Block chain-based big data analysis decision method and system
By adopting blockchain-based big data analysis and decision-making methods in the financial industry, combining blockchain data, historical feature information and public security case screening database, the problem of single-in-one risk behavior monitoring process in traditional technology is solved, and the accuracy and efficiency of risk detection are improved.
Patent Information
- Application Number
- CN202510157845.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-03
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The risk behavior monitoring process in the financial industry in traditional technology is single, resulting in misjudgment and inefficient decision-making.
The big data analysis and decision-making method based on blockchain is adopted, and the target data on the blockchain is obtained, the transmission path is counted, the correlation coefficient and risk abnormality trends are extracted in historical feature information, and the matching analysis is carried out in combination with the public security case screening database to comprehensively judge the risk abnormality of the part of the data to be verified.
It enhances the diversity analysis of risk abnormal detection results, reduces the chance of misjudgment, and improves the efficiency of data security monitoring.
Smart Images

Figure CN120088068A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data analysis technology, and in particular to a big data analysis decision-making method and system based on blockchain. Background Art
[0002] The real-time and tamper-proof nature of blockchain technology enables financial institutions to monitor the occurrence and development of risk events in real time. Once an abnormal situation is discovered, timely measures can be taken to respond and reduce risk losses.
[0003] In traditional technology, the judgment process for monitoring whether there are risky behaviors in the financial industry is relatively simple. For example, only abnormalities are detected based on the data on the blockchain, and no further verification is performed for misjudgments, resulting in errors in the final judgment results, resulting in low efficiency in the final decision-making work. Summary of the invention
[0004] In order to overcome the above-mentioned deficiencies of the prior art, the present application provides a big data analysis and decision-making method and system based on blockchain.
[0005] In a first aspect, the present application provides a big data analysis and decision-making method based on blockchain, the method comprising:
[0006] Obtain the target data to be detected on the blockchain, count the target delivery paths through which the target data is delivered, and if the target delivery path is a cross-network path, extract the historical parallel paths from the acquired historical feature information, and extract the correlation coefficients between the paths in the historical cross-paths;
[0007] Extracting part of the data to be verified that has not been determined to have risk anomalies from the target data, if there is an intersection in the target delivery path, predicting the risk anomalies of the part of the data to be verified according to the correlation coefficient, and synthesizing the prediction results to obtain a comprehensive data monitoring result, so as to make targeted data security decisions and obtain data analysis decision results;
[0008] If there is at least one intersection in the target transport path, obtain the public security case screening database, and judge whether the part of the data to be verified has risk anomalies based on the correlation coefficient and the screening matching degree between the part of the data to be verified and the public security case screening database, and output the comprehensive data monitoring results to make targeted data security decisions and obtain data analysis decision results;
[0009] If the target transport path is a parallel network path, extract the historical parallel path from the historical feature information, calculate the comprehensive concentrated position trend of risk anomalies in the historical parallel path during the historical period, and predict the current risk position correlation trend of the transport path to be tested based on the comprehensive concentrated position trend;
[0010] Based on the matching coincidence degree between the trend associated with the current risk position and the trend of the concentrated positions of risk anomalies in the statistically obtained historical parallel paths, judge the risk anomaly situation of the data to be proved, output the comprehensive data monitoring result, and make a targeted data security decision to obtain the data analysis decision result.
[0011] Preferably, obtain the target data to be detected on the blockchain, perform risk anomaly detection on the target data, and when the risk anomaly of the target data can be directly judged, output the data monitoring result;
[0012] When the risk anomaly of the target data cannot be directly judged, count the paths through which the target data is transported to obtain the target transport path;
[0013] Obtain historical feature information, and train a data risk simulation prediction model according to the historical feature information;
[0014] If the target transport path is a cross-network path, extract the historical cross paths from the historical feature information;
[0015] Extract the correlation degree coefficients between the paths in the historical cross paths to obtain the correlation coefficients.
[0016] Preferably, extract the first judged part of the data that has been determined to have a risk anomaly from the target data, and extract the data to be proved that has not been determined to have a risk anomaly from the target data;
[0017] If there is one intersection point in the target transport path, input the first judged part of the data, the data to be proved, and the correlation coefficient into the data risk simulation prediction model to predict whether there is a risk anomaly in the data to be proved to obtain the result of the second judged part of the data;
[0018] The judgment result of the first judged part of the data and the result of the second judged part of the data are combined into a comprehensive data monitoring result;
[0019] According to the comprehensive data monitoring result, make a targeted data security decision to obtain the data analysis decision result.
[0020] Preferably, if there are not less than one intersection point in the target transport path, extract the judged sub-part of the data that has an intersection point with the path where the data to be proved is located from the first judged part of the data;
[0021] Input the judged sub-part of the data, the correlation coefficient, and the data to be proved into the data risk simulation prediction model to predict whether there is a risk anomaly in the data to be proved to obtain the first prediction result;
[0022] Obtain the public security case screening database, and match the sentenced sub - part data and the data to be proved with the public security case screening database to obtain the screening matching degree;
[0023] Preset a matching judgment threshold. When the screening matching degree is greater than or equal to the matching judgment threshold, it is determined that there is a risk anomaly in the data to be proved, and a risk anomaly prediction result is output;
[0024] When the screening matching degree is less than the matching judgment threshold, it is determined that there is no risk anomaly in the data to be proved, and a normal prediction result is output;
[0025] If the first prediction result and the risk anomaly prediction result are the same, then it is comprehensively verified that the data to be proved is risk - abnormal data, and a monitoring result one is output;
[0026] If the first prediction result and the prediction result are the same, then it is comprehensively verified that the data to be proved is normal data, and a monitoring result two is output;
[0027] The judgment result of the first sentenced part data and the monitoring result one or the result of the first sentenced part data and the monitoring result two are combined into a comprehensive data monitoring result;
[0028] According to the comprehensive data monitoring result, formulate a targeted data security decision to obtain a data analysis decision result.
[0029] Preferably, if the target transmission path is a parallel network path, then extract the historical parallel path from the historical feature information;
[0030] Count multiple historical concentrated time periods in which risk anomalies occurred in the historical parallel path during the historical period to obtain a historical concentrated time period set. Statistically analyze the risk anomaly occurrence concentrated position trends of every three adjacent groups of transmission paths within each concentrated time period in the historical concentrated time period set to obtain a concentrated trend path set, and comprehensively calculate the average value of the concentrated trend path set to obtain a comprehensive concentrated position trend;
[0031] Obtain the to - be - measured transmission path where the data to be proved is located, and screen out the associated transmission path one of the sentenced data one and the associated transmission path two of the sentenced data two adjacent to the to - be - measured transmission path in the first sentenced part data;
[0032] According to the comprehensive concentrated position trend, the sentenced data one and the sentenced data two, predict the current risk position association trend between the to - be - measured transmission path, the associated transmission path one, and the associated transmission path two.
[0033] Preferably, a trend overlap threshold is preset. If the matching overlap between the current risk position associated trend and the central trend path set is not less than the trend overlap threshold, the partial data to be verified is judged to be risk abnormal data. If the matching overlap between the current risk position associated trend and the central trend path set is less than the trend overlap threshold, the partial data to be verified is judged to be normal data, and the third judged partial data result is output;
[0034] The judgment result of the first judged partial data and the result of the third judged partial data are combined into a comprehensive data monitoring result;
[0035] Based on the comprehensive data monitoring results, targeted data security decisions are made to obtain data analysis decision results.
[0036] Second, a big data analysis and decision-making system based on blockchain, including:
[0037] A correlation coefficient extraction unit is used to obtain the target data to be detected on the blockchain, and to count the target delivery path through which the target data is delivered. If the target delivery path is a cross-network path, the historical parallel path is extracted from the acquired historical feature information, and the correlation coefficient between each path in the historical cross path is extracted;
[0038] The situation one analysis and decision unit is used to extract the part of the data to be verified that has not been determined to have risk anomalies from the target data. If there is an intersection in the target transportation path, the risk anomaly of the part of the data to be verified is predicted according to the correlation coefficient, and the prediction results are combined to obtain the comprehensive data monitoring results, so as to make targeted data security decisions and obtain data analysis decision results;
[0039] The second situation analysis and decision-making unit is used to determine if there is at least one intersection in the target transportation path, obtain the public security case screening database, and determine whether the part of the data to be verified has risk anomalies based on the correlation coefficient and the screening matching degree between the part of the data to be verified and the public security case screening database, and output the comprehensive data monitoring results to make targeted data security decisions to obtain data analysis decision results;
[0040] The risk association trend prediction unit is used to determine if the target transport path is a parallel network path, extract the historical parallel path from the historical feature information, calculate the comprehensive concentrated position trend of risk anomalies in the historical parallel path during the historical period, and predict the current risk position association trend of the transport path to be tested based on the comprehensive concentrated position trend;
[0041] The analysis and decision-making unit for Case 3 is used to judge the risk anomalies of the data to be proved according to the matching coincidence degree between the trend associated with the current risk position and the trend of the concentrated positions of the risk anomalies occurring in the historical parallel paths statistically obtained, and output the comprehensive data monitoring results for making targeted data security decisions to obtain the data analysis decision results.
[0042] Compared with the prior art, the present invention has the following characteristics and beneficial effects:
[0043] By initially detecting the risk anomalies of the target data on the blockchain according to the prior art, when the target data can be directly detected as safe, the corresponding data protection decision can be made according to the originally formulated data security measures. When it is impossible to directly judge whether the target data is safe, the auxiliary verification and judgment are carried out by means of the network path characteristics through which the target data is conveyed. By initially judging whether the target conveying path of the target data is a cross-network path or a parallel network path, and if it is a cross-network path, it is also necessary to further judge how many cross-points there are in the cross-network path. If there is one cross-point, the correlation coefficient between the historical cross-paths in the historical feature information can be directly used as the main prediction influencing factor for predicting whether there are risk anomalies in the data to be judged subsequently. If there are not less than one cross-points, in addition to using the correlation coefficient as the main prediction influencing factor, it is also necessary to perform another matching analysis with the public security case screening database. Finally, the judgment results obtained by these two different detection methods are comprehensively judged to finally determine the risk anomalies of the data to be measured. When it is judged that the target conveying path of the target data is a parallel network path, the historical parallel paths are extracted from the historical feature information, and the concentrated trend of the risk anomaly occurrence positions between every adjacent three paths is statistically obtained as the main prediction influencing factor for predicting whether there are risk anomalies in the data to be measured subsequently. Through the verification and processing methods in the above three cases, the diversity analysis of the misjudgment situations affecting the risk anomaly detection results of the target data is enhanced, the probability of misjudgment is reduced, and the efficiency of the data security monitoring work is improved. Description of the Drawings
[0044] Figure 1 It is a block diagram of the steps of a big data analysis and decision-making method based on blockchain mainly embodied in this embodiment.
[0045] Figure 2 It is a block diagram of the structure of a big data analysis and decision-making system based on blockchain mainly embodied in this embodiment. Detailed Embodiment
[0046] The present invention will be further described in detail below in conjunction with the following embodiments.
[0047] Refer toFigure 1 , a big data analysis and decision-making method based on blockchain, the method comprising the following steps:
[0048] S1. Obtain the target data to be detected on the blockchain, and count the target delivery path through which the target data is delivered. If the target delivery path is a cross-network path, extract the historical parallel path from the acquired historical feature information, and extract the correlation coefficient between the paths in the historical cross-path.
[0049] S2. Extract the part of the data to be verified that has not been determined to have risk anomalies from the target data. If there is an intersection in the target transportation path, predict the risk anomaly of the part of the data to be verified based on the correlation coefficient, and obtain the comprehensive data monitoring result by combining the prediction results, so as to make targeted data security decisions and obtain data analysis decision results.
[0050] S3. If there is at least one intersection in the target transportation path, obtain the public security case screening database, and judge whether the part of the data to be verified has risk anomalies based on the correlation coefficient and the screening matching degree between the part of the data to be verified and the public security case screening database, and output the comprehensive data monitoring results to make targeted data security decisions and obtain data analysis decision results.
[0051] S4. If the target transport path is a parallel network path, extract the historical parallel paths from the historical feature information, calculate the comprehensive concentrated position trend of risk anomalies in the historical parallel paths during the historical period, and predict the current risk position association trend of the transport path to be tested based on the comprehensive concentrated position trend.
[0052] S5. According to the matching overlap between the current risk location correlation trend and the statistical trend of the concentrated location of risk anomalies in historical parallel paths, the risk anomaly situation of the part of the data to be verified is judged, and the comprehensive data monitoring results are output to make targeted data security decisions and obtain data analysis decision results.
[0053] Specifically, by initially detecting the risk anomaly of the target data on the blockchain according to the prior art, when the target data can be directly detected as safe, the corresponding data protection decision can be made according to the originally formulated data security measures. When it is impossible to directly determine whether the target data is safe, the network path characteristics through which the target data is conveyed are used for auxiliary verification and judgment. By initially determining whether the target conveying path of the target data is a cross-network path or a parallel network path, and if it is a cross-network path, it is further necessary to determine how many cross-points there are in the cross-network path. If there is one cross-point, the correlation coefficient between the historical cross-paths in the historical feature information can be directly used as the main prediction influencing factor for predicting whether there is a risk anomaly in the subsequent part of the data to be judged. If there are not less than one cross-points, in addition to using the correlation coefficient as the main prediction influencing factor, it is also necessary to perform another matching analysis with the public security case screening database. Finally, the judgment results obtained by these two different detection methods are comprehensively judged to finally determine the risk anomaly of the data to be measured. When it is determined that the target conveying path of the target data is a parallel network path, the historical parallel paths are extracted from the historical feature information, and the central tendency of the risk anomaly occurrence positions among every three adjacent paths is statistically analyzed as the main prediction influencing factor for predicting whether there is a risk anomaly in the subsequent part of the data to be judged. Through the verification and processing methods in the above three cases, the diversity analysis of the misjudgment situation affecting the risk anomaly detection result of the target data is enhanced, the misjudgment probability is reduced, and the efficiency of the data security monitoring work is improved.
[0054] Specifically, step S1 includes the following sub-steps:
[0055] Obtain the target data to be detected on the blockchain, perform risk anomaly detection on the target data, and output the data monitoring result when the risk anomaly of the target data can be directly judged.
[0056] When the risk anomaly of the target data cannot be directly judged, the path through which the target data is conveyed is statistically analyzed to obtain the target conveying path.
[0057] Obtain the historical feature information, and train a data risk simulation prediction model according to the historical feature information.
[0058] If the target conveying path is a cross-network path, extract the historical cross-paths from the historical feature information.
[0059] Extract the correlation degree coefficient between the paths in the historical cross-paths to obtain the correlation coefficient.
[0060] Specifically, for target data (including transaction data, customer identity data, credit data, market data, etc.), data monitoring results (risk anomaly detection here: according to the regulatory requirements, business norms and historical experience in the financial industry, a series of clear rules are preset in advance. For example, upper and lower limits are set for transaction amounts, and transactions exceeding or falling below a certain amount may be regarded as anomalies; rules can also be set for transaction frequencies, such as a large number of frequent transactions by a certain account in a short period of time may imply abnormal behavior. These rules will be written into computer programs, and the system will automatically match the transaction data on the blockchain with the customer identity data in real time. Once a situation that conforms to the abnormal rules is found, a warning will be triggered), target transmission paths (such as a situation where there is no direct transaction data but there are risk anomalies, such as external attacks or fraud - phishing websites or false transactions: users may accidentally enter phishing websites, and the transaction information entered on these websites may be obtained and utilized by criminals. Or, criminals create false transactions to defraud users' funds or information, and the data of these false transactions will also show abnormal characteristics in the system), data risk simulation prediction models (such as the data transmission network paths with risk anomalies detected through statistical detection in historical periods. According to the risk anomaly occurrence characteristics and risk prediction requirements of these historical data transmission network paths, appropriate machine learning or deep learning models are selected. For example, if the data has strong spatio - temporal correlation, models such as recurrent neural network (RNN) and its variants (such as LSTM, GRU) can be selected; if the data features are obvious, models such as decision trees and random forests can be selected), historical cross - paths (the historical cross - paths here can be in the same cross - form as the target transmission path or in a different cross - form), and correlation coefficients (the correlation coefficient here refers to the value of the risk induction influence degree between other cross - paths when a risk occurs in one path. For example, if a risk anomaly occurs in path a0 and the severe risk influence degree is 20%, and risks occur in paths a1, a2, and a3 accordingly. If the respective risk induction degrees of a1, a2, and a3 are 10%, 5%, and 5% respectively, then the correlation coefficient between a1 and a0 is 10% / 20%, and so on).
[0061] Specifically, step S2 includes the following sub - steps:
[0062] Extract the first part of the data that has been determined to have or not have risk anomalies from the target data, and extract the part of the data to be verified that has not been determined to have or not have risk anomalies from the target data.
[0063] If there is one intersection point in the target transmission path, then input the first part of the data that has been determined, the part of the data to be verified, and the correlation coefficient into the data risk simulation prediction model to predict whether there are risk anomalies in the part of the data to be verified and obtain the result of the second part of the data that has been determined.
[0064] The judgment results of the first judged partial data and the results of the second judged partial data are combined into a comprehensive data monitoring result.
[0065] Based on the comprehensive data monitoring result, targeted data security decisions are made to obtain data analysis decision results.
[0066] Specifically, the first judged partial data (refers to part of the target data that can be directly judged as safe data or risk abnormal data. If it is A), the part of the data to be proved (that is, the part of the target data that cannot be directly judged as normal. If it is B, the sum of A and B is the target data), the result of the second judged partial data (if there is a crossover point in the target transmission path, it means that the degree of correlation influence between each path in the target transmission path is relatively large. The correlation coefficient can be used as a decision influence factor for mainly judging whether the part of the data to be measured is safe, that is: according to the path where the risk abnormal data judged in the first judged partial data is located. If the paths where the abnormal data belongs are L1, L2, and L3, the correlation coefficients between L1, L2, and L3 and the path where B belongs are extracted from the correlation coefficient respectively. If they are x1, x2, and x3 respectively, according to the degree of data abnormality in L1, L2, and L3 respectively. If they are y1, y2, and y3 respectively, then the induced risk abnormal degree of B is approximately: (y1 * x1 + y2 * x2 + y3 * x3) / 3. If it is T1, when the value of T1 reaches the preset induced risk threshold Y, then B is determined as risk abnormal data), the data analysis decision result (that is, according to the finally judged comprehensive data monitoring result of the target data, the security protection measures for each risk abnormal data among them are optimized, such as strengthening password verification and identification processing, or multi-anti-theft layer reinforcement, or changing the transmission path, etc.).
[0067] Specifically, step S3 includes the following sub-steps:
[0068] If there is at least one crossover point in the target transmission path, then extract the judged sub-part data from the first judged partial data that has a crossover point with the path where the part of the data to be proved is located.
[0069] Input the judged sub-part data, the correlation coefficient, and the part of the data to be proved into the data risk simulation prediction model to predict whether there is risk abnormality in the part of the data to be proved and obtain the first prediction result.
[0070] Obtain the public security case screening database, and match the judged sub-part data and the part of the data to be proved with the public security case screening database to obtain the screening matching degree.
[0071] Preset a matching judgment threshold. When the screening matching degree is greater than or equal to the matching judgment threshold, then judge that there is a risk abnormal situation in the part of the data to be proved, and output a risk abnormal pre-judgment result.
[0072] When the screening matching degree is less than the matching judgment threshold, it is determined that there is no risk abnormality in the data to be proved, and a normal pre-judgment result is output.
[0073] If the first prediction result is the same as the risk abnormality pre-judgment result, it is comprehensively verified that the data to be proved is risk abnormal data, and the first monitoring result is output.
[0074] If the first prediction result is the same as the pre-judgment result, it is comprehensively verified that the data to be proved is normal data, and the second monitoring result is output.
[0075] The judgment result and the first monitoring result of the first judged part of the data, or the result of the first judged part of the data and the second monitoring result are combined into a comprehensive data monitoring result.
[0076] According to the comprehensive data monitoring result, targeted data security decisions are made to obtain data analysis decision results.
[0077] Specifically, such as the judged sub-part data (if it is a4, if there is no less than one intersection in the target transportation path, it is not enough to verify the data risk anomaly judgment based on the correlation coefficient between the intersection paths alone. If it is analyzed only based on the correlation coefficient, it is very likely to cause interference in the data risk anomaly judgment of the deviation intersection. Therefore, it is necessary to use the public security case screening database to conduct a preliminary analysis based on the correlation coefficient results, and then conduct a comparison screening with the public security case screening database alone. Finally, combine the analysis and judgment results of the two to determine whether they are the same, to judge the risk anomaly of B, so as to strengthen the verification of further data security monitoring results and reduce the probability of misjudgment), prediction result one (the explanation of the prediction process of the second judged partial data result is the same, and no further explanation is given here), screening matching degree (such as a4 and B with the public security case screening database (data risk anomaly record information of historical criminal behavior), for example, according to a4 and the sensitive information of B and the degree of risk anomaly induction in a4, and match these two feature information with the corresponding feature information in the public security case screening database for similarity), preset matching judgment threshold (that is, the critical value for reaching risk judgment, which is set according to historical feature data statistics and can be updated in real time, such as updating the threshold in real time every time risk monitoring is performed), monitoring result one (if the prediction result one and the risk anomaly prediction result are the same, it means that the judgment results obtained by the two different verification processing methods are abnormal, indicating that B is risk anomaly data), monitoring result two (if the prediction result one and the normal prediction result are the same, it means that the judgment results obtained by the two different verification processing methods are normal, indicating that B is normal data). It should be noted that if the prediction result one and the risk anomaly prediction result are not the same or the prediction result one and the normal prediction result are not the same, it is necessary to collect and analyze secondary data information to reduce the probability of misjudgment.
[0078] The specific step S4 includes the following sub-steps:
[0079] If the target transmission path is a parallel network path, the historical parallel path is extracted from the historical feature information.
[0080] The historical concentrated period sets are obtained by counting multiple historical concentrated periods in which abnormal risks occurred in historical parallel paths in the historical period, and the concentrated position trends of abnormal risks in each three adjacent groups of transportation paths in each concentrated period of the historical concentrated period are counted to obtain the concentrated trend path set, and the comprehensive concentrated position trend is obtained by comprehensively calculating the average value of the concentrated trend path set.
[0081] The conveying path to be tested where the partial data to be verified is located is obtained, and the associated conveying path 1 of the determined data 1 and the associated conveying path 2 of the determined data 2 in the first determined partial data adjacent to the conveying path to be tested are screened out.
[0082] Predict the current risk location correlation trend between the to-be-tested transportation path, associated transportation path 1, and associated transportation path 2 based on the comprehensive centralized location trend, judged data 1, and judged data 2.
[0083] Specifically, such as the historical centralized time period set (when the target transportation path is a parallel network path, the degree of correlation between each parallel path in this case is relatively low, so it cannot be used as a decision-making influencing factor for subsequent major decisions to judge whether the to-be-tested part of the data is safe. If the historical centralized time period set is the first historical time period, the second historical time period, and the third historical time period respectively, where the first historical time period is earlier than the second historical time period, the second historical time period is earlier than the third historical time period, and the three time periods are adjacent), the comprehensive centralized location trend (for every three adjacent sets of transportation paths: for example, L4, L5, L6, because according to the degree of correlation influence, the degree of correlation influence between adjacent paths is the highest, and the influence characteristics are analyzed for every three sets of transportation paths. In order to reduce the interference of marginalized information factors and reduce the lower accuracy of feature information analysis), the centralized trend path set (such as the centralized location trend of risk anomalies occurring in every three adjacent sets of transportation paths in the first historical time period, the second historical time period, and the third historical time period respectively: here, the centralized location trend refers to, for example, connecting the risk positions on L4, L5, and L6 at position points, presenting a curve or a straight line, that is, forming a centralized location trend path), the comprehensive centralized location trend (that is, calculating the average value of the curve change amplitude of the centralized location trends in the first historical time period, the second historical time period, and the third historical time period, that is, obtaining the comprehensive centralized location trend), the to-be-tested transportation path (if it is L12, associated transportation path 1 is L11, and associated transportation path 2 is L13, where L12 is adjacent to both L11 and L13), the current risk location correlation trend (that is, according to the risk anomaly degree of judged data 1 and judged data 2 and the degree of path correlation influence between each of them and B, matching the two sets of centralized location trends with the highest similarity from the comprehensive centralized location trend, that is, obtaining the change range of the current risk location correlation trend, and then according to the sensitivity information degree of B itself, estimating the risk node among the range nodes between the two sets of centralized location trends with the highest similarity. For example, there are multiple sub-processing nodes in a path, and the sub-processing nodes include weighted nodes - that is, having fault tolerance, and non-weighted nodes - that is, not having fault tolerance. The estimated risk node is most likely located at the non-weighted node position. Then, according to the position range between the two sets of centralized location trends with the highest similarity, estimate the current risk location correlation trend).
[0084] Specifically, step S5 includes the following sub-steps:
[0085] A preset trend coincidence threshold is set. If the matching coincidence degree between the current risk position - associated trend and the set of concentrated trend paths is not less than the trend coincidence threshold, it is determined that the data to be proved is risk - abnormal data. If the matching coincidence degree between the current risk position - associated trend and the set of concentrated trend paths is less than the trend coincidence threshold, it is determined that the data to be proved is normal data, and the result of the third part of the judged data is output.
[0086] The judgment result of the first part of the judged data and the result of the third part of the judged data are combined into a comprehensive data monitoring result.
[0087] Based on the comprehensive data monitoring result, targeted data - security decision - making is carried out to obtain a data - analysis decision result.
[0088] Specifically, for example, the preset trend coincidence threshold (i.e., the critical value for reaching risk determination, which is set according to historical characteristic data statistics), the result of the third part of the judged data (such as calculating the average of the two concentrated - position trends with the highest similarity to obtain the average concentrated - position trend, and matching the coincidence degree between the current risk position - associated trend and the average concentrated - position trend. If the matching coincidence degree between the current risk position - associated trend and the set of concentrated trend paths is not less than the trend coincidence threshold, it is determined that the data to be proved is risk - abnormal data; otherwise, it is determined that the data to be proved is normal data), and the data - analysis decision result (i.e., according to the comprehensive data monitoring result finally judged for the target data, optimizing the security protection measures for each risk - abnormal data, such as strengthening password verification and identification processing, or multi - anti - theft layer reinforcement, or changing the transmission path, etc.).
[0089] A big - data analysis and decision - making system based on blockchain, by applying a big - data analysis and decision - making method based on blockchain as described above, includes a correlation - coefficient extraction unit, a case - one analysis and decision - making unit, a case - two analysis and decision - making unit, a risk - associated trend prediction unit, and a case - three analysis and decision - making unit, referring to Figure 2, the target data to be detected on the blockchain is obtained through the correlation coefficient extraction unit, and the target transmission path through which the target data is transmitted is counted. If the target transmission path is a cross-network path, the historical parallel path is extracted from the historical feature information, and the correlation coefficient between the paths in the historical cross-path is extracted; the part of the data to be verified that is not determined to have risk anomalies is extracted from the target data through the situation one analysis and decision unit. If there is an intersection in the target transmission path, the risk anomaly of the part of the data to be verified is predicted according to the correlation coefficient, and the comprehensive data monitoring result is obtained by combining the prediction results, so as to make targeted data security decisions and obtain data analysis decision results; if it is determined by the situation two analysis and decision unit that there is no less than one intersection in the target transmission path, the public security case screening database is obtained, and according to the correlation coefficient and the part of the data to be verified and the The screening matching degree between the public security case screening databases is used to determine whether there are any risk anomalies in the part of the data to be verified, and the comprehensive data monitoring results are output to make targeted data security decisions to obtain data analysis decision results; the risk association trend prediction unit is used to determine if the target transmission path is a parallel network path, and the historical parallel path is extracted from the historical feature information, and the comprehensive concentrated position trend of risk anomalies in the historical parallel paths in the historical period is statistically calculated. According to the comprehensive concentrated position trend, the current risk position association trend of the transmission path to be tested is predicted; the situation three analysis and decision unit is used to determine the risk anomaly of the part of the data to be verified based on the matching overlap between the current risk position association trend and the statistical concentrated position trend of risk anomalies in the historical parallel paths, and output the comprehensive data monitoring results to make targeted data security decisions to obtain data analysis decision results.
[0090] The above are all preferred embodiments of the present application, and the protection scope of the present application is not limited thereto. Therefore, any equivalent changes made according to the structure, shape, and principle of the present application should be included in the protection scope of the present application.
Claims
1. A big data analysis and decision-making method based on blockchain, characterized in that: The following steps are involved: Obtain the target data to be detected on the blockchain, count the target delivery paths through which the target data is delivered, and if the target delivery path is a cross-network path, extract the historical parallel paths from the acquired historical feature information, and extract the correlation coefficients between the paths in the historical cross-paths; Extracting part of the data to be verified that has not been determined to have risk anomalies from the target data, if there is an intersection in the target delivery path, predicting the risk anomalies of the part of the data to be verified according to the correlation coefficient, and synthesizing the prediction results to obtain a comprehensive data monitoring result, so as to make targeted data security decisions and obtain data analysis decision results; If there is at least one intersection in the target transport path, obtain the public security case screening database, and judge whether the part of the data to be verified has risk anomalies based on the correlation coefficient and the screening matching degree between the part of the data to be verified and the public security case screening database, and output the comprehensive data monitoring results to make targeted data security decisions and obtain data analysis decision results; If the target transport path is a parallel network path, extract the historical parallel path from the historical feature information, calculate the comprehensive concentrated position trend of risk anomalies in the historical parallel path during the historical period, and predict the current risk position correlation trend of the transport path to be tested based on the comprehensive concentrated position trend; Based on the matching overlap between the current risk position association trend and the statistical trend of the concentrated position of risk anomalies in historical parallel paths, the risk anomaly situation of the part of the data to be verified is judged, and the comprehensive data monitoring results are output to make targeted data security decisions and obtain data analysis decision results.
2. According to the big data analysis and decision-making method based on blockchain according to claim 1, it is characterized in that: The target data to be detected on the blockchain is obtained, and the target delivery path through which the target data is delivered is counted. If the target delivery path is a cross-network path, the historical parallel paths are extracted from the acquired historical feature information, and the correlation coefficients between the paths in the historical cross-paths are extracted. Specifically, the steps are as follows: Obtain the target data to be detected on the blockchain, perform risk anomaly detection on the target data, and output the data monitoring results when the target data can directly determine whether there is a risk anomaly; When the target data cannot directly determine whether there is a risk anomaly, the target delivery path is obtained by counting the target data along the delivery path; Acquire historical feature information, and train a data risk simulation prediction model based on the historical feature information; If the target transport path is a cross-network path, extracting a historical cross-path from the historical feature information; The correlation coefficients between the paths in the historical cross paths are extracted to obtain the correlation coefficients.
3. According to a big data analysis and decision-making method based on blockchain according to claim 2, it is characterized in that: Extracting part of the data to be verified that has not been determined to have risk anomalies from the target data, if there is an intersection in the target delivery path, predicting the risk anomalies of the part of the data to be verified according to the correlation coefficient, and synthesizing the prediction results to obtain a comprehensive data monitoring result, so as to make targeted data security decisions and obtain the steps of data analysis decision results, specifically: Extracting the first determined partial data that has been determined to have risk anomalies from the target data, and extracting the pending partial data that has not been determined to have risk anomalies from the target data; If there is an intersection in the target transport path, the first determined partial data, the partial data to be verified and the correlation coefficient are all input into the data risk simulation prediction model to predict whether the partial data to be verified has risk anomalies, and obtain the second determined partial data result; The judgment result of the first judged partial data and the second judged partial data result are combined into a comprehensive data monitoring result; Based on the comprehensive data monitoring results, targeted data security decisions are made to obtain data analysis decision results.
4. According to a big data analysis and decision-making method based on blockchain according to claim 3, it is characterized in that: If there is at least one intersection in the target transport path, obtain the public security case screening database, determine whether the part of the data to be verified has risk anomalies based on the correlation coefficient and the screening matching degree between the part of the data to be verified and the public security case screening database, and output the comprehensive data monitoring results to make targeted data security decisions to obtain the data analysis decision results, specifically: If there is at least one intersection in the target transport path, extracting the judged sub-partial data having an intersection with the path where the partial data to be verified is located from the first judged partial data; Input the determined sub-part data, the correlation coefficient and the part of data to be verified into the data risk simulation prediction model to predict whether the part of data to be verified has risk anomalies and obtain prediction result 1; Obtaining a public security case screening database, and matching the judged sub-part data and the to-be-proven part data with the public security case screening database to obtain a screening matching degree; A matching judgment threshold is preset. When the screening matching degree is greater than or equal to the matching judgment threshold, it is judged that there is a risk abnormality in the part of the data to be verified, and a risk abnormality prediction result is output; When the screening match degree is less than the match judgment threshold, it is judged that there is no risk abnormality in the part of the data to be verified, and the normal prediction result is output; If the prediction result 1 and the risk abnormality prediction result are the same, then the part of the data to be verified is comprehensively verified to be risk abnormality data, and the monitoring result 1 is output; If the prediction result 1 is the same as the pre-judgment result, the data to be verified is found to be normal data through comprehensive verification, and the monitoring result 2 is output; The judgment result of the first judged partial data and the monitoring result 1 or the first judged partial data result and the monitoring result 2 are combined into a comprehensive data monitoring result; Based on the comprehensive data monitoring results, targeted data security decisions are made to obtain data analysis decision results.
5. According to the big data analysis and decision-making method based on blockchain according to claim 4, it is characterized in that: If the target transport path is a parallel network path, the historical parallel paths are extracted from the historical feature information, and the comprehensive concentrated position trend of risk anomalies in the historical parallel paths in the historical period is statistically calculated. According to the comprehensive concentrated position trend, the steps of predicting the current risk position correlation trend of the transport path to be tested are as follows: If the target transport path is a parallel network path, the historical parallel path is extracted from the historical feature information; A plurality of historical concentrated time periods in which risk anomalies occurred in historical parallel paths in the historical period are counted to obtain a historical concentrated time period set, and the risk anomaly occurrence concentrated position trends of each three adjacent groups of transportation paths in each concentrated time period of the historical concentrated time period are counted to obtain a concentrated trend path set, and the concentrated trend path set is comprehensively averaged to obtain a comprehensive concentrated position trend; Acquire the transport path to be tested where the partial data to be verified is located, and select the associated transport path 1 of the determined data 1 and the associated transport path 2 of the determined data 2 in the first determined partial data that are adjacent to the transport path to be tested; According to the comprehensive concentrated position trend, the determined data 1 and the determined data 2, the current risk position association trend between the transport path to be tested and the associated transport path 1 and the associated transport path 2 is predicted.
6. According to the big data analysis and decision-making method based on blockchain according to claim 5, it is characterized in that: According to the matching overlap between the current risk position correlation trend and the statistical trend of the concentrated risk anomaly occurrence position of the historical parallel path, the risk anomaly situation of the part of the data to be verified is judged, and the comprehensive data monitoring result is output to make targeted data security decisions to obtain the steps of data analysis decision results, which are specifically: A trend overlap threshold is preset. If the matching overlap between the current risk position associated trend and the central trend path set is not less than the trend overlap threshold, the partial data to be verified is judged to be risk abnormal data. If the matching overlap between the current risk position associated trend and the central trend path set is less than the trend overlap threshold, the partial data to be verified is judged to be normal data, and the third judged partial data result is output; The judgment result of the first judged partial data and the result of the third judged partial data are combined into a comprehensive data monitoring result; Based on the comprehensive data monitoring results, targeted data security decisions are made to obtain data analysis decision results.
7. A big data analysis and decision-making system based on blockchain, characterized in that: The system is used to implement a big data analysis and decision-making method based on blockchain as described in any one of claims 1 to 6, comprising: A correlation coefficient extraction unit is used to obtain the target data to be detected on the blockchain, and to count the target delivery path through which the target data is delivered. If the target delivery path is a cross-network path, the historical parallel path is extracted from the acquired historical feature information, and the correlation coefficient between each path in the historical cross path is extracted; The situation one analysis and decision unit is used to extract the part of the data to be verified that has not been determined to have risk anomalies from the target data. If there is an intersection in the target transportation path, the risk anomaly of the part of the data to be verified is predicted according to the correlation coefficient, and the prediction results are combined to obtain the comprehensive data monitoring results, so as to make targeted data security decisions and obtain data analysis decision results; The second situation analysis and decision-making unit is used to determine if there is at least one intersection in the target transportation path, obtain the public security case screening database, and determine whether the part of the data to be verified has risk anomalies based on the correlation coefficient and the screening matching degree between the part of the data to be verified and the public security case screening database, and output the comprehensive data monitoring results to make targeted data security decisions to obtain data analysis decision results; The risk association trend prediction unit is used to determine if the target transport path is a parallel network path, extract the historical parallel path from the historical feature information, calculate the comprehensive concentrated position trend of risk anomalies in the historical parallel path during the historical period, and predict the current risk position association trend of the transport path to be tested based on the comprehensive concentrated position trend; The situation three analysis and decision-making unit is used to judge the risk anomaly of the part of the data to be verified based on the matching overlap between the current risk position correlation trend and the statistical trend of the concentrated position of risk anomalies in the historical parallel paths, and output the comprehensive data monitoring results to make targeted data security decisions to obtain data analysis decision results.
Citation Information
Cited By
Bid inviting and tendering risk early warning system and method based on large model
CN120634281A
Network equipment vulnerability assessment method
CN120768705A
A network device vulnerability assessment method
CN120768705B