Data processing method and device, electronic equipment and storage medium

By using the rule configuration interface in the risk control management system to generate target rule files and broadcast and update, the problem of recompilation of risk strategy indicator adjustment in the existing technology is solved, and the unaware launch of risk assessment rules and the improvement of risk control business timeliness is achieved.

CN120197955AActive Publication Date: 2025-06-24RAJAX NETWORK &TECHNOLOGY (SHANGHAI) CO LTD

Patent Information

Application Number
CN202510668242.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-06-24
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

In the existing risk control management system, adjustments or changes in risk strategy indicators need to be modified by modifying the source code and recompiling/deployment, resulting in the inability to achieve smooth online launch, affecting the processing timeliness of risk control services.

Method used

Enter configuration information through the rule configuration interface to generate target rule files, and update and save them to the rule file library through broadcast to achieve unsensible online launch of risk assessment rules and avoid risk control services stop or interruption.

Benefits of technology

The unaware launch of risk assessment rules has been achieved, the timeliness of risk control business processing has been improved, and the interruption of risk control business has been avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197955A_ABST
    Figure CN120197955A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method and device, electronic equipment and a storage medium. And selecting the target script file according to the type of the rule configuration parameter. The target script file is a universal script template file corresponding to the type. The rule configuration parameters are generated into the target rule file based on the format of the target script file, the rule instance existing in the script template file can be replaced, and the new computational logic and the rule configuration parameters in the target rule instance are compiled into the target script file in real time. And the target rule file is updated and stored in a rule file library in a broadcast mode, namely, the target rule file is loaded to the rule file library. The target rule file can be directly and dynamically compiled and loaded, so that the target rule file becomes a pluggable logic unit, the risk management system can realize non-perceptual online of the risk assessment rule without stopping running, and the processing timeliness of the risk control business can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and more particularly, to a method, apparatus, electronic device, and storage medium for processing data in the technical field of data processing. Background Art

[0002] In a risk control management system, various behavioral data of platform users are usually analyzed. Based on set risk strategy indicators, it is determined whether a platform user is at risk of participating in abnormal behaviors. For example, by analyzing data such as the device fingerprint, Internet protocol address, participation time / frequency, etc. of a user's participation in a marketing activity, based on target risk strategy indicators, the user's abnormal participation behaviors are identified, including repeatedly registering accounts through virtual numbers, batch redeeming coupons through multiple accounts on the same device, etc., to prevent the risk of platform subsidies being embezzled.

[0003] In existing risk control management systems, each risk strategy indicator is implemented based on hard coding, that is, the logic and parameters of all risk strategy indicators are written in the code. This means that the adjustment or change of each risk strategy indicator must be made effective in the risk control management system by modifying the source code and recompiling / deploying. This also results in the adjusted or changed risk strategy indicators being unable to be smoothly launched in the risk control management system, and it is necessary to stop the real-time risk control service currently running in the risk control management system or interrupt the business requests being processed, which will affect the timeliness of risk control business processing.

[0004] Therefore, there is an urgent need for a method for processing data to solve the above problems. Summary of the Invention

[0005] This application provides a method, apparatus, electronic device, and storage medium for processing data. This method generates a target rule file through configuration information input through a rule configuration interface, and updates and saves the target rule file to a rule file library through a broadcast method, enabling the seamless launch of risk assessment rules (including risk strategy indicators), avoiding the stop or interruption of risk control services, and improving the timeliness of processing risk control services.

[0006] In a first aspect, a method for processing data is provided. The method includes: obtaining configuration information input by a developer through a rule configuration interface, and parsing the configuration information to obtain relevant rule configuration parameters; selecting a target script file according to the type of the rule configuration parameters, and generating a target rule file based on the format of the target script file; updating and saving the target rule file to a rule file library through a broadcast method; obtaining behavioral data of multiple users, and analyzing the behavioral data based on multiple rule files in the rule file library to determine the user behavioral data with risks.

[0007] In the process of processing the above data, by parsing the configuration information input on the visual rule configuration interface, rule configuration parameters are obtained, and a target script file is selected according to the type of the rule configuration parameters. The target script file is a general script template file corresponding to the type. Based on the format of the target script file, the rule configuration parameters are generated into a target rule file, and the existing rule instances in the target script file can be replaced, and the new calculation logic and rule configuration parameters in the target rule instance are immediately compiled into the target script file. Further, the target rule file is updated and saved to the rule file library by means of broadcasting, that is, the target rule file is loaded into the rule file library. The ability of the above target rule file to be directly dynamically compiled and loaded makes the target rule file a "pluggable" logical unit, which enables the risk assessment rules (including risk strategy indicators) to be seamlessly launched when the risk control business being processed in the risk control management system does not stop or interrupt, which can improve the timeliness of processing the risk control business. In addition, through the broadcasting mechanism, the target rule file only needs to be transmitted to the rule file library once, and subsequent tasks can directly read the rule file from the rule file library, avoiding waste of network bandwidth.

[0008] Combined with the first aspect, in some implementation manners of the first aspect, selecting a target script file according to the type of the rule configuration parameters includes: comparing the type with multiple preset types, determining a target type matching the type from the multiple preset types, and each preset type in the multiple preset types corresponds to a general script template file; determining the script template file corresponding to the target type as the target script file.

[0009] In the process of processing the above data, the preset types are strongly associated with the script template files, which can ensure the consistency of the same type of calculation logic (i.e., rule calculation logic). For example, all matching class rules automatically inherit the general logic of field exact matching, which can reduce the writing and maintenance costs of duplicate code. Moreover, the above solution matches the type automatically recognized with the script template file, so that developers do not need to manually write or select the organization form of the script file, which can reduce the risks caused by manual misselection or code errors, and improve the configuration efficiency and accuracy. In addition, the general script template file supports adaptation to diverse business scenarios while ensuring a standardized execution process through parametric design. For example, a time window and an aggregation algorithm are configured in the script template file corresponding to the statistical class rules, and the threshold for similarity judgment can be flexibly adjusted in the script template file corresponding to the matching class rules. Therefore, the above technical solution can balance the normativity and business specificity of the rules, and coexist flexibility and reusability under the unified script template framework.

[0010] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, based on multiple rule files in the rule file library, the behavior data is analyzed to determine user behavior data with risks, including: determining multiple candidate files matching the behavior data from the multiple rule files; analyzing the behavior data through an operation state machine corresponding to each candidate file to determine user behavior data with risks, where the operation state machine encapsulates the calculation logic and rule configuration parameters of the candidate file.

[0011] In the process of processing the data as described above, multiple candidate files are matched from the rule file library through a dynamic rule screening mechanism, which can avoid traversing all rule files and greatly reduce calculation redundancy. Moreover, each operation state machine encapsulates the calculation logic and rule configuration parameters of the corresponding rule file, ensuring that the rules do not interfere with each other. At the same time, modifying a single rule file only requires replacing the corresponding operation state machine, without global downtime or reloading, ensuring the processing continuity of the risk control service. Through the hierarchical processing mechanism of the rule file and the operation state machine, the timeliness of risk assessment and the maintainability of the risk management system can be significantly improved.

[0012] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, determining multiple candidate files matching the behavior data from the multiple rule files includes: determining multiple behavior types corresponding to the behavior data; comparing each behavior type with the behavior types corresponding to each rule file in the multiple rule files, and determining candidate behavior types corresponding one-to-one to the multiple behavior types from the behavior types corresponding to the multiple rule files; determining the rule files corresponding to the multiple candidate behavior types as the multiple candidate files.

[0013] In the process of processing the data as described above, based on multiple behavior types corresponding to the behavior data of multiple users, candidate behavior types corresponding one-to-one to the multiple behavior types are screened out from the behavior types corresponding to multiple rule files. This pre-classification screening method can quickly narrow the rule matching range and greatly reduce calculation redundancy. Moreover, the strict one-to-one matching logic can ensure a high degree of association between multiple candidate rule files and the behavior data of multiple users (for example, only the consumption expenditure rule participates in the analysis of transaction behavior), reduce the interference of mis-matching, and improve the rule hit rate. Therefore, this technical solution can significantly optimize the efficiency and accuracy of rule screening through the precise matching mechanism of behavior types and rule files.

[0014] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, by means of the operation state machine corresponding to each candidate file, the behavior data is analyzed to determine the user behavior data with risks, including: by means of the operation state machine corresponding to each candidate file, the behavior data is analyzed to generate an intermediate result, and the intermediate result is stored in an external storage module, and the external storage module is an independently deployed remote dictionary server cluster; by means of the operation state machine corresponding to each candidate file, based on the intermediate result, the user behavior data with risks is determined.

[0015] In the process of the above data processing, the intermediate results of the operation state machines corresponding to each of the multiple candidate files are stored in the external storage module, which can reduce the memory pressure of the electronic device and the consumption of the storage resources of the electronic device when the intermediate results are persisted in the memory of the electronic device. Replacing the full-scale aggregation based on the memory of the electronic device with the incremental aggregation based on the remote dictionary server can also greatly reduce the consumption of the storage resources of the electronic device during program operation.

[0016] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, before the target rule file is updated and saved to the rule file library by means of the broadcast method, the method further includes: publishing the target rule file to the database middleware, so that the database middleware routes the target rule file to a second external storage module, and the second external storage module supports distributed management.

[0017] In the process of the above data processing, before the target rule file is updated and saved to the rule file library by means of the broadcast method, the target rule file is also published to the database middleware to back up the target rule file to the second external storage module. Among them, the database middleware serves as a temporary buffer, which can temporarily store the target rule file before broadcasting, so as to prevent the target rule file from being directly overwritten to the rule file library due to transmission errors or incomplete reception, resulting in the loss of the target rule file. The second external storage module serves as an independent backup, which is physically isolated from the rule file library to prevent the hardware storing the rule file library from failing and causing the complete loss of the target rule file. The above solution can, through double guarantees, restore the original target rule file in case of broadcast failure, and avoid the loss of the target rule file and entering an uncontrollable state.

[0018] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, the method further includes: when the first operation state machine corresponding to the first candidate file among the multiple candidate files successfully preempts the distributed lock and analyzes the behavior data through the first operation state machine, statistically analyzing the user behavior data with risks after the first moment through the first operation state machine to obtain a first statistical result, where the first moment is the moment when the first operation state machine successfully preempts the distributed lock; when the second moment for statistically analyzing the user behavior data with risks is the third moment, outputting the first statistical result through the first operation state machine, where the second moment is later than the first moment.

[0019] During the above process of processing data, when multiple operation state machines analyze the behavior data of multiple users, a distributed lock preemption mechanism is introduced, which can ensure that the behavior data of the same behavior type is only processed by a single operation state machine, avoid data competition caused by multi-node concurrent control, and guarantee the result consistency of the statistical process. After the first operation state machine successfully preempts the distributed lock, it will combine the analysis of behavior data according to the behavior type and the output of the statistical result based on the dynamic time window, which can also avoid the pressure on resources caused by frequent result output. That is to say, through the collaborative design of the distributed lock preemption mechanism and the time window disclosure mechanism, the above solution can optimize the resource utilization rate while ensuring the result accuracy, provide flexible and controllable technical support for real-time risk monitoring in high-concurrency scenarios, and effectively improve the efficiency and reliability of user behavior data analysis in a distributed environment.

[0020] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, the method for determining the third moment includes any one of the following: when the distributed lock is set with a first expiration period, determining the third moment based on the first moment and the first expiration period; when a first preset duration is set through a preset timer, determining the third moment based on the first moment and the first preset duration.

[0021] Combined with the first aspect and the above implementation manners, in some implementation manners of the first aspect, the method further includes: determining whether the duration between the first moment and the second moment is equal to a second preset duration set through a cyclic timer; when the duration is equal to the second preset duration and the duration is not equal to the second expiration period of the distributed lock, continuing to analyze the behavior data through the first operation state machine until the duration is equal to the second expiration period, and outputting the first statistical result through the first operation state machine, where the second expiration period is greater than the second preset duration.

[0022] During the above process of processing data, the loop timer triggers the operation state machine to analyze the behavior data of the first type of behavior at a preset interval periodically, ensuring that the data analysis process is continuously attempted within the second validity period (the validity period of the distributed lock). At the same time, the second validity period of the distributed lock provides a clear execution window for the analysis process. On the premise of ensuring the exclusivity of the task, the processing progress is forced to advance through time constraints. This can not only ensure the integrity of the user behavior data at risk, but also automatically release the distributed lock in case of timeout to trigger fault tolerance, thus effectively alleviating data delay or processing speed differences and enhancing the anti-backpressure ability of the risk management system in high-concurrency scenarios.

[0023] In a second aspect, there is provided an apparatus for processing data, the apparatus comprising: an acquisition unit, configured to acquire configuration information input by a developer in a rule configuration interface, and parse the configuration information to obtain relevant rule configuration parameters; a generation unit, configured to select a target script file according to the type of the rule configuration parameters, and generate a target rule file based on the format of the target script file; a storage unit, configured to update and save the target rule file to a rule file library by means of broadcasting; a processing unit, configured to acquire behavior data of multiple users, and analyze the behavior data based on multiple rule files in the rule file library to determine user behavior data at risk.

[0024] In combination with the second aspect, in some implementation manners of the second aspect, the generation unit is specifically configured to: compare the type with multiple preset types, and determine a target type matching the type from the multiple preset types, where each of the multiple preset types corresponds to a general script template file; and determine the script template file corresponding to the target type as the target script file.

[0025] In combination with the second aspect and the above implementation manners, in some implementation manners of the second aspect, the processing unit is specifically configured to: determine multiple candidate files matching the behavior data from the multiple rule files; and analyze the behavior data through the operation state machine corresponding to each candidate file to determine user behavior data at risk, where the operation state machine encapsulates the calculation logic and rule configuration parameters of the candidate file.

[0026] In combination with the second aspect and the above implementation manners, in some implementation manners of the second aspect, the apparatus further comprises: a determination unit, configured to: determine multiple types of behavior corresponding to the behavior data; compare each type of behavior with the type of behavior corresponding to each rule file in the multiple rule files, and determine candidate types of behavior corresponding one-to-one to the multiple types of behavior from the types of behavior corresponding to the multiple rule files; and determine the rule files corresponding to the multiple candidate types of behavior as the multiple candidate files.

[0027] Combined with the second aspect and the above implementation manners, in some implementation manners of the second aspect, the processing unit is further specifically configured to: analyze the behavior data through the operation state machine corresponding to each candidate file to generate an intermediate result, and store the intermediate result in an external storage module, where the external storage module is an independently deployed remote dictionary server cluster; determine, through the operation state machine corresponding to each candidate file and based on the intermediate result, the user behavior data with risks.

[0028] Combined with the second aspect and the above implementation manners, in some implementation manners of the second aspect, before updating and saving the target rule file to the rule file library in a broadcast manner, the apparatus further includes: a publishing unit, configured to publish the target rule file to a database middleware, so that the database middleware routes the target rule file to a second external storage module, and the second external storage module supports distributed management.

[0029] Combined with the second aspect and the above implementation manners, in some implementation manners of the second aspect, the processing unit is further configured to, when the first operation state machine corresponding to the first candidate file among the multiple candidate files successfully preempts a distributed lock and analyzes the behavior data through the first operation state machine, count the user behavior data with risks after a first moment through the first operation state machine to obtain a first statistical result, where the first moment is the moment when the first operation state machine successfully preempts the distributed lock; the apparatus further includes: an output unit, configured to output the first statistical result through the first operation state machine when a second moment for counting the user behavior data with risks is a third moment, and the second moment is later than the first moment.

[0030] Combined with the second aspect and the above implementation manners, in some implementation manners of the second aspect, the determining unit is further configured to: determine the third moment based on the first moment and the first expiration period when the distributed lock is set with the first expiration period; determine the third moment based on the first moment and the first preset duration when a first preset duration is set through a preset timer.

[0031] Combined with the second aspect and the above implementation manners, in some implementation manners of the second aspect, the determining unit is further configured to determine whether a duration between the first moment and the second moment is equal to a second preset duration set through a cyclic timer; the storage unit is further configured to, when the duration is equal to the second preset duration and the duration is not equal to a second expiration period of the distributed lock, continue to analyze the behavior data through the first operation state machine until the duration is equal to the second expiration period, and output the first statistical result through the first operation state machine, where the second expiration period is greater than the second preset duration.

[0032] In a third aspect, an electronic device is provided, including a memory and a processor. The memory is used to store executable program code, and the processor is used to call and run the executable program code from the memory, so that the electronic device executes the method in the above first aspect or any possible implementation manner of the first aspect.

[0033] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores executable program code, and when the executable program code runs on a computer, the computer executes the method in the above first aspect or any possible implementation manner of the first aspect. Description of the Drawings

[0034] Figure 1 is a schematic diagram of the functional architecture of a data processing system provided by an embodiment of the present application; Figure 2 is a schematic diagram of the structure of a data processing system provided by an embodiment of the present application; Figure 3 is a schematic flowchart of a data processing method provided by an embodiment of the present application; Figure 4 is an architecture design diagram of a rule dynamic perception module provided by an embodiment of the present application; Figure 5 is a schematic diagram of dividing original behavior data into multiple message queue data in a message queue format provided by an embodiment of the present application; Figure 6 is a schematic diagram of the structure of another data processing system provided by an embodiment of the present application; Figure 7 is an architecture design diagram of a risk analysis calculation module provided by an embodiment of the present application; Figure 8 is a schematic flowchart of another data processing method provided by an embodiment of the present application; Figure 9 is a schematic flowchart of another data processing method provided by an embodiment of the present application; Figure 10 is a schematic diagram of the structure of a data processing device provided by an embodiment of the present application; Figure 11 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed Embodiments

[0035] The technical solutions in the present application will be clearly and elaborately described below in conjunction with the accompanying drawings. Among them, in the description of the embodiments of the present application, unless otherwise specified, " / " means "or". For example, A / B may represent A or B. The "and / or" in the text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present application, "a plurality of" means two or more than two.

[0036] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.

[0037] Currently, the risk control management system usually analyzes various behavioral data of platform users and determines whether platform users are involved in abnormal behaviors based on the risk strategy indicators set by developers, that is, determines the user behavior data with risks.

[0038] In some embodiments, it is obtained that N platform users register accounts under the same Internet protocol address within the first time period. After registering the accounts, M platform users conduct transaction behaviors of the first amount under this Internet protocol address, where M is less than N and is a positive integer greater than 1. The risk assessment rule set by developers through risk strategy indicators is: when N is greater than 50, the first time period is one hour, M is greater than 40, and the first amount is greater than 1000, the account registration behaviors and transaction behaviors of M platform users belong to abnormal behaviors (that is, if there are more than 80% of platform users registering accounts under the same Internet protocol address within one hour and, after registering the accounts, conducting transactions greater than 1000 under this Internet protocol address, then the account registration behaviors and transaction behaviors participated by more than 80% of platform users belong to abnormal behaviors). Among them, for the above embodiments, the risk strategy indicators are the quantity indicator of participants, the address indicator of participation events, the duration indicator of multiple participants in the same event, and the consumption indicator corresponding to the participants.

[0039] In the existing risk control management system, each risk strategy indicator is implemented based on hard coding, and the logic and parameters of the risk strategy indicators are written in the code. This means that the adjustment or change of each risk strategy indicator must take effect in the risk control management system by modifying the source code and recompiling / deploying. This also results in that the adjusted or changed risk strategy indicators cannot be smoothly launched in the risk control management system, and it is necessary to stop the real-time risk control service currently running in the risk control management system or interrupt the business requests being processed, which will affect the processing timeliness of the risk control business.

[0040] Therefore, in view of the above problems, the present application provides a method for processing data, which can realize the seamless online of risk assessment rules (including risk strategy indicators), avoid the suspension or interruption of the risk control service, and improve the timeliness of processing the risk control service.

[0041] Next, the technical solutions in the embodiments of the present application will be described in detail with reference to the accompanying drawings in the embodiments of the present application.

[0042] A method for processing data provided by the present application depends on Figure 1 the functional architecture shown in the figure. Specifically, Figure 1 the functional architecture in the figure includes an application layer, a computing layer, and a storage layer. Among them, the application layer includes a rule configuration center, a data source management center, and a result notification center; the rule configuration center is used to add rules, publish rules, and update rules. The data source management center is used to add data sources and update data sources (data sources can be obtained or updated from multiple platforms), and the data sources therein are the behavior data of users. The result notification center is used for status monitoring, exception notification, and analysis and quantification. Specifically, it can be used to continue monitoring the behavior data of at least one user, send an exception notification when an exception occurs, and analyze the cause behind the exception. Among them, the computing layer includes a data preprocessing module, a rule dynamic perception module, a risk analysis and calculation module, and a perception result output module. The data preprocessing module is used to preprocess the behavior data of multiple users. The rule dynamic perception module is used to perceive the rules in the rule configuration center. The risk analysis and calculation module is used to perform risk analysis on the behavior data of users based on the rules. The perception result output module is used to process and output the behavior data of users with risks. Among them, the storage layer includes a TDDL (Taobao Distributed Data Layer) database middleware, a Redis cluster, a TT (Times Ten) database, and a HOLO database. Among them, the TDDL database middleware is used to route rules to an external storage module (such as MySQL). The Redis cluster is used to store the operation state machine corresponding to each rule, as well as the intermediate results after analyzing the behavior data of multiple users. The TT database can be used to store the statistical results of continuing to process the behavior data of users with risks, and the HOLO database is a lightweight database based on the MySQL protocol, which is used to store the generated results after processing the statistical results under further trigger conditions.

[0043] It should be noted that the original behavior data preprocessed by the above data preprocessing module comes from the data source management center.

[0044] In addition, it should also be noted that Figure 1The rule configuration center and the rule dynamic perception module in it are newly added modules based on the existing functional architecture. The rule configuration center is used to generate or update rule files and send the rule files to the TDDL database middleware. The rule dynamic perception module is used to perceive the rule files. The risk analysis and calculation module is used to process the behavior data of multiple users based on the rule files and generate statistical results of risks. The perception result output module is used to output risk results. The result notification center is used to monitor the risk status, send anomaly notifications when anomalies are detected, and perform anomaly analysis.

[0045] A method for processing data provided by this application depends on Figure 2 the system for processing data shown in. Specifically, the data processing system 200 includes a rule configuration center 201, a rule dynamic perception module 202, a data source management center 203, and a risk analysis and calculation module 204. The risk analysis and calculation module 204 is connected to the data source management center 203; The data source management center 203 is used to obtain the behavior data of multiple users and send the behavior data of the multiple users to the risk analysis and calculation module 204; The rule configuration center 201 is used to obtain the configuration information input by developers in the rule configuration interface, parse the configuration information to obtain relevant rule configuration parameters, select a target script file according to the type of the rule configuration parameters, generate a target rule file based on the format of the target script file, and publish the target rule file through a broadcast method; The rule dynamic perception module 202 is used to update and save the target rule file to the rule file library in the task manager therein when the target rule file is perceived; The risk analysis and calculation module 204 is used to obtain the behavior data of the multiple users and multiple rule files in the rule file library, and analyze the behavior data based on the multiple rule files to determine the user behavior data with risks.

[0046] Specifically, referring to Figure 3 , Figure 3 is a schematic flowchart of a method for processing data provided by an embodiment of this application. It should be understood that the method 300 can be applied to an electronic device with data processing capabilities, or a cloud server, etc. The embodiment of this application does not limit the device form of the execution subject. The method 300 includes the following steps: S301, obtain the configuration information input by developers in the rule configuration interface, and parse the configuration information to obtain relevant rule configuration parameters.

[0047] S302. Select a target script file according to the type of the rule configuration parameter, and generate a target rule file based on the format of the target script file.

[0048] That is, the specific steps for the rule configuration center 201 to execute correspond to the above steps 301 and 302.

[0049] It should be understood that the rule configuration interface in S301 refers to a visual operation interface for configuring a rule file, and the rule file includes the calculation logic and rule configuration parameters of at least one rule (i.e., the risk assessment rule in the foregoing embodiment) for analyzing whether there is a risk in the behavior data of platform users. The rule configuration interface may include a rule type input box, a rule name input box, a rule logic expression input box, a parameter type input box, a risk level input box, etc. Among them, the rule type input box is used to configure the rule type, such as the transaction type for risk assessment of transaction behavior data. The rule logic expression input box is used to configure the calculation logic corresponding to the rule, that is, presented through an expression. The parameter type input box is used to configure the type of the rule configuration parameter, and this type refers to the logical classification of the rule, and this type can be regarded as a policy type, and this type includes matching types and statistical types, etc. The matching type refers to the type based on similarity judgment, emphasizing precise matching, and its core lies in directly performing pattern matching or judgment on data through a predefined rule or keyword set, without complex analysis and calculation. The statistical type refers to the type based on probability analysis, and its core lies in making a judgment through a predefined data distribution law. The risk level input box is used to configure the risk level existing after the corresponding rule is satisfied.

[0050] It should also be understood that the configuration information in S301 refers to a data set input in the rule configuration interface, and this data set includes rule basic information and dynamic parameters, usually in the form of key-value pairs. Among them, the rule basic information corresponds to the content that should be configured indicated by the input box, and the dynamic parameter corresponds to the content in the input box. In some embodiments, the first rule basic information is the rule name, and the corresponding dynamic parameter is the consumption expenditure rule; the second rule basic information is the total consumption expenditure, and the corresponding dynamic parameter is 50000000; the third rule basic information is the consumption expenditure duration, and the corresponding dynamic parameter is 10 minutes; the fourth rule basic information is the parameter type, and the corresponding dynamic parameter is the matching type; the fifth rule basic information is the risk level, and the corresponding dynamic parameter is high risk. That is, in consumption expenditure, the behavior of a total consumption expenditure of 50000000 within 10 minutes is a high-risk behavior.

[0051] It should also be understood that the configuration information includes rule configuration parameters, and the rule configuration parameters only refer to the logical parameters of the risk assessment rules, that is, some dynamic parameters. For the above consumption expenditure rule, the logical parameters can be 50000000 and 10 minutes. Among them, the rule configuration parameters are the specific manifestations of the risk strategy indicators, and the rule conditions during risk assessment are quantified through dynamic parameters.

[0052] It should also be understood that the target script file in S302 is a general script template file that matches the type of the rule configuration parameters. Optionally, the script template file is a Groovy script file. The Groovy script file is a text file with the extension.groovy and contains executable code written in the Groovy scripting language. The Groovy scripting language is a dynamic programming language based on the JVM (Java Virtual Machine). The Groovy scripting language is often used for dynamic logic embedding, such as rule engines.

[0053] It should also be understood that the format of the target script file in S302 refers to the organization form of the file content of the target script file. The organization form of the file content involves how to layout the code modules to write the calculation logic of the risk assessment rules and which other libraries or tool classes to reference. Optionally, the tool class RiskUtils is referenced, and its RiskUtils class encapsulates the public methods related to risk assessment. Correspondingly, it can be understood that the calculation logic is implemented through the Groovy scripting language. Furthermore, based on the above target script file, a target rule file can be generated through the rule configuration parameters, indicating that the target script file is a dynamically configurable script template file.

[0054] In some embodiments, generating the target rule file based on the format of the target script file in S302 includes: replacing the corresponding parts in the target script file with the rule configuration parameters and the corresponding rule basic information based on the format of the target script file to generate the target rule file.

[0055] It should be understood that the operation logic of the target rule file is implemented through a dynamic scripting language.

[0056] In a possible implementation, selecting the target script file according to the type of the rule configuration parameters in S302 includes: comparing the type with multiple preset types, determining a target type that matches the type from the multiple preset types, and each preset type in the multiple preset types corresponds to a general script template file; determining the script template file corresponding to the target type as the target script file.

[0057] It should be understood that each preset type corresponds to a general script template file, and the formats of different script template files are different. In the script template file corresponding to the rule of the statistical preset type, it usually includes logics such as accumulation, summation, grouping, and deduplication. In the script template file corresponding to the rule of the matching preset type, it usually includes logics such as equality, similarity, and approximate equality.

[0058] In the above technical solution, the preset type is strongly associated with the script template file, which can ensure the consistency of the calculation logics (i.e., rule calculation logics) of the same preset type. For example, all rules of the matching type automatically inherit the general logic of field exact matching, which can reduce the writing and maintenance costs of duplicate codes. Moreover, the above solution matches through type automatic recognition and the script template file, enabling developers to not need to manually write or select the organization form of the script file, which can reduce the risks caused by manual misselection or code errors, and improve the configuration efficiency and accuracy. In addition, the general script template file supports the adaptation of diverse business scenarios while ensuring a standardized execution process through parametric design. For example, configure the time window and aggregation algorithm in the script template file corresponding to the rule of the statistical type, and the threshold for similarity judgment can be flexibly adjusted in the script template file corresponding to the rule of the matching type. Therefore, the above technical solution can balance the normativity and business specificity of the rules under the unified script template framework, with both flexibility and reusability.

[0059] S303, update and save the target rule file to the rule file library through the broadcast method.

[0060] That is to say, the specific steps for the rule dynamic perception module 202 to execute correspond to the above step 303.

[0061] It should also be understood that the broadcast method in S303 means that multiple data receiving nodes can all obtain the target rule file of the same data sending node. Its core lies in that there is no specified data receiving node, and all data receiving nodes connected to the same broadcast domain can obtain the target rule file. Understandably, the above broadcast method is suitable for scenarios that need to notify multiple data receiving nodes simultaneously and is suitable for processing emergency services (such as risk control services). The above task manager is a type of data receiving node, and the above rule configuration center is a type of data sending node.

[0062] It should also be understood that the Groovy script file can be directly compiled into JVM bytecode at runtime without being pre-compiled into a.class file. After generating the target rule file (i.e., after replacing the existing rule instances in the target script file to obtain the target rule instances), the risk management system updates and saves the target rule file to the rule file library through broadcasting. In other words, the risk management system can immediately load the new calculation logic and rule configuration parameters in the target rule instances. The ability of the above target rule file to be directly and dynamically compiled and loaded makes the target rule file a "pluggable" logical unit, which enables the risk management system to continue running without stopping, thus avoiding the suspension or interruption of the risk control services being processed in the risk control management system.

[0063] It should also be noted here that replacing the existing rule instances in the target script file is a way to externally inject the rule configuration parameters to replace the existing rule instances, which decouples the script logic of the target script file from the above-mentioned rule configuration parameters and makes the generation process of the target rule file more flexible.

[0064] Optionally, before S303, the method 300 further includes: storing the target rule file in an external storage module; encapsulating the attribute information of the target rule file into a broadcast variable, where the attribute information includes the file storage path, corresponding version number, and checksum of the target rule file; sending the broadcast variable to multiple data receiving nodes through broadcasting; and S303 includes: each data receiving node among the multiple data receiving nodes listens to the broadcast channel, receives the broadcast variable, and parses the broadcast variable to obtain the attribute information of the target rule file; downloads the target rule file from the external storage module based on the attribute information and verifies the target rule file, and updates and saves the target rule file to the rule file library when the target rule file is complete.

[0065] It should be understood that the above version number is used to identify different versions of the rule file under the same rule name. The above checksum is used to verify the integrity of the target rule file.

[0066] It should also be understood that the above broadcast channel refers to the broadcast channel between the above data sending node and multiple data receiving nodes. The above data sending node and multiple data receiving nodes within the same local area network belong to the same broadcast domain.

[0067] Specifically, as Figure 4As shown, it is an architecture design diagram of a rule dynamic perception module provided by an embodiment of the present application. Exemplarily, the rule dynamic perception module 202 is used to perceive the target rule file through the Flink CDC (Change Data Capture) component. When the Flink CDC component perceives the target rule file, the target rule file is updated and saved to the rule file library in each task manager therein.

[0068] Optionally, the target rule file is updated and saved to the rule file library in the form of key-value pairs, where the key is the identifier of the target rule file and the value is the target rule file.

[0069] Optionally, the identifier is the behavior type corresponding to the target rule file.

[0070] S304. Obtain the behavior data of multiple users, and based on the multiple rule files in the rule file library, analyze the behavior data to determine the user behavior data with risks.

[0071] That is, the specific steps for the data source management center 203 to execute correspond to obtaining the behavior data of multiple users in step 304 above.

[0072] That is, the specific steps for the risk analysis and calculation module 204 to execute correspond to step 304 above.

[0073] It should be understood that the behavior data in S304 is used to describe the behaviors of multiple users.

[0074] In some embodiments, the behavior data may be data of a user accessing a device, transaction data of the user, data of the user sharing information, etc. Optionally, the data of the user accessing the device includes the record of the user opening or closing the door lock within the first time period, the number of times the user enters the password incorrectly within the second time period, and the number of times the user increases the air conditioner temperature within the third time period. The data of the user sharing information includes the user sharing the device control permission to the first account and the user deleting the first information through a temporary visitor account.

[0075] In a possible implementation manner, analyzing the behavior data based on the multiple rule files in the rule file library in S304 to determine the user behavior data with risks includes: determining multiple candidate files matching the behavior data from the multiple rule files; analyzing the behavior data through the operation state machine corresponding to each candidate file to determine the user behavior data with risks, and the operation state machine encapsulates the calculation logic and rule configuration parameters of the candidate file.

[0076] It should be understood that the above operation state machine refers to a data processing model encapsulating the calculation logic of a rule file and rule configuration parameters. The core function of this operation state machine is to dynamically apply the rule file based on the input data (behavior data of multiple users in this application) and output a risk determination result (user behavior data with risks in this application). The rule configuration parameters are injected into the operation state machine in the form of key-value pairs for the calculation logic to dynamically reference. Among them, the key refers to the rule basic information corresponding to the rule configuration parameter, and the value refers to the rule configuration parameter.

[0077] It should also be understood that the above multiple candidate files may or may not include the target rule file. Each candidate file corresponds to an operation state machine. In this way, each operation state machine can encapsulate the calculation logic of the corresponding rule file and rule configuration parameters. That is to say, each rule file has a corresponding operation state machine, and each operation state machine encapsulates its own calculation logic and is also responsible for maintaining its own rule configuration parameters. Therefore, each operation state machine can be regarded as a highly cohesive operation state machine.

[0078] It should be noted here that the above encapsulation means integrating the calculation logic of the rule file and the rule configuration parameters into an independent and reusable execution unit, while hiding the internal implementation details externally and only exposing standardized input and output interfaces. The core of encapsulation lies in realizing the decoupling of the calculation logic and the rule configuration parameters.

[0079] It should also be noted here that for the newly added target rule file in the rule file library, the calculation logic and rule configuration parameters of the target rule file can be encapsulated to obtain the operation state machine corresponding to the target rule file, and the calculation logic corresponding to the operation state machine is dynamic. In this way, for evaluating the behavior data of any first behavior type, by adding the first rule file corresponding to the first behavior type and then encapsulating the calculation logic and rule configuration parameters of the first rule file, the operation state machine corresponding to the first rule file can be obtained, and then the behavior data of the first behavior type can be analyzed through the operation state machine corresponding to the first rule file. Therefore, in the process of each operation state machine among multiple operation state machines processing the behavior data of the corresponding behavior type through the corresponding rule file, the multiple operation state machines do not affect each other. Therefore, the multiple operation state machines are loosely coupled.

[0080] In the above technical solution, through a dynamic rule screening mechanism, multiple candidate files are matched from the rule file library, which can avoid traversing all rule files and greatly reduce computational redundancy. Moreover, each operation state machine encapsulates the calculation logic and rule configuration parameters corresponding to the rule file, ensuring that the rules do not interfere with each other. At the same time, modifying a single rule file only requires replacing the corresponding operation state machine, without global downtime or reloading, guaranteeing the processing continuity of the risk control business. Through the hierarchical processing mechanism of the rule file and the operation state machine, the timeliness of risk assessment and the maintainability of the risk management system can be significantly improved.

[0081] In a possible implementation, determining multiple candidate files that match the behavior data from the multiple rule files includes: determining multiple behavior types corresponding to the behavior data; comparing each behavior type with the behavior types corresponding to each rule file in the multiple rule files, and determining candidate behavior types corresponding one-to-one to the multiple behavior types from the behavior types corresponding to the multiple rule files; and determining the rule files corresponding to the multiple candidate behavior types as the multiple candidate files.

[0082] It should be understood that the behavior types corresponding to the above rule files refer to the types of user behaviors targeted by the rule files, including behavior types of accessing devices, transaction types, information sharing types, etc.

[0083] In the above technical solution, based on multiple behavior types corresponding to the behavior data of multiple users, candidate behavior types corresponding one-to-one to the multiple behavior types are screened out from the behavior types corresponding to the multiple rule files. This pre-classification screening method can quickly narrow the rule matching range and greatly reduce computational redundancy. Moreover, the strict one-to-one matching logic can ensure a high correlation between multiple candidate rule files and the behavior data of multiple users (for example, only the consumption expenditure rule participates in the analysis of transaction behaviors), reduce the interference of mis-matching, and improve the rule hit rate. Therefore, this technical solution can significantly optimize the efficiency and accuracy of rule screening through the precise matching mechanism of behavior types and rule files.

[0084] Optionally, determining multiple behavior types corresponding to the behavior data includes: extracting the behavior characteristics of the behavior data; comparing the behavior characteristics with the sample behavior characteristics of the behavior types corresponding to the multiple rule files, and determining candidate behavior characteristics that match the behavior characteristics from the multiple sample behavior characteristics; and determining the behavior types corresponding to the candidate behavior characteristics as the multiple behavior types.

[0085] Optionally, the method for determining the behavior data of multiple users in S304 includes: based on multiple types of behavior corresponding to the original behavior data of multiple users, dividing the original behavior data into multiple message queue data in the message queue format, and determining the multiple message queue data as the behavior data, where each message queue data corresponds to one type of behavior, and the original behavior data is unprocessed behavior data.

[0086] Optionally, each message queue data includes the occurrence time of the behavior, the type of behavior, and the content of the behavior.

[0087] It should be understood that the process of dividing the original behavior data of multiple users into multiple message queue data in the message queue format can be regarded as a process of preprocessing the original behavior data.

[0088] Figure 5 It is a schematic diagram provided by an embodiment of the present application for dividing the original behavior data into multiple message queue data in the message queue format.

[0089] Exemplarily, as Figure 5 shown, the original behavior data of multiple users corresponds to multiple types of behavior, and the original behavior data is divided into multiple message queue data in the message queue format according to the type of behavior. That is, the multiple message queue data includes the behavior data of the first type of behavior, the behavior data of the second type of behavior, etc., where the behavior data of each type of behavior includes the type of behavior, the occurrence time of the behavior, and the specific content of the behavior.

[0090] In a possible implementation manner, through the operation state machine corresponding to each candidate file, the behavior data is analyzed to determine the user behavior data with risks, including: through the operation state machine corresponding to each candidate file, the behavior data is analyzed to generate an intermediate result, and the intermediate result is stored in an external storage module, and the external storage module is an independently deployed remote dictionary server cluster; through the operation state machine corresponding to each candidate file, based on the intermediate result, the user behavior data with risks is determined.

[0091] It should be understood that the above-mentioned remote dictionary server cluster is a Redis cluster, and the Redis cluster includes multiple Redis servers, and the Redis server is a high-performance database based on memory.

[0092] In the above technical solution, the intermediate results of the operation state machines corresponding to each candidate file among multiple candidate files are stored in an external storage module, which can relieve the memory pressure of the electronic device and reduce the consumption of the storage resources of the electronic device when the intermediate results are persisted in the memory of the electronic device. Replacing the full-volume aggregation based on the memory of the electronic device with the incremental aggregation based on the Redis server can also significantly reduce the consumption of the storage resources of the electronic device during program operation.

[0093] Exemplarily, for the account login behaviors of multiple users for a target application, the intermediate result is the number of consecutive login failures of each user within 5 minutes. If the number is greater than or equal to 3, it is determined that there is a risk in the login behavior of this user.

[0094] In a possible implementation manner, before updating and saving the target rule file to the rule file library by means of broadcasting, the method 300 further includes: publishing the target rule file to a database middleware, so that the database middleware routes the target rule file to a second external storage module, and the second external storage module supports distributed management.

[0095] In the above technical solution, before updating and saving the target rule file to the rule file library by means of broadcasting, the target rule file is also published to the database middleware to back up the target rule file to the second external storage module. Among them, the database middleware serves as a temporary buffer and can temporarily store the target rule file before broadcasting, so as to prevent the target rule file from being directly overwritten in the rule file library due to transmission errors or incomplete reception, resulting in the loss of the target rule file. The second external storage module serves as an independent backup and is physically isolated from the rule file library to prevent the hardware storing the rule file library from failing and causing the complete loss of the target rule file. Through the above double guarantee, the original target rule file can be restored in case of broadcast failure, avoiding the loss of the target rule file and entering an uncontrollable state.

[0096] Another exemplarily, as Figure 6 shown, the system 200 for processing data further includes a TDDL database middleware, a FlinkCDC component, a Source Connector component, a first external storage module, and a result analysis module. The rule dynamic perception module 202 includes the Flink CDC component. The risk analysis and calculation module 204 is connected to the data source management center 203 through the Source Connector component. The first external storage module is connected to the risk analysis and calculation module 204. The SinkConnector component is connected to the first external storage module through the window trigger.

[0097] Among them, the target rule file is published to the TDDL database middleware, so that the TDDL database middleware routes the target rule file to the second external storage module; the Flink CDC component is used to sense the target rule file; the Source Connector component is used to extract the behavior data of multiple users from the data source management center 203 and publish it to the risk analysis and calculation module 204 in the form of an event stream; the first external storage module is used to store the intermediate results obtained after multiple operation state machines analyze the behavior data of multiple users; the result analysis module is used to call the final result output by the risk analysis and calculation module 204 and analyze it.

[0098] Optionally, the system 200 for processing data further includes a window trigger and a Sink Connector component. The window trigger is used to read the intermediate results under a certain trigger condition and perform further calculations on the intermediate results to obtain calculation results; the Sink Connector component stores the calculation results in other external storage systems.

[0099] In addition, the rule dynamic sensing module 202 and the risk analysis and calculation module 204 can be designed based on a distributed stream processing framework. Optionally, the distributed stream processing framework is the Apache Flink framework. However, the source code (native Flink code) of the Apache Flink framework is not used in the embodiments of the present application. Instead, a target rule file is generated through a target script file.

[0100] Specifically, as Figure 7 shown, it is an architecture design diagram of a risk analysis and calculation module provided by an embodiment of the present application. Exemplarily, the risk analysis and calculation module 204 is specifically used to: determine multiple behavior types corresponding to the behavior data of multiple users; compare each behavior type with the behavior types corresponding to each rule file among multiple rule files, and determine candidate behavior types corresponding one-to-one to the multiple behavior types from the behavior types corresponding to the multiple rule files; determine the rule files corresponding to the multiple candidate behavior types as multiple candidate files; analyze the behavior data of multiple users through the operation state machine corresponding to each candidate file, and determine the user behavior data with risks. Among them, the intermediate results obtained after the operation state machine analyzes the behavior data of multiple users are stored in the first external storage module.

[0101] It should be understood that after multiple operation state machines analyze the behavior data of multiple users, there is a need to merge the risk results output by multiple operation state machines or update shared resources. For example, multiple operation state machines need to update the cumulative risk score of the same user, or count global risk indicators, etc. Therefore, the embodiments of the present application introduce concurrent control of multiple operation state machines. Figure 8It is a schematic flowchart of another method for processing data provided by an embodiment of the present application. Specifically, the method 800 includes: S801, obtain the behavior data of multiple users, and determine multiple candidate files that match the behavior data from multiple rule files in the rule file library.

[0102] S802, when the first operation state machine corresponding to the first candidate file among the multiple candidate files successfully preempts the distributed lock and analyzes the behavior data through the first operation state machine, statistically analyze the user behavior data with risks after the first moment through the first operation state machine to obtain a first statistical result, where the first moment is the moment when the first operation state machine successfully preempts the distributed lock; It should be understood that during the process of analyzing the behavior data of the multiple users through the first operation state machine, the user behavior data with risks will be determined from the behavior data of the multiple users.

[0103] It should also be understood that the first operation state machine in S802 corresponds to the first candidate file, and each rule file corresponds to a behavior type. Therefore, the first operation state machine can be regarded as an operation state machine for analyzing the behavior data of the first type of behavior in the behavior data and statistically analyzing the user behavior data with risks in the analysis. Among them, the behavior type corresponding to the first candidate file is the first type of behavior.

[0104] It should also be understood that the distributed lock in S802 is used for the operation state machine to preempt shared resources. When the first operation state machine successfully preempts the distributed lock, other operation state machines cannot perform merging processing on the risk results and cannot update the shared resources. That is, the present application ensures that only one operation state machine can modify the merged risk results or update the shared resources within the same time period through the forced serialization of the distributed lock preemption mechanism, which can ensure the mutual exclusion and result consistency in the concurrent scenario.

[0105] S803, when the second moment for statistically analyzing the user behavior data with risks is the third moment, output the first statistical result through the first operation state machine, where the second moment is later than the first moment.

[0106] It should be noted that the above solution describes that when the first operation state machine successfully preempts the distributed lock, the first operation state machine analyzes the behavior data of the first type of behavior in the behavior data to obtain the first type of user behavior data with risks. During the process of the first operation state machine analyzing the behavior data of the first type of behavior, the first operation state machine statistically analyzes the first user behavior data with risks after the first moment to obtain a first statistical result and outputs it. Among them, the end moment of the statistics is the above-mentioned third moment.

[0107] In addition, it should be noted that in the above embodiments, between the first moment and the second moment, the first operation state machine can complete the analysis of the behavior data of multiple users.

[0108] In the above technical solution, during the process of multiple operation state machines analyzing the behavior data of multiple users, a distributed lock preemption mechanism is introduced, which can ensure that the behavior data of the same behavior type is only processed by a single operation state machine, avoid data competition caused by multi-node concurrent control, and guarantee the result consistency of the statistical process. After the first operation state machine successfully preempts the distributed lock, it will combine the analysis of the behavior data according to the behavior type and the output of the statistical result based on the dynamic time window, which can also avoid the pressure on resources caused by frequent result output. That is to say, through the collaborative design of the distributed lock preemption mechanism and the time window disclosure mechanism, the above solution can optimize the resource utilization rate while ensuring the result accuracy, provide flexible and controllable technical support for real-time risk monitoring in high-concurrency scenarios, and effectively improve the efficiency and reliability of user behavior data analysis in a distributed environment.

[0109] Exemplarily, in the case where the first operation state machine successfully preempts the distributed lock, the first operation state machine analyzes the behavior data of the first type of behavior in the behavior data to obtain the number of users of the first type of behavior with risks. During the process of the first operation state machine analyzing the behavior data of the first type of behavior, the first operation state machine accumulates the number of users of the first type of behavior with risks after the first moment, obtains the accumulated number of users and outputs it until the end of the third moment.

[0110] In a possible implementation manner, the method for determining the third moment includes any one of the following: in the case where the distributed lock is set with a first expiration period, determining the third moment based on the first moment and the first expiration period; in the case where a first preset duration is set through a preset timer, determining the third moment based on the first moment and the first preset duration.

[0111] It should be understood that the above third moment is the moment after the first moment after passing the first expiration period or the moment after passing the first preset duration preset by the preset timer.

[0112] It should also be understood that the time period between the first moment and the third moment is the time period for outputting the first statistical result. In this regard, the above solution can be regarded as a process of window result disclosure based on the behavior time.

[0113] Optionally, determining the third moment based on the first moment and the first expiration period includes: determining the moment corresponding to the first expiration period after the first moment as the third moment; and determining the third moment based on the first moment and the first preset duration includes: determining the moment corresponding to the first preset duration after the first moment as the third moment.

[0114] It should be noted that the first operation state machine analyzes the behavior data of the first type of behavior in the behavior data and statistically analyzes the user behavior data of the first type of behavior with risks at the same time. In some cases, the processing speed of analyzing the behavior data of the first type of behavior is slower than the processing speed of statistically analyzing the user behavior data of the first type of behavior with risks. That is, there is a situation where the first preset duration set by the preset timer has reached, but the analysis of the behavior data of the first type of behavior in the behavior data has not been completed. If the first statistical result is directly output at this time, it will cause the loss of some user behavior data with risks obtained at the same time. Therefore, the following embodiments introduce the second expiration period of the loop timer and the distributed lock at the same time to solve the above problems. For details, see Figure 9 The schematic flowchart of another method for processing data provided. Specifically, the method 900 includes: S901, obtaining the behavior data of multiple users and determining multiple candidate files that match the behavior data from multiple rule files in the rule file library.

[0115] S902, when the first operation state machine corresponding to the first candidate file among the multiple candidate files successfully preempts the distributed lock and analyzes the behavior data through the first operation state machine, statistically analyzes the user behavior data with risks after the first moment through the first operation state machine to obtain a first statistical result, where the first moment is the moment when the first operation state machine successfully preempts the distributed lock.

[0116] S903, determining whether the duration between the first moment and the second moment for statistically analyzing the user behavior data with risks is equal to the second preset duration set by the loop timer.

[0117] S904, when the duration is equal to the second preset duration and the duration is not equal to the second expiration period of the distributed lock, continue to analyze the behavior data through the first operation state machine until the duration is equal to the second expiration period, and output the first statistical result through the first operation state machine. The second expiration period is greater than the second preset duration.

[0118] It should be understood that the above solution enables the behavior data of the first type of behavior to be analyzed by waiting in a loop within the second validity period for the first operation state machine to analyze the behavior data of the first type of behavior within the second preset duration.

[0119] In addition, it should be noted that in the first second preset duration described in the above embodiment, the first operation state machine did not finish analyzing the behavior data of multiple users.

[0120] In the above technical solution, the loop timer periodically triggers the operation state machine to analyze the behavior data of the first type of behavior at a preset interval, ensuring that the data analysis process is continuously attempted to be completed within the second validity period (the validity period of the distributed lock). At the same time, the second validity period of the distributed lock provides a clear execution window for the analysis process. Under the premise of ensuring the exclusivity of the task, the processing progress is forced to advance through time constraints. This can not only ensure the integrity of the user behavior data at risk but also automatically release the distributed lock in case of timeout to trigger fault tolerance, thereby effectively alleviating data latency or processing speed differences and enhancing the anti-backpressure ability of the risk management system in high-concurrency scenarios.

[0121] Figure 10 It is a schematic structural diagram of a device for processing data provided by an embodiment of the present application. The device 1000 includes an acquisition unit 1001, a generation unit 1002, a storage unit 1003, and a processing unit 1004.

[0122] The acquisition unit 1001 is configured to acquire the configuration information input by the developer in the rule configuration interface and parse the configuration information to obtain relevant rule configuration parameters; The generation unit 1002 is configured to select a target script file according to the type of the rule configuration parameters and generate a target rule file based on the format of the target script file; The storage unit 1003 is configured to update and save the target rule file to the rule file library by means of broadcasting; The processing unit 1004 is configured to acquire the behavior data of multiple users and analyze the behavior data based on multiple rule files in the rule file library to determine the user behavior data at risk.

[0123] In a possible implementation manner, the generation unit 1002 is specifically configured to: compare the type with multiple preset types, determine a target type matching the type from the multiple preset types, and each preset type in the multiple preset types corresponds to a general script template file; and determine the script template file corresponding to the target type as the target script file.

[0124] In a possible implementation, the processing unit 1004 is specifically configured to: determine multiple candidate files that match the behavior data from the multiple rule files; analyze the behavior data through the operation state machine corresponding to each candidate file to determine the user behavior data with risks, and the operation state machine encapsulates the calculation logic and rule configuration parameters of the candidate file.

[0125] In a possible implementation, the apparatus 1000 further includes: a determination unit configured to: determine multiple behavior types corresponding to the behavior data; compare each behavior type with the behavior types corresponding to each rule file in the multiple rule files, and determine candidate behavior types corresponding one-to-one to the multiple behavior types from the behavior types corresponding to the multiple rule files; and determine the rule files corresponding to the multiple candidate behavior types as the multiple candidate files.

[0126] In a possible implementation, the processing unit 1004 is further specifically configured to: analyze the behavior data through the operation state machine corresponding to each candidate file to generate an intermediate result, and store the intermediate result in an external storage module, where the external storage module is an independently deployed remote dictionary server cluster; and analyze the intermediate result through the operation state machine corresponding to each candidate file to determine the user behavior data with risks.

[0127] In a possible implementation, the storage unit 1003 is further configured to store the rule file library in the external storage module.

[0128] In a possible implementation, the processing unit 1004 is further configured to, when the first operation state machine corresponding to the first candidate file in the multiple candidate files successfully preempts a distributed lock and analyzes the behavior data through the first operation state machine, count the user behavior data with risks after a first moment through the first operation state machine to obtain a first statistical result, where the first moment is the moment when the first operation state machine successfully preempts the distributed lock; the apparatus 1000 further includes: an output unit configured to, when a second moment for counting the user behavior data with risks is a third moment, output the first statistical result through the first operation state machine, where the second moment is later than the first moment.

[0129] In a possible implementation, the determination unit is further configured to: when the distributed lock is set with a first expiration period, determine the third moment based on the first moment and the first expiration period; and when a first preset duration is set through a preset timer, determine the third moment based on the first moment and the first preset duration.

[0130] In a possible implementation, the determining unit is further configured to determine whether the duration between the first moment and the second moment is equal to a second preset duration set by a cyclic timer; the storage unit 1003 is further configured to, when the duration is equal to the second preset duration and the duration is not equal to the second validity period of the distributed lock, continue to analyze the behavior data through the first operation state machine until the duration is equal to the second validity period, and output the first statistical result through the first operation state machine, where the second validity period is greater than the second preset duration.

[0131] Figure 11 FIG. 4 is a schematic structural diagram of an electronic device provided in an embodiment of the present application. Optionally, the electronic device 1100 may be a device with computing functions or a server, and the embodiment of the present application does not make any limitations in this regard.

[0132] Exemplarily, as Figure 11 shown, the electronic device 1100 includes: a memory 1101 and a processor 1102. Among them, an executable program code 1103 is stored in the memory 1101, and the processor 1102 is configured to call and execute the executable program code 1103 to execute a method for processing data.

[0133] In addition, an embodiment of the present application also protects a device, which may include a memory and a processor. Among them, an executable program code is stored in the memory, and the processor is configured to call and execute the executable program code to execute a method for processing data provided in an embodiment of the present application.

[0134] In this embodiment, the device may be divided into functional modules according to the above method examples. For example, it may correspond to each functional module, or two or more functions may be integrated into one processing unit. The above integrated modules may be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there may be other division methods in actual implementation.

[0135] In the case of dividing each functional module according to each corresponding function, the device may further include an acquisition unit, a generation unit, a storage unit, a processing unit, a determination unit, an output unit, etc. It should be noted that all relevant content involved in the above method embodiments can be cited in the function descriptions of the corresponding functional modules, and will not be repeated here.

[0136] It should be understood that the device provided in this embodiment is used to execute the above method for processing data, so the same effects as the above implementation method can be achieved.

[0137] In the case of adopting an integrated unit, the device may include a processing unit and a storage module. Among them, when the device is applied to an electronic device, the processing unit can be used to control and manage the actions of the electronic device. The storage module can be used to support the electronic device to execute relevant executable program codes and the like.

[0138] Among them, the processing unit can be a processor or a controller, which can implement or execute various exemplary logic blocks, modules, and circuits shown in combination with the disclosure of this application. The processor can also be a combination that realizes computing functions, such as including a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc. The storage module can be a memory.

[0139] In addition, the device provided in the embodiments of this application can specifically be a chip, a component, or a module. The chip can include a processor and a memory connected thereto; among them, the memory is used to store instructions. When the processor calls and executes the instructions, the chip can execute a method for processing data provided in the above embodiments.

[0140] This embodiment also provides a computer-readable storage medium. An executable program code is stored in the computer-readable storage medium. When the executable program code runs on a computer, the computer is caused to execute the above-related method steps to implement a method for processing data provided in the above embodiments.

[0141] This embodiment also provides a computer program product. When the computer program product runs on a computer, the computer is caused to execute the above-related steps to implement a method for processing data provided in the above embodiments.

[0142] Among them, the device, the computer-readable storage medium, the computer program product, or the chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here.

[0143] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and conciseness of description, only the above division of each functional module is used as an example for illustration. In practical applications, the above functions can be allocated to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0144] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.

[0145] The above content is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A method for processing data, characterized in that, The method includes: Obtain the configuration information input by the developer in the rule configuration interface, and parse the configuration information to obtain relevant rule configuration parameters; Select a target script file according to the type of the rule configuration parameters, and generate a target rule file based on the format of the target script file; Update and save the target rule file to the rule file library by broadcasting; Obtain the behavior data of multiple users, and analyze the behavior data based on multiple rule files in the rule file library to determine the user behavior data with risks.

2. The method according to claim 1, characterized in that, The step of selecting a target script file according to the type of the rule configuration parameters includes: Compare the type with multiple preset types, and determine a target type that matches the type from the multiple preset types. Each preset type in the multiple preset types corresponds to a general script template file; Determine the script template file corresponding to the target type as the target script file.

3. The method according to claim 1, characterized in that, The step of analyzing the behavior data based on multiple rule files in the rule file library to determine the user behavior data with risks includes: Determine multiple candidate files that match the behavior data from the multiple rule files; Analyze the behavior data through the operation state machine corresponding to each candidate file to determine the user behavior data with risks. The operation state machine encapsulates the calculation logic and rule configuration parameters of the candidate file.

4. The method according to claim 3, wherein The step of determining multiple candidate files that match the behavior data from the multiple rule files includes: Determine multiple behavior types corresponding to the behavior data; Compare each behavior type with the behavior type corresponding to each rule file in the multiple rule files, and determine candidate behavior types corresponding one by one to the multiple behavior types from the behavior types corresponding to the multiple rule files; Determine the rule files corresponding to the multiple candidate behavior types as the multiple candidate files.

5. The method according to claim 3, characterized in that, The step of analyzing the behavior data through the operation state machine corresponding to each candidate file to determine the user behavior data with risks includes: Analyze the behavior data through the operation state machine corresponding to each candidate file to generate an intermediate result, and store the intermediate result in the first external storage module. The first external storage module is an independently deployed remote dictionary server cluster; Determine the user behavior data with risks based on the intermediate result through the operation state machine corresponding to each candidate file.

6. The method according to claim 1, wherein Before updating and saving the target rule file to the rule file library by broadcasting, the method further includes: Publish the target rule file to the database middleware, so that the database middleware routes the target rule file to the second external storage module, and the second external storage module supports distributed management.

7. The method according to claim 3, wherein The method further includes: When the first operation state machine corresponding to the first candidate file among the multiple candidate files successfully preempts the distributed lock and analyzes the behavior data through the first operation state machine, the first operation state machine statistically analyzes the user behavior data that is risky after the first moment, and obtains a first statistical result, where the first moment is the moment when the first operation state machine successfully preempts the distributed lock; When the second moment for statistically analyzing the user behavior data that is risky is the third moment, the first operation state machine outputs the first statistical result, where the second moment is later than the first moment.

8. The method according to claim 7, wherein The method for determining the third moment includes any one of the following: When the distributed lock is set with a first expiration period, based on the first moment and the first expiration period, determine the third moment; When a first preset duration is set through a preset timer, based on the first moment and the first preset duration, determine the third moment.

9. The method according to claim 7, characterized in that, The method further includes: Determine whether the duration between the first moment and the second moment is equal to a second preset duration set by a cyclic timer; When the duration is equal to the second preset duration and the duration is not equal to the second expiration period of the distributed lock, continue to analyze the behavior data through the first operation state machine until the duration is equal to the second expiration period, and output the first statistical result through the first operation state machine, where the second expiration period is greater than the second preset duration.

10. A device for processing data, characterized in that, The device includes: An acquisition unit, configured to acquire configuration information input by a developer in a rule configuration interface, and parse the configuration information to obtain relevant rule configuration parameters; A generation unit, configured to select a target script file according to the type of the rule configuration parameters, and generate a target rule file based on the format of the target script file; A storage unit, configured to update and save the target rule file to a rule file library by means of broadcasting; A processing unit, configured to acquire behavior data of multiple users, and based on multiple rule files in the rule file library, analyze the behavior data to determine user behavior data that is risky.

11. An electronic device, characterized in that, The electronic device includes: A memory, configured to store executable program code; A processor, configured to call and run the executable program code from the memory, so that the electronic device executes the method according to any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and when the computer instructions run on an electronic device, the electronic device is caused to execute the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Terminal anomaly analysis method and device based on process, equipment and storage medium

    CN112114995A

  • Business rule processing method and device, server and storage medium

    CN114490694A

  • Method and device for generating rule script of rule engine

    CN115686621A

  • Script file generation method and device, computer equipment and storage medium

    CN115756581A

  • Business processing method and device, storage medium and computer equipment

    CN116991493A

Cited By

  • ACL rule processing method and device, product, equipment and medium

    CN121396665A