Risk management method, system and device for non-bank financial institution and storage medium

By building risk detection tasks, maintaining risk indicator database, cumulative testing cases and adjusting testing processes, the risk management efficiency and accuracy problems of non-bank financial institutions have been solved, and comprehensive and accurate detection and effective rectification of risks have been achieved.

CN120354411APending Publication Date: 2025-07-22INTEGRITY TECH GRP INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510357864.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing financial risk detection solutions lack specialized processing capabilities in non-bank financial institutions, resulting in low efficiency and low accuracy of risk management, and are unable to provide comprehensive and effective rectification suggestions.

Method used

Build risk detection tasks, dynamically maintain risk indicator database, accumulate historical inspection cases, define and adjust detection processes, and manage risk detection documents through visual means, and provide automated risk rectification suggestions.

Benefits of technology

It has achieved comprehensive and accurate risk detection of non-bank financial institutions, improved the level of risk management, provided effective rectification suggestions, automatically updated risk indicators, and improved the efficiency and accuracy of risk management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354411A_ABST
    Figure CN120354411A_ABST
Patent Text Reader

Abstract

The invention provides a risk management method, system and device for a non-bank financial institution and a storage medium, and the method comprises the steps: creating and managing a risk detection task to respond to a risk detection request of the non-bank financial institution, and obtaining a detection result; dynamically maintaining and managing risk indexes of non-bank financial institutions in the index library; according to a detection result, accumulating and managing risk detection cases in a historical database; defining and dynamically adjusting an operation process of risk detection; documents generated in risk detection are visually managed. According to the method, comprehensive and accurate risk detection of the non-bank financial institution can be realized, effective rectification suggestions are provided, unique risk indexes of the non-bank financial institution are automatically updated, and the risk management level of the non-bank financial institution is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a risk management method, system, device, and storage medium for non-bank financial institutions. Background Art

[0002] In the current financial market, many existing financial risk detection solutions mainly focus on the risk detection of traditional banks. For the specific risks faced by non-bank financial institutions, these solutions often lack specialized processing and response capabilities. Most of the current systems on the market rely on manual detection and general risk indicator analysis to evaluate potential risks. This method is not only inefficient but also has unsatisfactory accuracy. In addition, these methods are also unable to provide comprehensive and effective solutions when it comes to offering risk rectification suggestions. During the risk detection process, the capabilities of data analysis and visualization are insufficient, which directly affects the risk management level of non-bank financial institutions, making it difficult for them to effectively identify, evaluate, and respond to various risks, thereby reducing the risk management efficiency and effectiveness of the entire non-bank financial institution to a certain extent. Summary of the Invention

[0003] In view of the above problems, embodiments of the present invention provide a risk management method, system, device, and storage medium for non-bank financial institutions, which solve the existing technical problems, achieve comprehensive and accurate risk detection for non-bank financial institutions, provide effective rectification suggestions, automatically update the unique risk indicators of non-bank financial institutions, and improve the risk management level of non-bank financial institutions.

[0004] To solve the above technical problems, the present invention provides the following technical solutions:

[0005] In a first aspect, the present invention provides a risk management method for non-bank financial institutions, the method comprising:

[0006] Creating and managing risk detection tasks to obtain detection results in response to a risk detection request from a non-bank financial institution;

[0007] Dynamically maintaining and managing the risk indicators of non-bank financial institutions in an indicator library;

[0008] Accumulating and managing risk detection cases in a historical database according to the detection results;

[0009] Defining and dynamically adjusting the operation process of risk detection;

[0010] Visualizing and managing the documents generated during risk detection.

[0011] In one embodiment, the creating and managing detection tasks to obtain detection results in response to a detection request from a non-bank financial institution includes:

[0012] Create corresponding risk detection tasks according to the risk detection requirements provided by non-bank financial institutions;

[0013] Automatically allocate corresponding types of detection methods and available resources according to the risk detection tasks to obtain detection results;

[0014] Track the execution process of the risk detection tasks, collect work logs in real time, and send out alarms in a timely manner when abnormalities occur.

[0015] In one embodiment, the risk indicators of non-bank financial institutions in the dynamically maintained and managed indicator library include:

[0016] Automatically update the general risk indicators based on threat intelligence;

[0017] Generate risk indicators of non-bank financial institutions by combining historical detection data;

[0018] Verify the effectiveness of the generated risk indicators of non-bank financial institutions;

[0019] Add the general risk indicators and effective risk indicators of non-bank financial institutions to the indicator library.

[0020] In one embodiment, the cumulative management of risk detection cases in the historical database according to the detection results includes:

[0021] Analyze the security events in the detection results to obtain the types of security vulnerabilities, attack methods, repair measures, and effectiveness evaluations of the repair measures;

[0022] Associate risk indicators, attack methods, and repair measures into a knowledge graph to generate risk detection cases;

[0023] Recommend similar risk cases to the generated risk detection cases based on graph neural networks;

[0024] Integrate the risk detection cases and similar risk cases into the historical database.

[0025] In one embodiment, the analysis of the security events in the detection results to obtain the types of security vulnerabilities, attack methods, repair measures, and effectiveness evaluations of the repair measures includes:

[0026] Obtain the identity identifier of the security event in the detection results and the detected date;

[0027] Determine the business type of the security event;

[0028] Obtain the security vulnerability that caused the security event;

[0029] Save the intrusion evidence of the vulnerability;

[0030] Automatically match repair measures according to the type of security vulnerability;

[0031] Evaluate the effectiveness of the repair measures.

[0032] In one embodiment, the operation process of defining and dynamically adjusting risk detection includes:

[0033] Collect interaction data of non-bank financial institutions from the user login interface and the transaction creation interface respectively;

[0034] Use an automated scanning tool to automatically detect security vulnerabilities existing in non-bank financial institutions;

[0035] Set an audit period to review the results of the automated scan;

[0036] When a new type of attack is detected, automatically insert memory forensics;

[0037] When an abnormality occurs in a certain step during the detection process, automatically start a parallel detection sub-process.

[0038] In one embodiment, the documents generated in the visual management of risk detection include:

[0039] Store the metadata of the risk detection process;

[0040] Use Git-LFS to manage the detection results;

[0041] Use a visualization tool to perform real-time visualization display on the metadata and the detection results.

[0042] In a second aspect, the present invention provides a risk management system for non-bank financial institutions, and the system includes:

[0043] Task management module: used to create and manage risk detection tasks to obtain detection results in response to the risk detection request of non-bank financial institutions;

[0044] Index library management module: used to dynamically maintain and manage the risk indexes of non-bank financial institutions in the index library;

[0045] Experience management module: used to accumulate and manage the risk detection cases in the historical database according to the detection results;

[0046] Process management module: used to define and dynamically adjust the operation process of risk detection;

[0047] Document management module: used to visually manage the documents generated in risk detection.

[0048] In one embodiment, the task management module is specifically used for:

[0049] Create corresponding risk detection tasks according to the risk detection requirements provided by non-bank financial institutions;

[0050] Automatically allocate corresponding types of detection methods and available resources according to the risk detection tasks to obtain detection results;

[0051] Track the execution process of the risk detection tasks, collect work logs in real time, and send out alarms in a timely manner when anomalies occur.

[0052] In one embodiment, the index library management module is specifically used for:

[0053] Automatically update general risk indicators based on threat intelligence;

[0054] Generate non-bank financial institution risk indicators by combining historical detection data;

[0055] Verify the effectiveness of the generated non-bank financial institution risk indicators;

[0056] Add general risk indicators and valid non-bank financial institution risk indicators to the index library.

[0057] In one embodiment, the experience management module is specifically used for:

[0058] Analyze security events in the detection results to obtain the types of security vulnerabilities, attack methods, repair measures, and effectiveness evaluations of the repair measures;

[0059] Associate risk indicators, attack methods, and repair measures into a knowledge graph to generate risk detection cases;

[0060] Recommend similar risk cases to the generated risk detection cases based on graph neural networks;

[0061] Integrate risk detection cases and similar risk cases into the historical database.

[0062] In one embodiment, analyzing security events in the detection results in the experience management module to obtain the types of security vulnerabilities, attack methods, repair measures, and effectiveness evaluations of the repair measures includes:

[0063] Obtain the identity identifier of the security event in the detection results and the date when it was detected;

[0064] Determine the business type of the security event;

[0065] Obtain the security vulnerability that caused the security event;

[0066] Save the intrusion evidence of the vulnerability;

[0067] Automatically match repair measures according to the type of security vulnerability;

[0068] Evaluate the effectiveness of the repair measures.

[0069] In one embodiment, the process management module is specifically configured to:

[0070] Collect interaction data of non-bank financial institutions from the user login interface and the transaction creation interface respectively;

[0071] Use an automated scanning tool to automatically detect security vulnerabilities existing in non-bank financial institutions;

[0072] Set an audit period to review the automated scanning results;

[0073] When a new type of attack is detected, automatically insert memory forensics;

[0074] When an abnormality occurs in a certain step during the detection process, automatically start a parallel detection subprocess.

[0075] In one embodiment, the document management module is specifically configured to:

[0076] Store the metadata of the risk detection process;

[0077] Use Git-LFS to manage the detection results;

[0078] Use a visualization tool to perform real-time visualization display of the metadata and the detection results.

[0079] In a third aspect, the present invention provides an electronic device, including: a processor and a memory;

[0080] The memory is used to store a computer program;

[0081] The processor is used to execute a risk management method for non-bank financial institutions provided in any one of the first aspects by calling the computer program.

[0082] In a fourth aspect, the present invention provides a computer-readable storage medium, where the computer-readable storage medium includes a program, and the program is used to implement a risk management method for non-bank financial institutions provided in any one of the first aspects when executed by a processor.

[0083] As can be seen from the above description, the risk management method, system, device, and storage medium provided by the embodiments of the present invention for non-bank financial institutions have the following advantages compared with the prior art: By constructing and manipulating risk detection tasks, the present invention meets the risk detection requirements of non-bank financial institutions and obtains detection results; dynamically maintains and manages the risk indicators of non-bank financial institutions in the indicator library; accumulates and manages the risk detection cases in the historical database based on the detection results; sets and flexibly adjusts the operation process of risk detection; manages the documents generated during the risk detection process through visualization means, realizes comprehensive and accurate risk detection of non-bank financial institutions, provides effective rectification suggestions, automatically updates the risk indicators unique to non-bank financial institutions, and improves the risk management level of non-bank financial institutions. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] Figure 1 FIG. 1 shows a schematic flowchart of a risk management method for non-bank financial institutions provided by an embodiment of the present invention;

[0085] Figure 2 FIG. 2 shows a schematic structural diagram of a risk management system for non-bank financial institutions provided by an embodiment of the present invention;

[0086] Figure 3 FIG. 3 shows a schematic structural diagram of an electronic device in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0087] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts belong to the scope of protection of the present invention.

[0088] Based on the disadvantages of the prior art, the embodiments of the present invention provide specific embodiments of the risk management method for non-bank financial institutions, as Figure 1 shown, the method includes the following steps:

[0089] S110: Create and manage a risk detection task to respond to the risk detection request of a non-bank financial institution and obtain a detection result.

[0090] The purpose of this step is to trigger an executable detection task for the risk detection request of a non-bank financial institution, realize the risk detection of a non-bank financial institution through the creation and management of the detection task, allocate and track the processing process of the risk detection task, and finally obtain a feedback result (i.e., the detection result) to meet the intelligent risk detection requirements of non-bank financial institutions.

[0091] The task creation process includes: creating corresponding risk detection tasks according to the risk detection requirements provided by non-bank financial institutions. Accepting the detection requests submitted by non-bank financial institutions, where the detection requests include request parameters such as institution type, detection scope, and event requirements. The detection scope refers to how many risk indicators need to be detected, and the risk indicators include, but are not limited to, indicators related to financial industry data leakage announced annually and quarterly. After obtaining the detection request, verify the legality of the request parameters, such as whether the detection scope conforms to the definition in the indicator library. When the legality verification passes, generate a task ID for the risk detection task, and the task ID can adopt the method of UUID + timestamp. Finally, store all the generated risk detection tasks in the task queue for processing according to the priority and urgency levels.

[0092] The task allocation process includes: automatically allocating corresponding types of detection methods and available resources according to the risk detection tasks to obtain detection results. Using a rule engine to match corresponding types of detection methods and available resources for the risk monitoring tasks. For example, high-risk tasks are preferentially allocated to high-level detection nodes, and for complex scenario tasks, a multi-model collaborative detection process is triggered, and the load conditions of each detection node are monitored in real time. When a certain detection node exceeds the set threshold, automatic expansion is performed to achieve real-time dynamic adjustment and adaptively realize the allocation of line detection tasks, so as to obtain the final detection results more quickly. The detection results include detection reports, vulnerability details, risk indicators, task IDs, and processing times, etc.

[0093] The task allocation process includes: tracking the execution process of the risk detection tasks, collecting work logs in real time, and sending out alarms in a timely manner when anomalies occur. The state machine model (NEW→RUNNING→PAUSED→COMPLETED / FAILED) can be used to track the execution process of the risk detection tasks, and the real-time collection of work logs can be achieved through Filebeat→Logstash→Elasticsearch. Threshold rules can be used to set multiple anomaly alarm trigger conditions, such as a processing timeout alarm is triggered when the detection time consumption > 3 times the average duration.

[0094] In this step, manage from the aspects of the creation, allocation, and tracking of risk detection tasks to achieve comprehensive and accurate risk detection for non-bank financial institutions. By creating customized risk detection tasks, ensure that the detection work targets actual risks and improve the accuracy, effectiveness, and flexibility of detection. By automatically allocating detection methods and resources, optimize resource utilization according to task complexity and technical requirements to avoid waste. By monitoring the task execution in real time, enable managers to master the progress and promptly discover and respond to potential risks. By collecting detailed work logs, provide data support for problem analysis and improvement of risk management strategies. By sending out alarms when anomalies occur, prompt relevant personnel to react quickly and ensure the progress of risk detection.

[0095] S120: Dynamically maintain and manage the risk indicators of non-bank financial institutions in the indicator library;

[0096] The purpose of this step is to dynamically manage and maintain the risk indicators of non-bank financial institutions in the indicator library, enabling non-bank financial institutions to quickly capture potential risks and take preventive measures in advance. By continuously updating and optimizing the risk indicators, various risks faced by non-bank financial institutions can be comprehensively and accurately evaluated. Dynamically managing the risk indicators helps to complete the risk warning system, making the warning signals more forward-looking and reliable, and better controlling risks.

[0097] The risk indicators include general risk indicators and specific risk indicators related to non-bank financial institutions.

[0098] For general risk indicators, automatically update the general risk indicators based on threat intelligence. Threat intelligence includes, but is not limited to, the CVE database and industry regulatory bulletins. According to the continuously updated threat intelligence, the general risk indicators included in the threat intelligence are further updated.

[0099] For the risk indicators exclusive to non-bank financial institutions, generate the risk indicators of non-bank financial institutions by combining historical detection data. For example, if a non-bank financial institution repeatedly has the same type of vulnerability, risk indicators for this type of vulnerability are formulated based on this vulnerability.

[0100] After the risk indicators of non-bank financial institutions are generated, it is necessary to verify the effectiveness of the generated risk indicators of non-bank financial institutions. During the verification, an expert team can be used to verify their effectiveness and rationality, exclude invalid risk indicators, and retain valid risk indicators.

[0101] Finally, add the general risk indicators and effective non-bank financial institution risk indicators to the indicator library. When adding the non-bank financial institution risk indicators to the indicator library, first, it is necessary to perform data encapsulation on the non-bank financial institution risk indicators. Before encapsulation, create a risk indicator model and initialize the risk indicator attributes of the risk indicator model. The risk indicator attributes include risk indicator identification, risk indicator content, risk indicator weight, risk indicator detection and risk indicator impact degree. Among them, the risk indicator identification refers to the unique identity identifier for identifying the risk indicator. The risk indicator content refers to the description of the content and purpose of the risk indicator. The risk indicator weight refers to the importance or proportion of the risk indicator in assessing the overall risk. The risk indicator detection and identification refer to the methods or means used to detect or identify the risk indicator. The risk indicator impact degree refers to the severity when the risk indicator is triggered. During encapsulation, collect the attribute values corresponding to the risk indicator attributes and assign the collected attribute values to the corresponding risk indicators in the risk indicator model to complete the encapsulation of the risk indicators. Finally, store both the general risk indicators and the effective non-bank financial institution risk indicators in the indicator library.

[0102] In this step, by automatically updating the general risk indicators, it is possible to achieve a rapid response to risks, improve the efficiency of risk identification, enable non-bank financial institutions to quickly respond to risk changes, and efficiently and accurately identify potential risks. The generated non-bank financial institution risk indicators can not only fit the risk status of non-bank financial institutions themselves but also deeply explore potential risk patterns, providing strong support for decision-making. Through the analysis of past situations, hidden risk trends can be discovered, and the effectiveness of the generated non-bank financial institution risk indicators can be verified to ensure the reliability of the indicators, enhance the risk management effect, meet regulatory requirements, ensure the authenticity and accuracy of the risk indicators, and thus facilitate the effective operation of the risk management system. Incorporating the general risk indicators and effective non-bank financial institution risk indicators into the indicator library can achieve centralized management, facilitate comparative analysis, and support continuous optimization, contributing to the continuous improvement of risk management capabilities.

[0103] S130: According to the detection results, accumulate and manage the risk detection cases in the historical database.

[0104] This step can integrate the security events detected during the historical risk detection process into risk detection cases and store them in the historical database. When a risk vulnerability is detected during the next risk detection, the historical database can recommend the same or similar risk detection cases to understand the handling methods for such risks at that time, thereby accelerating the risk handling speed.

[0105] The specific process of the historical database continuously accumulating and managing risk detection cases is as follows:

[0106] Analyze the security events in the detection results to obtain the types of security vulnerabilities, attack methods, repair measures, and the effectiveness evaluation of the repair measures.

[0107] More specifically, obtain the identity identifier of the security event in the detection results and the detected date. The identity identifier of the security event can be used to track and record the processing process of the security event, and the date helps to understand the timeline of the security event.

[0108] Determine the business type of the security event.

[0109] Obtain the security vulnerability that caused the security event.

[0110] Save the intrusion evidence of the vulnerability.

[0111] Automatically match repair measures according to the type of security vulnerability.

[0112] Evaluate the effectiveness of the repair measures.

[0113] Taking the vulnerability of unauthorized access to the API interface in P2P online lending as an example, first determine the identity identifier and occurrence date of the security event itself. The business type of the security event is P2P online lending. The security vulnerability found during the security event monitoring is unauthorized access to the API interface. Save the "access record without authentication Token in the request log" to provide specific evidence for the existence of the vulnerability. Propose a repair measure (implement the OAuth2.0 authentication mechanism) to address the discovered security vulnerability. Before or after implementing the repair measure, evaluate the effectiveness of the repair measure. For example, a effectiveness evaluation value of 0.95 is given, indicating that the expected repair measure can significantly reduce the risk or the impact of the vulnerability.

[0114] Associate risk metrics, attack methods, and repair measures into a knowledge graph to generate risk detection cases. When constructing the knowledge graph, the node types are Entity / Event / Relationship.

[0115] Recommend similar risk cases to the generated risk detection cases based on graph neural networks. For example: when "SQL injection" is detected, recommend historical cases of improper database configuration.

[0116] Finally, integrate the risk detection cases and similar risk cases into the historical database.

[0117] In this step, a knowledge graph can be utilized to generate risk detection cases, presenting complex security information in a visual form, which is conducive to providing practical reference examples when facing new security issues. Recommending similar risk cases based on graph neural networks can expand the security perspective, discover potential patterns, and improve the efficiency and accuracy of risk detection. By using the historical database, the accumulation and precipitation of security data can be completed, supporting long-term trend analysis, assisting compliance audits, and providing strong support for security planning, resource allocation, and meeting regulatory requirements.

[0118] S140: Define and dynamically adjust the operation process of risk detection.

[0119] This step can standardize the operation process of the risk detection process and dynamically adjust the operation process of risk detection according to the problems encountered during the detection process, enabling the risk detection process to run completely.

[0120] The specific operation process it stipulates is as follows:

[0121] Collect the interaction data of non-bank financial institutions from the user login interface and the transaction creation interface respectively.

[0122] Use an automated scanning tool to automatically detect the security vulnerabilities existing in non-bank financial institutions.

[0123] Set an audit period to review the results of the automated scan.

[0124] When a new type of attack is detected, memory forensics is automatically inserted.

[0125] When an abnormality occurs in a certain step during the detection process, a parallel detection subprocess is automatically started.

[0126] Taking the "Compliance Detection Process of Third-Party Payment Institutions" as an example:

[0127] First, data collection: Collect the key information and interaction data of the third-party payment institution system for subsequent analysis. Use API packet capture technology to record the communication between systems through the API. Specify two API endpoints for packet capture, namely the user login interface (user / login) and the transaction creation interface (transaction / create). These two endpoints usually involve the transmission of sensitive information and are therefore the key points of security detection.

[0128] After that, vulnerability scanning: Use the automated scanning tool AWVS2024 (automated vulnerability scanning software version) to conduct a comprehensive security scan of the system. Specify the rule set used by the scanning tool as PCI-DSS (Payment Card Industry Data Security Standard), and PCI-DSS aims to protect the security of payment card information.

[0129] Finally, conduct a review: Verify and conduct in-depth analysis on the results of automated scanning to ensure accuracy and completeness. Have security experts (Zhang San and Li Si) review the scanning results, identify possible false positives or missed reports, and evaluate the impact of potential risks. Also, specify the list of reviewers and the timeout for the review (48 hours). This ensures that the review work can be completed within the specified time, while ensuring sufficient time for in-depth analysis of the discovered problems.

[0130] In this step, the operation status can be comprehensively grasped, the risk sources can be accurately located, providing a rich data basis for risk detection; using automated scanning tools to automatically detect security vulnerabilities can greatly improve the detection efficiency and accuracy, quickly and reliably identify various types of vulnerabilities; setting a review deadline to review the results of automated scanning can not only ensure timely handling of risks, but also improve work efficiency and standardization; key evidence can be obtained to assist in the upgrade of the security research and defense system, providing strong support for emergency response and investigation; problems can be quickly investigated and rectified, improving the system stability and reliability, and ensuring the continuity of risk detection work.

[0131] S150: Visualize the documents generated during risk detection.

[0132] The purpose of this step is to visualize the risk detection documents for tracking and monitoring the changes in risks.

[0133] Store the metadata of the risk detection process. The metadata includes but is not limited to the generation time, responsible person, associated task ID, etc.

[0134] Use Git-LFS to manage the detection results, including but not limited to managing detection reports, vulnerability details, etc.

[0135] Use visualization tools to perform real-time visualization display of the metadata and detection results.

[0136] All operations (creation, modification, deletion, etc.) on the visualization web page are also recorded, and the operator, operation time, operation IP, etc. are associated. According to the saved documents, a compliance audit report can be generated regularly.

[0137] In this step, by real-time updating and managing the visualization content, the dynamic changes of risk indicators can be clearly displayed, the rising or falling trends of risks and newly emerging risk points can be discovered in a timely manner, enabling relevant personnel to adjust risk management strategies and measures in a timely manner to ensure that risks are always under control.

[0138] As described above, the present invention constructs and manipulates risk detection tasks to meet the risk detection requirements of non-bank financial institutions, obtains detection results, dynamically maintains and manages the risk indicators of non-bank financial institutions in the indicator library, accumulates and manages risk detection cases in the historical database based on the detection results, sets and flexibly adjusts the operation process of risk detection, and manages the documents generated during the risk detection process through visualization means, realizes comprehensive and accurate risk detection of non-bank financial institutions, provides effective rectification suggestions, automatically updates the risk indicators unique to non-bank financial institutions, and improves the risk management level of non-bank financial institutions.

[0139] Based on the same inventive concept, an embodiment of the present application further provides a risk management system for non-bank financial institutions, which can be used to implement a risk management method for non-bank financial institutions described in the above embodiment, as described in the following embodiment. Since the principle of the system to solve the problem is similar to the method, the implementation of the system can refer to the method implementation, and the repeated parts will not be described again. As used below, the term "unit" or "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the system described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0140] As Figure 2 shown, the present invention provides a risk management system for non-bank financial institutions. In Figure 2 it, the system includes:

[0141] A task management module 210: used to create and manage risk detection tasks to respond to the risk detection request of non-bank financial institutions and obtain detection results;

[0142] An indicator library management module 220: used to dynamically maintain and manage the risk indicators of non-bank financial institutions in the indicator library;

[0143] An experience management module 230: used to accumulate and manage risk detection cases in the historical database according to the detection results;

[0144] A process management module 240: used to define and dynamically adjust the operation process of risk detection;

[0145] A document management module 250: used to visually manage the documents generated during risk detection.

[0146] In an embodiment of the present invention, the task management module 210 is specifically used for:

[0147] Create corresponding risk detection tasks according to the risk detection requirements provided by non-bank financial institutions;

[0148] Automatically allocate the corresponding type of detection method and available resources according to the risk detection task to obtain the detection result;

[0149] Track the execution process of the risk detection task, collect work logs in real time, and issue an alarm in a timely manner when an anomaly occurs.

[0150] In an embodiment of the present invention, the index library management module 220 is specifically configured to:

[0151] Automatically update the general risk indicators based on threat intelligence;

[0152] Generate non-bank financial institution risk indicators by combining historical detection data;

[0153] Verify the effectiveness of the generated non-bank financial institution risk indicators;

[0154] Add the general risk indicators and the effective non-bank financial institution risk indicators to the index library.

[0155] In an embodiment of the present invention, the experience management module 230 is specifically configured to:

[0156] Analyze the security events in the detection result to obtain the type of security vulnerability, attack method, repair measure, and the effectiveness evaluation of the repair measure;

[0157] Associate the risk indicators, attack methods, and repair measures into a knowledge graph to generate risk detection cases;

[0158] Recommend similar risk cases based on the graph neural network and the generated risk detection cases;

[0159] Integrate the risk detection cases and similar risk cases into the historical database.

[0160] In an embodiment of the present invention, analyzing the security events in the detection result by the experience management module 230 to obtain the type of security vulnerability, attack method, repair measure, and the effectiveness evaluation of the repair measure includes:

[0161] Obtain the identity identifier of the security event in the detection result and the detected date;

[0162] Determine the business type of the security event;

[0163] Obtain the security vulnerability that generates the security event;

[0164] Save the intrusion evidence of the vulnerability;

[0165] Automatically match the repair measure according to the security vulnerability type;

[0166] Evaluate the effectiveness of the repair measure.

[0167] In an embodiment of the present invention, the process management module 240 is specifically configured to:

[0168] Collect interaction data of non-bank financial institutions from the user login interface and the transaction creation interface respectively;

[0169] Use an automated scanning tool to automatically detect security vulnerabilities existing in non-bank financial institutions;

[0170] Set an audit period to review the automated scanning results;

[0171] When a new type of attack is detected, automatically insert memory forensics;

[0172] When an abnormality occurs in a certain step during the detection process, automatically start a parallel detection sub-process.

[0173] In an embodiment of the present invention, the document management module 250 is specifically configured to:

[0174] Store the metadata of the risk detection process;

[0175] Use Git-LFS to manage the detection results.

[0176] An embodiment of the present application also provides a specific implementation manner of an electronic device capable of implementing all steps in the method in the above embodiment. Refer to Figure 3 , the electronic device 300 specifically includes the following contents:

[0177] A processor 310, a memory 320, a communication unit 330, and a bus 340;

[0178] Among them, the processor 310, the memory 320, and the communication unit 330 complete mutual communication through the bus 340; the communication unit 330 is used to implement information transmission between related devices such as server-side devices and terminal devices.

[0179] The processor 310 is used to call the computer program in the memory 320, and when the processor executes the computer program, all steps in the method in the above embodiment are implemented.

[0180] Those of ordinary skill in the art should understand that the memory can be, but is not limited to, random access memory (RAM), read only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc. Among them, the memory is used to store programs, and the processor executes the programs after receiving execution instructions. Further, the software programs and modules in the above-mentioned memory may also include an operating system, which may include various software components and / or drivers for managing system tasks (such as memory management, storage device control, power management, etc.), and may communicate with various hardware or software components to provide a running environment for other software components.

[0181] The processor can be an integrated circuit chip with the ability to process signals. The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc.

[0182] The present application also provides a computer-readable storage medium, and the computer-readable storage medium includes a program, and the program is used to execute the method provided in any one of the foregoing method embodiments when executed by the processor.

[0183] Those of ordinary skill in the art should understand that all or part of the steps for implementing the above-mentioned method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above-mentioned method embodiments; and the foregoing storage medium includes: ROM, RAM, magnetic disk, or optical disk, etc., which can store program codes, and the specific type of the medium is not limited in the present application.

[0184] As described above, it is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A risk management method for non-bank financial institutions, characterized in that, The method includes: Creating and managing risk detection tasks to respond to the risk detection requests of non-bank financial institutions and obtaining detection results; Dynamically maintaining and managing the risk indicators of non-bank financial institutions in the indicator library; Accumulating and managing risk detection cases in the historical database according to the detection results; Defining and dynamically adjusting the operation process of risk detection; Visualizing and managing the documents generated during risk detection.

2. The risk management method of a non-bank financial institution according to claim 1, characterized in that The creating and managing detection tasks to respond to the detection requests of non-bank financial institutions includes: Creating corresponding risk detection tasks according to the risk detection requirements provided by non-bank financial institutions; Automatically allocating corresponding types of detection methods and available resources according to the risk detection tasks to obtain detection results; Tracking the execution process of risk detection tasks, collecting work logs in real time, and sending alarms in a timely manner when abnormalities occur.

3. The risk management method of a non-bank financial institution as described in claim 2, wherein, The dynamically maintaining and managing the risk indicators of non-bank financial institutions in the indicator library includes: Automatically updating general risk indicators based on threat intelligence; Generating risk indicators for non-bank financial institutions by combining historical detection data; Verifying the effectiveness of the generated risk indicators for non-bank financial institutions; Adding general risk indicators and valid risk indicators for non-bank financial institutions to the indicator library.

4. The risk management method of a non-bank financial institution according to claim 1, characterized in that, The accumulating and managing risk detection cases in the historical database according to the detection results includes: Analyzing the security events in the detection results to obtain the types of security vulnerabilities, attack methods, repair measures, and effectiveness evaluations of the repair measures; Associating risk indicators, attack methods, and repair measures into a knowledge graph to generate risk detection cases; Recommending similar risk cases to the generated risk detection cases based on graph neural networks; Integrating risk detection cases and similar risk cases into the historical database.

5. The risk management method of a non-bank financial institution according to claim 4, wherein The analyzing the security events in the detection results to obtain the types of security vulnerabilities, attack methods, repair measures, and effectiveness evaluations of the repair measures includes: Obtaining the identity identifiers of security events and the detected dates in the detection results; Determining the business types of security events; Obtaining the security vulnerabilities that cause security events; Saving the intrusion evidence of the vulnerabilities; Automatically matching repair measures according to the types of security vulnerabilities; Evaluating the effectiveness of the repair measures.

6. The risk management method of a non-bank financial institution according to claim 1, wherein The defining and dynamically adjusting the operation process of risk detection includes: Collecting interaction data of non-bank financial institutions from the user login interface and the transaction creation interface respectively; Automatically detecting security vulnerabilities existing in non-bank financial institutions using an automated scanning tool; Setting an audit period to review the automated scanning results; Automatically inserting memory forensics when a new type of attack is detected; Automatically starting a parallel detection sub-process when an abnormality occurs in a certain step during the detection process.

7. The risk management method of a non-bank financial institution as described in claim 1, wherein The visualizing and managing the documents generated during risk detection includes: Storing the metadata of the risk detection process; Managing the detection results using Git-LFS; Using a visualization tool to perform real-time visualization display of the metadata and detection results.

8. A risk management system for a non-bank financial institution according to claim 5, characterized in that, The system includes: A task management module: used for creating and managing risk detection tasks to respond to the risk detection requests of non-bank financial institutions and obtaining detection results; An indicator library management module: used for dynamically maintaining and managing the risk indicators of non-bank financial institutions in the indicator library; Experience management module: used to accumulate and manage risk detection cases in the historical database according to the detection results; Process management module: used to define and dynamically adjust the operation process of risk detection; Document management module: used to visually manage the documents generated during risk detection.

9. An electronic device, characterized in that, Comprising: A processor and a memory; The memory is used to store computer programs; The processor is used to execute a risk management method for a non-bank financial institution according to any one of claims 1 to 7 by calling the computer program.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a program, and the program is used to implement a risk management method for a non-bank financial institution according to any one of claims 1 to 7 when executed by the processor.