Data governance risk early warning method based on big data mining

By constructing a three-dimensional hypernetwork topology and composite energy field model, the risk transmission path is identified and hierarchical warning is triggered dynamically, the complex challenges in meteorological and ocean data governance are solved, and the global risk perception and dynamic warning of the meteorological and ocean data governance system is realized.

CN120066862AActive Publication Date: 2025-05-30无锡九方科技有限公司

Patent Information

Application Number
CN202510541082.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-05-30
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively solve the complex challenges such as multi-data fusion, dynamic permission management, and geographical distributed backup in meteorological and marine data governance, especially the problem of failure of backup strategies in extreme weather.

Method used

The data governance risk warning method based on big data mining is adopted, and the global perception, dynamic prediction and closed-loop treatment of risks are achieved by building a three-dimensional coupled model. The specific steps include obtaining the metadata change log of the data governance platform, the multi-level dependency map of the management system and the real-time access behavior data of the system audit log, performing three-dimensional network fusion modeling, generating a three-dimensional hypernetwork topology, building a composite energy field model, generating an energy gradient field, monitoring the curvature changes of the energy surface in real time, identifying the critical area of ​​phase change, tracking the risk conduction path, and dynamically triggering a hierarchical early warning based on the number of key infrastructures covered by the conduction path, relative value of conduction intensity and regional expansion rate.

Benefits of technology

The global risk perception and dynamic warning of the meteorological and marine data governance system has been realized, the accuracy and response speed of risk warning have been improved, and the effectiveness of data backup strategies in extreme weather has been ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066862A_ABST
    Figure CN120066862A_ABST
Patent Text Reader

Abstract

The invention relates to the field of data governance, and discloses a data governance risk early warning method based on big data mining, which constructs a three-dimensional coupling model through a big data mining technology, and realizes global perception, dynamic prediction and closed-loop disposal of risks. The big data mining-based data governance risk early warning method comprises the steps of obtaining a three-dimensional super-network topological structure, obtaining a phase change critical region coordinate set, generating a cross-layer risk conduction path map, dynamically triggering graded early warning and outputting a disposal instruction set. According to the three-dimensional super-network modeling technology, the meteorological equipment topology, the data product dependency chain and the cross-border access behavior are fused, the composite energy field model with meteorological ocean domain characteristics is constructed, the cross-regional data chain fracture risk can be warned in advance, and the data backup failure probability during the typhoon passing period is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data governance, and particularly to a data governance risk early warning method based on big data mining. Background Art

[0002] With the acceleration of digital transformation, data governance faces unprecedented complex challenges.

[0003] In the field of meteorology and oceanography, data governance faces several core challenges: the pressure of multi-data fusion, as the global meteorological observation network generates more than 500TB of data every day, covering more than 20 data formats such as satellite remote sensing, buoy sensing, and numerical model output; the complexity of dynamic permission management, as cross-departmental collaboration involves more than 300 sub-permission groups in 6 categories such as military, civil aviation, and scientific research, and the need to meet the instantaneous rise and fall requirements of permissions in special scenarios such as real-time typhoon warnings; the particularity of geographically distributed backups, which requires an accurate balance between the timeliness and integrity of data synchronization between coastal disaster-prone areas and inland backup centers.

[0004] Currently, the single-dimensional monitoring system cannot adapt to the spatio-temporal correlation characteristics of meteorological and oceanographic data. There is a lack of assessment means for the physical-logical coupling risks between polar scientific expedition data and equatorial observation stations. There is insufficient intelligent association between permission changes and dynamic events such as typhoon paths and marine disasters. There is a lack of a blocking mechanism for the abnormal cross-border flow of important meteorological data during red alerts. The backup system is decoupled from real-time meteorological elements, and a dynamic mapping model of "typhoon eye area - data center disaster tolerance level" has not been established, resulting in the failure of backup strategies under extreme weather conditions.

[0005] Therefore, we propose a data governance risk early warning method based on big data mining to solve the above problems. Summary of the Invention

[0006] The present invention provides a data governance risk early warning method based on big data mining, which constructs a three-dimensional coupling model through big data mining technology to achieve global perception, dynamic prediction, and closed-loop disposal of risks.

[0007] The first aspect of the present invention provides a data governance risk warning method based on big data mining. The data governance risk warning method based on big data mining includes: obtaining the metadata change log of the data governance platform, the multi-level dependency relationship graph of the management system, and the real-time access behavior data of the system audit log, and performing three-dimensional network fusion modeling: mapping the physical connection topology between storage devices at the physical layer to generate a node load fluctuation matrix; parsing the data relationship chain at the logical layer to construct a dependency weight matrix; extracting the spatio-temporal characteristics of user access at the behavior layer to form an association frequency matrix; coupling the three-layer network through a dynamic weight adjustment mechanism, and outputting a three-dimensional hypernetwork topology structure marked with a timestamp; based on the three-dimensional hypernetwork topology structure, obtaining the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index, constructing a composite energy field model, generating an energy gradient field, monitoring the change of the energy surface curvature in real time, and obtaining a set of phase transition critical region coordinates; according to the set of phase transition critical region coordinates, tracing the potential energy decay path in the reverse direction of the energy gradient, combining the physical layer topology structure and the logical layer dependency relationship, and generating a cross-layer risk conduction path graph; performing a spatial convolution operation on the set of phase transition critical region coordinates and the cross-layer risk conduction path graph, and dynamically triggering hierarchical warnings according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and outputting a disposal instruction set.

[0008] Optionally, in the first implementation manner of the first aspect of the present invention, it includes: parsing the physical connection topology between storage nodes according to the data center hardware topology database and the real-time device load monitoring data stream, constructing an initial adjacency matrix, dynamically adjusting the connection weight based on the load fluctuation variance, generating a node load fluctuation matrix marked with a time window, and obtaining a physical layer dynamic adjacency matrix; parsing the multi-level data management system dependency chain according to the data management system relationship graph and the metadata change time sequence record, constructing an initial directed graph, calculating the dependency intensity according to the metadata change frequency, generating a dependency weight matrix, and obtaining a logical layer dependency weight matrix; counting the spatio-temporal distribution characteristics of access behavior within a unit time according to the user access audit log and the geospatial location database, constructing an association frequency matrix reflecting the abnormality degree of the access pattern, and obtaining a behavior layer association frequency matrix; establishing a cross-layer connection rule according to the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the behavior layer association frequency matrix, implementing dynamic weight adjustment, and embedding a timestamp marking mechanism to obtain a three-dimensional hypernetwork topology structure marked with a timestamp.

[0009] Optionally, in the second implementation manner of the first aspect of the present invention, it includes: parsing the dynamic change sequence of the connection weights between storage nodes according to the physical layer dynamic adjacency matrix in the three-dimensional hypernetwork topology, calculating the node load fluctuation variance and the load correlation of adjacent nodes, generating a scoring matrix reflecting the load balance state between devices, and obtaining the physical layer load balance degree matrix; tracing the complete hierarchical structure of the data relationship chain according to the logical layer dependency weight matrix in the three-dimensional hypernetwork topology, detecting the coverage rate of metadata change records in the dependency path, calculating the integrity decay index of the management system chain, and obtaining the logical layer management system integrity scoring matrix; comparing the spatio-temporal distribution differences between the real-time access pattern and the historical benchmark according to the behavior layer association frequency matrix in the three-dimensional hypernetwork topology, detecting the access aggregation phenomenon in unconventional time periods and unconventional geographical regions, quantifying the deviation degree of abnormal access behavior, and obtaining the behavior layer abnormal access index vector; establishing an energy value calculation rule according to the physical layer load balance degree matrix, the logical layer management system integrity scoring matrix, and the behavior layer abnormal access index vector, and using the diffusion mapping algorithm to obtain a three-dimensional composite energy field model; calculating the Gaussian curvature distribution of the energy surface in real time according to the three-dimensional composite energy field model and the historical normal state energy field database, and comparing the current curvature change acceleration with the historical baseline statistical characteristics to obtain the coordinate set of the phase transition critical region.

[0010] Optionally, in the third implementation manner of the first aspect of the present invention, it includes: starting from the center point of the phase transition critical region, tracing hop by hop along the negative direction of the energy gradient according to the coordinate set of the phase transition critical region and the gradient direction vector data in the three-dimensional composite energy field model, and combining the physical layer topology connection rules to constrain the path search range to obtain a preliminary conduction path sequence; detecting the connection points that simultaneously involve physical device nodes and logical data entities in the path according to the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the preliminary conduction path sequence in the three-dimensional hypernetwork topology, and verifying whether the cross-layer connection conforms to the preset mapping rule library to obtain a cross-layer transition node list; comparing the topological consistency between the current path and the historical normal path according to the cross-layer transition node list and the historical normal conduction path database, detecting abnormal conduction characteristics, and obtaining a verified risk conduction path; marking the cross-layer attributes of the path nodes according to the verified risk conduction path and the timestamp version of the three-dimensional hypernetwork topology, and calculating the conduction intensity index to obtain a cross-layer risk conduction path map.

[0011] Optionally, in the fourth implementation manner of the first aspect of the present invention, it includes: mapping the phase transition region into a spatial risk heat map according to the phase transition critical region coordinate set, the cross-layer risk conduction path map, and the list of critical infrastructure nodes, generating a risk propagation vector field along the conduction path, performing a spatial convolution operation, and generating a risk superposition map; extracting the current conduction intensity value according to the risk superposition map and the historical peak database, calculating the percentage relative to the historical peak, monitoring the daily growth rate of the influence radius of the phase transition region, and counting the number of critical infrastructure nodes covered by the conduction path to obtain a set of dynamic threshold parameters; obtaining a set of hierarchical warning instruction codes according to the set of dynamic threshold parameters and the pre-set warning rule library of the system; according to the set of hierarchical warning instruction codes, the node coordinate data in the three-dimensional hypernetwork topology structure, and the data governance operation rule library, matching the disposal strategy according to the warning level, converting the strategy into a topological coordinate operation instruction, and obtaining a set of topological coordinate disposal instructions; according to the set of topological coordinate disposal instructions, the data isolation system API interface, and the traffic scheduling device control protocol, distributing the instructions to the target system through the standard protocol format, and collecting the instruction execution status code and the effect index in real time to obtain the instruction execution feedback log.

[0012] Optionally, in the fifth implementation manner of the first aspect of the present invention, it further includes: collecting in real time the metadata status, the change of the management system relationship, and the access behavior data after the instruction execution, and feeding them back to the three-dimensional hypernetwork modeling module for dynamic update of the topology structure to realize the self-optimizing control of the warning system.

[0013] The second aspect of the present invention provides a data governance risk early warning device based on big data mining. The data governance risk early warning device based on big data mining includes: an acquisition module, configured to acquire real-time access behavior data of metadata change logs of a data governance platform, a multi-level dependency relationship graph of a management system, and system audit logs, and perform three-dimensional network fusion modeling: mapping the physical connection topology between storage devices at the physical layer to generate a node load fluctuation matrix; parsing the data relationship chain at the logical layer to construct a dependency weight matrix; extracting spatio-temporal features of user access at the behavior layer to form an association frequency matrix; coupling the three-layer network through a dynamic weight adjustment mechanism, and outputting a three-dimensional hypernetwork topology structure marked with a timestamp; a processing module, configured to obtain the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index based on the three-dimensional hypernetwork topology structure, construct a composite energy field model, generate an energy gradient field, and monitor the change of the energy surface curvature in real time to obtain a set of coordinates of the phase transition critical region; a setting module, configured to trace the potential energy decay path along the reverse direction of the energy gradient according to the set of coordinates of the phase transition critical region, and combine the physical layer topology structure and the logical layer dependency relationship to generate a cross-layer risk conduction path graph; an allocation module, configured to perform a spatial convolution operation on the set of coordinates of the phase transition critical region and the cross-layer risk conduction path graph, and dynamically trigger a hierarchical early warning according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and output a set of disposal instructions.

[0014] The third aspect of the present invention provides a data governance risk early warning device based on big data mining, including: a memory and at least one processor, wherein instructions are stored in the memory; the at least one processor calls the instructions in the memory so that the data governance risk early warning device based on big data mining executes the above-mentioned data governance risk early warning method based on big data mining.

[0015] The fourth aspect of the present invention provides a computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium, and when the instructions are run on a computer, the computer is made to execute the above-mentioned data governance risk early warning method based on big data mining.

[0016] In the technical solution provided by the present invention, the beneficial effects are as follows: Integrate the physical layer device topology, the logical layer blood relationship, and the behavior layer access mode into a unified modeling framework, and realize the coupling of the three-layer network through a dynamic weight adjustment mechanism, breaking the traditional single-dimensional analysis paradigm and solving the problem of fragmented risk perception; Introduce the concept of physical energy field, quantify device load, blood relationship integrity, and access abnormality as energy distribution, and monitor the risk phase transition critical point in real time through Gaussian curvature; Combining the gradient tracking algorithm with the topological constraint rules, realize the visualization of the conduction path of risks from the physical layer to the logical layer, and accurately locate the attack paths of critical infrastructure; Perform a spatial convolution operation on the risk superposition map and the historical peak database to dynamically generate hierarchical early warning instructions, support millisecond-level decision-making responses, automatically match the topological coordinate operation instructions, and shorten the system response time from the minute level of the traditional architecture to the second level. Description of the Drawings

[0017] Figure 1 It is a schematic diagram of an embodiment of the data governance risk early warning method based on big data mining in the embodiment of the present invention; Figure 2 It is a schematic diagram of another embodiment of the data governance risk early warning method based on big data mining in the embodiment of the present invention; Figure 3 It is a schematic diagram of an embodiment of the data governance risk early warning device based on big data mining in the embodiment of the present invention; Figure 4 It is a schematic diagram of an embodiment of the data governance risk early warning device based on big data mining in the embodiment of the present invention. Detailed Embodiments

[0018] The embodiment of the present invention provides a data governance risk early warning method based on big data mining. By constructing a three-dimensional coupling model through big data mining technology, global perception, dynamic prediction and closed-loop disposal of risks are realized. The terms "first", "second", "third", "fourth", etc. (if any) in the specification, claims and drawings of the present invention are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order different from that shown or described herein. In addition, the terms "including" or "having" and any deformation thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0019] For ease of understanding, the specific process of the embodiment of the present invention is described below. Please refer to Figure 1 An embodiment of the data governance risk early warning method based on big data mining in the embodiment of the present invention includes: 101. Obtain the metadata change log of the data governance platform, the multi-level dependency relationship map of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling: The physical layer maps the physical connection topology between storage devices to generate a node load fluctuation matrix; The logical layer analyzes the data relationship chain to construct a dependency weight matrix; The behavior layer extracts the spatio-temporal characteristics of user access to form an association frequency matrix; The three-layer network is coupled through a dynamic weight adjustment mechanism, and a three-dimensional hypernetwork topology structure with timestamp markings is output; It can be understood that the execution subject of the present invention can be a data governance risk warning device based on big data mining, or it can also be a terminal or a server. Specifically, it is not limited here. In the embodiments of the present invention, the server is used as the execution subject for illustration.

[0020] It should be noted that in the scenario of meteorological and ocean data governance, the three-dimensional network fusion modeling can be specifically implemented as follows: Data collection and preprocessing, metadata change log: Extract the metadata change records of the past 30 days from the data governance platform, including data table structure changes (field addition and deletion, permission adjustment), backup policy updates (backup period adjusted from daily to hourly), etc., to form a time series log. Example: 2025-03-15 14:00 | Table A permission change | Operator: admin | Affected backup policy ID: B001.

[0021] Multi-level dependency relationship graph: Analyze the dependency chain in the meteorological and ocean data management system: The storage of data table B depends on physical device nodes N1 and N3; The permission configuration table C is associated with the access policies of user groups G1 and G2; The backup task D depends on the availability of storage device N2.

[0022] Real-time access behavior data: Collect user access records (user U1 frequently accesses table A from 08:00 to 12:00, and the IP address location is abnormal) and API call records (service S1 triggers the backup interface 300 times per hour) in the system audit log.

[0023] Hierarchical modeling and matrix generation, physical layer topology and node load fluctuation matrix: Device topology mapping: Based on the physical connection relationship of storage devices (N1 - N5) (N1 and N2 are directly connected by optical fiber), construct a 5×5 adjacency matrix, and mark the bandwidth and delay parameters between devices.

[0024] Load fluctuation calculation: Collect the CPU, memory, and storage usage rates of devices every 5 minutes to generate a load fluctuation matrix: N1: [0.72, 0.68, 0.75,..., 0.81] / / 24-hour load sequence N2: [0.35, 0.41, 0.38, ..., 0.50] Logical layer dependency weight matrix: Data relationship chain analysis: Modeling the dependencies of permissions, backups, and storage through a graph database (Neo4j). The weight assignment rules are as follows: Master data dependency: The dependency weight between Table A and backup strategy B001 is 0.8 (strong dependency); Cross-system dependency: The weight between permission configuration table C and user group G1 is 0.6 (medium dependency); Redundant dependency: The mirror backup weight between devices N1 and N3 is 0.3 (weak dependency).

[0025] Matrix example: Device N1 → Table A: 0.9 | Table A → Backup B001: 0.8 | User G1 → Table C: 0.6; Behavior layer association frequency matrix, spatio-temporal feature extraction: Statistical spatio-temporal distribution of user accesses (the frequency of user U1 accessing Table A from 08:00 - 12:00 is 50 times per hour), combined with IP location (off-site login accounts for 30%), to generate a spatio-temporal association matrix: User U1 → Table A: Temporal density = 0.85 | Spatial anomaly index = 0.72; Service S1 → Backup interface: Call frequency = 300 times per hour; Normalization processing: Normalize indicators such as frequency and anomaly index to 0 - 1 values to form a 5×5 association matrix.

[0026] Dynamic weight coupling and hypernetwork generation, weight assignment mechanism: Dynamically adjust the weights of the three layers according to real-time risk scenarios (initial values: physical layer 40%, logical layer 35%, behavior layer 25%). When a sudden increase in the load of device N1 is detected (fluctuation > 0.8), the weight of the physical layer is increased to 50%.

[0027] Hypernetwork construction: Align the three-layer matrices according to the timestamp and couple them into a weighted hyperedge network. The hypernetwork nodes at a certain moment include: Physical nodes: N1 (load 0.81), N2 (load 0.50); Logical nodes: Table A (dependency weight 0.8), Backup B001; Behavior nodes: User U1 (anomaly index 0.72).

[0028] Output structure: Generate a three-dimensional hypernetwork topology in JSON format, mark the timestamp (2025-03-15T14:00:00Z), including node attributes, edge weights, and hierarchical mapping relationships.

[0029] 102. Based on the three-dimensional hypernetwork topology, obtain the load balance degree of physical layer devices, the integrity score of the logical layer management system, and the abnormal access index of the behavior layer. Construct a composite energy field model, use an improved diffusion mapping algorithm to generate an energy gradient field, and monitor the change of the energy surface curvature in real time. When the curvature acceleration in a local area is detected to exceed 3 times the standard deviation of the historical baseline, mark it as a phase transition critical area and output the coordinate set to obtain the coordinate set of the phase transition critical area; It should be noted that in the scenario of meteorological and oceanographic data governance, the implementation of step 102 can be combined with the following specific data and modeling processes: Input of three-dimensional hypernetwork topology: Suppose the three-dimensional hypernetwork topology of a certain meteorological and oceanographic data governance platform includes the following structure (timestamp: 2025-03-15T14:00:00Z): Physical layer: 5 storage devices (N1 - N5), directly connected by optical fibers between devices. The standard deviation of the CPU utilization rate of N1 in the load fluctuation matrix is 0.15 (baseline 0.1), and the standard deviation of N2 - N5 is ≤0.08.

[0030] Logical layer: The weight matrix shows that the weight of data table A and backup strategy B001 is 0.9, the weight of permission configuration table C and user group G1 is 0.7, and the dependence weight of backup task D on device N2 is 0.4.

[0031] Behavior layer: The access frequency of user U1 to table A from 08:00 to 12:00 is 200 times per hour (baseline 50 times), the abnormal rate of IP location is 30% (baseline 5%), and the spatio-temporal abnormal index of U1→table A in the associated frequency matrix is 0.68.

[0032] Calculation of hierarchical indicators, load balance degree of physical layer devices, calculation logic: Based on the node load fluctuation matrix, calculate the difference rate of load standard deviation between devices.

[0033] Example data: The load fluctuation standard deviation of N1 is 0.15 (historical baseline 0.1), exceeding the baseline by 50%; the average standard deviation of N2 - N5 is 0.06, and the balance degree scoring formula is: (Full score 1) Integrity score of the logical layer management system, evaluation dimensions: data backup integrity (weight 40%), permission consistency (weight 30%), redundancy degree of dependence chain (weight 30%).

[0034] Example data: Backup completion rate 95% (completion rate of table A backup is 100%, 5% of table C is missing due to device N3 failure); permission configuration consistency 98% (there are 2% redundant permissions in user group G2); Scoring result: 0.95×0.4 + 0.98×0.3 + 0.97×0.3 = 93 points (full score 100).

[0035] Behavior layer abnormal access index. Algorithm: Based on the association frequency matrix, combined with spatio-temporal features (frequency surge, off-site login), construct a Gaussian kernel density model to calculate the Z value deviating from the normal distribution.

[0036] Example data: The Z value of user U1 is 3.2 (threshold 2.5), and the abnormal index is 3.2 / 5 = 0.64 (normalized to 0 - 1).

[0037] Composite energy field modeling, energy field construction, parameter fusion: Map the hierarchical metrics to the three-dimensional coordinates of the energy field: X-axis: Physical layer balance degree (0.85) → Device load potential energy; Y-axis: Logical layer integrity (0.93) → System structure potential energy; Z-axis: Behavior layer abnormal index (0.64) → Access behavior potential energy.

[0038] Improved diffusion mapping algorithm: Introduce a time decay factor (current time weight 0.7, historical data weight 0.3) to generate an energy gradient field.

[0039] Example energy surface equation:

[0040] Curvature acceleration detection, dynamic baseline: The average value of the curvature acceleration of the energy surface in the past 30 days is 0.12, and the standard deviation is 0.03.

[0041] Abnormal determination: When the curvature acceleration of a certain area reaches 0.12 + 3×0.03 = 0.21, a mark is triggered.

[0042] Example result: The curvature acceleration of the associated area between device N1 and user U1 is 0.25, marked as a phase transition critical area, and the output coordinate set is (N1, Table A, U1).

[0043] 103. According to the coordinate set of the phase transition critical area, trace the potential energy decay path in the reverse direction of the energy gradient, combine the physical layer topology structure and the logical layer dependency relationship, identify the conduction characteristics across devices - data - applications, and generate a cross-layer risk conduction path map including a sequence of transition nodes and conduction intensity indicators; It should be noted that in the scenario of meteorological and oceanographic data governance, the coordinate set of the phase transition critical area: The coordinate set marked as a high-risk area is (N1, Table A, U1), corresponding to the physical layer storage device N1 (load fluctuation standard deviation 0.15), the logical layer data table A (depending on backup strategy B001, weight 0.9), and the behavior layer user U1 (abnormal access frequency 200 times / hour, IP abnormality rate 30%).

[0044] Energy gradient field data: In the composite energy field model, the potential energy attenuation direction of device N1 points to the logic layer data table A (the opposite direction of the energy gradient is N1→table A→backup B001).

[0045] Potential energy attenuation path tracing, physical layer topology analysis, device connection relationship: Device N1 is directly connected to N3 via optical fiber (bandwidth 10 Gbps), and N3 is the primary storage node of backup task D (dependency weight 0.8).

[0046] Load transmission characteristics: N1's high load fluctuation (standard deviation 0.15) is transmitted to N3 through the physical link, causing N3's CPU utilization to increase from the baseline 40% to 65%.

[0047] Logical layer dependency chain analysis, data relationship chain: table A → backup B001 → backup task D → service S1 (weather warning API), dependency weights are 0.9, 0.8, and 0.7 respectively. Conduction strength calculation: The conduction strength along the path table A → backup B001 → backup task D is the weight product (0.9×0.8×0.7=0.504), indicating the amplification effect of logical dependency on risk.

[0048] Abnormal conduction at the behavioral layer, user access path: User U1's abnormal access (200 times / hour) triggers frequent changes in the metadata of table A, resulting in a surge in the log write volume of backup B001 (the average daily log volume increased from 1 GB to 5 GB). Temporal and spatial correlation conduction: U1's abnormal IP (territorial abnormality rate 30%) overlaps with the geographical location of the storage device N3 of backup task D, forming a cross-layer temporal and spatial correlation (geographical conduction intensity 0.45).

[0049] Generation of cross-layer risk transmission path, transition node sequence: the tracing path is user U1→table A→device N1→backup B001→device N3→service S1, and the transmission strength indicators between nodes are as follows: U1→Table A: Behavior layer abnormality index (0.68) × access frequency weight (0.6) = 0.408; Table A→N1: Logical dependency weight (0.9) × physical load contribution (0.15 / 0.1=1.5) = 1.35; N1→Backup B001: Equipment load conduction (N1 load fluctuation 0.15 × dependency weight 0.8) = 0.12; Backup B001→N3: backup task dependency weight (0.8) × device N3 load growth rate (25%) = 0.2; N3 → Service S1: Service response delay (increased from 50 ms to 120 ms) × weight (0.7) = 0.49; Conduction Path Map: Integrate the above indicators to generate a cross-layer path map, and mark the key conduction nodes (N1, backup B001) and the intensity threshold (>0.3 is a high-risk link).

[0050] 104. Perform a spatial convolution operation on the set of coordinates of the phase transition critical region and the cross-layer risk conduction path map. According to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, dynamically trigger hierarchical warnings: Generate a red warning instruction when the path covers ≥3 critical nodes; generate an orange warning instruction when the conduction intensity > 80% of the historical peak; generate a yellow warning instruction when the daily growth rate of the influence radius > 200%; output a set of disposal instructions with topological coordinates to the data isolation system and the traffic scheduling device; It should be noted that in the scenario of meteorological and ocean data governance, the set of coordinates of the phase transition critical region: The set of coordinates marked as high-risk regions is (N1, Table A, U1), corresponding to the physical layer storage device N1 (load fluctuation standard deviation 0.15), the logical layer data table A (depending on the backup strategy B001, weight 0.9), and the behavioral layer user U1 (abnormal access frequency 200 times / hour, IP abnormality rate 30%).

[0051] Cross-layer Risk Conduction Path Map: The path is User U1 → Table A → Device N1 → Backup B001 → Device N3 → Service S1. The conduction intensity indicators include: U1 → Table A: 0.408 (behavioral layer abnormality index × access weight); Table A → N1: 1.35 (logical dependence × physical load contribution degree); N1 → Backup B001: 0.12 (load fluctuation × dependence weight); Backup B001 → Device N3: 0.2 (dependence weight × load growth rate 25%); Device N3 → Service S1: 0.49 (delay growth × weight).

[0052] Spatial Convolution Operation and Parameter Calculation, Spatial Convolution Kernel Design, Three-dimensional Convolution Kernel: Based on the three-dimensional topological structure of the device, data, and behavioral layers, design a 5×5×5 convolution kernel, and the weight assignment rule: Weight of the physical layer device node: 0.4 (load fluctuation of device N1 is 0.15); Weight of the logical layer data dependence: 0.3 (weight of backup B001 is 0.8); Weight of the behavioral layer abnormality index: 0.3 (abnormality index of user U1 is 0.68).

[0053] Convolution Operation: Superimpose the coordinates of the phase transition region (N1, Table A, U1) on the conduction path map and calculate the characteristic values of the overlapping region.

[0054] Example output: After convolution, the number of key nodes covered by the conduction path is 4 (N1, Table A, Backup B001, Device N3), the relative conduction intensity value is 0.504 (product of logical dependency chains), and the daily growth rate of the influence radius is 220% (the load of Device N3 increases from 40% to 65%).

[0055] Hierarchical warning trigger conditions: Red warning (covering ≥ 3 key nodes): The current path covers 4 key nodes (N1, Table A, Backup B001, Device N3), triggering a red warning.

[0056] Orange warning (conduction intensity > 80% of the historical peak): The historical peak conduction intensity is 0.6 (baseline of the typhoon warning model), and the current value is 0.504 (84% of the peak), triggering an orange warning.

[0057] Yellow warning (daily growth rate of the influence radius > 200%): The daily growth rate of the influence radius of the load of Device N3 is 220%, triggering a yellow warning.

[0058] Disposal instruction generation and execution, topological coordinate mapping: Map the warning area to physical layer devices (N1, N3), logical layer data (Table A, Backup B001), and behavioral layer users (U1).

[0059] Instruction set example: Data isolation system: Cut off User U1's access permission to Table A and freeze the metadata change of Backup B001 (to prevent the spread of abnormal backups).

[0060] Traffic scheduling device: Shunt the load of Device N1 to N2 (standard deviation of load fluctuation is 0.08), and limit the API call frequency of Service S1 to 100 times per minute.

[0061] Backup strategy adjustment: Temporarily switch the dependency of Backup B001 from Device N3 to N5 (standard deviation of load is 0.06), and start the incremental backup mode (to reduce the amount of log writing).

[0062] In the embodiments of the present invention, data in three dimensions of the physical layer, the logical layer, and the behavior layer are fused and modeled to form a comprehensive three-dimensional hypernetwork topology structure; a composite energy field model based on the three-dimensional hypernetwork topology structure is proposed, and an improved diffusion mapping algorithm is used to generate an energy gradient field to monitor the change of the energy surface curvature in real time; not only the risk areas are identified, but also the conduction paths of risks among the physical layer, the logical layer, and the behavior layer are further traced, and a cross-layer risk conduction path map is generated; according to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, a hierarchical early warning mechanism is dynamically triggered. Through the three-dimensional network fusion modeling and the composite energy field model, the state of the data governance system can be more comprehensively reflected, and the accuracy of risk early warning can be improved; by monitoring the change of the energy surface curvature in real time and tracing the cross-layer risk conduction path, potential security risks can be discovered and disposed of in time, and the security of the system can be enhanced; through the hierarchical early warning mechanism and the disposal instruction set, the resource allocation can be dynamically adjusted according to the actual situation, the system performance can be optimized, and the resource utilization rate can be improved; this method provides comprehensive means for risk monitoring and early warning, enabling managers to understand the system state in time, quickly respond to risk events, and improve the management efficiency. In summary, through the innovative three-dimensional network fusion modeling, composite energy field model, cross-layer risk conduction path map, and hierarchical early warning mechanism, this technology provides a brand-new solution for the monitoring and early warning of data governance risks.

[0063] Please refer to Figure 2 , another embodiment of the data governance risk early warning method based on big data mining in the embodiments of the present invention includes: 201. Obtain the metadata change log of the data governance platform, the multi-level dependency relationship map of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling: map the physical connection topology between storage devices in the physical layer to generate a node load fluctuation matrix; analyze the data relationship chain in the logical layer to construct a dependency weight matrix; extract the spatio-temporal characteristics of user access in the behavior layer to form an association frequency matrix; couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hypernetwork topology structure with timestamp marks; Specifically, based on the data center hardware topology database (physical connection relationship of storage devices) and the real-time device load monitoring data stream (SNMP protocol data from the device management system), analyze the physical connection topology between storage nodes, construct an initial adjacency matrix, dynamically adjust the connection weight based on the load fluctuation variance, generate a node load fluctuation matrix with time window marks, and obtain the physical layer dynamic adjacency matrix (the matrix element value is the connection weight between devices, and the weight value is dynamically updated with the load fluctuation) Parse the multi-level data management system dependency chain based on the data management system relationship graph (JSON format output from the management system) and the metadata change time series record (change log from the data governance platform), construct an initial directed graph, calculate the dependency strength based on the metadata change frequency, generate a dependency weight matrix, and obtain the logical layer dependency weight matrix (the rows of the matrix represent upstream data entities, the columns represent downstream dependent parties, and the element values are dependency strength coefficients). Based on the user access audit log (from the system security audit module) and the geospatial location database (GPS / IP location data from the access terminal), statistically analyze the spatio-temporal distribution characteristics of access behaviors within a unit of time, construct an association frequency matrix reflecting the abnormality degree of the access pattern, and obtain the behavior layer association frequency matrix (the element values of the matrix represent the cross-regional access association strength, and abnormal access patterns correspond to low frequency values). Based on the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the behavior layer association frequency matrix, establish cross-layer connection rules: the mapping relationship between physical layer devices and logical layer data entities, and the association rules between logical layer data entities and behavior layer access patterns; Implement dynamic weight adjustment: Adjust the cross-layer connection strength every 5 minutes according to the device load, lineage change frequency, and access anomaly index; Embed a timestamp marking mechanism: Record the version sequence of the evolution of the network structure over time; Obtain a three-dimensional hypernetwork topology structure with timestamp markings (including the coupling connection relationship and version evolution history of the physical-logical-behavior layers).

[0064] It should be noted that an e-commerce platform has deployed a distributed storage cluster (physical layer), which includes 6 storage nodes (S1 - S6), carrying core data entities such as user profile tables and order tables (logical layer), and processing daily access requests from operation personnel in 20 provinces (behavior layer). The system realizes the three-dimensional network integration through the following methods: Construction of the physical layer dynamic adjacency matrix. According to the hardware topology database, the initial connection topology is: S1 ↔ S2 (bandwidth 10G), S3 ↔ S4 (bandwidth 20G), S5 ↔ S6 (bandwidth 10G). Through real-time monitoring by the SNMP protocol, it is found that during the period from 11:00 to 11:05: the load variance of S1 reaches 35% (historical average 15%), and the load variance of S2 is 28%; Dynamically adjust the connection weight: the weight of S1 - S2 is reduced from 0.8 to 0.5; Add an emergency connection between S2 - S5 (bandwidth 5G), with an initial weight value of 0.3; Generate a matrix with time window markings, where the row vector of S2 is [0.5, 0, 0, 0, 0.3, 0]; The logic layer relies on the generation of the weight matrix. By parsing the blood relationship graph in JSON format, it is found that the user profile table (D1) is simultaneously relied on by the recommendation system (D2) and the advertising model (D3). The metadata change log shows that D1 is updated 3 times per hour, and D2 is synchronized once every 2 hours. Calculate the dependency strength: the coefficient of D1→D2 = 0.9 (strong dependency with high-frequency changes), and the coefficient of D1→D3 = 0.6. The value in the D1 row and D2 column of the matrix is 0.9, and the value in the D3 column is 0.6. The value of the item without direct dependency is 0; Calculate the association frequency matrix at the behavior layer. The audit log shows that the access terminal with the IP address in Beijing accesses D2 120 times per hour (baseline: 100 times) during the working hours (9:00 - 18:00). The access terminal with the IP address in Guangdong suddenly accesses D3 50 times at 2 am (historical same period ≤ 5 times). The results of spatio-temporal anomaly detection: the association strength of the Beijing terminal is 0.8 (normal), and the association strength of the Guangdong terminal is 0.2 (low-frequency anomaly). In the matrix, the value in the row of the Guangdong IP and the column of D3 is marked as 0.2; Cross-layer coupling and dynamic adjustment. Establish mapping rules: the physical node S1 stores the logical entity D1; the logical entity D2 is frequently accessed by the Beijing IP; Perform weight update every 5 minutes: when the change frequency of D1 exceeds the threshold by +20%, increase the connection weight between S1 - S2 to 0.7; if the abnormal access of the Guangdong IP lasts for 2 cycles, reduce its association weight with D3 to 0.1; generate a three-dimensional network of version V2.3, with the timestamp 2025-03-29 11:05:00; This model forms a traceable and evolvable hyper-network topology by dynamically coupling the three-dimensional features of device load, data blood relationship, and access behavior, providing a basis for subsequent risk early warning.

[0065] 202. Based on the above three-dimensional hyper-network topology structure, obtain the load balance degree of physical layer devices, the integrity score of the logic layer management system, and the abnormal access index of the behavior layer. Construct a composite energy field model, use an improved diffusion mapping algorithm to generate an energy gradient field, and monitor the change of the energy surface curvature in real time. When it is detected that the curvature acceleration in a local area exceeds 3 times the standard deviation of the historical baseline, mark it as a phase transition critical area and output the coordinate set, obtaining the coordinate set of the phase transition critical area; Specifically, according to the dynamic adjacency matrix in the three-dimensional hyper-network topology structure, analyze the dynamic change sequence of the connection weights between storage nodes, calculate the node load fluctuation variance and the load correlation of adjacent nodes, generate a scoring matrix reflecting the load balance state between devices, and obtain the load balance degree matrix of the physical layer (the matrix element value is the load coordination coefficient between devices, 0 ≤ coefficient ≤ 1); Trace the complete hierarchical structure of the data relationship chain based on the logical layer dependency weight matrix in the three-dimensional hypernetwork topology, detect the coverage rate of metadata change records in the dependency path, calculate the integrity decay index of the management system chain, and obtain the integrity score matrix of the logical layer management system (the rows of the matrix represent data entities, the columns represent integrity dimensions, and the element values are score values from 0 to 100); Based on the behavior layer association frequency matrix in the three-dimensional hypernetwork topology, compare the spatio-temporal distribution differences between the real-time access pattern and the historical benchmark, detect the access aggregation phenomena in unconventional time periods and geographical regions, and quantify the deviation degree of abnormal access behaviors to obtain the abnormal access index vector of the behavior layer (the element values of the vector are the abnormal probability values of each access terminal, ranging from 0 to 1); Based on the physical layer load balancing matrix, the integrity score matrix of the logical layer management system, and the abnormal access index vector of the behavior layer, establish the energy value calculation rules: Physical energy component = load balancing coefficient × device health index Logical energy component = blood relationship integrity score × data freshness factor Behavior energy component = 1 - abnormal access index Adopt an improved diffusion mapping algorithm: introduce topological constraint conditions to limit the energy diffusion path and dynamically adjust the diffusion coefficient to adapt to the changes in the network structure; obtain a three-dimensional composite energy field model (a three-dimensional tensor containing energy scalar values, gradient direction vectors, and diffusion rates); Based on the three-dimensional composite energy field model and the historical normal state energy field database (storing the benchmark energy distribution in the past 30 days), calculate the Gaussian curvature distribution of the energy surface in real time and compare the current curvature change acceleration with the historical baseline statistical characteristics When the local area satisfies: |Second derivative of curvature| > historical mean + 3 × standard deviation Mark it as a phase transition critical area to obtain the coordinate set of the phase transition critical area (including the area center coordinates, influence radius, and curvature mutation intensity value).

[0066] It should be noted that an e-commerce platform has deployed 6 storage nodes (S1 - S6), among which S1 - S3 carry the user portrait table (D1), and S4 - S6 store the order table (D2). The system realizes composite energy field modeling and phase transition detection through the following process: Physical layer load balancing calculation. Through SNMP monitoring, it is found that the load fluctuation variances of S1 and S2 are 38% and 25% respectively (historical mean 15%); the load correlation between nodes: S1 - S2 = 0.72 (strong correlation), S4 - S5 = 0.91 (overload risk); Generate a load balancing matrix: The row vector of S1 is [0, 0.65, 0, 0, 0, 0] (the load coordination coefficient between S1 and S2 is reduced to 0.65 due to exceeding the variance standard). Logical layer lineage integrity assessment. The lineage dependency chain analysis of the order table (D2) shows that: the coverage rate of field changes in the user portrait table (D1) on which it depends is 85% (missing address field update records); metadata change frequency: D1 is updated 3 times per hour, and D2 is only synchronized once; in the lineage integrity scoring matrix, the score for the D2 row and D1 column is 75 points (out of 100), and the data freshness factor is 0.8. Behavioral layer abnormal access detection. The audit log found that: IPs in Guangdong accessed D2 intensively at 2 am, reaching 50 times per minute (baseline: 5 times); the access frequency of IPs in Beijing to D1 during working hours exceeded the threshold by 120%; in the abnormal access index vector, the index corresponding to D2 for IPs in Guangdong is 0.92, and the index corresponding to D1 for IPs in Beijing is 0.3. Construct a composite energy field. According to the energy calculation rules: Physical energy: section S1 - S2 = 0.65×0.7 (equipment health index) = 0.455; Logical energy: section D2 - D1 = 75×0.8 = 60; Behavioral energy: 1 - 0.92 = 0.08 (access to D2 by IPs in Guangdong). Through an improved diffusion algorithm, set topological constraints: The diffusion path of the order data nodes (S4 - S6) preferentially conducts along the transaction link, and dynamically adjusts the diffusion coefficient of the relevant nodes of D2 to 1.2 times the baseline value.

[0067] Phase transition critical area identification. At 11:05, it was monitored in the order processing area (coordinates X = 4, Y = 5, Z = 2): The second derivative of the energy curvature reached 8.7 (historical mean 2.1 ± 1.3); the curvature acceleration exceeded 3 times the standard deviation threshold; the system marked this area as a phase transition critical area. The coordinate set includes the S4 node, the D2 entity, and the associated Guangdong IP terminals, and the influence radius covers 3 transaction database nodes.

[0068] This model accurately locates the cross - layer risk conduction source caused by abnormal order access by quantifying the energy interaction of device load, data lineage, and access behavior, providing a decision - making basis for subsequent risk path tracking.

[0069] 203. According to the coordinate set of the phase transition critical area, trace the potential energy decay path in the opposite direction of the energy gradient, combine the physical layer topological structure and the logical layer dependency relationship, identify the conduction characteristics across devices - data - applications, and generate a cross - layer risk conduction path map including the sequence of transition nodes and the conduction intensity index. Specifically, based on the coordinate set of the phase transition critical region and the gradient direction vector data in the three-dimensional composite energy field model, starting from the center point of the phase transition critical region, trace step by step along the negative energy gradient direction, and combine the physical layer topology connection rules to constrain the path search range to obtain a preliminary conduction path sequence (including node address, tracking timestamp, energy attenuation rate); Based on the physical layer dynamic adjacency matrix, logical layer dependency weight matrix in the three-dimensional hypernetwork topology structure, and the preliminary conduction path sequence, detect the connection points in the path that simultaneously involve physical device nodes and logical data entities, and verify whether the cross-layer connection conforms to the preset mapping rule library to obtain a cross-layer transition node list (annotating the three-layer association relationship of device-data entity-application); Based on the cross-layer transition node list and the historical normal conduction path database (storing the path records verified in the past 90 days), compare the topology consistency between the current path and the historical normal path, and detect abnormal conduction characteristics: direct connection between non-adjacent devices in the physical layer, and breakage of cross-level dependencies in the logical layer; obtain the verified risk conduction path (including path validity marker, abnormal conduction segment location); Based on the verified risk conduction path and the timestamp version of the three-dimensional hypernetwork topology structure, annotate the cross-layer attributes (physical device / data entity / application service) of the path nodes, and calculate the conduction intensity index: Physical segment intensity = reciprocal of the variance of device load fluctuation Logical segment intensity = attenuation rate of blood relationship integrity score Behavior segment intensity = increment of abnormal access index Obtain the cross-layer risk conduction path map (including node sequence with intensity annotation, cross-layer transition point coordinates, time evolution marker).

[0070] It should be noted that an e-commerce platform detected that the order processing area (coordinates X = 4, Y = 5, Z = 2) is a phase transition critical area, and the curvature mutation intensity reaches 8.7 (historical baseline 2.1 ± 1.3), and the system starts to track the risk conduction path: Path tracking and cross-layer verification, starting from the S4 storage node (physical layer), a conduction path is found along the negative energy gradient direction: S4 → D2 (order table entity) → Guangdong IP terminal (behavior layer); Verify the cross-layer mapping rule: The S4 physical node does store the D2 order table (conforming to the device-data mapping rule); the D2 order table is frequently accessed by the Guangdong IP terminal (association rule exception: this IP has no historical access record); Conduction feature detection, physical layer anomaly: The load variance between S4 and S5 reaches 45% (normal value < 20%), resulting in a sudden direct connection between non-adjacent nodes S4 - S3; Logical layer break: The blood relationship integrity score of the D2 order table for the D1 user profile drops from 80 points to 60 points (field-level dependency loss); Behavioral layer anomaly: The anomaly index of Guangdong IP accessing D2 reaches 0.92 (baseline 0.05), with a daily increment of 0.87; Conduction intensity calculation, physical segment intensity: 1 / 0.45 = 2.22 (reciprocal of the load fluctuation variance of S4); Logical segment intensity: (80 - 60) / 80 = 25% (blood relationship integrity attenuation rate); Behavioral segment intensity: 0.92 - 0.05 = 0.87 (anomaly index increment); Path graph generation, generating a conduction path with intensity markings: Node sequence: S4 (physical) → D2 (logical) → Guangdong IP (behavior); Cross-layer transition points: S4 - D2 transition coordinates (X = 4.2, Y = 5.1, Z = 2.3), peak conduction intensity 2.22; D2 - Guangdong IP transition coordinates (X = 4.5, Y = 5.3, Z = 2.8), peak conduction intensity 0.87; Time evolution markings: At 02:15 on March 29, 2025, the S4 load anomaly was first detected; At 02:28, the blood relationship score of D2 began to decay; At 02:35, the Guangdong IP triggered a behavioral layer alarm; This graph shows that the risk conducts from physical device overload (S4 node) to logical layer data blood relationship break (field-level dependency loss of the D2 order table), and finally manifests as abnormal regional access (illegal pulling of order data by Guangdong IP). Based on this, the platform locks the risk source as the D2 data service degradation caused by the hardware overload of the S4 node, and associates it with the data crawling behavior during the vulnerable period of the black production exploitation system.

[0071] 204. Perform a spatial convolution operation on the set of phase transition critical region coordinates and the cross-layer risk conduction path graph, and dynamically trigger hierarchical warnings according to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate: Generate a red warning instruction when the path covers ≥ 3 critical nodes; Generate an orange warning instruction when the conduction intensity > 80% of the historical peak; Generate a yellow warning instruction when the daily growth rate of the influence radius > 200%; Output a set of disposal instructions with topological coordinates to the data isolation system and the traffic scheduling device; Specifically, based on the phase transition critical region coordinate set (including the region center coordinates and the influence radius), the cross-layer risk conduction path map (including the node sequence and the conduction intensity index), and the list of critical infrastructure nodes (from the system configuration database), map the phase transition region to a spatial risk heat map, generate a risk propagation vector field along the conduction path, perform a spatial convolution operation, and generate a risk superposition map (annotating the peak area of risk intensity, the conduction direction, and the coverage mark of critical nodes); Based on the risk superposition map and the historical peak database (storing the risk conduction intensity records for the past 365 days), extract the current conduction intensity value, calculate the percentage relative to the historical peak, monitor the daily growth rate of the influence radius of the phase transition region, and count the number of critical infrastructure nodes covered by the conduction path to obtain a set of dynamic threshold parameters (including the relative intensity value, the growth rate, and the number of critical nodes); Based on the set of dynamic threshold parameters and the system's preset warning rule library (storing the classification judgment criteria), when both conditions are met: the number of critical node coverage ≥ 3 and there is a conduction path across the physical layer - logical layer, a red warning is triggered; When the following conditions are met: the relative conduction intensity value > 80% of the historical peak and the growth rate of the influence radius > 150% / day, an orange warning is triggered; When the following conditions are met: the daily growth rate of the influence radius > 200% and there is a conduction path that does not cover critical nodes, a yellow warning is triggered; Obtain a set of classification warning instruction codes (including the warning level, the trigger condition code, and the timestamp); Based on the set of classification warning instruction codes, the node coordinate data in the three-dimensional hypernetwork topology structure, and the data governance operation rule library (storing the preset handling strategies), match the handling strategies according to the warning level: Red instruction: Execute data isolation + traffic cut-off; Orange instruction: Implement access flow limiting + backup trigger; Yellow instruction: Start enhanced monitoring + log tracking; Convert the strategy into a topological coordinate operation instruction to obtain a set of topological coordinate handling instructions (including the target device IP list, the data entity ID set, and the operation command code); Based on the set of topological coordinate handling instructions, the data isolation system API interface, and the traffic scheduling device control protocol, distribute the instructions to the target system through the standard protocol format, and collect the instruction execution status code and effect indicators in real time to obtain the instruction execution feedback log (including success / failure mark, execution delay, and status change record).

[0072] It should be noted that during the Double Eleven period in 2025, an e-commerce platform detected risk conduction in the payment center area (coordinates X = 7, Y = 9, Z = 5) through the three-dimensional hypernetwork topology structure, and the system performed the following classification warning operations: Spatial convolution operation and risk superposition. The influence radius of the phase change region reaches 300 meters, covering three key nodes: the payment gateway cluster (PG1 - PG3), the order database (DB_Order), and the user profile server (S_Profile); the conduction path spreads along "PG2→DB_Order→Shanghai IP terminal", and the path strength reaches 85% of the historical peak (benchmark value: the peak of 100 TPS in 2024); the daily growth rate of the influence radius is 220% (the previous day's radius was 137 meters); a risk heat map is generated through spatial convolution operation, showing that a peak intensity area (risk value 8.7 / 10) is formed around the PG2 node; Dynamic threshold determination. The number of covered key nodes = 3 (triggering the red warning condition); the relative value of the conduction intensity = 85% (triggering the orange warning condition); the daily growth rate of the influence radius = 220% (triggering the yellow warning condition); According to the warning rule library, the system simultaneously triggers a combined red (node coverage) and orange (intensity exceeding the standard) warning; Topological coordinate disposal instruction generation. Red instruction: Isolate the partition of the DB_Order table associated with the PG2 node (data entity ID: TB_20251110), and cut off the abnormal IP access traffic (target IP list: 192.168.7.22 - 25); Orange instruction: Implement a 50% request flow limit on the PG1 / PG3 nodes, and trigger the real - time backup of payment data to the disaster recovery center (backup strategy ID: BKP_PAY_EMG); Yellow instruction: Enable full - volume SQL log tracing for the payment link (log label: PAY_TRACE_1129), and strengthen the access audit of the user profile server; Instruction execution and feedback. The data isolation system completes the isolation of the TB_20251110 table within 32 seconds, and the traffic scheduling device intercepts 12,000 abnormal requests per minute; the disaster recovery center receives a real - time data flow peak of up to 80 GB / s, and the log system captures 3 abnormal SQL queries (involving unauthorized access to user privacy fields); the system monitors that the peak of the risk heat map drops to 4.2 / 10 within 15 minutes, and the influence radius shrinks to 150 meters; This case shows that by quantifying the risk conduction intensity and scope through spatial convolution operation, combined with dynamic threshold judgment, precise hierarchical response is achieved. The red warning cuts off the core risk source, the orange warning ensures business continuity, and the yellow warning strengthens monitoring and evidence collection, forming a gradient defense system for risk disposal. The platform finally resolves the risk of payment link collapse within 1 hour, avoiding direct economic losses exceeding 230 million yuan.

[0073] 205. Real - time collect the metadata status, management system relationship changes, and access behavior data after the execution of the collection instruction, and feedback them to the three - dimensional hyper - network modeling module for dynamic topology update to achieve self - optimization control of the warning system.

[0074] Specifically, based on the operation log of the data isolation system (recording changes in the isolation status of data entities), the status code of the traffic scheduling device (including the execution results of the current limiting strategy), and the metadata version control system (recording the new version after the blood relationship is repaired), the system state changes after the execution of the instruction are captured in real time, and key feedback indicators are extracted: metadata change coverage, blood relationship repair completeness, access behavior pattern offset; and a closed-loop feedback data set is obtained (including timestamps, operation types, and structured records of state change values); Based on the current version of the three-dimensional super-network topology, verify whether the physical layer connection adjustment complies with the equipment security rules, detect whether the logical layer dependency repair introduces new loop risks, analyze whether the change of the behavioral layer access mode exceeds the preset tolerance threshold, and obtain a topology update compliance report (marking the network segments allowed to be updated and the prohibited operation areas); Based on the topology update compliance report and the historical version sequence of the three-dimensional super network topology structure, the physical layer is adjusted: the connection weight is dynamically updated according to the changes in device load, and the weight of the isolated area device is reset to zero; Adjustments to the logic layer: Increase the effective dependency weight according to the bloodline repair results, and reduce the broken dependency edge weight to 10% of the baseline value; Adjustments to the behavior layer: The rate at which the weight of the edges associated with abnormal access patterns decreases is doubled, and the initial weight of newly added legal access paths is set to the mean; Get the optimized three-dimensional super network topology structure (including the physical-logical-behavioral layer weight matrix marked with version numbers); Based on the optimized three-dimensional hypernetwork topology structure and the current parameter set of the energy field model, the energy diffusion coefficient is dynamically adjusted according to the topological change, the curvature calculation sensitivity parameter of the phase change detection is updated, and the time window range of the historical baseline database is reset; the adaptive control parameter set (including the diffusion coefficient table, sensitivity parameters, and baseline time window configuration) is obtained; Based on the adaptive control parameter set and the system stability test case library (predefined verification scenario set), the risk scenario is replayed in the sandbox environment to verify the update effect. When the risk detection coverage is ≥ 98% and the false alarm rate is ≤ 5%, the new version of the topology and parameters is released to obtain the officially released three-dimensional super network topology version (including version number, effective time, and change log).

[0075] It should be noted that a certain e-commerce platform triggered a red alert during the Double Eleven promotion. After data isolation was performed on the abnormal order table (TB_20251111), the system started the self-optimization process: Feedback data collection (2025-11-12 03:00), Metadata status: The lineage integrity of table TB_20251111 was restored from 62 points to 85 points (out of 100) by the isolation operation, covering 12 downstream analysis models; Access behavior deviation: The access volume from Guangdong IP decreased from a peak of 50 times per minute to 5 times, but there was a 15% abnormal increase in Beijing IP (baseline error ±5%); Device load change: The load variance of the original overloaded node S4 decreased from 45% to 18%, but the load variance of the standby node S7 increased to 28%; Topology compliance verification, Physical layer conflict: The new connection weight of node S7 is 0.8 (preset security threshold 0.7), triggering an alarm; Logical layer loop: A new dependency loop was formed between the user portrait table (D1) and the order table (D2) (score after repair: 85 → 70); Behavioral layer deviation: The abnormal index increase in the access of Beijing IP to D2 is 0.15 (tolerance threshold 0.1); Dynamic adjustment implementation, Physical layer: The weight of node S7 was reduced from 0.8 to 0.65, and the weight of the isolated node S4 was set to zero; Logical layer: The effective dependency weight from D1 to D2 was increased to 0.9, and the dependency weight of the broken promotion activity field decayed to 0.1; Behavioral layer: The associated edge weight of Beijing IP decreases by 40% daily (original 20%), and the initial weight of the newly added legal access path is set to the average value of 0.5; Parameter optimization and verification, Energy diffusion coefficient: Adjusted from 1.2 to 1.5 (to adapt to node load changes); Curvature sensitivity: The threshold was relaxed from 3σ to 2.8σ (to reduce false alarms); Historical baseline window: Adjusted from 30 days to 15 days (to cope with data characteristic changes after promotions); Simulating historical risk scenarios in the sandbox environment: Risk detection coverage rate is 98.7% (original 97.2%); False alarm rate is 3.1% (4.8% before optimization); Version release (V3.5), After the new topology structure takes effect: The expansion rate of the influence radius decreases from 220% / day to 75% / day; The peak value of the cross-layer conduction intensity decreases by 62%; Change log record: Version number: V3.5_20251112 Effective time: 2025-11-12 06:00 Main changes: Physical layer: S4 isolation / S7 weight optimization Logical layer: Repair of the D1-D2 dependency loop Behavioral layer: Upgrade of the monitoring strategy for Beijing IP This closed-loop mechanism drives model iteration through real-time feedback, enabling the system to complete the entire process from risk disposal to adaptive optimization within 24 hours, ensuring the continuous evolution of data governance capabilities after major promotions.

[0076] In the embodiments of the present invention, the metadata change log, the lineage graph, and the real-time access behavior data are three-dimensionally fused to construct a hyper-network topology structure including a physical layer, a logical layer, and a behavior layer. By real-time monitoring the device load, the lineage change frequency, and the access anomaly index, the cross-layer connection strength is dynamically adjusted, enabling the model to flexibly adapt to changes in the network structure. Timestamp records are embedded to document the evolution history of the network structure, providing precise support in the time dimension for risk warning and retrospective analysis. An improved diffusion mapping algorithm is used to generate an energy gradient field, and the change in the curvature of the energy surface is monitored in real time, providing a new perspective for risk warning. By detecting whether the curvature acceleration in a local area exceeds 3 times the standard deviation of the historical baseline, the risk source is accurately located and marked as a phase transition critical area. By calculating the load balance degree of the physical layer, the integrity score of the logical layer management system, and the abnormal access index of the behavior layer, a scientific basis is provided for risk quantification. The potential energy decay path is traced along the reverse direction of the energy gradient, and combined with the physical layer topology structure and the logical layer dependency relationship, the conduction characteristics across devices, data, and applications are accurately identified. By verifying whether the cross-layer connection conforms to the preset mapping rule library, the accuracy and reliability of the conduction path are ensured. By calculating the conduction strength indicators of the physical segment, the logical segment, and the behavior segment, a basis is provided for prioritizing the risk paths. Risk features are extracted through spatial convolution operations, considering the three-dimensional correlation across devices, data, and applications, improving the accuracy of risk warning. According to the number of critical infrastructures covered by the conduction path, the relative value of the conduction strength, and the regional expansion rate, hierarchical warnings are dynamically triggered, achieving precise control of risks. A disposal instruction set with topological coordinates is generated, providing a decision basis for automatically isolating high-risk trading links. The system state changes after the execution of the instructions are collected in real time and fed back to the three-dimensional hyper-network modeling module for dynamic topology update. Compliance verification is performed before the topology update to ensure that the adjustment complies with device security rules and data governance requirements. The energy diffusion coefficient and the curvature calculation sensitivity parameters are dynamically adjusted according to the topological changes, improving the adaptability and accuracy of the model.

[0077] The above describes the data governance risk warning method based on big data mining in the embodiments of the present invention. Next, the data governance risk warning device based on big data mining in the embodiments of the present invention will be described. Please refer to Figure 3, an embodiment of the data governance risk warning device based on big data mining in the embodiments of the present invention includes: an acquisition module 301, configured to acquire real-time access behavior data of metadata change logs of a data governance platform, a multi-level dependency relationship graph of a management system, and system audit logs, and perform three-dimensional network fusion modeling: map the physical connection topology between storage devices at the physical layer to generate a node load fluctuation matrix; parse the data relationship chain at the logical layer to construct a dependency weight matrix; extract the spatio-temporal characteristics of user access at the behavior layer to form an association frequency matrix; couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hypernetwork topology structure marked with a time stamp; a processing module 302, configured to obtain the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index based on the three-dimensional hypernetwork topology structure, construct a composite energy field model, generate an energy gradient field, monitor the change of the energy surface curvature in real time, and obtain a set of phase transition critical region coordinates; a setting module 303, configured to trace the potential energy decay path along the reverse direction of the energy gradient according to the set of phase transition critical region coordinates, and combine the physical layer topology structure and the logical layer dependency relationship to generate a cross-layer risk conduction path graph; an allocation module 304, configured to perform a spatial convolution operation on the set of phase transition critical region coordinates and the cross-layer risk conduction path graph, and dynamically trigger hierarchical warnings according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and output a set of disposal instructions.

[0078] In the embodiments of the present invention, through three-dimensional network fusion modeling and a composite energy field model, this technology can comprehensively and accurately monitor and warn data governance risks, reducing the false alarm rate and missed alarm rate; the modular design enables the system to conveniently expand new functional modules or upgrade existing modules to adapt to the changing data governance requirements; through cross-layer risk conduction path tracing and a hierarchical warning mechanism, this technology can quickly locate the risk source and generate a set of disposal instructions, improving the efficiency and accuracy of risk disposal; the cross-layer risk conduction path graph and the hierarchical warning instructions provide an intuitive decision-making basis for the data governance team, helping to formulate more scientific and reasonable risk disposal strategies; by monitoring and warning data governance risks in real time, this technology helps to ensure the compliance of data governance and reduce the legal risks and reputation losses caused by risks such as data leakage and abuse. In summary, through innovative methods such as modular design, composite energy field model, cross-layer risk conduction path tracing, spatial convolution operation, and hierarchical warning, this technology provides a comprehensive, accurate, efficient, and scalable solution for data governance risk warning, with important practical application value and promotion significance.

[0079] Above Figure 3The data governance risk warning device based on big data mining in the embodiments of the present invention is described in detail from the perspective of modular functional entities. Next, the data governance risk warning device based on big data mining in the embodiments of the present invention is described in detail from the perspective of hardware processing.

[0080] Figure 4 FIG. 4 is a schematic structural diagram of a data governance risk warning device based on big data mining provided by an embodiment of the present invention. The data governance risk warning device 400 based on big data mining may vary greatly due to configuration or performance, and may include one or more processors (central processing units, CPUs) 410 (for example, one or more processors) and a memory 420, and one or more storage media 430 for storing application programs 433 or data 432 (for example, one or more mass storage devices). Among them, the memory 420 and the storage media 430 may be transient storage or persistent storage. The program stored in the storage media 430 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the data governance risk warning device 400 based on big data mining. Further, the processor 410 may be configured to communicate with the storage media 430 and execute a series of instruction operations in the storage media 430 on the data governance risk warning device 400.

[0081] The data governance risk warning device 400 based on big data mining may further include one or more power supplies 440, one or more wired or wireless network interfaces 450, one or more input / output interfaces 460, and / or one or more operating systems 431, such as Windows Serve, Mac OS X, Unix, Linux, FreeBSD, and so on. Those skilled in the art can understand that Figure 4 the shown structure of the data governance risk warning device based on big data mining does not constitute a limitation on the data governance risk warning device based on big data mining, and may include more or fewer components than shown, or combine some components, or have different component arrangements.

[0082] The present invention also provides a data governance risk warning device based on big data mining. The data governance risk warning device based on big data mining includes a memory and a processor. When the computer-readable instructions stored in the memory are executed by the processor, the processor executes the steps of the data governance risk warning method in the above embodiments.

[0083] The present invention also provides a computer-readable storage medium, which can be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer, the computer is caused to execute the steps of the data governance risk warning method based on big data mining.

[0084] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0085] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs and other various media that can store program codes.

[0086] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data governance risk early warning method based on big data mining, characterized in that: The data governance risk early warning method based on big data mining includes: Obtain the metadata change log of the data governance platform, the multi-level dependency graph of the management system, and the real-time access behavior data of the system audit log to perform three-dimensional network fusion modeling: The physical layer maps the physical connection topology between storage devices and generates a node load fluctuation matrix; The logic layer analyzes the data relationship chain and constructs a dependency weight matrix; The behavior layer extracts the temporal and spatial characteristics of user visits and forms a correlation frequency matrix; The three-layer network is coupled through a dynamic weight adjustment mechanism to output a three-dimensional super-network topology with a timestamp. Based on the three-dimensional super network topology, the load balancing degree of the physical layer equipment, the integrity score of the logical layer management system and the abnormal access index of the behavioral layer are obtained, a composite energy field model is constructed, an energy gradient field is generated, and the curvature change of the energy surface is monitored in real time to obtain a set of coordinates of the phase change critical region; According to the phase change critical region coordinate set, the potential energy attenuation path is traced in the reverse direction of the energy gradient, and a cross-layer risk conduction path map is generated by combining the physical layer topology structure and the logic layer dependency relationship; The phase change critical area coordinate set is spatially convolved with the cross-layer risk conduction path map, and a graded warning is dynamically triggered based on the number of key infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and a disposal instruction set is output.

2. The data governance risk early warning method based on big data mining according to claim 1 is characterized in that: include: According to the data center hardware topology database and real-time equipment load monitoring data stream, the physical connection topology between storage nodes is analyzed, the initial adjacency matrix is ​​constructed, the connection weights are dynamically adjusted based on the load fluctuation variance, and the node load fluctuation matrix with time window markers is generated to obtain the physical layer dynamic adjacency matrix; According to the data management system relationship map and metadata change time series records, the multi-level data management system dependency chain is analyzed, the initial directed graph is constructed, the dependency strength is calculated according to the metadata change frequency, the dependency weight matrix is ​​generated, and the logic layer dependency weight matrix is ​​obtained; Based on user access audit logs and geographic spatial location database, the temporal and spatial distribution characteristics of access behaviors within a unit time are counted, and a correlation frequency matrix reflecting the abnormality of access patterns is constructed to obtain a behavior-level correlation frequency matrix. According to the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix and the behavioral layer association frequency matrix, cross-layer connection rules are established, dynamic weight adjustment is implemented, and a timestamp marking mechanism is embedded to obtain a three-dimensional super network topology structure with timestamp marking.

3. The data governance risk early warning method based on big data mining according to claim 2 is characterized in that: include: According to the physical layer dynamic adjacency matrix in the three-dimensional super network topology structure, the dynamic change sequence of connection weights between storage nodes is analyzed, the correlation between node load fluctuation variance and adjacent node load is calculated, and a scoring matrix reflecting the load balancing status between devices is generated to obtain the physical layer load balancing degree matrix; According to the logic layer dependency weight matrix in the three-dimensional hypernetwork topology, the complete hierarchical structure of the data relationship chain is traced, the coverage of metadata change records in the dependency path is detected, the integrity decay index of the management system chain is calculated, and the logic layer management system integrity scoring matrix is ​​obtained; Based on the behavior layer correlation frequency matrix in the three-dimensional hypernetwork topology, the temporal and spatial distribution differences between real-time access patterns and historical benchmarks are compared to detect access aggregation phenomena in unconventional time periods and unconventional geographical areas, quantify the degree of deviation of abnormal access behavior, and obtain the behavior layer abnormal access index vector; According to the load balancing matrix of the physical layer, the integrity scoring matrix of the management system of the logical layer, and the abnormal access index vector of the behavioral layer, the energy value calculation rules are established, and the diffusion mapping algorithm is used to obtain the three-dimensional composite energy field model; Based on the three-dimensional composite energy field model and the historical normal state energy field database, the Gaussian curvature distribution of the energy surface is calculated in real time, and the current curvature change acceleration is compared with the historical baseline statistical characteristics to obtain the coordinate set of the phase change critical area.

4. The data governance risk early warning method based on big data mining according to claim 3 is characterized in that: include: Based on the phase transition critical region coordinate set and the gradient direction vector data in the three-dimensional composite energy field model, starting from the center point of the phase transition critical region, hopping by hop is tracked along the negative direction of the energy gradient, and the path search range is constrained by the physical layer topological connection rules to obtain a preliminary conduction path sequence; According to the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the preliminary conduction path sequence in the three-dimensional super network topology structure, the connection points involving both physical device nodes and logical data entities in the path are detected, and whether the cross-layer connection conforms to the preset mapping rule library is verified to obtain a list of cross-layer transition nodes; Based on the cross-layer transition node list and the historical normal conduction path database, the topological consistency of the current path is compared with the historical normal path, the abnormal conduction characteristics are detected, and the verified risk conduction path is obtained; Based on the timestamp version of the verified risk transmission path and the three-dimensional hypernetwork topology structure, the cross-layer attributes of the path nodes are marked, the transmission intensity index is calculated, and the cross-layer risk transmission path map is obtained.

5. The data governance risk early warning method based on big data mining according to claim 4 is characterized in that: include: Based on the phase change critical area coordinate set, cross-layer risk transmission path map, and key infrastructure node list, the phase change area is mapped into a spatial risk heat map, and the risk propagation vector field is generated along the transmission path. The spatial convolution operation is performed to generate a risk superposition map. Based on the risk superposition map and historical peak database, the current conduction intensity value is extracted, the percentage relative to the historical peak is calculated, the daily growth rate of the impact radius of the phase change area is monitored, the number of key infrastructure nodes covered by the conduction path is counted, and a dynamic threshold parameter set is obtained; According to the dynamic threshold parameter set and the system preset warning rule library, a hierarchical warning instruction code set is obtained; According to the hierarchical warning instruction code set, the node coordinate data in the three-dimensional super network topology structure, and the data governance operation rule library, the processing strategy is matched according to the warning level, and the strategy is converted into a topological coordinate operation instruction to obtain a topological coordinate processing instruction set; According to the topological coordinate processing instruction set, data isolation system API interface, and traffic scheduling device control protocol, the instructions are distributed to the target system through the standard protocol format, and the instruction execution status code and effect indicators are collected in real time to obtain the instruction execution feedback log.

6. The data governance risk early warning method based on big data mining according to claim 5 is characterized in that: Also includes: The metadata status after instruction execution, management system relationship changes and access behavior data are collected in real time and fed back to the three-dimensional super network modeling module for dynamic update of the topology structure to achieve self-optimization control of the early warning system.

7. A data governance risk early warning device based on big data mining, characterized in that: The data governance risk early warning device based on big data mining includes: The acquisition module is used to obtain the metadata change log of the data governance platform, the multi-level dependency graph of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling: The physical layer maps the physical connection topology between storage devices and generates a node load fluctuation matrix; The logic layer analyzes the data relationship chain and constructs a dependency weight matrix; The behavior layer extracts the temporal and spatial characteristics of user visits and forms a correlation frequency matrix; The three-layer network is coupled through a dynamic weight adjustment mechanism to output a three-dimensional super-network topology with a timestamp. A processing module is used to obtain the load balancing degree of physical layer equipment, the integrity score of the logical layer management system and the abnormal access index of the behavioral layer based on the three-dimensional super network topology structure, build a composite energy field model, generate an energy gradient field, monitor the curvature change of the energy surface in real time, and obtain a set of coordinates of the phase change critical region; A setting module is used to track the potential energy attenuation path in the reverse direction of the energy gradient according to the phase change critical region coordinate set, and generate a cross-layer risk conduction path map by combining the physical layer topology structure and the logic layer dependency; The allocation module is used to perform spatial convolution operation on the phase change critical area coordinate set and the cross-layer risk conduction path map, dynamically trigger graded warnings according to the number of key infrastructure covered by the conduction path, the relative value of the conduction intensity and the regional expansion rate, and output a disposal instruction set.

8. A data governance risk early warning device based on big data mining, characterized in that: The data governance risk early warning device based on big data mining includes: a memory and at least one processor, wherein instructions are stored in the memory; The at least one processor calls the instructions in the memory so that the data governance risk warning device based on big data mining executes the data governance risk warning method based on big data mining as described in any one of claims 1-6.

9. A computer-readable storage medium having instructions stored thereon, characterized in that: When the instruction is executed by the processor, it implements the data governance risk warning method based on big data mining as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Building safety alert level dynamic adjustment method and system based on artificial intelligence driving

    CN119204699A

  • Eye health state monitoring and evaluating method and device based on big data

    CN119273659A

  • Predictive risk evaluation in manufacturing system modeling

    JP2024068660A

Cited By

  • Multi-modal data sensing processing method and system for sound intelligent film

    CN120281754A

  • User behavior intelligent analysis and management system based on big data technology

    CN120316448A

  • Data index secure access method and related equipment

    CN120337299A

  • A data index security access method and related equipment

    CN120337299B

  • Supply chain data management method, system and device based on industrial Internet of Things and medium

    CN120409870A