Risk processing method and device, storage medium and electronic equipment
By integrating the risk control engine on each service node of the risk control server and converting data using target protocol mapping rules, the problem of difficulty in synchronizing risk control models and strategies in traditional risk control systems is solved, and efficient risk processing and real-time response are achieved.
Patent Information
- Application Number
- CN202510170414.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-06-06
AI Technical Summary
When traditional risk control systems handle large-scale businesses, it is difficult to achieve real-time data synchronization between the risk control model and the risk control strategy, resulting in low risk processing efficiency.
By pre-integrating the risk control engine on each service node of the risk control server and converting the key information into standardized feature information according to the target protocol mapping rules, real-time synchronization of risk control strategies and localized risk calculations are achieved.
It effectively reduces data transmission delay, improves the real-time and accuracy of risk control processing, reduces unnecessary risk control model training, and improves overall efficiency and response speed.
Smart Images

Figure CN120106969A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computers, and in particular, to a risk management method and device, a storage medium, and an electronic device. Background Art
[0002] With the rapid development of Internet financial services, the requirements for risk control systems are getting higher and higher. Traditional risk control systems mainly include components such as risk control engine services, risk control data services, risk control model services, and risk control strategy configuration services. However, the architectural design of these components is relatively complex, and the service launch time is relatively long, which is not conducive to the rapid iteration and launch of the business.
[0003] Since risk control systems usually have strong real-time and high concurrency, and business scenarios vary, risk control strategies are complex and changeable, and it is difficult to achieve real-time data synchronization between risk control models and risk control strategies in traditional risk control systems. Therefore, for scenarios with large business volumes, it takes more time and resources to train risk control models, which leads to technical problems with low efficiency in the risk handling process.
[0004] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0005] The embodiments of the present application provide a risk management method and device, a storage medium, and an electronic device to at least solve the technical problem of low efficiency that occurs during the risk management process.
[0006] According to one aspect of an embodiment of the present application, a risk handling method is provided, including: in response to a group of received businesses, using a risk control engine pre-integrated on a service node of a risk control service end to parse the group of businesses to obtain a group of key information, wherein the business types of the group of businesses are the same; according to a target protocol mapping rule, converting the group of key information into a group of feature information that meets the requirements of a standardized format, wherein the target protocol mapping rule describes the mapping relationship between a target protocol field and a standardized feature; based on a group of feature information, the risk control engine executes risk calculation logic to obtain a group of estimated risk values; and obtaining a risk analysis result by reporting a group of feature information and a group of estimated risk values to a target risk control model.
[0007] Optionally, the above-mentioned converting a group of key information into a group of characteristic information that meets the requirements of the standardized format according to the target protocol mapping rules includes: converting the data type of a group of key information to obtain a converted group of key information, wherein the data types of the converted group of key information are the same; based on the mapping relationship between the target protocol field and the standardized characteristics, converting a group of protocol fields in the converted group of key information into a group of characteristic information that meets the requirements of the standardized format, wherein the target protocol field includes a group of protocol fields.
[0008] Optionally, the above-mentioned risk analysis results are obtained by reporting a set of feature information and a set of estimated risk values to the target risk control model, including: obtaining model configuration parameters of the target risk control model; based on the model configuration parameters, obtaining the target reporting address; encapsulating a set of feature information to obtain encapsulated feature information; reporting the encapsulated feature information and a set of estimated risk values from the risk control engine to the target risk control model through the target reporting address; based on the encapsulated feature information and a set of estimated risk values, performing aggregation training on the target risk control model to obtain the risk analysis results.
[0009] Optionally, the above-mentioned performing aggregate training on the target risk control model based on the encapsulated feature information and a set of estimated risk values to obtain risk analysis results, including: performing aggregate training on the target risk control model based on the encapsulated feature information and a set of estimated risk values to obtain target training data and risk assessment indicators, wherein the risk assessment indicators are used to represent the risk level or user credibility of a group of businesses; reporting the target training data and risk assessment indicators to the risk control management center; when the target training data indicates that the gradient of the model parameters of the target risk control model does not meet preset conditions, adjusting the model parameters of the target risk control model; when the risk assessment indicators are within the target value range, generating risk analysis results in a group of businesses.
[0010] Optionally, after obtaining the risk analysis results by reporting a set of feature information and a set of estimated risk values to the target risk control model, the above method also includes: determining at least part of the analysis results from the risk analysis results based on the target protocol mapping rules; sending at least part of the analysis results to a risk control engine on a service node through a risk control management center, and saving at least part of the analysis results to a local cache of a service node.
[0011] Optionally, the above method also includes: in response to the received target new business, using the risk control engine to parse the target new business to obtain target key information; according to the target protocol mapping rules, converting the target key information into target feature information; based on the target feature information, the risk control engine executes risk calculation logic to obtain a target estimated risk value; when the attribute information of the target new business is found from the local cache of a service node, the target feature information and the target estimated risk value are reported to the target risk control model.
[0012] Optionally, the above method also includes: when the target new business has the same business type as one of the businesses in a group of businesses, and the target new business has the same user identifier as one of the businesses, searching whether risk analysis data of one of the businesses exists in a local cache of a service node; when risk analysis data of one of the businesses is found in the local cache, the risk control engine outputs the risk analysis data, wherein the risk analysis result includes the risk analysis data.
[0013] Optionally, before parsing a group of businesses in response to a received group of businesses using a risk control engine pre-integrated on a service node of the risk control server, the above method also includes: integrating the risk control engine on a service node of the risk control server in response to a risk control engine request or a push notification sent by the risk control management center.
[0014] According to another aspect of the embodiment of the present application, a risk handling device is also provided, including: a parsing unit, used to respond to a group of received businesses, and use a risk control engine pre-integrated on a service node of a risk control server to parse the group of businesses to obtain a group of key information, wherein the business types of a group of businesses are the same; a first conversion unit, used to convert a group of key information into a group of feature information that meets the requirements of a standardized format according to a target protocol mapping rule, wherein the target protocol mapping rule describes the mapping relationship between the target protocol field and the standardized feature; a first processing unit, used to execute risk calculation logic based on a group of feature information by the risk control engine to obtain a group of estimated risk values; a second processing unit, used to obtain a risk analysis result by reporting a group of feature information and a group of estimated risk values to a target risk control model.
[0015] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is used to execute the above-mentioned risk handling method when executed by an electronic device.
[0016] According to another aspect of the embodiments of the present application, a computer program product is also provided, including a computer program that implements the steps of the above method when the computer program is executed by a processor.
[0017] According to another aspect of the embodiments of the present application, there is further provided an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the risk handling method through the computer program.
[0018] By adopting the above-mentioned embodiment provided by the present application, the risk control engine is built into each service node in the edge service, so that the configuration and model parameters of the risk control engine are distributed to the service node, and the real-time synchronization and localized risk calculation of the risk control strategy are realized, which effectively reduces the data transmission delay and improves the real-time and accuracy of the risk control processing. Secondly, according to the target protocol mapping rules, the key information of multiple businesses extracted is converted into standardized feature information, so that the risk control system can flexibly adapt to different business scenarios, reduce unnecessary risk control model training, improve the overall efficiency and response speed of risk calculation, and solve the technical problem of low efficiency in the risk processing process in related technologies. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute improper limitations on the present application.
[0020] Figure 1 is a schematic diagram of an application scenario of an optional risk management method according to an embodiment of the present application;
[0021] Figure 2 is a flow chart of an optional risk management method according to an embodiment of the present application;
[0022] Figure 3 is an overall schematic diagram of an optional risk management system according to an embodiment of the present application;
[0023] Figure 4 This is a flow chart of an optional risk control SDK reporting data according to an embodiment of the present application;
[0024] Figure 5 is a flow chart of an optional training of a risk control model according to an embodiment of the present application;
[0025] Figure 6 This is an optional flow chart of a risk control management center receiving a training data set result according to an embodiment of the present application;
[0026] Figure 7 is a flow chart of an optional multi-service or cluster access risk control configuration according to an embodiment of the present application;
[0027] Figure 8 This is a flowchart of an optional risk control SDK configuration access and update according to an embodiment of the present application;
[0028] Fig. 9 is another optional flow chart of risk control SDK configuration access and update according to an embodiment of the present application;
[0029] Fig.10is a schematic structural diagram of an optional risk management device according to an embodiment of the present application;
[0030] Fig.11 It is a schematic diagram of the structure of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0031] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0032] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0033] The technical solutions in the embodiments of the present application will comply with legal provisions during implementation. When performing operations according to the technical solutions in the embodiments, the data used will not involve user privacy. While ensuring that the operation process is compliant and legal, the security of the data is guaranteed.
[0034] In addition, when the above embodiments of the present application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data need to comply with relevant regulations and standards of the relevant country or region.
[0035] According to one aspect of the embodiments of the present application, a risk management method is provided. As an optional implementation, the risk management method can be applied to, but is not limited to, Figure 1 The application scenario shown in Figure 1In the application scenario shown, the target terminal 102 may, but is not limited to, communicate with the server 106 via the network 104, and the server 106 may, but is not limited to, perform operations on the database 108, such as write data operations or read data operations. The above-mentioned target terminal 102 may, but is not limited to, include a human-computer interaction screen, a processor, and a memory. The above-mentioned human-computer interaction screen may, but is not limited to, be used to display the target interaction content and target review results in the content interaction platform on the target terminal 102. The above-mentioned processor may, but is not limited to, be used to respond to the above-mentioned human-computer interaction operation, perform corresponding operations, or generate corresponding instructions, and send the generated instructions to the server 106. The above-mentioned memory is used to store relevant processing data, such as a group of services, target protocol mapping rules, and a group of feature information.
[0036] Optionally, in this embodiment, the target terminal may be a terminal configured with a target client, which may include but is not limited to at least one of the following: a mobile phone (such as an Android phone, an iOS phone, etc.), a laptop, a tablet computer, a PDA, a MID (Mobile Internet Devices), a PAD, a desktop computer, a smart TV, etc. The target client may be a video client, an instant messaging client, a browser client, an education client, etc. The network may include but is not limited to: a wired network, a wireless network, wherein the wired network includes: a local area network, a metropolitan area network and a wide area network, and the wireless network includes: Bluetooth, WIFI and other networks that realize wireless communication. The server may be a single server, or a server cluster consisting of multiple servers, or a cloud server.
[0037] In order to solve the problem of low efficiency in the risk handling process, a risk handling method is proposed in the embodiment of the present application. Figure 2 It is a flow chart of a risk handling method according to an embodiment of the present application, and the flow chart includes the following steps S202 to S208.
[0038] It should be noted that the risk handling method shown in step S202 to step S208 can be executed by, but not limited to, an electronic device, wherein the electronic device can be, but not limited to, Figure 1 The target terminal or server is shown.
[0039] Step S202, in response to the received group of services, a risk control engine pre-integrated on a service node of the risk control server is used to parse the group of services to obtain a group of key information, wherein the group of services have the same business type;
[0040] Step S204, converting a set of key information into a set of feature information that meets the requirements of the standardized format according to the target protocol mapping rule, wherein the target protocol mapping rule describes the mapping relationship between the target protocol field and the standardized feature;
[0041] The target protocol field includes at least part of the fields in a set of characteristic information.
[0042] Step S206: Based on a set of feature information, the risk control engine executes risk calculation logic to obtain a set of estimated risk values;
[0043] Step S208, obtaining a risk analysis result by reporting a set of feature information and a set of estimated risk values to a target risk control model.
[0044] like Figure 3 As shown, the risk control system used in the risk management method in the embodiment of the present application includes but is not limited to at least one edge network service (for example, service A, service B, etc.), at least one risk control model (for example, a mall risk control model, a financial risk control model, etc.) and a risk control management center.
[0045] from Figure 3 It can be seen intuitively that the risk control SDK (which can also be understood as the risk control engine) is integrated in each service node on each cluster / service. When a business request is initiated, the configuration parameters of the risk control management center are pulled. When the risk level strategy configuration in the risk control model needs to be adjusted, the risk control management center updates the risk control configuration parameters by push notification or by periodically pulling the risk control SDK.
[0046] It should be noted that in the embodiments of the present application, the risk control engine and the risk control SDK have the same meaning.
[0047] A service node may be, but is not limited to, a server, a virtual machine, a container, or a smaller computing device such as a router, a switch, or a load balancer.
[0048] After the edge service (which can also be understood as the edge network service) calls the SDK, the risk control SDK will calculate the risk level based on the risk control configuration and related parameters, and format the parameters and related results and send them asynchronously to the risk control management center.
[0049] The risk control management center parses the logs, reports and cleans the data based on the received parameters and related results, and finally writes the cleaned risk indicators back to the service node of the edge service to provide them to the risk control SDK in the service node for subsequent risk level calculation.
[0050] Among them, the risk control SDK is a software development kit that integrates risk control functions. It is designed to help developers quickly implement risk control functions in their applications. The main functions of the risk control SDK include at least one of the following:
[0051] (1) Fighting against fraudulent behaviors: The risk control SDK provides powerful anti-fraud capabilities, which can detect and fight against business fraud behaviors such as memory modification, process debugging, and simulated clicks;
[0052] (2) Strategy model defense: Through multiple strategy models, it can effectively defend against variant cheating tools;
[0053] (3) Feature strategy hot update: The feature strategy hot update capability is retained to promptly respond to new plug-in attacks without requiring customers to update the SDK.
[0054] (4) Data verification interface: Provides a data verification interface to help businesses implement business data security verification and prevent data tampering and cheating.
[0055] In the embodiment of the present application, the processing process of the risk control SDK includes but is not limited to configuration and indicator acquisition and update, parameter protocol data mapping conversion, risk value calculation, data encryption and decryption, data reporting, and configuration and indicator storage.
[0056] Among them, the purpose of data encryption is to prevent data leakage and tampering during data transmission. Data reporting includes but is not limited to reporting the estimated risk value calculated by the risk control SDK and a set of feature information converted according to the target protocol mapping rules to the risk model.
[0057] In an embodiment of the present application, the risk control SDK is only provided to each service node for integration. The risk control SDK on each service node does not participate in model training, but only outputs risk values based on the configured calculation task parameters and indicator results. For example, a credit score is output based on the user's phone call, and the probability of fraud is output based on the user's purchase request.
[0058] In the embodiment of the present application, the design of integrating the risk control SDK into each service node enables the risk control system to respond quickly to business needs, especially in scenarios with high real-time requirements such as financial transactions and network security monitoring, which can significantly improve the efficiency of risk identification and processing.
[0059] The risk control SDK uses the storage capabilities of the service itself, such as redis and mangoDB, to store the acquired indicators locally in the service, including the amount withdrawn by user A in one day, the activity score of user B of 80, etc., so that it can be quickly provided to the task module of the risk control SDK to perform risk calculations.
[0060] In addition, a target protocol mapping rule is also set in the embodiment of the present application. Through this mapping rule, the key information of multiple businesses extracted can be converted into standardized feature information, and then the standardized feature information can be reported to the risk control model training system, ensuring that the same type of business with different data formats can share the risk control model, reducing the training of the risk control model, and saving training resources and data processing processes.
[0061] Among them, the process of using the risk model to process the data reported by the risk control SDK includes but is not limited to configuration and indicator acquisition and update, data cleaning, model training, data encryption and decryption, and result reporting.
[0062] Data cleaning methods include but are not limited to performing processing such as aggregation calculations and labeling based on the data. At the same time, the cleaned data and historical training data obtained from the risk control management center are used to train the risk control model, and the training results are encrypted and finally reported to the risk control management center.
[0063] The risk control management center mainly performs processing procedures based on the data reported by the risk control SDK and the risk control model, including but not limited to configuration and indicator acquisition and update, gradient aggregation, indicator and parameter storage, data encryption and decryption, and result reporting.
[0064] Specifically, according to the data reported by the risk control model, a gradient aggregation calculation is performed to determine whether to update the model parameters of the risk control model, and the risk index is output according to the data analyzed by the risk control model. For example, when it is determined that the user credit output by the risk control model is within the first preset interval, it is determined that the business 1 initiated by the user is handled normally; when it is determined that the user credit output by the risk control model is within the second preset interval, it is determined that the risk value of business 2 exceeds the threshold, and the credit level of the user is reduced.
[0065] It should be noted that the risk control SDK integrated on the service node focuses on providing risk control tools and interfaces at the front-end application level, while the risk control model is based on the estimated risk value calculated by the risk control SDK for back-end data analysis and risk assessment. In other words, the risk control model focuses more on identifying and quantifying risks through data analysis and algorithms. For example, based on the prepaid risk value calculated by the risk control SDK, the risk level and credit rating of each user can be analyzed.
[0066] By adopting the above method, by embedding the risk control SDK in each service node in the edge service, the configuration and model parameters of the risk control engine are distributed to the service nodes, realizing the real-time synchronization of risk control strategies and localized risk calculation, effectively reducing data transmission delays, and improving the real-time and accuracy of risk control processing. Secondly, according to the target protocol mapping rules, the key information of multiple businesses extracted is converted into standardized feature information, so that the risk control system can flexibly adapt to different business scenarios, reduce unnecessary risk control model training, improve the overall efficiency and response speed of risk calculation, and solve the technical problem of low efficiency in the risk processing process in related technologies.
[0067] As an optional example, the above converting a set of key information into a set of feature information that meets the requirements of the standardized format according to the target protocol mapping rule includes:
[0068] Converting the data type of a set of key information to obtain a converted set of key information, wherein the data types of the converted set of key information are the same;
[0069] Based on the mapping relationship between the target protocol field and the standardized features, a group of protocol fields in the converted group of key information is converted into a group of feature information that meets the standardized format requirements, wherein the target protocol field includes a group of protocol fields.
[0070] Among them, a group of key information is information extracted from the business information of a group of businesses, such as user account, business type and business parameters (such as loan amount, transaction time, payment method, etc.).
[0071] In this embodiment, the processing flow that the target protocol mapping rule can provide is as follows:
[0072] S11, protocol analysis module;
[0073] In this embodiment, multiple protocols are provided to configure (Protocol Adapter) to support original data formats of different services, for example, data in protocol formats such as JSON, XML, and CSV, for extracting key information.
[0074] S12, mapping rule engine;
[0075] The mapping relationship between protocol fields and standardized features is defined through configuration files, and supports field self-verification, conversion (such as data type conversion, normalization) and verification (such as missing value filling).
[0076] S13, feature normalization module;
[0077] Standardize the mapped field data into a unified format, for example, convert the protocol field in the key information into a vector of a specific dimension; provide feature engineering tools, such as normalization, discretization, and one-hot encoding.
[0078] S14, reporting module.
[0079] The processed data is packaged according to the model requirements, and the packaged data is uploaded to the unified model training system, supporting multiple data transmission protocols, such as HTTP, gRPC, etc.
[0080] The configuration target protocol mapping relationship shows how the data fields of the loan business and payment business are mapped to standardized features through configuration. Specifically, it includes:
[0081] S21, according to the business identifier (such as loan, payment), calling the corresponding protocol adapter from the original data to parse the protocol field;
[0082] S22, field mapping and conversion;
[0083] Use the mapping rule engine to read the field mapping rules of the corresponding business and complete the standardization of the fields.
[0084] S23, normalizing or logarithmically transforming continuous data (such as amount, rating), i.e., performing feature processing;
[0085] This includes but is not limited to encoding discrete data (e.g., classification, device type) (e.g., one-hot, label, binary encoding).
[0086] S24, the processed data is encapsulated into a unified input format (such as a fixed-dimensional vector) and uploaded to the model for training, that is, output in a unified format.
[0087] The following uses the loan and payment businesses as examples to describe the specific process of using the target protocol mapping rules to access the adapter and convert the protocol fields into data in a standardized format.
[0088] Loan business adaptation
[0089] Original data (json):
[0090] {
[0091] "user_id":"12345",
[0092] "loan_amount":5000,
[0093] "loan_purpose":"education",
[0094] "credit_score":720
[0095] }
[0096] Mapped features (json):
[0097] {
[0098] "uid":"12345",
[0099] "amount":0.35, / / Min-max scaling result
[0100] "purpose":[1,0,0,0], / / One-hot encoding
[0101] "credit":-0.12 / / Z-score result
[0102] }
[0103] Payment service adaptation
[0104] Original data (json):
[0105] {
[0106] "user_id":"67890",
[0107] "transaction_amount":200,
[0108] "merchant_category":"electronics",
[0109] "device_type":"mobile"
[0110] }
[0111] Mapped features (json):
[0112] {
[0113] "uid":"67890",
[0114] "amount":5.29, / / logarithmic transformation result
[0115] "category":3, / / label encoding result
[0116] "device":[0,1] / / binary encoding
[0117] }
[0118] Through the above method, the data of the same type of business can be converted into a unified format, and relying on the business identifier and user identifier, the different businesses of the same type can be accurately identified so that they can be subsequently assigned to the same risk control model for training, reducing the problem of excessive resource consumption caused by training models for each business of the same type.
[0119] As an optional implementation method, the above-mentioned risk analysis results are obtained by reporting a set of feature information and a set of estimated risk values to the target risk control model, including:
[0120] Obtain the model configuration parameters of the target risk control model;
[0121] Based on the model configuration parameters, obtain the target reporting address;
[0122] Encapsulate a set of feature information to obtain encapsulated feature information;
[0123] Through the target reporting address, the packaged feature information and a set of estimated risk values are reported from the risk control engine to the target risk control model;
[0124] Based on the encapsulated feature information and a set of estimated risk values, aggregate training is performed on the target risk control model to obtain risk analysis results.
[0125] Among them, after the risk control SDK (which can also be understood as the risk control engine) performs risk calculation, it reports the calculated estimated risk value and a set of feature information converted by the target protocol mapping rules to the risk control model.
[0126] Combine the following Figure 4 Explain the risk control SDK computer reporting process.
[0127] S402, responding to the service request;
[0128] S404, obtaining a target protocol mapping rule;
[0129] The process of configuring and mapping the protocol fields (key fields in the service data) in the target protocol mapping rules to standardized features may refer to the description in the above embodiments.
[0130] S406, conversion protocol;
[0131] Through the various protocol adapters provided, the original data formats of different businesses are supported, and the protocol fields are converted through the mapping relationship between the protocol fields defined in the configuration file and the standardized features.
[0132] S408, querying computing task parameters;
[0133] The key business parameters involved in risk calculation are queried from the business information of a group of businesses, which can also be understood as the key task parameters involved in risk calculation.
[0134] S410, performing risk calculation based on the queried calculation task parameters, and obtaining an estimated risk value;
[0135] S412, encapsulating the risk calculation result and the original value (a set of characteristic information);
[0136] Obviously, although the risk calculation results and a set of characteristic information are encapsulated, the encapsulated data keeps the key business information unchanged, such as user ID, device ID, loan amount, etc., and only the data format changes.
[0137] S414, differential privacy + homomorphic encryption processing;
[0138] Differential privacy is mainly used to identify sensitive parts of risk control strategies, such as user privacy data such as amount and age, while allowing analysis results or training data to be shared in distributed systems. Homomorphic encryption mainly includes encrypted transmission, which is used to prevent data leakage or tampering during transmission.
[0139] S416, obtaining a reporting address according to the model configuration;
[0140] Among them, the risk calculation results of a group of businesses may be assigned to the same risk control model at the same time, or may be assigned to multiple risk control models.
[0141] S418: Report the packaged feature information and a set of prepayment risk values to the risk control model through the obtained reporting address.
[0142] As an optional implementation method, the above-mentioned aggregation training is performed on the target risk control model based on the encapsulated feature information and a set of estimated risk values to obtain risk analysis results, including:
[0143] Based on the encapsulated feature information and a set of estimated risk values, aggregate training is performed on the target risk control model to obtain target training data and risk assessment indicators, where the risk assessment indicators are used to represent the risk level of a set of businesses or the credibility of users;
[0144] Report target training data and risk assessment indicators to the risk control management center;
[0145] When the target training data indicates that the gradient of the model parameters of the target risk control model does not meet the preset conditions, adjusting the model parameters of the target risk control model;
[0146] When the risk assessment indicator is within the target value range, a set of risk analysis results in the business is generated.
[0147] like Figure 5 As shown in the figure, based on the data reported by the risk control SDK, the specific process of training the risk control model is as follows:
[0148] S502, obtaining reported business data;
[0149] Among them, the data reported by the risk control SDK includes two parts. One part is the estimated risk calculation obtained for a group of businesses, and the other part is the feature information converted and encapsulated by the target protocol mapping rules.
[0150] S504, parsing the received business data;
[0151] S506, obtaining service configuration;
[0152] Among them, the business configuration defines the mapping relationship between standardized features and protocol fields.
[0153] S508, performing data homomorphic decryption according to the business configuration;
[0154] In combination with the description in the above embodiments, it can be seen that in the reporting process, in order to prevent data leakage or tampering, the business data is homomorphically encrypted. Therefore, after receiving the reported data, it needs to be homomorphically decrypted.
[0155] S510, performing aggregation training on the data according to the risk control model;
[0156] During the model training process, data from different businesses are reported to different risk control models for training based on business attributes, reducing the waste of resources caused by each service node performing its own model training.
[0157] S512: Report the training data to the risk control management center.
[0158] As an optional example, after obtaining the risk analysis result by reporting a set of feature information and a set of estimated risk values to the target risk control model, the method further includes:
[0159] Determining at least a portion of the analysis results from the risk analysis results based on the target protocol mapping rule;
[0160] At least part of the analysis results are sent to a risk control engine on a service node through a risk control management center, and at least part of the analysis results are saved in a local cache of a service node.
[0161] By utilizing the above-mentioned target protocol mapping relationship, not only can the business data of a group of businesses be converted into standardized features, but also the mapping relationship between the protocol fields and the risk analysis results can be defined, so that the risk control management center can determine at least part of the analysis results to be sent down or returned to the risk control SDK based on the mapping relationship.
[0162] Obviously, it is easy to understand that through Figure 3 Before the risk control management center sends risk indicators, task parameters, and risk control configurations to the risk control SDK, it is also necessary to Figure 6 The flowchart shown receives training data and risk analysis results.
[0163] S602, training data reporting;
[0164] The data after risk control training is reported to the risk control management center, and through the control logic in risk control management, it is determined whether the model parameters of the risk control model need to be adjusted.
[0165] S604, analyzing the training data;
[0166] S606, obtaining service configuration;
[0167] In addition to the training data reported by the risk control model, the risk control SDK will also report the mapped business data (that is, standardized feature information) to the risk control management center.
[0168] S608, comparing and updating the index results;
[0169] S610, calculating the aggregation gradient for each service node;
[0170] The aggregate gradient is used to determine whether the model parameters of the risk control model need to be adjusted.
[0171] S612, update model configuration.
[0172] Among them, the configuration parameters that need to be updated include but are not limited to updating the model parameters of the risk control model and updating the task parameters and indicator results on the service node where the risk control SDK is located.
[0173] The risk control management center obtains the cleaned risk indicators, selects the master node when the service is registered according to the configuration (the mapping relationship in the target protocol mapping rule), and writes the business indicators back to the master node of the edge service. The risk control SDK of the master node can store the indicators at the service level, for example, the indicator maintenance of network cache, redis, database, etc., and provide them to the risk control SDK for subsequent risk level calculation.
[0174] Through the above method, when the same user repeatedly handles the same type of business, it can be determined whether it is necessary to perform risk calculation again based on the latest risk analysis results of the risk control management center on the user or the business, thereby improving.
[0175] As an optional implementation, the above method further includes:
[0176] In response to the received target new business, the risk control engine is used to analyze the target new business to obtain the target key information;
[0177] According to the target protocol mapping rules, the target key information is converted into target feature information;
[0178] Based on the target feature information, the risk control engine executes the risk calculation logic to obtain the target estimated risk value;
[0179] When the attribute information of the target new business is found in the local cache of a service node, the target feature information and the target estimated risk value are reported to the target risk control model.
[0180] In an embodiment of the present application, for a newly connected risk control business, the business access can be quickly performed by simply selecting a corresponding risk control model according to the business characteristics and configuring a protocol mapping relationship without the need for model training based on historical data.
[0181] In other words, for a new risk control business, if it is found that the risk control model assigned to the risk control business has processed data analysis and model training for the same type of business, and the risk analysis results reported to the risk control management center by the risk control model have been sent to the risk control SDK, then there is no need to perform risk calculation again, which reduces computing resources and improves risk assessment efficiency.
[0182] Specifically, when the target new service is the same as the service type of one of the services in the group of services, and the target new service is the same as the user identifier of one of the services, searching whether there is risk analysis data of one of the services in a local cache of a service node;
[0183] When the risk analysis data of one of the businesses is found in the local cache, the risk control SDK outputs the risk analysis data, wherein the risk analysis result includes the risk analysis data.
[0184] Combined with the description in the above embodiments, it can be known that the key to realizing the technical solution of the present application is that the risk control SDK is pre-integrated on each service node of the risk control server. That is, before the risk control SDK pre-integrated on a service node of the risk control server is used to parse a group of services in response to a group of services received, the risk control SDK is integrated on a service node of the risk control server in response to a risk control SDK request or a push notification sent by the risk control management center.
[0185] Combine the following Figure 7 The flowchart of service or cluster access shown in the figure describes the access process from the risk control server.
[0186] S702, register each service;
[0187] S704, select risk control SDK;
[0188] According to business attributes and risk calculation logic, select risk control SDKs on different service nodes for different businesses to perform risk calculations.
[0189] S706, select a risk control model;
[0190] like Figure 3 As shown, in a risk control system, including but not limited to multiple different types of risk control models, in actual application scenarios, the risk calculation data reported by the risk SDK and the standardized feature information after protocol conversion are reported to different risk control models according to the business attributes of different businesses.
[0191] S708: Configure reporting protocol mapping rules.
[0192] That is, a first mapping relationship between the protocol field in the business data and the standardized features is configured, and a second mapping relationship between the standardized features and the data sent by the risk control management center is configured.
[0193] After the service or cluster is connected, you need to Figure 8 As shown in the schematic diagram, the risk control SDK is connected to each service node.
[0194] like Fig. 9 As shown, the way to access the risk control SDK includes responding to SDK requests (risk control SDK timed pull) and message push from the risk control management center, thereby connecting the risk control SDK to the corresponding service node. Figure 8 As shown, the parameter protocol configuration, computing task parameter configuration, and indicator results can also be sent to the risk control SDK through the risk control management center, and the updated indicator results and parameter configuration data can be saved in the local cache of the risk control SDK.
[0195] Through the above-mentioned interaction process between the risk control management center and the risk control SDK, real-time synchronization of data between the two can be ensured. At the same time, for the same type of business, protocol processing can be performed according to the configured protocol mapping relationship, and then the real-time data can be reported to the same risk control model to realize multi-task learning of the model and maximize resource sharing.
[0196] It can be seen from the description of the above embodiments that the technical solution in the embodiments of the present application is used to process real-time data, which has at least the following beneficial effects:
[0197] (1) By integrating the risk control SDK in each service node, the risk control response efficiency is improved. At the same time, the service availability requirements for risk control can be improved in cross-cloud, cross-data center, and even cross-regional network environments.
[0198] (2) By configuring the protocol mapping relationship, it can be dynamically adjusted according to the business scenario to support risk control strategies in different business areas. This dynamic adjustment capability enables the system to flexibly adapt to various business needs and provide more comprehensive and sophisticated risk management services for scenarios with multiple businesses running in parallel, such as comprehensive financial service platforms and diversified e-commerce platforms;
[0199] (3) Using protocol mapping rules, the risk calculation and analysis data is sent from the risk control management center to the risk control SDK, thereby reducing unnecessary risk control model training and saving resources when processing the same type of business in the future;
[0200] (4) Through the interaction between the risk control management center and the risk control SDK integrated on the service node, ensure the real-time synchronization between the risk control strategy of the service node and the parameter configuration of the risk control management center.
[0201] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0202] According to another aspect of the embodiment of the present application, there is also provided Fig.10 A risk management device is shown, the device comprising:
[0203] The first parsing unit 1002 is used to parse the group of services in response to the received group of services by using a risk control engine pre-integrated on a service node of the risk control server to obtain a group of key information, wherein the group of services have the same business type;
[0204] The first conversion unit 1004 is used to convert a set of key information into a set of feature information that meets the requirements of the standardized format according to the target protocol mapping rule, wherein the target protocol mapping rule describes the mapping relationship between the target protocol field and the standardized feature;
[0205] The first processing unit 1006 is used for the risk control engine to execute risk calculation logic based on a set of feature information to obtain a set of estimated risk values;
[0206] The second processing unit 1008 is used to obtain a risk analysis result by reporting a set of feature information and a set of estimated risk values to a target risk control model.
[0207] Optionally, the first conversion unit 1004 includes:
[0208] A first conversion module is used to convert the data type of a set of key information to obtain a converted set of key information, wherein the data types of the converted set of key information are the same;
[0209] The second conversion module is used to convert a group of protocol fields in a converted group of key information into a group of feature information that meets the standardized format requirements based on the mapping relationship between the target protocol field and the standardized features, wherein the target protocol field includes a group of protocol fields.
[0210] Optionally, the second processing unit 1008 includes:
[0211] A first acquisition module is used to acquire model configuration parameters of a target risk control model;
[0212] The second acquisition module is used to obtain the target reporting address based on the model configuration parameters;
[0213] The encapsulation module is used to encapsulate a set of characteristic information to obtain encapsulated characteristic information;
[0214] A first reporting module, used to report the encapsulated feature information and a set of estimated risk values from the risk control engine to the target risk control model through a target reporting address;
[0215] The first processing module is used to perform aggregation training on the target risk control model based on the encapsulated feature information and a set of estimated risk values to obtain risk analysis results.
[0216] Optionally, the first processing module includes:
[0217] The second processing module is used to perform aggregate training on the target risk control model based on the encapsulated feature information and a set of estimated risk values to obtain target training data and risk assessment indicators, wherein the risk assessment indicators are used to represent the risk level of a set of businesses or the credibility of users;
[0218] The second reporting module is used to report the target training data and risk assessment indicators to the risk control management center;
[0219] A first adjustment module, configured to adjust the model parameters of the target risk control model when the target training data indicates that the gradient of the model parameters of the target risk control model does not meet a preset condition;
[0220] The third processing module is used to generate a set of risk analysis results in the business when the risk assessment indicator is within the target value range.
[0221] Optionally, the above device further includes:
[0222] a third processing unit, configured to determine at least part of the analysis results from the risk analysis results based on the target protocol mapping rule after obtaining the risk analysis results by reporting a set of feature information and a set of estimated risk values to the target risk control model;
[0223] The sending unit is used to send at least part of the analysis results to the risk control engine on a service node through the risk control management center, and save at least part of the analysis results to the local cache of a service node.
[0224] Optionally, the above device further includes:
[0225] A second parsing unit is used to respond to the received target new business and use the risk control engine to parse the target new business to obtain target key information;
[0226] A second conversion unit, used to convert the target key information into target feature information according to the target protocol mapping rule;
[0227] The fourth processing unit is used for the risk control engine to execute risk calculation logic based on the target feature information to obtain a target estimated risk value;
[0228] The reporting unit is used to report the target feature information and the target estimated risk value to the target risk control model when the attribute information of the target new business is found from the local cache of a service node.
[0229] Optionally, the above device further includes:
[0230] a search unit, configured to search whether risk analysis data of one of the services exists in a local cache of a service node when the target new service has the same service type as one of the services in a group of services and the target new service has the same user identifier as one of the services;
[0231] The fifth processing unit is used to output the risk analysis data when the risk analysis data of one of the businesses is found in the local cache, wherein the risk analysis result includes the risk analysis data.
[0232] Optionally, the above device further includes:
[0233] The sixth processing unit is used to integrate the risk control engine on a service node of the risk control server in response to a risk control engine request or a push notification sent by the risk control management center before parsing a group of businesses using a risk control engine pre-integrated on a service node of the risk control server in response to a group of businesses received.
[0234] By applying the above device to each service node that has the risk control SDK built into the edge service, the configuration and model parameters of the risk control engine are distributed to the service nodes, realizing real-time synchronization of risk control strategies and localized risk calculation, effectively reducing data transmission delays, and improving the real-time and accuracy of risk control processing. Secondly, according to the target protocol mapping rules, the key information of multiple businesses extracted is converted into standardized feature information, so that the risk control system can flexibly adapt to different business scenarios, reduce unnecessary risk control model training, improve the overall efficiency and response speed of risk calculation, and solve the technical problem of low efficiency in the risk processing process in related technologies.
[0235] It should be noted that the embodiments of the risk handling device here can refer to the embodiments of the risk handling method mentioned above, which will not be described in detail here.
[0236] According to another aspect of the embodiment of the present application, an electronic device for implementing the above-mentioned risk handling method is also provided. The electronic device may be Figure 1 The target terminal or server shown in FIG. This embodiment is described by taking the electronic device as the target terminal as an example. Fig.11 As shown, the electronic device includes a memory 1102 and a processor 1104. The memory 1102 stores a computer program, and the processor 1104 is configured to execute the steps in any of the above method embodiments through the computer program.
[0237] Optionally, in this embodiment, the electronic device may be located in at least one network device among a plurality of network devices of a computer network.
[0238] Optionally, in this embodiment, the processor may be configured to perform the following steps through a computer program:
[0239] S1, in response to a group of received businesses, a risk control SDK pre-integrated on a service node of a risk control server is used to parse the group of businesses to obtain a group of key information, wherein the business types of the group of businesses are the same;
[0240] S2, converting a set of key information into a set of feature information that meets the requirements of the standardized format according to the target protocol mapping rule, wherein the target protocol mapping rule describes the mapping relationship between the target protocol field and the standardized feature;
[0241] S3, based on a set of feature information, the risk control SDK executes the risk calculation logic to obtain a set of estimated risk values;
[0242] S4, by reporting a set of characteristic information and a set of estimated risk values to the target risk control model, the risk analysis results are obtained.
[0243] Alternatively, a person skilled in the art may understand that: Fig.11 The structure shown is for illustration only. Fig.11 The electronic device and the electronic equipment described above are not limited in structure. Fig.11 More or fewer components (such as network interfaces, etc.) as shown in, or with Fig.11 Different configurations are shown.
[0244] Among them, the memory 1102 can be used to store software programs and modules, such as program instructions / modules corresponding to the risk management method and device in the embodiments of the present application. The processor 1104 executes various functional applications and data processing by running the software programs and modules stored in the memory 1102, that is, to implement the above-mentioned risk management method. The memory 1102 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 1102 may further include a memory remotely located relative to the processor 1104, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. Among them, the memory 1102 may be specifically, but not limited to, used to store a set of key information, a set of characteristic information, and a set of estimated risk values, etc. As an example, such as Fig.11As shown, the memory 1102 may include, but is not limited to, the first parsing unit 1002, the first conversion unit 1004, the first processing unit 1006, and the second processing unit 1008 in the risk processing device. In addition, it may also include, but is not limited to, other module units in the risk processing device, which will not be repeated in this example.
[0245] Optionally, the transmission device 1106 is used to receive or send data via a network. Specific examples of the network may include a wired network and a wireless network. In one example, the transmission device 1106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices and routers via a network cable so as to communicate with the Internet or a local area network. In one example, the transmission device 1106 is a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0246] In addition, the electronic device further includes: a display 1108 for displaying the group of businesses and risk analysis results; and a connection bus 1110 for connecting various module components in the electronic device.
[0247] In other embodiments, the target terminal or server may be a node in a distributed system, wherein the distributed system may be a blockchain system, and the blockchain system may be a distributed system formed by connecting the multiple nodes through network communication. The nodes may form a point-to-point network, and any form of computing device, such as a server, a target terminal or other electronic device, may become a node in the blockchain system by joining the point-to-point network.
[0248] According to another aspect of the present application, a computer program product or computer program is provided, the computer program product or computer program includes computer instructions, the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device performs the risk processing method provided in various optional implementations of the above-mentioned server verification processing and other aspects, wherein the computer program is configured to perform the steps of any of the above-mentioned method embodiments when running.
[0249] Optionally, in this embodiment, the computer-readable storage medium may be configured to store a computer program for performing the following steps:
[0250] S1, in response to a group of received businesses, a risk control SDK pre-integrated on a service node of a risk control server is used to parse the group of businesses to obtain a group of key information, wherein the business types of the group of businesses are the same;
[0251] S2, converting a set of key information into a set of feature information that meets the requirements of the standardized format according to the target protocol mapping rule, wherein the target protocol mapping rule describes the mapping relationship between the target protocol field and the standardized feature;
[0252] S3, based on a set of feature information, the risk control SDK executes the risk calculation logic to obtain a set of estimated risk values;
[0253] S4, by reporting a set of characteristic information and a set of estimated risk values to the target risk control model, the risk analysis results are obtained.
[0254] Optionally, in the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories), or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0255] Optionally, in this embodiment, a person of ordinary skill in the art may understand that all or part of the steps in the various methods of the above embodiments may be completed by instructing the hardware related to the target terminal through a program, and the program may be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, etc.
[0256] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0257] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling one or more computer devices (which can be personal computers, servers or network devices, etc.) to execute all or part of the steps of the methods of each embodiment of the present application.
[0258] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0259] In the several embodiments provided in the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only schematic, for example, the division of units is only a logical function division, and there may be other division methods in actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0260] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0261] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0262] The above are only preferred implementations of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A risk management method, characterized in that: include: In response to the received group of businesses, a risk control engine pre-integrated on a service node of the risk control server is used to parse the group of businesses to obtain a group of key information, wherein the business types of the group of businesses are the same; According to the target protocol mapping rule, converting the set of key information into a set of feature information that meets the requirements of the standardized format, wherein the target protocol mapping rule describes the mapping relationship between the target protocol field and the standardized feature; Based on the set of feature information, the risk control engine executes risk calculation logic to obtain a set of estimated risk values; The risk analysis result is obtained by reporting the set of characteristic information and the set of estimated risk values to the target risk control model.
2. The method according to claim 1, characterized in that The step of converting the set of key information into a set of feature information that meets the requirements of a standardized format according to the target protocol mapping rule includes: Converting the data type of the set of key information to obtain a converted set of key information, wherein the data types of the converted set of key information are the same; Based on the mapping relationship between the target protocol field and the standardized feature, a group of protocol fields in the converted group of key information is converted into the group of feature information that meets the standardized format requirements, wherein the target protocol field includes the group of protocol fields.
3. The method according to claim 1, characterized in that The step of obtaining a risk analysis result by reporting the set of feature information and the set of estimated risk values to the target risk control model includes: Obtaining model configuration parameters of the target risk control model; Based on the model configuration parameters, obtaining a target reporting address; Encapsulating the set of characteristic information to obtain encapsulated characteristic information; Reporting the packaged feature information and the set of estimated risk values from the risk control engine to the target risk control model through the target reporting address; Based on the packaged feature information and the set of estimated risk values, aggregate training is performed on the target risk control model to obtain the risk analysis result.
4. The method according to claim 3, characterized in that The performing aggregation training on the target risk control model based on the packaged feature information and the set of estimated risk values to obtain the risk analysis result includes: Based on the packaged feature information and the set of estimated risk values, performing aggregate training on the target risk control model to obtain target training data and risk assessment indicators, wherein the risk assessment indicators are used to represent the risk level of the set of businesses or the user credibility; Reporting the target training data and the risk assessment indicators to the risk control management center; When the target training data indicates that the gradient of the model parameter of the target risk control model does not meet a preset condition, adjusting the model parameter of the target risk control model; When the risk assessment indicator is within the target value range, a risk analysis result for the group of businesses is generated.
5. The method according to any one of claims 1 to 4, characterized in that After obtaining the risk analysis result by reporting the set of feature information and the set of estimated risk values to the target risk control model, the method further includes: Determining at least part of the analysis results from the risk analysis results based on the target protocol mapping rule; The at least part of the analysis result is sent to the risk control engine on the one service node through the risk control management center, and the at least part of the analysis result is saved in the local cache of the one service node.
6. The method according to claim 5, characterized in that The method further comprises: In response to the received target new business, the risk control engine is used to analyze the target new business to obtain target key information; According to the target protocol mapping rule, converting the target key information into target feature information; Based on the target feature information, the risk control engine executes risk calculation logic to obtain a target estimated risk value; When the attribute information of the target new business is found in the local cache of the one service node, the target feature information and the target estimated risk value are reported to the target risk control model.
7. The method according to claim 5, characterized in that The method further comprises: When the target new service is of the same service type as one of the services in the group of services, and the target new service is of the same user identifier as one of the services, searching whether risk analysis data of the one of the services exists in a local cache of the one service node; In the case where the risk analysis data of one of the businesses is found in the local cache, the risk control engine outputs the risk analysis data, wherein the risk analysis result includes the risk analysis data.
8. The method according to claim 1, characterized in that Before, in response to the received set of services, parsing the set of services using a risk control engine pre-integrated on a service node of the risk control server, the method further includes: In response to a risk control engine request or a push notification sent by a risk control management center, the risk control engine is integrated on the one service node of the risk control server.
9. A risk management device, characterized in that: include: A parsing unit, configured to, in response to a received group of services, parse the group of services using a risk control engine pre-integrated on a service node of a risk control server to obtain a group of key information, wherein the group of services have the same service type; A first conversion unit, configured to convert the set of key information into a set of feature information that meets the requirements of a standardized format according to a target protocol mapping rule, wherein the target protocol mapping rule describes a mapping relationship between a target protocol field and a standardized feature; A first processing unit, configured to cause the risk control engine to execute risk calculation logic based on the set of feature information to obtain a set of estimated risk values; The second processing unit is used to obtain a risk analysis result by reporting the set of feature information and the set of estimated risk values to a target risk control model.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored program, wherein the program can be executed by a terminal device or a computer to execute the method described in any one of claims 1 to 8.
11. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method described in any one of claims 1 to 8 are implemented.
12. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to execute the method according to any one of claims 1 to 8 through the computer program.