Service channel interaction data security detection method and system based on spatial-temporal feature analysis
By conducting spatiotemporal and spatial characteristics analysis and security assessment of service channel interaction data, a comprehensive security risk score is generated, which solves the problem of difficult to identify data abnormalities and potential risks in the existing technology, and achieves higher security guarantees for power grid operation.
Patent Information
- Application Number
- CN202510114382.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to accurately identify abnormalities and potential risks in service channel interaction data, affecting the stability and security of power grid operation, and lacks a comprehensive assessment of multi-dimensional features.
Using a method based on spatiotemporal feature analysis, the time-stamp calibration, time-dimensional feature analysis, spatial-dimensional feature analysis and correlation feature analysis of the interactive data on the payment agency are used, and a comprehensive security risk score is generated and security alarm information is generated based on the score.
It improves the accuracy and comprehensiveness of service channel interactive data security detection, effectively identifies data abnormalities and potential security risks, improves the security of data transmission, and makes the power grid operation more stable and safe.
Smart Images

Figure CN120011786A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of service channel interaction data security detection, and in particular relates to a service channel interaction data security detection method and system based on spatiotemporal feature analysis. Background Art
[0002] With the development of the Internet, a large number of payment channels have emerged, and the diversity and complexity of the interactive data of payment channels have increased significantly. Traditional security detection methods are difficult to accurately identify data anomalies and potential risks, affecting the stability and security of power grid operation. Existing technologies are insufficient in data consistency, spatial distribution and logical correlation detection, and lack comprehensive evaluation of multi-dimensional features. Summary of the invention
[0003] In order to solve the deficiencies in the prior art, the present invention provides a service channel interaction data security detection method and system based on spatiotemporal feature analysis to solve the technical problem of improving the accuracy and effectiveness of channel payment interaction data security detection.
[0004] In order to solve the above technical problems, the present invention adopts the following technical solutions.
[0005] The present invention first discloses a service channel interaction data security detection method based on spatiotemporal feature analysis, which comprises the following steps:
[0006] Step 1: Obtain payment interaction data generated by multiple service channels from multiple data sources, including channel codes, access IP location data, account number location data, and actual payment data, and uniformly calibrate the timestamps of the data;
[0007] Step 2. Perform spatiotemporal feature analysis on the calibrated data, including time dimension feature analysis, space dimension feature analysis and correlation feature analysis;
[0008] Step 3: Input the results of the time dimension feature analysis, space dimension feature analysis and correlation feature analysis into the security assessment engine to comprehensively assess the security of the payment interaction data;
[0009] Step 4: Evaluate the confidentiality, integrity and authenticity of the payment interaction data, and determine the confidentiality level of the payment interaction data, whether the data has been tampered with or damaged, and the source of the data and its credibility;
[0010] Step 5: Generate a comprehensive security risk score based on the security assessment engine’s security assessment results of the payment interaction data, as well as the confidentiality, integrity and authenticity assessment results;
[0011] Step 6: If the comprehensive security risk score exceeds a preset threshold, a security warning message is generated and the security warning message notification is output in a variety of ways. The security warning message includes the risk level, abnormality type, impact scope and handling suggestions.
[0012] The present invention further includes the following preferred embodiments:
[0013] The unified calibration of the timestamps of the data further includes:
[0014] Use the network time protocol NTP or global positioning system GPS timing technology to calibrate the timestamp uniformly and synchronize the time of all data sources to a unified standard time T standard ; For each data source D i , calculate the deviation ΔT between local time and standard time i =T standard -T i ; Correct the timestamp of each data record: t′ ij =t ij +ΔT i Among them, t ij is the original timestamp, t′ ij The corrected timestamp.
[0015] The time dimension feature analysis predicts historical data and compares it with actual data by using a time series analysis algorithm, an autoregressive integrated moving average model ARIMA or a long short-term memory model LSTM to identify abnormalities in the data time series;
[0016] The spatial dimension feature analysis uses a spatial clustering algorithm to identify data distribution anomalies in geographic space, and detects anomalies in spatial location through analysis of geographic distribution;
[0017] The correlation feature analysis establishes a correlation model between the channel code and the access IP location data to perform a matching test between the two.
[0018] The security assessment engine adopts a weighted scoring model to assign different weights to various feature analysis results and ultimately generate a comprehensive assessment result. The weights are dynamically adjusted based on the characteristics of the channel payment interaction data.
[0019] The evaluation of the confidentiality, integrity and authenticity of the payment interaction data further includes:
[0020] Check the encryption measures during data transmission and storage, and confirm the encryption protocols and algorithms used. If strong encryption algorithms and protocols are used, the confidentiality assessment passes; if no encryption is used or weak encryption algorithms and protocols are used, the confidentiality assessment fails;
[0021] Verify whether the data has been tampered with by digital signature or hash verification, and calculate the hash value h for the data v computed :
[0022] h computed =Hash(v)
[0023] Compare the calculated hash value with the hash value h provided by the sender provided For comparison, if h computed =h provided , the data integrity verification passes; if they are not equal, it is determined that the integrity verification fails;
[0024] Verify the source and credibility of the data using the sender’s public key K pub Verify the digital signature σ:
[0025] Verify(v,σ,K pub )=True or False
[0026] If the verification result is True, the data source is credible; if it is False, the authenticity of the data is not credible.
[0027] Generating a comprehensive security risk score further includes:
[0028] Set the score for security attribute evaluation: confidentiality score confidentiality : 0 and 1 represent pass and fail respectively; completeness score s integrity : 0 and 1 represent pass and fail respectively; authenticity score s authenticity : 0 and 1 represent pass and fail respectively;
[0029] The comprehensive security risk score calculation formula is:
[0030] S risk =αS total +βs confidentiality +γs integrity +δs authenticity
[0031] The weight coefficients α, β, γ, and δ can be set according to the actual situation and satisfy:
[0032] α+β+γ+δ=1
[0033] According to the comprehensive security risk score S risk The risk levels are divided into: low risk, medium risk, high risk and severe risk.
[0034] Characterized in that the security warning information includes:
[0035] Risk level: low risk, medium risk, high risk or severe risk;
[0036] Anomaly type: time dimension anomaly, space dimension anomaly, correlation anomaly or security attribute anomaly;
[0037] Impact scope: affected data types, device numbers, and region information;
[0038] Recommended processing measures: For timestamp anomalies, it is recommended to check the time synchronization mechanism of the data source; for confidentiality assessment failure, it is recommended to upgrade the encryption protocol or algorithm; for operation sequence anomalies, it is recommended to review the operation permissions and processes.
[0039] The present invention also discloses a service channel interaction data security detection system based on spatiotemporal feature analysis using the aforementioned service channel interaction data security detection method based on spatiotemporal feature analysis, comprising:
[0040] The data acquisition module is used to obtain payment interaction data generated by multiple data acquisition service channels, including channel codes, access IP location data, account number location data and actual payment data, and to uniformly calibrate the timestamp of the data;
[0041] The spatiotemporal feature analysis module is used to perform spatiotemporal feature analysis on the calibrated data, including time dimension feature analysis, space dimension feature analysis and correlation feature analysis;
[0042] A security assessment module, used to input the results of time dimension feature analysis, space dimension feature analysis and correlation feature analysis into a security assessment engine, and comprehensively assess the security of the payment interaction data;
[0043] The security attribute evaluation module is used to evaluate the confidentiality, integrity and authenticity of the payment interaction data, and to determine the confidentiality level of the payment interaction data, whether the data has been tampered with or damaged, and the source of the data and its credibility;
[0044] Comprehensive scoring module, which is used to generate a comprehensive security risk score based on the security assessment results of the payment interaction data generated by the security assessment engine, as well as the confidentiality, integrity and authenticity assessment results;
[0045] The alarm generation module is used to generate security alarm information if the comprehensive security risk score exceeds a preset threshold, and output the security alarm information notification in a variety of ways. The security alarm information includes risk level, abnormality type, impact scope and handling suggestions.
[0046] Accordingly, the present application also discloses a terminal, including a processor and a storage medium;
[0047] The storage medium is used to store instructions;
[0048] The processor is used to operate according to the instructions to execute the steps of the aforementioned service channel interaction data security detection method based on spatiotemporal feature analysis.
[0049] Correspondingly, the present application also discloses a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the aforementioned service channel interaction data security detection method based on spatiotemporal feature analysis.
[0050] The beneficial effect of the present invention is that, compared with the prior art, the present invention provides a service channel interaction data security detection method and system based on spatiotemporal feature analysis. Through the multidimensional analysis method based on spatiotemporal features, the accuracy and comprehensiveness of the service channel interaction data security detection are improved, and the in-depth detection of time series consistency, spatial distribution characteristics, logical correlation and other aspects is realized, and data anomalies and potential security risks are effectively identified. The changes of data in different dimensions can be monitored in real time, and the reliability of data anomaly identification is significantly improved by combining the comparison and verification of multi-source data. In addition, the designed security assessment engine comprehensively assigns weighted scores in terms of confidentiality, integrity and authenticity, generates more accurate risk assessment results, and prompts users in time through the threshold warning mechanism, so that the power grid system has higher security protection during data transmission and storage, and realizes multi-dimensional detection and security assessment of service channel interaction data in spatiotemporal features, improves the accuracy of anomaly identification and the security of data transmission, and makes the power grid operation more stable and safe. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] Figure 1 This is a schematic diagram of the overall architecture of the service channel interaction data security assessment system.
[0052] Figure 2 Detailed architecture diagram of the feature analysis and evaluation process.
[0053] Figure 3 Schematic diagram of the technical implementation flow of the feature analysis algorithm. DETAILED DESCRIPTION
[0054] In order to make the purpose, technical solution and advantages of the present invention more clear, the technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention.
[0055] The embodiments described in this application are only some embodiments of the present invention, not all embodiments. Based on the spirit of the present invention, other embodiments obtained by ordinary technicians in this field without creative work are all within the protection scope of the present invention.
[0056] In view of the shortcomings of the prior art, the present invention proposes a service channel interaction data security detection method and system based on spatiotemporal feature analysis, which realizes comprehensive security detection and risk warning of service channel interaction data through multi-source data acquisition, spatiotemporal feature analysis, security assessment and risk scoring, and security alarm generation.
[0057] Figure 1 The service channel interaction data security assessment system is schematically shown in FIG. 1 . The service channel interaction data security detection method based on spatiotemporal feature analysis disclosed in the present invention comprises the following steps:
[0058] Step 1: Obtain payment interaction data generated by multiple service channels from multiple data sources, including channel codes, access IP location data, household number location data, and actual payment data, and uniformly calibrate the timestamps of the data.
[0059] First, data acquisition is performed, including synchronously acquiring data generated during operation from multiple data sources and uniformly calibrating the timestamps to ensure the integrity, timeliness and consistency of the data so as to more accurately perform spatiotemporal feature analysis. The step 1 further includes:
[0060] Step 1.1: From different data sources set D = {D1, D2, ..., D n} synchronously collects payment interaction data from channels, including but not limited to: electric power data P(t), recording the output power of new energy power generation equipment at time t. Access IP location data M(t), including wind speed V(t), temperature T(t), humidity H(t), solar radiation intensity I(t), etc. Household number location data E(t), including voltage U(t), current I(t), frequency f(t), etc. Actual payment data C(t), including control commands issued by the dispatch center, equipment operation instructions, etc.
[0061] Step 1.2: For each data source D i , the collected data set is represented as: S i ={(t i1 , v i1 ), (t i2 , v i2 ),...,(t im , v im )}. Among them, t ij is the original timestamp of the data record, v ij is the corresponding data value.
[0062] Step 1.3: Use the Network Time Protocol (NTP) or Global Positioning System (GPS) timing technology to calibrate the timestamp and synchronize the time of all data sources to a unified standard time T standard For each data source Di , the deviation between local time and standard time is: ΔT i =T standard -T i Correct the timestamp of each data record: t′ ij =t ij +ΔT i Among them, t ij is the original timestamp, t′ ij The corrected timestamp.
[0063] Step 2. Perform spatiotemporal feature analysis on the calibrated data, including time dimension feature analysis, space dimension feature analysis, and correlation feature analysis.
[0064] Figure 2 It is a detailed architectural diagram of the feature analysis and evaluation process, which shows in detail the specific processing flow of the three branches of time dimension feature analysis, space dimension feature analysis and logical correlation feature analysis, as well as the summary of the evaluation results of each branch into a comprehensive risk assessment.
[0065] After acquiring and calibrating the data, the data is subjected to in-depth spatiotemporal feature analysis, including time dimension feature analysis, space dimension feature analysis, and correlation feature analysis, to comprehensively identify abnormal features of the data. The time dimension feature analysis checks the continuity and consistency of the historical time series of the data through data time series consistency detection, and ensures its continuity by verifying the timestamp of the data record, without jumps, duplications or regressions, while monitoring the data update frequency and identifying frequency anomalies; the space dimension feature analysis analyzes the spatial distribution characteristics of the data based on the geographic information system, monitors the geographic location of data access to identify access from unauthorized areas, and tracks the data transmission path to detect whether it passes through unexpected intermediate nodes; the correlation feature analysis verifies the logical relationship between the data by establishing a logical model between the data, checks the rationality of the operation process and identifies unauthorized operations, and detects inconsistencies by comparing the consistency of multi-source data acquisition.
[0066] The step 2 further comprises:
[0067] Step 2.1: Perform time dimension feature analysis on the payment interaction data to detect the consistency and rationality of the data in the time series and ensure that the time series characteristics of the data meet expectations. Figure 3 This is a flowchart of the technical implementation of the feature analysis algorithm. Specifically:
[0068] Step 2.1.1 Use the time series analysis algorithm to model and predict historical data to detect the temporal consistency of the data. First, select the historical data series {v t-n , v t-n+1 , ..., v t}, establish the time series model M.
[0069] For the ARIMA model, the general form is:
[0070] φ(B)(1-B) d v t =θ(B)∈ t
[0071] Where φ(B)=1-φ1B-φ2B 2 -…-φ p B p is an autoregressive polynomial, which represents the relationship between the current value of the time series and the previous p lagged values; θ(B) = 1-θ1B-θ2B 2 -…-θ q B q is a moving average polynomial, which represents the relationship between the current value and the random error white noise of q lag periods; B is the lag operator, Bv t =v t-1 ; d is the number of differences; ∈ t is white noise. p is the order of the autoregressive polynomial φ(B), which indicates the number of lags in the autoregressive part of the model. q is the order of the moving average polynomial θ(B), which indicates the number of lags in the moving average part of the model.
[0072] For the LSTM model, a long short-term memory neural network is used to train by inputting historical data sequences, and the model parameters are optimized through the back-propagation algorithm.
[0073] Use the time series model M to predict the data value at the next moment
[0074] Calculate the error between the actual value and the predicted value:
[0075]
[0076] If the error e t+ 1 超 Over the preset threshold δ, that is:
[0077] e t+1 >δ
[0078] It is determined that the data is abnormal.
[0079] Step 2.1.2: For the corrected timestamp sequence {t′1, t′2, ..., t′ n} Perform difference calculation to obtain the time interval sequence:
[0080] Δt i =t′ i+1 -t′ i
[0081] Under normal circumstances, the time interval should be close to the preset sampling period τ, that is:
[0082] Δt i ≈τ
[0083] If Δt i ≤0, it means that the timestamp is backward or repeated, which is considered abnormal.
[0084] If Δt i >>τ, if it exceeds the allowable error range, it is judged as a time jump and an abnormality.
[0085] Step 2.1.3: Count the number of data updates per unit time and calculate the actual update frequency f actual :
[0086]
[0087] Where N is the number of data records within the time interval ΔT.
[0088] Compare the actual update frequency with the expected update frequency f expected Compare:
[0089] If f actual >f expected ×(1+∈), then the update frequency is judged to be too high, where ∈ is the predefined allowable frequency deviation ratio.
[0090] If f factual <f expected ×(1-∈), then it is judged that the update frequency is too low.
[0091] Step 2.2: Analyze the distribution characteristics of data in geographic space to perform spatial dimension feature analysis and identify abnormal situations in spatial locations. Specifically:
[0092] Step 2.2.1: Use geographic information system (GIS) and spatial clustering algorithm to analyze the spatial distribution of data and identify abnormal spatial distribution. First, obtain the geographic coordinates (x i ,y i ). Density clustering algorithm is used for spatial clustering.
[0093] Step 2.2.2: Detect the geographic location of the data access request and identify access from unauthorized areas. Then obtain the visitor's geographic location L through IP address positioning or GPS information. i . i With the authorized area list L auth Matching: If L i ∈L auth , then the access is normal. If The access is abnormal and you need to be alert to potential security risks.
[0094] Step 2.2.3: Trace the data transmission path in the network to detect whether it passes through unexpected intermediate nodes to prevent man-in-the-middle attacks.
[0095] First, use a network routing tracking tool (such as Traceroute) to obtain the transmission path of the data packet {P1, P2, ..., P k}. Then compare the actual path P with the expected legal path P expected For comparison: If The transmission path is normal. If there is a node The transmission path is abnormal and data hijacking may occur.
[0096] Step 2.3: Analyze the correlation characteristics by establishing a logical model between data to verify the logical consistency between data and the rationality of the operation process. This includes the following steps:
[0097] Step 2.3.1: Check the execution order of the actual payment data to ensure that the operation process complies with the predetermined business logic. Define the operation sequence S = {O1, O2, ..., O n}, where O i represents the i-th operation, with attribute A i According to the grid operation specifications, a legal operation sequence rule set R is established. The actual operation sequence S is verified: if S∈R, the operation sequence is legal; if There are illegal or unauthorized operations, so be alert to security risks.
[0098] Step 2.3.2: Compare the results of the same data obtained from different sources to check data consistency. First, i Get the same data item v i . Calculate consistency indicators of the data, such as the mean And standard deviation σ:
[0099]
[0100]
[0101] If the standard deviation σ exceeds the threshold δ v ,Right now:
[0102] σ>δ v
[0103] It is determined that the data is inconsistent and needs further investigation.
[0104] Step 3: Input the results of the time dimension feature analysis, space dimension feature analysis and correlation feature analysis into the security assessment engine to comprehensively assess the security of the payment interaction data.
[0105] The step 3 comprises the following steps:
[0106] Step 3.1: Arrange the abnormal indicators generated by each feature analysis step into a feature vector s = [s1, s2, ..., s m ], where: s i =1 means that the i-th feature is abnormal; s i =0 means the i-th feature is normal.
[0107] Step 3.2: Use a weighted scoring model to assign different weights w to each feature i , calculate the comprehensive safety score S total :
[0108]
[0109] Where: w i ≥0;
[0110]
[0111] Weight w i The setting can be adjusted according to the importance of the feature, the statistical results of historical data or expert experience.
[0112] Step 4: Evaluate the confidentiality, integrity and authenticity of the payment interaction data, and determine the confidentiality level of the payment interaction data, whether the data has been tampered with or damaged, and the source of the data and its credibility.
[0113] To ensure the security of data during transmission, storage and access, the confidentiality, integrity and authenticity of the payment interaction data are evaluated. The confidentiality assessment is used to evaluate the confidentiality of the payment interaction data during transmission and storage. The integrity assessment is used to verify whether the data has been tampered with or damaged. The authenticity assessment is used to confirm the source of the data and its credibility. Step 4 further includes the following steps:
[0114] Step 4.1: Check the encryption measures during data transmission and storage, and evaluate the confidentiality of the data. Confirm whether a secure encryption protocol (such as TLS1.2, TLS1.3) is used; check the encryption algorithm (such as AES, RSA) and key length used: AES-256, RSA-2048, etc. are considered safe. DES, RC4, etc. are considered unsafe. If a strong encryption algorithm and protocol are used, the confidentiality assessment passes. If no encryption is used or weak encryption is used, the confidentiality assessment fails, and there is a security risk.
[0115] Step 4.2: Verify whether the data has been tampered with by digital signature or hash verification. Calculate the hash value h for the data v computed :
[0116] h computed =Hash (v)
[0117] The hash algorithms include SHA-256, SHA-3, etc.
[0118] Compare the calculated hash value with the hash value h provided by the sender provided For comparison: If h computed =h provided , the data integrity verification passes. If they are not equal, it is determined that the data may have been tampered with and the integrity verification fails.
[0119] Step 4.3: Verify the source and credibility of the data to ensure the authenticity of the data. Use the sender's public key K pub Verify the digital signature σ:
[0120] Verify(v,σ,K pub )=True or False
[0121] If the verification result is True, the data source is credible. If it is False, the authenticity of the data is not credible. Verify whether the digital certificate is valid and whether the certificate has been revoked.
[0122] Step 5: Generate a comprehensive security risk score based on the security assessment results of the payment interaction data generated by the security assessment engine, as well as the confidentiality, integrity and authenticity assessment results.
[0123] Preferably, the step 5 specifically comprises the following steps:
[0124] Step 5.1: Set the score for security attribute evaluation: confidentiality score s confidentiality : 0 and 1 represent pass and fail respectively. Completeness score s integrity : 0 and 1 represent pass and fail respectively. Authenticity score s authenticity : 0 and 1 represent pass and fail respectively.
[0125] The comprehensive security risk score calculation formula is:
[0126] S risk =αS total +βs confidentiality +γs integrity +δs authenticity
[0127] The weight coefficients α, β, γ, and δ can be set according to the actual situation and satisfy:
[0128] α+β+γ+δ=1
[0129] Step 5.2: Score the overall security risk risk The risk level is divided into: Low risk: 0≤S risk <0.3 Medium risk: 0.3≤S risk <0.6 High risk: 0.6≤S risk <0.8 Severe risk: S risk ≥0.8.
[0130] Step 6: If the comprehensive security risk score exceeds a preset threshold, a security warning message is generated and the security warning message notification is output in a variety of ways. The security warning message includes the risk level, abnormality type, impact scope and handling suggestions.
[0131] When the security risk score exceeds the preset threshold, a security alert is generated to indicate potential risks and handling suggestions. Alert information is graded according to different risk levels so that users can take appropriate countermeasures. Specifically:
[0132] Step 6.1: Generate warning information, the warning information includes:
[0133] Risk level: low, medium, high, severe; Anomaly type: Indicates in which feature analysis the anomaly is detected, such as time dimension anomaly, space dimension anomaly, correlation anomaly, security attribute anomaly, etc.; Impact scope: Detailed information such as the affected data type, device number, region, etc.; Recommended processing measures: Provide processing suggestions based on the specific anomaly, for example: for timestamp anomalies, it is recommended to check the time synchronization mechanism of the data source; for confidentiality assessment failure, it is recommended to upgrade the encryption protocol or algorithm; for operation sequence anomalies, it is recommended to review the operation permissions and processes.
[0134] Step 6.2: Notify relevant personnel of the alarm information in a variety of ways to ensure timely response. For example, real-time prompts such as pop-up windows and color changes on the system monitoring interface; send alarm information to the mobile phone number of relevant personnel via SMS notification; send alarm emails to the preset email address, and the email content contains detailed alarm information and handling suggestions.
[0135] The beneficial effect of the present invention is that, compared with the prior art, the present invention provides a service channel interaction data security detection method and system based on spatiotemporal feature analysis. Through the multidimensional analysis method based on spatiotemporal features, the accuracy and comprehensiveness of the service channel interaction data security detection are improved, and the in-depth detection of time series consistency, spatial distribution characteristics, logical correlation and other aspects is realized, and data anomalies and potential security risks are effectively identified. The changes of data in different dimensions can be monitored in real time, and the reliability of data anomaly identification is significantly improved by combining the comparison and verification of multi-source data. In addition, the designed security assessment engine comprehensively assigns weighted scores in terms of confidentiality, integrity and authenticity, generates more accurate risk assessment results, and prompts users in time through the threshold warning mechanism, so that the power grid system has higher security protection during data transmission and storage, and realizes multi-dimensional detection and security assessment of service channel interaction data in spatiotemporal features, improves the accuracy of anomaly identification and the security of data transmission, and makes the power grid operation more stable and safe.
[0136] The present invention may be a system, a method and / or a computer program product. The present invention also discloses a service channel interaction data security detection system based on spatiotemporal feature analysis based on the aforementioned service channel interaction data security detection method based on spatiotemporal feature analysis, comprising:
[0137] The data acquisition module is used to obtain payment interaction data generated by multiple data acquisition service channels, including channel codes, access IP location data, account number location data and actual payment data, and to uniformly calibrate the timestamp of the data;
[0138] The spatiotemporal feature analysis module is used to perform spatiotemporal feature analysis on the calibrated data, including time dimension feature analysis, space dimension feature analysis and correlation feature analysis;
[0139] A security assessment module, used to input the results of time dimension feature analysis, space dimension feature analysis and correlation feature analysis into a security assessment engine, and comprehensively assess the security of the payment interaction data;
[0140] The security attribute evaluation module is used to evaluate the confidentiality, integrity and authenticity of the payment interaction data, and to determine the confidentiality level of the payment interaction data, whether the data has been tampered with or damaged, and the source of the data and its credibility;
[0141] Comprehensive scoring module, which is used to generate a comprehensive security risk score based on the security assessment results of the payment interaction data generated by the security assessment engine, as well as the confidentiality, integrity and authenticity assessment results;
[0142] The alarm generation module is used to generate security alarm information if the comprehensive security risk score exceeds a preset threshold, and output the security alarm information notification in a variety of ways. The security alarm information includes risk level, abnormality type, impact scope and handling suggestions.
[0143] Preferably, the system also includes a data storage module for storing historical data and analysis results to support subsequent data mining and model optimization. The detection capability and accuracy of the system can be further improved by analyzing the stored data.
[0144] The system adopts a modular design to facilitate expansion and maintenance, so that the system can flexibly adapt to power grid systems of different sizes and needs, and adapt to new data types and feature analysis requirements by adding or adjusting modules.
[0145] The system has self-learning capabilities, and optimizes feature analysis models and evaluation engines through historical alarms and processing results, so that the system can gradually improve its detection accuracy and adaptability, thereby better meeting the needs of channel payment interaction data security detection.
[0146] Based on the spirit of the present invention, those skilled in the art can easily think that a computer program product can be obtained based on the aforementioned service channel interaction data security detection method based on spatiotemporal feature analysis. The computer program product may include a computer-readable storage medium, which carries computer-readable program instructions for enabling a processor to implement various aspects of the present disclosure. That is, the present application also includes a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the aforementioned service channel interaction data security detection method based on spatiotemporal feature analysis.
[0147] Computer readable storage medium can be a tangible device that can keep and store the instructions used by the instruction execution device. Computer readable storage medium can be, for example, - but not limited to - electrical storage device, magnetic storage device, optical storage device, electromagnetic storage device, semiconductor storage device or any suitable combination of the above. More specific examples (non-exhaustive list) of computer readable storage medium include: portable computer disk, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanical encoding device, for example, punch card or groove protrusion structure with instructions stored thereon and any suitable combination of the above. Computer readable storage medium used here is not interpreted as instantaneous signal itself, such as radio wave or other free propagating electromagnetic wave, electromagnetic wave propagated by waveguide or other transmission medium (for example, light pulse by optical fiber cable) or electrical signal transmitted by wire.
[0148] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0149] The computer program instructions for performing the operation of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages-such as Smalltalk, C++, etc., and conventional procedural programming languages-such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network-including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may be personalized by utilizing the state information of a computer-readable program instruction, and the electronic circuit may execute a computer-readable program instruction, thereby realizing various aspects of the present disclosure.
[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A service channel interaction data security detection method based on spatiotemporal feature analysis, characterized in that: The following steps are involved: Step 1: Obtain payment interaction data generated by multiple service channels from multiple data sources, including channel codes, access IP location data, account number location data, and actual payment data, and uniformly calibrate the timestamps of the data; Step 2. Perform spatiotemporal feature analysis on the calibrated data, including time dimension feature analysis, space dimension feature analysis and correlation feature analysis; Step 3: Input the results of the time dimension feature analysis, space dimension feature analysis and correlation feature analysis into the security assessment engine to comprehensively assess the security of the payment interaction data; Step 4: Evaluate the confidentiality, integrity and authenticity of the payment interaction data, and determine the confidentiality level of the payment interaction data, whether the data has been tampered with or damaged, and the source of the data and its credibility; Step 5: Generate a comprehensive security risk score based on the security assessment engine’s security assessment results of the payment interaction data, as well as the confidentiality, integrity and authenticity assessment results; Step 6: If the comprehensive security risk score exceeds a preset threshold, a security warning message is generated and the security warning message notification is output in a variety of ways. The security warning message includes the risk level, abnormality type, impact scope and handling suggestions.
2. The service channel interaction data security detection method based on spatiotemporal feature analysis according to claim 1 is characterized in that: The unified calibration of the timestamps of the data further includes: Use the network time protocol NTP or global positioning system GPS timing technology to calibrate the timestamp uniformly and synchronize the time of all data sources to a unified standard time T standard ; For each data source D i , calculate the deviation ΔT between local time and standard time i =T standard -T i ; Correct the timestamp of each data record: t i ′ j =t ij +ΔT i ; where t ij is the original timestamp, t i ′ i The corrected timestamp.
3. The service channel interaction data security detection method based on spatiotemporal feature analysis according to claim 2 is characterized in that: The time dimension feature analysis predicts historical data and compares it with actual data by using a time series analysis algorithm, an autoregressive integrated moving average model ARIMA or a long short-term memory model LSTM to identify abnormalities in the data time series; The spatial dimension feature analysis uses a spatial clustering algorithm to identify data distribution anomalies in geographic space, and detects anomalies in spatial location through analysis of geographic distribution; The correlation feature analysis establishes a correlation model between the channel code and the access IP location data to perform a matching test between the two.
4. The service channel interaction data security detection method based on spatiotemporal feature analysis according to claim 3 is characterized in that: The security assessment engine adopts a weighted scoring model to assign different weights to various feature analysis results and ultimately generate a comprehensive assessment result. The weights are dynamically adjusted based on the characteristics of the channel payment interaction data.
5. The service channel interaction data security detection method based on spatiotemporal feature analysis according to claim 4 is characterized in that: The evaluation of the confidentiality, integrity and authenticity of the payment interaction data further includes: Check the encryption measures during data transmission and storage, and confirm the encryption protocols and algorithms used. If strong encryption algorithms and protocols are used, the confidentiality assessment passes; if no encryption is used or weak encryption algorithms and protocols are used, the confidentiality assessment fails; Verify whether the data has been tampered with by digital signature or hash verification, and calculate the hash value h for the data v computed : h computed =Hash (v) Compare the calculated hash value with the hash value h provided by the sender provided For comparison, if h computed =h provided , the data integrity verification passes; if they are not equal, it is determined that the integrity verification fails; Verify the source and credibility of the data using the sender’s public key K pub Verify the digital signature σ: Verify(v,σ,K pub )=True or False If the verification result is True, the data source is credible; if it is False, the authenticity of the data is not credible.
6. The service channel interaction data security detection method based on spatiotemporal feature analysis according to claim 5 is characterized in that: Generating a comprehensive security risk score further includes: Set the score for security attribute evaluation: confidentiality score confidentiality : 0 and 1 represent pass and fail respectively; completeness score s integrity : 0 and 1 represent pass and fail respectively; authenticity score s authenticity : 0 and 1 represent pass and fail respectively; The comprehensive security risk score calculation formula is: S risk =αS total +βs confidentiality +γs integrity +δs authenticity The weight coefficients α, β, γ, and δ can be set according to the actual situation and satisfy: α+β+γ+δ=1 According to the comprehensive security risk score S risk The risk levels are divided into: low risk, medium risk, high risk and severe risk.
7. The service channel interaction data security detection method based on spatiotemporal feature analysis according to claim 6 is characterized in that: The security warning information includes: Risk level: low risk, medium risk, high risk or severe risk; Anomaly type: time dimension anomaly, space dimension anomaly, correlation anomaly or security attribute anomaly; Impact scope: affected data types, device numbers, and region information; Recommended processing measures: For timestamp anomalies, it is recommended to check the time synchronization mechanism of the data source; for confidentiality assessment failure, it is recommended to upgrade the encryption protocol or algorithm; for operation sequence anomalies, it is recommended to review the operation permissions and processes.
8. A service channel interaction data security detection system based on spatiotemporal feature analysis, characterized in that: include: The data acquisition module is used to obtain payment interaction data generated by multiple data acquisition service channels, including channel codes, access IP location data, account number location data and actual payment data, and to uniformly calibrate the timestamp of the data; The spatiotemporal feature analysis module is used to perform spatiotemporal feature analysis on the calibrated data, including time dimension feature analysis, space dimension feature analysis and correlation feature analysis; A security assessment module, used to input the results of time dimension feature analysis, space dimension feature analysis and correlation feature analysis into a security assessment engine, and comprehensively assess the security of the payment interaction data; The security attribute evaluation module is used to evaluate the confidentiality, integrity and authenticity of the payment interaction data, and to determine the confidentiality level of the payment interaction data, whether the data has been tampered with or damaged, and the source of the data and its credibility; Comprehensive scoring module, which is used to generate a comprehensive security risk score based on the security assessment results of the payment interaction data generated by the security assessment engine, as well as the confidentiality, integrity and authenticity assessment results; The alarm generation module is used to generate security alarm information if the comprehensive security risk score exceeds a preset threshold, and output the security alarm information notification in a variety of ways. The security alarm information includes risk level, abnormality type, impact scope and handling suggestions.
9. A terminal comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the service channel interaction data security detection method based on spatiotemporal feature analysis according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the service channel interaction data security detection method based on spatiotemporal feature analysis described in any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Power network user permission anomaly detection method and system based on time sequence behavior mining
CN120632874A