A Smart Risk Control Method Based on Enterprise Multidimensional Data
By building a hyperbolic collaborative trend analysis model and a business risk assessment model, combined with the enterprise risk control management mechanism, the problem of inaccurate risk assessment in enterprise risk supervision is solved, real-time dynamic monitoring and accurate assessment of enterprise risks is achieved, and management efficiency and response capabilities are improved.
Patent Information
- Application Number
- CN202510541840.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-28
AI Technical Summary
The existing technology cannot effectively capture the diversity and differentiated responses of risk sources in corporate risk supervision, resulting in inaccurate risk assessment and low management efficiency, and traditional methods cannot adapt to changes in the rapid development of the business.
By constructing a hyperbolic collaborative trend analysis model based on enterprise multidimensional data, key risk feature vectors are generated, and a pre-trained business risk assessment model is used for risk assessment and management, and differentiated control is carried out in combination with the enterprise risk control management mechanism, considering the dependence relationship and risk propagation between business projects.
Real-time dynamic monitoring and accurate assessment of enterprise risks is achieved, targeted risk management strategies are provided, and the accuracy and management efficiency of risk assessment are improved, the antagonistic relationship of risk degree values in traditional methods is avoided, and the company's risk response capabilities are improved.
Smart Images

Figure CN120069564B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data analysis, and in particular, to an intelligent risk control method based on enterprise multi-dimensional data. Background Art
[0002] Enterprises are the guarantee for the stable and long-term development of modern society, and enterprise security is the core competitiveness of enterprise development; the safe development of enterprises is an important benchmark for measuring the high-quality development, high-level security, and high-quality ecology of enterprises; nowadays, the progress of technology has led to the rapid expansion of social demands, and the information-based society has made the supply of business demands between enterprises and users become complex in type and rapid in quantity growth. Correspondingly, it is whether the business supervision technology can be balanced with its growth rate; currently, the types and quantities of enterprises are quite large, and the corresponding number of business processes has increased exponentially. Obviously, the traditional business supervision and analysis methods are no longer applicable to the current environment. While it is time-consuming and laborious to conduct business risk analysis manually, its low-intelligence analysis methods cannot match the changing speed of the current rapid business development. In the current environment with a large number of business quantities, it is prone to the potential risk of abnormal development of a large number of businesses.
[0003] The Chinese invention patent with the patent application number 202411412523.7 discloses a multi-dimensional information evaluation method for enterprise security indexes. By retrieving real-time business development data to analyze the risk values at each time point, using the risk value analysis at each point to fit the business curve development, and through comparison with the predicted data analysis, abnormal points of the current business are marked, and real-time risk monitoring of business projects is realized based on the processing results of abnormal points, which greatly improves the efficiency and accuracy of traditional business monitoring and realizes the timely monitoring of enterprise business security risks.
[0004] However, simply generating a risk degree value based on the product of the security development characteristic value and the potential loss characteristic value may cover up the antagonistic or synergistic relationship between security and loss, and lack the differential response mechanism to risk sources and the ability to capture the time dimension synergistic effect. Because the diversity of risk sources and the differential risk degrees will both have a certain impact on the risk control of the final enterprise risk. Summary of the Invention
[0005] This application provides an intelligent risk control method based on enterprise multi-dimensional data. Based on the collaborative relationship between multi-dimensional data, it can analyze risk characteristics more comprehensively, improve the accuracy of risk assessment and management efficiency.
[0006] This application provides an intelligent risk control method based on enterprise multi-dimensional data, including:
[0007] S101. Obtain the risk correlation data set of each business project of the enterprise within a preset time period, including the security vulnerability characteristic data and potential loss characteristic data of each unit time;
[0008] S102. Based on the risk correlation data set, use the preset hyperbolic collaborative trend analysis model to generate the key risk feature vector;
[0009] S103. Input the key risk feature vector into the pre-trained business risk assessment model to output the risk result sequence corresponding to the business project;
[0010] S104. Based on the risk result sequences of each business project, input them into the preset enterprise risk control management mechanism to perform risk control management on each business project.
[0011] Preferably, the preset hyperbolic collaborative trend analysis model specifically includes:
[0012] S201. Construct the first curve and the second curve that are associated with the security vulnerability characteristic data and potential loss characteristic data on the time series within the preset time period;
[0013] S202. Based on the first curve and the second curve, segment the first curve according to the second curve to generate a sequence of sub-curve segments, and the sequence of sub-curve segments includes several sub-curve segments arranged in chronological order;
[0014] S203. Extract features from the sequence of sub-curve segments to obtain the key risk feature vector.
[0015] Preferably, the obtaining method of the first curve is: calculate the product value of the security vulnerability characteristic data and the potential loss characteristic data as the first eigenvalue, and generate the curve fitted with the first eigenvalue on the time series as the first curve; the obtaining method of the second curve is: calculate the collaborative quantization value of the security vulnerability characteristic data and the potential loss characteristic data as the second eigenvalue, and generate the curve fitted with the second eigenvalue on the time series as the second curve.
[0016] Preferably, the obtaining method of the second eigenvalue is specifically:
[0017] A1. Respectively construct the independent curves of the security vulnerability characteristic data and the potential loss characteristic data on the time series, which are L(t) and F(t) respectively;
[0018] A2. Calculate the second eigenvalue according to the following formula:
[0019]
[0020] Where, is the second eigenvalue at the time node t, is the covariance of L(t) and F(t) within the sliding window before the time node t. is the absolute value of the product of the change rates of the independent curves at the time node t. is a preset weight coefficient used to adjust the influence degree of the collaboration speed.
[0021] Preferably, in the S202, segmenting the first curve according to the second curve includes:
[0022] Traverse the second eigenvalue gradually from the starting point of the second curve in time series until the difference between the current second eigenvalue and the previous second eigenvalue is greater than the preset difference threshold, then cut off to obtain a sub-curve segment, continue to traverse the remaining second curve until the end point is reached, generate all sub-curve segments, and form a sub-curve segment sequence;
[0023] Among them, each sub-curve segment is set with a corresponding collaboration feature label, and the collaboration feature label is: the average value of all second eigenvalues in the sub-curve segment.
[0024] Preferably, in the S203, extracting features from the sub-curve segment sequence includes:
[0025] B1. Obtain the first curve segment corresponding to each sub-curve segment in the first curve;
[0026] B2. Based on the first curve segment, obtain the extreme difference, average value, and variance value of its first eigenvalue as the key features of the first curve segment;
[0027] B3. Arrange the key features of all sub-curve segments in chronological order to form a key risk feature vector, that is, a key feature sequence.
[0028] Preferably, each of the said business items corresponds to a business risk assessment model. The way to obtain the pre-trained business risk assessment model is:
[0029] C1. Collect a large number of risk-related data sets within the preset time period in the history of the corresponding business item types, obtain the key risk feature vectors in each historical preset time period, and perform label annotation. The annotation content is set as a risk result sequence composed of the actual risk results of each sub-curve segment; the actual risk result of each sub-curve segment includes a risk assessment value and its corresponding actual risk type;
[0030] C2. Use all the labeled key risk feature vectors as the training set, and use the training set to train the pre-selected neural network structure, continuously optimize the model parameters, and generate the final business risk assessment model.
[0031] Preferably, in the S104, the preset enterprise risk control management mechanism specifically includes:
[0032] S301. Based on the risk result sequences of each business project, extract the risk change features based on collaborative feature tags, including the risk event frequency, risk duration, and risk intensity value. The method for obtaining the risk change features is as follows:
[0033] D1. Obtain the collaborative feature tags of the sub-curve segment sequences corresponding to the risk result sequences. Based on the collaborative feature tags, cluster the risk results of all sub-curve segments to obtain several clusters. Each cluster includes the risk results of at least one sub-curve segment, and each cluster is set with a corresponding class label, which is set as the average value of the collaborative feature tags of all sub-curve segments therein.
[0034] D2. Based on each cluster, obtain the high-risk proportion, average high-risk duration, and class risk intensity of the class.
[0035] D3. Perform weighted summation on the high-risk proportion, average high-risk duration, and class risk intensity of all clusters respectively to obtain the risk event frequency, risk duration, and risk intensity value of this business project, which constitute the risk change features.
[0036] S302. Based on the risk change features, calculate the comprehensive risk score of this business project, specifically: perform weighted summation on the risk event frequency, risk duration, and risk intensity value.
[0037] S303. According to the comprehensive risk scores of each business project and the preset risk threshold interval, conduct differential control on each business project.
[0038] Preferably, in D3, the determination method of the weight factor of each cluster includes: based on each cluster, according to the preset time series distribution association algorithm, quantitatively analyze the time series correlation of the sub-curve segments therein, and determine the weight factor of this cluster.
[0039] Preferably, before S303, when calculating the comprehensive risk score of this business project, it further includes: using the preset cross-business risk propagation model to update the comprehensive risk score of this business project. The preset cross-business risk propagation model specifically includes:
[0040] S401. Based on the pre-constructed business association network, obtain the dependency intensity sequence of each business project.
[0041] S402. Based on the dependency intensity sequence and comprehensive risk score of each business project, determine the risk propagation probability.
[0042] S403. Use the risk propagation probability corresponding to the dependency intensity sequence and the comprehensive risk score to update the comprehensive risk score of this business project.
[0043] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0044] By constructing a hyperbola in the time series, it is possible to dynamically track and evaluate the risk changes of business projects, timely capture the evolution trend of risks, and provide real-time risk warnings and response strategies for enterprises; using the hyperbola collaborative trend analysis model, it is possible to generate key risk feature vectors and input them into the business risk assessment model for accurate estimation of the risk level, and roughly give the risk evolution types with the highest probability, such as conventional operation and maintenance fluctuations, DDoS attacks, etc., providing targeted risk management opinions and references for enterprise risk control; based on the risk result sequences of each business project, it can be input into the enterprise risk control management mechanism to achieve intelligent risk control management, effectively improving the enterprise's risk response ability and management efficiency; it more accurately reflects the collaborative relationship between security and loss, avoiding the antagonistic relationship that may be masked by the traditional one-size-fits-all risk level value;
[0045] Aiming at the problems of fragmented local risk assessment and redundant risk patterns, optimize the enterprise risk control management mechanism through clustering analysis and comprehensive scoring model; aggregate the risks of scattered sub-curve segments into the overall business risk portrait, cluster and integrate the global risk patterns and introduce comprehensive scoring to avoid fragmentation and improve the overall trend insight; by introducing the time series distribution correlation algorithm, further refine the determination method of each clustering weight factor, making the risk assessment more scientific and accurate, improving the accuracy and comprehensiveness of risk assessment, and by quantitatively analyzing the time series correlation of sub-curve segments, it can better reflect the distribution law and evolution trend of the collaborative relationship between multi-dimensional data in time, improving the reliability and stability of risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 It is a schematic flowchart of the intelligent risk control method based on enterprise multi-dimensional data according to an embodiment of the present invention. DETAILED DESCRIPTION
[0047] To facilitate the understanding of the present invention, the present application will be described more comprehensively with reference to the relevant drawings; the drawings show preferred embodiments of the present invention, however, the present invention can be implemented in many different forms and is not limited to the embodiments described herein; on the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.
[0048] It should be noted that the terms "vertical", "horizontal", "up", "down", "left", "right" and similar expressions used herein are for illustrative purposes only and do not represent the only embodiments.
[0049] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this invention belongs; the terms used in the description of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention; the term "and / or" as used herein includes any and all combinations of one or more of the related listed items.
[0050] Embodiment 1: Figure 1 It is a schematic flowchart of the intelligent risk control method based on enterprise multi-dimensional data according to an embodiment of the present invention.
[0051] As Figure 1 shown, an intelligent risk control method based on enterprise multi-dimensional data includes the following steps:
[0052] S101, obtain a risk association data set of each business project of the enterprise within a preset time period, including security vulnerability characteristic data and potential loss characteristic data for each unit time.
[0053] Specifically, the preset time period can be set to the past month or adjusted according to actual needs. The unit time can be set to daily or weekly and can also be adaptively adjusted to reflect the risk association data within the time window.
[0054] It can be understood that the security vulnerability characteristic data reflects the enterprise's security management ability within a specific time window, integrating the frequency of security incidents and system stability; the security vulnerability characteristic data is obtained by weighted summation according to the quantization value of the security incident frequency and the quantization value of the security incident stability. The quantization value of the security incident frequency represents the number of security incidents occurring within the unit time, and the quantization value of the security incident stability represents the degree of impact of the security incident on business continuity (such as the service interruption duration).
[0055] It can be understood that the potential loss characteristic data reflects the direct or indirect loss risk caused by security incidents to the enterprise, including financial losses and business value impairment; the potential loss characteristic data is obtained by weighted summation according to the value loss quantization value and the loss stability quantization value. The value loss quantization value is used to quantify the economic losses caused by security incidents (such as data leakage compensation, customer churn cost), and the loss stability quantization value represents the degree of impact of the value loss on business continuity.
[0056] It should be noted that the above-presented data can be obtained from the enterprise's security log system (which automatically records network attacks, abnormal logins, malware events, etc.), operation and maintenance monitoring system (records service interruption time), business impact analysis report (evaluates the impact of events on key business functions, such as order processing delays), financial system (direct losses, such as ransomware ransoms, compliance fines), and customer relationship management data (indirect losses, such as increased customer churn rate, brand value depreciation), and data normalization processing is performed. The present invention will not elaborate and limit this.
[0057] S102. Based on the risk correlation data set, use the pre-set hyperbolic collaborative trend analysis model to generate key risk feature vectors.
[0058] In some embodiments, the pre-set hyperbolic collaborative trend analysis model specifically includes:
[0059] S201. Construct a first curve and a second curve that are associated with security vulnerability feature data and potential loss feature data on a time series within a preset time period.
[0060] Specifically, the acquisition method of the first curve is: calculate the product value of the security vulnerability feature data and the potential loss feature data as the first eigenvalue, and generate a curve fitted with the first eigenvalue on the time series as the first curve; the acquisition method of the second curve is: calculate the collaborative quantization value of the security vulnerability feature data and the potential loss feature data as the second eigenvalue, and generate a curve fitted with the second eigenvalue on the time series as the second curve.
[0061] Among them, the acquisition method of the second eigenvalue is specifically:
[0062] A1. Respectively construct independent curves of security vulnerability feature data and potential loss feature data on the time series, which are L(t) and F(t) respectively;
[0063] A2. Calculate the second eigenvalue according to the following formula:
[0064]
[0065] Among them, is the second eigenvalue at time node t, is the covariance of L(t) and F(t) within the sliding window (pre-set, which can be set to the unit time window size or less than the unit time window size, and can reflect the collaborative features within the small window) before time node t, capturing the synchronous collaboration (changing in the same or opposite direction), is the absolute value of the product of the change rates of the independent curves at time node t, identifying accelerated collaboration (such as when L surges, F surges synchronously), is a preset weight coefficient used to adjust the influence degree of the collaboration speed and is preset according to the actual situation and requirements. For example, it is set to 0.4.
[0066] S202. Based on the first curve and the second curve, segment the first curve according to the second curve to generate a sequence of sub-curve segments, and the sequence of sub-curve segments includes several sub-curve segments arranged in chronological order.
[0067] Specifically, segmenting the first curve according to the second curve includes:
[0068] Traverse the second eigenvalue gradually from the starting point of the second curve in the time series until the difference between the current second eigenvalue and the previous second eigenvalue is greater than a preset difference threshold (set according to the actual situation and expert experience and used to measure the jump degree of the second eigenvalue), then cut off to obtain a sub-curve segment, continue to traverse the remaining second curve until the end point is reached, generate all sub-curve segments, and form a sequence of sub-curve segments.
[0069] Among them, each sub-curve segment is set with a corresponding collaboration feature label, and the collaboration feature label is: the average value of all second eigenvalues in the sub-curve segment.
[0070] S203. Extract features from the sequence of sub-curve segments to obtain a key risk feature vector.
[0071] Specifically, extracting features from the sequence of sub-curve segments includes:
[0072] B1. Obtain the first curve segment corresponding to each sub-curve segment in the first curve (corresponding in terms of time).
[0073] B2. Based on the first curve segment, obtain the extreme difference, average value, and variance value of its first eigenvalue as the key features of this first curve segment.
[0074] B3. Arrange the key features of all sub-curve segments in chronological order to form a key risk feature vector, that is, a key feature sequence.
[0075] S103. Input the key risk feature vector into a pre-trained business risk assessment model and output a risk result sequence corresponding to the business project.
[0076] In some embodiments, each business project corresponds to a business risk assessment model. The way to obtain the pre-trained business risk assessment model is:
[0077] C1. Collect a large number of risk-related data sets within a preset period of time in the history of the corresponding business project type, obtain the key risk feature vectors within each historical preset period, and label them. The label content is set to a risk result sequence composed of the actual risk results of each sub-curve segment.
[0078] Among them, the actual risk result of each sub-curve segment includes the actual risk assessment value and its corresponding actual risk type. The risk assessment value is determined and scored by experts based on the actual operation of the business project within the time window corresponding to the sub-curve segment. The score is between 0 and 1. The larger the score, the worse the actual operation situation.
[0079] For example, sub-curve segment 1: risk assessment value = 0.3 (low risk, actual type is "regular operation and maintenance fluctuation"), sub-curve segment 2: risk assessment value = 0.8 (high risk, actual type is "DDoS attack causes business paralysis").
[0080] C2. Use all the labeled key risk feature vectors as training sets, use the training sets to train the pre-selected neural network structure, continuously optimize the model parameters, and generate the final business risk assessment model.
[0081] S104, based on the risk result sequence of each business project, input it into the pre-set enterprise risk control management mechanism to perform risk control management of each business project.
[0082] The technical solutions in the above embodiments of the present application have at least the following technical effects or advantages:
[0083] By integrating and analyzing the security vulnerability characteristic data and potential loss characteristic data of various business projects of the enterprise in multiple dimensions, we have achieved in-depth fusion analysis of multi-dimensional data. Multi-dimensional data fusion helps to reveal the overall picture of enterprise business risks more comprehensively and improve the accuracy and comprehensiveness of risk assessment. By constructing a hyperbola on the time series, we can dynamically track and evaluate the risk changes of business projects, capture the evolution trend of risks in a timely manner, and provide enterprises with real-time risk warnings and response strategies. By using the hyperbola collaborative trend analysis model, we can generate key risk characteristic vectors and input them into the business risk assessment model to accurately estimate the risk level, and roughly give the risk evolution type with the highest probability, such as regular operation and maintenance fluctuations, DDoS attacks, etc., to provide targeted risk management opinions and references for enterprise risk control. Based on the risk result sequence of each business project, it can be input into the enterprise risk control management mechanism to realize intelligent risk control management, which effectively improves the enterprise's risk response capabilities and management efficiency.
[0084] Generate the second eigenvalue through the product of covariance and rate of change, capture the synchronous and accelerating synergies between safety and loss, cut the first curve according to the dynamic differences of the second eigenvalue, and identify the risk characteristics in different time periods; train a neural network based on historical data, combine multi-dimensional features such as range, mean, and variance, output a risk result sequence, and adapt to the personalized risk patterns of different business scenarios;
[0085] It more accurately reflects the synergistic relationship between safety and loss, and avoids the antagonistic relationship that may be masked by the traditional one-size-fits-all risk degree value; by constructing a hyperbolic curve synergy trend analysis model, it can more comprehensively analyze risk characteristics, improve the accuracy of risk assessment, provide a more scientific and accurate basis for enterprise risk control management, and help enterprises discover and respond to potential risks in a timely manner.
[0086] Example 2: Example 1 provides multiple local risk assessments on the entire risk curve through the risk results of sub-curve segments. The risk results of each sub-curve segment are independent, lacking a quantitative expression of the overall risk trend of business projects, and further improvement is required for the risk result sequence and the enterprise risk control management mechanism; moreover, the change synergy relationship between multi-dimensional data may reflect different risk patterns and characteristics. If direct risk assessment is performed on all sub-curve segments corresponding to the risk result sequence, it may lead to waste of repetitive computing resources for the same pattern, and the evolution or change characteristics of different risk patterns within the preset time period are not considered.
[0087] Therefore, the embodiments of this application are optimized on the basis of the above embodiments.
[0088] In some embodiments, in step S104, the preset enterprise risk control management mechanism specifically includes:
[0089] S301, based on the risk result sequence of each business project, extract the risk change characteristics based on the synergy feature labels, including the frequency of risk events, the duration of risk persistence, and the risk intensity value.
[0090] Specifically, the acquisition method of the risk change characteristics is as follows:
[0091] D1. Obtain the synergy feature labels of the sub-curve segment sequence corresponding to the risk result sequence. Based on the synergy feature labels, cluster the risk results of all sub-curve segments (for example, the K-means algorithm) to obtain several clusters. Each cluster includes the risk results of at least one sub-curve segment, and each cluster is set with a corresponding class label, which is set as the average value of the synergy feature labels of all sub-curve segments therein.
[0092] D2. Based on each cluster, obtain the proportion of high-risk in the class, the average duration of high-risk in the class, and the class risk intensity (quantifying the severity of the threat).
[0093] Among them, the judgment condition for high risk is set as: the risk assessment value is greater than the preset risk threshold, and the preset risk threshold is set according to the actual situation and expert experience. For example, it is set to 0.6.
[0094] Among them, the ratio of the high-risk category is set as the ratio of the number of high-risk occurrences to the total number of sub-curve segments in the clustering; the average duration of the high-risk category is set as the average value of the durations of the sub-curve segments of all high risks; the risk intensity of the category is set as: the ratio of the sum of the products of the risk assessment values of all sub-curve segments and the corresponding durations to the total duration (the sum of the durations of all sub-curve segments in this clustering), expressed as: , where n is the total number of sub-curve segments in the clustering, is the risk assessment value of the i-th sub-curve segment, is the duration of the i-th sub-curve segment, and T is the sum of the durations of all sub-curve segments in the clustering.
[0095] Among them, the duration of the sub-curve segment is set as the difference between the end time and the start time of the sub-curve segment.
[0096] D3. Weighted sum the ratio of the high-risk category, the average duration of the high-risk category, and the risk intensity of all clusterings respectively to obtain the risk event frequency, risk duration, and risk intensity value of this business project, which constitute the risk change characteristics.
[0097] Specifically, calculate the risk event frequency, risk duration, and risk intensity value according to the following formula:
[0098]
[0099] Among them, is the risk event frequency, is the ratio of the high-risk category of the k-th clustering, is the risk duration, is the average duration of the high-risk category of the k-th clustering, is the risk intensity value, is the risk intensity of the k-th clustering, M is the total number of all clusterings, is the pre-set weight factor of the k-th clustering, which is used to represent the influence degree value of this clustering on the overall risk change of the sub-curve segment sequence.
[0100] S302. Based on the risk change characteristics, calculate the comprehensive risk score of this business project. Specifically: Weighted sum the risk event frequency, risk duration, and risk intensity value.
[0101] It should be noted that the weight values of the risk event frequency, risk duration, and risk intensity value can be set according to actual needs, or evenly distributed, with the sum being 1. For example, the weight value of the risk event frequency is set to 0.4, the weight value of the risk duration is set to 0.3, and the weight value of the risk intensity value is set to 0.3.
[0102] S303. According to the comprehensive risk scores of each business project and the preset risk threshold range, perform differential control on each business project.
[0103] Among them, the preset risk threshold range is preset according to the actual situation and expert experience. For example, it is set to [0.4, 0.7].
[0104] Specifically, step S303 includes: determining the risk level of the business project according to the comprehensive risk score and the risk threshold range:
[0105] When the comprehensive risk score is less than the lower limit value of the risk threshold range, it is determined as a low-risk business project and routine monitoring is performed;
[0106] When the comprehensive risk score is greater than the upper limit value of the risk threshold range, it is determined as a high-risk business project, and the business project is suspended and the enterprise's emergency plan (the emergency plan for different business project types preset by the enterprise administrator) is activated;
[0107] When the comprehensive risk score is within the risk threshold range, it is determined as a medium-risk business project, and the audit resource allocation is reviewed and the audit is strengthened.
[0108] The technical solutions in the embodiments of the present application described above have at least the following technical effects or advantages:
[0109] On the basis of Embodiment 1, in Embodiment 2, aiming at the problems of fragmented local risk assessment and redundant risk patterns, the enterprise risk control management mechanism is optimized through clustering analysis and comprehensive scoring model; the risks of scattered sub-curve segments are aggregated into the overall risk portrait of the business, the global risk patterns are clustered and integrated, and comprehensive scoring is introduced to avoid fragmentation and improve the overall trend insight; the quantitative scoring model is adapted to complex risk scenarios to achieve the upgrade from "manual judgment" to "intelligent triggering"; redundant risk control investment is reduced through pattern recognition, and the enterprise management efficiency is improved. Through a data-driven method, risk management is shifted from "post-event response" to "pre-event prevention", significantly enhancing the enterprise's safety resilience. The pertinence and effectiveness of business project risk management are improved, and through differential control, precise management of business projects with different risk levels is achieved.
[0110] It improves the accuracy and comprehensiveness of business project risk assessment. By means of cluster analysis and weighted summation of the risk change characteristics of all clusters, richer risk characteristics are extracted globally, providing a more comprehensive and accurate risk assessment and management tool for enterprises, helping enterprises better identify, assess and respond to potential risks, and ensuring the stable development of enterprises.
[0111] Embodiment 3: In Embodiment 2, there is no specific limitation on how to determine the weight factors corresponding to each cluster when calculating the overall risk change characteristics. Traditional methods are generally based on expert experience and preset settings. However, risks often have relevance and variability in the time series within a preset period, and the distribution characteristics of several sub-curve segments in each cluster in the time series within the preset period are not considered. It may lead to deviation in the final risk assessment due to the difference in the reference value of different clusters.
[0112] Therefore, the embodiments of the present application are optimized to a certain extent on the basis of the above embodiments.
[0113] In some embodiments, in step D3, the determination method of the weight factor of each cluster includes: based on each cluster, according to the preset time series distribution association algorithm, that is, quantitatively analyzing the time series relevance of the sub-curve segments therein to determine the weight factor of the cluster.
[0114] Specifically, the time series distribution association algorithm is:
[0115]
[0116] Among them, is the weight factor preset for the kth cluster, is the cluster time coverage ratio, is the time series distribution law index, is the preset weight coefficient used to adjust the weight ratio of the time coverage ratio and the time series distribution law index, and is set to 0.6, is the total duration of all sub-curve segments in the kth cluster, is the length of the preset period, is the sub-curve segment distribution clutter value (the smaller the value, the more uniform the time interval between sub-curve segments, and the stronger the evolution continuity or relevance), n is the total number of sub-curve segments in the cluster, is the interval between the start time of the ith sub-curve segment and the start time of the i + 1th sub-curve segment, is the average value of the intervals between the start times of all adjacent sub-curve segments in the cluster.
[0117] The technical solutions in the embodiments of the present application at least have the following technical effects or advantages:
[0118] By introducing a time - series distribution correlation algorithm, the determination method of the clustering weight factor is further refined, making the risk assessment more scientific and accurate, improving the accuracy and comprehensiveness of the risk assessment. By quantifying the time - series correlation of sub - curve segments, it can better reflect the distribution law and evolution trend of the collaborative relationship between multi - dimensional data in time, improving the reliability and stability of the risk assessment.
[0119] Example 4: In a complex enterprise business system, there are complex dependencies between business projects, and risks can spread between businesses, but it is difficult to accurately quantify the impact of this spread. Traditional risk assessment methods often only focus on individual business projects and ignore the correlation between businesses, resulting in incomplete risk assessment. In the foregoing examples, the risk assessment of only individual business projects may be concerned, and each business project is analyzed and controlled independently.
[0120] Therefore, the embodiments of the present application are optimized to a certain extent on the basis of the above - mentioned embodiments.
[0121] In some embodiments, before step S303, that is, after calculating the comprehensive risk score of the business project, it further includes: using a preset cross - business risk propagation model to update the comprehensive risk score of the business project. The preset cross - business risk propagation model specifically includes:
[0122] S401, based on a pre - constructed business association network, obtain the dependence intensity sequence of each business project, that is, the dependence intensity sequence on other business projects. The dependence intensity sequence includes at least one dependence intensity value.
[0123] Specifically, the construction method of the business association network is as follows:
[0124] E1. Define all business projects within the enterprise (such as payment systems, order processing systems, inventory management systems) as nodes, the dependencies between business projects (such as data flow, resource sharing, process dependence) as edges, and the dependence intensity as edge weights, which are used to represent the influence probability of the dependent party on the relying party. It is quantified through historical risk data statistics or expert evaluation and set to be between 0 and 1.
[0125] E2. Use an adjacency matrix G to represent the association network, represents the dependence intensity of business project B on business project A. For example, if the impact probability of the failure of business project B on business project A is 0.8, then , the relying party is business project B, and the dependent party is business project A.
[0126] S402, based on the dependence intensity sequence and comprehensive risk score of each business project, determine the risk propagation probability.
[0127] Specifically, using the preset risk propagation conditions, determine the risk propagation probability of each business's dependent party in the dependence intensity sequence:
[0128]
[0129] is the risk propagation probability of the i-th dependent party in the dependence intensity sequence for business project B, is the dependence intensity, is the initial comprehensive risk score of the dependent party.
[0130] Among them, the risk propagation conditions are set as: ≥ and < , is the dependence intensity threshold, used to indicate that the dependence relationship between businesses triggers propagation only when it reaches a certain intensity. For example, = 0.6; is the risk score ratio threshold, used to indicate that propagation is allowed only when the dependent party is lower than a certain proportion of the dependent party (it can also be used to measure the degree of cross-level of the risk levels corresponding to the comprehensive risk scores of two business projects. The smaller the threshold, the greater the degree of cross-level, and it is set according to the size of the risk threshold interval). For example, = 0.4.
[0131] S403. Update the comprehensive risk score of this business project using the risk propagation probability and comprehensive risk score corresponding to the dependence intensity sequence.
[0132] Specifically, calculate the updated comprehensive risk score of this business project according to the following formula:
[0133]
[0134] Among them, is the updated comprehensive risk score of this business project, is the initial comprehensive risk score of this business project, is the total number of dependence intensities in the dependence intensity sequence of this business project, that is, the number of dependent parties, is the risk propagation probability of the i-th dependent party in the dependence intensity sequence for this business project, is the initial comprehensive risk score of the i-th dependent party.
[0135] The technical solutions in the embodiments of the present application described above have at least the following technical effects or advantages:
[0136] By constructing a business association network, the dependence relationships and intensities among various business projects are clarified, providing basic data for subsequent risk propagation analysis; according to the dependence intensity and risk score ratio, the risk propagation probability is determined, taking into account the intensity of the dependence relationship between businesses and the difference in risk levels, making the risk propagation analysis more accurate; using the risk propagation probability and the initial comprehensive risk score of the dependent party to update the comprehensive risk score of the business project, more comprehensively reflecting the actual risk status of the business project under cross-business risk propagation, avoiding the perspective limitation of risk assessment and the risk assessment deviation caused by ignoring the association relationship between businesses, and making the assessment result closer to the actual situation.
[0137] Through the cross-business risk propagation model, the limitation of isolated assessment of business risks in traditional solutions is solved. From the global perspective of a single business to an association network, latent risk links are identified (such as a payment failure triggering the collapse of an order system); through risk propagation conditions, ineffective propagation and over-propagation are avoided, achieving precise propagation control.
[0138] By quantifying the dependence relationship and propagation probability of business projects, the risk control process is upgraded from "point defense" to "network defense", constructing a more robust risk prevention and control system for enterprises and significantly enhancing the overall security resilience.
[0139] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, various changes and modifications can be made to the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A smart risk control method based on enterprise multi-dimensional data, characterized in that, Including: S101, obtaining a risk correlation dataset of each business project of the enterprise within a preset time period, including security vulnerability characteristic data and potential loss characteristic data for each unit time; S102. Based on the risk-associated data set, use the hyperbolic co-trend analysis model to generate key risk feature vectors, including: constructing a first curve and a second curve that are associated with the security vulnerability feature data and the potential loss feature data on the time series within a preset time period, calculating the product value of the security vulnerability feature data and the potential loss feature data as the first eigenvalue, and generating a curve fitted with the first eigenvalue on the time series as the first curve; calculating the co-quantification value of the security vulnerability feature data and the potential loss feature data as the second eigenvalue, and generating a curve fitted with the second eigenvalue on the time series as the second curve; the way to obtain the second eigenvalue is: respectively construct independent curves L(t) and F(t) of the security vulnerability feature data and the potential loss feature data on the time series, and calculate the second eigenvalue according to the following formula: , is the second eigenvalue at time node t, is the covariance of L(t) and F(t) within the sliding window before time node t, is the absolute value of the product of the change rates of the independent curves at time node t, is a preset weight coefficient used to adjust the influence degree of the co-speed; segment the first curve according to the second curve to generate a sub-curve segment sequence, including: traversing the second eigenvalue step by step from the starting point of the second curve according to the time series until the difference between the current second eigenvalue and the previous second eigenvalue is greater than the preset difference threshold, then cutting off to obtain a sub-curve segment, continuing to traverse the remaining second curve until the end point is reached to generate all sub-curve segments, forming a sub-curve segment sequence, setting the average value of all second eigenvalues in each sub-curve segment as the co-feature label of the sub-curve segment, and the sub-curve segment sequence includes several sub-curve segments arranged in chronological order; perform feature extraction on the sub-curve segment sequence to obtain the key risk feature vector; S103, inputting the key risk feature vector into a pre-trained business risk assessment model, and outputting a risk result sequence corresponding to the business project; S104, based on the risk result sequences of each business project, inputting them into a preset enterprise risk control management mechanism to conduct risk control management for each business project.
2. The intelligent risk control method based on enterprise multi-dimensional data according to claim 1, wherein The feature extraction of the sub-curve segment sequence includes: B1, obtaining the first curve segment corresponding to each sub-curve segment in the first curve; B2, based on the first curve segment, obtaining the extreme difference, average value, and variance value of its first eigenvalue as the key features of the first curve segment; B3, sequentially forming a key risk feature vector, that is, a key feature sequence, by the key features of all sub-curve segments in chronological order.
3. The intelligent risk control method based on enterprise multi-dimensional data according to claim 1, characterized in that, Each of the above-mentioned business projects corresponds to a business risk assessment model. The pre-trained business risk assessment model is obtained in the following way: C1, collecting a large number of risk correlation datasets of corresponding business project types within a preset time period in history, obtaining the key risk feature vectors for each historical preset time period, and performing label annotation. The annotation content is set as a risk result sequence composed of the actual risk results of each sub-curve segment; the actual risk result of each sub-curve segment includes a risk assessment value and its corresponding actual risk type; C2, using all the labeled key risk feature vectors as a training set, training a pre-selected neural network structure with the training set, continuously optimizing the model parameters, and generating the final business risk assessment model.
4. The intelligent risk control method based on enterprise multi-dimensional data according to claim 1, characterized in that In S104, the preset enterprise risk control management mechanism specifically includes: S301, based on the risk result sequences of each business project, extracting risk change features based on collaborative feature labels, including risk event frequency, risk duration, and risk intensity value; the risk change features are obtained in the following way: D1, obtaining the collaborative feature labels of the sub-curve segment sequence corresponding to the risk result sequence, clustering the risk results of all sub-curve segments based on the collaborative feature labels to obtain several clusters. Each cluster includes the risk results of at least one sub-curve segment, and each cluster is set with a corresponding class label, which is set as the average value of the collaborative feature labels of all sub-curve segments therein; D2, based on each cluster, obtaining the proportion of high-risk in the class, the average duration of high-risk in the class, and the risk intensity of the class; D3, respectively performing weighted summation on the proportion of high-risk in the class, the average duration of high-risk in the class, and the risk intensity of all clusters to obtain the risk event frequency, risk duration, and risk intensity value of the business project, which constitute the risk change features; S302, based on the risk change features, calculating the comprehensive risk score of the business project, specifically: performing weighted summation on the risk event frequency, risk duration, and risk intensity value; S303, according to the comprehensive risk scores of each business project and the preset risk threshold interval, conducting differential control for each business project.
5. The intelligent risk control method based on enterprise multi-dimensional data according to claim 4, wherein, In D3, the method for determining the weight factor of each cluster includes: based on each cluster, according to a preset time series distribution association algorithm, quantitatively analyzing the time series correlation of the sub-curve segments therein, and determining the weight factor of the cluster.
6. The intelligent risk control method based on enterprise multi-dimensional data according to claim 4, characterized in that, Before S303, calculating the comprehensive risk score of the business project further includes: using a preset cross-business risk propagation model to update the comprehensive risk score of the business project; the preset cross-business risk propagation model specifically includes: S401, obtaining the dependence intensity sequence of each business project based on a pre-constructed business association network; S402, determining the risk propagation probability based on the dependence intensity sequence and the comprehensive risk score of each business project; S403, using the risk propagation probability corresponding to the dependence intensity sequence and the comprehensive risk score to update the comprehensive risk score of the business project.
Citation Information
Patent Citations
A multi-dimensional information evaluation method and system for enterprise safety index
CN118917675B
Multi-dimensional information evaluation method and system for enterprise safety index
CN118917675A
Railway roadbed deformation early warning grade determination method and system and storage medium
CN119459816A