A financial data security management system and its method

By introducing data monitoring, vulnerability prediction, dynamic isolation and behavioral analysis modules into the financial data security management system, the shortcomings of the existing system in monitoring account behavior and permission changes are solved, and more effective security management of financial data is achieved, and data security and stability are improved.

CN119848882BActive Publication Date: 2025-06-13QUANZHOU ENG VOCATIONAL & TECH COLLEGE

Patent Information

Application Number
CN202510343533.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-13
Estimated Expiration
2045-03-21

AI Technical Summary

Technical Problem

The existing financial data security management system lacks continuous monitoring of account behavior and permission changes, resulting in insufficient effectiveness in dealing with internal risks and complex security threats, difficulty in adapting to rapidly changing threat environments, and increasing the risk of data breaches or financial fraud.

Method used

It provides a financial data security management system, including data monitoring module, vulnerability prediction module, dynamic isolation module and behavior analysis module. By collecting and analyzing transaction flows and account behaviors in financial data flows in real time, identifying abnormal operation risks, predicting security vulnerabilities, dynamically isolating data storage nodes, and analyzing account behavior patterns, adjusting access permissions and transaction verification methods.

Benefits of technology

Through in-depth monitoring and analysis of financial data, the ability to identify and handle abnormal operations is improved, data security is enhanced, and the security of data in transmission and storage is significantly improved, ensuring the overall security and stability of the financial data environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119848882B_ABST
    Figure CN119848882B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data security, and specifically to a financial data security management system and method, including a data monitoring module, a vulnerability prediction module, a dynamic isolation module, a behavior analysis module, and a security response module. In the present invention, through in-depth monitoring and analysis of financial data, the ability to identify and handle abnormal operations is improved, thereby enhancing data security. By collecting financial transaction and account behavior data in real time, and conducting detailed analysis on the frequency of fund flow and account access, risks are effectively identified and potential security vulnerabilities are predicted. By dynamically analyzing the association between transaction nodes and risk events, the risk level is evaluated, and the data storage location and access permissions are automatically adjusted according to the risk assessment, significantly improving the security of data during transmission and storage. In addition, by monitoring the changes in the behavior patterns of accounts after isolation, abnormal activities are further identified and corrected, ensuring the overall security and stability of the financial data environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a financial data security management system and method. Background Art

[0002] The technical field of data security encompasses information protection and management, aiming to prevent unauthorized access, use, disclosure, destruction, modification, or interruption. It covers a wide range of technologies from physical security measures to encryption techniques to protect data stored on digital media, including network security measures such as firewalls and intrusion detection systems, data encryption technologies, and access control mechanisms to ensure that only authorized users can access sensitive information. Overall, the technical field of data security focuses on developing and applying various tools and strategies to combat data leakage, data theft, and other forms of information security threats.

[0003] Among them, a financial data security management system refers to a system specifically designed to protect and process sensitive financial-related data. The subject matter covers technical measures for specific security requirements of financial data, such as implementing enhanced data encryption, specific access control policies, and data integrity verification to ensure that only users with corresponding permissions can access or modify financial data, and implementing encryption during data transmission and storage to prevent unauthorized access or leakage of data, including monitoring functions for data access and modification activities for security auditing and compliance checks.

[0004] The prior art lacks continuous monitoring of account behaviors and permission changes, which limits its effectiveness in dealing with internal risks and complex security threats, lacks sufficient flexibility to adapt to a rapidly changing threat environment, especially in the financial field with high data liquidity and frequent transactions. It responds slowly when new or variant security threats emerge, increasing the risk of data leakage or financial fraud. It lacks in-depth integration of account behavior patterns and capital liquidity analysis, making it difficult to predict and prevent potential internal and external security threats in a timely manner, thus resulting in unauthorized access to or loss of important financial information. Summary of the Invention

[0005] In order to solve the technical problems existing in the prior art, which lacks continuous monitoring of account behaviors and permission changes, limits its effectiveness in dealing with internal risks and complex security threats, lacks sufficient flexibility to adapt to a rapidly changing threat environment, especially in the financial field with high data liquidity and frequent transactions, responds slowly when new or variant security threats emerge, increases the risk of data leakage or financial fraud, lacks in-depth integration of account behavior patterns and capital liquidity analysis, and makes it difficult to predict and prevent potential internal and external security threats in a timely manner, thus resulting in unauthorized access to or loss of important financial information, the embodiments of the present invention provide a financial data security management system and method. The technical solution is as follows:

[0006] On the one hand, a financial data security management system is provided, and the system includes:

[0007] The data monitoring module collects transaction records and account behaviors in the financial data stream, analyzes the change frequency of fund flows, calculates the access frequency of accounts, compares the change frequency of fund flows with the access frequency, judges the abnormal operation risk of accounts, and generates abnormal operation indicators;

[0008] The vulnerability prediction module locates the transaction nodes of abnormal accounts based on the abnormal operation indicators, analyzes the matching relationship between transaction nodes and risk events, evaluates the risk level of nodes, calculates the correlation degree between transaction frequency and risk events, predicts security vulnerabilities that occur in transaction nodes, and generates vulnerability risk assessment results;

[0009] The dynamic isolation module identifies risk data storage nodes based on the vulnerability risk assessment results, analyzes the distribution of financial data, calculates the migration priority, plans the transfer path, migrates data to low-risk storage nodes, and obtains data node isolation configurations;

[0010] The behavior analysis module compares the data access frequencies of accounts before and after isolation based on the data node isolation configurations, identifies abnormal account activities, judges the abnormal characteristics of account behavior patterns, locates the sources of security vulnerabilities, and obtains behavior characteristic analysis results.

[0011] On the other hand, the abnormal operation indicators include the change frequency of account funds, the access frequency difference, and the permission change frequency. The vulnerability risk assessment results include the node risk level, the transaction and event matching degree, and the vulnerability identification result. The data node isolation configurations include the data migration priority, the data migration path, and the permission update standard; The behavior characteristic analysis results include the behavior pattern change index, the access frequency comparison result, and the abnormal activity identifier.

[0012] On the other hand, the data monitoring module includes;

[0013] The fund flow analysis sub-module collects transaction records and account behaviors in the financial data stream, analyzes the time series of fund inflows and outflows of transaction records, calculates the time interval between consecutive transactions, counts the frequency changes of fund flows, compares the inflow and outflow ratios of funds, identifies accounts with abnormal fund activities, and obtains fund liquidity indicators;

[0014] The account access monitoring sub-module retrieves the access data of accounts with abnormal funds based on the fund liquidity indicators, analyzes the distribution of access times in different time periods, calculates the access fluctuation degree of accounts in the short term, judges whether there are abnormal access behaviors in accounts, and obtains account access fluctuation indicators;

[0015] Based on the account access fluctuation metrics, the privilege change statistics sub-module calls the privilege modification records of the account, counts the number of privilege changes, combines the fund flow and access monitoring data of the account, calculates the anomaly degree of the privilege change, and generates the anomaly operation metrics.

[0016] On the other hand, the vulnerability prediction module includes;

[0017] Based on the anomaly operation metrics, the abnormal transaction identification sub-module filters the transaction data of the abnormal accounts, analyzes the relevance between the transaction time and amount and the account operation mode, measures the distribution density of the abnormal transactions and classifies them, identifies the abnormal transaction nodes, and generates the abnormal transaction node set;

[0018] The transaction node matching sub-module calls the abnormal transaction node set, analyzes the transaction behavior characteristics, compares with the patterns of the identified risk events, calculates the matching degree between the nodes and the risk events, evaluates the risk level of the transaction nodes, and generates the transaction risk matching index;

[0019] Based on the transaction risk matching index, the vulnerability risk assessment sub-module analyzes the transaction frequency of the abnormal nodes, extracts the transaction time interval, calculates the transaction fluctuation range within a short period, predicts the probability of security vulnerabilities according to the risk matching degree of the nodes, and generates the vulnerability risk assessment result.

[0020] On the other hand, the calculation formula for the matching degree between the nodes and the risk events is:

[0021] ;

[0022] Evaluate the risk level of the transaction nodes and generate the transaction risk matching index;

[0023] Where M represents the matching degree between the transaction node and the risk event, represents the eigenvalue of transaction node i, represents the reference eigenvalue of risk event i, and n represents the total number of characteristics involved in the transaction node.

[0024] On the other hand, the dynamic isolation module includes;

[0025] Based on the vulnerability risk assessment result, the risk node identification sub-module detects the risk nodes in the data storage network, analyzes the types and sensitivity of the financial data stored in the nodes, filters the storage nodes with security vulnerabilities, determines the range of data nodes to be isolated, and obtains the risk node list;

[0026] Based on the risk node list, the data migration analysis sub-module analyzes the data distribution in the affected nodes, calculates the data correlation degree and interaction frequency between the nodes, judges the impact range and priority of the data migration, and generates the data migration priority index;

[0027] The data association degree and interaction frequency between the computing nodes are calculated using the formula:

[0028] ;

[0029] Judge the influence range and priority order of data migration, and generate a data migration priority index;

[0030] Calculate the data interaction frequency , judge the influence range and priority order of data migration, and generate a data migration priority index;

[0031] Among them, represents the data interaction frequency between node a and node b, represents the data throughput of node a in data dimension v, represents the data throughput of node b in data dimension v, represents the request frequency of node a in data dimension v, represents the request frequency of node b in data dimension v, and w represents the total number of data dimensions;

[0032] Based on the data migration priority index, the data storage reconstruction sub-module analyzes the data transfer path between storage nodes, allocates storage resources, plans the optimal data migration path, and adjusts the access permissions of secure storage nodes to obtain the data node isolation configuration.

[0033] On the other hand, the behavior analysis module includes;

[0034] Based on the data node isolation configuration, the behavior pattern change analysis sub-module calls the behavior records of the isolated accounts, compares the account activity characteristics before and after isolation, analyzes the amplitude and frequency of account behavior changes, calculates the deviation degree of the behavior pattern, and obtains the behavior pattern deviation index;

[0035] Based on the behavior pattern deviation index, the data access frequency comparison sub-module compares the data access frequencies of the accounts before and after isolation, analyzes the changes in the access time point, access duration, and access frequency, judges the fluctuation of the access frequency, and generates an access frequency fluctuation index;

[0036] Based on the access frequency fluctuation index, the abnormal behavior recognition sub-module identifies account activities that deviate from the normal pattern, analyzes the characteristics of the account abnormal behavior pattern, matches the relationship between the account activity characteristics and known vulnerabilities, locates the source of security vulnerabilities, and generates a behavior characteristic analysis result.

[0037] On the other hand, the system further includes:

[0038] Based on the results of the behavioral feature analysis, the security response module determines abnormal trading accounts, adjusts account access permissions, allocates the proportion of trading quotas, updates the account trading verification method, and generates security protection measures;

[0039] The security protection measures are specifically the account permission adjustment results, trading quota configuration, and the updated verification method.

[0040] On the other hand, the security response module includes;

[0041] The account permission control sub-module analyzes the risk operation frequency of the account based on the results of the behavioral feature analysis, calculates the impact range of account permission changes, identifies accounts with frequent abnormal operations, reconfigures the access permissions of the accounts, implements access restrictions on high-risk accounts, and generates account permission adjustment configurations;

[0042] The trading quota management sub-module calls the account permission adjustment configuration, calls the trading records of abnormal accounts, calculates the fluctuation range of trading quotas, analyzes the short-term trading quota change trend, judges the deviation degree of the trading amount from the normal account behavior, adjusts the upper limit of the trading quota of the account, allocates the proportion of trading quotas, and generates optimized trading quotas;

[0043] The verification method optimization sub-module filters accounts with abnormal trading frequencies based on the optimized trading quotas, extracts the identity verification records of the accounts, analyzes the security level of the trading verification of abnormal accounts, judges whether the trading verification matches the account risk level, optimizes the trading verification method of the account, and generates security protection measures.

[0044] On the other hand, a financial data security management method is provided. This method is applied to a financial data security management system and includes the following steps:

[0045] S1: Collect the transaction records and account behaviors in the financial data stream, analyze the change frequency of fund flows, calculate the access frequency of the account, compare the change frequency of fund flows with the access frequency, judge the abnormal operation risk of the account, and generate abnormal operation indicators;

[0046] S2: Based on the abnormal operation indicators, locate the trading nodes of abnormal accounts, analyze the matching relationship between the trading nodes and risk events, evaluate the risk level of the nodes, calculate the correlation degree between the trading frequency and risk events, predict the security vulnerabilities that may occur at the trading nodes, and generate vulnerability risk assessment results;

[0047] S3: Based on the vulnerability risk assessment results, identify the risk data storage nodes, analyze the financial data distribution, calculate the migration priority, plan the transfer path, and migrate the data to low-risk storage nodes to obtain data node isolation configurations;

[0048] S4: Based on the data node isolation configuration, compare the data access frequencies of the accounts before and after isolation, identify abnormal account activities, judge the abnormal characteristics of the account behavior patterns, locate the sources of security vulnerabilities, and obtain the analysis results of behavior characteristics;

[0049] S5: Based on the analysis results of the behavior characteristics, judge the abnormal transaction accounts, adjust the account access permissions, allocate the transaction quota ratios, update the account transaction verification methods, and generate security protection measures.

[0050] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention at least include:

[0051] Through the in-depth monitoring and analysis of financial data, the ability to identify and handle abnormal operations is improved, thereby enhancing data security. By collecting financial transaction and account behavior data in real time, the frequency of fund flows and account access frequencies are carefully analyzed to effectively identify risks and predict potential security vulnerabilities. By dynamically analyzing the association between transaction nodes and risk events, the risk levels are evaluated, and the data storage locations and access permissions are automatically adjusted according to the risk assessment, significantly improving the security of data during transmission and storage. In addition, by monitoring the changes in the behavior patterns of accounts after isolation, abnormal activities are further identified and corrected, ensuring the overall security and stability of the financial data environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0053] Figure 1 is a schematic diagram of the system of the present invention;

[0054] Figure 2 is a schematic diagram of the system framework of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0055] The following will describe the technical solutions in the present invention with reference to the drawings.

[0056] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two can be selected.

[0057] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, their intended meanings are the same. "Of", "corresponding", and "corresponding to" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, their intended meanings are the same.

[0058] In the embodiments of the present invention, sometimes subscripts such as W 1 may be written in a non-subscript form such as W1. When the difference is not emphasized, their intended meanings are the same.

[0059] To make the technical problems, technical solutions, and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0060] The embodiments of the present invention provide a financial data security management system, as Figure 1 shown. The system includes:

[0061] The data monitoring module collects transaction records and account behaviors in the financial data stream, analyzes the change frequency of fund flows, calculates the access frequency of each account, compares the change frequency of fund flows with the access frequency, and combines the number of times of account permission modification to judge the abnormal operation risk of the account and generate abnormal operation indicators.

[0062] The vulnerability prediction module locates the transaction nodes of abnormal accounts based on the abnormal operation indicators, analyzes the matching relationship between the transaction nodes and known risk events, evaluates the risk level of the transaction nodes, calculates the correlation degree between the transaction frequency and risk events, predicts the security vulnerabilities that may occur in the abnormal transaction nodes, and generates vulnerability risk assessment results.

[0063] The dynamic isolation module identifies the risk data storage nodes based on the vulnerability risk assessment results, analyzes the distribution of affected financial data, calculates the data migration priority between storage nodes, plans the data transfer path, migrates the data to low-risk storage nodes, and adjusts the access permissions of the nodes to obtain the data node isolation configuration.

[0064] The behavior analysis module analyzes the change in the behavior pattern of isolated accounts based on the data node isolation configuration, compares the data access frequency of the accounts before and after isolation, identifies account activities that deviate from normal behaviors, judges the abnormal characteristics of the account behavior pattern, and locates the source of security vulnerabilities to obtain the behavior characteristic analysis results.

[0065] The security response module judges abnormal transaction accounts based on the behavior characteristic analysis results, adjusts the account access permissions according to the account risk level, allocates the transaction quota ratio, updates the account transaction verification method, optimizes the security protection of the account, and generates security protection measures.

[0066] Abnormal operation indicators include the frequency of account fund changes, the difference in access frequencies, and the frequency of permission changes. The results of vulnerability risk assessment include the node risk level, the matching degree of transactions and events, and the vulnerability identification results. The data node isolation configuration includes the data migration priority, the data migration path, and the permission update standard; the results of behavior feature analysis include the behavior pattern change indicators, the comparison results of access frequencies, and the abnormal activity identification; the specific security protection measures are the account permission adjustment results, the transaction amount configuration, and the updated verification method.

[0067] As Figure 2 shown, the data monitoring module includes;

[0068] The fund flow analysis sub-module collects the transaction records and account behaviors in the financial data stream, analyzes the time series of fund inflows and outflows of the transaction records, calculates the time intervals between consecutive transactions, statistically analyzes the frequency changes of fund flows, compares the inflow and outflow ratios of funds, identifies the accounts with abnormal fund activities, and obtains the fund liquidity indicators;

[0069] Extract the fund inflow and outflow data from the transaction record logs and account behavior monitoring records. The time series of fund inflows and outflows is obtained by parsing the timestamp field in the transaction record. After sorting each transaction in chronological order, calculate the time interval between adjacent transactions. Assume that the transaction record data set contains a transaction time field , then the calculation method of the time interval between consecutive transactions is , where represents the time interval between the th transaction and the previous transaction. After calculating all the time interval values, statistically analyze their mean, variance, and extreme values to obtain the time distribution characteristics of transaction activities. When calculating the fund flow frequency, set a time window , and count the number of transactions within the time window. Then the calculation method of the fund flow frequency is . If the number of transactions of an account within a 1-hour window is 25, then transactions per hour. The fund flow ratio is calculated separately for fund inflows and outflows. Assume that the fund inflow amount is , and the fund outflow amount is . Then the calculation method of the fund flow ratio is . For example, if the total fund inflow of an account within a day is 50,000 yuan and the total fund outflow is 40,000 yuan, then the fund flow ratio . If the fund flow ratio exceeds the set threshold, it may indicate abnormal fund operations. When identifying abnormal fund accounts, select the standard deviation of the transaction time interval and the fund flow ratio as the judgment basis. If the standard deviation of the transaction time interval of an account minutes and the fund flow ratio and is higher than the system-set abnormal threshold , then it is determined that the account is an abnormal account, and the capital liquidity index is integrated based on the above calculation results.

[0070] The account access monitoring sub-module retrieves the access data of the abnormal capital account based on the capital liquidity index, analyzes the distribution of the number of accesses in different time periods, calculates the access fluctuation degree of the account in the short term, determines whether there is abnormal access behavior of the account, and obtains the account access fluctuation index;

[0071] Set the time partition and the corresponding number of accesses , then the access frequency distribution vector is , the short-term access fluctuation degree is measured by calculating the change rate of the number of accesses. Set the time period and The number of accesses in are and , respectively, then the calculation method of the access volatility is , if an account has 15 accesses in the 10-minute time period , and 30 accesses in the time period , then the access volatility , that is, the number of accesses increases by 100%. The judgment of abnormal access behavior is based on the abnormal threshold of the access volatility , if it is set , then the volatility 1.0 of this account is higher than the threshold, and it is determined as abnormal access. The account access fluctuation index is obtained by integrating the access frequency distribution vector and the access volatility.

[0072] The permission change statistics sub-module calls the permission modification records of the account based on the account access fluctuation index, counts the number of permission changes, combines the capital flow and access monitoring data of the account, calculates the abnormal degree of the permission change, and generates an abnormal operation index.

[0073] Set the account The number of permission modifications within the time window is , the number of permission changes is , combining the capital flow and access monitoring data, calculate the abnormal degree of the permission change. Set the capital liquidity index and the account access fluctuation index , then the calculation method of the abnormal permission change score is , where , , are adjustment coefficients, set according to the original data statistics. If it is set that an account has 5 permission changes in the past 24 hours, the capital liquidity index is 3.2, and the access fluctuation index is 1.8. The adjustment coefficient is taken , , , if , the abnormal privilege change score exceeds the set threshold , then the account is determined to be an abnormal account, and the abnormal operation index is calculated based on the comprehensive calculation of the number of privilege changes, capital liquidity, and access fluctuation data.

[0074] As Figure 2 shown, the vulnerability prediction module includes;

[0075] The abnormal transaction identification sub-module filters the transaction data of abnormal accounts based on the abnormal operation index, analyzes the correlation between the transaction time and amount and the account operation mode, calculates the distribution density of abnormal transactions and classifies them, identifies abnormal transaction nodes, and generates a set of abnormal transaction nodes;

[0076] Call the database log to extract the account transaction details. Let the set of all transaction records of account P within time Q be , and retain all transactions that meet during the screening. The correlation analysis of the transaction time and amount uses the transaction data regression method. Let the transaction amount of account P at transaction time Q be , and the time interval be , calculate its regression relationship, and define the correlation calculation formula:

[0077] ;

[0078] where and are the means of the transaction amount and transaction time interval of account P respectively. If , then the correlation between the transaction mode and the account operation mode is relatively strong. The calculation of the abnormal transaction distribution density uses the kernel density estimation method. Let the transaction amount density function be f(R), then the abnormal transaction density calculation formula is , where h is the smoothing parameter and K(x) is the kernel function. The transaction categories with higher density values are classified as high-risk transaction types. The identification of abnormal transaction nodes is obtained by calculating the transaction abnormality degree. Let the transaction abnormality score be , and the calculation method is , where , are the weight parameters. If exceeds the set threshold , then mark the transaction as an abnormal transaction and generate a set of abnormal transaction nodes.

[0079] The trading node matching sub-module calls the abnormal trading node set, analyzes the trading behavior characteristics, compares the patterns of the identified risk events, calculates the matching degree between the node and the risk event, evaluates the risk level of the trading node, and generates a trading risk matching index;

[0080] Calculate the matching degree between the node and the risk event using the formula:

[0081] ;

[0082] Evaluate the risk level of the trading node and generate a trading risk matching index;

[0083] Among them, M represents the matching degree between the trading node and the risk event, represents the eigenvalue of trading node i, represents the reference eigenvalue of risk event i, and n represents the total number of characteristics involved in the trading node;

[0084] Trading node eigenvalue Obtained by monitoring and statistical analysis of historical trading data, the eigenvalue sources of each trading node include dimensions such as trading amount, trading frequency, number of trading counterparts, and trading time distribution. The eigenvalue calculation uses standardization processing to normalize the data of each dimension to interval, and the standardization method is:

[0085] ;

[0086] Among them, represents the original trading data value, and min(X) and max(X) respectively represent the minimum and maximum values of this trading characteristic among all trading nodes;

[0087] Risk event reference eigenvalue Obtained by analyzing the trading characteristics of known risk events, and used for comparative analysis after normalization using the same standardization method. The calculation method is:

[0088] ;

[0089] Among them, represents the eigenvalue of the identified risk event, and min(Y) and max(Y) respectively represent the minimum and maximum values of this risk event among all known risk events;

[0090] For a set of trading data, assume n = 4, and the four trading characteristics are trading amount, trading frequency, number of trading counterparts, and trading time distribution. The collected trading node characteristic data is as follows:

[0091] ;

[0092] Set the maximum and minimum values of this feature among all trading nodes:

[0093] , ;

[0094] After standardization:

[0095] ;

[0096] Features corresponding to known risk events:

[0097] ;

[0098] , ;

[0099] After standardization:

[0100] ;

[0101] Calculate the matching degree between the feature value and the risk event:

[0102]

[0103]

[0104] Calculate the sum of squares of trading features:

[0105]

[0106] Calculate the average value of risk event features:

[0107] ;

[0108] ;

[0109] Substitute into the calculation formula:

[0110] ;

[0111] Calculate the square root:

[0112] ;

[0113] Final calculation:

[0114] ;

[0115] This result indicates that the matching degree between this trading node and the identified risk event is 0.8793. The closer the value is to 1, the closer the trading behavior of the trading node is to the identified risk event, and the higher the risk level. The matching index is used for risk level assessment.

[0116] The vulnerability risk assessment sub-module analyzes the transaction frequency of abnormal nodes based on the transaction risk matching index, extracts the transaction time interval, calculates the transaction fluctuation range within a short period, predicts the probability of security vulnerabilities according to the risk matching degree of the nodes, and generates the vulnerability risk assessment result.

[0117] The vulnerability risk assessment sub-module analyzes the transaction frequency of abnormal transaction nodes, extracts the transaction time interval data. Let the number of transactions of node W within the time window X be , then the calculation method of the transaction frequency is . When calculating the short-period transaction fluctuation range, let the average value of the transaction time intervals within the time window X be , and the variance be , then the calculation method of the transaction fluctuation range is , where represents the transaction fluctuation range within the 95% confidence interval, and the transaction risk matching index is used to measure the similarity between the transaction pattern and the known risk transactions, and the calculation method is , where is the average value of the transaction frequency. The vulnerability risk prediction is calculated based on the transaction risk matching index and the transaction fluctuation range. Let the vulnerability risk score be , and the calculation method is , where , are adjustment coefficients. If exceeds the set threshold , then it is predicted that there is a security vulnerability in this node, and the vulnerability risk assessment result is generated.

[0118] As Figure 2 shown, the dynamic isolation module includes;

[0119] The risk node identification sub-module detects the risk nodes in the data storage network based on the vulnerability risk assessment result, analyzes the types and sensitivity of the financial data stored in the nodes, screens the storage nodes with security vulnerabilities, determines the range of data nodes to be isolated, and obtains the risk node list;

[0120] Call the built-in data monitoring log of the system, read the log files of the storage nodes one by one, extract the storage operations, read and write requests, and data access records. For each storage node, parse the parameters such as access time, access frequency, and data size in the log content, and compare them with the historical access records. During this process, it is necessary to count the number of accesses of each storage node in the recent period of time, calculate its access frequency change rate, set the time window to 24 hours, and record the number of accesses within each hour as , then the access frequency calculation formula is as follows: , where, represents the average access frequency of the storage node L. If the daily average change exceeds a certain set threshold, it is initially determined that there may be abnormal access behavior for this node. In addition, it is also necessary to calculate the data flow situation of the storage node, including the amount of data stored and the amount of data read , and calculate its data flow ratio : . If is significantly higher or lower than a certain reference value. For example, if the set reference value is 1.2, then when , it indicates that more data is stored in this node, which may be an abnormal upload behavior. If , it may be an abnormal data extraction behavior. Further, calculate the access distribution of the storage node in different time periods, and use the coefficient of variation to measure the fluctuation of the access behavior: , where is the standard deviation of the number of accesses, is the mean value of the number of accesses. If , it indicates that the access behavior fluctuates greatly and there may be abnormalities. Then, analyze the data types of the storage nodes, extract the data storage type fields from the logs, and determine whether they contain highly sensitive data, such as account information, transaction data, etc. Set the proportion threshold of sensitive data to 50%. If the proportion of sensitive data stored in a certain storage node exceeds 50%, the risk level of this node will be increased. Finally, combine all the calculation results, and select the storage nodes that meet one of the following conditions as risk nodes: the change rate of access frequency exceeds the set threshold; the data flow ratio is significantly abnormal (>1.2 or <0.8); the access fluctuation coefficient is greater than 1.5; the proportion of sensitive data storage exceeds 50%. The storage nodes that meet any of the above items will be included in the risk node list.

[0121] Based on the risk node list, the data migration analysis sub-module analyzes the data distribution in the affected nodes, calculates the data association degree and interaction frequency between nodes, judges the influence scope and priority of data migration, and generates a data migration priority index;

[0122] Calculate the data association degree and interaction frequency between nodes, using the formula:

[0123] ;

[0124] Judge the influence scope and priority of data migration, and generate a data migration priority index;

[0125] Among them, represents the data interaction frequency between node a and node b, represents the data throughput of node a in data dimension v, Represents the data throughput of node b in data dimension v, Represents the request frequency of node a in data dimension v, Represents the request frequency of node b in data dimension v, where w represents the total number of data dimensions;

[0126] and Represents the data throughput of node a and node b in data dimension v, with the unit of MB / s. This parameter is obtained through the traffic monitoring system, which records the transmission rate of data packets during the monitoring period and calculates it based on traffic integration. In actual data monitoring, the measured throughput values of node a in data dimension are 58.4 MB / s, 69.7 MB / s, and 63.5 MB / s respectively, and the measured throughput values of node b in the same dimension are 53.2 MB / s, 66.1 MB / s, and 61.8 MB / s respectively;

[0127] and Represents the request frequency of node a and node b in data dimension v, with the unit of times / s. This parameter is obtained through server log analysis, which counts the number of requests during the monitoring period and classifies them by data dimension. Log analysis shows that the request frequencies of node a in data dimension are 102 times / s, 118 times / s, and 109 times / s respectively, and the request frequencies of node b in the same dimension are 97 times / s, 123 times / s, and 113 times / s respectively;

[0128] The total number of data dimensions w = 3;

[0129] Calculation process:

[0130] First part of the calculation:

[0131] ;

[0132] Calculate each item:

[0133] 58.4×53.2 = 3107.68, 69.7×66.1 = 4610.17, 63.5×61.8 = 3928.30;

[0134] Sum:

[0135] ;

[0136] Take the square root:

[0137] ;

[0138] Second part of the calculation:

[0139] ;

[0140] Calculate each item:

[0141] 102 × 97 = 9894, 118 × 123 = 14514, 109 × 113 = 12317;

[0142] Sum:

[0143] 9894 + 14514 + 12317 = 36725;

[0144] Take the average value:

[0145] ;

[0146] Final calculation:

[0147] ;

[0148] Result analysis:

[0149] The calculation result represents the data interaction frequency between node a and node b. The magnitude of the value reflects the comprehensive level of data transmission and access intensity. A higher value indicates more frequent data interaction between nodes and more active data flow, which is suitable as an important basis for data migration analysis.

[0150] The data storage reconstruction sub-module analyzes the data transfer path between storage nodes based on the data migration priority index, allocates storage resources, plans the optimal data migration path, and adjusts the access permissions of secure storage nodes to obtain the data node isolation configuration.

[0151] Parse the risk node list, read the data transfer situation of each risk node's storage data, calculate its data interaction intensity with other storage nodes, and set the data interaction frequency The calculation formula is as follows: , where represents the data access and storage volume of storage node e in data dimension u, is the access and storage volume of storage node f in the same data dimension, V is the total number of data dimensions. If , it indicates that there is a strong data interaction between storage node e and node f, and they may need to be migrated together. In the calculation of data migration priority, the load pressure of the storage node also needs to be calculated. The load pressure is defined as: , where is the current storage utilization rate of the storage node, is the maximum storage capacity of this node. If , it indicates that the storage pressure of this node is relatively high, and it is recommended to migrate it first. In addition, it is necessary to calculate the number of access conflicts of the storage node, that is, the situation where the storage node is accessed by multiple users simultaneously within a certain period of time. Let the number of conflicts be , if times, it is considered that there is an access bottleneck for this node. Combining the data interaction frequency, load pressure and access conflict situation, calculate the data migration priority of the storage node : , where , , are the weights of different factors respectively. Set , , , if the calculation result , then migrate this storage node first. Next, based on the data migration priority index, plan the optimal data migration path, and adopt the principle of the shortest data flow path, that is, preferentially select the path with the smallest data transmission volume in the migration path, and calculate the data transmission path weight : , where represents the data transmission volume on path , represents the path bandwidth, H is the total number of optional paths, and select the path with the smallest value for data migration. After the migration is completed, adjust the access permissions of the target storage node, and set the access permission update rules as follows: if the original node is a high-risk node, the target node only allows administrators to access; if the original node has a high number of access conflicts, the target node needs to set a single-user concurrent access limit to complete the data node isolation configuration.

[0152] As Figure 2 shown, the behavior analysis module includes;

[0153] The behavior pattern change analysis sub-module, based on the data node isolation configuration, calls the behavior records of the isolated accounts, compares the account activity characteristics before and after isolation, analyzes the amplitude and frequency of the account behavior changes, calculates the deviation degree of the behavior pattern, and obtains the behavior pattern deviation index;

[0154] Call the behavior records of the isolated accounts, and compare the account activity characteristics before and after isolation. Among them, the data node isolation configuration defines the data access permissions and transaction capabilities of the restricted accounts. The system extracts the access logs of the isolated accounts, identifies the data such as the number of accesses, access time intervals, changes in transaction amounts, and account operation types of each account before and after isolation, calculates the mean and standard deviation of the access time series through time series analysis methods, and sets the benchmark value of the transaction amount as the transaction mean of the account before isolation, and set the transaction amount mean before isolation Yuan, the average post-isolation transaction Yuan, calculate the change rate of the transaction amount as , set the benchmark value of the access frequency as the average daily access times of the account before isolation. Assume that the access times before isolation are 40 times per day, and after isolation, the access times drop to 22 times per day. The change rate is calculated as (22 - 40) / 40 = -45%. Determine whether there is an abnormal change in the account by setting a threshold. For example, set the behavior change threshold , if , then mark that there is a significant change in the account behavior. Combine the account operation types and count the number of operation instructions before and after isolation. For example, the average daily password modification before isolation is 2 times, and after isolation, it increases to 5 times. Then the increase rate is (5 - 2) / 2 = 150%, exceeding the abnormal change threshold , and obtain the behavior pattern deviation index.

[0155] The data access frequency comparison sub-module, based on the behavior pattern deviation index, compares the data access frequencies of the account before and after isolation, analyzes the changes in the access time points, access durations, and access frequencies, determines the fluctuations in the access frequency, and generates an access frequency fluctuation indicator;

[0156] Extract the data of the access time points, access durations, and access frequencies. The system counts the access situations of the isolated account in different time periods. Assume that the high-frequency access period of the account before isolation is 10:00 - 12:00, with 15 accesses per hour. After isolation, the access times in the same time period drop to 6 times. Calculate the access frequency change as (6 - 15) / 15 = -60%. Assume that the average access duration of the account before isolation is 30 minutes, and after isolation, it drops to 18 minutes. Calculate the change rate as (18 - 30) / 30 = -40%. Define the access frequency fluctuation indicator The calculation formula is as follows: ; where and are the average daily access frequencies before and after isolation respectively, and are the access durations. Set the fluctuation threshold , if , then mark that there is an abnormal fluctuation in the access frequency. The system analyzes the change in the access time point. Assume that the hourly access distribution of the account before isolation is {12, 15, 18, 14}, and after isolation, it changes to {5, 8, 6, 7}. Calculate the mean square error , if (set the abnormal access fluctuation threshold to 5), then determine that there is a significant fluctuation in the access mode and generate an access frequency fluctuation indicator.

[0157] The abnormal behavior recognition sub-module identifies account activities that deviate from the normal pattern based on the access frequency fluctuation index, analyzes the characteristics of abnormal behavior patterns of the account, matches the relationship between the account activity characteristics and known vulnerabilities, locates the source of security vulnerabilities, and generates the behavior characteristic analysis results.

[0158] Extract the access behavior records of the account and construct the access feature vector , calculate the similarity between the account behavior characteristics and known vulnerabilities, and set the vulnerability feature vector , and use the cosine similarity calculation: , if (set the risk threshold to 0.8), then it is identified that the account has high-risk behavior. The system counts the frequency of abnormal activities of the account. Suppose the number of abnormal logins of the account before isolation is 3 times per day, and it increases to 9 times per day after isolation. Calculate the growth rate (9 - 3) / 3 = 200%, which exceeds the abnormal threshold of 50%. It is determined that the account behavior is abnormal. The system matches the account behavior characteristics with the known vulnerability patterns and sets the vulnerability matching threshold . If the account behavior matching degree is higher than this threshold, then locate the source of the security vulnerability and generate the behavior characteristic analysis results.

[0159] As Figure 2 shown, the security response module includes;

[0160] The account permission control sub-module analyzes the risk operation frequency of the account based on the behavior characteristic analysis results, calculates the influence scope of the account permission change, identifies the accounts with frequent abnormal operations, reconfigures the access permissions of the account, implements access restrictions on high-risk accounts, and generates the account permission adjustment configuration;

[0161] Extract the operation records of the account and analyze the risk operation frequency of the account, and set the monitoring period to 30 days, and obtain the operation frequency of the account within this period from the log data , including the number of logins, the number of transaction submissions, the number of permission changes, etc., and calculate the average operation frequency of the account in the past period and the standard deviation , set the abnormal operation frequency threshold . If the current operation frequency of the account meets , then the account is marked as a high-risk account. Further calculate the influence scope of the account permission change, extract the account permission modification log, count the number of permission adjustments and calculate its mean and the standard deviation , set the abnormal permission change threshold . If , then the account has abnormal permission change behavior. Combine the risk score of the account Calculate the overall risk level of the account, set the rules for adjusting account access permissions. If (where is the high-risk threshold), then impose access restrictions on the account, including reducing data query permissions, increasing multi-factor authentication steps, restricting transaction amounts, etc., and generate the account permission adjustment configuration.

[0162] The transaction amount management sub-module calls the account permission adjustment configuration, retrieves the transaction records of abnormal accounts, calculates the fluctuation range of the transaction amount, analyzes the short-term trend of transaction amount changes, determines the deviation degree of the transaction amount from the normal account behavior, adjusts the upper limit of the account's transaction amount, allocates the transaction amount ratio, and generates the optimized transaction amount;

[0163] Obtain the transaction permission range of the restricted account, call the transaction records of abnormal accounts, and extract the transaction amount and calculate its mean and standard deviation In the transaction data of the past 30 days, calculate the fluctuation range of the current transaction amount , set the abnormal transaction fluctuation threshold , if , then determine that the account transaction amount fluctuates abnormally, further analyze the short-term trend of transaction amount changes, set the analysis window days, calculate the daily transaction amount mean sequence , calculate the regression slope of the sequence , if is greater than the positive abnormal growth threshold or less than the negative abnormal decline threshold , then the transaction amount trend is abnormal, calculate the transaction amount deviation , set the transaction amount abnormal threshold , if , then determine that the transaction amount significantly deviates from the normal behavior, finally adjust the upper limit of the account's transaction amount, set the adjustment rules , and re-allocate the transaction amount ratio, set different transaction amount adjustment ranges according to the risk level of the account, such as reducing the high-risk account amount by 50%, reducing the medium-risk account amount by 30%, and reducing the low-risk account amount by 10%, and generate the optimized transaction amount.

[0164] The verification method optimization sub-module, based on the optimized transaction amount, screens the accounts with abnormal transaction frequencies, extracts the identity verification records of the accounts, analyzes the security level of the abnormal account transaction verification, determines whether the transaction verification matches the account risk level, optimizes the account's transaction verification method, and generates security protection measures.

[0165] Screen accounts with abnormal transaction frequencies, extract the identity verification records of the accounts, analyze the transaction verification security levels of the abnormal accounts, and set the account transaction frequency detection window days, and extract the transaction count sequence of the account within the past period , calculate the average transaction frequency and the standard deviation , set the threshold for abnormal transaction frequencies , if the current transaction count of the account meets , then determine that the account's transaction frequency is abnormal, further analyze the identity verification security level of the account, extract the identity verification logs of the account, and count the usage times of different verification methods (such as passwords, fingerprints, SMS verification codes, etc.), calculate the average value of the verification methods and the standard deviation , set the threshold for the number of times of low-security-level verification , if the number of times the account uses low-security-level verification methods meets , then determine that the account has security risks. Finally, optimize the transaction verification method according to the account risk level. High-risk accounts need to use multi-factor authentication (MFA), medium-risk accounts need to add biometric authentication, and low-risk accounts need to increase the password complexity to generate security protection measures

[0166] A financial data security management method includes the following steps:

[0167] S1: Collect transaction records and account behaviors in the financial data stream, analyze the change frequency of fund flows, calculate the access frequency of the account, compare the change frequency of fund flows with the access frequency, judge the abnormal operation risk of the account, and generate abnormal operation indicators

[0168] S2: Based on the abnormal operation indicators, locate the transaction nodes of the abnormal accounts, analyze the matching relationship between the transaction nodes and risk events, evaluate the risk levels of the nodes, calculate the correlation degree between the transaction frequency and risk events, predict the security vulnerabilities that occur at the transaction nodes, and generate vulnerability risk assessment results

[0169] S3: Based on the vulnerability risk assessment results, identify the risk data storage nodes, analyze the financial data distribution, calculate the migration priority, plan the transfer path, and migrate the data to low-risk storage nodes to obtain the data node isolation configuration

[0170] S4: Based on the data node isolation configuration, compare the data access frequencies of the account before and after isolation, identify abnormal account activities, judge the abnormal characteristics of the account behavior pattern, locate the source of the security vulnerability, and obtain the behavior characteristic analysis results

[0171] S5: Based on the results of behavioral feature analysis, identify abnormal trading accounts, adjust account access permissions, allocate trading quota ratios, update account trading verification methods, and generate security protection measures.

[0172] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, both A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship. The specific meaning can be understood by referring to the context before and after.

[0173] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0174] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined based on its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0175] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different systems for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.

[0176] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the devices, apparatuses, and units described above can refer to the corresponding processes in the foregoing system embodiments and will not be elaborated herein.

[0177] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and systems can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.

[0178] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0179] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0180] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the systems described in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0181] As described above, the above are only the specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A financial data security management system, characterized in that: The system comprises: The data monitoring module collects transaction flows and account behaviors in the financial data stream, analyzes the frequency of changes in capital flows, calculates the frequency of account accesses, compares the frequency of changes in capital flows with the frequency of accesses, determines the risk of abnormal operations of accounts, and generates abnormal operation indicators; The vulnerability prediction module locates the transaction nodes of abnormal accounts based on the abnormal operation indicators, analyzes the matching relationship between the transaction nodes and risk events, evaluates the risk level of the nodes, calculates the correlation between the transaction frequency and the risk events, predicts the security vulnerabilities that appear in the transaction nodes, and generates vulnerability risk assessment results; Based on the vulnerability risk assessment results, the dynamic isolation module identifies risky data storage nodes, analyzes financial data distribution, calculates migration priorities, plans transfer paths, migrates data to low-risk storage nodes, and obtains data node isolation configurations, which include data migration priorities, data migration paths, and permission update standards; The behavior analysis module compares the data access frequency of the account before and after isolation based on the data node isolation configuration, identifies abnormal account activities, analyzes the characteristics of the account's abnormal behavior patterns, locates the source of security vulnerabilities, and obtains behavior characteristic analysis results; The dynamic isolation module comprises: The risk node identification submodule detects risk nodes in the data storage network based on the vulnerability risk assessment results, analyzes the type and sensitivity of financial data stored in the nodes, screens storage nodes with security vulnerabilities, determines the range of data nodes that need to be isolated, and obtains a risk node list; The data migration analysis submodule analyzes the data distribution in the affected nodes based on the risk node list, calculates the data association degree and interaction frequency between nodes, determines the impact scope and priority of data migration, and generates a data migration priority index; The data association degree and interaction frequency between the computing nodes are calculated using the formula: ; in, Represents the frequency of data interaction between node a and node b, Represents the data flow of node a in data dimension v, represents the data flow of node b in data dimension v, Represents the request frequency of node a on data dimension v, represents the request frequency of node b on data dimension v, and w represents the total number of data dimensions; The data storage reconstruction submodule analyzes the data flow path between storage nodes based on the data migration priority index, allocates storage resources, plans the optimal data migration path, and adjusts the access rights of the secure storage nodes to obtain the data node isolation configuration.

2. The financial data security management system according to claim 1, characterized in that: The abnormal operation indicators include the frequency of account fund changes, access frequency differences and permission change frequencies; the vulnerability risk assessment results include node risk levels, transaction and event matching degrees and vulnerability identification results; the behavior feature analysis results include behavior pattern change indicators, access frequency comparison results and abnormal activity identification.

3. The financial data security management system according to claim 1, characterized in that: The data monitoring module includes: The fund flow analysis submodule collects transaction flows and account behaviors in the financial data stream, analyzes the time series of fund inflows and outflows in the transaction flows, calculates the time intervals between consecutive transactions, counts the frequency changes of fund flows, compares the ratio of fund inflows and outflows, identifies accounts with abnormal fund activities, and obtains fund liquidity indicators; The account access monitoring submodule retrieves access data of abnormal fund accounts based on the fund liquidity index, analyzes the distribution of access times in different time periods, calculates the access fluctuation degree of the account in a short period of time, determines whether there is abnormal access behavior in the account, and obtains the account access fluctuation index; The permission change statistics submodule calls the account's permission modification records based on the account access fluctuation index, counts the number of permission changes, combines the account's capital flow and access monitoring data, calculates the abnormal degree of permission changes, and generates abnormal operation indicators.

4. The financial data security management system according to claim 1, characterized in that: The vulnerability prediction module includes: The abnormal transaction identification submodule screens the transaction data of abnormal accounts based on the abnormal operation indicators, analyzes the correlation between transaction time and amount and account operation mode, measures the distribution density of abnormal transactions and classifies them, identifies abnormal transaction nodes, and generates an abnormal transaction node set; The transaction node matching submodule calls the abnormal transaction node set, analyzes the transaction behavior characteristics, compares the patterns of the identified risk events, calculates the matching degree between the nodes and the risk events, evaluates the risk level of the transaction nodes, and generates a transaction risk matching index; The vulnerability risk assessment submodule analyzes the transaction frequency of abnormal nodes, extracts transaction time intervals, calculates the transaction fluctuation range within a short period, predicts the probability of security vulnerabilities according to the risk matching degree of the nodes, and generates vulnerability risk assessment results.

5. The financial data security management system according to claim 4, characterized in that: The matching degree between the calculation node and the risk event is calculated using the formula: ; Evaluate the risk level of transaction nodes and generate a transaction risk matching index; Among them, M represents the matching degree between the transaction node and the risk event. represents the characteristic value of transaction node i, represents the reference feature value of risk event i, and n represents the total number of features involved in the transaction node.

6. The financial data security management system according to claim 1, characterized in that: The behavior analysis module includes: The behavior pattern change analysis submodule calls the behavior records of the isolated account based on the data node isolation configuration, compares the account activity characteristics before and after isolation, analyzes the amplitude and frequency of the account behavior changes, calculates the degree of deviation of the behavior pattern, and obtains the behavior pattern deviation index; The data access frequency comparison submodule compares the data access frequency of the account before and after isolation based on the behavior pattern deviation index, analyzes the changes in access time point, access duration and access frequency, determines the fluctuation of access frequency, and generates an access frequency fluctuation index; The abnormal behavior identification submodule identifies account activities that deviate from normal patterns based on the access frequency fluctuation index, analyzes the characteristics of account abnormal behavior patterns, matches the relationship between account activity characteristics and known vulnerabilities, locates the source of security vulnerabilities, and generates behavior feature analysis results.

7. The financial data security management system according to claim 1, characterized in that: The system further comprises: The security response module determines abnormal transaction accounts based on the behavior feature analysis results, adjusts account access rights, allocates transaction quota ratios, updates account transaction verification methods, and generates security protection measures; The security protection measures specifically include account authority adjustment results, transaction limit configuration and updated verification methods.

8. The financial data security management system according to claim 7, characterized in that: The security response module includes: Based on the behavior feature analysis results, the account authority control submodule analyzes the frequency of risky operations of the account, calculates the impact scope of account authority changes, identifies accounts with frequent abnormal operations, reconfigures account access rights, imposes access restrictions on high-risk accounts, and generates account authority adjustment configurations; The transaction quota management submodule calls the account authority adjustment configuration, calls the transaction records of abnormal accounts, calculates the fluctuation range of transaction quotas, analyzes the trend of transaction quota changes in the short term, determines the degree of deviation between the transaction amount and the normal behavior of the account, adjusts the transaction quota upper limit of the account, allocates the transaction quota ratio, and generates the optimized transaction quota; The verification method optimization submodule screens accounts with abnormal transaction frequencies based on the optimized transaction amount, extracts the identity authentication records of the accounts, analyzes the security level of transaction verification of abnormal accounts, determines whether the transaction verification matches the account risk level, optimizes the transaction verification method of the accounts, and generates security protection measures.

9. A financial data security management method, the financial data security management method is used to implement the financial data security management system according to any one of claims 1 to 8, characterized in that: The following steps are involved: S1: Collect transaction flows and account behaviors in financial data streams, analyze the frequency of changes in capital flows, calculate the frequency of account accesses, compare the frequency of capital flow changes with the frequency of accesses, determine the abnormal operation risk of the account, and generate abnormal operation indicators; S2: Based on the abnormal operation indicators, locate the transaction nodes of abnormal accounts, analyze the matching relationship between transaction nodes and risk events, evaluate the risk level of nodes, calculate the correlation between transaction frequency and risk events, predict security vulnerabilities in transaction nodes, and generate vulnerability risk assessment results; S3: Based on the vulnerability risk assessment results, identify risky data storage nodes, analyze financial data distribution, calculate migration priorities, plan migration paths, migrate data to low-risk storage nodes, and obtain data node isolation configuration; S4: Based on the data node isolation configuration, compare the data access frequency of the account before and after isolation, identify abnormal account activities, determine the abnormal characteristics of the account behavior pattern, locate the source of the security vulnerability, and obtain the behavior characteristic analysis results; S5: Based on the behavior feature analysis results, determine abnormal transaction accounts, adjust account access rights, allocate transaction quota ratios, update account transaction verification methods, and generate security protection measures.

Citation Information

Patent Citations

  • Performance evaluation system and method for multi-stage RAID system

    CN117909198A

  • Power information system supply chain security risk static analysis method and system

    CN118427828A

  • Financial data full-link monitoring method and system

    CN118552330A

Cited By

  • Financial data security management system based on multi-factor identity authentication

    CN122491896A