Enterprise security risk assessment method and device and computer readable storage medium
By integrating basic information and risk information of the enterprise and combining similarity comparison technology to assess enterprise security risks, the problems of missed and false alarms in existing methods are solved, and a more accurate and comprehensive risk assessment is achieved.
Patent Information
- Application Number
- CN202510162908.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-06-06
AI Technical Summary
Existing enterprise security risk assessment methods rely on simple text matching or keyword search, which are prone to missed or false positives, and cannot accurately and comprehensively evaluate enterprise security risks.
By obtaining basic information of the enterprise, enterprise self-inspection risk information and third-party inspection risk information, combining data processing and similarity comparison technology, similar enterprises similar to the target enterprise, and refer to their risk information to check for the risk of the target enterprise and accurately assess the risk of the underreport.
It improves the accuracy and comprehensiveness of enterprise security risk assessment, can accurately identify underreported risks, and enhances the firmness of enterprise security defense.
Smart Images

Figure CN120106555A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to an enterprise security risk assessment method, device, and computer-readable storage medium. Background Art
[0002] In recent years, with the continuous advancement of industrialization and urbanization, the production and operation scale of various enterprises has continued to expand, and various production and construction activities have also been developed in full swing. However, safety accidents have also occurred continuously. In this context, safety risk assessment and screening have become the cornerstone for enterprises to build a solid safety line of defense.
[0003] Currently, most companies build a fixed keyword library based on risk types and descriptions. When these keywords are included in the information reported by the company, it is considered that there is a corresponding risk. However, this method of identifying risk information only through simple text matching or keyword search is too simple and direct, and there may be omissions or false positives.
[0004] Therefore, it is necessary to establish a method that can accurately and comprehensively assess enterprise security risks. Summary of the invention
[0005] In view of this, the present application provides an enterprise security risk assessment method, device and computer-readable storage medium, which can accurately assess enterprise security risks.
[0006] In order to solve the above technical problems, on the one hand, the present application provides an enterprise security risk assessment method, including: obtaining the basic information of all enterprises, enterprise self-inspection risk information and third-party inspection risk information; based on the basic information of the enterprises, determining similar enterprises similar to the target enterprise; based on the self-inspection risk information and third-party inspection risk information of the target enterprise and similar enterprises, obtaining the underreporting risk of the target enterprise.
[0007] According to some embodiments of the present application, the basic information of an enterprise includes the name of the enterprise. The steps of determining similar enterprises similar to the target enterprise based on the basic information of the enterprise include: vectorizing the enterprise name to obtain a name vectorization result; and determining similar enterprises based on the name vectorization results of the target enterprise and other enterprises.
[0008] According to some embodiments of the present application, the step of determining similar enterprises based on the name vectorization results of the target enterprise and other enterprises includes: calculating the similarity between the name vectorization results of the target enterprise and other enterprises through a cosine similarity algorithm; and filtering out similar enterprises from all other enterprises based on the similarity.
[0009] According to some embodiments of the present application, the steps of obtaining the underreporting risk of the target enterprise based on the enterprise self-inspection risk information and third-party inspection risk information of the target enterprise and similar enterprises include: obtaining the enterprise self-inspection risk information of all similar enterprises to form a self-inspection risk set; removing the information that is the same as the self-inspection risk information of the target enterprise from the self-inspection risk set to form an initial underreporting risk set; determining the similarity between each risk information in the initial underreporting risk set and the third-party inspection risk information of similar enterprises, and based on the similarity, screening out the underreporting risk of the target enterprise from the initial underreporting risk set.
[0010] According to some embodiments of the present application, the method also includes: after obtaining the basic information of all enterprises, the enterprise self-inspection risk information and the third-party inspection risk information, first performing data cleaning on the basic information of the enterprises, the enterprise self-inspection risk information and the third-party inspection risk information, and retaining duplicate values, and then executing subsequent steps to determine similar enterprises similar to the target enterprise based on the basic information of the enterprises.
[0011] In a second aspect, an embodiment of the present application provides an electronic device, comprising: a processor; and a memory, wherein computer program instructions are stored in the memory.
[0012] When the computer program instructions are executed by the processor, the processor executes the steps of the enterprise security risk assessment method as shown in the above technical solution.
[0013] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the processor executes the steps of the enterprise security risk assessment method as shown in the above technical solution.
[0014] The above-mentioned technical scheme of the present application has at least one of the following beneficial effects: by integrating the basic information of the enterprise, the self-inspection risk information of the enterprise and the third-party inspection risk information, and combining data processing and similarity comparison technology, the basic information of the enterprise, the self-inspection risk information of the enterprise and the third-party inspection risk information are deeply mined and analyzed, and similar enterprises similar to the target enterprise are screened out, and then the self-inspection risk information and third-party inspection risk information of each similar enterprise are referred to to check and fill in the gaps in the risks of the target enterprise, so as to accurately obtain the underreported risks of the target enterprise and improve the accuracy and comprehensiveness of the enterprise safety risk assessment.
[0015] In addition, the use of natural language processing, such as the N-shortest path word segmentation algorithm, BERT and other technologies, can better understand the semantics and contextual information of the text, thereby more accurately identifying the characteristics of each enterprise and accurately identifying enterprises similar to the target enterprise, laying the foundation for subsequent accurate and comprehensive assessment of enterprise security risks.
[0016] In addition, through natural language processing and similarity comparison technology, the underreporting risks of the target enterprise can be comprehensively checked by utilizing the self-inspection risks and third-party inspection risks of similar enterprises, which can accurately identify the underreporting risks of the target enterprise, thereby improving the accuracy and comprehensiveness of the target enterprise's security risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A flowchart of a method for assessing enterprise security risks according to an embodiment of the present application;
[0018] Figure 2 A flowchart of the steps of determining similar enterprises similar to the target enterprise based on basic enterprise information in the enterprise security risk assessment method of an embodiment of the present application;
[0019] Figure 3 A flowchart of the steps of determining similar enterprises based on the name vectorization results of the target enterprise and other enterprises in the enterprise security risk assessment method of an embodiment of the present application;
[0020] Figure 4 A flowchart of the steps of obtaining the underreporting risk of a target enterprise based on the enterprise self-inspection risk information and third-party inspection risk information of the target enterprise and similar enterprises in the enterprise security risk assessment method of the embodiment of the present application;
[0021] Figure 5 A schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] The specific implementation methods of the present application will be further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present application but are not intended to limit the scope of the present application.
[0023] In recent years, with the continuous advancement of industrialization and urbanization, the production and operation scale of various enterprises has continued to expand, and various production and construction activities have also been developed in full swing. However, safety accidents have also occurred continuously. In this context, safety risk assessment and screening have become the cornerstone for enterprises to build a solid safety line of defense. Among them, safety risk assessment refers to the process of systematically identifying and analyzing the security threats, vulnerabilities and potential impacts faced by enterprises, and then determining the risk level and taking corresponding protective measures. This process not only helps enterprises to prepare for a rainy day, deploy defense measures in advance, avoid or reduce the occurrence of safety accidents, but also is an important means to ensure the compliance of enterprises. In addition, based on the results of risk assessment, enterprises can reasonably allocate security resources, give priority to high-risk areas, improve safety management efficiency, and provide management with a comprehensive view of the safety status, so as to make more scientific and reasonable safety investment decisions.
[0024] Currently, most companies build a fixed keyword library based on risk types and descriptions. When these keywords are included in the information reported by the company, it is considered that there is a corresponding risk. However, this method of identifying risk information only through simple text matching or keyword search is too simple and direct, and there may be omissions or false positives.
[0025] Therefore, it is necessary to establish a method that can accurately and comprehensively assess enterprise security risks.
[0026] In order to solve the above-mentioned technical problems and realize accurate assessment of enterprise security risks, this application proposes an enterprise security risk assessment method, which integrates basic enterprise information, enterprise self-inspection risk information and third-party inspection risk information, and combines data processing and similarity comparison technology to extract key security risk factors. It can accurately identify the risks that are not reported by the enterprise and improve the accuracy and comprehensiveness of enterprise security risk assessment.
[0027] The following is a detailed introduction to the enterprise security risk assessment method proposed in this application. Figure 1 As shown, the enterprise security risk assessment method of the embodiment of the present application includes:
[0028] Step 110: Obtain basic enterprise information, enterprise self-inspection risk information, and third-party inspection risk information of all enterprises.
[0029] Basic information of an enterprise may include basic information such as enterprise name, nature of enterprise, address, business scope or establishment time. Self-inspection risk information of an enterprise refers to the risk information discovered by the enterprise through self-inspection, and third-party inspection risk information refers to the risk information obtained by insurance companies or other third-party institutions through inspection of the enterprise.
[0030] In one embodiment, after obtaining the basic information of all enterprises, the self-inspection risk information of the enterprises and the third-party inspection risk information, the basic information of the enterprises, the self-inspection risk information of the enterprises and the third-party inspection risk information may be cleansed first, and then subsequent steps 120 to 130 may be executed.
[0031] Specifically, the "data cleaning" operation may include, but is not limited to, using natural language processing and machine learning technologies to perform feature screening and vectorization processing on the above-mentioned basic information of the enterprise, the enterprise self-inspection risk information, and the third-party inspection risk information. It can be understood that the basic information of the enterprise, the enterprise self-inspection risk information, and the third-party inspection risk information can be cleaned by conventional data cleaning methods in the field of data processing technology, and duplicate values are retained. The data cleaning process does not include data deduplication. The frequency of the original data is of great significance in this method.
[0032] In one embodiment, during the data cleaning stage, the enhanced natural language processing module can also be used to perform word segmentation, part-of-speech tagging, semantic understanding, sentiment analysis, entity recognition, etc. on the enterprise self-inspection risk information and the third-party inspection risk information to improve the efficiency and accuracy of data calculation, thereby facilitating the subsequent steps to more accurately extract and filter risk key information from the enterprise basic information, the enterprise self-inspection risk information, and the third-party inspection risk information. It can be understood that the enhanced natural language processing module can be a conventional model in the field of data processing technology that can implement natural language processing, and is not limited here.
[0033] Step 120: Based on the basic information of the enterprise, determine similar enterprises that are similar to the target enterprise.
[0034] By comparing the basic information of the target enterprise with the basic information of other enterprises, similar enterprises similar to the target enterprise can be found. The risk information of the similar enterprises is similar to that of the target enterprise, which can be used as a reference for screening the missed risks of the target enterprise. In one embodiment, the enterprise characteristics of the enterprise can be first identified from the basic information of the enterprise, and then similar enterprises similar to the target enterprise are determined by the similarity between the enterprise characteristics of the target enterprise and other enterprises.
[0035] Step 130: Based on the self-inspection risk information of the target enterprise and similar enterprises and the third-party inspection risk information, the underreporting risk of the target enterprise is obtained.
[0036] After using the above steps to identify similar enterprises, you can refer to the self-inspection risk information and third-party inspection risk information of each similar enterprise to check for omissions in the risks of the target enterprise, so as to accurately obtain the underreported risks of the target enterprise.
[0037] This embodiment integrates the basic information of enterprises, the enterprise self-inspection risk information and the third-party inspection risk information, and combines data processing and similarity comparison technology to conduct in-depth mining and analysis of the basic information of enterprises, the enterprise self-inspection risk information and the third-party inspection risk information, thereby screening out similar enterprises similar to the target enterprise, and then referring to the enterprise self-inspection risk information and the third-party inspection risk information of each similar enterprise to check and fill in the gaps in the risks of the target enterprise, thereby accurately obtaining the underreported risks of the target enterprise and improving the accuracy and comprehensiveness of the enterprise security risk assessment.
[0038] The steps 120 and 130 in the above embodiment are introduced in sequence below.
[0039] First, in one embodiment, if Figure 2 As shown, the above step 120, i.e., the step of determining similar enterprises similar to the target enterprise based on the basic information of the enterprise, may specifically include:
[0040] Step 121: vectorize the enterprise name to obtain a name vectorization result.
[0041] In one example, the company name can be first transformed using the Bidiretional Encoder Representations from Transformers (BERT) model to obtain the embedded vector form shown in the following formula (1):
[0042] x i =e token,i +e position,i +e segment,i Formula (1)
[0043] In the above formula (1), e token,i refers to the word embedding of the i-th company name, e position,i refers to the position embedding of the i-th enterprise name, e segment,i refers to the segment embedding of the i-th enterprise name.
[0044] Step 122: Determine similar enterprises based on the name vectorization results of the target enterprise and other enterprises.
[0045] In one embodiment, if Figure 3 As shown, the above step 122, i.e., the step of determining similar enterprises based on the name vectorization results of the target enterprise and other enterprises, may specifically include:
[0046] Step 1221: Calculate the similarity between the target enterprise and the name vectorization results of other enterprises through the cosine similarity algorithm.
[0047] In one example, it is specifically shown in the following formula (2):
[0048]
[0049] In the above formula (2), cos a,b It refers to the cosine similarity between the name a of the target enterprise and the name b of other enterprises, a·b refers to the dot product of enterprise name a and enterprise name b, and |a|·|b| refers to the norm product of enterprise name a and enterprise name b.
[0050] Step 1222: Based on the similarity, similar enterprises are screened out from all other enterprises.
[0051] Enterprises with similarity greater than a preset threshold may be regarded as similar enterprises, wherein the preset threshold may be set according to actual conditions and is not limited here.
[0052] This embodiment uses natural language processing, such as the N-shortest path word segmentation algorithm, BERT and other technologies, to better understand the semantics and contextual information of the text, thereby more accurately identifying the characteristics of each enterprise and accurately identifying enterprises similar to the target enterprise, laying the foundation for subsequent accurate and comprehensive assessment of enterprise security risks.
[0053] In one embodiment, the machine learning technology can be further combined to pre-build an enterprise similarity recognition model, and the enterprise similarity recognition model can be trained through a large amount of enterprise basic information, so that the enterprise similarity recognition model has the ability to recognize multi-dimensional key information in the enterprise basic information, and can accurately evaluate the similarity between the target enterprise and other enterprises. In one example, in the stage of building the enterprise similarity recognition model, the features extracted from different data sources or different feature extraction methods can be fused to generate a more representative feature vector, thereby improving the training effect of the enterprise similarity recognition model, so that the enterprise similarity recognition model can more accurately capture the similarities between enterprises.
[0054] The following is a detailed description of the above step 130, i.e., the step of obtaining the target enterprise's underreporting risk based on the target enterprise's and similar enterprises' self-inspection risk information and third-party inspection risk information. Figure 4 The following steps are shown in the flow:
[0055] Step 131: Obtain the enterprise self-inspection risk information of all similar enterprises to form a self-inspection risk set.
[0056] Obtain the self-inspection risk information of all similar enterprises to form the self-inspection risk set shown in the following formula (3):
[0057]
[0058] In the above formula (3), O refers to the self-inspection risk set, S is the set of similar enterprises, and H j is the self-inspection risk information of similar enterprise j.
[0059] Step 132: Remove information that is the same as the self-examination risk information of the target enterprise from the self-examination risk set to form an initial underreporting risk set.
[0060] In order to identify the target enterprise’s underreported risk information, it is necessary to first remove the set of self-inspection risk information that is the same as the target enterprise’s self-inspection risk information. Taking the target enterprise i, the self-inspection risk set is O as an example, the initial underreported risk set is OH i .
[0061] Step 133: Determine the similarity between each risk information in the initial underreporting risk set and the third-party inspection risk information of similar enterprises.
[0062] In one embodiment, the enterprise self-inspection risk information and third-party inspection risk information can be analyzed and keywords extracted to form three types of keyword dictionaries: stop words, address description words, and hidden danger description words. Then, based on the hidden danger description words, the risk information in the initial missed risk set is compared with the third-party inspection risk information of similar enterprises for similarity. Among them, the "analysis and keyword extraction" process may include but is not limited to: generating and counting the frequency of single-word, double-word, three-word and above phrases and the frequency of prefix and suffix characters, calculating mutual information and distribution entropy, filtering and sorting phrases, which are not limited here.
[0063] In one example, the similarity between each risk information in the initial underreporting risk set and the third-party inspection risk information of similar enterprises can be determined using the following formulas (4)-(5):
[0064]
[0065] In the above formula (4), x m Refers to the initial underreporting risk set OH i The mth risk information in y n Refers to the nth risk information in the third-party inspection risk information set Y of all similar enterprises, Refers to x m With y n The distance between them, k refers to the dimension after risk information is vectorized.
[0066] In the above formula (5), Refers to x m With y n The similarity between them is , and γ refers to a hyperparameter that controls the width of the kernel density.
[0067] Step 134: Based on the similarity, the underreporting risks of the target enterprise are screened out from the initial underreporting risk set.
[0068] In one example, risk information with a similarity greater than a similarity threshold can be determined as the underreporting risk of the target enterprise. Specifically, the underreporting risk of the target enterprise can be screened out from the initial underreporting risk set using the following formula (6):
[0069]
[0070] In the above formula (6), R refers to the underreporting risk set of the target enterprise, and threshold refers to the similarity threshold. It can be understood that the similarity threshold can be set according to the actual situation and is not limited here.
[0071] This embodiment uses natural language processing and similarity comparison technology, and utilizes the self-inspection risks and third-party inspection risks of similar enterprises to conduct a comprehensive investigation of the target enterprise's underreporting risks, and can accurately identify the target enterprise's underreporting risks, thereby improving the accuracy and comprehensiveness of the target enterprise's security risk assessment.
[0072] An embodiment of the present application also provides an electronic device, which includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the enterprise security risk assessment method provided in the above method embodiment.
[0073] The memory can be used to store software programs and modules. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs required for functions, etc.; the data storage area can store data created according to the use of the device, etc. In addition, the memory can include a high-speed random access memory and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. Accordingly, the memory can also include a memory controller to provide the processor with access to the memory.
[0074] In a specific embodiment, Figure 5 A schematic diagram of the structure of an electronic device for implementing the embodiment of the present application is shown, and the electronic device may be a computer terminal, a mobile terminal or other devices.
[0075] like Figure 5 As shown, an embodiment of the present application provides an electronic device 500, including: a processor 501 and a memory 502, in which computer program instructions are stored, wherein when the computer program instructions are executed by the processor, the processor 501 executes the enterprise security risk assessment method described in the above embodiment.
[0076] Furthermore, if Figure 5 As shown, the electronic device 500 further includes a network interface 503 , an input device 504 , a hard disk 505 , and a display device 506 .
[0077] The above-mentioned interfaces and devices can be interconnected through a bus architecture. The bus architecture can be a bus and bridge that can include any number of interconnected buses. Specifically, one or more central processing units (CPUs) represented by processor 501 and various circuits of one or more memories represented by memory 502 are connected together. The bus architecture can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits together. It can be understood that the bus architecture is used to achieve connection and communication between these components. In addition to the data bus, the bus architecture also includes a power bus, a control bus, and a status signal bus, which are all well known in the art, so they are not described in detail herein.
[0078] The network interface 503 can be connected to a network (such as the Internet, a local area network, etc.), obtain relevant data from the network, and save it in the hard disk 505.
[0079] The input device 504 can receive various instructions input by the operator and send them to the processor 501 for execution. The input device 504 can include a keyboard or a pointing device, such as a mouse, a trackball, a touch pad or a touch screen.
[0080] The display device 506 can display the result obtained by the processor 501 executing the instruction.
[0081] The memory 502 is used to store programs and data necessary for the operation of the operating system, as well as data such as intermediate results during the calculation process of the processor 501.
[0082] It is understood that the memory 502 in the embodiment of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM) or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. The memory 502 of the apparatus and method described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0083] In some implementations, the memory 502 stores the following elements, executable modules or data structures, or a subset thereof, or an extended set thereof: an operating system 5021 and an application program 5022 .
[0084] The operating system 5021 includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., which are used to implement various basic services and process hardware-based tasks. The application 5022 includes various application programs, such as a browser, etc., which are used to implement various application services. The program for implementing the method of the embodiment of the present application can be included in the application 5022.
[0085] The processor 501 executes the enterprise security risk assessment method described in the above embodiment when calling and executing the application and data stored in the memory 502, specifically, the program or instruction stored in the application 5022.
[0086] The method disclosed in the above embodiment of the present application can be applied to the processor 501, or implemented by the processor 501. The processor 501 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 501. The above processor 501 can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a readily available programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to execute, or the hardware and software modules in the decoding processor are combined and executed. The software module can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 502, and the processor 501 reads the information in the memory 502 and completes the steps of the above method in combination with its hardware.
[0087] It is understood that the embodiments described herein can be implemented in hardware, software, firmware, middleware, microcode or a combination thereof. For hardware implementation, the processing unit can be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), general purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described in the present application or a combination thereof.
[0088] For software implementation, the techniques described herein can be implemented by modules (e.g., procedures, functions, etc.) that perform the functions described herein. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or outside the processor.
[0089] In addition, an embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the processor executes the enterprise security risk assessment method as described in the above embodiment.
[0090] In the several embodiments provided in the present application, it should be understood that the disclosed methods and devices can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0091] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may be physically included separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0092] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform some steps of the sending and receiving method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (RandomAccess Memory, referred to as RAM), disk or optical disk and other media that can store program codes.
[0093] The above is a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles described in the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A method for enterprise security risk assessment, characterized in that: The steps include: Obtain basic information of all enterprises, enterprise self-inspection risk information and third-party inspection risk information; Based on the basic information of the enterprise, identify similar enterprises that are similar to the target enterprise; Based on the self-inspection risk information and third-party inspection risk information of the target enterprise and the similar enterprises, the underreporting risk of the target enterprise is obtained.
2. The enterprise security risk assessment method according to claim 1, characterized in that: The basic information of the enterprise includes the name of the enterprise, and the step of determining similar enterprises similar to the target enterprise based on the basic information of the enterprise includes: Vectorizing the enterprise name to obtain a name vectorization result; Based on the name vectorization results of the target enterprise and other enterprises, the similar enterprises are determined.
3. The enterprise security risk assessment method according to claim 2, characterized in that: The step of determining the similar enterprises based on the vectorized results of the names of the target enterprise and other enterprises comprises: Calculate the similarity between the target enterprise and other enterprises’ name vectorization results through the cosine similarity algorithm; Based on the similarity, the similar enterprises are screened out from all other enterprises.
4. The enterprise security risk assessment method according to claim 1, characterized in that: The step of obtaining the underreporting risk of the target enterprise based on the self-inspection risk information of the target enterprise and the similar enterprises and the third-party inspection risk information comprises: Obtaining the self-inspection risk information of all similar enterprises to form a self-inspection risk set; Removing information identical to the self-examination risk information of the target enterprise from the self-examination risk set to form an initial underreporting risk set; Determine the similarity between each risk information in the initial underreporting risk set and the third-party inspection risk information of the similar enterprises, and based on the similarity, screen out the underreporting risk of the target enterprise from the initial underreporting risk set.
5. The enterprise security risk assessment method according to claim 1, characterized in that: The method further comprises: After obtaining the basic information of all enterprises, the self-inspection risk information of the enterprises and the third-party inspection risk information, data cleaning is first performed on the basic information of the enterprises, the self-inspection risk information of the enterprises and the third-party inspection risk information, and duplicate values are retained. Then, subsequent steps are performed to determine similar enterprises similar to the target enterprise based on the basic information of the enterprises.
6. An electronic device, characterized in that: include: processor; and a memory having computer program instructions stored therein, Wherein, when the computer program instructions are executed by the processor, the processor is caused to execute the enterprise security risk assessment method according to any one of claims 1 to 5.
7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer program instructions, and when the computer program instructions are executed by a processor, the processor executes the enterprise security risk assessment method according to any one of claims 1 to 5.