RPA security analysis method based on process mining, terminal equipment and storage medium

Through the RPA security analysis method based on process mining, RPA business process execution data is automatically collected and analyzed, and process deviations and security risks are dynamically identified, the problems of low efficiency and lag in traditional security analysis methods are solved, and the real-time improvement of RPA process security protection is achieved.

CN119939577AInactive Publication Date: 2025-05-06NINETECH INFORMATION TECH (SHENZHEN) CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510431536.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-05-06
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional RPA security analysis methods rely on manual review and periodic security testing, which is time-consuming and labor-intensive, and difficult to detect security threats in a timely manner.

Method used

The RPA security analysis method based on process mining is adopted to automatically collect RPA business process execution data, build an actual execution model, and dynamically identify the process deviation from the preset standardized model in combination with process mining technology to generate security analysis results.

Benefits of technology

Real-time monitoring of potential abnormal behaviors in RPA operations is achieved, effectively solving the problems of low efficiency of traditional manual review and lagging security threat discovery, and improving the real-time security protection of RPA processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939577A_ABST
    Figure CN119939577A_ABST
Patent Text Reader

Abstract

The invention is suitable for the field of data processing, and discloses an RPA security analysis method based on process mining, terminal equipment and a storage medium. The RPA security analysis method based on process mining comprises the following steps: collecting execution data of an RPA business process; performing flow mining operation on the execution data to obtain an actual execution model; identifying a process deviation between the actual execution model and a preset standardized model, and generating a potential safety risk corresponding to the actual execution model; and generating a safety analysis result according to the process deviation and the potential safety risk. According to the method, the relevance between the process deviation and the security risk is systematically analyzed, so that the conversion from passive defense to active early warning is realized, the limitation of traditional single-point detection is broken through, the integrity verification of a cross-system operation link is supported, and the real-time performance of RPA process security protection is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data processing, and in particular relates to an RPA security analysis method based on process mining, a terminal device and a storage medium. Background Art

[0002] With the widespread application of RPA technology in enterprises, automated RPA business processes increasingly involve sensitive data and critical operations.

[0003] Traditional security analysis methods often rely on manual review and periodic security testing, which is not only time-consuming and labor-intensive, but also difficult to detect security threats in a timely manner. Therefore, a new technical means is needed to solve the above technical problems. Summary of the invention

[0004] In view of this, an embodiment of the present invention provides an RPA security analysis method, a terminal device and a storage medium based on process mining, which can solve the problems in related technologies that are time-consuming and labor-intensive, and difficult to detect security threats in a timely manner.

[0005] A first aspect of the present invention provides an RPA security analysis method based on process mining, comprising: Collect execution data of RPA business processes; Performing a process mining operation on the execution data to obtain an actual execution model; Identify the process deviation between the actual execution model and the preset standardized model, and generate potential security risks corresponding to the actual execution model; A safety analysis result is generated based on the process deviation and the potential safety risk.

[0006] Optionally, in a first implementation of the first aspect of the present invention, the step of generating a security analysis result according to the process deviation and the potential security risk includes: Generate an abnormal node analysis report based on the abnormal nodes in the process deviation; Generate a process optimization plan based on the abnormal node analysis report, wherein the process optimization plan includes node logic adjustment and resource reallocation; The safety analysis result is generated according to the process optimization plan and the potential safety risks.

[0007] Optionally, in a second implementation of the first aspect of the present invention, the step of generating a security analysis result according to the process deviation and the potential security risk includes: Generate a list of high-risk points based on the high-risk points in the potential security risks; Generate security reinforcement information based on the high-risk point list, the security reinforcement information including technical repair measures and monitoring mechanism deployment; The security analysis result is generated according to the security reinforcement information and the process deviation.

[0008] Optionally, in a third implementation manner of the first aspect of the present invention, the step of performing a process mining operation on the execution data to obtain an actual execution model includes: Performing a process mining operation on the execution data to obtain an initial execution model; Generate a process path analysis result according to the process path in the initial execution model; Generate path optimization information according to the process path analysis result, wherein the path optimization information includes path simplification and redundant path deletion; The actual execution model is obtained according to the path optimization information and by adjusting the initial execution model.

[0009] Optionally, in a fourth implementation manner of the first aspect of the present invention, after the step of generating a security analysis result according to the process deviation and the potential security risk, the method further includes: Generating a risk level distribution map according to the risk level in the safety analysis result; According to the risk level distribution map, risk response information is generated, and the risk response information includes risk avoidance measures and emergency response information.

[0010] Optionally, in a fifth implementation manner of the first aspect of the present invention, after the step of identifying a process deviation between the actual execution model and the preset standardized model, the method further includes: Generate a time delay analysis report based on the time delay in the process deviation; A resource optimization configuration operation is performed according to the time delay analysis report.

[0011] Optionally, in a sixth implementation of the first aspect of the present invention, the step of collecting execution data of the RPA business process includes: Collecting original execution data of the RPA business process from multiple preset data sources; Perform data cleaning operations on the original data to obtain standardized execution data.

[0012] Optionally, in a seventh implementation manner of the first aspect of the present invention, the step of performing a process mining operation on the execution data to obtain an actual execution model includes: Dynamically selecting a process mining algorithm based on event log features in the execution data to generate an initial process model; Performing logic verification on the initial process model based on preset format requirements to obtain model correction parameters; The topology structure of the initial process model is adjusted and the node attributes are updated according to the model correction parameters to obtain the actual execution model.

[0013] In a second aspect, an embodiment of the present invention provides a terminal device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the above-mentioned RPA security analysis method based on process mining are implemented.

[0014] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps of the above-mentioned RPA security analysis method based on process mining are implemented.

[0015] In a fourth aspect, an embodiment of the present invention provides a computer program product. When the computer program product runs on a terminal device, the terminal device executes the above-mentioned RPA security analysis method based on process mining.

[0016] Compared with the prior art, the beneficial effects of the embodiments of the present invention are: by automatically collecting RPA business process execution data and building an actual execution model, combined with process mining technology to dynamically identify process deviations from the preset standardized model, it can monitor potential abnormal behaviors in RPA operations in real time, effectively solving the problems of low efficiency of traditional manual review and delayed security threat discovery. By systematically analyzing the correlation between process deviations and security risks, it has achieved a transition from passive defense to active warning, while breaking through the limitations of traditional single-point detection, supporting integrity verification of cross-system operation links, and significantly improving the real-time security protection of RPA processes. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0018] Figure 1 A schematic diagram of an embodiment of an RPA security analysis method based on process mining in an embodiment of the present invention; Figure 2 This is a schematic diagram of a specific embodiment of step 104 of RPA security analysis based on process mining in an embodiment of the present invention; Figure 3This is a schematic diagram of a specific embodiment of step 104 of RPA security analysis based on process mining in an embodiment of the present invention; Figure 4 This is a schematic diagram of a specific embodiment of step 102 of RPA security analysis based on process mining in an embodiment of the present invention; Figure 5 The figure is a schematic diagram of an embodiment of a terminal device in an embodiment of the present invention. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative work are protected by the present invention.

[0020] It should be noted that the terms "include", "comprises" and "have" and any variations thereof in the specification and claims of the present invention and the above-mentioned drawings are intended to cover non-exclusive inclusions. For example, a process, method, terminal, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units that are inherent to these processes, methods, products or devices. In the claims, specifications and drawings of the present invention, relational terms such as "first" and "second" are merely used to distinguish one entity / operation / object from another entity / operation / object, and do not necessarily require or imply any such real-time relationship or order between these entities / operations / objects.

[0021] Reference to an "embodiment" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiment may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0022] With the widespread application of RPA technology in enterprises, automated RPA business processes increasingly involve sensitive data and critical operations.

[0023] Traditional security analysis methods often rely on manual review and periodic security testing, which is not only time-consuming and labor-intensive, but also difficult to detect security threats in a timely manner. Therefore, a new technical means is needed to solve the above technical problems.

[0024] In view of this, the embodiment of the present invention provides an RPA security analysis method, terminal device and storage medium based on process mining, which automatically collects RPA business process execution data and builds an actual execution model, and combines process mining technology to dynamically identify process deviations from preset standardized models, so as to monitor potential abnormal behaviors in RPA operations in real time, and effectively solve the problems of low efficiency of traditional manual review and delayed security threat discovery. By systematically analyzing the correlation between process deviations and security risks, the transition from passive defense to active warning is achieved, while breaking through the limitations of traditional single-point detection, supporting integrity verification of cross-system operation links, and significantly improving the real-time performance of RPA process security protection.

[0025] In order to illustrate the technical solution of the present invention, specific embodiments are provided below for illustration.

[0026] The professional terms involved in the embodiments of the present invention include but are not limited to: Process Mining: A technology that automatically reconstructs business process models by analyzing event logs recorded by information systems (such as task execution records and system operation logs). This invention is used to extract actual business process models from RPA execution data and compare them with preset models to find deviations.

[0027] RPA (Robotic Process Automation): A technology that uses software robots to automatically execute repetitive and rule-defined business processes. The present invention is used to analyze RPA automated processes, with the goal of improving their execution security.

[0028] BPMN 2.0 (Business Process Model and Notation): An international standard for business process modeling and notation, used to graphically describe business processes. The present invention is used as a storage format for process models and supports cross-system compatibility.

[0029] XES (eXtensible Event Stream): a standard event log format in the field of process mining, supporting metadata storage such as timestamps and resource consumption. The standardized execution data used in this invention after data cleaning must meet the XES format requirements.

[0030] Alpha++ algorithm: An improved version of the classic Alpha algorithm for process mining, which supports modeling of concurrent events (such as parallel approvals). It is suitable for high-concurrency and low-repetition scenarios (such as parallel approval flows).

[0031] Fuzzy Miner algorithm: A process mining algorithm based on fuzzy theory, which is robust to log data containing noise (such as interruptions and repeated events). In the present invention, it is preferred when the log missing rate is >15%.

[0032] Heuristic Miner: An algorithm that generates an interpretable process model by analyzing the dependencies between statistical events. The advantage is that it can generate a highly interpretable model, which is convenient for security analysis.

[0033] LSTM (Long Short-Term Memory): A type of recurrent neural network (RNN) that is good at processing long-term dependencies in time series data. In this invention, it is deployed in the optimized process path for real-time abnormal behavior detection.

[0034] Genetic Algorithm: An optimization algorithm that simulates the biological evolution process and iterates the optimization solution through selection, crossover, and mutation operations. The present invention is used for model topology optimization of resource-sensitive processes.

[0035] RBAC (Role-Based Access Control): A role-based access control model that associates permissions with roles rather than directly authorizing users. The present invention is used to update access control rules for high-risk nodes.

[0036] CVSS (Common Vulnerability Scoring System): A common vulnerability scoring system that quantitatively evaluates the threat level of vulnerabilities. The present invention is used to mark the threat level of detected high-risk points.

[0037] SM4 / AES: Both the national SM4 and the international AES are symmetric encryption algorithms, and SM4 is the Chinese commercial encryption standard. The present invention is used to implement field-level encryption for data tampering risk points.

[0038] Graph Neural Network (GNN): A neural network that specializes in processing graph structure data and can identify complex relationships between nodes. This invention is used to merge overlapping conditional branches and reconstruct process topology.

[0039] Heatmap overlay algorithm: A technique for visualizing data density or intensity through color gradients. This invention is used to generate a risk level distribution map, with red indicating high-risk areas.

[0040] Preemptive resource allocation: A resource allocation strategy that forcibly interrupts low-priority tasks to give priority to critical tasks. The present invention is used to implement time-sensitive nodes such as payment verification.

[0041] Blockchain Evidence Storage Module: A technology that uses the tamper-proof nature of blockchain to record key operation logs. This invention is used to be deployed in nodes where data tampering is likely to occur, enhancing audit credibility.

[0042] Figure 1 The present invention provides a schematic diagram of an RPA security analysis method based on process mining, which can be applied to a terminal device. The terminal device can be a mobile phone, a tablet computer, a laptop computer, an ultra-mobile personal computer (UMPC), a netbook, etc.

[0043] Specifically, the above-mentioned RPA security analysis method based on process mining may include the following steps S101 to S104.

[0044] Step S101, collecting execution data of the RPA business process; In an embodiment of the present invention, a log collection agent (such as Filebeat or a custom API listener) is deployed on the RPA robot node to capture the original log data generated during the execution of the business process in real time, including the task trigger timestamp, execution step sequence (such as "data extraction, form filling, system submission"), operation subject (user ID, permission role), system interaction record (API call response code, database transaction log) and abnormal events (such as timeout, permission denial).

[0045] After the collection is completed, the ETL tool (such as Apache NiFi) is called to associate and integrate the scattered logs according to business entities (such as order number, customer ID), and generate structured execution data through data cleaning (deduplication, missing value filling) and standardization (unified timestamp format, activity naming specifications) to ensure that it meets the input requirements of the process mining algorithm (such as XES format).

[0046] Step S102, performing a process mining operation on the execution data to obtain an actual execution model; In the implementation of the present invention, a process mining algorithm is dynamically selected according to the characteristics of the data set. If there are high-frequency concurrent events in the log (such as parallel approval flows), the Alpha++ algorithm that supports concurrent modeling is used; if the data noise is high (such as a large number of interruptions or repeated events), the noise-resistant Fuzzy Miner algorithm is selected; if a model with strong interpretability needs to be generated, heuristic mining (Heuristic Miner) is applied.

[0047] After the algorithm is executed, an initial process model is generated, including activity nodes (such as "order review" and "payment processing"), control flow logic (sequence, branching, loop) and performance indicators (average node time, resource utilization). The initial model is then logically verified (such as eliminating deadlocks and pruning redundant paths) through model optimization tools (such as ProM plug-ins), and the final output is a process model that is consistent with the actual execution and has a complete structure, which can be stored in BPMN 2.0 or PNML format.

[0048] Step S103, identifying the process deviation between the actual execution model and the preset standardized model, and generating potential security risks corresponding to the actual execution model; In an embodiment of the present invention, the actual model is structurally aligned with the standardized model by a model comparison tool (such as Apromore or a custom script) to identify the deviation type, including: Control flow deviation: unauthorized shortcut paths (such as bypassing approval nodes), redundant loops (such as retry logic that has no business significance); Data flow deviation: sensitive data (such as PII information) flows to untrusted systems or unencrypted channels; Timing skew: critical nodes execute overtime (e.g. payment processing exceeds threshold).

[0049] Subsequently, the deviations are risk matched based on the predefined security rule base, and static rule matching and dynamic baseline analysis can be performed. Static rule matching directly associates known vulnerability patterns (for example, unencrypted transmission is marked as high risk); dynamic baseline analysis uses machine learning to detect deviations from historical normal behavior (for example, high-frequency operations during non-working hours).

[0050] Finally, a list of potential security risks is generated, with each risk marked with the type (e.g., privilege escalation, data leakage), the scope of impact (e.g., cross-system impact), and the associated deviation node (e.g., specific BPMN activity ID).

[0051] Step S104: Generate security analysis results based on process deviations and potential security risks.

[0052] Among them, the risk matrix model (Impact-Likelihood matrix) is used to quantitatively evaluate risks, for example: High risk: high impact (e.g. causing business interruption) and high probability (e.g. appearing frequently in logs); Medium risk: high impact but low probability (e.g. occasional data error); Low risk: Low impact and low probability (e.g., interface operation delays).

[0053] Based on the assessment results, generate repair recommendations: Technical fixes: Implement patches for vulnerable nodes (e.g., adding encryption layers, fixing permission configurations); Process optimization: refactoring logic (e.g. splitting highly coupled nodes and deleting redundant paths); Monitoring enhancement: Deploy real-time audit rules or anomaly detection models.

[0054] The final report is presented in an interactive visual format (such as a Power BI dashboard), which supports clicking on risk items to view details (associated logs, model screenshots, and remediation steps), and comes with an executable action plan template (responsible party, timeline, and acceptance criteria) to achieve closed-loop risk management.

[0055] In the embodiment of the present invention, by automatically collecting RPA business process execution data and building an actual execution model, combined with process mining technology to dynamically identify process deviations from the preset standardized model, it can monitor potential abnormal behaviors in RPA operations in real time, effectively solving the problems of low efficiency of traditional manual review and delayed security threat discovery. By systematically analyzing the correlation between process deviations and security risks, the transition from passive defense to active warning is achieved, while breaking through the limitations of traditional single-point detection, supporting integrity verification of cross-system operation links, and significantly improving the real-time security protection of RPA processes.

[0056] Traditional security audits rely on static rule bases and cannot effectively identify complex abnormal patterns generated during the dynamic execution of RPA; existing resource allocation solutions use fixed deployment modes and are difficult to adapt to the elastic expansion requirements of automated processes; manual analysis reports lack structured data support, resulting in decision-making blind spots in the implementation of optimization solutions. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0057] Reference Figure 2 , Figure 2 This is a schematic diagram of a specific embodiment of step 104 of RPA security analysis based on process mining in an embodiment of the present invention. Step 104 also includes the following specific implementation methods: 1041. Call the resource occupation segmentation method to calculate the resource occupation growth rate of the Redis key according to the first node information and the second node information.

[0058] 1042. Call the Redis cluster resource usage trend prediction method to predict the trend information of the Redis key in the future according to the resource usage growth rate.

[0059] 1043. Generate safety analysis results based on process optimization plans and potential safety risks.

[0060] In the embodiment of the present invention, when generating security analysis results, firstly, based on the deviation analysis between the actual execution model obtained by process mining and the preset standardized model, a deep security audit is performed on the detected abnormal nodes. Specifically, the abnormal node analysis module generates a multi-dimensional analysis report including node location, risk level and violation type by comparing the unauthorized operation nodes, abnormal data access nodes and timed execution nodes in the process path; In the node logic adjustment, a two-factor authentication module is forcibly inserted into the detected unauthorized access nodes, field-level encryption transformation is implemented on abnormal data access nodes, and an automated verification mechanism is deployed on redundant operation nodes.

[0061] In terms of resource reallocation, the deployment density of monitoring servers is increased for process branches where high-frequency abnormal nodes are located, and dedicated isolated computing resources are allocated to sensitive data processing nodes.

[0062] The security assessment module performs regression testing on the optimized process model and the original risk data to generate an optimization verification report containing indicators such as false alarm rate and detection accuracy as part of the final security analysis results.

[0063] In this optional embodiment, the security response speed is improved through the combination of automated node-level anomaly detection and intelligent repair suggestions; the dynamic resource allocation mechanism improves the utilization rate of security protection resources at key nodes; and the multi-dimensional analysis report provides a traceable decision-making basis, thereby increasing the success rate of implementing the process optimization plan.

[0064] Traditional security reinforcement solutions rely on a general rule base and cannot adapt to the dynamic path changes of the RPA process, resulting in a misalignment between the repair measures and the actual risk points; the existing monitoring system adopts a centralized log analysis architecture, which is difficult to cope with the real-time monitoring needs of high-concurrency RPA nodes; static security policies lack correlation analysis of process topology and cannot effectively defend against compound attacks based on process vulnerabilities. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0065] Reference Figure 3 , Figure 3 This is a schematic diagram of a specific embodiment of step 104 of RPA security analysis based on process mining in an embodiment of the present invention. Step 104 also includes the following specific implementation methods: 1044. Generate a list of high-risk points based on the high-risk points in potential security risks; In an embodiment of the present invention, based on the execution data, an association rule mining algorithm (such as the Apriori algorithm) is used to analyze abnormal access sequences, permission-crossing operations, and sensitive data leakage patterns in event logs to generate a list of high-risk points including risk type (such as data tampering, unauthorized access), threat level (based on CVSS score), and impact range; Calculate the weights of high-frequency abnormal paths and mark the topological locations of high-risk points (such as process branch nodes and loop structure entrances).

[0066] 1045. Generate security reinforcement information based on the list of high-risk points, which includes technical repair measures and monitoring mechanism deployment.

[0067] In an implementation manner of the present invention, a field-level encryption module based on SM4 / AES is deployed for data tampering risk points, and access control rules are updated based on the RBAC model; for nodes with out-of-bounds permissions, a real-time permission verification plug-in is inserted to enforce the principle of least privilege.

[0068] Integrate lightweight monitoring agents in sensitive operation nodes and allocate dedicated log storage resources through resource optimization configuration operations; Based on the process path analysis results, deploy an abnormal behavior detection model (such as LSTM timing analysis) after the redundant paths are deleted to trigger the alarm threshold in real time.

[0069] 1046. Generate security analysis results based on security reinforcement information and process deviations.

[0070] In an embodiment of the present invention, the process model after security reinforcement is compared with the original process deviation data (such as a time delay analysis report), and the effectiveness of the repair is verified through a simulated attack injection test; and a security analysis result including indicators such as vulnerability repair coverage and monitoring response delay is generated.

[0071] In this optional embodiment, by dynamically associating risk points with process topology structures, security repair measures are deeply bound to the business process context to reduce the false positive rate; the coordinated deployment of lightweight monitoring agents and dedicated log resources improves the threat detection response speed; and the monitoring strategy is dynamically adjusted based on the process path to cover new attack vectors (such as zero-day vulnerability exploits).

[0072] Traditional process mining tools only generate static models and cannot dynamically identify and optimize inefficient paths, resulting in large deviations between process models and actual execution; existing path optimization methods rely on manual experience to formulate rules, making it difficult to quantitatively evaluate path efficiency (such as frequency and time consumption), and the optimization results are highly subjective; redundant path detection algorithms lack analysis of resource competition relationships and are prone to cause new conflicts after optimization. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0073] Reference Figure 4 , Figure 4 This is a schematic diagram of a specific embodiment of step 102 of RPA security analysis based on process mining in an embodiment of the present invention. Step 102 also includes the following specific implementation methods: 1021. Perform process mining operations on the execution data to obtain an initial execution model.

[0074] 1022. Generate a process path analysis result according to the process path in the initial execution model.

[0075] 1023. Generate path optimization information based on the process path analysis result, where the path optimization information includes path simplification and redundant path deletion.

[0076] 1024. Obtain an actual execution model according to the path optimization information and the adjusted initial execution model.

[0077] In an embodiment of the present invention, based on the execution data, an initial execution model including complete node relationships and transfer conditions is generated by a dynamic process mining algorithm (such as an Alpha algorithm or a probabilistic mining algorithm based on event log sequence matching).

[0078] The parallel paths, loop structures and conditional branches in the initial model are extracted through the topology analysis module to form a process path map.

[0079] Calculate the execution frequency (based on historical log statistics), average time consumption, and resource consumption (such as CPU / memory usage) of each path; Identify redundant operations in the path (e.g., duplicate data checkpoints, stateless loop structures) and conflicting dependencies (e.g., resource contention in concurrent paths).

[0080] Paths with execution frequencies below a preset threshold (e.g., 5%) are marked as inefficient paths, and path simplification suggestions (e.g., deletion or merging) are generated. For parallel paths with resource conflicts, a redundant path deletion scheme is generated based on the resource reallocation strategy.

[0081] Map the path optimization information (such as deleting redundant paths and merging overlapping conditional branches) to the topological structure of the initial execution model, and adjust the logical relationship between nodes through the node attribute update module to obtain the actual execution model.

[0082] In this optional embodiment, the average execution time of the RPA process can be shortened by deleting redundant paths and optimizing conflicting paths; reducing the resource usage of inefficient paths can reduce the overall resource consumption of the system by more than 1%. The dynamic path adjustment mechanism can improve the matching degree between the actual execution model and the real business process.

[0083] Traditional risk reports rely on text descriptions and cannot intuitively display the spatial association between risks and business processes, resulting in decision delays; existing emergency plans use static plan libraries, which are difficult to adapt to dynamic changes in RPA processes (such as node additions and subtractions, path adjustments); cross-departmental risk responsibility division is vague, which easily leads to buck-passing during the handling process. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0084] After step 104, the following specific implementations are also included: 201. Generate a risk level distribution map based on the risk level in the safety analysis results.

[0085] 202. Generate risk response information based on the risk level distribution map, which includes risk avoidance measures and emergency response information.

[0086] In an embodiment of the present invention, based on the high-risk point list and process path analysis results, a multi-dimensional data aggregation technology (e.g., a heat map overlay algorithm) is called to map the risk level (e.g., high / medium / low) to the topological structure of the actual execution model, and generate a three-dimensional visual distribution map; Combined with the time delay analysis report, time-sensitive risk areas (such as key nodes where delay exceeds the threshold) are marked in the distribution map; By executing the business attributes in the data (such as department affiliation, data classification), the distribution map is layered and colored to distinguish the risk coverage of different responsible entities.

[0087] For high-risk areas (such as the red blocks in the distribution map), call node logic to adjust the strategy, such as deploying blockchain evidence modules in nodes with high incidence of data tampering; For medium-risk areas (e.g., yellow blocks), a path redirection solution is generated based on a dynamic process mining algorithm to avoid potential conflicting paths.

[0088] For time-sensitive risks, combined with resource optimization configuration operations, spare computing resources are dynamically allocated to shorten emergency response time.

[0089] Based on the deployment results of the monitoring mechanism, an emergency plan document is generated that includes alarm trigger conditions (such as CPU usage > 90%) and handling processes (such as automatic node isolation).

[0090] Re-enter the risk response measures into the process deviation detection module, and verify the effectiveness of the avoidance measures through simulated attacks; update the historical disposal records in the risk level distribution map to form a traceable risk management knowledge base.

[0091] In this optional embodiment, the three-dimensional visual distribution map can speed up the identification of complex risk situations; the generation of emergency plans based on the topological structure can shorten the average handling time of high-risk incidents; and the layered coloring mechanism can clarify the boundaries of responsibility and improve the accuracy of risk handling task allocation.

[0092] Traditional resource allocation relies on a fixed quota model and cannot dynamically respond to changes in the time sensitivity of business processes, resulting in systematic delays during peak periods; existing delay analysis tools lack correlation analysis of process topology, making it difficult to distinguish between node performance issues and path-level resource competition; static task scheduling strategies cannot adapt to the path structure optimized by process mining, which can easily lead to secondary resource conflicts. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0093] Step 103 and the following specific implementations are also included: 203. Generate a time delay analysis report based on the time delay in process deviation.

[0094] 204. Perform resource optimization configuration operations according to the time delay analysis report.

[0095] In the embodiment of the present invention, based on the execution data, the execution timestamp sequence of each process node (including task start time, waiting time, and completion time) is extracted, and the node-level delay (for example, the delay of a single node exceeds the preset threshold of 200ms) and the path-level delay (for example, the total delay of the critical path exceeds 1s) are calculated by the temporal difference algorithm; Combined with the process path analysis results, perform resource occupancy correlation analysis on high-frequency delay nodes (for example, when CPU utilization is > 80%, the delay increases sharply); For resource contention-related delays in parallel paths (such as database connection pool contention), the conflicting paths are verified through topology adjustment results.

[0096] For nodes with persistent high latency (e.g., three consecutive execution delays), dynamically add virtual machine instances or allocate dedicated GPU resources according to the resource reallocation strategy of claim 2; For periodic delay paths (such as daily peak hours), expand the container cluster in advance based on historical data prediction models.

[0097] After the redundant paths are removed, the remaining paths are graded according to their delay sensitivity and a priority queue scheduling algorithm (e.g., shortest job first) is used; Implement preemptive resource allocation for time-critical nodes (such as payment verification nodes) and suspend low-priority tasks.

[0098] Import the optimized resource allocation plan into the process execution environment, re-collect time data and generate a delay comparison report.

[0099] In this optional embodiment, the average execution time of the RPA process can be shortened through node-level delay attribution analysis and dynamic resource allocation; the server cluster utilization rate can be improved by accurately locating resource competition hotspots; and the preemptive resource allocation mechanism can reduce the delay volatility of time-critical nodes.

[0100] Traditional resource allocation relies on a fixed quota model and cannot dynamically respond to changes in the time sensitivity of business processes, resulting in systematic delays during peak periods; existing delay analysis tools lack correlation analysis of process topology, making it difficult to distinguish between node performance issues and path-level resource competition; static task scheduling strategies cannot adapt to the path structure optimized by process mining, which can easily lead to secondary resource conflicts. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0101] Step 101 also includes the following specific implementations: 1011. Collect original execution data of RPA business processes from multiple preset data sources.

[0102] 1012. Perform data cleaning operations on the original data to obtain standardized execution data.

[0103] In the embodiment of the present invention, based on the execution data, the execution timestamp sequence of each process node (including task start time, waiting time, and completion time) is extracted, and the node-level delay (for example, the delay of a single node exceeds the preset threshold of 200ms) and the path-level delay (for example, the total delay of the critical path exceeds 1s) are calculated by the temporal difference algorithm; Combined with the process path analysis results, perform resource occupancy correlation analysis on high-frequency delay nodes (for example, when CPU utilization is > 80%, the delay increases sharply); For resource contention-related delays in parallel paths (such as database connection pool contention), the conflicting paths are verified through topology adjustment results.

[0104] For nodes with persistent high latency (e.g., three consecutive execution delays), dynamically add virtual machine instances or allocate dedicated GPU resources according to the resource reallocation strategy of claim 2; For periodic delay paths (such as daily peak hours), expand the container cluster in advance based on historical data prediction models.

[0105] After the redundant paths are removed, the remaining paths are graded according to their delay sensitivity and a priority queue scheduling algorithm (e.g., shortest job first) is used; Implement preemptive resource allocation for time-critical nodes (such as payment verification nodes) and suspend low-priority tasks.

[0106] Import the optimized resource allocation plan into the process execution environment, re-collect time data and generate a delay comparison report.

[0107] In this optional embodiment, the average execution time of the RPA process can be shortened through node-level delay attribution analysis and dynamic resource allocation; the server cluster utilization rate can be improved by accurately locating resource competition hotspots; and the preemptive resource allocation mechanism can reduce the delay volatility of time-critical nodes.

[0108] Traditional process mining tools use a fixed single algorithm (such as the Alpha algorithm), which cannot adapt to the data characteristics of different types of RPA processes, resulting in model distortion; the existing modeling system lacks a business rule verification module, and the generated model often has logical loopholes (such as dead loop paths), which require manual secondary correction; static topology structures are difficult to integrate real-time security policies (such as node-level monitoring requirements), forcing security analysis to lag behind process changes. In order to solve the above technical problems, the present invention proposes an optional embodiment.

[0109] Step 102 also includes the following specific implementations: 1025. Based on the event log features in the execution data, a process mining algorithm is dynamically selected to generate an initial process model.

[0110] 1026. Perform logic verification on the initial process model based on the preset format requirements to obtain model correction parameters.

[0111] 1027. The topology structure of the initial process model is adjusted and the node attributes are updated according to the model correction parameters to obtain the actual execution model.

[0112] In an embodiment of the present invention, based on the execution data, the event log characteristics (including the concurrency of the event sequence, the activity repetition frequency, and the log integrity level) are analyzed, and the optimal process mining algorithm is selected through a weighted decision tree model. For example, the Alpha++ algorithm is used for high-concurrency and low-repetition scenarios (such as parallel approval processes) to enhance the parallel relationship recognition capability; a heuristic mining algorithm is used for noisy data scenarios (such as log missing rate >15%) to complete the missing paths through fuzzy matching; and a genetic algorithm is used to optimize the model topology for resource-sensitive processes (such as the time-delay hotspot path of claim 6).

[0113] When generating the initial process model, node attributes (including execution time, associated resource types, and access permission labels) are automatically annotated.

[0114] Based on preset business rules (e.g., “there must be an approval node before a payment node”), check the causal logic integrity of the initial model and identify isolated nodes (no predecessor / successor associations) and conflicting paths (e.g., bidirectional loop structures); Through the time constraint verification module, the time order contradictions between nodes are detected (for example, the task completion time is earlier than the start time).

[0115] For logical conflicting paths, invalid branches are deleted based on path optimization information. For nodes with mismatched resource attributes (for example, nodes with high CPU usage are not marked as compute-intensive), node attribute labels are updated and associated with resource allocation policies.

[0116] Optionally, perform dynamic topology optimization and use graph neural networks to reconstruct the model topology. Merge overlapping conditional branches (for example, multiple IF-ELSE judgments on the same variable) to generate a streamlined decision tree; insert monitoring agent nodes and allocate independent resource pools for high-frequency security risk paths (such as the list of high-risk points in claim 3); when outputting the actual execution model, synchronously generate model version metadata (including algorithm selection basis, revision records, and topology change instructions).

[0117] In this optional embodiment, the dynamic algorithm selection mechanism can improve the accuracy of model restoration of complex processes; the automatic association of node attributes and resource strategies can improve the reliability of security analysis results; and the closed-loop mechanism of logic verification and topology optimization can automatically repair conventional model defects.

[0118] For example Figure 5 As shown, it is a schematic diagram of a terminal device provided by an embodiment of the present invention. The terminal device 5 may include: a processor 501, a memory 502, and a computer program 503 stored in the memory 502 and executable on the processor 501, such as an RPA security analysis program based on process mining. When the processor 501 executes the computer program 503, the steps in each of the above-mentioned RPA security analysis embodiments based on process mining are implemented.

[0119] The computer program may be divided into one or more modules / units, one or more modules / units are stored in the memory 502 and executed by the processor 501 to complete the present invention. One or more modules / units may be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.

[0120] The terminal device may include, but is not limited to, a processor 501 and a memory 502. Those skilled in the art will appreciate that Figure 5 It is only an example of a terminal device and does not constitute a limitation of the terminal device. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the terminal device may also include input and output devices, network access devices, buses, etc.

[0121] The processor 501 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.

[0122] The memory 502 may be an internal storage unit of the terminal device, such as a hard disk or memory of the terminal device. The memory 502 may also be an external storage device of the terminal device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the terminal device. Further, the memory 502 may also include both an internal storage unit of the terminal device and an external storage device. The memory 502 is used to store computer programs and other programs and data required by the terminal device. The memory 502 may also be used to temporarily store data that has been output or is to be output.

[0123] It should be noted that, for the convenience and brevity of description, the structure of the above-mentioned terminal device can also refer to the specific description of the structure in the method embodiment, which will not be repeated here.

[0124] An embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned RPA security analysis method based on process mining can be implemented.

[0125] An embodiment of the present invention provides a computer program product. When the computer program product runs on a mobile terminal, the mobile terminal can implement the steps in the above-mentioned RPA security analysis method based on process mining when executing the computer program product.

[0126] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0127] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0128] In the embodiments provided by the present invention, it should be understood that the disclosed terminal devices and methods can be implemented in other ways. For example, the terminal device embodiments described above are only exemplary. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.

[0129] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0130] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0131] If the integrated module / unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present invention implements all or part of the processes in the above-mentioned embodiment method, and can also be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium, and the computer program can implement the steps of the above-mentioned various method embodiments when executed by the processor. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electric carrier signals and telecommunication signals.

[0132] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the above embodiments, it should be understood by those skilled in the art that the technical solutions described in the above embodiments can still be modified, or some of the technical features can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention.

Claims

1. A RPA security analysis method based on process mining, characterized in that: include: Collect execution data of RPA business processes; Performing a process mining operation on the execution data to obtain an actual execution model; Identify the process deviation between the actual execution model and the preset standardized model, and generate potential security risks corresponding to the actual execution model; A safety analysis result is generated based on the process deviation and the potential safety risk.

2. The RPA security analysis method based on process mining according to claim 1 is characterized in that: The step of generating a safety analysis result according to the process deviation and the potential safety risk comprises: Generate an abnormal node analysis report based on the abnormal nodes in the process deviation; Generate a process optimization plan based on the abnormal node analysis report, wherein the process optimization plan includes node logic adjustment and resource reallocation; The safety analysis result is generated according to the process optimization plan and the potential safety risks.

3. The RPA security analysis method based on process mining according to claim 1 is characterized in that: The step of generating a safety analysis result according to the process deviation and the potential safety risk comprises: Generate a list of high-risk points based on the high-risk points in the potential security risks; Generate security reinforcement information based on the high-risk point list, the security reinforcement information including technical repair measures and monitoring mechanism deployment; The security analysis result is generated according to the security reinforcement information and the process deviation.

4. The RPA security analysis method based on process mining according to claim 1 is characterized in that: The step of performing a process mining operation on the execution data to obtain an actual execution model comprises: Performing a process mining operation on the execution data to obtain an initial execution model; Generate a process path analysis result according to the process path in the initial execution model; Generate path optimization information according to the process path analysis result, wherein the path optimization information includes path simplification and redundant path deletion; The actual execution model is obtained according to the path optimization information and by adjusting the initial execution model.

5. The RPA security analysis method based on process mining according to claim 1, characterized in that: After the step of generating a safety analysis result according to the process deviation and the potential safety risk, the method further comprises: Generating a risk level distribution map according to the risk level in the safety analysis result; According to the risk level distribution map, risk response information is generated, and the risk response information includes risk avoidance measures and emergency response information.

6. The RPA security analysis method based on process mining according to claim 1, characterized in that: After the step of identifying the process deviation between the actual execution model and the preset standardized model, the method further includes: Generate a time delay analysis report based on the time delay in the process deviation; A resource optimization configuration operation is performed according to the time delay analysis report.

7. The RPA security analysis method based on process mining according to claim 1 is characterized in that: The step of collecting the execution data of the RPA business process includes: Collecting original execution data of the RPA business process from multiple preset data sources; A data cleaning operation is performed on the original execution data to obtain standardized execution data.

8. The RPA security analysis method based on process mining according to claim 1, characterized in that: The step of performing a process mining operation on the execution data to obtain an actual execution model comprises: Dynamically selecting a process mining algorithm based on event log features in the execution data to generate an initial process model; Performing logic verification on the initial process model based on preset format requirements to obtain model correction parameters; The topology structure of the initial process model is adjusted and the node attributes are updated according to the model correction parameters to obtain the actual execution model.

9. A terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the RPA security analysis method based on process mining as described in any one of claims 1 to 8 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the RPA security analysis method based on process mining as described in any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Supply chain process reproduction method and system based on process mining

    CN115511233A

  • Process mining-based early warning event automatic diagnosis method, storage medium and equipment

    CN116227900A

  • Information data management method based on process mining technology

    CN118279067A

  • Automatic log decomposition process mining method based on RPA

    CN118643471A

  • Robot cluster management method and device, equipment, storage medium and program product

    CN119668969A