Enterprise risk assessment method and system based on big data

By generating interfering data during data transmission and performing data splitting and mixing processing, and detecting data integrity and abnormal situations at the receiving end, the problem of insufficient data transmission security analysis in the prior art is solved, and the security and analysis accuracy of data transmission are improved.

CN120150994APending Publication Date: 2025-06-13SHANXI COKING COAL GROUP FINANCE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510214892.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The existing technology does not conduct security analysis on the data transmission process, which is prone to data interception problems, resulting in data leakage.

Method used

By obtaining the characteristics of the information to be transmitted, interfering data is generated, the information to be transmitted is split and mixed with the interference data to process, and the data integrity and abnormal situation are detected at the receiving end, whether there is a risk of interception in the network environment, and the parameters are adjusted or an alarm is issued based on the analysis results.

Benefits of technology

It improves the security of the data transmission process, enhances the accuracy of the analysis of the data transmission process and the enterprise network environment, promptly remediates to prevent data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120150994A_ABST
    Figure CN120150994A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of enterprise informatization, in particular to an enterprise risk assessment method and system based on big data, and the method comprises the steps: generating interference data based on the characteristics of to-be-transmitted information, splitting the to-be-transmitted information, mixing the split data with the interference data, and transmitting the mixed data. According to the method, interference data exist in intercepted data, the safety of the data transmission process is improved, and in consideration of the abnormal conditions of missing, repetition and the like of the received data due to the operation of an interceptor when data interception occurs, the data are numbered before data transmission, so that the data interception efficiency is improved. Whether the data transmission process is subjected to data interception or not is analyzed according to the integrity condition of the received data, so that the analysis accuracy for the data transmission process is improved, the analysis accuracy for the network environment of an enterprise is improved, and when it is judged that data interception exists, remedy is conducted in time, so that the data transmission safety is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of enterprise informatization technology, and particularly to an enterprise risk assessment method and system based on big data. Background Art

[0002] With the advent of the big data era, important information of enterprises is mostly transmitted online. Existing technologies mostly use intelligent technologies to create various types of accounts according to contracts, monitor business information, regularly send and save relevant data such as materials, self-inspection information, and reports, improve the data transmission rate between enterprises, ensure information transparency between enterprises, and promote business transactions between enterprises. However, the security analysis of the data transmission process is not carried out, and data interception problems are likely to occur, resulting in data leakage.

[0003] Chinese Patent Publication No.: CN113887987A discloses an enterprise operation risk assessment method, including a management background, a service enterprise, an authorized enterprise, and an operation analysis system; the management background creates service enterprise accounts and authorized enterprise accounts according to contracts respectively; the management background conducts third-party industrial and commercial information association verification on the operation analysis system; the management background sends the service enterprise accounts and authorized enterprise accounts to the corresponding service enterprises and authorized enterprises respectively; the service enterprise accounts import the authorized enterprise list, company name, and taxpayer identification number, and perform invitation relationship matching on the authorized enterprises; the authorized enterprises start synchronous monitoring of the operation analysis system; the authorized enterprises regularly send materials, self-inspection information, and operation reports to the service enterprises; the management background automatically saves the data. It enables enterprises to quickly and effectively understand the operation risk status of relevant enterprises and enables enterprises to better conduct business transactions with relevant enterprises.

[0004] However, the existing technologies still have the following problems: The security analysis of the data transmission process is not carried out, and data interception problems are likely to occur, resulting in data leakage. Summary of the Invention

[0005] Therefore, the present invention provides an enterprise risk assessment method and system based on big data to overcome the problems in the existing technologies that the security analysis of the data transmission process is not carried out, data interception problems are likely to occur, and data leakage is caused.

[0006] To achieve the above object, the present invention provides an enterprise risk assessment method based on big data. The method includes: Step S1, obtaining the characteristics of the information to be transmitted, generating interference data based on the characteristics, splitting the information to be transmitted to obtain a plurality of data, and performing mixing processing on the data and the interference data; Step S2, numbering each of the mixed data according to the conveying order, and after the numbering is completed, conveying them in sequence, and periodically detecting and recording the total flow at each time node during the data transmission process; Step S3: Receive the transmitted data, detect the integrity of the received data and abnormal data, determine whether there is an interception risk in the enterprise's network environment according to the integrity, make a secondary determination on whether there is an interception risk in the enterprise's network environment based on the recorded total traffic, or determine that the enterprise's network environment is suspected of having an interception risk and analyze the reasons. The results of the secondary determination include: Determine that there is no interception risk in the enterprise's network environment based on variance, there is network fluctuation, or determine that the enterprise's network environment is suspected of having an interception risk; Step S4: Make a secondary determination on the reasons suspected of having an interception risk according to the distribution of the abnormal data, adjust the corresponding parameters according to the analyzed reasons, and issue an alarm when it is determined that there is an interception risk. The adjustment process includes: Reduce the proportion of interference data for mixing processing based on the average traffic at each recorded time node. Increase the number of servers based on the number of bytes of the transmitted data; Step S5: Make a secondary determination on the reasons why the network environment is suspected of having an interception risk according to the distribution of the abnormal data, including: Determine that there is an interception risk, or determine that the system load is unqualified.

[0007] Further, the determination of whether there is an interception risk in the enterprise's network environment according to the integrity includes: Determine that there is no interception risk in the enterprise's network environment; Make a secondary determination on whether there is an interception risk in the enterprise's network environment based on the recorded total traffic, or analyze the reasons why the network environment is suspected of having an interception risk based on the integrity.

[0008] Further, the secondary determination on whether there is an interception risk in the enterprise's network environment based on the recorded total traffic includes: Calculate the variance of the total traffic at each recorded time node. Determine that there is no interception risk in the enterprise's network environment based on variance, there is network fluctuation. Or, determine that the enterprise's network environment is suspected of having an interception risk, and analyze the reasons why the network environment is suspected of having an interception risk based on the integrity.

[0009] Further, under the condition of determining that there is network fluctuation, reduce the proportion of interference data for mixing processing based on the average traffic at each recorded time node, where: The reduction amount of the proportion of interference data for mixing processing is negatively correlated with the average traffic.

[0010] Further, the reasons for the suspected interception risk in the network environment based on the integrity analysis include: Calculate the difference between the first preset integrity standard threshold and the integrity. Based on the difference, determine that the reason for the suspected interception risk in the network environment is that the system load is unqualified. Based on the difference, conduct a secondary determination on the reasons for the suspected interception risk in the network environment based on the distribution of abnormal data, or determine the existence of an interception risk.

[0011] Further, under the condition of determining that the system load is unqualified, increase the number of servers based on the number of bytes of the transmitted data, where The increase in the number of servers is positively correlated with the number of bytes of the transmitted data.

[0012] Further, the secondary determination of the reasons for the suspected interception risk in the network environment based on the distribution of abnormal data includes: Identify the received data. Determine the abnormal data in the data. Based on the distribution of the abnormal data, determine the existence of an interception risk, or determine that the system load is unqualified.

[0013] Further, under the condition of determining the existence of an interception risk, issue an alarm, and amplify the number of features of the information to be transmitted extracted before the subsequent data transmission, where The amplified features of the information to be transmitted are obtained from historical data.

[0014] Further, the amplification of the number of features of the information to be transmitted extracted before the subsequent data transmission includes: Determine the selection time interval of the historical data according to the number of features to be amplified, where The span of the time interval is positively correlated with the number of features to be amplified.

[0015] The present invention provides an enterprise risk assessment system based on big data. The system includes: A data acquisition module for extracting the features of the information to be transmitted. A preprocessing module connected to the data acquisition module for generating interference data based on the features extracted by the data acquisition module, splitting the information to be transmitted, and mixing the data and the interference data. A data transmission module connected to the preprocessing module for numbering and transmitting the mixed data. A monitoring module connected to the data transmission module for monitoring the total traffic at each time node during the data transmission process. A data receiving module, which is connected to the data transmission module and the monitoring module, is used to receive data, detect the integrity of the data, and detect abnormal data; A data analysis module, which is connected to the data acquisition module, the preprocessing module, the data transmission module, the monitoring module, and the data receiving module, is used to analyze whether there is an interception risk in the enterprise's network environment based on the integrity of the data, to make a secondary determination on whether there is an interception risk in the enterprise's network environment according to the total traffic monitored, to analyze the reasons for the suspected interception risk, to make a secondary determination on the reasons for the suspected interception risk in the network environment based on the distribution of abnormal data, to reduce the proportion of interference data used for mixed processing based on the average traffic at each recorded time node, to increase the number of servers based on the number of bytes of transmitted data, and to amplify the number of features of the information to be transmitted extracted before subsequent data transmission; An alarm module, which is connected to the data analysis module, is used to issue a data interception alarm.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows. In the present invention, interference data is generated based on the characteristics of the information to be transmitted, and the information to be transmitted is split. The split data is mixed with the interference data and then transmitted, so that the intercepted data contains interference data, improving the security of the data transmission process. Considering that when data interception occurs, the received data may have abnormal situations such as missing and duplication due to the operations of the interceptor, the present invention numbers the data before data transmission, and analyzes whether the data transmission process has suffered data interception according to the integrity of the received data, thereby improving the analysis accuracy of the data transmission process and the analysis accuracy of the enterprise's network environment. When it is determined that there is data interception, timely remedies are taken, thereby improving the security of data transmission.

[0017] Further, in the present invention, when the integrity of the received data is between the first preset integrity standard threshold and the second preset integrity standard threshold, considering that if there is data interception, the total traffic in the data transmission process will significantly increase during a certain period, so the dispersion of the total data volume at each time node in the data transmission process is used to make a secondary analysis on whether there is an interception risk in the network environment, thereby improving the analysis accuracy.

[0018] Furthermore, in the present invention, the variance analysis of the total traffic at each time node is used to determine whether there is an interception risk in the enterprise's network environment. When the variance is small, considering that during the peak network usage period, a large number of users access the Internet simultaneously, the network bandwidth of the ISP will become tense, and network data will also experience delays and fluctuations due to channel congestion during transmission, resulting in network fluctuations such as slow network speed and lags. Therefore, in the present invention, when the variance of the traffic is small, it is determined that there is network fluctuation, and when the variance is large, it is determined that there is an interception risk, and the reasons for the interception risk are further analyzed, thereby improving the control accuracy for the network transmission process.

[0019] Furthermore, in the present invention, considering that when the amount of data to be transmitted is large, network data will experience delays and fluctuations due to channel congestion during transmission. Therefore, when it is determined that there is network fluctuation, the amount of interfering data is reduced according to the average traffic at each time node, thereby reducing the total amount of data transmitted, and thus improving the data transmission efficiency while ensuring the security of the data transmission process.

[0020] Furthermore, in the present invention, considering that when the system load capacity is insufficient, it will lead to low data transmission efficiency. Therefore, when it is determined that the system load is unqualified, the number of servers is increased according to the number of bytes of the transmitted data, thereby improving the system load capacity and the data transmission efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 is the decision flow chart of the enterprise risk assessment method based on big data of the present invention; Figure 2 is the structural block diagram of the enterprise risk assessment system based on big data; Figure 3 is the decision flow chart for determining whether there is an interception risk in the enterprise's network environment; Figure 4 is the decision flow chart for re-determining whether there is an interception risk in the enterprise's network environment. DETAILED DESCRIPTION OF THE INVENTION

[0022] In order to make the objectives and advantages of the present invention more clear, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0023] It should be noted that the data in this embodiment are all obtained through comprehensive analysis and evaluation of the historical data of the previous six months before this determination by the system of the present invention and the corresponding historical determination results. Those skilled in the art can understand that the determination method of the system of the present invention for a single above-mentioned parameter can be to select the value with the highest proportion according to the data distribution as the preset standard parameter, use weighted summation to take the obtained value as the preset standard parameter, substitute each historical data into a specific formula and take the value obtained by using this formula as the preset standard parameter, or other selection methods, as long as it satisfies that the system of the present invention can clearly define different specific situations in the single determination process through the obtained values.

[0024] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.

[0025] It should be noted that in the description of the present invention, the terms indicating directions or positional relationships such as "upper", "lower", "left", "right", "inner", "outer", etc. are based on the directions or positional relationships shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention.

[0026] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0027] Please refer to Figure 1 as shown, which is the determination flowchart of the enterprise risk assessment method based on big data of the present invention.

[0028] The embodiment of the present invention provides an enterprise risk assessment method based on big data, including: Step S1, obtaining the characteristics of the information to be transmitted, generating interference data based on the characteristics, splitting the information to be transmitted to obtain several data, and performing a mixing process on the data and the interference data; Step S2, numbering each of the mixed data according to the conveying order, and after numbering, conveying them in sequence, and periodically detecting and recording the total flow at each time node during the data transmission process; Step S3: Receive the transmitted data, detect the integrity of the received data and abnormal data, determine whether there is an interception risk in the enterprise's network environment based on the integrity, and conduct a secondary determination on whether there is an interception risk in the enterprise's network environment according to the recorded total traffic, or, determine that the enterprise's network environment is suspected of having an interception risk and analyze the reasons. The results of the secondary determination include: Based on variance, it is determined that there is no interception risk in the enterprise's network environment, there is network fluctuation, or, it is determined that the enterprise's network environment is suspected of having an interception risk; Step S4: Conduct a secondary determination on the reasons suspected of having an interception risk according to the distribution of abnormal data, adjust the corresponding parameters according to the analyzed reasons, and issue an alarm when it is determined that there is an interception risk. The adjustment process includes: Based on the average traffic at each time node recorded, reduce the proportion of interference data used for mixing processing. Based on the number of bytes of the transmitted data, increase the number of servers. Step S5: Conduct a secondary determination on the reasons why the network environment is suspected of having an interception risk according to the distribution of abnormal data, including: Determine that there is an interception risk, or, determine that the system load is unqualified.

[0029] In the present invention, interference data is generated based on the characteristics of the information to be transmitted, the information to be transmitted is split, and the split data is mixed with the interference data for transmission, so that the intercepted data contains interference data, improving the security of the data transmission process. Considering that when data interception occurs, the received data may have abnormal situations such as missing and duplication due to the operations of the interceptor, the present invention numbers the data before data transmission, analyzes whether the data transmission process has suffered data interception according to the integrity of the received data, thereby improving the analysis accuracy for the data transmission process and the analysis accuracy for the enterprise's network environment. When it is determined that there is data interception, timely remedies are taken, thereby improving the security of data transmission.

[0030] Please refer to Figure 2 as shown, which is the structural block diagram of an enterprise risk assessment system based on big data.

[0031] An embodiment of the present invention provides an enterprise risk assessment system based on big data, including: A data acquisition module, which is used to extract the characteristics of the information to be transmitted; A preprocessing module, which is connected to the data acquisition module and is used to generate interference data based on the characteristics extracted by the data acquisition module, split the information to be transmitted, and mix the data and the interference data; A data transmission module, which is connected to the preprocessing module and is used to label each piece of data after mixing and transmit the data; A monitoring module, which is connected to the data transmission module and is used to monitor the total flow at each time node during the data transmission process; A data receiving module, which is connected to the data transmission module and the monitoring module and is used to receive data and detect the integrity and abnormal data of the data; A data analysis module, which is connected to the data acquisition module, the preprocessing module, the data transmission module, the monitoring module, and the data receiving module, and is used to analyze whether there is an interception risk in the enterprise's network environment based on the integrity of the data, to make a secondary determination of whether there is an interception risk in the enterprise's network environment according to the monitored total flow, to analyze the reasons for the suspected interception risk, to make a secondary determination of the reasons for the suspected interception risk in the network environment based on the distribution of abnormal data, to reduce the proportion of interference data for mixing processing based on the average flow at each recorded time node, to increase the number of servers based on the number of bytes of the transmitted data, and to amplify the number of features of the to-be-transmitted information extracted before the subsequent data transmission; An alarm module, which is connected to the data analysis module and is used to issue a data interception alarm.

[0032] Please refer to Figure 3 As shown, it is a determination flowchart for determining whether there is an interception risk in the enterprise's network environment.

[0033] Specifically, the determination of whether there is an interception risk in the enterprise's network environment according to the integrity includes: If the integrity is greater than or equal to the first preset integrity standard threshold, it is determined that there is no interception risk in the enterprise's network environment; If the integrity is less than the first preset integrity standard threshold and greater than or equal to the second preset integrity standard threshold, it is determined to make a secondary determination of whether there is an interception risk in the enterprise's network environment based on the recorded total flow; If the integrity is less than the second preset integrity standard threshold, it is determined that the enterprise's network environment is suspected of having an interception risk, and the reasons for the suspected interception risk in the network environment are analyzed based on the integrity.

[0034] Specifically, in this embodiment, the process of calculating the integrity is as follows: Determine the data that is the same between the received data and the transmitted data, record it as the same data, calculate the ratio of the amount of the same data to the amount of the transmitted data to obtain the integrity, where the same data satisfies that the data content and the sorting of the data are the same as the transmitted data.

[0035] Specifically, in this embodiment, the first preset integrity standard threshold is selected within the range of [0.85, 0.95], and the second preset integrity standard threshold is selected within the range of [0.7, 0.75].

[0036] In the present invention, when the integrity of the received data is between the first preset integrity standard threshold and the second preset integrity standard threshold, considering that if there is data interception, the total traffic during the data transmission process will significantly increase during a certain period of time, the dispersion of the total data volume at each time node during the data transmission process is used to perform a secondary analysis on whether there is an interception risk in the network environment, thereby improving the analysis accuracy.

[0037] Please refer to Figure 4 as shown, which is a determination flowchart for secondarily determining whether there is an interception risk in the enterprise's network environment.

[0038] Specifically, the secondary determination of whether there is an interception risk in the enterprise's network environment based on the recorded total traffic includes: Calculating the variance of the total traffic at each recorded time node, If the variance is less than or equal to the preset variance, it is determined that there is no interception risk in the enterprise's network environment and there is network fluctuation; If the variance is greater than the preset variance, it is determined that there is a suspected interception risk in the enterprise's network environment, and the reason for the suspected interception risk in the network environment is analyzed based on the integrity.

[0039] Specifically, in this embodiment, the preset variance is obtained by pre-measurement. The total traffic during the data transmission process in several secure environment conditions is obtained, the variances of the total traffic are calculated respectively, and the variance mean value is solved to obtain the preset variance.

[0040] In the present invention, whether there is an interception risk in the enterprise's network environment is analyzed based on the variance of the total traffic at each time node. When the variance is small, considering that during the peak network usage period, a large number of users access the Internet simultaneously, the network bandwidth of the ISP will be strained, and network data will also experience delays and fluctuations due to channel congestion during the transmission process, resulting in network fluctuations such as slower network speed and lags. Therefore, in the present invention, when the variance of the traffic is small, it is determined that there is network fluctuation, and when the variance is large, it is determined that there is an interception risk, and the reason for the interception risk is further analyzed, thereby improving the control accuracy for the network transmission process.

[0041] Specifically, under the condition of determining that there is network fluctuation, the proportion of interference data used for mixing processing is reduced based on the average traffic at each recorded time node, where: The reduction amount of the proportion of interference data used for mixing processing is negatively correlated with the average traffic.

[0042] In the present invention, considering that when the amount of data to be transmitted is large, network data may experience delays and fluctuations due to channel congestion during transmission. Therefore, when it is determined that there is network fluctuation, the amount of interfering data is reduced according to the average traffic at each time node, thereby reducing the total amount of data to be transmitted. Thus, while ensuring the security of the data transmission process, the data transmission efficiency is improved.

[0043] Specifically, the reasons for the suspected interception risk in the network environment based on the integrity analysis include: Calculate the difference between the first preset integrity standard threshold and the integrity. If the difference is less than or equal to the first preset difference, it is determined that the reason for the suspected interception risk in the network environment is that the system load is unqualified. If the difference is greater than the first preset difference and less than or equal to the second preset difference, it is determined to perform a secondary determination on the reasons for the suspected interception risk in the network environment based on the distribution of abnormal data. If the difference is greater than the second preset difference, it is determined that there is an interception risk.

[0044] Specifically, in this embodiment, the first preset difference is 0.1 to 0.15 times the first preset integrity standard threshold, and the second preset difference is 0.17 to 0.2 times the first preset integrity standard threshold.

[0045] Specifically, under the condition that it is determined that the system load is unqualified, the number of servers is increased based on the number of bytes of the transmitted data. Among them, The increase in the number of servers is positively correlated with the number of bytes of the transmitted data.

[0046] In this embodiment, optionally, Compare the number of bytes of the transmitted data with the first preset number of bytes and the second preset number of bytes. If the number of bytes of the transmitted data is less than or equal to the first preset number of bytes, increase the number of the first servers, and the number of the first servers is 0.1 times the initial number of servers. If the number of bytes of the transmitted data is greater than the first preset number of bytes and less than or equal to the second preset number of bytes, increase the number of the second servers, and the number of the second servers is 0.2 times the initial number of servers. If the number of bytes of the transmitted data is greater than the second preset number of bytes, increase the number of the third servers, and the number of the third servers is 0.3 times the initial number of servers. Among them, the number of bytes standard threshold is determined based on big data. The first preset number of bytes is 0.82 to 0.92 times the number of bytes standard threshold, and the second preset number of bytes is 0.98 to 1.08 times the number of bytes standard threshold.

[0047] In the present invention, considering that insufficient system load capacity may lead to low data transmission efficiency, when it is determined that the system load is unqualified, the number of servers is increased according to the number of bytes of the transmitted data, thereby improving the system load capacity and the data transmission efficiency.

[0048] Specifically, the secondary determination of the reason for the suspected interception risk in the network environment based on the distribution of abnormal data includes: Identifying the received data, Determining the abnormal data in the data, If the abnormal data is concentratedly distributed, it is determined that there is an interception risk; If the abnormal data is dispersedly distributed, it is determined that the system load is unqualified.

[0049] Specifically, under the condition that an interception risk is determined, an alarm is issued, and the number of features of the information to be transmitted extracted before the subsequent data transmission is amplified, where The amplified features of the information to be transmitted are obtained from historical data.

[0050] Specifically, the amplification of the number of features of the information to be transmitted extracted before the subsequent data transmission includes: Determining the selection time interval of historical data according to the number of features to be amplified, where The span of the time interval is positively correlated with the number of features to be amplified.

[0051] In this embodiment, optionally, Comparing the number of amplified features with a first preset number of features and a second preset number of features, If the number of amplified features is less than or equal to the first preset number of features, the first time interval is increased, and the first time interval is 0.05 times the initial time interval; If the number of amplified features is greater than the first preset number of features and less than or equal to the second preset number of features, the second time interval is increased, and the second time interval is 0.1 times the initial time interval; If the number of amplified features is greater than the second preset number of features, the third time interval is increased, and the third time interval is 0.15 times the initial time interval; Among them, the increased time interval is selected from the one adjacent to the original time interval and before the original time interval.

[0052] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, those skilled in the art can easily understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

[0053] The above are only the preferred embodiments of the present invention and are not used to limit the present invention; for those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent substitution, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for enterprise risk assessment based on big data, characterized in that: include: Step S1, obtaining characteristics of information to be transmitted, generating interference data based on the characteristics, splitting the information to be transmitted to obtain a plurality of data, and mixing the data and the interference data; Step S2, labeling each mixed data in the transmission order, and transmitting them in sequence after labeling, and periodically detecting and recording the total flow of each time node during the data transmission process; Step S3, receiving each transmitted data, detecting the integrity of the received data and abnormal data, determining whether the enterprise's network environment has an interception risk according to the integrity, making a secondary determination on whether the enterprise's network environment has an interception risk according to the recorded total traffic, or determining that the enterprise's network environment is suspected of having an interception risk and analyzing the cause, the result of the secondary determination includes: Based on the variance, it is determined that the enterprise's network environment does not have interception risks, there are network fluctuations, or it is determined that the enterprise's network environment is suspected of having interception risks; Step S4: secondly determine the reason for the suspected interception risk based on the distribution of abnormal data, adjust the corresponding parameters according to the analyzed reason, and issue an alarm when it is determined that there is an interception risk. The adjustment process includes: Based on the average flow recorded at each time node, the proportion of interference data used for mixed processing is reduced. Increase the number of servers based on the number of bytes of data transferred; Step S5, based on the distribution of abnormal data, a secondary determination is made on the cause of the suspected interception risk in the network environment, including: It is determined that there is a risk of interception, or that the system load is unqualified.

2. The enterprise risk assessment method based on big data according to claim 1 is characterized in that: The determination of whether the enterprise's network environment has interception risks based on integrity includes: Determine that there is no risk of interception in the enterprise's network environment; A secondary determination is made on whether there is an interception risk in the enterprise's network environment based on the total traffic recorded, or reasons why the network environment is suspected to be at risk of interception are analyzed based on completeness.

3. The enterprise risk assessment method based on big data according to claim 1 is characterized in that: The second determination of whether the enterprise's network environment has an interception risk based on the total traffic recorded includes: Calculate the variance of the total flow at each time node recorded, Based on the variance, it is determined that there is no interception risk in the enterprise's network environment, but there is network fluctuation. Or, determine that the enterprise's network environment is suspected of having an interception risk, and analyze the reasons why the network environment is suspected of having an interception risk based on the integrity.

4. The enterprise risk assessment method based on big data according to claim 3 is characterized in that: Under the condition that it is determined that there is network fluctuation, the proportion of interference data used for hybrid processing is reduced based on the average flow recorded at each time node, where: The reduction in the proportion of interference data used for hybrid processing is negatively correlated with the average flow rate.

5. The enterprise risk assessment method based on big data according to claim 2 is characterized in that: The reasons why the network environment is suspected to have an interception risk based on the integrity analysis include: Calculating the difference between a first preset integrity standard threshold and the integrity, Based on the difference, it is determined that the network environment is suspected of interception risk because the system load is unqualified; Based on the difference, a secondary determination is made on the reason why the network environment is suspected to have an interception risk based on the distribution of abnormal data, or it is determined that there is an interception risk.

6. The enterprise risk assessment method based on big data according to claim 5 is characterized in that: Under the condition that the system load is determined to be unqualified, the number of servers is increased based on the number of bytes of transmitted data, where: The increase in the number of servers is positively correlated with the number of bytes of transmitted data.

7. The enterprise risk assessment method based on big data according to claim 5 is characterized in that: The secondary determination of the reasons why the network environment is suspected of having interception risks based on the distribution of abnormal data includes: Identify the received data, Identify outliers in your data, Based on the distribution of abnormal data, it is determined that there is a risk of interception, or that the system load is unqualified.

8. The enterprise risk assessment method based on big data according to claim 1 is characterized in that: If there is a risk of interception, an alarm is issued and the number of features of the information to be transmitted extracted before subsequent data transmission is amplified, wherein: The features of the amplified information to be transmitted are obtained from historical data.

9. The enterprise risk assessment method based on big data according to claim 8 is characterized in that: The amplifying the number of features of the information to be transmitted extracted before the subsequent data transmission includes: The selection time interval of historical data is determined according to the number of features to be amplified, where: The span of the time interval is positively correlated with the number of features to be amplified.

10. An enterprise risk assessment system based on big data that implements the method described in any one of claims 1 to 9, characterized in that: include: A data acquisition module, which is used to extract features of information to be transmitted; A preprocessing module, connected to the data acquisition module, for generating interference data based on the features extracted by the data acquisition module, splitting the information to be transmitted, and mixing the data and the interference data; A data transmission module, connected to the preprocessing module, for labeling each mixed data and transmitting the data; A monitoring module, which is connected to the data transmission module and is used to monitor the total flow at each time node during the data transmission process; A data receiving module, connected to the data transmission module and the monitoring module, for receiving data and detecting data integrity and abnormal data; a data analysis module, which is connected to the data acquisition module, the preprocessing module, the data delivery module, the monitoring module and the data receiving module, and is used to analyze whether the enterprise's network environment has an interception risk based on the completeness of the data, to make a secondary determination on whether the enterprise's network environment has an interception risk based on the monitored total traffic, to analyze the cause of the suspected interception risk, to make a secondary determination on the cause of the suspected interception risk in the network environment based on the distribution of abnormal data, to reduce the proportion of interference data used for mixed processing based on the average traffic recorded at each time node, to increase the number of servers based on the number of bytes of transmitted data, and to amplify the number of features of the information to be transmitted extracted before subsequent data transmission; An alarm module is connected to the data analysis module and is used to issue a data interception alarm.

Citation Information

Patent Citations

  • Enterprise operation risk assessment method

    CN113887987A