Financial institution operation and maintenance service automatic management method and system

By cleaning, screening and feature calculation of data increments of financial institutions, a data increment relationship model is built, which solves the problem of inaccurately judging data increment abnormalities in the existing technology, and achieves more efficient data monitoring and abnormal positioning.

CN120067937APending Publication Date: 2025-05-30XIAMEN ZHIHENG RONGXING INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510136692.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing data monitoring technologies for financial institutions cannot fully clean and screen historical data when monitoring the incremental amount of financial institutions, and at the same time, they can accurately determine the location of abnormal data increments in combination with external characteristics.

Method used

By collecting relevant traffic data of financial institutions and data incremental data of servers, performing data cleaning and screening, calculating data incremental characteristics, and building a data incremental relationship model, using this model for abnormal monitoring and positioning analysis.

Benefits of technology

Accurately determine the location of data increment abnormality in data fluctuations, improve the accuracy of data increment abnormality monitoring, and provide operation and maintenance personnel with detailed abnormal information to facilitate problem investigation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120067937A_ABST
    Figure CN120067937A_ABST
Patent Text Reader

Abstract

The invention discloses a financial institution operation and maintenance service automatic management method and system, and relates to the technical field of financial institution data monitoring, and the method comprises the following steps: collecting related human traffic data of a financial institution and incremental data of a financial institution server, and carrying out the data cleaning and screening processing; calculating data increment related characteristics, and constructing a data increment relation model; performing anomaly monitoring on data increment of the financial institution server by using the data increment relation model to obtain anomaly increment data; performing anomaly positioning analysis based on the anomaly incremental data, and positioning the time when the data increment is abnormal; the method is used for solving the problem that when an existing financial institution data monitoring technology is used for monitoring financial institution data increment, historical data cannot be fully cleaned and screened, and meanwhile, the position where data increment abnormity occurs in data fluctuation cannot be accurately judged in combination with some external characteristics closely related to the data increment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of financial institution data monitoring, and specifically to an automated management method and system for the operation and maintenance services of financial institutions. Background Art

[0002] The financial institution data monitoring technology refers to the technology by which financial institutions use a series of methods, tools, and systems to continuously collect, organize, analyze, and monitor various financial data. It aims to help financial institutions promptly discover and address potential risks and challenges by real-time monitoring and analyzing financial transaction data.

[0003] When the existing financial institution data monitoring technology monitors the data increment of financial institutions, it often analyzes and monitors the current data relying on the data characteristics of historical data, and often only relies on historical data for analysis and monitoring. However, in the data monitoring of financial institutions, historical data is often interfered by various factors, such as equipment failures, temporary business peaks, and data entry errors, resulting in certain quality problems and low data quality of historical data. Directly using historical data or only performing some simple cleaning processes on historical data cannot guarantee the reliability of subsequent analysis and monitoring. For example, in the patent application with the publication number CN111984503A, a method and device for identifying abnormal monitoring index data are disclosed. This solution analyzes and discriminates the current data relying on the data characteristics of historical data without cleaning and screening the historical data, resulting in insufficient reliability in judging data anomalies. Moreover, only relying on historical data for analysis and monitoring usually only observes the simple trends of data increments in the time series, such as linear growth, downward trends, or periodic fluctuations, etc. However, this simple trend analysis does not fully consider the characteristics closely related to data increments and cannot deeply understand the complex business driving factors behind the changes in data increments. The data increments of financial institutions are not only affected by internal business activities but also interfered by external factors. Relying solely on the data characteristics of historical data, it is difficult to accurately determine the location where data anomalies occur during data fluctuations, resulting in low accuracy in anomaly judgment. Therefore, when the existing financial institution data monitoring technology monitors the data increment of financial institutions, it cannot fully clean and screen historical data and combine some external characteristics closely related to data increments to accurately determine the location where data increment anomalies occur during data fluctuations. Summary of the Invention

[0004] The present invention aims to solve at least one of the technical problems in the prior art to a certain extent. By collecting relevant pedestrian flow data of financial institutions and data increment data of financial institution servers, performing data cleaning and screening processing, calculating data increment-related features, and constructing a data increment relationship model; using the data increment relationship model to monitor the data increment of financial institution servers for anomalies and performing anomaly location analysis to locate the time when the data increment appears abnormal; to solve the problem that the existing financial institution data monitoring technology cannot fully clean and screen historical data while combining some external features closely related to the data increment to accurately determine the location where the data increment anomaly appears during data fluctuations.

[0005] To achieve the above object, in a first aspect, the present application provides an automated management method for financial institution operation and maintenance services, including the following steps:

[0006] Collect relevant pedestrian flow data of financial institutions and data increment data of financial institution servers, and perform data cleaning and screening processing to obtain first pedestrian flow data and first increment data;

[0007] Calculate data increment-related features based on the first pedestrian flow data and construct a data increment relationship model;

[0008] Use the data increment relationship model to monitor the data increment of financial institution servers for anomalies to obtain abnormal increment data;

[0009] Perform anomaly location analysis based on the abnormal increment data to locate the time when the data increment appears abnormal.

[0010] Further, collecting relevant pedestrian flow data of financial institutions and data increment data of financial institution servers, and performing data cleaning and screening processing to obtain first pedestrian flow data and first increment data includes the following sub-steps:

[0011] During the working hours of the financial institution, obtain the number of people entering the financial institution at a first time interval, denoted as the entering number, the number of people coming out of the financial institution, denoted as the coming-out number, and the number of people taking numbers at the queuing number-taking machine in the financial institution, denoted as the number-taking number; mark the obtained entering number, coming-out number, number-taking number, and the specific time of acquisition as relevant pedestrian flow data, and the first time interval is t1;

[0012] And at the same time, obtain the data increment size of the financial institution server at the first time interval and record the specific time of acquisition, marked as data increment data.

[0013] Further, collecting the relevant passenger flow data of financial institutions and the data increment data of financial institution servers, and performing data cleaning and screening processing to obtain the first passenger flow data and the first increment data further includes the following sub-steps:

[0014] Performing data cleaning and screening processing on the relevant passenger flow data, and obtaining the first passenger flow data after completion; performing data cleaning and screening processing on the data increment data, and obtaining the first increment data after completion.

[0015] The data cleaning and screening processing includes: setting a data sliding window, where the size of the data sliding window is a1, and a1 is an odd number; the sliding step length is 1; sorting the corresponding data according to the specific time obtained, denoted as the time data sequence; using the data sliding window to slide on the time data sequence, calculating the average value of the corresponding data within the sliding window after each slide, and replacing the corresponding data at the middle position within the sliding window; obtaining the corresponding smoothed data sequence after completion.

[0016] Calculating the average value and standard deviation of the smoothed data sequence, denoted as E0 and E1 in sequence; arranging the smoothed data sequence in ascending order according to the data size, denoted as the size data sequence, obtaining the total number of data in the size data sequence, denoted as n, denoting any corresponding data in the size data sequence as DQi, where i represents the serial number in the size data sequence; setting the first ratio v1 and the first ratio v2, v1 < v2, and the value ranges of v1 and v2 are [0, 1], calculating [n * v1] and [n * v2], and obtaining the [n * v1]-th data DQ[n * v1] and the [n * v2]-th data DQ[n * v2] in the size data sequence; denoting DQ[n * v1] and DQ[n * v2] as D1Q and D2Q in sequence.

[0017] Further, the data cleaning and screening processing further includes the following sub-steps:

[0018] Denoting any corresponding data in the smoothed data sequence as PQj, calculating the first anomaly index for PQj through the first anomaly formula and calculating the second anomaly index through the second anomaly formula. The first anomaly formula is as follows: where D1j represents the first anomaly index of PQj, and the first anomaly formula is as follows: Where D2j represents the second anomaly index of PQj; set the first anomaly threshold YD1 and the second anomaly threshold YD2; if D1j and D2j satisfy (q1*D1j + q2*D2j) > (q1*YD1 + q2*YD2), where q1 and q2 are weight coefficients, q1 + q2 = 1, and the value ranges of q1 and q2 are [0, 1]; then determine that PQj is abnormal data, remove the data corresponding to PQj, and also remove other types of data at the same acquisition time as the removed data.

[0019] Furthermore, calculating data increment-related features based on the first pedestrian flow data and constructing a data increment relationship model includes the following sub-steps:

[0020] Based on the first pedestrian flow data and the first increment data, repeatedly extract the first pedestrian flow data and the first increment data without any missing values within the second time interval, and sum the number of people entering, the number of people leaving, the number of people taking numbers, and the data increment size within the second time interval respectively; after completion, obtain the second pedestrian flow data and the second increment data; the second time interval is t2, and t2 > t1;

[0021] The data increment-related features include the first related feature, the second related feature, and the third related feature. Based on the second pedestrian flow data, repeatedly obtain the corresponding number of people entering, the number of people leaving, and the number of people taking numbers within the same second time interval, calculate the first related feature, the second related feature, and the third related feature respectively, and merge and store the obtained data increment-related features with the second increment data, marked as the first feature data;

[0022] Calculating the first related feature includes: calculating the first related feature through the first feature formula, and the first feature formula is as follows: U1 = R3 + p*(R1 - R3), where U1 represents the first related feature, R1 is the number of people entering within the second time interval, R3 is the number of people taking numbers within the second time interval, and p is the proportionality coefficient;

[0023] Calculating the second related feature includes: calculating the second related feature through the second feature formula, and the first feature formula is as follows: Where U2 represents the second related feature, and R2 is the number of people leaving within the second time interval;

[0024] Calculating the third related feature includes: calculating the third related feature through the third feature formula, and the first feature formula is as follows: Where U3 represents the third related feature.

[0025] Furthermore, calculating data increment-related features based on the first pedestrian flow data and constructing a data increment relationship model also includes the following sub-steps:

[0026] Normalize the first feature data separately based on the data type, and scale all data sizes to [0, 1]; after completion, obtain the second feature data;

[0027] Divide the second feature data into a model training set and a model test set according to a ratio of 8:2;

[0028] Construct a first relationship model using a multi-layer perceptron. The first relationship model includes: an input layer, a first hidden layer, a second hidden layer, and an output layer. The input layer includes 3 neurons, the output layer includes 1 neuron, the first hidden layer includes B1 neurons, and the second hidden layer includes B2 neurons;

[0029] Use the model training set to train the first relationship model. After completion, obtain a data increment relationship model, and use the model test set to test the data increment relationship model. Calculate the mean absolute error MA of the data increment relationship model. The formula for the mean absolute error is as follows: Where Yk is the true data increment size, Xk is the data increment size output by the data increment relationship model, and K is the number of data increments input into the data increment relationship model.

[0030] Furthermore, use the data increment relationship model to perform anomaly monitoring on the data increment of the financial institution server. The steps to obtain the abnormal increment data are as follows:

[0031] Collect the relevant pedestrian flow data of the financial institution and the data increment data of the financial institution server at the first time interval, denoted as the first collection data, and merge the first collection data into the second collection data at the second time interval;

[0032] Calculate the data increment-related features based on the second collection data, perform normalization processing, and then input them into the data increment relationship model to obtain the output data increment size, denoted as the estimated increment size MB. Calculate the normal increment range based on the estimated increment size and the mean absolute error. The normal increment range is [MB * (1 - MA), MB * (1 + MA)], and determine whether the data increment size corresponding to the time in the second collection data is within the normal increment range; if it is within the normal increment range, it is determined that the data increment size corresponding to the time is normal; if it is not within the normal increment range, it is determined that the data increment size corresponding to the time is abnormal, and mark the abnormal data increment size and the corresponding first collection data as abnormal increment data.

[0033] Furthermore, perform anomaly location analysis based on the abnormal increment data. The steps to locate the time when the data increment appears abnormal are as follows:

[0034] Sort the abnormal incremental data in chronological order, and denote the size of any data increment as Zf, where f represents the sorting serial number of the data increment size; at the same time, calculate the mean value and standard deviation of the data increment size at the first time interval in the abnormal incremental data, and denote them as L1 and L2 respectively in sequence.

[0035] Further, for abnormal location analysis based on the abnormal incremental data, the location of the time when the data increment appears abnormally further includes the following sub-steps:

[0036] Judge whether |Zf - L1| > 3 * L2 is satisfied for Zf; if it is satisfied, mark the acquisition time corresponding to Zf as the abnormal occurrence time, if it is not satisfied, mark the acquisition time corresponding to Zf as the normal time, and repeat the judgment for all data increment sizes of the abnormal incremental data; after the judgment is completed, if there is no corresponding abnormal occurrence time in the abnormal incremental data, mark the acquisition time corresponding to the entire abnormal incremental data as the abnormal occurrence time.

[0037] In a second aspect, the present application provides an automated management system for financial institution operation and maintenance services, including a data collection module, a feature model module, an anomaly monitoring module, and a time location module;

[0038] The data collection module includes a data acquisition unit and a data processing unit. The data acquisition unit is used to collect relevant passenger flow data of financial institutions and data increment data of financial institution servers, and the data processing unit is used to perform data cleaning and screening processing to obtain the first passenger flow data and the first increment data;

[0039] The feature model module includes a feature calculation unit and a model construction unit. The feature calculation unit calculates data increment-related features based on the first passenger flow data, and the model construction unit is used to construct a data increment relationship model;

[0040] The anomaly monitoring module uses the data increment relationship model to monitor the data increment of the financial institution server for anomalies and obtains abnormal incremental data;

[0041] The time location module performs abnormal location analysis based on the abnormal incremental data to locate the time when the data increment appears abnormally.

[0042] Advantages of the present invention: The present invention collects relevant footfall data of financial institutions and data increment data of financial institution servers, and performs data cleaning and screening to obtain the first footfall data and the first increment data; calculates data increment-related features based on the first footfall data, and constructs a data increment relationship model; uses the data increment relationship model to perform anomaly monitoring on the data increment of the financial institution server to obtain abnormal increment data; performs anomaly location analysis based on the abnormal increment data to locate the time when the data increment appears abnormal; while fully cleaning and screening historical data, combining external features closely related to the data increment of financial institutions with the data features of historical data can accurately determine the location where the data increment anomaly appears in data fluctuations;

[0043] The present invention cleans and screens historical data by calculating the first anomaly index and the second anomaly index of historical data, which can effectively remove incorrect data or abnormal data caused by special circumstances, thereby providing a high-quality data basis for subsequent model training and analysis; calculates data increment-related features through the number of people entering, the number of people leaving, and the number of people taking numbers. The advantage is that these related features can accurately reflect the internal connection between external features and server data increment; through the model constructed based on these features, it can better capture the change law of data increment, improve the accuracy of the model's analysis of data increment, and further improve the accuracy of data increment anomaly monitoring; locates the time when the anomaly appears through the standard deviation of abnormal data increment. The advantage is that it can locate when the data increment anomaly appears specifically, providing more detailed anomaly information for operation and maintenance personnel and facilitating them to troubleshoot problems more accurately. Brief Description of the Drawings

[0044] Figure 1 is the principle block diagram of the system of the present invention;

[0045] Figure 2 is the step flow chart of the method of the present invention;

[0046] Figure 3 is the structural schematic diagram of the first relationship model of the present invention;

[0047] Figure 4 is the anomaly monitoring strategy flow chart of the present invention;

[0048] Figure 5 is the structural schematic diagram of the electronic device of the present invention. Detailed Embodiments

[0049] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0050] Example 1. Refer to Figure 1 As shown, the present application provides an automated management system for the operation and maintenance services of financial institutions, including a data collection module, a feature model module, an anomaly monitoring module, and a time positioning module.

[0051] The data collection module includes a data acquisition unit and a data processing unit. The data acquisition unit is used to collect relevant pedestrian flow data of financial institutions and data increment data of financial institution servers. The data processing unit is used to perform data cleaning and screening processing to obtain the first pedestrian flow data and the first increment data.

[0052] The data acquisition unit is configured with a data acquisition strategy, which includes: obtaining the number of people entering the financial institution at a first time interval during the working hours of the financial institution, denoted as the entering number, the number of people coming out of the financial institution, denoted as the leaving number, and the number of people taking numbers at the queuing number-taking machine in the financial institution, denoted as the number-taking number; marking the obtained entering number, leaving number, number-taking number, and the specific time of acquisition as relevant pedestrian flow data, and the first time interval is t1; in this embodiment, the first time interval t1 is 6 minutes, that is, the entering number, leaving number, and number-taking number within these 6 minutes are obtained every 6 minutes.

[0053] And at the same time, obtain the data increment size of the financial institution server at the first time interval, and record the specific time of acquisition, marked as data increment data; the data increment of the financial institution server refers to the increased part of the data stored on the financial institution server relative to a previous time point within a certain period; it reflects the accumulation of new data generated by financial business activities; for example, the newly added customer transaction records of the bank server, the newly added securities trading order data of the securities company server, etc. all belong to the category of data increment.

[0054] Perform data cleaning and screening processing on the relevant pedestrian flow data, and after completion, obtain the first pedestrian flow data. Perform data cleaning and screening processing on the data increment data, and after completion, obtain the first increment data.

[0055] Data cleaning and screening processing includes: setting a data sliding window with a size of a1, where a1 is an odd number; a sliding step of 1; sorting the corresponding data according to the specific time obtained, denoted as the time data sequence; the corresponding data includes the number of people entering, the number of people leaving, the number of people taking numbers, and the data increment size; using the data sliding window to slide on the time data sequence, calculating the average value of the corresponding data within the sliding window after each slide, and replacing the corresponding data at the middle position within the sliding window; after completion, obtaining the corresponding smoothed data sequence; in this embodiment, a1 is 3, and each time 3 times of collected data are selected through the data sliding window, and a1 is generally 3 or 5; the time data sequence often contains various short-term and irregular fluctuations, which may be caused by accidental factors; through data smoothing with a sliding window, these short-term fluctuations can be effectively filtered out, making the main trends and laws of the data clearer;

[0056] Calculate the average value and standard deviation of the smoothed data sequence, denoted as E0 and E1 in sequence; and arrange the smoothed data sequence in ascending order according to the data size, denoted as the size data sequence, obtain the total number of data in the size data sequence, denoted as n, and denote any corresponding data in the size data sequence as DQi, where i represents the serial number in the size data sequence; for example, DQ2 represents the second data in the size data sequence;

[0057] Set the first ratio v1 and the first ratio v2, where v1 < v2, and the value ranges of v1 and v2 are [0, 1], calculate [n*v1] and [n*v2], and obtain the [n*v1]-th data DQ[n*v1] and the [n*v2]-th data DQ[n*v2] in the size data sequence; denote DQ[n*v1] and DQ[n*v2] as D1Q and D2Q in sequence; in this embodiment, the first ratio v1 is 10%, and the first ratio v2 is 90%; for example, if n is 20; then [n*v1] = [20*10%] = 2, [n*v2] = [20*90%] = 18; D1Q = DQ2, D2Q = DQ18;

[0058] Denote any corresponding data in the smoothed data sequence as PQj, calculate the first anomaly index for PQj through the first anomaly formula, and calculate the second anomaly index through the second anomaly formula. The first anomaly formula is as follows: where D1j represents the first anomaly index of PQj, and the first anomaly formula is as follows: Among them, D2j represents the second anomaly index of PQj; a first anomaly threshold YD1 and a second anomaly threshold YD2 are set; if D1j and D2j satisfy (q1*D1j + q2*D2j) > (q1*YD1 + q2*YD2), where q1 and q2 are weight coefficients, q1 + q2 = 1, and the value ranges of q1 and q2 are [0, 1]; then it is determined that PQj is abnormal data, the data corresponding to PQj is removed, and the data of other types at the same acquisition time as the removed data is also removed; q1 and q2 can be set according to the actual application scenario. In this embodiment, q1 = q2 = 0.5;

[0059] In the specific implementation process, the first anomaly threshold YD1 and the second anomaly threshold YD2 can be determined through historical data analysis. For example, a part of the historical data can be used to determine the threshold, and then simulated anomaly value detection can be carried out on the remaining historical data; by continuously adjusting the threshold and observing the accuracy of the detection results, including the false positive rate and the false negative rate; until a threshold that is more appropriate in terms of accuracy and practicality is found; by setting the first anomaly index and the second anomaly index to clean and screen the data, abnormal values can be identified and processed more comprehensively and accurately; for example, the first anomaly index can capture data points that deviate significantly from the mean, and the first anomaly index can find abnormal values at both ends of the data distribution; through the first anomaly index and the second anomaly index, incorrect data or abnormal data caused by special circumstances can be effectively removed, thereby providing a high-quality data basis for subsequent model training and analysis.

[0060] The feature model module includes a feature calculation unit and a model construction unit. The feature calculation unit calculates data increment-related features based on the first passenger flow data, and the model construction unit is used to construct a data increment relationship model;

[0061] The feature calculation unit is configured with a feature calculation strategy, and the feature calculation strategy includes: based on the first passenger flow data and the first increment data, repeatedly extract the first passenger flow data and the first increment data without any missing data within the second time interval, and sum up the number of people entering, the number of people leaving, the number of people taking numbers, and the data increment size within the second time interval respectively; after completion, the second passenger flow data and the second increment data are obtained; the second time interval is t2, t2 > t1; in this embodiment, the second time interval t2 is 1 hour. For example, the first time interval is 6 minutes, that is, the data collected every 6 minutes is merged into the data collected once every 1 hour;

[0062] Data increment-related features include the first related feature, the second related feature, and the third related feature. Based on the second pedestrian flow data, repeatedly obtain the corresponding number of people entering, the number of people coming out, and the number of people taking numbers within the same second time interval, calculate the first related feature, the second related feature, and the third related feature respectively, and merge and store the obtained data increment-related features with the second increment data, marked as the first feature data;

[0063] Calculating the first related feature includes: calculating the first related feature through the first feature formula. The first feature formula is as follows: U1 = R3 + p * (R1 - R3), where U1 represents the first related feature, R1 is the number of people entering within the second time interval, R3 is the number of people taking numbers within the second time interval, and p is the proportionality coefficient; p represents the number of people who did not take numbers but caused data increase due to effective business activities in the actual scenario, which can be estimated through historical data or business experience; the first related feature reflects the proportion of people who are truly related to the server data increment within the second time interval; the server data increment is mainly generated by the effective business activities carried out by customers, such as handling transfers, opening accounts, etc.; when it is relatively high, it indicates that more people may generate business-related data within this second time interval, thus having a more direct association with the server data increment;

[0064] Calculating the second related feature includes: calculating the second related feature through the second feature formula. The first feature formula is as follows: where U2 represents the second related feature, and R2 is the number of people coming out within the second time interval; the second related feature is closely related to the server data increment; when the second related feature is relatively large, it indicates that more people are conducting business activities within the institution, which will increase the load on the server and generate more data, such as transaction records, customer information updates, etc.;

[0065] Calculating the third related feature includes: calculating the third related feature through the third feature formula. The first feature formula is as follows: where U3 represents the third related feature; the third related feature represents the dynamic balance state of personnel flow and is closely related to the stability of business activities; when the absolute value of the third related feature is relatively large, it means that the imbalance within the second time interval is relatively serious; for example, when the third related feature is a relatively large positive value, it indicates that the number of people entering is much more than the number of people coming out, which may be due to specific business activities attracting a large number of customers to enter concentratedly, and these customers may conduct a series of business operations, such as opening accounts, consulting, handling complex financial products, etc., thus resulting in a significant increase in the server data increment; conversely, when the third related feature is a relatively large negative value, the number of people coming out is much more than the number of people entering, which may mean that the peak period of business handling has passed, and a large number of customers leave after completing their business, but during this process, the server has processed a large amount of business data and generated the corresponding data increment;

[0066] The model construction unit is configured with a model construction strategy, which includes: normalizing the first feature data separately based on the data type and scaling all data sizes to [0, 1]; after completion, obtaining the second feature data;

[0067] Dividing the second feature data into a model training set and a model test set according to a ratio of 8:2;

[0068] Construct a first relationship model using a multi-layer perceptron. Please refer to Figure 3 As shown, the first relationship model includes: an input layer, a first hidden layer, a second hidden layer, and an output layer. The input layer includes 3 neurons because only the first relevant feature, the second relevant feature, and the third relevant feature are input; the output layer includes 1 neuron for outputting the data increment. The first hidden layer includes B1 neurons, and the second hidden layer includes B2 neurons; in this embodiment, B1 = B2 = 32, and B1 and B2 can be increased or decreased according to the actual application scenario;

[0069] Use the model training set to train the first relationship model. After completion, obtain the data increment relationship model, and use the model test set to test the data increment relationship model. Calculate the mean absolute error MA of the data increment relationship model. The formula for the mean absolute error is as follows: Where Yk is the true data increment size, Xk is the data increment size output by the data increment relationship model, and K is the number of data increments input into the data increment relationship model; the mean absolute error is an index to measure the accuracy of the prediction model; it represents the deviation degree of each prediction from the true value on average for the model; the smaller the value of the mean absolute error, the more accurate the prediction of the model because it indicates that the average gap between the predicted value and the true value is smaller; during the model test process, if the mean absolute error of the model is large, the model can be retrained; so that the accuracy of the model will not be too low;

[0070] In the specific implementation process, use the data increment-related features to construct the data increment relationship model instead of directly using the number of people entering, the number of people leaving, and the number of people taking numbers; the advantage is that it can more accurately reflect the relationship between the business activities of financial institutions and the data increment. Directly using the three original data dimensions of the number of people entering, the number of people leaving, and the number of people taking numbers has a relatively high dimension and may contain more noise and redundant information; by constructing the above three relevant features, the original data can be integrated and refined, reducing the data dimension, and at the same time reducing the noise interference caused by these accidental factors and correlations, enabling the model to focus more on the information truly related to the data increment; and because the first relevant feature, the second relevant feature, and the third relevant feature start from the business essence and comprehensively consider the influence of various factors on business activities, they have better adaptability in different financial institution scenarios and business change situations.

[0071] The anomaly monitoring module uses the data increment relationship model to perform anomaly monitoring on the data increment of the financial institution's server, and obtains the abnormal increment data;

[0072] The anomaly monitoring module is configured with an anomaly monitoring strategy, and the anomaly monitoring strategy includes: Please refer to Figure 4 As shown, collect the relevant pedestrian flow data of the financial institution and the data increment data of the financial institution's server at the first time interval, record it as the first collection data, and merge the first collection data into the second collection data at the second time interval; for example, collect data once every 6 minutes, and merge the data of 10 consecutive 6-minute periods into data collected once an hour;

[0073] Calculate the data increment related features based on the second collection data, and after normalization, input them into the data increment relationship model to obtain the output data increment size, recorded as the estimated increment size MB. Calculate the normal increment range based on the estimated increment size and the mean absolute error. The normal increment range is [MB*(1 - MA), MB*(1 + MA)], and judge whether the data increment size corresponding to the time in the second collection data is within the normal increment range; if it is within the normal increment range, it is judged that the data increment size corresponding to the time is normal; if it is not within the normal increment range, it is judged that the data increment size corresponding to the time is abnormal, and mark the abnormal data increment size and the corresponding first collection data as abnormal increment data; for example, the estimated increment size for a certain hour is 300M, and the mean absolute error of the data increment relationship model is 0.1, then the normal increment range for this hour is [300*(1 - 0.1), 300*(1 + 0.1)], that is, [270, 330];

[0074] In the specific implementation process, the reason for merging the first collection data into the second collection data at the second time interval is that in a short period of time, such as the first time interval, the data increment of the financial institution's server may fluctuate violently due to various accidental factors; for example, the complex business operations of individual customers may cause a sudden increase in the data volume within a few minutes, but this kind of fluctuation may not be representative and cannot reflect the overall business trend; while the data increment in units of the second time interval can smooth these accidental fluctuations to a certain extent, making the obtained estimated increment size more stable; it can comprehensively consider the comprehensive impact of various business activities within this time period, and can better reflect the overall operation state of the financial institution's business.

[0075] The time positioning module performs anomaly positioning analysis based on the abnormal increment data to locate the time when the data increment appears abnormal;

[0076] The time positioning module is configured with a time positioning strategy, which includes: sorting the abnormal incremental data in chronological order, and denoting the data increment size of any one as Zf, where f represents the sorting serial number of the data increment size; at the same time, calculating the mean value and standard deviation of the data increment sizes at the first time interval in the abnormal incremental data, denoted as L1 and L2 in sequence; for example, the first time interval is 6 minutes, the first time interval is 1 hour, and if the data increment from 15:00 to 16:00 is abnormal, then the 10 data collected from 15:00 to 16:00 in this hour are sorted in chronological order, and Z2 represents the data collected in the second 6 minutes from 15:00 to 16:00, that is, from 15:06 to 15:12, and calculate the mean value and standard deviation;

[0077] For Zf, judge whether |Zf - L1| > 3 * L2 is satisfied; if it is satisfied, mark the acquisition time corresponding to Zf as the abnormal occurrence time, if it is not satisfied, mark the acquisition time corresponding to Zf as the normal time, and repeat the judgment for all data increment sizes of the abnormal incremental data; after the judgment is completed, if there is no corresponding abnormal occurrence time in the abnormal incremental data, then mark the acquisition time corresponding to the entire abnormal incremental data as the abnormal occurrence time; for example, Z2 represents the data collected in the second 6 minutes from 15:00 to 16:00, that is, from 15:06 to 15:12, and if |Z2 - L1| > 3 * L2, then mark the time from 15:06 to 15:12 as the abnormal occurrence time;

[0078] In the specific implementation process, if no abnormal occurrence time is judged in the abnormal incremental data of the second time interval, it means that the entire corresponding second time interval of the abnormal incremental data, such as from 15:00 to 16:00, has an abnormality at the beginning, so that no abnormal occurrence time is judged within the corresponding second time interval through the mean value and standard deviation.

[0079] Example 2, please refer to Figure 2 As shown, the present application provides an automated management method for the operation and maintenance services of financial institutions, including the following steps:

[0080] Step S1, collect the relevant passenger flow data of the financial institution and the data increment data of the financial institution server, and perform data cleaning and screening processing to obtain the first passenger flow data and the first increment data; Step S1 includes the following sub-steps:

[0081] Step S101, within the working hours of the financial institution, obtain the number of people entering the financial institution at the first time interval, denoted as the entering number, the number of people coming out of the financial institution, denoted as the coming-out number, and the number of people taking numbers at the queuing number-taking machine in the financial institution, denoted as the number-taking number;

[0082] Step S102: Mark the obtained number of people entering, number of people leaving, number of people taking numbers, and the specific time obtained as relevant passenger flow data, and the first time interval is t1.

[0083] Step S103: At the same time, obtain the data increment size of the financial institution server at the first time interval, record the specific time obtained, and mark it as data increment data.

[0084] Step S104: Perform data cleaning and screening on the relevant passenger flow data. After completion, obtain the first passenger flow data, and perform data cleaning and screening on the data increment data. After completion, obtain the first increment data.

[0085] Step S105: Data cleaning and screening process. Step S105 includes the following sub-steps:

[0086] Step S1051: Set a data sliding window. The size of the data sliding window is a1, and a1 is an odd number; the sliding step is 1; sort the corresponding data according to the obtained specific time, and record it as a time data sequence.

[0087] Step S1052: Use the data sliding window to slide on the time data sequence. After each slide, calculate the average value of the corresponding data within the sliding window, and replace the corresponding data at the middle position within the sliding window; after completion, obtain the corresponding smoothed data sequence.

[0088] Step S1053: Calculate the average value and standard deviation of the smoothed data sequence, and record them as E0 and E1 in sequence; and arrange the smoothed data sequence in ascending order according to the data size, record it as a size data sequence, obtain the total number of data in the size data sequence, record it as n, and record any corresponding data in the size data sequence as DQi, where i represents the serial number in the size data sequence.

[0089] Step S1054: Set the first ratio v1 and the first ratio v2, v1 < v2, and the value ranges of v1 and v2 are [0, 1]. Calculate [n*v1] and [n*v2], and obtain the [n*v1]-th data DQ[n*v1] and the [n*v2]-th data DQ[n*v2] in the size data sequence; record DQ[n*v1] and DQ[n*v2] as D1Q and D2Q in sequence.

[0090] Step S1055: Record any corresponding data in the smoothed data sequence as PQj. Calculate the first anomaly index for PQj through the first anomaly formula and calculate the second anomaly index through the second anomaly formula. The first anomaly formula is as follows: Among them, D1j represents the first anomaly index of PQj, and the first anomaly formula is as follows: where D2j represents the second anomaly index of PQj;

[0091] Step S1056, set the first anomaly threshold YD1 and the second anomaly threshold YD2; if D1j and D2j satisfy (q1*D1j + q2*D2j) > (q1*YD1 + q2*YD2), where q1 and q2 are weight coefficients, q1 + q2 = 1, and the value ranges of q1 and q2 are [0, 1]; then determine that PQj is abnormal data, remove the data corresponding to PQj, and also remove other types of data at the same acquisition time as the removed data.

[0092] Step S2, calculate data increment-related features based on the first pedestrian flow data and construct a data increment relationship model; Step S2 includes the following sub-steps:

[0093] Step S201, based on the first pedestrian flow data and the first increment data, repeatedly extract the first pedestrian flow data and the first increment data without any missing data within the second time interval, and sum up the number of people entering, the number of people leaving, the number of people taking numbers, and the data increment size within the second time interval respectively; after completion, obtain the second pedestrian flow data and the second increment data; the second time interval is t2, t2 > t1;

[0094] Step S202, the data increment-related features include the first related feature, the second related feature, and the third related feature. Based on the second pedestrian flow data, repeatedly obtain the corresponding number of people entering, the number of people leaving, and the number of people taking numbers within the same second time interval, calculate the first related feature, the second related feature, and the third related feature respectively, and merge and store the obtained data increment-related features with the second increment data, marked as the first feature data;

[0095] Calculating the first related feature in Step S203 includes: calculating the first related feature through the first feature formula, and the first feature formula is as follows: U1 = R3 + p*(R1 - R3), where U1 represents the first related feature, R1 is the number of people entering within the second time interval, R3 is the number of people taking numbers within the second time interval, and p is the proportionality coefficient;

[0096] Calculating the second related feature in Step S204 includes: calculating the second related feature through the second feature formula, and the first feature formula is as follows: where U2 represents the second related feature, and R2 is the number of people leaving within the second time interval;

[0097] Calculating the third related feature in Step S205 includes: calculating the third related feature through the third feature formula, and the first feature formula is as follows: where U3 represents the third related feature;

[0098] Step S206: Normalize the first feature data separately based on the data type, and scale all data sizes to [0, 1]; after completion, obtain the second feature data;

[0099] Step S207: Divide the second feature data into a model training set and a model test set according to a ratio of 8:2;

[0100] Step S208: Use a multi-layer perceptron to construct a first relationship model. The first relationship model includes: an input layer, a first hidden layer, a second hidden layer, and an output layer. The input layer includes 3 neurons, the output layer includes 1 neuron, the first hidden layer includes B1 neurons, and the second hidden layer includes B2 neurons;

[0101] Step S209: Use the model training set to train the first relationship model. After completion, obtain a data increment relationship model, and use the model test set to test the data increment relationship model, and calculate the mean absolute error MA of the data increment relationship model. The mean absolute error calculation formula is as follows: Where Yk is the true data increment size, Xk is the data increment size output by the data increment relationship model, and K is the number of data inputs to the data increment relationship model.

[0102] Step S3: Use the data increment relationship model to perform anomaly monitoring on the data increment of the financial institution server to obtain anomaly increment data; Step S3 includes the following sub-steps:

[0103] Step S301: Collect relevant pedestrian flow data of the financial institution and data increment data of the financial institution server at a first time interval, denoted as the first collection data, and merge the first collection data into the second collection data at a second time interval;

[0104] Step S302: Calculate data increment-related features based on the second collection data, and after normalization, input them into the data increment relationship model to obtain the output data increment size, denoted as the estimated increment size MB;

[0105] Step S303: Calculate the normal increment range based on the estimated increment size and the mean absolute error. The normal increment range is [MB*(1 - MA), MB*(1 + MA)], and determine whether the data increment size corresponding to the time in the second collection data is within the normal increment range;

[0106] Step S304: If it is within the normal increment range, determine that the data increment size corresponding to the time is normal; if it is not within the normal increment range, determine that the data increment size corresponding to the time is abnormal, and mark the abnormal data increment size and the corresponding first collection data as abnormal increment data.

[0107] Step S4: Perform anomaly location analysis based on the abnormal incremental data to locate the time when the data increment is abnormal. Step S4 includes the following sub-steps:

[0108] Step S401: Sort the abnormal incremental data in chronological order, and denote the size of any data increment as Zf, where f represents the sorting serial number of the data increment size.

[0109] Step S402: Simultaneously calculate the mean and standard deviation of the data increment sizes at the first time interval in the abnormal incremental data, and denote them as L1 and L2 in sequence.

[0110] Step S403: For Zf, determine whether |Zf - L1| > 3 * L2 is satisfied; if satisfied, mark the acquisition time corresponding to Zf as the abnormal occurrence time, if not satisfied, mark the acquisition time corresponding to Zf as the normal time, and repeat the judgment for all data increment sizes of the abnormal incremental data.

[0111] Step S404: After the judgment is completed, if there is no corresponding abnormal occurrence time in the abnormal incremental data, mark the acquisition time corresponding to the entire abnormal incremental data as the abnormal occurrence time.

[0112] Embodiment 3, please refer to Figure 5 as shown in Figure 5 illustrates a schematic structural diagram of an electronic device. The electronic device may include: a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus. The memory stores computer-readable instructions, and the processor can call the instructions in the memory. When the computer-readable instructions are executed by the processor, the steps in a method for automated management of operation and maintenance services of a financial institution are run to achieve the following functions: collecting relevant passenger flow data of a financial institution and data increment data of the financial institution server, and performing data cleaning and screening processing to obtain the first passenger flow data and the first increment data; calculating data increment-related features based on the first passenger flow data, and constructing a data increment relationship model; using the data increment relationship model to monitor the data increment of the financial institution server for anomalies to obtain abnormal incremental data; performing anomaly location analysis based on the abnormal incremental data to locate the time when the data increment is abnormal.

[0113] In addition, when the logical instructions in the above-mentioned memory are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0114] Embodiment 4, this application also provides a computer-readable storage medium. This application provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, it runs the steps in the above-mentioned method for automated management of financial institution operation and maintenance services to achieve the following functions: collecting relevant footfall data of a financial institution and data increment data of the financial institution's server, and performing data cleaning and screening processing to obtain first footfall data and first increment data; calculating data increment-related features based on the first footfall data and constructing a data increment relationship model; using the data increment relationship model to perform anomaly monitoring on the data increment of the financial institution's server to obtain anomaly increment data; performing anomaly location analysis based on the anomaly increment data to locate the time when the data increment appears abnormal.

[0115] Through the description of the above embodiments, the embodiments of the present invention can be provided as a method, a system, or a computer program product. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disks, optical discs, etc., and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments.

[0116] In the embodiments provided in the present application, it should be understood that the disclosed system or method can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of systems, modules, and units can be in electrical, mechanical, or other forms.

[0117] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or equivalently replace some of the technical features. However, such modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for automated management of operation and maintenance services of a financial institution, characterized in that: It includes the following steps: Collect the relevant footfall data of financial institutions and the data increment data of financial institution servers, and perform data cleaning and screening processing to obtain the first footfall data and the first increment data; Calculate the data increment-related features based on the first footfall data and construct a data increment relationship model; Use the data increment relationship model to monitor the data increment of the financial institution server for anomalies and obtain the abnormal increment data; Conduct anomaly location analysis based on the abnormal increment data to locate the time when the data increment appears abnormal.

2. A method for automated management of operation and maintenance services of a financial institution according to claim 1, characterized in that: Collect the relevant footfall data of financial institutions and the data increment data of financial institution servers, and perform data cleaning and screening processing to obtain the first footfall data and the first increment data, including the following sub-steps: Obtain the number of people entering the financial institution at a first time interval during the working hours of the financial institution, denoted as the entering number, the number of people coming out of the financial institution, denoted as the coming-out number, and the number of people taking numbers at the queuing number-taking machine in the financial institution, denoted as the number-taking number; mark the obtained entering number, coming-out number, number-taking number, and the specific time of acquisition as the relevant footfall data, and the first time interval is t1; And at the same time, obtain the data increment size of the financial institution server at the first time interval and record the specific time of acquisition, marked as the data increment data.

3. A method for automated management of operation and maintenance services of a financial institution according to claim 2, characterized in that: Collect the relevant footfall data of financial institutions and the data increment data of financial institution servers, and perform data cleaning and screening processing to obtain the first footfall data and the first increment data, which also includes the following sub-steps: Perform data cleaning and screening processing on the relevant footfall data, and after completion, obtain the first footfall data, and perform data cleaning and screening processing on the data increment data, and after completion, obtain the first increment data; The data cleaning and screening processing includes: setting a data sliding window, the size of the data sliding window is a1, a1 is an odd number; the sliding step is 1; sort the corresponding data according to the specific time of acquisition, denoted as the time data sequence; use the data sliding window to slide on the time data sequence, calculate the average value of the corresponding data within the sliding window after each slide, and replace the corresponding data at the middle position within the sliding window; after completion, obtain the corresponding smoothed data sequence; Calculate the average value and standard deviation of the smoothed data sequence, denoted as E0 and E1 in sequence; and arrange the smoothed data sequence in ascending order according to the data size, denoted as the size data sequence, obtain the total number of data in the size data sequence, denoted as n, denote any corresponding data in the size data sequence as DQi, and i represents the serial number in the size data sequence; Set the first ratio v1 and the first ratio v2, v1 < v2, and the value ranges of v1 and v2 are [0, 1], calculate [n*v1] and [n*v2], and obtain the [n*v1]-th data DQ[n*v1] and the [n*v2]-th data DQ[n*v2] in the size data sequence; denote DQ[n*v1] and DQ[n*v2] as D1Q and D2Q in sequence.

4. A method for automated management of operation and maintenance services of a financial institution according to claim 3, characterized in that: The data cleaning and screening processing also includes the following sub-steps: Any corresponding data in the smoothed data sequence is recorded as PQj. For PQj, the first abnormal index is calculated by the first abnormal formula, and the second abnormal index is calculated by the second abnormal formula. The first abnormal formula is as follows: Where D1j represents the first abnormality index of PQj, and the first abnormality formula is as follows: Wherein D2j represents the second abnormality indicator of PQj; set the first abnormality threshold YD1 and the second abnormality threshold YD2; if D1j and D2j satisfy (q1*D1j+q2*D2j)>(q1*YD1+q2*YD2), wherein q1 and q2 are weight coefficients, q1+q2=1, and the value range of q1 and q2 is [0, 1]; then PQj is judged as abnormal data, the data corresponding to PQj is removed, and other types of data acquired at the same time as the removed data are also removed.

5. A method for automated management of operation and maintenance services of a financial institution according to claim 4, characterized in that: Calculating data increment related features based on the first person flow data and building a data increment relationship model includes the following sub-steps: Based on the first flow data and the first incremental data, the first flow data and the first incremental data without any missing data in the second time interval are repeatedly extracted, and the number of people entering, the number of people leaving, the number of people taking numbers and the data increment size in the second time interval are summed up respectively; after completion, the second flow data and the second incremental data are obtained; the second time interval is t2, t2>t1; The data increment related features include the first related feature, the second related feature and the third related feature. Based on the second passenger flow data, the number of people entering, the number of people leaving and the number taking number in the same second time interval are repeatedly obtained, and the first related feature, the second related feature and the third related feature are respectively calculated, and the obtained data increment related features are combined with the second incremental data for storage and marked as the first feature data; Calculating the first related feature includes: calculating the first related feature by a first feature formula, the first feature formula is as follows: U1=R3+p*(R1-R3), wherein U1 represents the first related feature, R1 is the number of people entering in the second time interval, R3 is the number of people taking numbers in the second time interval, and p is a proportional coefficient; Calculating the second related feature includes: calculating the second related feature by a second feature formula, the first feature formula is as follows: Where U2 represents the second relevant feature, and R2 is the number of people coming out during the second time interval; Calculating the third related feature includes: calculating the third related feature by a third feature formula, where the first feature formula is as follows: Wherein U3 represents the third related feature.

6. A method for automated management of operation and maintenance services of a financial institution according to claim 5, characterized in that: Calculating data increment related features based on the first person flow data and building a data increment relationship model also includes the following sub-steps: Normalize the first feature data based on the data type and scale all data sizes to [0, 1]; after completion, obtain the second feature data; The second feature data is divided into a model training set and a model test set in a ratio of 8:2; A first relational model is constructed using a multilayer perceptron. The first relational model includes: an input layer, a first hidden layer, a second hidden layer, and an output layer. The input layer includes 3 neurons, the output layer includes 1 neuron, the first hidden layer includes B1 neurons, and the second hidden layer includes B2 neurons. The first relational model is trained using the model training set. After completion, the data incremental relational model is obtained. The data incremental relational model is tested using the model test set. The mean absolute error MA of the data incremental relational model is calculated. The mean absolute error calculation formula is as follows: Where Yk is the actual data increment size, Xk is the data increment size output by the data increment relational model, and K is the amount of data input into the data increment relational model.

7. A method for automated management of operation and maintenance services of a financial institution according to claim 6, characterized in that: Using the data increment relationship model to monitor the data increment of the financial institution server for abnormality, obtaining abnormal incremental data includes the following sub-steps: Collecting relevant traffic data of the financial institution and incremental data of the server of the financial institution at a first time interval, recording them as first collected data, and merging the first collected data into second collected data at a second time interval; Based on the second collected data, the data increment related features are calculated, and after normalization processing, they are input into the data increment relationship model to obtain the output data increment size, which is recorded as the estimated increment size MB. Based on the estimated increment size and the mean absolute error, the normal increment range is calculated, and the normal increment range is [MB*(1-MA), MB*(1+MA)]. It is determined whether the data increment size at the corresponding time in the second collected data is within the normal increment range; if it is within the normal increment range, it is determined that the data increment size at the corresponding time is normal; If it is not within the normal increment range, it is determined that the data increment size of the corresponding time is abnormal, and the abnormal data increment size and the corresponding first collected data are marked as abnormal increment data.

8. A method for automated management of operation and maintenance services of a financial institution according to claim 7, characterized in that: Based on the abnormal incremental data, the abnormal location analysis is performed to locate the time when the data increment abnormality occurs, which includes the following sub-steps: Sort the abnormal incremental data in chronological order, and record any data incremental size as Zf, where f represents the sorting order of the data incremental size; at the same time, calculate the mean and standard deviation of the data incremental size in the abnormal incremental data at the first time interval, and record them as L1 and L2 respectively.

9. A method for automated management of operation and maintenance services of a financial institution according to claim 8, characterized in that: Based on the abnormal incremental data, the abnormal location analysis is performed to locate the time when the data increment abnormality occurs, which also includes the following sub-steps: For Zf, determine whether |Zf-L1|>3*L2 is satisfied; if so, mark the collection time corresponding to Zf as the abnormal occurrence time; if not, mark the collection time corresponding to Zf as the normal time, and repeat the judgment for all data increments of the abnormal incremental data; after the judgment is completed, if there is no corresponding abnormal occurrence time in the abnormal incremental data, mark the collection time corresponding to the entire abnormal incremental data as the abnormal occurrence time.

10. An automated management system for operation and maintenance services of a financial institution, applicable to an automated management method for operation and maintenance services of a financial institution as claimed in any one of claims 1 to 9, characterized in that: It includes data collection module, feature model module, anomaly monitoring module and time positioning module; The data collection module includes a data acquisition unit and a data processing unit. The data acquisition unit is used to collect relevant human flow data of the financial institution and data increment data of the server of the financial institution. The data processing unit is used to perform data cleaning and screening to obtain the first human flow data and the first increment data. The feature model module includes a feature calculation unit and a model construction unit, the feature calculation unit calculates data increment related features based on the first pedestrian flow data, and the model construction unit is used to construct a data increment relationship model; The anomaly monitoring module uses the data increment relationship model to perform anomaly monitoring on the data increment of the financial institution server to obtain abnormal increment data; The time location module performs anomaly location analysis based on the abnormal incremental data and locates the time when the abnormal data increment occurs.

Citation Information

Patent Citations

  • Method and device for identifying abnormal data of monitoring index data

    CN111984503A