A data governance risk early warning method based on big data mining

By building a three-dimensional coupled model and combining big data mining technology, the problem of insufficient risk assessment in meteorological and marine data governance is solved, global perception and dynamic prediction are realized, and the security and management efficiency of the data governance system are improved.

CN120066862BActive Publication Date: 2025-07-11无锡九方科技有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510541082.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-11
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The existing data governance system cannot adapt to complex challenges such as multi-data fusion, dynamic permission management, and geographical distributed backup in the meteorological and ocean fields, resulting in insufficient risk assessment. The backup strategy of important data in extreme weather is invalid and global perception and dynamic prediction cannot be achieved.

Method used

Through big data mining, a three-dimensional coupled model is built, combining the physical layer equipment topology, logical layer blood relationship and behavioral layer access mode, a three-dimensional hypernetwork topology structure is generated, and the curvature changes of energy surfaces are monitored in real time, risk transmission paths are tracked, and hierarchical warnings are triggered dynamically.

Benefits of technology

It realizes global risk perception and dynamic prediction of meteorological and marine data, accurately locates the source of risks, supports millisecond-level decision-making response, and improves the security and management efficiency of the data governance system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120066862B_ABST
    Figure CN120066862B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data governance, and discloses a data governance risk early warning method based on big data mining. By using big data mining technology to construct a three-dimensional coupling model, global perception, dynamic prediction and closed-loop disposal of risks are realized. The data governance risk early warning method based on big data mining includes: obtaining a three-dimensional hypernetwork topology structure, obtaining a set of coordinates of the phase transition critical region, generating a cross-layer risk conduction path map, dynamically triggering hierarchical early warning, and outputting a disposal instruction set. The three-dimensional hypernetwork modeling technology of the present invention constructs a composite energy field model with the characteristics of the meteorological and oceanographic fields by integrating the meteorological equipment topology, the data product dependency chain and cross-border access behaviors, can early warn of the risk of cross-regional data chain breakage, and reduce the probability of data backup failure during typhoon passing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data governance, and particularly to a data governance risk early warning method based on big data mining. Background Art

[0002] With the acceleration of digital transformation, data governance faces unprecedented complex challenges.

[0003] In the field of meteorology and oceanography, data governance faces several core challenges: the pressure of multi-data fusion, with the global meteorological observation network generating more than 500TB of data every day, covering more than 20 data formats such as satellite remote sensing, buoy sensing, and numerical model output; the complexity of dynamic permission management, with cross-departmental collaboration involving more than 300 sub-permission groups in 6 categories such as military, civil aviation, and scientific research, and the need to meet the instantaneous rise and fall requirements of permissions in special scenarios such as real-time typhoon warnings; the particularity of geographically distributed backups, which requires an accurate balance between the timeliness and integrity of data synchronization between coastal disaster-prone areas and inland backup centers.

[0004] Currently, the single-dimensional monitoring system cannot adapt to the spatio-temporal correlation characteristics of meteorological and oceanographic data. There is a lack of assessment means for the physical-logical coupling risks between polar scientific research data and equatorial observation stations. There is insufficient intelligent association between permission changes and dynamic events such as typhoon paths and marine disasters. There is a lack of a blocking mechanism for abnormal cross-border flows of important meteorological data during red alerts. The backup system is decoupled from real-time meteorological elements, and a dynamic mapping model of "typhoon eye area - data center disaster tolerance level" has not been established, resulting in the failure of backup strategies under extreme weather conditions.

[0005] Therefore, we propose a data governance risk early warning method based on big data mining to solve the above problems. Summary of the Invention

[0006] The present invention provides a data governance risk early warning method based on big data mining, which constructs a three-dimensional coupling model through big data mining technology to achieve global perception, dynamic prediction, and closed-loop disposal of risks.

[0007] In the first aspect of the present invention, a data governance risk early warning method based on big data mining is provided. The data governance risk early warning method based on big data mining includes: obtaining real-time access behavior data of the metadata change log of the data governance platform, the multi-level dependency relationship graph of the management system, and the system audit log, and performing three-dimensional network fusion modeling: mapping the physical connection topology between storage devices at the physical layer to generate a node load fluctuation matrix; parsing the data relationship chain at the logical layer to construct a dependency weight matrix; extracting the spatio-temporal characteristics of user access at the behavior layer to form an association frequency matrix; coupling the three-layer network through a dynamic weight adjustment mechanism, and outputting a three-dimensional hypernetwork topology structure marked with a timestamp; based on the three-dimensional hypernetwork topology structure, obtaining the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index, constructing a composite energy field model, generating an energy gradient field, monitoring the change of the energy surface curvature in real time, and obtaining a set of coordinates of the phase transition critical region; according to the set of coordinates of the phase transition critical region, tracing the potential energy decay path in the reverse direction of the energy gradient, combining the physical layer topology structure and the logical layer dependency relationship, and generating a cross-layer risk conduction path graph; performing a spatial convolution operation on the set of coordinates of the phase transition critical region and the cross-layer risk conduction path graph, and dynamically triggering hierarchical early warning according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and outputting a disposal instruction set.

[0008] Optionally, in the first implementation manner of the first aspect of the present invention, it includes: parsing the physical connection topology between storage nodes according to the data center hardware topology database and the real-time device load monitoring data stream, constructing an initial adjacency matrix, dynamically adjusting the connection weight based on the load fluctuation variance, generating a node load fluctuation matrix marked with a time window, and obtaining a physical layer dynamic adjacency matrix; parsing the multi-level data management system dependency chain according to the data management system relationship graph and the metadata change timing record, constructing an initial directed graph, calculating the dependency intensity according to the metadata change frequency, and generating a dependency weight matrix to obtain a logical layer dependency weight matrix; statistically analyzing the spatio-temporal distribution characteristics of access behavior within a unit time according to the user access audit log and the geospatial location database, constructing an association frequency matrix reflecting the abnormality degree of the access mode, and obtaining a behavior layer association frequency matrix; establishing a cross-layer connection rule according to the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the behavior layer association frequency matrix, implementing dynamic weight adjustment, and embedding a timestamp marking mechanism to obtain a three-dimensional hypernetwork topology structure marked with a timestamp.

[0009] Optionally, in the second implementation manner of the first aspect of the present invention, it includes: analyzing the dynamic change sequence of the connection weights between storage nodes based on the physical layer dynamic adjacency matrix in the three-dimensional hypernetwork topology, calculating the variance of node load fluctuations and the correlation between the loads of adjacent nodes, generating a scoring matrix reflecting the load balance state between devices, and obtaining the physical layer load balance degree matrix; tracing the complete hierarchical structure of the data relationship chain based on the logical layer dependency weight matrix in the three-dimensional hypernetwork topology, detecting the coverage rate of metadata change records in the dependency path, calculating the integrity decay index of the management system chain, and obtaining the logical layer management system integrity scoring matrix; comparing the spatio-temporal distribution differences between the real-time access pattern and the historical benchmark based on the behavior layer association frequency matrix in the three-dimensional hypernetwork topology, detecting access aggregation phenomena in unconventional time periods and unconventional geographical regions, quantifying the deviation degree of abnormal access behaviors, and obtaining the behavior layer abnormal access index vector; establishing an energy value calculation rule based on the physical layer load balance degree matrix, the logical layer management system integrity scoring matrix, and the behavior layer abnormal access index vector, and using the diffusion mapping algorithm to obtain the three-dimensional composite energy field model; calculating the Gaussian curvature distribution of the energy surface in real time based on the three-dimensional composite energy field model and the historical normal state energy field database, and comparing the current curvature change acceleration with the historical baseline statistical characteristics to obtain the coordinate set of the phase transition critical region.

[0010] Optionally, in the third implementation manner of the first aspect of the present invention, it includes: starting from the center point of the phase transition critical region, tracing hop by hop along the negative direction of the energy gradient according to the coordinate set of the phase transition critical region and the gradient direction vector data in the three-dimensional composite energy field model, and combining the physical layer topology connection rules to constrain the path search range to obtain the preliminary conduction path sequence; detecting the connection points that simultaneously involve physical device nodes and logical data entities in the path based on the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the preliminary conduction path sequence in the three-dimensional hypernetwork topology, and verifying whether the cross-layer connection conforms to the preset mapping rule library to obtain the cross-layer transition node list; comparing the topological consistency between the current path and the historical normal path based on the cross-layer transition node list and the historical normal conduction path database, and detecting abnormal conduction characteristics to obtain the verified risk conduction path; marking the cross-layer attributes of the path nodes based on the verified risk conduction path and the timestamp version of the three-dimensional hypernetwork topology, and calculating the conduction intensity index to obtain the cross-layer risk conduction path map.

[0011] Optionally, in the fourth implementation manner of the first aspect of the present invention, it includes: mapping the phase change region into a spatial risk heat map according to the phase change critical region coordinate set, the cross-layer risk conduction path map, and the list of critical infrastructure nodes, generating a risk propagation vector field along the conduction path, performing a spatial convolution operation, and generating a risk superposition map; extracting the current conduction intensity value according to the risk superposition map and the historical peak database, calculating the percentage relative to the historical peak, monitoring the daily growth rate of the influence radius of the phase change region, and counting the number of critical infrastructure nodes covered by the conduction path to obtain a set of dynamic threshold parameters; obtaining a hierarchical early warning instruction code set according to the set of dynamic threshold parameters and the pre-set early warning rule library of the system; according to the hierarchical early warning instruction code set, the node coordinate data in the three-dimensional hyper network topology structure, and the data governance operation rule library, matching the disposal strategy according to the early warning level, converting the strategy into a topological coordinate operation instruction, and obtaining a topological coordinate disposal instruction set; according to the topological coordinate disposal instruction set, the data isolation system API interface, and the traffic scheduling device control protocol, distributing the instructions to the target system through the standard protocol format, and collecting the instruction execution status code and the effect index in real time to obtain the instruction execution feedback log.

[0012] Optionally, in the fifth implementation manner of the first aspect of the present invention, it further includes: collecting in real time the metadata status, the change of the management system relationship, and the access behavior data after the instruction is executed, and feeding them back to the three-dimensional hyper network modeling module for dynamic update of the topological structure, so as to realize the self-optimizing control of the early warning system.

[0013] In a second aspect of the present invention, a data governance risk early warning device based on big data mining is provided. The data governance risk early warning device based on big data mining includes: an acquisition module, configured to acquire real-time access behavior data of metadata change logs of a data governance platform, a multi-level dependency relationship graph of a management system, and system audit logs, and perform three-dimensional network fusion modeling: map the physical connection topology between storage devices at the physical layer to generate a node load fluctuation matrix; parse the data relationship chain at the logical layer to construct a dependency weight matrix; extract the spatio-temporal characteristics of user access at the behavior layer to form an association frequency matrix; couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hypernetwork topology structure marked with a time stamp; a processing module, configured to obtain the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index based on the three-dimensional hypernetwork topology structure, construct a composite energy field model, generate an energy gradient field, and monitor the change of the energy surface curvature in real time to obtain a set of coordinates of a phase transition critical region; a setting module, configured to trace the potential energy decay path along the reverse direction of the energy gradient according to the set of coordinates of the phase transition critical region, and combine the physical layer topology structure and the logical layer dependency relationship to generate a cross-layer risk conduction path graph; an allocation module, configured to perform a spatial convolution operation on the set of coordinates of the phase transition critical region and the cross-layer risk conduction path graph, and dynamically trigger a hierarchical early warning according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and output a set of disposal instructions.

[0014] In a third aspect of the present invention, a data governance risk early warning device based on big data mining is provided, including: a memory and at least one processor, wherein instructions are stored in the memory; the at least one processor calls the instructions in the memory so that the data governance risk early warning device based on big data mining executes the above-mentioned data governance risk early warning method based on big data mining.

[0015] In a fourth aspect of the present invention, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, and when it runs on a computer, it causes the computer to execute the above-mentioned data governance risk early warning method based on big data mining.

[0016] In the technical solution provided by the present invention, the beneficial effects are as follows:

[0017] Integrate the physical layer device topology, the logical layer blood relationship, and the behavior layer access mode into a unified modeling framework, and realize the coupling of the three-layer network through a dynamic weight adjustment mechanism, breaking the traditional single-dimensional analysis paradigm and solving the problem of fragmented risk perception;

[0018] Introduce the concept of physical energy field, quantify device load, blood relationship integrity, and access abnormality as energy distribution, and real-time monitor the risk phase transition critical point through Gaussian curvature;

[0019] Combining the gradient tracking algorithm with the topological constraint rules, realizing the visualization of the conduction path of risks from the physical layer to the logical layer, and accurately positioning the attack paths of critical infrastructure;

[0020] Performing a spatial convolution operation on the risk superposition map and the historical peak database, dynamically generating hierarchical early warning instructions, supporting millisecond-level decision-making responses, automatically matching the topological coordinate operation instructions, and shortening the system response time from the minute level of the traditional architecture to the second level. Brief Description of the Drawings

[0021] Figure 1 It is a schematic diagram of an embodiment of the data governance risk early warning method based on big data mining in an embodiment of the present invention;

[0022] Figure 2 It is a schematic diagram of another embodiment of the data governance risk early warning method based on big data mining in an embodiment of the present invention;

[0023] Figure 3 It is a schematic diagram of an embodiment of the data governance risk early warning device based on big data mining in an embodiment of the present invention;

[0024] Figure 4 It is a schematic diagram of an embodiment of the data governance risk early warning device based on big data mining in an embodiment of the present invention. Detailed Description of the Invention

[0025] The embodiment of the present invention provides a data governance risk early warning method based on big data mining, which constructs a three-dimensional coupling model through big data mining technology to realize the global perception, dynamic prediction and closed-loop disposal of risks. The terms "first", "second", "third", "fourth", etc. (if any) in the description and claims of the present invention and the above drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order different from that shown or described here. In addition, the terms "including" or "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0026] For the convenience of understanding, the specific process of the embodiment of the present invention will be described below. Please refer to Figure 1 An embodiment of the data governance risk early warning method based on big data mining in an embodiment of the present invention includes:

[0027] 101. Obtain the metadata change log of the data governance platform, the multi-level dependency relationship graph of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling:

[0028] The physical layer maps the physical connection topology between storage devices to generate a node load fluctuation matrix;

[0029] The logical layer analyzes the data relationship chain to construct a dependency weight matrix;

[0030] The behavior layer extracts the spatio-temporal characteristics of user access to form an association frequency matrix;

[0031] Couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hypernetwork topology structure with timestamp marks;

[0032] It can be understood that the execution subject of the present invention can be a data governance risk warning device based on big data mining, or a terminal or a server, and specific limitations are not made here. In the embodiments of the present invention, the server is taken as the execution subject for illustration.

[0033] It should be noted that in the scenario of meteorological and ocean data governance, the three-dimensional network fusion modeling can be specifically implemented as follows:

[0034] Data collection and preprocessing, metadata change log: Extract the metadata change records of the past 30 days from the data governance platform, including data table structure changes (field addition and deletion, permission adjustment), backup policy updates (backup period adjusted from daily to hourly), etc., to form a time series log. Example: 2025-03-15 14:00 | Table A permission change | Operator: admin | Affected backup policy ID: B001.

[0035] Multi-level dependency relationship graph: Analyze the dependency chain in the meteorological and ocean data management system:

[0036] The storage of data table B depends on physical device nodes N1 and N3;

[0037] The permission configuration table C is associated with the access policies of user groups G1 and G2;

[0038] The backup task D depends on the availability of the storage device N2.

[0039] Real-time access behavior data: Collect user access records (user U1 frequently accesses table A from 08:00 to 12:00, and the IP address location is abnormal) and API call records (service S1 triggers the backup interface 300 times per hour) in the system audit log.

[0040] Hierarchical modeling and matrix generation, physical layer topology and node load fluctuation matrix:

[0041] Device Topology Mapping: Based on the physical connection relationships of storage devices (N1 - N5) (N1 and N2 are directly connected by fiber optic), construct a 5×5 adjacency matrix, and mark the bandwidth and latency parameters between devices.

[0042] Load Fluctuation Calculation: Collect the CPU, memory, and storage utilization rates of devices every 5 minutes, and generate a load fluctuation matrix:

[0043] N1: [0.72, 0.68, 0.75, ..., 0.81] / / 24-hour load sequence

[0044] N2: [0.35, 0.41, 0.38, ..., 0.50]

[0045] Logical Layer Dependency Weight Matrix: Data Relationship Chain Analysis: Model the dependency relationships of permissions, backups, and storage through a graph database (Neo4j), and the weight assignment rules are as follows:

[0046] Master Data Dependency: The dependency weight between Table A and Backup Policy B001 is 0.8 (strong dependency);

[0047] Cross-System Dependency: The weight between Permission Configuration Table C and User Group G1 is 0.6 (medium dependency);

[0048] Redundant Dependency: The mirror backup weight between Device N1 and N3 is 0.3 (weak dependency).

[0049] Matrix Example:

[0050] Device N1 → Table A: 0.9 | Table A → Backup B001: 0.8 | User G1 → Table C: 0.6;

[0051] Behavior Layer Association Frequency Matrix, Spatiotemporal Feature Extraction: Statistically analyze the spatiotemporal distribution of user accesses (the access frequency of User U1 to Table A is 50 times per hour from 08:00 to 12:00), and combine with the IP location (the proportion of off-site logins is 30%) to generate a spatiotemporal association matrix:

[0052] User U1 → Table A: Time Density = 0.85 | Spatial Anomaly Index = 0.72;

[0053] Service S1 → Backup Interface: Call Frequency = 300 times per hour;

[0054] Normalization Processing: Normalize metrics such as frequency and anomaly index to values between 0 and 1 to form a 5×5 association matrix.

[0055] Dynamic weight coupling and hypernetwork generation, weight allocation mechanism: Dynamically adjust the three-layer weights according to real-time risk scenarios (initial values: physical layer 40%, logical layer 35%, behavioral layer 25%). When a sudden increase in the load of device N1 is detected (fluctuation > 0.8), the weight of the physical layer is increased to 50%.

[0056] Hypernetwork construction: Align the three-layer matrices according to the timestamp and couple them into a weighted hyperedge network. The hypernetwork nodes at a certain moment include:

[0057] Physical nodes: N1 (load 0.81), N2 (load 0.50);

[0058] Logical nodes: Table A (dependency weight 0.8), backup B001;

[0059] Behavioral nodes: User U1 (anomaly index 0.72).

[0060] Output structure: Generate a three-dimensional hypernetwork topology in JSON format, mark the timestamp (2025-03-15T14:00:00Z), including node attributes, edge weights, and hierarchical mapping relationships.

[0061] 102. Based on the three-dimensional hypernetwork topology structure, obtain the load balance degree of physical layer devices, the integrity score of the logical layer management system, and the abnormal access index of the behavioral layer. Construct a composite energy field model, use an improved diffusion mapping algorithm to generate an energy gradient field, and monitor the change of the energy surface curvature in real time. When the curvature acceleration in a local area is detected to exceed 3 times the standard deviation of the historical baseline, mark it as a phase transition critical area and output the coordinate set to obtain the coordinate set of the phase transition critical area;

[0062] It should be noted that in the scenario of meteorological and ocean data governance, the implementation of step 102 can be combined with the following specific data and modeling processes: Input of three-dimensional hypernetwork topology:

[0063] Set the three-dimensional hypernetwork topology of a certain meteorological and ocean data governance platform to include the following structure (timestamp: 2025-03-15T14:00:00Z):

[0064] Physical layer: 5 storage devices (N1 - N5), directly connected by optical fibers between devices. The standard deviation of the CPU utilization rate of N1 in the load fluctuation matrix is 0.15 (baseline 0.1), and the standard deviation of N2 - N5 is ≤0.08.

[0065] Logical layer: The dependency weight matrix shows that the weights of data table A and backup strategy B001 are 0.9, the weights of permission configuration table C and user group G1 are 0.7, and the dependency weight of backup task D on device N2 is 0.4.

[0066] Behavior layer: User U1 accessed Table A 200 times per hour (baseline: 50 times) between 08:00 - 12:00, with an abnormal IP location rate of 30% (baseline: 5%). The spatio-temporal anomaly index of U1→Table A in the associated frequency matrix is 0.68.

[0067] Calculation of hierarchical metrics, physical layer device load balancing degree, calculation logic: Based on the node load fluctuation matrix, calculate the difference rate of load standard deviation between devices.

[0068] Example data: The standard deviation of the load fluctuation of N1 is 0.15 (historical baseline: 0.1), exceeding the baseline by 50%; the average standard deviation of N2 - N5 is 0.06. The load balancing degree scoring formula is:

[0069] (Full score: 1)

[0070] Scoring of the integrity of the logical layer management system, evaluation dimensions: data backup integrity (weight: 40%), permission consistency (weight: 30%), redundancy degree of the dependency chain (weight: 30%).

[0071] Example data: Backup completion rate is 95% (Table A backup completion rate is 100%, 5% of Table C is missing due to the failure of device N3); permission configuration consistency is 98% (there are 2% redundant permissions in user group G2);

[0072] Scoring result: 0.95×0.4 + 0.98×0.3 + 0.97×0.3 = 93 points (full score: 100).

[0073] Behavior layer abnormal access index, algorithm: Based on the associated frequency matrix, combined with spatio-temporal features (sudden increase in frequency, off-site login), construct a Gaussian kernel density model to calculate the Z value deviating from the normal distribution.

[0074] Example data: The Z value of user U1 is 3.2 (threshold: 2.5), and the abnormal index is 3.2 / 5 = 0.64 (normalized to 0 - 1).

[0075] Composite energy field modeling, energy field construction, parameter fusion: Map the hierarchical metrics to the three-dimensional coordinates of the energy field: X-axis: physical layer balancing degree (0.85) → device load potential energy; Y-axis: logical layer integrity (0.93) → system structure potential energy; Z-axis: behavior layer abnormal index (0.64) → access behavior potential energy.

[0076] Improved diffusion mapping algorithm: Introduce a time decay factor (current time weight: 0.7, historical data weight: 0.3) to generate an energy gradient field.

[0077] Example energy surface equation:

[0078]

[0079] Curvature acceleration detection, dynamic baseline: The average value of the curvature acceleration of the energy surface in the past 30 days is 0.12, and the standard deviation is 0.03.

[0080] Anomaly determination: When the curvature acceleration in a certain area reaches 0.12 + 3×0.03 = 0.21, a mark is triggered.

[0081] Example result: The curvature acceleration of the associated area between device N1 and user U1 is 0.25, marked as the phase transition critical area, and the output coordinate set is (N1, Table A, U1).

[0082] 103. According to the coordinate set of the phase transition critical area, trace the potential energy decay path in the opposite direction of the energy gradient, combine the physical layer topology structure and the logical layer dependency relationship, identify the conduction characteristics across devices - data - applications, and generate a cross - layer risk conduction path map containing the sequence of transition nodes and the conduction intensity index;

[0083] It should be noted that in the meteorological and oceanographic data governance scenario, the coordinate set of the phase transition critical area: The coordinate set marked as the high - risk area is (N1, Table A, U1), corresponding to the physical layer storage device N1 (load fluctuation standard deviation 0.15), the logical layer data table A (depending on backup strategy B001, weight 0.9), and the behavioral layer user U1 (abnormal access frequency 200 times / hour, IP abnormality rate 30%).

[0084] Energy gradient field data: In the composite energy field model, the potential energy decay direction of device N1 points to the logical layer data table A (the opposite direction of the energy gradient is N1 → Table A → Backup B001).

[0085] Potential energy decay path tracing, physical layer topology analysis, device connection relationship: Device N1 is directly connected to N3 through an optical fiber (bandwidth 10 Gbps), and N3 is the main storage node of backup task D (dependency weight 0.8).

[0086] Load conduction characteristics: The high load fluctuation of N1 (standard deviation 0.15) is transmitted to N3 through the physical link, resulting in the CPU utilization rate of N3 rising from the baseline of 40% to 65%.

[0087] Logical layer dependency chain parsing, data relationship chain: Table A → Backup B001 → Backup task D → Service S1 (meteorological warning API), with dependency weights of 0.9, 0.8, and 0.7 respectively. Conduction intensity calculation: The conduction intensity along the path Table A → Backup B001 → Backup task D is the product of the weights (0.9×0.8×0.7 = 0.504), indicating the amplification effect of logical dependencies on risks.

[0088] Abnormal conduction at the behavioral layer, user access path: The abnormal access of user U1 (200 times / hour) triggers frequent changes in the metadata of Table A, resulting in a sharp increase in the log write volume of backup B001 (the daily average log volume increases from 1 GB to 5 GB). Spatiotemporal correlation conduction: The abnormal IP of U1 (the abnormal rate of the location is 30%) overlaps with the geographical location of storage device N3 of backup task D, forming a cross-layer spatiotemporal correlation (the geographical conduction intensity is 0.45).

[0089] Generation of cross-layer risk conduction path, transition node sequence: The tracking path is user U1 → Table A → device N1 → backup B001 → device N3 → service S1, and the conduction intensity indicators between nodes are as follows:

[0090] U1 → Table A: Abnormal behavior index (0.68) × access frequency weight (0.6) = 0.408;

[0091] Table A → N1: Logical dependency weight (0.9) × physical load contribution degree (0.15 / 0.1 = 1.5) = 1.35;

[0092] N1 → backup B001: Device load conduction (N1 load fluctuation 0.15 × dependency weight 0.8) = 0.12;

[0093] Backup B001 → N3: Backup task dependency weight (0.8) × device N3 load growth rate (25%) = 0.2;

[0094] N3 → service S1: Service response delay (from 50 ms to 120 ms) × weight (0.7) = 0.49;

[0095] Conduction path map: Integrate the above indicators to generate a cross-layer path map, and mark the key conduction nodes (N1, backup B001) and the intensity threshold (>0.3 is a high-risk link).

[0096] 104. Perform a spatial convolution operation on the set of coordinates of the phase transition critical region and the cross-layer risk conduction path map. According to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, dynamically trigger hierarchical early warnings: Generate a red early warning instruction when the path covers ≥3 key nodes; Generate an orange early warning instruction when the conduction intensity > 80% of the historical peak; Generate a yellow early warning instruction when the daily growth rate of the influence radius > 200%; Output a set of disposal instructions with topological coordinates to the data isolation system and the traffic scheduling device;

[0097] It should be noted that in the scenario of meteorological and ocean data governance, the coordinate set of the phase transition critical region: the coordinate set marked as the high-risk region is (N1, Table A, U1), corresponding to the physical layer storage device N1 (standard deviation of load fluctuation 0.15), the logical layer data table A (depending on backup strategy B001, weight 0.9), and the behavioral layer user U1 (abnormal access frequency 200 times / hour, IP abnormality rate 30%).

[0098] Cross-layer risk conduction path map: The path is User U1 → Table A → Device N1 → Backup B001 → Device N3 → Service S1. The conduction intensity indicators include: U1 → Table A: 0.408 (behavioral layer abnormality index × access weight); Table A → N1: 1.35 (logical dependence × physical load contribution degree); N1 → Backup B001: 0.12 (load fluctuation × dependence weight); Backup B001 → Device N3: 0.2 (dependence weight × load growth rate 25%); Device N3 → Service S1: 0.49 (delay growth × weight).

[0099] Spatial convolution operation and parameter calculation, spatial convolution kernel design, three-dimensional convolution kernel: Based on the three-dimensional topological structure of the device, data, and behavioral layers, a 5×5×5 convolution kernel is designed. The weight distribution rule:

[0100] Weight of the physical layer device node: 0.4 (load fluctuation of device N1 is 0.15);

[0101] Weight of the logical layer data dependence: 0.3 (weight of backup B001 is 0.8);

[0102] Weight of the behavioral layer abnormality index: 0.3 (abnormality index of user U1 is 0.68).

[0103] Convolution operation: Superimpose the phase transition region coordinates (N1, Table A, U1) with the conduction path map, and calculate the eigenvalue of the overlapping region.

[0104] Example output: After convolution, the number of key nodes covered by the conduction path is 4 (N1, Table A, Backup B001, Device N3), the relative value of the conduction intensity is 0.504 (product of the logical dependence chain), and the daily growth rate of the influence radius is 220% (the load of device N3 increases from 40% to 65%).

[0105] Trigger conditions for hierarchical early warning:

[0106] Red early warning (covering ≥ 3 key nodes): The current path covers 4 key nodes (N1, Table A, Backup B001, Device N3), triggering a red early warning.

[0107] Orange Alert (Conduction Intensity > 80% of Historical Peak): The historical peak conduction intensity is 0.6 (baseline of typhoon warning model), and the current value is 0.504 (84% of the peak), triggering an orange alert.

[0108] Yellow Alert (Daily Growth Rate of Influence Radius > 200%): The daily growth rate of the influence radius of device N3 load is 220%, triggering a yellow alert.

[0109] Disposal Instruction Generation and Execution, Topological Coordinate Mapping: Map the warning area to physical layer devices (N1, N3), logical layer data (Table A, Backup B001), and behavioral layer users (U1).

[0110] Instruction Set Example:

[0111] Data Isolation System: Cut off user U1's access permission to Table A and freeze the metadata change of Backup B001 (to prevent the spread of abnormal backups).

[0112] Traffic Scheduling Device: Shunt the load of device N1 to N2 (standard deviation of load fluctuation is 0.08), and limit the API call frequency of service S1 to 100 times per minute.

[0113] Backup Strategy Adjustment: Temporarily switch the dependency of Backup B001 from device N3 to N5 (standard deviation of load is 0.06), and start the incremental backup mode (to reduce the amount of log writing).

[0114] In the embodiments of the present invention, data in three dimensions of the physical layer, the logical layer, and the behavioral layer are fused and modeled to form a comprehensive three-dimensional hypernetwork topology; a composite energy field model based on the three-dimensional hypernetwork topology is proposed, and an improved diffusion mapping algorithm is used to generate an energy gradient field to monitor the change of the energy surface curvature in real time; not only the risk areas are identified, but also the conduction paths of risks between the physical layer, the logical layer, and the behavioral layer are further traced, and a cross-layer risk conduction path map is generated; according to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, a hierarchical early warning mechanism is dynamically triggered. Through the three-dimensional network fusion modeling and the composite energy field model, the state of the data governance system can be more comprehensively reflected, and the accuracy of risk early warning can be improved; by monitoring the change of the energy surface curvature in real time and tracing the cross-layer risk conduction path, potential security risks can be discovered and disposed of in time, and the security of the system can be enhanced; through the hierarchical early warning mechanism and the disposal instruction set, the resource allocation can be dynamically adjusted according to the actual situation, the system performance can be optimized, and the resource utilization rate can be improved; this method provides comprehensive risk monitoring and early warning means, enabling managers to understand the system state in time, quickly respond to risk events, and improve the management efficiency. In summary, through the innovative three-dimensional network fusion modeling, composite energy field model, cross-layer risk conduction path map, and hierarchical early warning mechanism, this technology provides a new solution for the monitoring and early warning of data governance risks.

[0115] Please refer to Figure 2 , another embodiment of the data governance risk early warning method based on big data mining in the embodiments of the present invention includes:

[0116] 201. Obtain the metadata change log of the data governance platform, the multi-level dependency relationship map of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling: map the physical connection topology between storage devices in the physical layer to generate a node load fluctuation matrix; analyze the data relationship chain in the logical layer to construct a dependency weight matrix; extract the spatio-temporal characteristics of user access in the behavioral layer to form an association frequency matrix; couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hypernetwork topology structure with timestamp marks;

[0117] Specifically, based on the hardware topology database of the data center (physical connection relationship of storage devices) and the real-time device load monitoring data stream (SNMP protocol data from the device management system), analyze the physical connection topology between storage nodes, construct an initial adjacency matrix, dynamically adjust the connection weight based on the load fluctuation variance, generate a node load fluctuation matrix with time window marks, and obtain the dynamic adjacency matrix of the physical layer (the matrix element value is the connection weight between devices, and the weight value is dynamically updated with the load fluctuation)

[0118] Parse the multi-level data management system dependency chain based on the data management system relationship graph (JSON format output from the management system) and the metadata change time series record (change log from the data governance platform), construct an initial directed graph, calculate the dependency strength according to the metadata change frequency, generate a dependency weight matrix, and obtain the logical layer dependency weight matrix (the matrix rows represent upstream data entities, the columns represent downstream dependent parties, and the element values are dependency strength coefficients).

[0119] Based on the user access audit log (from the system security audit module) and the geospatial location database (GPS / IP location data from the access terminal), statistically analyze the spatio-temporal distribution characteristics of access behaviors within a unit time, construct an association frequency matrix reflecting the anomaly degree of the access pattern, and obtain the behavior layer association frequency matrix (the matrix element values represent the cross-regional access association strength, and abnormal access patterns correspond to low frequency values).

[0120] Based on the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the behavior layer association frequency matrix, establish cross-layer connection rules: the mapping relationship between physical layer devices and logical layer data entities, and the association rules between logical layer data entities and behavior layer access patterns;

[0121] Implement dynamic weight adjustment: Adjust the cross-layer connection strength every 5 minutes according to the device load, lineage change frequency, and access anomaly index;

[0122] Embed a timestamp marking mechanism: Record the version sequence of the network structure evolution over time;

[0123] Obtain a three-dimensional hypernetwork topology structure with timestamp markings (including the coupling connection relationship and version evolution history of the physical-logical-behavior layers).

[0124] It should be noted that an e-commerce platform has deployed a distributed storage cluster (physical layer), which includes 6 storage nodes (S1 - S6), carrying core data entities such as user portrait tables and order tables (logical layer), and processes access requests from operation personnel in 20 provinces daily (behavior layer). The system realizes the three-dimensional network fusion through the following methods:

[0125] Construction of the physical layer dynamic adjacency matrix. According to the hardware topology database, the initial connection topology is: S1 ↔ S2 (bandwidth 10G), S3 ↔ S4 (bandwidth 20G), S5 ↔ S6 (bandwidth 10G). Through real-time monitoring by the SNMP protocol, it is found that during the period from 11:00 to 11:05: the load variance of S1 reaches 35% (historical average 15%), and the load variance of S2 is 28%; Dynamically adjust the connection weight: the weight of S1 - S2 is reduced from 0.8 to 0.5; Add an emergency connection between S2 - S5 (bandwidth 5G), with an initial weight value of 0.3; Generate a matrix with time window markings, where the row vector of S2 is [0.5, 0, 0, 0, 0.3, 0];

[0126] The logic layer depends on the generation of the weight matrix. By parsing the JSON-format blood relationship graph, it is found that the user portrait table (D1) is simultaneously depended on by the recommendation system (D2) and the advertising model (D3). The metadata change log shows that D1 is updated 3 times per hour, and D2 is synchronized once every 2 hours. Calculate the dependency strength: the coefficient of D1→D2 = 0.9 (strong dependency with high-frequency changes), and the coefficient of D1→D3 = 0.6; the value in the D1 row and D2 column in the matrix is 0.9, and the value in the D3 column is 0.6. The value for the items without direct dependency is 0;

[0127] For the calculation of the behavior layer association frequency matrix, the audit log shows that the access terminal with the IP address in Beijing accesses D2 120 times per hour (baseline 100 times) during the working hours (9:00 - 18:00); the access from the Guangdong IP to D3 suddenly reaches 50 times at 2 am (historical same period ≤ 5 times); the results of spatio-temporal anomaly detection: the association strength of the Beijing terminal is 0.8 (normal), and the association strength of the Guangdong terminal is 0.2 (low-frequency anomaly); the Guangdong IP row and D3 column in the matrix are marked as 0.2;

[0128] Cross-layer coupling and dynamic adjustment, establish mapping rules: the physical node S1 stores the logical entity D1; the logical entity D2 is frequently accessed by the Beijing IP;

[0129] Perform weight update every 5 minutes: when the change frequency of D1 exceeds the threshold by +20%, increase the connection weight between S1 - S2 to 0.7; if the abnormal access from the Guangdong IP lasts for 2 cycles, reduce its association weight with D3 to 0.1; generate a three-dimensional network of version V2.3, with the timestamp 2025-03-29 11:05:00;

[0130] This model forms a traceable and evolving hyper-network topology by dynamically coupling the three-dimensional features of device load, data blood relationship, and access behavior, providing a basis for subsequent risk early warning.

[0131] 202. Based on the three-dimensional hyper-network topology structure, obtain the load balance degree of physical layer devices, the integrity score of the logic layer management system, and the abnormal access index of the behavior layer. Construct a composite energy field model, use an improved diffusion mapping algorithm to generate an energy gradient field, and monitor the change of the energy surface curvature in real time. When it is detected that the curvature acceleration in a local area exceeds 3 times the standard deviation of the historical baseline, mark it as a phase transition critical area and output the coordinate set, obtaining the coordinate set of the phase transition critical area;

[0132] Specifically, based on the physical layer dynamic adjacency matrix in the three-dimensional hyper-network topology structure, analyze the dynamic change sequence of the connection weights between storage nodes, calculate the node load fluctuation variance and the load correlation of adjacent nodes, generate a scoring matrix reflecting the load balance state between devices, and obtain the physical layer load balance degree matrix (the matrix element value is the load coordination coefficient between devices, 0 ≤ coefficient ≤ 1);

[0133] Based on the logical layer dependency weight matrix in the three-dimensional hypernetwork topology structure, trace the complete hierarchical structure of the data relationship chain, detect the coverage rate of metadata change records in the dependency path, calculate the integrity decay index of the management system chain, and obtain the integrity score matrix of the logical layer management system (the rows of the matrix represent data entities, the columns represent integrity dimensions, and the element values are scoring values from 0 to 100);

[0134] Based on the behavior layer association frequency matrix in the three-dimensional hypernetwork topology structure, compare the spatio-temporal distribution differences between the real-time access pattern and the historical benchmark, detect the access aggregation phenomenon in unconventional time periods and unconventional geographical regions, and quantify the deviation degree of abnormal access behavior to obtain the abnormal access index vector of the behavior layer (the vector element values are the abnormal probability values of each access terminal, ranging from 0 to 1);

[0135] Based on the physical layer load balancing matrix, the integrity score matrix of the logical layer management system, and the abnormal access index vector of the behavior layer, establish an energy value calculation rule:

[0136] Physical energy component = load balancing coefficient × device health index

[0137] Logical energy component = blood relationship integrity score × data freshness factor

[0138] Behavior energy component = 1 - abnormal access index

[0139] Adopt an improved diffusion mapping algorithm: introduce topological constraint conditions to limit the energy diffusion path and dynamically adjust the diffusion coefficient to adapt to the changes in the network structure; obtain a three-dimensional composite energy field model (a three-dimensional tensor containing energy scalar values, gradient direction vectors, and diffusion rates);

[0140] Based on the three-dimensional composite energy field model and the historical normal state energy field database (storing the benchmark energy distribution in the past 30 days), calculate the Gaussian curvature distribution of the energy surface in real time and compare the current curvature change acceleration with the historical baseline statistical characteristics

[0141] When the local area satisfies:

[0142] |Second derivative of curvature| > historical mean + 3×standard deviation

[0143] Mark it as a phase transition critical area, and obtain the coordinate set of the phase transition critical area (including the center coordinates of the area, the influence radius, and the curvature mutation intensity value).

[0144] It should be noted that an e-commerce platform has deployed 6 storage nodes (S1 - S6), among which S1 - S3 carry the user portrait table (D1), and S4 - S6 store the order table (D2). The system realizes composite energy field modeling and phase transition detection through the following process:

[0145] Physical layer load balancing degree calculation, through SNMP monitoring, it is found that: the load fluctuation variances of S1 and S2 are 38% and 25% respectively (historical average value of 15%); the load correlation between nodes: S1 - S2 = 0.72 (strong correlation), S4 - S5 = 0.91 (overload risk);

[0146] Generate a load balancing matrix: the row vector of S1 is [0, 0.65, 0, 0, 0, 0] (the load coordination coefficient between S1 - S2 is reduced to 0.65 due to the variance exceeding the standard);

[0147] Logical layer blood relationship integrity assessment, the blood relationship dependency chain analysis of the order table (D2) shows that: the coverage rate of field changes depending on the user portrait table (D1) is 85% (missing the update record of the address field); the metadata change frequency: D1 is updated 3 times per hour, and D2 is only synchronized once; in the blood relationship integrity scoring matrix, the score of the D2 row and D1 column is 75 points (full score of 100), and the data freshness factor is 0.8;

[0148] Behavior layer abnormal access detection, through audit logs, it is found that: Guangdong IP accesses D2 intensively up to 50 times per minute at 2 am (baseline of 5 times); Beijing IP accesses D1 more frequently than the threshold by 120% during working hours; in the abnormal access index vector, the index corresponding to Guangdong IP for D2 is 0.92, and the index corresponding to Beijing IP for D1 is 0.3;

[0149] Composite energy field construction, according to the energy calculation rules: physical energy: the section of S1 - S2 = 0.65×0.7 (equipment health index) = 0.455; logical energy: the section of D2 - D1 = 75×0.8 = 60; behavioral energy: 1 - 0.92 = 0.08 (Guangdong IP accesses D2);

[0150] Through an improved diffusion algorithm, set topological constraints: the diffusion path of the order data nodes (S4 - S6) preferentially conducts along the transaction link, and dynamically adjusts the diffusion coefficient of the relevant nodes of D2 to 1.2 times the benchmark value.

[0151] Phase transition critical area identification, at 11:05, it is monitored in the order processing area (coordinates X = 4, Y = 5, Z = 2): the second derivative of the energy curvature reaches 8.7 (historical average value of 2.1±1.3); the curvature acceleration exceeds 3 times the standard deviation threshold; the system marks this area as the phase transition critical area, and the coordinate set includes the S4 node, the D2 entity, and the associated Guangdong IP terminal, and the influence radius covers 3 transaction database nodes.

[0152] This model accurately locates the cross - layer risk conduction source caused by abnormal order access by quantifying the energy interaction of device load, data blood relationship, and access behavior, providing a decision - making basis for subsequent risk path tracking.

[0153] 203. According to the set of coordinates of the phase transition critical region, trace the potential energy decay path in the reverse direction of the energy gradient, combine the physical layer topology structure and the logical layer dependency relationship, identify the conduction characteristics across devices-data-applications, and generate a cross-layer risk conduction path map containing the sequence of transition nodes and the conduction intensity index;

[0154] Specifically, based on the set of coordinates of the phase transition critical region and the gradient direction vector data in the three-dimensional composite energy field model, starting from the center point of the phase transition critical region, trace step by step in the negative direction of the energy gradient, and combine the physical layer topology connection rules to constrain the path search range to obtain a preliminary conduction path sequence (including node address, tracking timestamp, energy decay rate);

[0155] Based on the physical layer dynamic adjacency matrix, logical layer dependency weight matrix in the three-dimensional super network topology structure, and the preliminary conduction path sequence, detect the connection points in the path that simultaneously involve physical device nodes and logical data entities, and verify whether the cross-layer connection conforms to the preset mapping rule library to obtain a list of cross-layer transition nodes (marking the three-layer association relationship of device-data entity-application);

[0156] Based on the list of cross-layer transition nodes and the historical normal conduction path database (storing the path records verified in the past 90 days), compare the topological consistency between the current path and the historical normal path, and detect abnormal conduction characteristics: direct connection between non-adjacent devices in the physical layer, breakage of cross-level dependencies in the logical layer; obtain the verified risk conduction path (including path validity mark, abnormal conduction segment positioning);

[0157] Based on the verified risk conduction path and the timestamp version of the three-dimensional super network topology structure, mark the cross-layer attributes (physical device / data entity / application service) of the path nodes, and calculate the conduction intensity index:

[0158] Physical segment intensity = reciprocal of the variance of device load fluctuation

[0159] Logical segment intensity = attenuation rate of blood relationship integrity score

[0160] Behavior segment intensity = increment of abnormal access index

[0161] Obtain a cross-layer risk conduction path map (including the node sequence with intensity annotation, cross-layer transition point coordinates, time evolution mark).

[0162] It should be noted that an e-commerce platform detected that the order processing area (coordinates X = 4, Y = 5, Z = 2) is a phase transition critical area, and the curvature mutation intensity reaches 8.7 (historical baseline 2.1 ± 1.3), and the system starts to trace the risk conduction path:

[0163] Path tracing and cross-layer verification start from the S4 storage node (physical layer) and discover the conduction path along the negative direction of the energy gradient: S4 → D2 (order form entity) → Guangdong IP terminal (behavior layer);

[0164] Verify the cross-layer mapping rules: The S4 physical node indeed stores the D2 order form (complies with the device-data mapping rule); The D2 order form is frequently accessed by the Guangdong IP terminal (association rule anomaly: this IP has no historical access record);

[0165] Conduction feature detection, physical layer anomaly: The load variance between S4 and S5 reaches 45% (normal value < 20%), resulting in a sudden direct connection between non-adjacent nodes S4 - S3; Logical layer break: The blood relationship integrity score of the D2 order form for the D1 user portrait drops from 80 points to 60 points (field-level dependency loss); Behavior layer anomaly: The anomaly index of the Guangdong IP accessing D2 reaches 0.92 (baseline 0.05), with a single-day increment of 0.87;

[0166] Conduction intensity calculation, physical segment intensity: 1 / 0.45 = 2.22 (reciprocal of the load fluctuation variance of S4); Logical segment intensity: (80 - 60) / 80 = 25% (blood relationship integrity attenuation rate); Behavior segment intensity: 0.92 - 0.05 = 0.87 (anomaly index increment);

[0167] Path graph generation, generate a conduction path with intensity markings: Node sequence: S4 (physical) → D2 (logical) → Guangdong IP (behavior);

[0168] Cross-layer transition points: S4 - D2 transition coordinates (X = 4.2, Y = 5.1, Z = 2.3), conduction intensity peak 2.22; D2 - Guangdong IP transition coordinates (X = 4.5, Y = 5.3, Z = 2.8), conduction intensity peak 0.87;

[0169] Time evolution markings: The abnormal load of S4 was first detected at 02:15 on March 29, 2025; The blood relationship score of D2 began to decay at 02:28; The behavior layer alarm was triggered by the Guangdong IP at 02:35;

[0170] This graph shows that the risk conducts from the physical device overload (S4 node) to the logical layer data blood relationship break (field-level dependency loss of the D2 order form), and finally manifests as abnormal regional access (illegal pulling of order data by the Guangdong IP). Based on this, the platform locks the risk source as the D2 data service degradation caused by the hardware overload of the S4 node, and associates it with the data scraping behavior during the vulnerable period of the black production exploitation system.

[0171] 204. Perform a spatial convolution operation on the set of phase transition critical region coordinates and the cross-layer risk conduction path graph, and dynamically trigger hierarchical early warnings according to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate:

[0172] Generate a red warning instruction when the path coverage ≥ 3 critical nodes;

[0173] Generate an orange warning instruction when the conduction intensity > 80% of the historical peak;

[0174] Generate a yellow warning instruction when the daily growth rate of the influence radius > 200%;

[0175] Output a disposal instruction set with topological coordinates to the data isolation system and the traffic scheduling device;

[0176] Specifically, according to the phase transition critical region coordinate set (including the region center coordinates and the influence radius), the cross-layer risk conduction path map (including the node sequence and the conduction intensity index), and the list of critical infrastructure nodes (from the system configuration database), map the phase transition region to a spatial risk heat map, generate a risk propagation vector field along the conduction path, perform a spatial convolution operation, and generate a risk superposition map (marking the peak area of risk intensity, the conduction direction, and the critical node coverage mark);

[0177] According to the risk superposition map and the historical peak database (storing the risk conduction intensity records of the past 365 days), extract the current conduction intensity value, calculate the percentage relative to the historical peak, monitor the daily growth rate of the influence radius of the phase transition region, and count the number of critical infrastructure nodes covered by the conduction path to obtain a set of dynamic threshold parameters (including the relative intensity value, the growth rate, and the number of critical nodes);

[0178] According to the set of dynamic threshold parameters and the system's preset warning rule library (storing the classification judgment criteria), when both conditions are met: the number of critical node covers ≥ 3 and there is a conduction path across the physical layer - logical layer, the red warning is triggered;

[0179] When the following conditions are met: the relative conduction intensity value > 80% of the historical peak and the influence radius growth rate > 150% / day, the orange warning is triggered;

[0180] When the following conditions are met: the daily growth rate of the influence radius > 200% and there is a conduction path that does not cover critical nodes, the yellow warning is triggered;

[0181] Obtain a hierarchical warning instruction code set (including the warning level, the trigger condition code, and the timestamp);

[0182] According to the hierarchical warning instruction code set, the node coordinate data in the three-dimensional hypernetwork topology structure, and the data governance operation rule library (storing the preset disposal strategies), match the disposal strategies according to the warning level:

[0183] Red instruction: Execute data isolation + traffic cut-off;

[0184] Orange instruction: Implement access rate limiting + backup trigger;

[0185] Yellow instruction: Start monitoring enhancement + log tracking;

[0186] Convert the policy into topological coordinate operation instructions to obtain a topological coordinate disposal instruction set (including the target device IP list, data entity ID set, operation command code);

[0187] According to the topological coordinate disposal instruction set, the data isolation system API interface, and the traffic scheduling device control protocol, distribute the instructions to the target system through the standard protocol format, and collect the instruction execution status code and effect indicators in real time to obtain the instruction execution feedback log (including success / failure flag, execution delay, status change record).

[0188] It should be noted that during the Double Eleven period in 2025, an e-commerce platform detected risk conduction in the payment center area (coordinates X = 7, Y = 9, Z = 5) through a three-dimensional hypernetwork topology structure, and the system performed the following hierarchical warning operations:

[0189] Spatial convolution operation and risk superposition, the influence radius of the phase transition area reaches 300 meters, covering 3 key nodes: the payment gateway cluster (PG1 - PG3), the order database (DB_Order), and the user profile server (S_Profile); the conduction path spreads along "PG2 → DB_Order → Shanghai IP terminal", and the path strength reaches 85% of the historical peak (benchmark value: the peak in 2024 is 100 TPS); the daily growth rate of the influence radius is 220% (the radius of the previous day is 137 meters); generate a risk heat map through spatial convolution operation, showing that a peak intensity area (risk value 8.7 / 10) is formed around the PG2 node;

[0190] Dynamic threshold determination, the number of covered key nodes = 3 (triggering the red warning condition); the relative value of the conduction intensity = 85% (triggering the orange warning condition); the daily growth rate of the influence radius = 220% (triggering the yellow warning condition);

[0191] According to the warning rule library, the system simultaneously triggers a combined red (node coverage) and orange (intensity exceeding the standard) warning;

[0192] Generation of topological coordinate disposal instructions, red instruction: Isolate the partition of the DB_Order table associated with the PG2 node (data entity ID: TB_20251110), and cut off the abnormal IP access traffic (target IP list: 192.168.7.22 - 25); orange instruction: Implement 50% request rate limiting on the PG1 / PG3 nodes, and trigger real-time backup of payment data to the disaster recovery center (backup policy ID: BKP_PAY_EMG); yellow instruction: Enable full - volume SQL log tracking for the payment link (log label: PAY_TRACE_1129), and strengthen the access audit of the user profile server;

[0193] Instruction execution and feedback. The data isolation system completed the isolation of Table TB_20251110 within 32 seconds, and the traffic scheduling device intercepted 12,000 abnormal requests per minute; the disaster recovery center received a real-time data stream peak of up to 80 GB / s, and the log system captured 3 abnormal SQL queries (involving unauthorized access to user privacy fields); the system detected that the peak of the risk heat map dropped to 4.2 / 10 within 15 minutes, and the influence radius retracted to 150 meters;

[0194] This case shows that by quantifying the intensity and scope of risk conduction through spatial convolution operations and combining dynamic threshold judgment to achieve precise hierarchical response. The red warning cuts off the core risk source, the orange warning ensures business continuity, and the yellow warning strengthens monitoring and evidence collection, forming a gradient defense system for risk disposal. The platform finally resolved the risk of payment link collapse within 1 hour, avoiding direct economic losses exceeding 230 million yuan.

[0195] 205. Real-time collect the metadata status, management system relationship changes, and access behavior data after instruction execution, and feedback them to the three-dimensional hypernetwork modeling module for dynamic topology update to achieve self-optimizing control of the warning system.

[0196] Specifically, based on the operation logs of the data isolation system (recording the changes in the isolation status of data entities), the status codes of the traffic scheduling device (including the execution results of the flow limiting strategy), and the metadata version control system (recording the new versions after the repair of the lineage relationship), capture the system status changes after instruction execution in real time, and extract key feedback indicators: metadata change coverage rate, lineage repair integrity, access behavior pattern deviation; obtain a closed-loop feedback data set (a structured record containing timestamps, operation types, and status change values);

[0197] Based on the current version of the three-dimensional hypernetwork topology structure, verify whether the physical layer connection adjustment complies with the device security rules, detect whether the repair of the logical layer dependency relationship introduces new loop risks, and analyze whether the change in the access pattern at the behavior layer exceeds the preset tolerance threshold, and obtain a topology update compliance report (marking the network segments allowed for update and the prohibited operation areas);

[0198] Based on the topology update compliance report and the historical version sequence of the three-dimensional hypernetwork topology structure, adjust the physical layer: dynamically update the connection weights according to the device load changes, and set the weights of the devices in the isolation area to zero;

[0199] Adjust the logical layer: increase the effective dependency weights according to the lineage repair results, and decay the weights of the broken dependency edges to 10% of the reference value;

[0200] Adjust the behavior layer: double the rate of decrease of the weights of the associated edges of the abnormal access pattern, and set the initial weights of the newly added legal access paths to the average value;

[0201] Get the optimized three-dimensional super network topology structure (including the physical-logical-behavioral layer weight matrix marked with version numbers);

[0202] Based on the optimized three-dimensional hypernetwork topology structure and the current parameter set of the energy field model, the energy diffusion coefficient is dynamically adjusted according to the topological change, the curvature calculation sensitivity parameter of the phase change detection is updated, and the time window range of the historical baseline database is reset; the adaptive control parameter set (including the diffusion coefficient table, sensitivity parameters, and baseline time window configuration) is obtained;

[0203] Based on the adaptive control parameter set and the system stability test case library (predefined verification scenario set), the risk scenario is replayed in the sandbox environment to verify the update effect. When the risk detection coverage is ≥ 98% and the false alarm rate is ≤ 5%, the new version of the topology and parameters is released to obtain the officially released three-dimensional super network topology version (including version number, effective time, and change log).

[0204] It should be noted that a certain e-commerce platform triggered a red alert during the Double Eleven promotion. After data isolation was performed on the abnormal order table (TB_20251111), the system started the self-optimization process:

[0205] Feedback data collection (2025-11-12 03:00), metadata status: the isolation operation restored the lineage integrity of the TB_20251111 table from 62 points to 85 points (full score 100), covering 12 downstream analysis models; access behavior deviation: Guangdong IP access volume dropped from a peak of 50 times / minute to 5 times, but Beijing IP showed an abnormal increase of 15% (baseline error ±5%); equipment load change: the load variance of the original overloaded node S4 dropped from 45% to 18%, but the load variance of the standby node S7 increased to 28%;

[0206] Topology compliance verification, physical layer conflict: S7 node added a connection weight of 0.8 (preset security threshold 0.7), triggering an alarm; logical layer loop: the user portrait table (D1) and the order table (D2) formed a new dependency loop (after repair, the score was 85→70); behavior layer deviation: the abnormal index increment of Beijing IP access to D2 was 0.15 (tolerance threshold 0.1);

[0207] Dynamic adjustment implementation: Physical layer: reduce the weight of S7 node from 0.8 to 0.65, and reset the weight of isolated node S4 to zero; Logical layer: increase the effective dependency weight of D1→D2 to 0.9, and decay the dependency weight of the broken promotional activity field to 0.1; Behavioral layer: Beijing IP association edge weight decreases by 40% (originally 20%) every day, and the initial weight of the newly added legal access path is set to an average of 0.5;

[0208] Parameter Optimization and Verification, Energy Diffusion Coefficient: adjusted from 1.2 to 1.5 (to adapt to node load changes); Curvature Sensitivity: threshold relaxed from 3σ to 2.8σ (to reduce false alarms); Historical Baseline Window: adjusted from 30 days to 15 days (to cope with data characteristic changes after promotions);

[0209] Simulate historical risk scenarios in the sandbox environment: Risk detection coverage rate 98.7% (previously 97.2%); False alarm rate 3.1% (4.8% before optimization);

[0210] Version Release (V3.5), after the new topology takes effect: The expansion rate of the influence radius drops from 220% / day to 75% / day; The peak value of the cross-layer conduction intensity drops by 62%;

[0211] Change Log Record:

[0212] Version Number: V3.5_20251112

[0213] Effective Time: 2025-11-12 06:00

[0214] Major Changes:

[0215] Physical Layer: S4 Isolation / S7 Weight Optimization

[0216] Logical Layer: Repair of D1-D2 Dependency Loop

[0217] Behavioral Layer: Upgrade of Beijing IP Monitoring Strategy

[0218] This closed-loop mechanism drives model iteration through real-time feedback, enabling the system to complete the entire process from risk disposal to adaptive optimization within 24 hours, ensuring the continuous evolution of data governance capabilities after major promotions.

[0219] In the embodiments of the present invention, the metadata change log, the lineage graph, and the real-time access behavior data are three-dimensionally fused to construct a hyper-network topology structure including a physical layer, a logical layer, and a behavior layer; by real-time monitoring the device load, the lineage change frequency, and the access anomaly index, the cross-layer connection strength is dynamically adjusted, enabling the model to flexibly adapt to changes in the network structure; embedding timestamps to record the evolution history of the network structure provides precise support in the time dimension for risk early warning and retrospective analysis; using an improved diffusion mapping algorithm to generate an energy gradient field and real-time monitoring the change in the curvature of the energy surface provides a new perspective for risk early warning; by detecting whether the curvature acceleration in a local area exceeds 3 times the standard deviation of the historical baseline, the risk source is accurately located and marked as a phase transition critical area; by calculating the load balance degree of the physical layer, the integrity score of the logical layer management system, and the abnormal access index of the behavior layer, a scientific basis for risk quantification is provided; tracing the potential energy decay path in the opposite direction of the energy gradient, combined with the physical layer topology structure and the logical layer dependency relationship, accurately identifies the conduction characteristics across devices-data-applications; by verifying whether the cross-layer connection conforms to the preset mapping rule library, the accuracy and reliability of the conduction path are ensured; by calculating the conduction strength indicators of the physical segment, the logical segment, and the behavior segment, a basis for prioritizing the risk paths is provided; extracting risk features through spatial convolution operations, considering the three-dimensional association across devices-data-applications, improves the accuracy of risk early warning; according to the number of critical infrastructures covered by the conduction path, the relative value of the conduction strength, and the regional expansion rate, a hierarchical early warning is dynamically triggered, achieving precise control of risks; generating a disposal instruction set with topological coordinates provides a decision-making basis for automatically isolating high-risk transaction links; real-time collecting the system state changes after the execution of the instructions and feeding them back to the three-dimensional hyper-network modeling module for dynamic topology update; performing compliance verification before topology update to ensure that the adjustment complies with device security rules and data governance requirements; dynamically adjusting the energy diffusion coefficient and the curvature calculation sensitivity parameters according to the topology changes to improve the adaptability and accuracy of the model.

[0220] The above describes the data governance risk early warning method based on big data mining in the embodiments of the present invention. Next, the data governance risk early warning device based on big data mining in the embodiments of the present invention will be described. Please refer to Figure 3, an embodiment of the data governance risk early warning device based on big data mining in the embodiments of the present invention includes: an acquisition module 301, configured to acquire the metadata change log of the data governance platform, the multi-level dependency relationship graph of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling: map the physical connection topology between storage devices at the physical layer to generate a node load fluctuation matrix; parse the data relationship chain at the logical layer to construct a dependency weight matrix; extract the spatio-temporal characteristics of user access at the behavior layer to form an association frequency matrix; couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hyper-network topology structure with timestamp marks; a processing module 302, configured to obtain the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index based on the three-dimensional hyper-network topology structure, construct a composite energy field model, generate an energy gradient field, monitor the change of the energy surface curvature in real time, and obtain a set of phase transition critical region coordinates; a setting module 303, configured to trace the potential energy decay path along the reverse direction of the energy gradient according to the set of phase transition critical region coordinates, and combine the physical layer topology structure and the logical layer dependency relationship to generate a cross-layer risk conduction path graph; an allocation module 304, configured to perform a spatial convolution operation on the set of phase transition critical region coordinates and the cross-layer risk conduction path graph, and dynamically trigger hierarchical early warning according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and output a set of disposal instructions.

[0221] In the embodiments of the present invention, through three-dimensional network fusion modeling and a composite energy field model, this technology can comprehensively and accurately monitor and early warn data governance risks, reducing the false alarm rate and missed alarm rate; the modular design enables the system to conveniently expand new functional modules or upgrade existing modules to adapt to the changing data governance requirements; through cross-layer risk conduction path tracing and hierarchical early warning mechanisms, this technology can quickly locate the risk source and generate a set of disposal instructions, improving the efficiency and accuracy of risk disposal; the cross-layer risk conduction path graph and hierarchical early warning instructions provide an intuitive decision-making basis for the data governance team, helping to formulate more scientific and reasonable risk disposal strategies; by real-time monitoring and early warning of data governance risks, this technology helps to ensure the compliance of data governance and reduce the legal risks and reputation losses caused by risks such as data leakage and abuse. In summary, through innovative methods such as modular design, composite energy field model, cross-layer risk conduction path tracing, spatial convolution operation, and hierarchical early warning, this technology provides a comprehensive, accurate, efficient, and scalable solution for data governance risk early warning, with important practical application value and promotion significance.

[0222] Above Figure 3The data governance risk warning device based on big data mining in the embodiments of the present invention is described in detail from the perspective of modular functional entities. Next, the data governance risk warning device based on big data mining in the embodiments of the present invention is described in detail from the perspective of hardware processing.

[0223] Figure 4 FIG. 4 is a schematic structural diagram of a data governance risk warning device based on big data mining provided by an embodiment of the present invention. The data governance risk warning device 400 based on big data mining may vary greatly due to configuration or performance, and may include one or more processors (central processing units, CPUs) 410 (for example, one or more processors) and a memory 420, and one or more storage media 430 for storing application programs 433 or data 432 (for example, one or more mass storage devices). Among them, the memory 420 and the storage media 430 may be transient storage or persistent storage. The program stored in the storage media 430 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the data governance risk warning device 400 based on big data mining. Further, the processor 410 may be configured to communicate with the storage media 430 and execute a series of instruction operations in the storage media 430 on the data governance risk warning device 400.

[0224] The data governance risk warning device 400 based on big data mining may further include one or more power supplies 440, one or more wired or wireless network interfaces 450, one or more input / output interfaces 460, and / or one or more operating systems 431, such as Windows Serve, Mac OS X, Unix, Linux, FreeBSD, and so on. Those skilled in the art can understand that Figure 4 the shown structural diagram of the data governance risk warning device based on big data mining does not limit the data governance risk warning device based on big data mining, and may include more or fewer components than shown, or combine some components, or have different component arrangements.

[0225] The present invention also provides a data governance risk warning device based on big data mining. The data governance risk warning device based on big data mining includes a memory and a processor. When the computer-readable instructions stored in the memory are executed by the processor, the processor executes the steps of the data governance risk warning method in the above embodiments.

[0226] The present invention also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer, the computer is caused to execute the steps of the data governance risk warning method based on big data mining.

[0227] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0228] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0229] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data governance risk early warning method based on big data mining, characterized in that, The data governance risk early warning method based on big data mining includes: Obtain the metadata change log of the data governance platform, the multi-level dependency relationship map of the management system, and the real-time access behavior data of the system audit log, and perform three-dimensional network fusion modeling: The physical layer maps the physical connection topology between storage devices to generate a node load fluctuation matrix; The logical layer analyzes the data relationship chain to construct a dependency weight matrix; The behavior layer extracts the spatio-temporal characteristics of user access to form an association frequency matrix; Couple the three-layer network through a dynamic weight adjustment mechanism, and output a three-dimensional hypernetwork topology structure with timestamp markings; Based on the three-dimensional hypernetwork topology structure, obtain the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index, construct a composite energy field model, generate an energy gradient field, and monitor the change of the energy surface curvature in real time to obtain the coordinate set of the phase transition critical region, including: According to the physical layer dynamic adjacency matrix in the three-dimensional hypernetwork topology structure, analyze the dynamic change sequence of the connection weights between storage nodes, calculate the node load fluctuation variance and the correlation between the load of adjacent nodes, generate a score matrix reflecting the load balance state between devices, and obtain the physical layer load balance degree matrix; According to the logical layer dependency weight matrix in the three-dimensional hypernetwork topology structure, trace the complete hierarchical structure of the data relationship chain, detect the coverage rate of metadata change records in the dependency path, calculate the integrity decay index of the management system chain, and obtain the logical layer management system integrity score matrix; According to the behavior layer association frequency matrix in the three-dimensional hypernetwork topology structure, compare the spatio-temporal distribution differences between the real-time access pattern and the historical benchmark, detect the access aggregation phenomenon in unconventional time periods and unconventional geographical regions, and quantify the deviation degree of abnormal access behavior to obtain the behavior layer abnormal access index vector; Based on the physical layer load balance degree matrix, the logical layer management system integrity score matrix, and the behavior layer abnormal access index vector, establish an energy value calculation rule, and use the diffusion mapping algorithm to obtain a three-dimensional composite energy field model; According to the three-dimensional composite energy field model and the historical normal state energy field database, calculate the Gaussian curvature distribution of the energy surface in real time, compare the current curvature change acceleration with the historical baseline statistical characteristics, and obtain the coordinate set of the phase transition critical region; According to the coordinate set of the phase transition critical region, trace the potential energy decay path in the reverse direction of the energy gradient, and combine the physical layer topology structure and the logical layer dependency relationship to generate a cross-layer risk conduction path map; Perform a spatial convolution operation on the coordinate set of the phase transition critical region and the cross-layer risk conduction path map, and dynamically trigger hierarchical early warnings according to the number of critical infrastructures covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and output a disposal instruction set.

2. The data governance risk warning method based on big data mining according to claim 1, wherein, Including: According to the data center hardware topology database and the real-time device load monitoring data stream, analyze the physical connection topology between storage nodes, construct an initial adjacency matrix, dynamically adjust the connection weights based on the load fluctuation variance, generate a node load fluctuation matrix with time window markings, and obtain the physical layer dynamic adjacency matrix; Parse the multi-level data management system dependency chain based on the data management system relationship graph and the chronological record of metadata changes, construct an initial directed graph, calculate the dependency strength according to the metadata change frequency, generate a dependency weight matrix, and obtain the logical layer dependency weight matrix; Statistically analyze the spatio-temporal distribution characteristics of access behaviors within a unit time based on the user access audit log and the geospatial location database, construct an association frequency matrix reflecting the abnormality degree of the access pattern, and obtain the behavior layer association frequency matrix; Establish cross-layer connection rules, implement dynamic weight adjustment, and embed a timestamp marking mechanism based on the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the behavior layer association frequency matrix to obtain a three-dimensional hypernetwork topology structure with timestamp markings; 3. The data governance risk warning method based on big data mining according to claim 1, wherein Include: Based on the phase transition critical region coordinate set and the gradient direction vector data in the three-dimensional composite energy field model, start from the center point of the phase transition critical region, trace step by step along the negative direction of the energy gradient, and combine the physical layer topology connection rules to constrain the path search range to obtain a preliminary conduction path sequence; Based on the physical layer dynamic adjacency matrix, the logical layer dependency weight matrix, and the preliminary conduction path sequence in the three-dimensional hypernetwork topology structure, detect the connection points in the path that involve both physical device nodes and logical data entities at the same time, and verify whether the cross-layer connection conforms to the preset mapping rule library to obtain a cross-layer transition node list; Based on the cross-layer transition node list and the historical normal conduction path database, compare the topological consistency between the current path and the historical normal path, and detect abnormal conduction characteristics to obtain the verified risk conduction path; Based on the verified risk conduction path and the timestamp version of the three-dimensional hypernetwork topology structure, label the cross-layer attributes of the path nodes, calculate the conduction strength index, and obtain the cross-layer risk conduction path graph; 4. The data governance risk early warning method based on big data mining according to claim 3, characterized in that, Include: Based on the phase transition critical region coordinate set, the cross-layer risk conduction path graph, and the list of critical infrastructure nodes, map the phase transition region to a spatial risk heat map, generate a risk propagation vector field along the conduction path, and perform a spatial convolution operation to generate a risk superposition graph; Based on the risk superposition graph and the historical peak database, extract the current conduction strength value, calculate the percentage relative to the historical peak, monitor the daily growth rate of the influence radius of the phase transition region, and count the number of critical infrastructure nodes covered by the conduction path to obtain a set of dynamic threshold parameters; Based on the set of dynamic threshold parameters and the system's preset warning rule library, obtain a hierarchical warning instruction code set; Based on the hierarchical warning instruction code set, the node coordinate data in the three-dimensional hypernetwork topology structure, and the data governance operation rule library, match the disposal strategy according to the warning level, and convert the strategy into a topological coordinate operation instruction to obtain a topological coordinate disposal instruction set; Based on the topological coordinate disposal instruction set, the data isolation system API interface, and the traffic scheduling device control protocol, distribute the instructions to the target system through the standard protocol format, and collect the instruction execution status code and effect indicators in real time to obtain the instruction execution feedback log; 5. The data governance risk warning method based on big data mining according to claim 4, characterized in that Also include: Real-time collect the metadata status, management system relationship changes, and access behavior data after the instruction execution, and feedback them to the three-dimensional hypernetwork modeling module for dynamic update of the topology structure to achieve self-optimizing control of the warning system.

6. A data governance risk early warning device based on big data mining, characterized in that, The data governance risk early warning device based on big data mining includes: An acquisition module, configured to acquire real-time access behavior data of metadata change logs of a data governance platform, a multi-level dependency relationship graph of a management system, and system audit logs, and perform three-dimensional network fusion modeling: The physical layer maps the physical connection topology between storage devices to generate a node load fluctuation matrix; The logical layer analyzes the data relationship chain to construct a dependency weight matrix; The behavior layer extracts the spatio-temporal characteristics of user access to form an association frequency matrix; The three-layer network is coupled through a dynamic weight adjustment mechanism, and a three-dimensional hypernetwork topology structure marked with a timestamp is output; A processing module, configured to obtain the physical layer device load balance degree, the logical layer management system integrity score, and the behavior layer abnormal access index based on the three-dimensional hypernetwork topology structure, construct a composite energy field model, generate an energy gradient field, and monitor the change of the energy surface curvature in real time to obtain a set of phase transition critical region coordinates, including: According to the physical layer dynamic adjacency matrix in the three-dimensional hypernetwork topology structure, analyze the dynamic change sequence of the connection weights between storage nodes, calculate the node load fluctuation variance and the load correlation of adjacent nodes, generate a score matrix reflecting the load balance state between devices, and obtain the physical layer load balance degree matrix; According to the logical layer dependency weight matrix in the three-dimensional hypernetwork topology structure, trace the complete hierarchical structure of the data relationship chain, detect the coverage rate of metadata change records in the dependency path, calculate the integrity decay index of the management system chain, and obtain the logical layer management system integrity score matrix; According to the behavior layer association frequency matrix in the three-dimensional hypernetwork topology structure, compare the spatio-temporal distribution differences between the real-time access pattern and the historical benchmark, detect the access aggregation phenomenon in unconventional time periods and unconventional geographical regions, and quantify the deviation degree of abnormal access behavior to obtain the behavior layer abnormal access index vector; According to the physical layer load balance degree matrix, the logical layer management system integrity score matrix, and the behavior layer abnormal access index vector, establish an energy value calculation rule, and use the diffusion mapping algorithm to obtain a three-dimensional composite energy field model; According to the three-dimensional composite energy field model and the historical normal state energy field database, calculate the Gaussian curvature distribution of the energy surface in real time, compare the current curvature change acceleration with the historical baseline statistical characteristics, and obtain a set of phase transition critical region coordinates; A setting module, configured to trace the potential energy decay path along the reverse direction of the energy gradient according to the set of phase transition critical region coordinates, and generate a cross-layer risk conduction path map in combination with the physical layer topology structure and the logical layer dependency relationship; An allocation module, configured to perform a spatial convolution operation on the set of phase transition critical region coordinates and the cross-layer risk conduction path map, and dynamically trigger a hierarchical early warning according to the number of critical infrastructure covered by the conduction path, the relative value of the conduction intensity, and the regional expansion rate, and output a set of disposal instructions.

7. A data governance risk early warning device based on big data mining, characterized in that, The data governance risk early warning device based on big data mining includes: a memory and at least one processor, and instructions are stored in the memory; The at least one processor invokes the instructions in the memory to cause the data governance risk warning device based on big data mining to execute the data governance risk warning method based on big data mining according to any one of claims 1-5.

8. A computer-readable storage medium having instructions stored thereon, characterized in that, When the instructions are executed by the processor, the data governance risk warning method based on big data mining according to any one of claims 1-5 is implemented.

Citation Information

Patent Citations

  • Eye health state monitoring and evaluating method and device based on big data

    CN119273659A

  • Predictive risk evaluation in manufacturing system modeling

    JP2024068660A