiments of the present application, in step S104, the initial weight set is modified using the entropy weight of the target risk indicator set, wherein the entropy weight of the target risk indicator set is determined based on an entropy weight method.
[0093] Specifically, the process of the entropy weight method is as follows: Based on the initial weight set, the entropy weight method original data matrix Y = (y ij ) m×n (i=1,2,…,m;j=1,2,…,n), m represents the number of risk indicators, n represents the number of experts, y ij It represents the subjective weight of expert j on risk indicator i. The information entropy is calculated based on the original data matrix of the entropy weight method, and the entropy weight is calculated based on the information entropy. The specific formula is as follows:
[0094]
[0095] Among them, E j represents the jth information entropy, ω j represents the jth entropy weight.
[0096] Finally, the initial weights calculated in step S103 are modified based on the entropy weight, as follows:
[0097]
[0098] in, represents the target weight of the mth risk indicator, ω n represents the nth entropy weight, Y T is the transposed matrix of the original matrix Y, and the transposed matrix can be expressed as Y T =(y ji ) n×m (j=1,2,…,m; i=1,2,…,n).
[0099] In the embodiment of the present application, the initial weights obtained by the fuzzy analytic hierarchy process are corrected by the entropy weight method to further improve the accuracy of the weights.
[0100] In some embodiments of the present application, after obtaining the target weight of the target risk indicator set, a fuzzy comprehensive evaluation result is calculated based on a fuzzy comprehensive evaluation method, and the security of the data is evaluated based on the fuzzy comprehensive evaluation result.
[0101] Specifically, first determine the evaluation factor set. Financial data security risk is affected by multiple factors, all of which together constitute the evaluation factor set. In this embodiment of the application, the evaluation factor set is constructed based on the target risk indicator set, denoted as U = (u1, u2, ..., u n ). Divide the evaluation factor set U into s sub-factor sets U1, U2, ..., U s , where U i={u i1 ,u i2 ,…,u im}(i∈s),u im represents the mth risk indicator in the i-th sub-factor set.
[0102] Then, we determine the comment set and divide the polarity of the comments on financial data security risks under the premise of ensuring that the evaluation method maintains the discrimination and stability, which is recorded as V = {v1,v2,…,v b}(b is the rating number of the review).
[0103] We further calculated U i ={u i1 ,u i2 ,…,u im}Index u im Fuzzy set of comment V in is the index u in the index concentration i1 For the element v in the review set j Membership degree of (j=1,2,…,b). Membership degree It can be expressed as: in Indicates the index u im have v j Rating comments.
[0104] U i The fuzzy membership matrix is obtained by fuzzy evaluation of each factor in
[0105]
[0106] Where m is the set U i (i∈1,2,…,n), i is the number of risk indicators in the evaluation factor set U, and b is the number of comment levels.
[0107] First, fuzzy comprehensive evaluation is performed on each sub-factor set, that is, i The target weight C i and the fuzzy membership matrix R of the sub-factor set i Perform synthesis operation to obtain the fuzzy evaluation set of the sub-factor set:
[0108]
[0109] in Represents the synthesis rule, here we use Rules are used to protect the single-factor fuzzy evaluation information. Because the membership of the review set has normalization, The operation rule is multiplication.
[0110] According to D i Compute the fuzzy membership matrix of the evaluation factor set:
[0111]
[0112] Then the fuzzy evaluation set of the evaluation factor set is:
[0113]
[0114] Among them, C represents the target indicator weight set of the first-level risk indicator set.
[0115] Collection of Comments v j Assignment calculation to obtain fuzzy comprehensive evaluation results
[0116]
[0117] Among them, Q T represents the transposed matrix of Q, where Q represents the review set v j The assignment matrix.
[0118] In the embodiments of the present application, we first sort out and analyze relevant literature and cases, identify key risk indicators of financial data security, and use the TOPSIS method to screen risk indicators, so as to construct a systematic and scientific financial data security risk assessment indicator system, and form a scientific, convenient, accurate, and actual data security risk assessment indicator system that conforms to the scenarios of financial institutions, laying the foundation for quantitative financial data security risk assessment; on this basis, based on the financial industry data security risk assessment indicator system, we use the fuzzy hierarchical analysis method and the entropy weight method to determine the subjective and objective weights, and then use the fuzzy comprehensive evaluation method to calculate the data security risk value, thereby constructing a financial data security risk assessment method, which can conduct objective and accurate data security risk assessment, fully grasp the current data security management status and problems of the assessment object, and have good effectiveness, applicability and execution strength at the practical level.
[0119] In some embodiments of the present application, the security of financial data is analyzed based on the fuzzy membership matrix and target weight set of the first-level risk indicator set to determine the first-level risk indicator with the highest security risk; the security of financial data is analyzed based on the fuzzy membership matrix and target weight set of the second-level risk indicator set to determine the second-level risk indicator with the highest security risk; and security measures to improve the security of financial data are formulated based on the first-level risk indicator with the highest security risk and the second-level risk indicator with the highest security risk.
[0120] In some embodiments of the present application, Figure 3As shown, a complete flow chart of the financial data security risk assessment method provided by this application is provided. The specific process is as follows: First, the target risk indicator set is screened using the TOPSIS method: the initial risk indicator set is determined, experts score the risk indicators in the initial security risk indicator set, a standard decision matrix is calculated based on the scoring table, the standard decision matrix is normalized to obtain a standard matrix, the positive ideal solution and the negative ideal solution are determined based on the scoring table, the distance between each risk indicator and the positive ideal solution and the negative ideal solution is calculated, the relative proximity of each risk indicator is calculated, and the target risk indicator set is screened based on the proximity. Then, the initial weights of the risk indicators are determined using the fuzzy hierarchical analysis method: the fuzzy judgment matrix of the target risk indicator set is determined, the fuzzy judgment matrix of the target risk indicator set is tested for consistency, a fuzzy consistency matrix of the target risk indicator set is generated, and the initial weight set of the target risk indicator set is calculated based on the fuzzy consistency matrix of the target risk indicator set. The initial weight set of the target risk indicator set is further modified based on the entropy weight: the entropy weight method original data matrix is constructed based on the initial weight set, the information entropy is calculated, the entropy weight is calculated based on the information entropy, and the initial weight is modified using the entropy weight to obtain the target weight. Finally, the risk value is calculated based on the fuzzy comprehensive evaluation method: the evaluation factor set and comment set are determined, the fuzzy membership matrix is constructed, and the fuzzy comprehensive evaluation results are calculated based on the fuzzy membership matrix and target weights.
[0121] In the embodiment of the present application, the present application proposes a financial data security risk assessment method. First, the relevant literature and cases are sorted out and analyzed to identify the key risk indicators of financial data security, and the TOPSIS method is used to screen the risk indicators to build a systematic and scientific financial data security risk assessment indicator system to ensure its scientificity, convenience and accuracy, and to meet the actual scenario needs of financial institutions, laying the foundation for quantitative assessment of financial data security risks; on this basis, based on the financial industry data security risk assessment indicator system, the fuzzy hierarchical analysis method and the entropy weight method are used to determine the subjective and objective weights, and then the fuzzy comprehensive evaluation method is used to calculate the data security risk value to construct a financial data security risk assessment method, which can conduct objective and accurate data security risk assessment and fully grasp the data security risk. The present invention can grasp the current data security management status and problems of the assessment object, and has good effectiveness, applicability and execution strength at the practical level; the financial data security risk assessment method and device proposed in the present invention can well meet the work needs of data security planning, system construction, data security governance, data security utilization and other work of various institutions in the financial industry. With the help of scientific, reasonable, feasible and effective data security risk assessment results, it can timely discover and deal with data security risks, clarify the key tasks, core technologies, weak links and other issues that need to be focused on and solved in the process of data security management and technical protection, provide strong support for financial institutions to further improve or enhance their own data security capabilities, and can effectively promote the reasonable formulation and effective implementation of financial institutions' data security management and control strategies and mechanisms.
[0122] The following describes a financial data security risk assessment method provided by this application through specific examples.
[0123] A green loan service system of a company using big data technology was selected as an empirical case, and the financial data security risk assessment method proposed in this application was used to assess the company's data security risk. The assessment results were then analyzed to verify the effectiveness, applicability and implementation of the method in actual operations.
[0124] 1. Determine the weight of indicator levels
[0125] This embodiment of the present application constructs a financial data security risk assessment indicator system (based on the full set of target risk indicators mentioned in the above embodiment, through adaptive optimization, to form the data security risk assessment indicator system of this embodiment), as detailed in Table 6. Subsequently, six data management experts from the company were invited to score the importance of the evaluation indicators in Table 6 according to the relative importance scaling rules in Table 5. Based on the expert scores, a 48-point fuzzy judgment matrix consisting of one set of primary indicators and seven sets of secondary indicators was constructed.
[0126] Table 6 Index evaluation criteria
[0127]
[0128]
[0129] Taking the three secondary indicators in the first-level risk indicator data asset management C1 as an example, six experts were gathered to score the importance of the secondary indicators in the data asset management indicators. The specific data are shown in Table 7.
[0130] Table 7 Expert scoring table of the importance of data asset management risk indicators
[0131]
[0132]
[0133] Based on the expert scores, a fuzzy judgment matrix is constructed and normalized to form a fuzzy consistency matrix. Based on this, the subjective weights assigned by the six experts to the three risk indicators are calculated using formula (6), and the initial weight results of the three risk indicators are obtained as follows: Figure 4 As shown. Based on the entropy weight method and using formulas (7) and (8), the entropy weight of risk indicators C11-C13 is calculated as ω1 = (0.1639, 0.3193, 0.0239, 0.0239, 0.1639, 0.3051), as shown Figure 5 By modifying the subjective weights of C11-C13 through entropy weight, the target weights for determining the risk indicators of data asset management are obtained as follows:
[0134] Similarly, the target indicator weights of the data security management risk indicators are calculated based on the expert scoring results: The target indicator weights of the network security risk indicator are: The target indicator weights of data security operation risk indicators are: The target indicator weights of the data behavior security risk indicator are: The target indicator weights of the data flow security risk indicator are: The target indicator weights of data application security risk indicators are: The modified subjective weight of the secondary indicator is as follows: Figure 6 shown.
[0135] According to the analysis of the importance of the first-level risk indicators in the expert scoring table, the target indicator weight distribution of the first-level risk indicators is obtained as follows: * =(0.1286,0.1333,0.1306,0.1509,0.1392,0.1608,0.1567).
[0136] 2. Implement data security risk assessment
[0137] 1) Determine the evaluation factor set, comment set and evaluation criteria
[0138] Based on Table 8, a financial data security risk assessment method is established, and then an evaluation factor set U = (u1, u2, ..., u7) is constructed. On this basis, the evaluation factor comment sets at each level are determined, and according to the risk level classification standard, combined with the evaluation accuracy and implementation scenario, the data security risk assessment level is subdivided into five levels: V = (v1, v2, v3, v4, v5) = (safe, relatively safe, general, relatively dangerous, and very dangerous). In order to quantify the evaluation index system, the comprehensive evaluation results of the evaluation indicators are obtained through the comment set. This application adopts an expert scoring mechanism and quantifies the evaluation level on a percentage basis. The score intervals for the five-level evaluation are set as [100, 80], [80, 60], [60, 40], [40, 20], and [20, 0]. The middle value of each interval is selected as the evaluation value, that is, the comment set Q = (90, 70, 50, 30, 10).
[0139] In order to ensure that evaluators have a clear reference when evaluating indicators, the connotation of the evaluation indicators is supplemented with qualitative descriptions, as shown in Table 8.
[0140] Table 8 Index evaluation standards
[0141]
[0142]
[0143]
[0144]
[0145] 2) Constructing the fuzzy membership matrix
[0146] This embodiment uses a questionnaire survey method to construct a fuzzy membership matrix. To ensure the validity of the questionnaire survey results, 20 staff members were selected as survey subjects, and an evaluation level distribution table of the department's safety risk assessment indicators was obtained, as shown in Table 9.
[0147] Table 9 Financial Data Security Risk Index Score Table
[0148]
[0149]
[0150] 3) Construct fuzzy comprehensive evaluation based on weights
[0151] Taking the comprehensive evaluation of data management asset risk as an example, according to the financial data security risk index score table in Table 9, the fuzzy membership matrix R of the evaluation factor set U1 is i for:
[0152]
[0153] The target indicator weight C1 is (0.3277, 0.3868, 0.2855).
[0154] The fuzzy comprehensive evaluation set D1 is:
[0155]
[0156] 4) Analysis of financial data security risk assessment results
[0157] By analogy, the remaining fuzzy comprehensive evaluation sets D2…D7 can be obtained. According to the fuzzy comprehensive evaluation sets D1…D7, the fuzzy membership matrix R of the comment set U can be obtained as follows:
[0158]
[0159] Target indicator weight C = (0.1286, 0.1333, 0.1306, 0.1509, 0.1392, 0.1608, 0.1567)
[0160] The fuzzy comprehensive evaluation result S is: S = DQ T =69.08
[0161] 3. Analysis of Financial Data Security Risk Assessment Results
[0162] Using the financial industry data security risk assessment method, the company's data security score reached 69.08, placing it at the "relatively secure" level, but still falling short of the "secure" standard. To ensure data security, the company urgently needs to strengthen its data security system.
[0163] An in-depth analysis of the first-level risk indicators based on their fuzzy membership matrix and target weights revealed that the data asset management risk and data behavior security risk assessment sets were (0.2441, 0.4378, 0.2660, 0.0521, 0.0000) and (0.1739, 0.4991, 0.1920, 0.1061, 0.0289), respectively. The assessments fell primarily in the "relatively safe" and "general" ranges, with "relatively safe" having the highest membership. The data security management risk and network security assurance risk assessment sets were (0.4057, 0.3948, 0.1691, 0.0198, 0.0106) and (0.4890, 0.4036, 0.1001, 0.0073, 0.0000), respectively. The assessments were primarily in the "safe" and "relatively safe" ranges, with "safe" having the highest membership. The data security operation risk and data flow security risk assessment sets are (0.2858, 0.5557, 0.1128, 0.0456, 0.0000) and (0.2037, 0.5061, 0.2028, 0.0788, 0.0086), respectively. The evaluation results are primarily in the "safe" and "relatively safe" ranges, with "relatively safe" having the highest membership. The data application security risk assessment set is (0.2214, 0.3847, 0.3153, 0.0786, 0.0000), and the evaluation results are primarily distributed in the "relatively safe" and "general" ranges. The "relatively safe" range has a higher membership, but the "general" range has a membership close to "relatively safe."
[0164] An in-depth analysis of the secondary risk indicator set, based on the fuzzy membership matrix and target weight set, revealed that, according to the maximum membership principle, the data application security risk assessment revealed that data access security, data provision security, and data aggregation and fusion security performed the worst, with their evaluation results primarily falling within the "general" category. In terms of impact, data provision security and data aggregation and fusion security ranked first and second with weights of 0.4285 and 0.2928, respectively, and had the greatest impact on overall data application security risk. Meanwhile, data asset management risk also had a high "general" membership, with data asset identification and classification and grading management having weights of 0.3277 and 0.3868, respectively, making them key risk factors in data asset management.
[0165] The above analysis shows that data application security risks are the highest, and the department needs to focus on monitoring and preventing them. Data access security should be ensured through access control, and encryption, desensitization, and watermarking technologies should be used to ensure the security of data transmission. At the same time, the security of data aggregation and integration should be ensured through scope control and assessment. Data security management, network security assurance, data security operations, and data flow security risks are relatively low, but continued strengthening of management and control is still required. Data asset management and data behavior security risks are in the "relatively safe" range, but "general" risks account for a large proportion. To prevent potential risks, it is necessary to control the agency's data intellectual property catalog, classify and label the data, and verify the quality of the collected data.
[0166] The experiment shows that, combined with the actual situation of this case, the application of the financial data security risk assessment method proposed in this application can scientifically, conveniently and accurately construct a data security risk assessment indicator system that conforms to the actual scenario of financial institutions, laying the foundation for the next step of quantitative financial data security risk assessment of the assessment object. On this basis, it is possible to objectively and accurately evaluate the data security risk of the system described in this case, fully understand its current data security management status and problems, and further verify that the method described in this application has good effectiveness, applicability and execution strength at the practical level, and can well meet the data security planning, system construction, data security governance, data security utilization and other work needs of various financial institutions. With the help of scientific, reasonable, feasible and effective data security risk assessment results, it is possible to timely discover and deal with data security risks, clarify the key tasks, core technologies, weak links and other issues that need to be focused on and resolved in the process of data security management and technical protection, provide strong support for financial institutions to further improve or enhance their own data security capabilities, and effectively promote the rational formulation and effective implementation of financial institutions' data security management strategies and mechanisms.
[0167] In some embodiments of the present application, a financial data security risk assessment device is provided, which corresponds one-to-one to the financial data security risk assessment method in the above embodiment. Figure 7 As shown, the financial data security risk assessment device includes a determination module 101, a screening module 102, a correction module 103, a calculation module 104 and an analysis module 105. The functional modules are described in detail as follows:
[0168] A determination module 101 is configured to determine an initial risk indicator set, wherein the initial risk indicator set includes a plurality of risk indicators that affect the security of financial data;
[0169] A screening module 102 is configured to screen the initial risk indicator set based on an approximate ideal solution sorting method to determine a target risk indicator set, wherein the target risk indicator set includes n first-level risk indicators, and the n first-level risk indicators correspond to n second-level risk indicator sets;
[0170] The determination module 101 is further configured to determine an initial weight set of the target risk indicator set based on the fuzzy analytic hierarchy process, wherein the weight set includes the weight sets of the n first-level risk indicators and the weight set of each second-level risk indicator set;
[0171] A correction module 103 is used to correct the initial weight set of the target risk indicator set by using the entropy weight of the target risk indicator set to obtain a target weight set of the target risk indicator set;
[0172] The calculation module 104 is used to calculate the fuzzy comprehensive evaluation result of the financial data security risk based on the fuzzy membership matrix of the evaluation factor set, the target weight set of the target risk indicator set, and the assignment matrix of the comment set; wherein the evaluation factor set includes factors affecting the financial data security risk assessment, and the comment set represents the assessment level of the financial data security risk.
[0173] In some embodiments of the present application, the determination module 101 is specifically used to determine the distance between each risk indicator in the initial risk indicator set and the positive ideal solution, as well as the distance between each risk indicator and the negative ideal solution; based on the distance between each risk indicator and the positive ideal solution, as well as the distance between each risk indicator and the negative ideal solution, calculate the relative proximity of each risk indicator; and use the risk indicator with a relative proximity higher than a threshold as the target risk indicator set.
[0174] In some embodiments of the present application, the determination module 101 is specifically used to determine the fuzzy judgment matrix of the target risk indicator set, perform consistency check on the fuzzy judgment matrix of the target risk indicator set, and generate a fuzzy consistency matrix of the target risk indicator set; based on the fuzzy consistency matrix of the target risk indicator set, calculate the initial weight set of the target risk indicator set.
[0175] In some embodiments of the present application, the determination module 101 is specifically configured to determine a fuzzy judgment matrix of the first-level risk indicator set and fuzzy judgment matrices of n second-level risk indicator sets, perform a consistency check on each fuzzy judgment matrix, and generate a fuzzy consistency matrix of the first-level risk indicator set and a fuzzy consistency matrix of each second-level risk indicator set;
[0176] In some embodiments of the present application, the determination module 101 is specifically used to calculate the initial weight set of the first-level risk indicator set based on the fuzzy consistency matrix of the first-level risk indicator set, wherein the initial weight set of the first-level risk indicator set includes the initial weight of each first-level risk indicator; and calculate the initial weight set of each second-level risk indicator set based on the fuzzy consistency matrix of n second-level risk indicator sets.
[0177] In some embodiments of the present application, the entropy weight of the target risk indicator set is determined based on the following process: constructing an entropy weight method original data matrix based on the initial weight set of the target risk indicator set; determining the information entropy of each risk indicator based on the entropy weight method original data matrix; and calculating the entropy weight of each risk indicator based on the information entropy of each risk indicator.
[0178] In some embodiments of the present application, the correction module 103 is specifically used to correct the initial weight set of the first-level risk indicator set based on the entropy weight of the first-level risk indicator set to obtain the target weight set of the first-level risk indicator set; and correct the initial weight set of each second-level risk indicator set based on the entropy weight of each second-level risk indicator set to obtain the target weight set of each second-level risk indicator set.
[0179] In some embodiments of the present application, the evaluation factor set is determined, and the evaluation factor set is divided into s sub-factor sets; wherein, the evaluation factor set corresponds to a first-level risk indicator set, and each sub-factor set corresponds to a second-level risk indicator set; each sub-factor set is fuzzy evaluated to determine a fuzzy evaluation set of each sub-factor set; based on the fuzzy evaluation set of each sub-factor set and the target indicator weight set of its corresponding second-level risk indicator set, a fuzzy comprehensive evaluation set of each sub-factor set is determined; based on the fuzzy comprehensive evaluation sets of the s sub-factor sets, a fuzzy membership matrix of the evaluation factor set is constructed.
[0180] In some embodiments of the present application, the fuzzy comprehensive evaluation result is calculated based on the following method:
[0181]
[0182] Among them, S represents the fuzzy comprehensive evaluation result, C represents the target indicator weight set of the first-level risk indicator set, R represents the fuzzy membership matrix of the evaluation factor set, Q T represents the transposed matrix of Q, and Q represents the assignment matrix of the comment set.
[0183] In some embodiments of the present application, the device further comprises an analysis module 105, which is configured to analyze the financial data security based on the fuzzy membership matrix of the first-level risk indicator set and the target weight set, determine the first-level risk indicator with the highest security risk; analyze the financial data security based on the fuzzy membership matrix of the second-level risk indicator set and the target weight set, determine the second-level risk indicator with the highest security risk; and develop security measures to improve the security of the financial data based on the first-level risk indicator with the highest security risk and the second-level risk indicator with the highest security risk.
[0184] It should be noted that any of the above financial data security risk assessment devices can correspond to the implementation of the aforementioned financial data security risk assessment method, which will not be described here.
[0185] Figure 8 A structural schematic diagram of an electronic device provided by an embodiment of the present application is shown. As shown in the figure, Figure 8 At the hardware level, the electronic device includes a processor, and optionally further includes an internal bus, a network interface, and a memory. The memory can include a memory such as a random-access memory (RAM), and can also include a non-volatile memory such as at least one disk memory. Of course, the electronic device can also include other hardware required by the business.
[0186] The processor, network interface, and memory can be connected to each other through an internal bus, which can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, and a control bus. For ease of representation, Figure 8 In the figure, only one bidirectional arrow is used to represent the bus, but it does not mean that there is only one bus or only one type of bus.
[0187] The memory is used to store programs. Specifically, the program can include program code, and the program code includes computer operation instructions. The memory can include a memory and a non-volatile memory, and provides instructions and data to the processor.
[0188] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs, and forms a financial data security risk assessment device at the logical level. The processor executes the program stored in the memory, and is specifically configured to execute the aforementioned method.
[0189] The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by hardware integrated logic circuits in the processor or by software instructions. The above processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of this application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly implemented and executed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.
[0190] The electronic device can execute the financial data security risk assessment method provided by multiple embodiments of the present application, and realize a financial data security risk assessment device in Figure 7 The functions of the illustrated embodiment will not be described in detail in the embodiments of the present application.
[0191] An embodiment of the present application also proposes a computer-readable storage medium, which stores one or more programs, and the one or more programs include instructions. When the instructions are executed by an electronic device including multiple application programs, the electronic device can execute the financial data security risk assessment method provided by multiple embodiments of the present application.
[0192] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0193] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0194] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0195] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0196] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0197] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0198] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0199] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0200] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0201] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A financial data security risk assessment method, characterized in that: The method comprises: Determining an initial risk indicator set, wherein the initial risk indicator set includes a plurality of risk indicators that affect financial data security; Based on the approximate ideal solution sorting method, the initial risk indicator set is screened to determine the target risk indicator set, which includes A first-level risk indicator, The first-level risk indicators correspond to A set of secondary risk indicators; the primary risk indicators include asset management risk, data security management risk, network security risk, data security operation risk, data behavior security risk, data flow security risk and data application security risk; The initial weight set of the target risk indicator set is determined based on the fuzzy analytic hierarchy process, and the weight set includes The weight set of each first-level risk indicator and the weight set of each second-level risk indicator set; The entropy weight of the target risk indicator set is used to modify the initial weight set of the target risk indicator set to obtain the target weight set of the target risk indicator set; Calculating a fuzzy comprehensive evaluation result of the financial data security risk based on a fuzzy membership matrix of an evaluation factor set, a target weight set of a target risk indicator set, and an assignment matrix of a comment set; wherein the evaluation factor set includes factors affecting the financial data security risk assessment, and the comment set represents an assessment level of the financial data security risk; The fuzzy membership matrix of the evaluation factor set is determined based on the following method: Determine the evaluation factor set and divide the evaluation factor set into sub-factor sets; among them, the assessment factor set corresponds to the first-level risk indicator set, and each sub-factor set corresponds to a second-level risk indicator set; Conduct fuzzy evaluation on each sub-factor set and determine the fuzzy evaluation set of each sub-factor set; Based on the fuzzy evaluation set of each sub-factor set and the target indicator weight set of the corresponding secondary risk indicator set, the fuzzy comprehensive evaluation set of each sub-factor set is determined; based on The fuzzy comprehensive evaluation set of the sub-factor sets is constructed to construct the fuzzy membership matrix of the evaluation factor set.
2. The method according to claim 1, characterized in that The method of sorting based on the approximate ideal solution is used to screen the initial risk indicator set to determine the target risk indicator set, including: Determining the distance between each risk indicator in the initial risk indicator set and a positive ideal solution, and the distance between each risk indicator and a negative ideal solution; Calculate the relative closeness of each risk indicator based on the distance between each risk indicator and the positive ideal solution, and the distance between each risk indicator and the negative ideal solution; The risk indicators with relative proximity higher than the threshold are used as the target risk indicator set.
3. The method according to claim 1, characterized in that The initial weight set of the target risk indicator set is determined based on the fuzzy analytic hierarchy process, including: Determine the fuzzy judgment matrix of the target risk indicator set, perform consistency test on the fuzzy judgment matrix of the target risk indicator set, and generate the fuzzy consistency matrix of the target risk indicator set; Based on the fuzzy consistency matrix of the target risk indicator set, the initial weight set of the target risk indicator set is calculated.
4. The method according to claim 3, characterized in that The step of determining the fuzzy judgment matrix of the target risk indicator set, performing consistency check on the fuzzy judgment matrix of the target risk indicator set, and generating the fuzzy consistency matrix of the target risk indicator set includes: Determine the fuzzy judgment matrix and The fuzzy judgment matrix of the second-level risk indicator set is constructed, and the consistency test is performed on each fuzzy judgment matrix to generate the fuzzy consistency matrix of the first-level risk indicator set and the fuzzy consistency matrix of each second-level risk indicator set; The calculation of the initial weight set of the target risk indicator set based on the fuzzy consistency matrix of the target risk indicator set includes: Calculating an initial weight set of the first-level risk indicator set based on the fuzzy consistency matrix of the first-level risk indicator set, wherein the initial weight set of the first-level risk indicator set includes an initial weight of each first-level risk indicator; based on The fuzzy consistency matrix of the secondary risk indicator set is used to calculate the initial weight set of each secondary risk indicator set.
5. The method according to claim 1, wherein The entropy weight of the target risk indicator set is determined based on the following process: Constructing an entropy weight method original data matrix based on the initial weight set of the target risk indicator set; Determine the information entropy of each risk indicator based on the original data matrix of the entropy weight method; The entropy weight of each risk indicator is calculated based on the information entropy of each risk indicator.
6. The method according to claim 4, characterized in that The method of modifying the initial weight set of the target risk indicator set by using the entropy weight of the target risk indicator set to obtain the target weight set of the target risk indicator set includes: Based on the entropy weight of the first-level risk indicator set, the initial weight set of the first-level risk indicator set is modified to obtain the target weight set of the first-level risk indicator set; Based on the entropy weight of each secondary risk indicator set, the initial weight set of each secondary risk indicator set is modified to obtain the target weight set of each secondary risk indicator set.
7. The method according to claim 1, characterized in that The fuzzy comprehensive evaluation results are calculated based on the following method: in, represents the fuzzy comprehensive evaluation result, , Represents the target indicator weight set of the first-level risk indicator set, represents the fuzzy membership matrix of the evaluation factor set, represents the transposed matrix of Q, and Q represents the assignment matrix of the comment set.
8. The method according to any one of claims 1 to 7, characterized in that The method further comprises: Analyze financial data security based on the fuzzy membership matrix and target weight set of the first-level risk indicator set to determine the first-level risk indicator with the highest security risk; Analyze financial data security based on the fuzzy membership matrix and target weight set of the secondary risk indicator set to determine the secondary risk indicator with the highest security risk; Based on the first-level risk indicators with the highest security risks and the second-level risk indicators with the highest security risks, security measures to improve the security of financial data are formulated.
9. A financial data security risk assessment device, characterized in that: The device comprises: a determination module, configured to determine an initial risk indicator set, wherein the initial risk indicator set includes a plurality of risk indicators that affect the security of financial data; A screening module is used to screen the initial risk indicator set based on the approximate ideal solution sorting method to determine the target risk indicator set, which includes A first-level risk indicator, The first-level risk indicators correspond to A set of secondary risk indicators; the primary risk indicators include asset management risk, data security management risk, network security risk, data security operation risk, data behavior security risk, data flow security risk and data application security risk; The determination module is also used to determine the initial weight set of the target risk indicator set based on the fuzzy hierarchical analysis method, and the weight set includes The weight set of each first-level risk indicator and the weight set of each second-level risk indicator set; A correction module is used to correct the initial weight set of the target risk indicator set by using the entropy weight of the target risk indicator set to obtain a target weight set of the target risk indicator set; A calculation module is configured to calculate a fuzzy comprehensive evaluation result of the financial data security risk based on a fuzzy membership matrix of an evaluation factor set, a target weight set of a target risk indicator set, and an assignment matrix of a comment set; wherein the evaluation factor set includes factors affecting the financial data security risk assessment, and the comment set represents an assessment level of the financial data security risk; and the fuzzy membership matrix of the evaluation factor set is determined based on the following method: Determine the evaluation factor set and divide the evaluation factor set into sub-factor sets; among them, the assessment factor set corresponds to the first-level risk indicator set, and each sub-factor set corresponds to a second-level risk indicator set; Conduct fuzzy evaluation on each sub-factor set and determine the fuzzy evaluation set of each sub-factor set; Based on the fuzzy evaluation set of each sub-factor set and the target indicator weight set of the corresponding secondary risk indicator set, the fuzzy comprehensive evaluation set of each sub-factor set is determined; based on The fuzzy comprehensive evaluation set of the sub-factor sets is constructed to construct the fuzzy membership matrix of the evaluation factor set.
Citation Information
Patent Citations
Data asset security risk assessment method and device, equipment and medium
CN115292756A
Pipe network safety risk level assessment method and device, electronic equipment and storage medium
CN118674280A