Intelligent risk control method based on enterprise multi-dimensional data

By building a hyperbolic collaborative trend analysis model and a business risk assessment model, combined with the enterprise risk control management mechanism, the problem of inaccurate assessment in traditional risk analysis methods is solved, real-time monitoring and precise management of enterprise risks is achieved, and risk response capabilities and management efficiency are improved.

CN120069564AActive Publication Date: 2025-05-30BEIJING 616 INFORMATION TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510541840.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-05-30
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

Traditional enterprise business risk analysis methods cannot match rapidly changing business needs, resulting in inaccurate risk assessment and lack of differentiated response mechanisms for risk sources and the ability to capture time-dimensional synergy.

Method used

By constructing a hyperbolic collaborative trend analysis model based on enterprise multidimensional data, key risk feature vectors are generated, and risk assessment is used to use pre-trained business risk assessment models, and differentiated control is carried out in combination with enterprise risk control management mechanisms, considering the dependence relationship and risk propagation between business projects.

Benefits of technology

Real-time monitoring and accurate assessment of enterprise risks is achieved, targeted risk management opinions are provided, risk response capabilities and management efficiency are improved, antagonistic relationships that may be masked by the one-size-fits-all risk level value in traditional methods, and the accuracy and comprehensiveness of risk assessment are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120069564A_ABST
    Figure CN120069564A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent risk control method based on enterprise multi-dimensional data, and the method comprises the steps: obtaining a risk association data set of each business project of an enterprise in a preset time period, and the risk association data set comprises the safety vulnerability feature data and potential loss feature data of each unit time; based on the risk association data set, generating a key risk feature vector by using a preset hyperbolic curve collaborative trend analysis model; inputting the key risk feature vector into a pre-trained business risk assessment model, and outputting a risk result sequence of the corresponding business item; and based on the risk result sequence of each business project, inputting the risk result sequence into a preset enterprise risk control management mechanism, and carrying out risk control management on each business project. Therefore, on the basis of the collaborative relationship among the multi-dimensional data, the risk characteristics can be analyzed more comprehensively, and the accuracy and management efficiency of risk assessment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data analysis, and particularly to a smart risk control method based on enterprise multi-dimensional data. Background Art

[0002] Enterprises are the guarantee for the stable and long-term development of modern society, and enterprise security is the core competitiveness of enterprise development; the safe development of enterprises is an important benchmark for measuring the high-quality development, high-level security and high-quality ecology of enterprises; nowadays, the progress of technology has driven the rapid expansion of social demands, and the information-based society has made the supply of business demands between enterprises and users become complex in type and rapid in quantity growth. Correspondingly, it is a matter of whether the business supervision technology can be balanced with its growth rate; currently, the types and quantities of enterprises are quite large, and the corresponding number of business processes has increased exponentially. Obviously, the traditional business supervision and analysis methods are no longer applicable to the current environment. Conducting business risk analysis manually is time-consuming and laborious, and its low-intelligent analysis methods cannot match the changing speed of the current rapid business development. In the current environment with a large number of business quantities, it is prone to the potential risk of abnormal development of a large number of businesses.

[0003] The Chinese invention patent with the patent application number 202411412523.7 discloses a multi-dimensional information evaluation method for enterprise security indexes. By retrieving the real-time development data of the business, the risk values are analyzed for each time point, the business curve development is fitted by using the risk value analysis of each point, and through the comparison and prediction data analysis, the abnormal points of the current business are marked. Based on the processing results of the abnormal points, the real-time risk monitoring of the business project is realized, which greatly improves the efficiency and accuracy of traditional business monitoring and realizes the timely monitoring of enterprise business security risks.

[0004] However, simply generating the risk degree value based on the product of the safety development characteristic value and the potential loss characteristic value may mask the antagonistic or synergistic relationship between safety and loss, and lacks the differential response mechanism to risk sources and the ability to capture the time dimension synergistic effect. Because the diversity of risk sources and the differential risk degrees will both have a certain impact on the risk control of the final enterprise risk. Summary of the Invention

[0005] This application provides a smart risk control method based on enterprise multi-dimensional data. Based on the collaborative relationship between multi-dimensional data, it can analyze risk characteristics more comprehensively and improve the accuracy of risk assessment and management efficiency.

[0006] This application provides a smart risk control method based on enterprise multi-dimensional data, including: S101, obtaining the risk association data set of each business project of the enterprise within a preset time period, including the security vulnerability characteristic data and potential loss characteristic data of each unit time; S102. Based on the risk association dataset, use the preset hyperbolic collaborative trend analysis model to generate key risk feature vectors; S103. Input the key risk feature vectors into the pre-trained business risk assessment model to output the risk result sequence of the corresponding business project; S104. Based on the risk result sequences of each business project, input them into the preset enterprise risk control management mechanism to perform risk control management on each business project.

[0007] Preferably, the preset hyperbolic collaborative trend analysis model specifically includes: S201. Construct a first curve and a second curve that are associated with the security vulnerability feature data and the potential loss feature data on the time series within a preset time period; S202. Based on the first curve and the second curve, segment the first curve according to the second curve to generate a sequence of sub-curve segments, and the sequence of sub-curve segments includes several sub-curve segments arranged in chronological order; S203. Extract features from the sequence of sub-curve segments to obtain key risk feature vectors.

[0008] Preferably, the obtaining method of the first curve is: calculate the product value of the security vulnerability feature data and the potential loss feature data as the first eigenvalue, and generate a curve fitted with the first eigenvalue on the time series as the first curve; the obtaining method of the second curve is: calculate the collaborative quantization value of the security vulnerability feature data and the potential loss feature data as the second eigenvalue, and generate a curve fitted with the second eigenvalue on the time series as the second curve.

[0009] Preferably, the obtaining method of the second eigenvalue is specifically: A1. Respectively construct independent curves of the security vulnerability feature data and the potential loss feature data on the time series, which are L(t) and F(t) respectively; A2. Calculate the second eigenvalue according to the following formula:

[0010] Where, is the second eigenvalue at time node t, is the covariance within the sliding window before time node t of L(t) and F(t), is the absolute value of the product of the change rates of the independent curves at time node t, is the preset weight coefficient used to adjust the influence degree of the collaborative speed.

[0011] Preferably, in S202, segmenting the first curve according to the second curve includes: Traverse the second eigenvalue step by step from the starting point of the second curve according to the time series until the difference between the current second eigenvalue and the previous second eigenvalue is greater than the preset difference threshold, then perform cutting to obtain a sub-curve segment. Continue to traverse the remaining second curve until the end point is reached, generate all sub-curve segments, and form a sub-curve segment sequence; Among them, each sub-curve segment is set with a corresponding collaborative feature label, and the collaborative feature label is: the average value of all second eigenvalues in the sub-curve segment.

[0012] Preferably, in S203, feature extraction is performed on the sub-curve segment sequence, including: B1. Obtain the first curve segment corresponding to each sub-curve segment in the first curve; B2. Based on the first curve segment, obtain the extreme difference, average value, and variance value of its first eigenvalue as the key features of the first curve segment; B3. Arrange the key features of all sub-curve segments in chronological order to form a key risk feature vector, that is, a key feature sequence.

[0013] Preferably, each of the business items corresponds to a business risk assessment model. The pre-trained business risk assessment model is obtained in the following way: C1. Collect a large number of risk association data sets within a preset time period in the history of the corresponding business item type, obtain the key risk feature vectors within each historical preset time period, and perform label annotation. The annotation content is set as a risk result sequence composed of the actual risk results of each sub-curve segment; the actual risk result of each sub-curve segment includes a risk assessment value and its corresponding actual risk type; C2. Use all the labeled key risk feature vectors as the training set, and use the training set to train a pre-selected neural network structure, continuously optimize the model parameters, and generate the final business risk assessment model.

[0014] Preferably, in S104, the preset enterprise risk control management mechanism specifically includes: S301. Based on the risk result sequence of each business item, extract risk change features based on the collaborative feature label, including risk event frequency, risk duration, and risk intensity value; the risk change features are obtained in the following way: D1. Obtain the collaborative feature label of the sub-curve segment sequence corresponding to the risk result sequence. Based on the collaborative feature label, cluster the risk results of all sub-curve segments to obtain several clusters. Each cluster includes the risk results of at least one sub-curve segment, and each cluster is set with a corresponding class label, which is set as the average value of the collaborative feature labels of all sub-curve segments therein; D2. Based on each cluster, obtain the class high-risk occupancy ratio, class high-risk average duration, and class risk intensity; D3. Weighted sum the ratio of class high-risk occupancy, average duration of class high-risk, and class risk intensity for all clusters respectively to obtain the risk event frequency, risk duration, and risk intensity value of this business project, which constitute the risk change characteristics. S302. Based on the risk change characteristics, calculate the comprehensive risk score of this business project, specifically: weighted sum the risk event frequency, risk duration, and risk intensity value. S303. According to the comprehensive risk score of each business project and the preset risk threshold interval, conduct differential control for each business project.

[0015] Preferably, in D3, the determination method of the weight factor for each cluster includes: based on each cluster, according to the preset time series distribution association algorithm, quantitatively analyze the time series correlation of the sub-curve segments therein, and determine the weight factor of this cluster.

[0016] Preferably, before S303, calculating the comprehensive risk score of this business project further includes: using the preset cross-business risk propagation model to update the comprehensive risk score of this business project; the preset cross-business risk propagation model specifically includes: S401. Based on the pre-constructed business association network, obtain the dependency intensity sequence of each business project. S402. Based on the dependency intensity sequence and comprehensive risk score of each business project, determine the risk propagation probability. S403. Use the risk propagation probability corresponding to the dependency intensity sequence and the comprehensive risk score to update the comprehensive risk score of this business project.

[0017] One or more technical solutions provided in this application have at least the following technical effects or advantages: By constructing a hyperbola in the time series, it can dynamically track and evaluate the risk changes of business projects, timely capture the evolution trend of risks, and provide real-time risk warnings and response strategies for enterprises; using the hyperbola collaborative trend analysis model, it can generate key risk feature vectors and input them into the business risk assessment model for accurate estimation of the risk level, and roughly give the most probable risk evolution types, such as regular operation and maintenance fluctuations, DDoS attacks, etc., providing targeted risk management opinions and references for enterprise risk control; based on the risk result sequences of each business project, it can be input into the enterprise risk control management mechanism to achieve intelligent risk control management, effectively improving the enterprise's risk response ability and management efficiency; it more accurately reflects the synergistic relationship between security and loss, and avoids the antagonistic relationship that may be masked by the traditional one-size-fits-all risk level value. To address the issues of fragmented local risk assessment and redundant risk patterns, the enterprise risk control management mechanism is optimized through clustering analysis and a comprehensive scoring model. The risks of scattered sub-curve segments are aggregated into an overall risk portrait of the business. The global risk patterns are clustered and integrated, and a comprehensive score is introduced to avoid fragmentation and enhance the insight into the overall trend. By introducing a time series distribution correlation algorithm, the determination method of each clustering weight factor is further refined, making the risk assessment more scientific and accurate, improving the accuracy and comprehensiveness of the risk assessment. By quantitatively analyzing the time series correlation of sub-curve segments, the distribution law and evolution trend of the collaborative relationship between multi-dimensional data over time can be better reflected, improving the reliability and stability of the risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 FIG. is a schematic flowchart of a smart risk control method based on enterprise multi-dimensional data according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] To facilitate the understanding of the present invention, the present application will be described more comprehensively with reference to the relevant drawings. The preferred embodiments of the present invention are shown in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.

[0020] It should be noted that the terms "vertical", "horizontal", "upper", "lower", "left", "right" and similar expressions used herein are for illustrative purposes only and do not represent the only embodiments.

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the description of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0022] Embodiment 1: Figure 1 FIG. is a schematic flowchart of a smart risk control method based on enterprise multi-dimensional data according to an embodiment of the present invention.

[0023] As Figure 1 shown, a smart risk control method based on enterprise multi-dimensional data includes the following steps: S101, obtaining a risk correlation data set of each business project of the enterprise within a preset time period, including security vulnerability feature data and potential loss feature data for each unit time.

[0024] Specifically, the preset time period can be set to the last month or adjusted according to actual needs. The unit time can be set to daily or weekly and can also be adjusted adaptively to reflect the risk correlation data within the time window.

[0025] It can be understood that the security vulnerability characteristic data reflects the enterprise's security management ability within a specific time window, integrating the frequency of security incidents and system stability. The security vulnerability characteristic data is obtained by weighted summation based on the quantization value of the security incident frequency and the quantization value of the security incident stability. The quantization value of the security incident frequency represents the number of security incidents occurring within the unit time, and the quantization value of the security incident stability represents the degree of impact of the security incident on business continuity (such as service interruption duration).

[0026] It can be understood that the potential loss characteristic data reflects the direct or indirect loss risks caused by security incidents to the enterprise, including financial losses and damaged business value. The potential loss characteristic data is obtained by weighted summation based on the value loss quantization value and the loss stability quantization value. The value loss quantization value is used to quantify the economic losses caused by security incidents (such as data breach compensation, customer churn cost), and the loss stability quantization value represents the degree of impact of the value loss on business continuity.

[0027] It should be noted that the above-presented data can be obtained from the enterprise's security log system (automatically recording network attacks, abnormal logins, malware events, etc.), operation and maintenance monitoring system (recording service interruption time), business impact analysis report (evaluating the impact of events on key business functions, such as order processing delays), financial system (direct losses, such as ransomware ransom, compliance fines), and customer relationship management data (indirect losses, such as increased customer churn rate, brand value depreciation), and data normalization processing is performed. The present invention will not elaborate and limit this.

[0028] S102. Based on the risk correlation data set, use the pre-set hyperbolic collaborative trend analysis model to generate key risk feature vectors.

[0029] In some embodiments, the pre-set hyperbolic collaborative trend analysis model specifically includes: S201. Construct a first curve and a second curve that are associated with the security vulnerability characteristic data and the potential loss characteristic data on the time series within the preset time period.

[0030] Specifically, the first curve is obtained by: calculating the product value of the security vulnerability characteristic data and the potential loss characteristic data as the first eigenvalue, and generating a curve fitted to the first eigenvalue on the time series as the first curve; the second curve is obtained by: calculating the collaborative quantization value of the security vulnerability characteristic data and the potential loss characteristic data as the second eigenvalue, and generating a curve fitted to the second eigenvalue on the time series as the second curve.

[0031] Among them, the method for obtaining the second eigenvalue is specifically as follows: A1. Independently construct curves for the security vulnerability feature data and potential loss feature data in the time series, which are L(t) and F(t) respectively; A2. Calculate the second eigenvalue according to the following formula:

[0032] Among them, is the second eigenvalue at time node t, is the covariance of L(t) and F(t) within the sliding window (pre-set, which can be set to the unit time window size or smaller than the unit time window size and can reflect the collaborative features within the small window) before time node t, capturing the contemporaneous collaboration (co-variation in the same or opposite directions), is the absolute value of the product of the change rates of the independent curves at time node t, identifying the accelerating collaboration (such as when L surges, F surges synchronously), is the pre-set weight coefficient, used to adjust the influence degree of the collaboration speed, and is pre-set according to the actual situation and requirements. For example, it is set to 0.4.

[0033] S202. Based on the first curve and the second curve, segment the first curve according to the second curve to generate a sub-curve segment sequence, and the sub-curve segment sequence includes several sub-curve segments arranged in chronological order.

[0034] Specifically, segmenting the first curve according to the second curve includes: Traverse the second eigenvalue step by step from the starting point of the second curve in the time series until the difference between the current second eigenvalue and the previous second eigenvalue is greater than the pre-set difference threshold (set according to the actual situation and expert experience, used to measure the jump degree of the second eigenvalue), then cut off to obtain a sub-curve segment, continue to traverse the remaining second curve until reaching the end point, generate all sub-curve segments, and form a sub-curve segment sequence.

[0035] Among them, each sub-curve segment is set with a corresponding collaboration feature label, and the collaboration feature label is: the average value of all second eigenvalues in the sub-curve segment.

[0036] S203. Extract features from the sub-curve segment sequence to obtain the key risk feature vector.

[0037] Specifically, extracting features from the sub-curve segment sequence includes: B1. Obtain the first curve segment corresponding to each sub-curve segment in the first curve (corresponding in terms of time).

[0038] B2. Based on the first curve segment, obtain the extreme difference value, average value, and variance value of its first eigenvalue as the key features of the first curve segment.

[0039] B3. Arrange the key features of all sub-curve segments in chronological order to form a key risk feature vector, that is, a key feature sequence.

[0040] S103. Input the key risk feature vector into the pre-trained business risk assessment model to output the risk result sequence corresponding to the business project.

[0041] In some embodiments, each business project corresponds to a business risk assessment model. The way to obtain the pre-trained business risk assessment model is as follows: C1. Collect a large number of risk correlation data sets within the preset time period in the history of the corresponding business project type, obtain the key risk feature vectors within each historical preset time period, and perform label annotation. The annotation content is set as the risk result sequence composed of the actual risk results of each sub-curve segment.

[0042] Among them, the actual risk result of each sub-curve segment includes the actual risk assessment value and its corresponding actual risk type. The risk assessment value is determined and scored by expert personnel according to the actual operation situation of the business project within the time window corresponding to the sub-curve segment, and the score is between 0 and 1. The larger the score, the worse the actual operation situation.

[0043] For example, sub-curve segment 1: risk assessment value = 0.3 (low risk, actual type is "routine operation and maintenance fluctuation"), sub-curve segment 2: risk assessment value = 0.8 (high risk, actual type is "business paralysis caused by DDoS attack").

[0044] C2. Use all the labeled key risk feature vectors as the training set, and use the training set to train the pre-selected neural network structure, continuously optimize the model parameters, and generate the final business risk assessment model.

[0045] S104. Based on the risk result sequences of each business project, input them into the pre-set enterprise risk control management mechanism for risk control management of each business project.

[0046] The technical solutions in the embodiments of the present application above have at least the following technical effects or advantages: By integrating and analyzing the security vulnerability characteristic data and potential loss characteristic data of various business projects of the enterprise in multiple dimensions, we have achieved in-depth fusion analysis of multi-dimensional data. Multi-dimensional data fusion helps to reveal the overall picture of enterprise business risks more comprehensively and improve the accuracy and comprehensiveness of risk assessment. By constructing a hyperbola on the time series, we can dynamically track and evaluate the risk changes of business projects, capture the evolution trend of risks in a timely manner, and provide enterprises with real-time risk warnings and response strategies. By using the hyperbola collaborative trend analysis model, we can generate key risk characteristic vectors and input them into the business risk assessment model to accurately estimate the risk level, and roughly give the risk evolution type with the highest probability, such as regular operation and maintenance fluctuations, DDoS attacks, etc., to provide targeted risk management opinions and references for enterprise risk control. Based on the risk result sequence of each business project, it can be input into the enterprise risk control management mechanism to realize intelligent risk control management, which effectively improves the enterprise's risk response capabilities and management efficiency.

[0047] The second eigenvalue is generated by multiplying the covariance and the rate of change to capture the synchronous synergy and accelerated synergy of safety and loss. The first curve is cut according to the dynamic difference of the second eigenvalue to identify the risk characteristics of different periods. The neural network is trained based on historical data, combined with multi-dimensional features such as range, mean, variance, etc., to output a sequence of risk results to adapt to personalized risk models for different business scenarios. It more accurately reflects the synergistic relationship between safety and loss, avoiding the antagonistic relationship that may be concealed by the traditional one-size-fits-all risk level value; by constructing a hyperbolic collaborative trend analysis model, it can more comprehensively analyze risk characteristics, improve the accuracy of risk assessment, and provide a more scientific and accurate basis for enterprise risk management, which helps enterprises to promptly discover and respond to potential risks.

[0048] Embodiment 2: Embodiment 1 provides multiple local risk assessments on the entire risk curve through the risk results of sub-curve segments. The risk results of each sub-curve segment are independent, and lack quantitative expression of the overall risk trend of the business project. It is necessary to further improve the risk result sequence and the enterprise risk control management mechanism; and the changing synergistic relationship between multi-dimensional data may reflect different risk patterns and characteristics. If risk assessments are directly performed on all sub-curve segments corresponding to the risk result sequence, it may lead to a waste of repetitive computing resources of the same pattern, and does not consider the evolution or change characteristics of different risk patterns within a preset time period.

[0049] Therefore, the embodiments of the present application are optimized to a certain extent based on the above embodiments.

[0050] In some embodiments, in step S104, the pre-set enterprise risk control management mechanism specifically includes: S301. Based on the risk result sequence of each business project, extract risk change features based on collaborative feature tags, including risk event frequency, risk duration, and risk intensity value.

[0051] Specifically, the way to obtain risk change features is as follows: D1. Obtain the collaborative feature tags of the sub-curve segment sequence corresponding to the risk result sequence. Based on the collaborative feature tags, cluster the risk results of all sub-curve segments (e.g., using the K-means algorithm) to obtain several clusters. Each cluster includes the risk results of at least one sub-curve segment, and each cluster is set with a corresponding class label, which is set as the average value of the collaborative feature tags of all sub-curve segments therein.

[0052] D2. Based on each cluster, obtain the ratio of high-risk cases in the class, the average duration of high-risk cases in the class, and the risk intensity of the class (quantifying the severity of threats).

[0053] Among them, the judgment condition for high risk is set as: the risk assessment value is greater than the preset risk threshold, and the preset risk threshold is set according to the actual situation and expert experience. For example, it is set to 0.6.

[0054] Among them, the ratio of high-risk cases in the class is set as the ratio of the number of high-risk occurrences to the total number of sub-curve segments in the cluster; the average duration of high-risk cases in the class is set as the average value of the durations of all high-risk sub-curve segments; the risk intensity of the class is set as: the sum of the products of the risk assessment values and the corresponding durations of all sub-curve segments, divided by the total duration (the sum of the durations of all sub-curve segments in this cluster), which is expressed as: , where n is the total number of sub-curve segments in the cluster, is the risk assessment value of the i-th sub-curve segment, is the duration of the i-th sub-curve segment, and T is the sum of the durations of all sub-curve segments in the cluster.

[0055] Among them, the duration of the sub-curve segment is set as the difference between the end time and the start time of the sub-curve segment.

[0056] D3. Perform weighted summation on the ratio of high-risk cases in the class, the average duration of high-risk cases in the class, and the risk intensity of the class for all clusters respectively to obtain the risk event frequency, risk duration, and risk intensity value of this business project, which constitute the risk change features.

[0057] Specifically, calculate the risk event frequency, risk duration, and risk intensity value according to the following formulas:

[0058] Among them, is the risk event frequency, is the ratio of high-risk cases in the class of the k-th cluster, is the risk duration is the average high - risk duration of the k - th cluster is the risk intensity value is the risk intensity of the k - th cluster, and M is the total number of all clusters is the pre - set weight factor of the k - th cluster, which is used to represent the influence degree value of this cluster on the overall risk change of the sub - curve segment sequence

[0059] S302. Based on the risk change characteristics, calculate the comprehensive risk score of this business project. Specifically: perform a weighted sum of the risk event frequency, risk duration, and risk intensity value

[0060] It should be noted that the weight values of the risk event frequency, risk duration, and risk intensity value can be set according to actual needs, or can be evenly distributed, and the sum is 1. For example, the weight value of the risk event frequency is set to 0.4, the weight value of the risk duration is set to 0.3, and the weight value of the risk intensity value is set to 0.3

[0061] S303. According to the comprehensive risk scores of each business project and the pre - set risk threshold interval, conduct differential control of each business project

[0062] Among them, the pre - set risk threshold interval is pre - set according to the actual situation and expert experience. For example, it is set to [0.4, 0.7]

[0063] Specifically, step S303 includes: determining the risk level of the business project according to the comprehensive risk score and the risk threshold interval When the comprehensive risk score is less than the lower limit value of the risk threshold interval, it is determined as a low - risk business project and routine monitoring is carried out When the comprehensive risk score is greater than the upper limit value of the risk threshold interval, it is determined as a high - risk business project, and this business project is suspended and the enterprise's emergency plan (the emergency plan for different business project types pre - set by the enterprise administrator) is started When the comprehensive risk score is within the risk threshold interval, it is determined as a medium - risk business project, and the audit resource allocation is reviewed and the audit is strengthened

[0064] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages Example 2: Based on Example 1, to address the issues of fragmented local risk assessment and redundant risk patterns, the enterprise risk control management mechanism is optimized through cluster analysis and comprehensive scoring model; the risks of scattered sub-curve segments are aggregated into an overall risk portrait of the business, the global risk patterns are clustered and integrated, and comprehensive scoring is introduced to avoid fragmentation and enhance the overall trend insight; the quantitative scoring model is adapted to complex risk scenarios to achieve the upgrade from "manual judgment" to "intelligent trigger"; redundant risk control inputs are reduced through pattern recognition to improve enterprise management efficiency. Through a data-driven approach, risk management is shifted from "post-event response" to "pre-event prevention", significantly enhancing the enterprise's security resilience. The pertinence and effectiveness of business project risk management are improved, and precise management of business projects with different risk levels is achieved through differential control.

[0065] The accuracy and comprehensiveness of business project risk assessment are improved. Through cluster analysis and weighted summation of the risk change characteristics of all clusters, richer risk characteristics are extracted globally, providing a more comprehensive and accurate risk assessment and management tool for the enterprise, helping the enterprise better identify, assess, and respond to potential risks, and ensuring the stable development of the enterprise.

[0066] Example 3: In Example 2, there is no specific limitation on how to determine the weight factors corresponding to each cluster when calculating the overall risk change characteristics. Traditional methods are generally based on expert experience and preset settings. However, risks often have relevance and variability in the time series within a preset period, and the distribution characteristics of several sub-curve segments within each cluster in the preset period time series are not considered, which may lead to final risk assessment deviations due to the differences in the reference values of different clusters.

[0067] Therefore, certain optimizations are made to this application example based on the above examples.

[0068] In some examples, in step D3, the determination method of the weight factor for each cluster includes: based on each cluster, according to the preset time series distribution association algorithm, that is, quantitatively analyzing the time series relevance of the sub-curve segments therein to determine the weight factor of the cluster.

[0069] Specifically, the time series distribution association algorithm is:

[0070] Among them, is the weight factor preset for the kth cluster, is the cluster time coverage ratio, is the time series distribution law index, is the preset weight coefficient used to adjust the weight ratio of the time coverage ratio and the time series distribution law index, and is set to 0.6, is the total duration of all sub-curve segments in the k-th cluster, is the length of the preset time period, is the disorder value of the distribution of sub-curve segments (the smaller the value, the more uniform the time intervals between sub-curve segments, and the stronger the evolution continuity or correlation). n is the total number of sub-curve segments in the cluster, is the interval between the start time of the i-th sub-curve segment and the start time of the (i + 1)-th sub-curve segment, is the average value of the intervals between the start times of all adjacent sub-curve segments in the cluster.

[0071] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By introducing the time series distribution correlation algorithm, the determination method of the clustering weight factor is further refined, making the risk assessment more scientific and accurate, improving the accuracy and comprehensiveness of the risk assessment. By quantitatively analyzing the time series correlation of sub-curve segments, it can better reflect the distribution law and evolution trend of the collaborative relationship between multi-dimensional data in time, and improve the reliability and stability of the risk assessment.

[0072] Embodiment 4: In a complex enterprise business system, there are complex dependency relationships between business projects, and risks will spread between businesses, but it is difficult to accurately quantify the impact of this spread. Traditional risk assessment methods often only focus on individual business projects and ignore the correlation between businesses, resulting in incomplete risk assessment. In the foregoing embodiments, the risk assessment of only individual business projects may be concerned, and each business project is analyzed and controlled independently.

[0073] Therefore, the embodiments of the present application are optimized on the basis of the above embodiments.

[0074] In some embodiments, before step S303, that is, after calculating the comprehensive risk score of the business project, it further includes: using a preset cross-business risk propagation model to update the comprehensive risk score of the business project. The preset cross-business risk propagation model specifically includes: S401, based on the pre-constructed business association network, obtain the dependency strength sequence of each business project, that is, the dependency strength sequence on other business projects. The dependency strength sequence includes at least one dependency strength value.

[0075] Specifically, the construction method of the business association network is: E1. Define all business projects within the enterprise (such as payment system, order processing system, inventory management system) as nodes, define the dependency relationships between business projects (such as data flow, resource sharing, process dependency) as edges, and define the dependency strength as the edge weight, which is used to represent the influence probability of the dependent party on the relying party, and is quantified through historical risk data statistics or expert evaluation, and is set between 0 and 1.

[0076] E2. Use the adjacency matrix G to represent the association network, indicating the dependence intensity of business item B on business item A. For example, if the impact probability of the failure of business item B on business item A is 0.8, then , the dependent party is business item B, and the party being depended on is business item A.

[0077] S402. Determine the risk propagation probability based on the dependence intensity sequence and the comprehensive risk score of each business item.

[0078] Specifically, use the preset risk propagation conditions to determine the risk propagation probability of each business party being depended on in the dependence intensity sequence:

[0079] is the risk propagation probability of the i-th party being depended on in the dependence intensity sequence for business item B, is the dependence intensity, is the initial comprehensive risk score of the party being depended on.

[0080] Among them, the risk propagation conditions are set as: ≥ and < , is the dependence intensity threshold, used to indicate that the dependence relationship between businesses triggers propagation only when it reaches a certain intensity. For example, = 0.6; is the risk score ratio threshold, used to indicate that propagation is allowed only when the dependent party is lower than a certain proportion of the party being depended on (it can also be used to measure the degree of cross-level of the risk levels corresponding to the comprehensive risk scores of two business items. The smaller the threshold, the greater the degree of cross-level, and it is set according to the size of the risk threshold interval). For example, = 0.4.

[0081] S403. Update the comprehensive risk score of this business item using the risk propagation probability and the comprehensive risk score corresponding to the dependence intensity sequence.

[0082] Specifically, calculate the updated comprehensive risk score of this business item according to the following formula:

[0083] Among them, is the updated comprehensive risk score of this business item, is the initial comprehensive risk score of this business item, is the total number of dependency strengths in the dependency strength sequence of the business project, that is, the number of dependent parties. is the risk propagation probability of the i-th dependent party in the dependency strength sequence for the business project. is the initial comprehensive risk score of the i-th dependent party.

[0084] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages: By constructing a business association network, the dependency relationships and strengths between business projects are clarified, providing basic data for subsequent risk propagation analysis; according to the dependency strength and risk score ratio, the risk propagation probability is determined, taking into account the strength of the dependency relationships between businesses and the differences in risk levels, making the risk propagation analysis more accurate; using the risk propagation probability and the initial comprehensive risk score of the dependent party to update the comprehensive risk score of the business project, more comprehensively reflecting the actual risk situation of the business project under cross-business risk propagation, avoiding the perspective limitation of risk assessment and the risk assessment deviation caused by ignoring the association relationships between businesses, and making the assessment results closer to the actual situation.

[0085] Through the cross-business risk propagation model, the limitation of isolated assessment of business risks in the traditional solution is solved. From the global perspective of a single business to an association network, latent risk links are identified (such as a payment failure causing the order system to crash); through risk propagation conditions, ineffective propagation and over-propagation are avoided, achieving precise propagation control. By quantifying the business project dependency relationships and propagation probabilities, the risk control process is upgraded from "point defense" to "network defense", building a more robust risk prevention and control system for enterprises and significantly enhancing the overall security resilience.

[0086] The above is only the preferred embodiment of the present invention and is not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A smart risk control method based on enterprise multi-dimensional data, characterized in that: include: S101, obtaining risk-related data sets of each business project of the enterprise within a preset period, including security vulnerability characteristic data and potential loss characteristic data of each unit time; S102, based on the risk association data set, using a preset hyperbolic collaborative trend analysis model, generating a key risk feature vector; S103, inputting the key risk feature vector into the pre-trained business risk assessment model, and outputting a risk result sequence corresponding to the business project; S104, based on the risk result sequence of each business project, input it into the preset enterprise risk control management mechanism to perform risk control management of each business project.

2. The intelligent risk control method based on enterprise multi-dimensional data according to claim 1, characterized in that: The preset hyperbolic collaborative trend analysis model specifically includes: S201, constructing a first curve and a second curve that associate security vulnerability feature data and potential loss feature data in a time series within a preset period of time; S202, based on the first curve and the second curve, segmenting the first curve according to the second curve to generate a sub-curve segment sequence, where the sub-curve segment sequence includes a plurality of sub-curve segments arranged in chronological order; S203, extracting features from the sub-curve segment sequence to obtain a key risk feature vector.

3. The intelligent risk control method based on enterprise multi-dimensional data as claimed in claim 2, characterized in that: The first curve is obtained by calculating the product of the security vulnerability characteristic data and the potential loss characteristic data as the first eigenvalue, and generating a curve fitting the first eigenvalue on the time series as the first curve; the second curve is obtained by calculating the coordinated quantization value of the security vulnerability characteristic data and the potential loss characteristic data as the second eigenvalue, and generating a curve fitting the second eigenvalue on the time series as the second curve.

4. The intelligent risk control method based on enterprise multi-dimensional data as claimed in claim 3, characterized in that: The method for obtaining the second characteristic value is specifically as follows: A1. Construct independent curves of security vulnerability characteristic data and potential loss characteristic data in time series, which are L(t) and F(t) respectively; A2. Calculate the second eigenvalue according to the following formula: in, is the second eigenvalue at time node t, is the covariance of L(t) and F(t) in the sliding window before time node t, is the absolute value of the product of the rate of change of the independent curve at time node t, It is a preset weight coefficient used to adjust the influence of collaborative speed.

5. The intelligent risk control method based on enterprise multi-dimensional data as claimed in claim 2, characterized in that: In S202, segmenting the first curve according to the second curve includes: According to the time sequence, the second characteristic value is traversed step by step from the starting point of the second curve until the difference between the current second characteristic value and the previous second characteristic value is greater than the preset difference threshold, then it is cut off to obtain a sub-curve segment, and the remaining second curves are traversed until the end point is reached, all sub-curve segments are generated, and a sub-curve segment sequence is formed; Each sub-curve segment is provided with a corresponding collaborative feature label, and the collaborative feature label is: the average value of all second eigenvalues ​​in the sub-curve segment.

6. The intelligent risk control method based on enterprise multi-dimensional data as claimed in claim 2, characterized in that: In S203, feature extraction is performed on the sub-curve segment sequence, including: B1. Obtain the first curve segment in the first curve corresponding to each sub-curve segment; B2. Based on the first curve segment, obtain the range, average, and variance of the first eigenvalue as the key features of the first curve segment; B3. The key features of all sub-curve segments are sequentially combined into a key risk feature vector in chronological order, namely, a key feature sequence.

7. The intelligent risk control method based on enterprise multi-dimensional data as claimed in claim 1, characterized in that: Each of the business items corresponds to a business risk assessment model. The pre-trained business risk assessment model is obtained as follows: C1. Collect a large number of risk-related data sets in the preset period of history for the corresponding business project types, obtain the key risk feature vectors in each historical preset period, and label them. The label content is set to a risk result sequence composed of the actual risk results of each sub-curve segment; the actual risk results of each sub-curve segment include the risk assessment value and its corresponding actual risk type; C2. Use all the labeled key risk feature vectors as training sets, use the training sets to train the pre-selected neural network structure, continuously optimize the model parameters, and generate the final business risk assessment model.

8. The intelligent risk control method based on enterprise multi-dimensional data as claimed in claim 5, characterized in that: In S104, the preset enterprise risk control management mechanism specifically includes: S301, based on the risk result sequence of each business project, extract risk change characteristics based on collaborative feature tags, including risk event frequency, risk duration, and risk intensity value; the risk change characteristics are obtained in the following manner: D1. Obtain collaborative feature labels of the sub-curve segment sequence corresponding to the risk result sequence, and cluster the risk results of all sub-curve segments based on the collaborative feature labels to obtain a number of clusters, each cluster including the risk result of at least one sub-curve segment, and each cluster is provided with a corresponding class label, which is set to the average value of the collaborative feature labels of all sub-curve segments therein; D2. Based on each cluster, obtain the proportion of high-risk classes, the average duration of high-risk classes, and the intensity of class risk; D3. Perform weighted summation of the high-risk proportion, average duration, and intensity of all clusters to obtain the risk event frequency, risk duration, and risk intensity value of the business project, which constitute the risk change characteristics; S302, based on the risk change characteristics, calculate the comprehensive risk score of the business project, specifically: weighted sum of the risk event frequency, risk duration, and risk intensity value; S303: Perform differentiated management and control of each business project based on the comprehensive risk score of each business project and the preset risk threshold range.

9. The intelligent risk control method based on enterprise multi-dimensional data according to claim 8, characterized in that: In D3, the weight factor of each cluster is determined by quantitatively analyzing the time series correlation of the sub-curve segments based on each cluster according to a preset time series distribution association algorithm to determine the weight factor of the cluster.

10. The intelligent risk control method based on enterprise multi-dimensional data according to claim 8, characterized in that: Before S303, the comprehensive risk score of the business project is calculated, and the method further includes: updating the comprehensive risk score of the business project by using a preset cross-business risk propagation model; the preset cross-business risk propagation model specifically includes: S401, obtaining a dependency strength sequence of each business item based on a pre-built business association network; S402, determining the risk propagation probability based on the dependency intensity sequence and comprehensive risk score of each business project; S403, using the risk propagation probability and the comprehensive risk score corresponding to the dependency strength sequence, update the comprehensive risk score of the business project.

Citation Information

Patent Citations

  • A multi-dimensional information evaluation method and system for enterprise safety index

    CN118917675B

  • Coal-fired unit intelligent decision operation control method and system based on working condition optimization

    CN118409501A

  • Multi-dimensional information evaluation method and system for enterprise safety index

    CN118917675A

  • Assessment method and device for operation safety of power distribution network, terminal equipment and storage medium

    CN119168383A

  • Railway roadbed deformation early warning grade determination method and system and storage medium

    CN119459816A