Computer information security management method and system based on big data

Through the computer information security management method based on big data, the real-time acquisition and risk prediction model of multiple data sources is used to identify risks in financial transactions, and combined with multi-factor authentication and abnormal feature comparison, efficient and accurate risk identification and security management in the financial transaction process is achieved, and the problems of low efficiency and insufficient accuracy of risk identification in the existing technology are solved.

CN120047250AActive Publication Date: 2025-05-27JIANGMEN POLYTECHNIC

Patent Information

Application Number
CN202510534504.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-05-27
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

In the process of financial transactions, real-time risk identification and exception handling of computer information security are inefficient and insufficient accuracy.

Method used

Through the computer information security management method based on big data, real-time collection of financial transaction data from multiple data sources is realized, risk prediction models are used to identify risks, multi-factor authentication and abnormal feature comparison, and multiple verifications are carried out to ensure security approval.

Benefits of technology

A comprehensive computer information security risk prevention and control system has been built, which has improved the accuracy of risk identification and transaction security, reduced misjudgment and misjudgment, and enhanced user experience and system flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120047250A_ABST
    Figure CN120047250A_ABST
Patent Text Reader

Abstract

The invention discloses a computer information security management method and system based on big data, and relates to the technical field of information security management, and the method comprises the steps: carrying out the risk recognition of financial transaction application computer storage data, marking a key transaction concerned object, carrying out the first verification, and marking an abnormal computer information condition; according to the marked abnormal computer information condition, identifying and marking the financial computer information abnormity type with the highest matching degree, and then carrying out second verification to judge whether the financial computer information abnormity type exists or not; when the financial computer information exception type does not exist, obtaining related verification data for third verification; based on the third verification result, whether security approval passes is judged, if the security approval passes, a manual inspection demand is triggered, an abnormal specific reason marked by manual inspection is obtained, and an abnormal label is created for the abnormal specific reason. The multi-level security verification and intelligent abnormity management are realized, and the transaction security and the user experience are significantly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security management, and in particular to a computer information security management method and system based on big data. Background Art

[0002] With the continuous development of the financial market, the scale of financial transactions continues to expand, the types of transactions are becoming increasingly complex and diverse, and new financial products and transaction models continue to emerge, such as financial derivatives transactions, cross-border e-commerce financial transactions, etc. This makes the risks faced by financial transactions more complex and changeable, and puts forward higher requirements for computer information security management in the process of financial transactions; and in the era of big data, the amount of computer data generated by financial transactions is exploding. These data contain rich information, but how to effectively collect, process and analyze these data, tap their value, and use them for risk identification and security management has become an important issue facing the financial industry.

[0003] When faced with massive amounts of financial transaction data, existing technologies have problems such as untimely data processing and inaccurate risk identification; and existing anomaly detection methods only rely on single-dimensional data or simple rules, resulting in a large number of misjudgments and missed judgments; some existing computer information security management methods in financial transaction processes lack user participation, and when a transaction encounters anomalies, it is impossible to flexibly obtain more information for verification.

[0004] Therefore, in response to the above problems, there is an urgent need for a computer information security management method and system based on big data. Summary of the invention

[0005] In view of the deficiencies in the prior art, the present invention provides a computer information security management method based on big data, which solves the problems of low efficiency and insufficient accuracy in real-time risk identification and exception handling of computer information security in financial transactions.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A computer information security management method based on big data, comprising the following steps: S1, real-time collecting computer storage data of financial transaction applications based on multiple data sources of a financial transaction system, where the computer storage data of financial transaction applications includes basic transaction information and information of both parties to the transaction; S2, using a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then marking key transaction attention objects based on the risk identification results; S3, performing multi-factor authentication on the key transaction attention objects, and then performing a first verification on the security of the key transaction attention objects based on the multi-factor authentication results, and identifying and marking abnormal computer information conditions; S4, for the marked abnormal computer information conditions, extracting abnormal features, and then comparing and retrieving the abnormal features with various stored abnormal patterns to identify and mark the financial computer information abnormal type with the highest matching degree; S5, for the marked financial computer information abnormal type, obtaining relevant feature information of the financial computer information abnormal type, and then performing a second verification on the relevant feature information of the financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; S6, when there is no such financial computer information abnormal type, presenting a secondary financial transaction application page to the user, obtaining the user's authorization to obtain relevant verification data, and then obtaining relevant verification data from the corresponding data sources according to the authorization result, and then performing a third verification on the relevant verification data; S7, determining whether to grant security approval based on the third verification result. If the security approval is passed, triggering a manual inspection requirement, obtaining the specific reasons for the abnormalities marked by the manual inspection, creating an abnormal information label for the specific reasons for the abnormalities. If the security approval is not passed, sending a warning prompt to the user.

[0007] Further, the specific steps of S2 include: inputting the real-time monitored computer storage data of financial transaction applications into the risk prediction model, outputting a risk probability value, and then comparing the risk probability value with a risk probability threshold. Financial transaction applications with a risk probability value greater than or equal to the risk probability threshold are marked as key transaction attention objects.

[0008] Further, the specific analysis of the first verification is: using a convolutional neural network and a support vector machine to output the authentication results of each multi-factor authentication, and then summing the authentication results of each multi-factor authentication to obtain a first verification score. Comparing the first verification score with a first verification score threshold, and when the first verification score is greater than or equal to the first verification score threshold, it is marked as an abnormal computer information condition.

[0009] Further, the specific steps of S4 include: obtaining the abnormal proportional coefficient of the marked abnormal computer information status and the reference proportional coefficients of various abnormal patterns, and then respectively taking the absolute difference between the abnormal proportional coefficient and the reference proportional coefficients of various abnormal patterns, and marking the one with the smallest absolute difference as the financial computer information abnormal type with the highest matching degree.

[0010] Further, the specific analysis of obtaining the abnormal proportional coefficient of the marked abnormal computer information status and the reference proportional coefficients of various abnormal patterns is as follows: performing quantization processing on the abnormal features, and then based on logistic regression, training and inputting the abnormal features, and outputting to obtain the abnormal proportional coefficient; extracting the stored features of various abnormal patterns, and respectively training and inputting the features of various abnormal patterns based on logistic regression, and outputting to obtain the reference proportional coefficients of various abnormal patterns.

[0011] Further, the specific steps of S5 include: according to the marked financial computer information abnormal type, retrieving the typical feature information of this financial computer information abnormal type, and then obtaining the typical confidence interval of this financial computer information abnormal type; comparing the relevant feature information of this financial computer information abnormal type with the typical confidence interval, and when the relevant feature information of this financial computer information abnormal type conforms to the typical confidence interval of this financial computer information abnormal type, it is determined that this financial computer information abnormal type exists, the second verification is qualified, and security approval is given, otherwise it is determined that this financial computer information abnormal type does not exist.

[0012] Further, the specific steps of S6 include: when the monitored user refuses authorization, the security approval fails, a risk warning prompt is sent to the user, and the user is marked as a risk; when the monitored user agrees to authorize, the relevant verification data of the user is obtained, and the relevant verification data is respectively retrieved and verified according to the relevant typical patterns. When there is relevant verification data that does not conform to the relevant typical patterns, it is marked that the third verification is unqualified, otherwise security approval is given.

[0013] A computer information security management system based on big data, applying the above-mentioned computer information security management method based on big data, includes: a data acquisition module, used for real-time collecting the financial transaction application computer storage data based on multiple data sources of the financial trading system, and the financial transaction application computer storage data includes transaction basic information and transaction party information; a risk identification module, used for using a risk prediction model to identify the risks of the financial transaction application computer storage data, and then marking the key transaction attention objects based on the risk identification results. The first verification module is used to perform multi-factor authentication on the key transaction attention objects, and then based on the multi-factor authentication results, perform the first verification on the security of the key transaction attention objects, and identify and mark the abnormal computer information status; the retrieval module is used to extract abnormal features for the marked abnormal computer information status, and then compare and retrieve the abnormal features with various stored abnormal patterns to identify and mark the financial computer information abnormal type with the highest matching degree; the second verification module is used to obtain the relevant feature information of the marked financial computer information abnormal type, and then perform the second verification on the relevant feature information of the marked financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; the third verification module is used to, when there is no such financial computer information abnormal type, display a secondary financial transaction application page to the user, obtain the user's authorization for obtaining relevant verification data, and then obtain relevant verification data from the corresponding data sources according to the authorization result, and then perform the third verification on the relevant verification data; the approval management module is used to determine whether to give a security approval based on the third verification result. If the security approval is passed, trigger a manual inspection requirement, obtain the specific reason for the abnormality marked by the manual inspection, and create an abnormality information label for the specific reason for the abnormality. If the security approval is not passed, send a warning prompt to the user.

[0014] The present invention has the following beneficial effects: The computer information security management method and system based on big data constructs a comprehensive computer information security risk prevention and control system from data collection to multi-factor authentication, and then to the identification and multiple verifications of financial computer information abnormal types. By collecting transaction application data in real time from multiple data sources, it can obtain richer and more accurate information, providing a solid foundation for subsequent risk identification; the multiple verification mechanism further improves the accuracy of information risk identification and comprehensively guarantees the security of financial transactions; in terms of processing abnormal computer information status, by extracting abnormal features and comparing and retrieving them with stored abnormal patterns, it can accurately identify the financial computer information abnormal type with the highest matching degree, perform the second verification on the relevant feature information of the financial computer information abnormal type, and perform the third verification when there is no established financial computer information abnormal type, ensuring the accurate judgment of abnormal transactions, reducing misjudgment and missed judgment, and improving the accuracy of abnormal information detection; when there is no known financial computer information abnormal type, displaying a secondary financial transaction application page to the user to obtain authorization not only guarantees the security of transactions, but also gives users the opportunity to participate in transaction verification, improving the user experience to a certain extent. At the same time, allowing more verification data to be obtained when necessary increases the flexibility of transactions and can adapt to complex and changeable financial transaction scenarios; if the security approval is passed, triggering a manual inspection requirement and creating an abnormality label helps to continuously accumulate experience and improve the financial computer information abnormal type library and risk prediction model. Brief Description of the Drawings

[0015] Figure 1 This is a flowchart of a computer information security management method based on big data according to the present invention.

[0016] Figure 2 This is a structure diagram of a computer information security management system based on big data according to the present invention. Detailed implementation manners

[0017] In the embodiments of the present application, through a computer information security management method and system based on big data, multi-level computer information security verification and intelligent exception management are realized, significantly improving transaction security and user experience.

[0018] The general idea of the embodiments of the present application is as follows: First, transaction application data is collected in real time from multiple data sources of the financial trading system to ensure the comprehensiveness and timeliness of the data; then, a risk prediction model is used to identify risks in the collected data and mark key transaction attention objects; next, multi-factor authentication is performed on the key transaction attention objects to conduct a first verification of their security from multiple dimensions and identify and mark abnormal computer information conditions; for the marked abnormal computer information conditions, abnormal features are extracted and compared and retrieved with stored abnormal patterns to determine the financial computer information abnormal type with the highest matching degree; for the marked financial computer information abnormal type, relevant feature information is obtained for a second verification to determine whether there is such a financial computer information abnormal type; when there is no such financial computer information abnormal type, authorization is obtained from the user, and relevant verification data is obtained from the corresponding data source for a third verification; finally, it is determined whether to give a security approval based on the result of the third verification. If it passes, manual inspection is triggered and an abnormal information label is created. If it fails, a warning prompt is sent to the user.

[0019] Please refer to Figure 1, an embodiment of the present invention provides a technical solution: a computer information security management method based on big data, including the following steps: S1, real-time collect computer storage data of financial transaction applications based on multiple data sources of the financial transaction system, and the computer storage data of financial transaction applications includes transaction basic information and transaction party information; S2, use a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then mark key transaction attention objects based on the risk identification results; S3, conduct multi-factor authentication on the key transaction attention objects, and then conduct a first verification on the security of the key transaction attention objects based on the multi-factor authentication results, and identify and mark abnormal computer information conditions; S4, for the marked abnormal computer information conditions, extract abnormal features, and then compare and retrieve the abnormal features with various stored abnormal patterns to identify and mark the financial computer information abnormal type with the highest matching degree; S5, for the marked financial computer information abnormal type, obtain relevant feature information of the financial computer information abnormal type, and then conduct a second verification on the relevant feature information of the financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; S6, when there is no such financial computer information abnormal type, display a secondary financial transaction application page to the user, obtain the user's authorization for obtaining relevant verification data, and then obtain relevant verification data from the corresponding data source according to the authorization result, and then conduct a third verification on the relevant verification data; S7, determine whether to grant security approval based on the third verification result. If the security approval is passed, trigger a manual inspection requirement, obtain the specific reason for the abnormality marked by the manual inspection, create an abnormal label for the specific reason for the abnormality. If the security approval is not passed, send a warning prompt to the user.

[0020] Specifically, the specific steps of S2 include: cleaning and feature extraction of the computer storage data of financial transaction applications. The transaction basic information includes but is not limited to transaction amount, transaction time, transaction frequency, and transaction device. The transaction party information includes but is not limited to the DI of the transaction parties, the credit scores of the transaction parties, the historical transaction records of the transaction parties, the professional types of the transaction parties, and the risk marking status of the transaction parties; divide the computer storage data of financial transaction applications into a training set and a test set, use logistic regression for training to obtain a risk prediction model; input the real-time monitored computer storage data of financial transaction applications into the risk prediction model, output a risk probability value, and then compare the risk probability value with a risk probability threshold. Financial transaction applications with a risk probability value greater than or equal to the risk probability threshold are marked as key transaction attention objects.

[0021] In this implementation, the specific steps for training a risk prediction model using logistic regression are as follows: After cleaning and feature extraction of the computer-stored data of financial transaction applications, the data is divided into a training set and a test set according to a certain ratio (such as 70% - 30% or 80% - 20%). The training set is used for model training, and the test set is used to evaluate the model performance; the extracted features are screened to remove features with high correlation or small contribution to risk prediction to reduce the complexity and overfitting risk of the model; the features are standardized to scale the feature values to the same range; the parameters of the logistic regression model are initialized, including the intercept term and the coefficients of each feature, specifically initialized by setting the coefficients to zero or random values; the logistic regression model is trained using the training set data; the logistic regression model estimates the parameters of the model through the maximum likelihood estimation method to maximize the likelihood function of the probability predicted by the model and the actual label; the parameters of the model are updated iteratively to continuously reduce the value of the loss function until the convergence condition is reached; the trained model is evaluated using the test set data, and the performance metrics of the model, such as accuracy, recall rate, F1 value, etc., are calculated to evaluate the prediction ability and generalization ability of the model; according to the evaluation results, the parameters of the model are adjusted or feature engineering is carried out to further optimize the model performance; after multiple adjustments and evaluations, the final risk prediction model is determined. An example of the specific expression for obtaining the risk prediction model is: , where represents the probability of risk when given the computer-stored data of a financial transaction application , represents the intercept term, which is obtained through the maximum likelihood estimation method represents the parameters of the risk prediction model, which are obtained through the maximum likelihood estimation method represents the specific feature values in the computer-stored data of a financial transaction application represents the total number of computer-stored data of financial transaction applications

[0022] The transaction amount refers to the amount of funds involved in each financial transaction, which is directly obtained from the transaction records of the financial transaction system and directly quantified using the actual transaction amount value; the transaction time represents the specific moment or time period when the transaction occurs. Similarly, the timestamp information of the transaction is obtained from the transaction records, and the transaction time is converted into a timestamp, or the features of the transaction time are extracted for quantification; the transaction frequency refers to the number of transactions occurring within a certain period of time, which is calculated by counting the number of transaction records within a certain period of time, and the counted number of transactions is used as the quantification value; the transaction device refers to the type of device used for the transaction, such as mobile phone, computer, ATM, etc. The transaction system will record the device identification information used when the transaction is initiated, and one-hot encoding is used to convert different device types into binary vectors for quantification.

[0023] The IDs of the two trading parties represent the identity numbers used to uniquely identify the two trading parties, which are assigned and recorded in the transaction records by financial institutions or trading systems, and are quantified through hash encoding or simple number mapping; the credit scores of the two trading parties represent the score values reflecting the credit status of the two trading parties, which are obtained from credit rating agencies or calculated by financial institutions according to their own credit assessment models, and the numerical values of the credit scores are directly used for quantification; the historical transaction records of the two trading parties represent the past transaction behavior records of the two trading parties, which are obtained from the historical data of the financial trading system, and some statistical features can be extracted, such as the number of transactions, the total transaction amount, the average transaction amount, etc. for quantification; the occupational types of the two trading parties represent the occupational categories engaged by the two trading parties, which are identified from the information collected during user registration or transactions, and the different occupational types are converted into binary vectors for quantification using one-hot encoding; the risk flag status of the two trading parties represents the identification information indicating whether there are risks for the two trading parties, and the flag information is converted into a numerical value, where "0" indicates no risk and "1" indicates risk.

[0024] The method for obtaining the risk probability threshold is as follows: According to the historical experience and business requirements of financial institutions, a fixed risk probability threshold is set. For example, based on past risk control experience, a financial institution sets the risk probability threshold to 0.5 or 0.6; the risk probability threshold can also be determined according to the business objectives of financial institutions, such as risk preference, return target, etc. If a financial institution pays more attention to risk prevention and control, the threshold may be set lower, and if it pays more attention to business expansion, the threshold can be appropriately increased; by evaluating the performance indicators of the model under different thresholds on the validation set, a threshold that can make the model achieve the best performance under business requirements can also be selected. For example, an ROC curve can be plotted and an appropriate threshold can be selected according to the shape of the curve and business requirements; the risk losses and business revenues under different risk probability thresholds can also be considered, and by calculating the cost-benefit ratio, the threshold that optimizes the cost-benefit ratio can be selected. For example, when the risk probability exceeds the threshold, a financial institution may need to take additional risk control measures, which will incur certain costs, while when it is lower than the threshold, it may increase business risks resulting in losses.

[0025] Cleaning the computer - stored data of financial transaction applications can remove noisy, duplicate, and incorrect data, ensuring data accuracy and consistency, providing a high - quality data foundation for subsequent risk prediction, and improving the reliability of the model; extracting features from transaction basic information and information of both trading parties helps to discover potential patterns and risk factors in the data, enabling the model to consider various factors affecting transaction risks more comprehensively and enhancing the accuracy of risk prediction; the logistic regression model has good interpretability, and its coefficients can intuitively reflect the direction and degree of the impact of each feature on the risk probability, facilitating financial institutions to understand and analyze risk factors and make reasonable decisions; inputting the computer - stored data of real - time monitored financial transaction applications into the risk prediction model can output risk probability values in a timely manner, and by comparing with the risk probability threshold, quickly mark key transaction objects of concern, realizing real - time monitoring and early warning of financial transaction risks, and helping to take timely measures to prevent risks.

[0026] Specifically, multi - factor authentication includes, but is not limited to, personal identification number (PIN) authentication, biometric authentication, and device identification; the first verification is specifically analyzed as follows: using a convolutional neural network (CNN) and a support vector machine (SVM) to output the authentication results of each multi - factor authentication, and then summing the authentication results of each multi - factor authentication to obtain the first verification score; comparing the first verification score with the first verification score threshold, and when the first verification score is greater than or equal to the first verification score threshold, it is marked as an abnormal computer information status.

[0027] In this implementation plan, the specific steps of using a convolutional neural network and a support vector machine to output the authentication results of each multi - factor authentication are as follows: For PIN authentication: Collect the PIN entered by the user and convert it into a format suitable for model input, such as encoding the PIN as a vector form; normalize the PIN data to ensure that all data has the same scale range; input the pre - processed PIN data into the trained CNN model. The CNN model will automatically extract features from the PIN data, perform feature extraction and dimensionality reduction on the data through operations such as convolutional layers and pooling layers; finally, map the extracted features to the output layer through a fully - connected layer to output a probability value indicating the likelihood that the PIN passes the authentication. Use the features extracted by the CNN as the input of the SVM model. The SVM model will classify the input features according to the trained classification hyperplane and output a classification result (pass or fail authentication) and the corresponding confidence level. Integrate the probability value output by the CNN, the classification result and confidence level output by the SVM to obtain the final authentication result of PIN authentication. The specific integration method can use weighted average for result fusion.

[0028] For biometric authentication: Collect biometric data such as fingerprints, facial images, iris images, etc. Preprocess the collected biometric data, including operations such as image enhancement, normalization, and cropping, to improve the quality and consistency of the data. Convert the preprocessed biometric data into a format suitable for input to the CNN. Input the preprocessed biometric data into the CNN model. The CNN model extracts features from the biometric data and learns the essential features of the biometric characteristics. Output a probability value through the output layer, indicating the likelihood that the biometric data matches the registered data. Use the biometric features extracted by the CNN as the input to the SVM model. The SVM model classifies the biometric features according to the trained classification hyperplane and outputs the classification result (match or no match) and confidence. Combine the probability value output by the CNN and the classification result and confidence output by the SVM to obtain the final authentication result of biometric authentication. The specific combination method can use weighted average for result fusion.

[0029] For device identification: Collect relevant information about the device, such as device model, operating system version, device unique identifier, etc. Encode and normalize the device information and convert it into a vector form suitable for model input. Input the preprocessed device information into the CNN model. The CNN model extracts features from the device information and learns the feature patterns of the device. Output a probability value through the output layer, indicating the likelihood that the device is a trusted device. Use the device features extracted by the CNN as the input to the SVM model. The SVM model classifies the device features according to the trained classification hyperplane and outputs the classification result (trusted or untrusted) and confidence. Combine the probability value output by the CNN and the classification result and confidence output by the SVM to obtain the final authentication result of device identification. The specific combination method can use weighted average for result fusion.

[0030] The first verification score threshold is obtained in the following ways: Based on the historical experience and business practices of financial institutions, a fixed first verification score threshold is set. For example, a financial institution can set the threshold as an empirical value, such as 70 points or 80 points, according to past authentication data and the marking situation of abnormal computer information. It can also determine the threshold based on the business objectives and risk preferences of the financial institution. If the financial institution pays more attention to risk prevention and control and hopes to minimize the occurrence of abnormal transactions as much as possible, the threshold can be set higher. If it pays more attention to user experience and business efficiency and hopes to reduce misjudgment, the threshold can be appropriately lowered. Use historical authentication data for model evaluation. By adjusting the threshold, observe indicators such as the accuracy rate and recall rate of the marking of abnormal computer information under different thresholds, and select a threshold that can achieve the best balance of these indicators under business requirements. For example, an ROC curve can be drawn and a suitable threshold can be selected according to the shape of the curve and business requirements. It is also possible to consider the risk losses and authentication costs under different thresholds. When the threshold is too high, more normal transactions may be misjudged as abnormal, increasing the authentication cost and user inconvenience. When the threshold is too low, more abnormal transactions may be missed, increasing the risk loss. By calculating the cost-benefit ratio under different thresholds, select the threshold that optimizes the cost-benefit ratio.

[0031] Multi-factor authentication (PIN authentication, biometric authentication, device identification) is used to authenticate the identity of key transaction attention objects from multiple dimensions, greatly increasing the difficulty of identity theft and fraud and effectively improving the security of financial transactions. Two different machine learning models, convolutional neural network (CNN) and support vector machine (SVM), are used to output the authentication results. CNN has strong feature extraction capabilities and is especially suitable for processing data with spatial structures, such as biometric data. SVM performs well in processing high-dimensional data and small-sample data and can provide accurate classification results. The combination of the two can give full play to their respective advantages and improve the accuracy and reliability of authentication. By summing the authentication results of each multi-factor authentication to obtain the first verification score and comparing it with the first verification score threshold, a quantitative evaluation and standardized judgment of the authentication results are achieved, making the authentication process more objective and scientific, reducing the interference of human factors, and improving the accuracy and consistency of the marking of abnormal computer information. The multi-factor authentication method in the design can be extended and adjusted according to actual needs. For example, new authentication factors can be added or the authentication model can be replaced. At the same time, the first verification score threshold can also be dynamically adjusted according to different business scenarios and risk preferences, with strong scalability and flexibility.

[0032] Specifically, the specific steps of S4 include: obtaining the abnormal proportionality coefficient of the marked abnormal computer information status and the reference proportionality coefficients of various abnormal patterns, and then respectively taking the absolute differences between the abnormal proportionality coefficient and the reference proportionality coefficients of various abnormal patterns, and marking the one with the smallest absolute difference as the financial computer information abnormal type with the highest matching degree.

[0033] The specific analysis of obtaining the abnormal proportionality coefficient of the marked abnormal computer information status and the reference proportionality coefficients of various abnormal patterns is as follows: The abnormal features include but are not limited to the fund inflow time, source account, and debt-to-income ratio; the abnormal features are quantified, and then based on logistic regression, the abnormal features are trained and input, and the abnormal proportionality coefficient is output; the features of various abnormal patterns stored are extracted, and the abnormal patterns include but are not limited to market fluctuations, business expansion, and interest rate and exchange rate changes; for various abnormal patterns, based on logistic regression, the features of various abnormal patterns are trained and input respectively, and the reference proportionality coefficients of various abnormal patterns are output.

[0034] In this implementation plan, the fund inflow time represents the specific time point when the funds enter the trading account, which is extracted from the timestamp record of the financial trading system. The specific quantification can convert the time into a time interval based on a certain fixed time point. For example, based on the zero point of the day when the transaction occurs, calculate the number of minutes or hours between the fund inflow time and this reference time; the source account refers to the information of the transfer account of the funds, and the relevant account identifier is obtained from the financial transaction record. The quantification method can encode the account, such as using hash encoding or digital encoding, to convert the account information into a digital form for easy processing; the debt-to-income ratio refers to the ratio of the total debt to the total income, and the acquisition method is to calculate by obtaining the debt information and income information of both parties to the transaction, and the quantification method is to directly use the calculated ratio value.

[0035] The specific steps for training and inputting abnormal features based on logistic regression and outputting the abnormal ratio coefficient are as follows: Clean and standardize the abnormal features to ensure the quality and consistency of the data; According to business experience and correlation analysis, select the abnormal features that have a significant impact on the abnormal computer information status as the input variables of the logistic regression model. For example, if it is found that some features have a low correlation with the abnormal computer information status, they can be considered excluded to improve the efficiency and accuracy of the model; Construct a logistic regression model, using the processed abnormal features as independent variables and the abnormal computer information status (e.g., marked as abnormal or normal) as the dependent variable; Use the training data set to train the logistic regression model. By adjusting the parameters of the model, the model can best fit the training data. During the training process, the maximum likelihood estimation method is used to solve the parameters of the model to minimize the difference between the predicted results of the model and the actual results; After training, the output of the model is the abnormal ratio coefficient, and the abnormal ratio coefficient represents the comprehensive quantitative value of the abnormal computer information status.

[0036] For various abnormal patterns, the specific steps for training and inputting the features of each abnormal pattern based on logistic regression and outputting the reference ratio coefficients of each abnormal pattern are as follows: For each abnormal pattern, extract the corresponding features from the relevant data and perform preprocessing, including cleaning, standardization, etc. For example, for the abnormal pattern of market volatility, it is necessary to extract the volatility data of relevant market indexes and perform normalization processing. For the abnormal pattern of business expansion, it may be necessary to extract the business expansion index data of the enterprise, such as new business areas, new customer numbers, etc., and perform standardization processing; According to the characteristics of each abnormal pattern and business understanding, select the representative features of the abnormal pattern as the input variables of the logistic regression model. For example, for the abnormal pattern of interest rate and exchange rate changes, select the indicators related to interest rates and exchange rates as features and exclude other features irrelevant to this pattern; For each abnormal pattern, construct a logistic regression model separately and use the corresponding training data set for training. During the training process, also by adjusting the parameters of the model, the model can accurately fit the relationship between the features of this abnormal pattern and the actual situation; After training, the output of the model is the reference ratio coefficients of each abnormal pattern, and these coefficients reflect the comprehensive quantitative values of each abnormal pattern.

[0037] An example of the calculation formula for the absolute difference between the abnormal ratio coefficient and the reference ratio coefficients of various abnormal patterns is: , where represents the absolute difference between the abnormal ratio coefficient and the reference ratio coefficient of abnormal pattern C, represents the abnormal ratio coefficient, , represents the reference ratio coefficient of abnormal pattern C, , and respectively represent the calculation parameters of the abnormal ratio coefficient and the reference ratio coefficient of the abnormal pattern C, and are obtained by the maximum likelihood estimation method. and respectively represent the specific values of the abnormal feature and the abnormal pattern C feature. m and w respectively represent the total numbers of the abnormal feature and the abnormal pattern C feature.

[0038] Through quantitative analysis and comparison, the matching degree between the abnormal computer information status and various abnormal patterns is accurately identified, providing a strong basis for subsequent targeted processing. Using logistic regression for training can fully explore the potential relationship between abnormal features and abnormal patterns, improving the accuracy and reliability of recognition. At the same time, by calculating the absolute difference, the abnormal type of financial computer information with the highest matching degree is determined. The method is simple and intuitive, with strong operability.

[0039] Specifically, the specific steps of S5 include: according to the marked abnormal type of financial computer information, retrieving the typical feature information of this abnormal type of financial computer information in the database of the financial trading system, combining the typical feature information to form a typical feature set, and obtaining the typical confidence interval of this abnormal type of financial computer information in combination with the preset confidence level; based on real-time monitoring, obtaining the relevant feature information of this abnormal type of financial computer information, and then using the relevant feature information of this abnormal type of financial computer information to compare with the typical confidence interval of this abnormal type of financial computer information. When the relevant feature information of this abnormal type of financial computer information conforms to the typical confidence interval of this abnormal type of financial computer information, it is determined that this abnormal type of financial computer information exists, and the second verification is qualified, and the security approval is passed; when the relevant feature information of this abnormal type of financial computer information does not conform to the typical confidence interval of this abnormal type of financial computer information, it is determined that this abnormal type of financial computer information does not exist.

[0040] In this implementation, taking market volatility as an example, typical characteristic information includes, but is not limited to, trading price fluctuations, trading volume changes, market index movements, and macroeconomic indicator correlations. Specifically, trading price fluctuations indicate that the trading price of a financial product experiences significant increases or decreases, exceeding the normal fluctuation range. For example, stock prices rise or fall sharply in a short period, or foreign exchange rates experience drastic fluctuations. Trading volume changes indicate that the trading volume in the trading market significantly expands or shrinks, showing abnormalities compared to the same period in history. For instance, the trading volume of stocks on a certain trading day suddenly becomes several times that of usual, or the trading volume in the bond market continuously shrinks. Market index movements indicate that relevant market indices, such as the overall market index or industry indices in the stock market, experience significant fluctuations, reflecting the instability of the overall market or a specific industry. For example, if a certain industry index drops by more than a certain percentage in a short period, it may imply that the industry faces market volatility risks. Macroeconomic indicator correlations indicate abnormal correlations with changes in macroeconomic indicators. For example, changes in indicators such as interest rates and inflation rates have an impact on financial transactions that exceeds expectations. When interest rates rise, the decline in bond prices far exceeds the theoretical value.

[0041] Taking market volatility as an example, the steps for obtaining a typical confidence interval are as follows: Collect historical data related to market volatility over a past period from the database of the financial trading system, including various data of the above-mentioned typical characteristic information; Clean the collected data to remove outliers and missing values, and perform preprocessing operations such as standardization or normalization to ensure the quality and consistency of the data; Calculate statistics such as the mean and standard deviation of each typical characteristic information based on the preprocessed data; Preset a confidence level according to actual needs and risk preferences, such as the commonly used 95% or 99%; Calculate the confidence interval of each typical characteristic information according to the selected confidence level and the corresponding statistical distribution (such as the normal distribution). Taking the trading price as an example, assuming it follows a normal distribution, at a 95% confidence level, the mean is 0 and the standard deviation is 1. This means we need to find two points, and the area between these two points accounts for 95% of the total area. Since the normal distribution is symmetric, the distances of these two points from the mean are the same. Starting from the mean, the area within approximately 1.96 standard deviations extended to both the left and right sides is about 95%. Then the expression for the typical confidence interval is , represents the mean of the trading price, represents the standard deviation of the trading price.

[0042] By retrieving the typical feature information of abnormal types of financial computer information in the database and comparing it with the relevant feature information monitored in real time, it is possible to accurately determine whether there is a specific abnormal type of financial computer information, improve the accuracy of judging abnormal situations in financial transactions, and help detect potential risks in a timely manner; using a data-driven method to make judgments based on the typical feature set and confidence interval reduces the interference of human factors, makes the decision-making more scientific and objective, and enhances the reliability and stability of the information security management method.

[0043] Specifically, the specific steps of S6 include: presenting the generated secondary financial transaction application page to the user and providing "agree to authorize" and "reject to authorize" exchange buttons. When it is monitored that the user selects "reject to authorize", the security approval fails, a risk warning prompt is sent to the user, and the user is marked as a risk. When it is monitored that the user selects "agree to authorize", relevant user verification data is obtained. The relevant verification data includes but is not limited to the asset information of other financial institutions, the business transaction details of upstream and downstream enterprises, and the user's transaction flow. The relevant typical patterns are retrieved and verified for the relevant verification data respectively. When there is relevant verification data that does not conform to the relevant typical pattern, the third verification is marked as unqualified and the security approval fails. When all the relevant verification data conform to the corresponding relevant typical patterns, the third verification is marked as qualified and the security approval is passed.

[0044] In this implementation plan, the asset information of other financial institutions refers to the various asset statuses that the user has in other financial institutions, such as deposits, wealth management products, stocks, bonds, etc. The acquisition method is through user authorization, and the financial trading system exchanges data with other financial institutions to obtain it. The quantification method is: quantifying different types of assets according to the market value or book value. For example, deposits are calculated based on the actual amount, and stocks are calculated based on the current stock price and the number of shares held.

[0045] The business transaction details of upstream and downstream enterprises specifically refer to the transaction details between upstream and downstream enterprises that have business dealings with the user, including information such as transaction amount, transaction time, and traded goods or services. The acquisition method is to extract from the enterprise's business system or relevant database, provided that the financial trading system has the right to access this data. The quantification method is: using the transaction amount as the main quantification index, and at the same time, the transaction frequency, transaction time interval, etc. can also be quantified, such as represented by the number of transactions per month, the average number of days between each transaction, etc.

[0046] The user's transaction flow is all the financial transaction records of the user within a certain period, including information such as transaction amount, transaction time, and transaction counterparty. The acquisition method is to obtain from the transaction record database of the financial trading system itself. The quantification method is: based on the transaction amount and the number of transaction records, such as calculating the total transaction amount, average transaction amount, and change rate of the number of transaction records within a certain period.

[0047] The specific logical steps for retrieving and validating relevant typical patterns for relevant validation data are as follows: Analyze historical data and business experience to determine the typical patterns of various types of relevant validation data. For example, for the asset information of other financial institutions, the typical pattern is that the asset distribution conforms to a certain industry average level, or the amplitude of asset growth or decline within a certain period is within a reasonable range; perform preprocessing operations such as cleaning and transformation on the obtained relevant validation data to make it conform to the format and requirements of the typical pattern. For example, classify and summarize the asset information by different categories, and organize the transaction flow data according to the time series; extract key features from the preprocessed data, such as the total amount of assets, the proportion of various types of assets, the peak and trough values of the transaction flow, etc.; compare the extracted features with the features of the typical pattern, calculate the similarity or difference degree. Specifically, distance measurement methods such as Euclidean distance and Manhattan distance can be used to measure the difference between the actual data and the typical pattern; judge whether it conforms to the typical pattern according to the set threshold. If the difference degree is less than the threshold, it is considered to conform to the typical pattern, otherwise, it is considered not to conform.

[0048] Taking the asset information of other financial institutions as an example, an example of retrieving and validating relevant typical patterns is as follows: Assume that the typical pattern is that in the assets of other financial institutions of users in a certain industry, the proportion of deposits is about 50% - 70%, the proportion of wealth management products is about 20% - 30%, the proportion of equity assets such as stocks and bonds is about 10% - 20%, and the total amount of assets has increased or decreased by no more than 20% in the past year. First, obtain the asset information data of the user's other financial institutions. After preprocessing, obtain the actual proportion of various types of assets of the user and the change in the total amount of assets; then extract key features, such as the current deposit proportion is 60%, the proportion of wealth management products is 25%, the proportion of equity assets is 15%, and the total amount of assets has increased by 15% in the past year; compare these features with the typical pattern and calculate the difference degree between each feature and the corresponding range of the typical pattern. For example, the difference degree of the deposit proportion is 0, the difference degree of the proportion of wealth management products is 0, the difference degree of the proportion of equity assets is 0, and the difference degree of the growth of the total amount of assets is 0.25. Assume that the set comprehensive difference degree threshold is 0.3. Since the weighted average value of the difference degrees of each feature (assuming that the weights of each feature are the same and the weighted average difference degree is 0.0625) is less than the threshold, it is considered that the asset information of the user's other financial institutions conforms to the relevant typical pattern.

[0049] By obtaining more-dimensional relevant validation data of users and performing typical pattern retrieval and validation, the transaction security can be evaluated more comprehensively and the risk can be reduced; performing targeted validation on validation data from different sources helps to accurately judge whether there are abnormalities in the transaction and avoid misjudgment or missed judgment; providing a clear authorization selection interface allows users to clearly understand the consequences of the operation, and at the same time, risk mark users who refuse authorization to guide users to actively cooperate with security verification.

[0050] Please refer to Figure 2 , a computer information security management system based on big data, which applies the above-mentioned computer information security management method based on big data, and includes: a data acquisition module for real-time collecting computer storage data of financial transaction applications based on multiple data sources of a financial transaction system, where the computer storage data of financial transaction applications includes basic transaction information and information of both parties to the transaction; a risk identification module for using a risk prediction model to identify risks in the computer storage data of financial transaction applications, and then marking key transaction focus objects based on the risk identification results; a first verification module for performing multi-factor authentication on the key transaction focus objects, and then performing a first verification on the security of the key transaction focus objects based on the multi-factor authentication results, and identifying and marking abnormal computer information conditions; a retrieval module for extracting abnormal features for the marked abnormal computer information conditions, and then comparing and retrieving the abnormal features with various stored abnormal patterns to identify and mark the financial computer information abnormal type with the highest matching degree; a second verification module for obtaining relevant feature information of the marked financial computer information abnormal type, and then performing a second verification on the relevant feature information of the marked financial computer information abnormal type to determine whether there is such a financial computer information abnormal type; a third verification module for, when there is no such financial computer information abnormal type, displaying a secondary financial transaction application page to the user, obtaining the user's authorization for obtaining relevant verification data, and then obtaining relevant verification data from the corresponding data sources according to the authorization results, and then performing a third verification on the relevant verification data; an approval management module for determining whether to give a security approval based on the third verification results. If the security approval is passed, triggering a manual inspection requirement, obtaining the specific reasons for the abnormalities marked by the manual inspection, and creating an abnormal information label for the specific reasons for the abnormalities. If the security approval is not passed, sending a warning prompt to the user.

[0051] In summary, the present application has at least the following effects: By collecting the computer storage data of financial transaction applications in real time, it can ensure the instant monitoring of computer information during the financial transaction process and promptly detect potential computer information security risks; Using the risk prediction model for risk identification can mark in advance the transactions that may have risks, thereby effectively preventing the occurrence of fraud and illegal transactions; The multi-factor authentication increases the security of computer information during the transaction process and ensures the authenticity of the identities of both parties to the transaction through multiple verification means; Further refining and verifying the abnormal computer information conditions, by comparing abnormal features and abnormal patterns, improves the accuracy and efficiency of abnormal identification; For the abnormal types of financial computer information that are not recognized, further verification is carried out by obtaining user authorization and relevant verification data to ensure the accuracy and rationality of the decision-making; For the specific reasons for the abnormalities confirmed by manual inspection, abnormal information tags can be created to provide valuable references for future risk prediction and abnormal identification.

[0052] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0053] The present invention is described with reference to the flowcharts and structural diagrams of methods and systems according to the embodiments of the present invention. It should be understood that each process and module combination in the flowcharts and structural diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and structures Figure 1 one module or multiple modules.

[0054] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in Figure 1 one process or multiple processes and structures Figure 1 one module or multiple modules.

[0055] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the steps in the process Figure 1 a process or processes and architectures Figure 1 steps for specifying the functions specified in a module or modules.

[0056] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0057] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A computer information security management method based on big data, characterized in that: The following steps are involved: S1, collecting computer storage data of financial transaction applications in real time based on multiple data sources of the financial transaction system, wherein the computer storage data of the financial transaction applications includes basic transaction information and information of both parties to the transaction; S2, using the risk prediction model to identify the risks of the computer storage data of financial transaction applications, and then marking the key transaction objects based on the risk identification results; S3, performing multi-factor authentication on the key transaction object, and then performing a first verification on the security of the key transaction object based on the multi-factor authentication result, and identifying and marking abnormal computer information status; S4, extracting abnormal features for the marked abnormal computer information status, and then comparing and retrieving the abnormal features with various stored abnormal patterns, identifying and marking the abnormal type of financial computer information with the highest matching degree; S5, for the marked financial computer information anomaly type, obtaining relevant characteristic information of the financial computer information anomaly type, and then performing a second verification on the relevant characteristic information of the financial computer information anomaly type to determine whether the financial computer information anomaly type exists; S6, when the financial computer information abnormality type does not exist, display the secondary financial transaction application page to the user, obtain the user's authorization to obtain relevant verification data, and then obtain the relevant verification data from the corresponding data source according to the authorization result, and then perform a third verification on the relevant verification data; S7, based on the third verification result, determine whether to grant security approval. If the security approval is passed, trigger the manual inspection requirement, obtain the specific cause of the exception marked by the manual inspection, create an exception information label for the specific cause of the exception, and if the security approval is not passed, send a warning prompt to the user.

2. A computer information security management method based on big data according to claim 1, characterized in that: The specific steps of S2 include: inputting the computer storage data of the real-time monitored financial transaction applications into the risk prediction model, outputting the risk probability value, and then comparing the risk probability value with the risk probability threshold. When the financial transaction application has a risk probability value greater than or equal to the risk probability threshold, it is marked as a key transaction focus object.

3. A computer information security management method based on big data according to claim 1, characterized in that: The specific analysis of the first verification is: using the convolutional neural network and support vector machine outputs to obtain the authentication results of each multi-factor authentication, and then summing the authentication results of each multi-factor authentication to obtain a first verification score, comparing the first verification score with a first verification score threshold, and when the first verification score is greater than or equal to the first verification score threshold, marking it as an abnormal computer information status.

4. The computer information security management method based on big data according to claim 1 is characterized in that: The specific steps of S4 include: obtaining the abnormal proportion coefficient of the marked abnormal computer information status and the reference proportion coefficient of each abnormal pattern, and then taking the absolute difference between the abnormal proportion coefficient and the reference proportion coefficient of each abnormal pattern, and marking the one with the smallest absolute difference as the financial computer information abnormality type with the highest matching degree.

5. A computer information security management method based on big data according to claim 4, characterized in that: The specific analysis of the abnormal proportion coefficient of the abnormal computer information status and the reference proportion coefficient of each abnormal mode obtained by the above method is as follows: quantifying the abnormal features, and then training the abnormal features based on logistic regression, and outputting the abnormal proportion coefficient; The stored features of various abnormal patterns are extracted, and the features of various abnormal patterns are trained and inputted respectively based on logistic regression, and the reference proportion coefficients of various abnormal patterns are outputted.

6. A computer information security management method based on big data according to claim 1, characterized in that: S5 specifically includes: according to the marked financial computer information anomaly type, retrieving typical characteristic information of the financial computer information anomaly type, and then obtaining a typical confidence interval of the financial computer information anomaly type; The typical confidence interval is compared with the relevant characteristic information of the financial computer information anomaly type. When the relevant characteristic information of the financial computer information anomaly type meets the typical confidence interval of the financial computer information anomaly type, it is determined that the financial computer information anomaly type exists, the second verification is qualified, and the security approval is passed. Otherwise, it is determined that the financial computer information anomaly type does not exist.

7. A computer information security management method based on big data according to claim 1, characterized in that: The specific steps of S6 include: When the monitored user refuses authorization, the security approval fails, a risk warning prompt is sent to the user, and the user is marked as a risk; When the monitored user agrees to the authorization, the user's relevant verification data is obtained, and the relevant verification data is retrieved and verified according to the relevant typical patterns. When there is relevant verification data that does not conform to the relevant typical pattern, the third verification is marked as unqualified, otherwise it is given a security approval.

8. A computer information security management system based on big data, applying a computer information security management method based on big data as claimed in any one of claims 1 to 7, characterized in that: include: A data acquisition module, used for collecting computer-stored data of financial transaction applications in real time based on multiple data sources of the financial transaction system, wherein the computer-stored data of financial transaction applications includes basic transaction information and information of both parties to the transaction; A risk identification module is used to identify risks in the computer storage data of financial transaction applications using a risk prediction model, and then mark key transaction focus objects based on the risk identification results; A first verification module, used to perform multi-factor authentication on the key transaction object, and then perform a first verification on the security of the key transaction object based on the multi-factor authentication result, and identify and mark abnormal computer information conditions; A retrieval module is used to extract abnormal features from the marked abnormal computer information status, and then compare and retrieve the abnormal features with various stored abnormal patterns to identify and mark the abnormal type of financial computer information with the highest matching degree; A second verification module is used to obtain relevant characteristic information of the marked financial computer information anomaly type, and then perform a second verification on the relevant characteristic information of the financial computer information anomaly type to determine whether the financial computer information anomaly type exists; A third verification module is used to display a secondary financial transaction application page to the user when the financial computer information abnormality type does not exist, obtain the user's authorization to obtain relevant verification data, and then obtain the relevant verification data from the corresponding data source according to the authorization result, and then perform a third verification on the relevant verification data; The approval management module is used to determine whether to grant security approval based on the third verification result. If the security approval is passed, the manual inspection requirement is triggered, the specific cause of the exception marked by the manual inspection is obtained, and an exception information label is created for the specific cause of the exception. If the security approval is not passed, a warning prompt is sent to the user.

Citation Information

Patent Citations

  • Digital wallet management system and method

    CN117114677A

  • Financial transaction risk control method based on financial sequence generation technology

    CN118333763A

  • Financial transaction anomaly detection and risk assessment method and device based on artificial intelligence

    CN119693111A

  • Financial data security management system and method thereof

    CN119848882A

  • Transaction risk detection method and apparatus

    US20170300919A1

Cited By

  • Digital economic risk identification system and method based on artificial intelligence

    CN121190204A