Object risk determination method, object risk control method and device
By collecting and monitoring risk business log data in real time, building a collection of risk objects, the problem of insufficient real-time risk determination and risk control in the existing technology is solved, and efficient risk monitoring and processing is achieved.
Patent Information
- Application Number
- CN202510613815.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-08-19
AI Technical Summary
In the prior art, the real-time nature of risk determination and risk control is poor, and it is impossible to detect and handle users' risk business behavior in a timely manner.
By collecting log data from risk business nodes in real time, and based on setting risk strategies to monitor the risk request behavior of objects within the risk monitoring time window, a collection of risk objects is constructed and stored, and high-risk users are monitored and processed in a timely manner.
Real-time risk determination and risk control are realized, and users' risk business behaviors are discovered and handled in a timely manner, ensuring the timeliness and accuracy of risk control.
Smart Images

Figure CN120509727A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and more particularly to a method for determining object risk, and a method and device for controlling object risk. Background Art
[0002] With the rapid development of computer technology and Internet technology, online business processing is becoming more and more common. The risks involved in business processing are also increasing, and the losses caused are becoming more and more serious. For this reason, risk control is receiving more and more attention, and it is necessary to analyze user risks when conducting risk control.
[0003] In existing technologies, when a user's business request is received, the user's behavior data is collected from relevant business nodes, and analysis is performed to determine whether the user poses a risk, thereby determining and processing the business request. However, this method suffers from poor real-time performance in risk assessment and control, making it difficult to promptly detect and address risky business behaviors. Therefore, a more real-time and accurate risk assessment and control solution is urgently needed. Summary of the Invention
[0004] In light of this, embodiments of this specification provide a method for determining object risk. One or more embodiments of this specification also include an object risk control method, an object risk determination apparatus, an object risk control apparatus, a computing device, a computer-readable storage medium, and a computer program product to address technical deficiencies in the prior art.
[0005] According to a first aspect of an embodiment of this specification, a method for determining an object risk is provided, the method comprising: Collecting risk business log data of at least one risk business node, wherein the risk business log data records risk request behaviors of each object at each risk business node; Based on the set risk strategy, risk monitoring is performed on the risk request behavior of each object within the risk monitoring time window, and the object risk type of each object within the risk monitoring time window is determined; A risk object set is constructed and stored according to each risk object having a risk type.
[0006] According to a second aspect of the embodiments of this specification, a method for object risk control is provided, the method comprising: In response to a risk business request of a target object, determining whether the target object is a risk object based on a risk object set, wherein the risk object set is constructed based on the above-mentioned object risk determination method; If the target object is not a risk object, executing the risk service request of the target object; In a case where the target object is a risky object, the risky service request of the target object is intercepted.
[0007] According to a third aspect of the embodiments of this specification, there is provided an object risk determination device, the device comprising: a collection module configured to collect risk business log data of at least one risk business node, wherein the risk business log data records risk request behaviors of each object at each risk business node; a monitoring module configured to perform risk monitoring on the risk request behavior of each object within a risk monitoring time window based on a set risk strategy, and determine an object risk type of each object within the risk monitoring time window; The construction module is configured to construct and store a risk object set according to each risk object with risk type.
[0008] According to a fourth aspect of the embodiments of this specification, there is provided an object risk control device, the device comprising: a determination module configured to, in response to a risk business request of a target object, determine whether the target object is a risk object based on a risk object set, wherein the risk object set is constructed based on the above-mentioned object risk determination method; a first execution module, configured to execute the risk service request of the target object if the target object is not a risk object; The interception module is configured to intercept the risky service request of the target object if the target object is a risky object.
[0009] According to a fifth aspect of the embodiments of this specification, there is provided a computing device, including: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned object risk determination method or object risk control method are implemented.
[0010] According to a sixth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions, which, when executed by a processor, implement the steps of the above-mentioned object risk determination method or object risk control method.
[0011] According to a seventh aspect of the embodiments of this specification, a computer program product is provided, including a computer program / instruction, which, when executed by a processor, implements the steps of the above-mentioned object risk determination method or object risk control method.
[0012] The embodiments of this specification provide a method for determining object risk, which implements real-time collection of log data from each risk business node to obtain the risk request behavior of each object at each risk business node. Based on a set risk strategy, the method performs risk monitoring on the risk request behavior of each object within a risk monitoring time window, determines the object risk type of each object within the risk monitoring time window, screens out risky risk objects, and constructs and stores a risk object set. In this way, the risk request behavior of each object can be collected in real time, the object risk type of each object within the risk monitoring time window can be monitored in real time, and risky users can be promptly added to the risk object set, ensuring the timeliness of object risk determination, thereby ensuring the timeliness of object risk control, and promptly discovering and handling users' risky business behaviors.
[0013] The embodiments of this specification provide an object risk control method, which enables direct access to a risk object set when a risk business request from a target object is received. The risk object set is based on real-time collection of risk request behaviors of each object, monitored and obtained within a risk monitoring time window, and can indicate risky users in real time. Based on the risk object set, it can be quickly determined whether the target object currently initiating the request is a risk object. If it is not a risk object, the risk business request of the target object is executed. If it is a risk object, the risk business request is directly intercepted, and the user's risk business request is discovered and processed in a timely manner to ensure the timeliness of object risk control. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 This is a flow chart of a method for determining object risk provided by one embodiment of this specification; Figure 2 This is a schematic diagram of a processing process of a method for determining object risk provided by an embodiment of this specification; Figure 3 This is a flow chart of an object risk control method provided by one embodiment of this specification; Figure 4 This is a flowchart of a process for determining object risk and a method for controlling object risk provided by one embodiment of this specification; Figure 5 This is a schematic diagram of the structure of an object risk determination device provided by one embodiment of this specification; Figure 6 This is a schematic diagram of the structure of an object risk control device provided by an embodiment of this specification; Figure 7 This is a structural block diagram of a computing device provided by one embodiment of this specification. DETAILED DESCRIPTION
[0015] The following description sets forth many specific details to facilitate a thorough understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the scope of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.
[0016] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a," "an," and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0017] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0018] In addition, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0019] First, the terms involved in one or more embodiments of this specification are explained.
[0020] Risk control refers to the identification, assessment, monitoring, and intervention of potential risks in businesses or systems through technology, rules, models, and other means to reduce losses or avoid adverse consequences. This includes, for example, underwriting (also known as underwriting) and claims settlement in insurance scenarios.
[0021] ODPS (Open Data Processing Service): is a large-scale data warehouse solution used for massive data storage, computing, and analysis. It is suitable for enterprise-level big data processing and supports efficient processing of structured data (SQL), semi-structured data (JSON / XML), and unstructured data (text / logs).
[0022] Data warehouse: A subject-oriented, integrated, relatively stable data collection that reflects historical changes and is used to support enterprise decision analysis (OLAP). Its core goal is to extract, clean, and integrate data from multiple business systems and provide high-performance query and analysis capabilities, rather than directly supporting transaction processing (OLTP).
[0023] SLS (Simple Log Service): is a one-stop log data platform that supports log collection, storage, analysis, visualization, and alerting. It is widely used in scenarios such as operation and maintenance monitoring, security auditing, and business analysis.
[0024] Flink cluster: A distributed stream processing framework that supports high-throughput, low-latency, and stateful computation. It is widely used in scenarios such as real-time ETL, event-driven applications, and complex event processing (CEP). A Flink cluster is a collection of computing resources for running Flink tasks, typically consisting of a JobManager (management node) and a TaskManager (worker node). The JobManager is the cluster's control center, responsible for receiving jobs, scheduling tasks, and coordinating resources. The TaskManager is responsible for executing specific computational tasks, processing data, and performing operations such as transformation and aggregation.
[0025] It should be noted that, taking the insurance scenario as an example, when a user's insurance request is received, the user's insurance behavior data is often collected from the relevant insurance node to analyze whether the user is at risk, and then the insurance request is judged and processed. The real-time performance of risk assessment and risk control is poor, and the user's risk insurance behavior cannot be discovered and processed in a timely manner.
[0026] In an optional implementation method, logs can be collected into a data warehouse and calculated using ODPS. This method requires regular batch processing jobs, which may lead to delays in risk assessment and poor real-time performance, making it impossible to detect and handle users' abnormal insurance behavior in a timely manner.
[0027] The embodiments of this specification provide a method for determining and controlling object risk. These methods can determine the current user's risk profile based on user behavior data collected through risk control statistics, such as the frequency of a user's insurance purchases. If a user frequently purchases insurance within a short period of time, reaching a certain threshold, the user is blacklisted and prohibited from purchasing insurance until a configurable period of time has passed. Specifically, through real-time data collection, transmission, and processing, combined with the efficient stream processing capabilities of a Flink cluster, real-time calculation and risk assessment of the number of user insurance purchases within a specified time window can be achieved. If a user's frequent insurance purchases within a short period of time reach a preset threshold, the user can be immediately marked as a high-risk user and added to a blacklist. Dynamic configuration of risk control policies and automatic blacklist removal are also supported, ensuring the real-time and flexibility of the system.
[0028] As can be seen from the above, the embodiments of this specification can collect, transmit, and process log data of user insurance requests in real time, efficiently clean and convert data, calculate the number of insurance applications for each user within a specified time window in real time, and determine the user's risk profile based on preset thresholds, promptly adding high-risk users to a blacklist. Furthermore, risk control strategies can be flexibly configured and adjusted within the risk assessment system, such as setting thresholds for the number of insurance applications and the time it takes to remove a blacklist, storing data on high-risk users in an appropriate storage system, prohibiting these users from applying for insurance during the blacklist validity period, and notifying the risk control team via email or text message for further investigation and processing.
[0029] In this specification, a method for determining an object risk is provided. This specification also involves an object risk control method, an object risk determination device, an object risk control device, a computing device, a computer-readable storage medium, and a computer program product, which are described in detail one by one in the following embodiments.
[0030] See also Figure 1 , Figure 1 A flow chart of a method for determining object risk according to an embodiment of the present specification is shown, which specifically includes the following steps 102-106.
[0031] Step 102: Collect risk business log data of at least one risk business node, wherein the risk business log data records risk request behaviors of each object at each risk business node.
[0032] Specifically, a risk business node is a processing node in the risk assessment system that is responsible for a certain risk business. The risk business refers to a business that may involve risks, such as insurance business (also known as underwriting business) and claims settlement business. Taking the insurance scenario as an example, the risk business node can be a processing node for insurance business, or the risk business node can also be a processing node for claims settlement business, etc.
[0033] Risk business log data refers to log data related to risk business processing at risk business nodes. This log data can record risk request behaviors of various objects at each risk business node. The objects are targets for risk analysis, such as users, products, and merchants. Risk request behaviors refer to behaviors related to risk business requests at risk business nodes.
[0034] In actual implementation, you can use a log collection tool (such as Logstash or Fluentd) to collect risk business log data corresponding to risk request behaviors of each object from each risk business node in real time. This risk business log data can include the object identifier (such as user name, user ID), behavior time, and information about the requested risk business. For example, if the risk business is insurance, the collected risk business log data can include key information such as user ID, insurance time, and insurance product type, such as {"user_id": "123456", "timestamp": "2023-09-01T10:00:00Z", "product_type": "Health Insurance", "action": "Insurance"}.
[0035] It should be noted that the risk business log data records every risk business request behavior of the object, including information such as the time of the behavior and the business type, providing basic data for subsequent risk assessment.
[0036] In specific implementation, the collected risk business log data can be transmitted to the risk assessment system through the Log Service (SLS). SLS can efficiently transmit large amounts of log data and support real-time streaming processing, ensuring that the risk business log data can be transmitted to the risk assessment system in a timely manner for real-time analysis and processing.
[0037] In an optional implementation of this embodiment, after collecting risky service log data of at least one risky service node, at least one of the following items is further included: Based on the key fields corresponding to the risk monitoring, the risk business log data is cleaned, and other fields except the key fields in the risk business log data are screened out to obtain the first update log data; Based on the key fields corresponding to the risk monitoring and / or the set risk strategy, invalid log data in the risk business log data is filtered out to obtain second update log data; Based on the key fields corresponding to risk monitoring and / or the set risk strategy, determine whether there is log data with missing set fields in the risk business log data. If so, complete the set fields for the log data with missing set fields to obtain third updated log data.
[0038] It should be noted that different types of risk monitoring may require different key fields. For example, for risk monitoring of insurance business, the key fields required are user ID, insurance time, and insured product type. For risk monitoring of claims settlement business, the key fields required are user ID, claim settlement time, claim settlement results, and claims settler. In actual applications, the selection of key fields should be set according to specific risk monitoring requirements to ensure the accuracy and effectiveness of data cleaning and screening.
[0039] A risk strategy is a preconfigured strategy for determining risk for an object. For example, a risk strategy might be set based on the number of risk behaviors reaching a risk threshold within a risk monitoring window, or when risk behavior characteristics match a pre-set risk behavior pattern. In practice, the development of risk strategies should comprehensively consider factors such as business scenarios, risk types, and historical data to ensure the accuracy and effectiveness of risk assessments.
[0040] In an optional implementation method, the risk business log data may include multiple fields, and not all of these fields will be used in the subsequent risk monitoring process. If the complete risk business log data is transmitted, a large amount of redundant data may be transmitted, wasting transmission resources. Therefore, in actual implementation, the risk business log data can be cleaned based on the key fields corresponding to risk monitoring, and other fields in the risk business log data except the key fields can be screened out to obtain the first update log data, and only the first update log data can be transmitted to the risk judgment system for processing and analysis.
[0041] In another optional implementation method, invalid log data may also exist in the risk business log data. For example, invalid log data may be log data that lacks key fields and / or cannot be matched and analyzed with the set risk strategy. Such invalid log data will waste transmission resources and processing resources. Therefore, in actual implementation, it is also possible to screen out invalid log data in the risk business log data based on the key fields corresponding to risk monitoring and / or set risk strategies, obtain second updated log data, and only transmit the first updated log data to the risk determination system for processing and analysis.
[0042] In another optional implementation method, certain setting fields may be missing in the risk business log data. The setting fields refer to pre-configured fields that do not affect the judgment logic of risk monitoring but affect data integrity. Therefore, in actual implementation, the log data with missing setting fields in the risk business log data can be supplemented with setting fields based on the key fields corresponding to risk monitoring and / or set risk strategies to obtain third updated log data, and the supplemented third updated log data can be transmitted to the risk judgment system for processing and analysis.
[0043] Specifically, if the missing setting field is a non-key field, you can directly fill it with the preset default value; or, fill in the missing value by associating other fields (such as associating the user profile table with user_id to obtain user_level); or, for time series fields (such as event_time), linear interpolation is performed based on the timestamps of the previous and next logs; or, call the risk assessment system API or database to fill in the field, etc.
[0044] Of course, in actual implementation, the collected risk business log data can also be directly transmitted to the risk assessment system, and then the risk assessment system will perform data processing operations such as filtering out other fields other than key fields, invalid log data, and completing missing fields. The embodiments of this specification do not limit this.
[0045] In the embodiments of this specification, data cleansing and screening of risk business log data can further reduce data redundancy and invalidity, ensuring data quality for subsequent processing, avoiding misjudgments due to invalid data, and improving the efficiency and accuracy of subsequent risk monitoring. Furthermore, timely completion of missing fields in log data ensures data integrity and consistency, providing more reliable data support for subsequent risk analysis and processing.
[0046] Step 104: Based on the set risk strategy, risk monitoring is performed on the risk request behavior of each object within the risk monitoring time window to determine the object risk type of each object within the risk monitoring time window.
[0047] Specifically, a risk strategy is a preconfigured strategy for determining risk for an object. For example, a risk strategy might be set based on the number of risk behaviors reaching a risk threshold within a risk monitoring window, or when risk behavior characteristics match a pre-set risk behavior pattern. In practice, the formulation of risk strategies should comprehensively consider factors such as business scenarios, risk types, and historical data to ensure the accuracy and effectiveness of risk assessments.
[0048] The risk monitoring time window is a core concept in the risk assessment system. It is used to define the temporal and spatial scope of risk analysis. By dividing the continuous event stream into limited time periods, it enables accurate identification and response to risky behaviors. For example, the risk monitoring time window can be 1 day, 2 days, 1 week, or half a month.
[0049] The object risk type refers to whether the object has a risk within the risk monitoring time window. The object risk type can include risk exists and risk does not exist.
[0050] In actual implementation, risk business logs, that is, risk request behaviors of each object, can be accessed in real time. The risk request behaviors of each object can be counted according to the risk monitoring time window. Based on the statistical results and the set risk strategy, the object risk type of each object can be determined.
[0051] In an optional implementation of this embodiment, the method is applied to a distributed risk assessment system. Based on a set risk strategy, risk monitoring is performed on risk request behaviors of each object within a risk monitoring time window, and the object risk type of each object within the risk monitoring time window is determined, including: Dividing each object into at least one group of objects to be monitored; Dispatching at least one group of objects to be monitored to at least one risk determination node in the distributed risk determination system; The target risk determination node is used to monitor the risk request behavior of the target object group within the risk monitoring time window, and the object risk type of each object in the target object group within the risk monitoring time window is determined, wherein the target risk determination node is any risk determination node in the distributed risk determination system, and the target object group is the group of objects to be monitored that is scheduled to the target risk determination node.
[0052] The embodiments of this specification can be applied to a distributed risk assessment system. For example, the distributed risk assessment system can be a Flink cluster, configured with sufficient computing resources to process real-time risk business log data. The Flink cluster can receive risk business log data transmitted from the SLS and perform real-time processing, leveraging the high throughput and low latency of the Flink cluster to ensure efficient real-time processing. Of course, in actual implementation, the distributed risk assessment system can use other distributed frameworks, such as stream processing frameworks or batch processing frameworks, in addition to the Flink cluster, but this embodiment of this specification does not limit this.
[0053] In actual implementation, the distributed risk assessment system may include a management node and a working node. The management node may receive risk request behaviors of each object (i.e., risk business log data), group each risk request behavior according to the object, obtain at least one group of objects to be monitored, and dispatch different groups of objects to be detected to different risk assessment nodes (i.e., working nodes). Each risk assessment node analyzes the risk request behaviors of each object in its group of objects to be monitored and determines the object risk type of each object in its group of objects to be monitored.
[0054] In the embodiments of this specification, the objects that need to be monitored can be grouped through a distributed risk assessment system, different object groups can be dispatched to different risk assessment nodes, and risk monitoring of each object can be performed in parallel, realizing large-scale real-time data processing and ensuring the efficiency of real-time risk monitoring.
[0055] In an optional implementation of this embodiment, a risk policy is set such that the risk behavior count within a risk monitoring time window reaches a risk threshold. Based on the set risk policy, risk monitoring is performed on the risk request behavior of each object within the risk monitoring time window to determine the object risk type of each object within the risk monitoring time window, including: Determine a target object corresponding to a target risk request behavior, wherein the target risk request behavior is any one of the risk request behaviors of each object; Based on the risk monitoring time window and target risk request behavior, the target object's risk behavior is counted; If the risk behavior count reaches the risk threshold, the target object's object risk type is determined to be risky; If the risk behavior count does not reach the risk threshold, the risk behavior count of the target object will continue to be performed within the risk monitoring time window until the risk monitoring time window is reached.
[0056] In actual implementation, taking the pre-configured risk strategy as an example where the risk behavior count within the risk monitoring time window reaches the risk threshold, it is necessary to monitor the risk behavior count of each object within the risk monitoring time window to determine whether the risk threshold is reached and determine the object risk type of each object.
[0057] In specific implementation, for any risk request behavior, its corresponding target object can be determined, and the risk behavior count can be performed within the risk monitoring time window of the target object. If the risk behavior count reaches the risk threshold, it means that the target object has performed too many risk behaviors within the risk monitoring time window, and the object risk type of the target object is determined to be risky; if the risk behavior count does not reach the risk threshold, it means that the target object has performed fewer risk behaviors within the risk monitoring time window, and the user has not currently reached a high risk. At this time, the risk behavior count of the target object can continue to be performed within the risk monitoring time window until the risk monitoring time window is reached, and the monitoring of the target object is stopped, indicating that the target object is a normal user.
[0058] It should be noted that, if applied to a distributed risk determination system, each risk determination node in the distributed risk determination system can perform the above-mentioned risk type determination and monitor whether the corresponding object has risks.
[0059] For example, taking the insurance business as an example, each risk determination node in the distributed risk determination system can calculate the number of insurance purchases of each user within the risk monitoring time window (such as 1 hour). If the number of insurance purchases of a user within 1 hour reaches a preset threshold (for example, 5 times), the user will be marked as a high-risk user, that is, the object risk type is risky.
[0060] In the embodiments of this specification, the number of risky business requests for each object within the risk monitoring time window can be monitored. If the number reaches the risk threshold, the object can be marked as risky, and the risky users can be identified in a timely manner to ensure the timeliness of the object risk assessment.
[0061] In an optional implementation of this embodiment, risk behavior counting is performed on the target object based on the risk monitoring time window and the target risk request behavior, including: Determine the time of action for the target risk request behavior; If the target risk request behavior is the first risk request behavior of the target object, the behavior time of the target risk request behavior is determined as the start time of the risk monitoring time window, and the risk behavior count of the target object is performed; If the target risk request behavior is not the first risk request behavior of the target object, the risk behavior count for the target object will continue.
[0062] In actual implementation, for any target risk request behavior, it is possible to determine whether the target risk request behavior is the first risk request behavior within the risk monitoring time window based on the behavior time of the target risk request behavior. If so, the behavior time of the target risk request behavior is used as the starting time of the risk monitoring time window, and the risk behavior count of the target object is increased by 1. Subsequently, within the risk monitoring time window, if the target object has a risk request behavior, the risk behavior count of the target object will continue to be accumulated. After each count, it is determined whether the current risk behavior count has reached the risk threshold. If the target risk request behavior is not the first risk request behavior of the target object, it means that the target object has accumulated risk behavior counts within the risk monitoring time window, and the counting will continue until the current risk monitoring time window is reached, and the monitoring will be canceled, indicating that there is no risk for the target object within the current risk monitoring time window. If the target object has a risk request behavior after the current risk monitoring time window, the risk monitoring of the next risk monitoring time window will continue.
[0063] For example, assuming the risk threshold is 5 and the risk monitoring window is 10 minutes, user 1 has insurance request 1 at 00:00:10, insurance request 2 at 00:05:00, insurance request 3 at 00:07:10, insurance request 4 at 00:08:30, and insurance request 5 at 00:09:15. Insurance request 1 is the first insurance request in the current risk monitoring window, and its risk behavior count is "1," which does not reach the risk threshold. Monitoring continues within the current risk monitoring window. Insurance request 2 is detected, but it is not the first insurance request in the current risk monitoring window. The risk behavior count continues to accumulate to "2," which does not reach the risk threshold. Monitoring continues within the current risk monitoring window. Similarly, when insurance request 5 is detected, the risk behavior count continues to accumulate to "5," reaching the risk threshold, and user 1 is determined to be at risk.
[0064] Assume that the risk threshold is 5 and the risk monitoring time window is 10 minutes. User 1 has 1 insurance request 1 at 00:00:10, 1 insurance request 2 at 00:08:00, 1 insurance request 3 at 00:09:10, 1 insurance request 4 at 00:15:30, and 1 insurance request 5 at 00:17:15. For insurance request 1, it is the first insurance request in the current risk monitoring time window. At this time, the risk behavior count is "1", which has not reached the risk threshold, and continues to be monitored in the current risk monitoring time window; insurance request 2 is monitored, which is not the first insurance request in the current risk monitoring time window. At this time, the risk behavior count continues to accumulate to "2", which has not reached the risk threshold, and continues to be monitored in the current risk monitoring time window; insurance request 3 is monitored, and the risk behavior count continues to accumulate to "3", which has not reached the risk threshold, and continues to be monitored in the current risk monitoring time window. When monitoring reaches 00:10:00, the risk behavior count is still "3", which has not reached the risk threshold, and monitoring of user 1 is canceled. There is no risk for user 1 in the current risk monitoring time window. At 00:15:30, it was detected that user 1 had an insurance request 4, and the next risk monitoring time window was opened. Insurance request 4 was the first insurance request in the next risk monitoring time window. At this time, the risk behavior count was "1", which did not reach the risk threshold, and monitoring continued in the next risk monitoring time window; insurance request 5 was monitored, which was not the first insurance request in the next risk monitoring time window. At this time, the risk behavior count continued to accumulate to "2", which did not reach the risk threshold, and monitoring continued in the next risk monitoring time window, and so on, indicating that monitoring will continue until 00:20:00.
[0065] In the embodiments of this specification, the risk monitoring time window can be customized, and the risk monitoring time window can be used as the monitoring time period to monitor whether each object has risks in different time periods, avoiding misjudgments caused by long-term risk behavior counting, and ensuring the real-time and accuracy of risk monitoring.
[0066] In an optional implementation of this embodiment, the method further includes: In response to the risk policy configuration request, obtaining risk policy information indicated by the risk policy configuration request, wherein the risk policy information includes at least one of a risk monitoring time window, a risk threshold, and a risk release condition; Based on the risk strategy information, a risk strategy is generated.
[0067] In actual implementation, business personnel can pre-configure risk strategies in the risk assessment system and customize relevant constraints for risk assessment.
[0068] Specifically, business personnel can define at least one of the risk monitoring time window, risk threshold, and risk release conditions as risk strategy information, and initiate a risk strategy configuration request. The risk control system generates a corresponding set risk strategy based on the risk strategy information indicated in the risk strategy configuration request, and subsequently performs risk monitoring on each object based on the set risk strategy.
[0069] It should be noted that business personnel have a certain degree of autonomy and can select at least one element from the risk monitoring time window, risk threshold, and risk release conditions as risk strategy information. For example, the risk monitoring time window can be 10 minutes, 1 day, 1 week, etc.; the risk threshold can be the upper limit of the risk behavior count, such as 5 times; and the risk release condition can be a constraint that changes the object from risky to non-risky, such as automatic release after a set period of time or release after the submission of set materials for review.
[0070] In specific implementations, the risk monitoring time window, risk threshold, and risk release conditions can be dynamically adjusted based on actual business needs. For example, you can customize the configuration to indicate that a user is at risk if they purchase insurance five times within an hour, with the risk valid for seven days. This means that the risk release condition is automatically released after seven days, allowing them to purchase insurance again.
[0071] In the embodiments of this specification, business personnel can independently define risk strategy information such as risk monitoring time windows, risk thresholds, and risk release conditions based on the characteristics and needs of different business scenarios, and quickly respond to changes in the business environment.
[0072] Step 106: Construct and store a risk object set based on each risk object with a risk type.
[0073] It should be noted that the risk object set is a set including various risk objects, similar to a risk "blacklist", and all objects included in the risk object set are risky.
[0074] In actual implementation, after determining the object risk type for each object, a risk object set can be constructed and stored based on each risk object with a risk type. This means filtering out risky users and constructing a risk object set. Subsequently, real-time monitoring can be performed, and each time a risk object is detected, it can be added to the risk object set, thus updating the risk object set.
[0075] In an optional implementation of this embodiment, a risk object set is constructed and stored based on each risk object with a risk type, including: Determine the volume of risky business and determine the appropriate storage system based on the volume; A risk object set is constructed for each risk object with risk according to the object risk type, and the risk object set is stored in an adapted storage system.
[0076] It should be noted that different risky businesses have different business volumes and corresponding storage requirements. Therefore, in actual implementation, the business volume of the risky business can be determined and a storage system suitable for the business volume can be selected.
[0077] The storage system can refer to a database capable of storing risk objects, such as HBase and MySQL. HBase is a distributed, scalable, and open-source NoSQL database that supports massive data storage. It boasts high reliability, high performance, and scalability, making it suitable for storing large amounts of sparse data and commonly used in scenarios such as real-time read and write operations and big data analysis. MySQL is a widely used open-source relational database management system (RDBMS) with high performance, high reliability, ease of use, and low cost. It supports multi-user, multi-threading, and multiple storage engines. It uses Structured Query Language (SQL) for data management and is suitable for applications of all sizes and can be used to store and manage various types of data.
[0078] In actual implementation, the constructed risk object set can be stored in the selected storage system so that the risk objects in the risk object set can be continuously updated in the future. For example, after the risk elimination conditions are met, the corresponding object is removed from the risk object set; after a new risk object is monitored, it is added to the risk object set, etc.
[0079] Furthermore, the storage system storing the risk object set can also provide query and analysis functions for the risk objects. The stored risk object set includes information such as the object identifier and marking time of the risk object.
[0080] For example, records of risky users can be stored in a MySQL database so that the risk control team can query and manage them at any time.
[0081] In the embodiments of this specification, the adapted storage system may be different storage solutions selected based on different business volumes to ensure storage efficiency and security of the risk object set.
[0082] In an optional implementation of this embodiment, after constructing and storing the risk object set based on each risk object having a risk type, the following steps are further included: Determine the corresponding risk control method based on the risk business, where the risk control method is used to indicate the control strategy for each risk object under the risk business; Execute control strategies on each risk object in the risk object set based on the risk control method.
[0083] It should be noted that different risk businesses may correspond to different risk control methods, which refer to strategies for controlling risk objects. For example, risk control methods may include prohibiting risk objects from continuing to request risk businesses and reviewing risk objects.
[0084] In one optional implementation, the risk control method is to prohibit the risk subject from continuing to execute risky business requests. Specifically, in response to a risky business request from a target subject, a determination is made based on a risk subject set whether the target subject is a risk subject. If the target subject is not a risk subject, the risky business request from the target subject can be executed normally. If the target subject is a risk subject, the risky business request from the target subject is directly intercepted and prohibited from continuing to execute the risky business request.
[0085] As an example, taking the risk business as the insurance business, the corresponding risk control method is to prohibit the risk user from continuing to insure. If an insurance request is received from the target user, it can be determined first whether the target user is a user in the risk object set. If not, the target user can be insured normally; if so, the insurance request of the target user is intercepted and the target user is prohibited from insuring.
[0086] In another optional implementation method, the risk control method is to transmit the risk object set to the risk control platform, and the risk control personnel view the information of each risk object in the risk object set through the risk control platform, and further verify and process each risk object.
[0087] It should be noted that different risk businesses can correspond to different risk control methods, and corresponding risk control methods can be used to manage each risk object in the risk object set. Through a complete risk identification and risk control process, risks can be managed more effectively and business security can be improved.
[0088] The embodiments of this specification provide a method for determining object risk, which can collect risk request behaviors of each object in real time, monitor the object risk type of each object within the risk monitoring time window in real time, and promptly add users at risk to the risk object set to ensure the timeliness of object risk determination, thereby ensuring the timeliness of object risk control, and promptly discovering and handling users' risky business behaviors.
[0089] Figure 2 FIG. 1 shows a schematic diagram of a process of determining an object risk according to an embodiment of the present disclosure. Figure 2 As shown, the log service transmits the risk business log data of the risk business node to the risk assessment system, which is configured with corresponding computing resources. The risk business log data is processed by data cleaning, screening, missing field completion, etc. to ensure the quality of the risk business log data. Based on the processed risk business log data, the risk business count of each object within the risk monitoring time window is calculated to determine whether the risk business count reaches the risk threshold. If it reaches the threshold, it is marked as a risky user; if not, monitoring continues. If the current risk monitoring time window of an object ends, the risk monitoring of the object ends, and the object is not marked (or marked as a normal object).
[0090] See also Figure 3 , Figure 3 A flow chart of an object risk control method provided according to an embodiment of the present specification is shown, which specifically includes the following steps 302-306.
[0091] Step 302: In response to the risk business request of the target object, determine whether the target object is a risk object based on a risk object set, wherein the risk object set is constructed based on the above-mentioned object risk determination method.
[0092] Step 304: If the target object is not a risk object, execute the risk service request of the target object.
[0093] Step 306: If the target object is a risky object, intercept the risky service request of the target object.
[0094] It should be noted that when the risk control system receives a risk business request initiated by a target object, it can determine whether the target object is a risk object based on the risk object set. If the judgment result shows that the target object is not a risk object, the risk control system will process the risk business request of the target object normally, that is, allow it to complete the corresponding business operation; if the judgment result shows that the target object is a risk object, the risk control system will immediately take interception measures to prevent the target object from continuing to execute the risk business request, thereby reducing business risks and ensuring the security of the system and other relevant parties.
[0095] Among them, the risk control system and the above-mentioned risk assessment system can be the same system or two independent systems, which can access each other through communication connections to realize object risk control management.
[0096] The embodiments of this specification provide an object risk control method, which enables direct access to a risk object set when a risk business request from a target object is received. The risk object set is based on real-time collection of risk request behaviors of each object, monitored and obtained within a risk monitoring time window, and can indicate risky users in real time. Based on the risk object set, it can be quickly determined whether the target object currently initiating the request is a risk object. If it is not a risk object, the risk business request of the target object is executed. If it is a risk object, the risk business request is directly intercepted, and the user's risk business request is discovered and processed in a timely manner to ensure the timeliness of object risk control.
[0097] The above is a schematic scheme of an object risk control method according to this embodiment. It should be noted that the technical scheme of this object risk control method and the technical scheme of the aforementioned object risk determination method are based on the same concept. For details not described in detail in the technical scheme of the object risk control method, please refer to the description of the technical scheme of the aforementioned object risk determination method.
[0098] The following combined Figure 4 Taking the application of the object risk determination method and object risk control method provided in this specification to the insurance business in the insurance scenario as an example, the object risk determination method and object risk control method are further explained. Figure 4 A flowchart of a processing process of an object risk determination method and an object risk control method provided by an embodiment of this specification is shown, which specifically includes the following steps.
[0099] Step 402: The log service collects insurance log data of each insurance service node and transmits the insurance log data to the distributed risk determination system. The insurance log data records the insurance behavior of each user at each insurance service node.
[0100] Step 404: The management node in the distributed risk assessment system groups the users to obtain at least one user group to be monitored, and dispatches each user group to be monitored to a different risk assessment node.
[0101] Step 406: The risk determination node in the distributed risk determination system performs data cleaning, screening, missing field completion and other data processing on the insurance log data of each user in the user group to be monitored assigned to it to obtain high-quality insurance log data.
[0102] Step 408: The risk determination node in the distributed risk determination system calculates the number of times each user has been insured within the risk monitoring time window based on high-quality insurance log data, and determines whether the number of times the user has been insured has reached the insurance threshold. If so, the user is marked as a risky user; if not, monitoring continues. If the current risk monitoring time window of the user ends, the risk monitoring of the user ends, and the user is not marked (or marked as a normal user).
[0103] Step 410: The risk determination node in the distributed risk determination system adds the monitored risky users to the risky user set stored in the storage system in real time.
[0104] Step 412: If the risk control system receives the insurance request from the target user, it accesses the storage system to determine whether the target user is a risky user in the risk user set. If not, the target user can be insured normally; if so, the insurance request of the target user is intercepted and the target user is prohibited from being insured.
[0105] By applying the embodiments of this specification, it is possible to collect the insurance behavior of each user in real time, monitor in real time whether each user is a risky user within the risk monitoring time window, and promptly add risky users to the risky user set to ensure the timeliness of risk judgment. When receiving the insurance request of the target user, it is possible to directly access the risky user set, directly intercept the insurance request of the risky user, promptly discover and process the insurance request of the risky user, and ensure the timeliness of risk control.
[0106] Corresponding to the above method embodiment, this specification also provides an object risk determination device embodiment, Figure 5 FIG1 shows a schematic diagram of the structure of an object risk determination device provided by an embodiment of this specification. Figure 5 As shown, the device includes: A collection module 502 is configured to collect risk business log data of at least one risk business node, wherein the risk business log data records risk request behaviors of each object at each risk business node; The monitoring module 504 is configured to perform risk monitoring on the risk request behavior of each object within the risk monitoring time window based on the set risk strategy, and determine the object risk type of each object within the risk monitoring time window; The construction module 506 is configured to construct and store a risk object set according to each risk object with a risk type.
[0107] Optionally, the risk strategy is set to the risk behavior count within the risk monitoring time window reaches the risk threshold; the monitoring module 504 is further configured to: Determine a target object corresponding to a target risk request behavior, wherein the target risk request behavior is any one of the risk request behaviors of each object; Based on the risk monitoring time window and target risk request behavior, the target object's risk behavior is counted; If the risk behavior count reaches the risk threshold, the target object's object risk type is determined to be risky; If the risk behavior count does not reach the risk threshold, the risk behavior count of the target object will continue to be performed within the risk monitoring time window until the risk monitoring time window is reached.
[0108] Optionally, the monitoring module 504 is further configured to: Determine the time of action for the target risk request behavior; If the target risk request behavior is the first risk request behavior of the target object, the behavior time of the target risk request behavior is determined as the start time of the risk monitoring time window, and the risk behavior count of the target object is performed; If the target risk request behavior is not the first risk request behavior of the target object, the risk behavior count for the target object will continue.
[0109] Optionally, the construction module 506 is further configured to: Determine the volume of risky business and determine the appropriate storage system based on the volume; A risk object set is constructed for each risk object with risk according to the object risk type, and the risk object set is stored in an adapted storage system.
[0110] Optionally, the method is applied to a distributed risk determination system, and the monitoring module 504 is further configured to: Dividing each object into at least one group of objects to be monitored; Dispatching at least one group of objects to be monitored to at least one risk determination node in the distributed risk determination system; The target risk determination node is used to monitor the risk request behavior of the target object group within the risk monitoring time window, and the object risk type of each object in the target object group within the risk monitoring time window is determined, wherein the target risk determination node is any risk determination node in the distributed risk determination system, and the target object group is the group of objects to be monitored that is scheduled to the target risk determination node.
[0111] Optionally, the device further includes a configuration module configured to: In response to the risk policy configuration request, obtaining risk policy information indicated by the risk policy configuration request, wherein the risk policy information includes at least one of a risk monitoring time window, a risk threshold, and a risk release condition; Based on the risk strategy information, a risk strategy is generated.
[0112] Optionally, the apparatus further includes a processing module configured to do at least one of the following: Based on the key fields corresponding to the risk monitoring, the risk business log data is cleaned, and other fields except the key fields in the risk business log data are screened out to obtain the first update log data; Based on the key fields corresponding to the risk monitoring and / or the set risk strategy, invalid log data in the risk business log data is filtered out to obtain second update log data; Based on the key fields corresponding to risk monitoring and / or the set risk strategy, determine whether there is log data with missing set fields in the risk business log data. If so, complete the set fields for the log data with missing set fields to obtain third updated log data.
[0113] Optionally, the device further includes a second execution module configured to: Determine the corresponding risk control method based on the risk business, where the risk control method is used to indicate the control strategy for each risk object under the risk business; Execute control strategies on each risk object in the risk object set based on the risk control method.
[0114] The embodiments of this specification provide an object risk determination device that can collect risk request behaviors of each object in real time, monitor the object risk type of each object within the risk monitoring time window in real time, and promptly add risky users to the risk object set to ensure the timeliness of object risk determination, thereby ensuring the timeliness of object risk control, and promptly discovering and handling users' risky business behaviors.
[0115] The above is a schematic diagram of an object risk determination device according to this embodiment. It should be noted that the technical solution of this object risk determination device and the technical solution of the aforementioned object risk determination method are based on the same concept. For details not described in detail in the technical solution of the object risk determination device, please refer to the description of the technical solution of the aforementioned object risk determination method.
[0116] Corresponding to the above method embodiment, this specification also provides an object risk control device embodiment, Figure 6 FIG1 shows a schematic diagram of the structure of an object risk control device provided by an embodiment of this specification. Figure 6 As shown, the device includes: A determination module 602 is configured to determine whether the target object is a risk object based on a risk object set in response to a risk business request of the target object, wherein the risk object set is constructed based on the above-mentioned object risk determination method; A first execution module 604 is configured to execute the risk business request of the target object if the target object is not a risk object; The interception module 606 is configured to intercept the risky service request of the target object if the target object is a risky object.
[0117] An embodiment of the present specification provides an object risk control device, which enables direct access to a risk object set when a risk business request from a target object is received. The risk object set is based on real-time collection of risk request behaviors of each object, monitored within a risk monitoring time window, and can indicate risky users in real time. Based on the risk object set, it can be quickly determined whether the target object currently initiating the request is a risk object. If it is not a risk object, the risk business request of the target object is executed. If it is a risk object, the risk business request is directly intercepted, and the user's risk business request is discovered and processed in a timely manner to ensure the timeliness of object risk control.
[0118] The above is a schematic diagram of an object risk control device according to this embodiment. It should be noted that the technical solution of this object risk control device is based on the same concept as the technical solutions of the aforementioned object risk determination method and object risk control method. For details not described in detail in the technical solution of the object risk control device, please refer to the description of the technical solutions of the aforementioned object risk determination method and object risk control method.
[0119] Figure 7 7. The block diagram of a computing device according to one embodiment of the present disclosure is shown. Components of the computing device 700 include, but are not limited to, a memory 710 and a processor 720. The processor 720 is connected to the memory 710 via a bus 730, and a database 750 is used to store data.
[0120] Computing device 700 also includes an access device 740 that enables computing device 700 to communicate via one or more networks 760. Examples of such networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. Access device 740 may include one or more of any type of network interface (e.g., a network interface controller (NIC)) whether wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, or a near field communication (NFC) interface.
[0121] In one embodiment of the present specification, the above components of the computing device 700 and Figure 7 Other components not shown in the figure may also be connected to each other, for example, via a bus. Figure 7 The computing device structure block diagram shown is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art may add or replace other components as needed.
[0122] Computing device 700 can be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, personal digital assistant, laptop computer, notebook computer, netbook computer, etc.), a mobile phone (e.g., a smartphone), a wearable computing device (e.g., a smartwatch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or personal computer (PC). Computing device 700 can also be a mobile or stationary server.
[0123] The processor 720 is configured to execute the following computer-executable instructions, which, when executed by the processor, implement the steps of the above-mentioned object risk determination method or object risk control method.
[0124] The above is a schematic diagram of a computing device according to this embodiment. It should be noted that the technical solution of this computing device is based on the same concept as the technical solution of the aforementioned object risk determination method or object risk control method. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solution of the aforementioned object risk determination method or object risk control method.
[0125] An embodiment of the present specification further provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the above-mentioned object risk determination method or object risk control method.
[0126] The above is an illustrative embodiment of a computer-readable storage medium. It should be noted that the technical solution of this storage medium is based on the same concept as the technical solution of the aforementioned object risk determination method or object risk control method. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solution of the aforementioned object risk determination method or object risk control method.
[0127] An embodiment of the present specification further provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned object risk determination method or object risk control method.
[0128] The above is an illustrative embodiment of a computer program. It should be noted that the technical solution of this computer program is based on the same concept as the technical solution of the aforementioned object risk determination method or object risk control method. For details not described in detail in the technical solution of the computer program, please refer to the description of the technical solution of the aforementioned object risk determination method or object risk control method.
[0129] The foregoing description of this specification describes specific embodiments. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0130] Computer instructions include computer program code, which may be in source code, object code, executable files, or some intermediate form. Computer-readable media may include any entity or device capable of carrying computer program code, recording media, USB flash drives, removable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunications signals, and software distribution media. It should be noted that the content of computer-readable media may be appropriately expanded or reduced based on the requirements of patent practice. For example, in some jurisdictions, according to patent practice, computer-readable media does not include electric carrier signals or telecommunications signals.
[0131] It should be noted that for the aforementioned method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0132] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0133] The preferred embodiments disclosed above are intended only to help illustrate this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made based on the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.
Claims
1. A method for determining object risk, characterized in that: The method comprises: Collecting risk business log data of at least one risk business node, wherein the risk business log data records risk request behaviors of each object at each risk business node; Based on the set risk strategy, risk monitoring is performed on the risk request behavior of each object within the risk monitoring time window, and the object risk type of each object within the risk monitoring time window is determined; A risk object set is constructed and stored according to each risk object having a risk type.
2. The object risk determination method according to claim 1, characterized in that: The risk strategy is set such that the risk behavior count within the risk monitoring time window reaches a risk threshold; The risk monitoring of the risk request behavior of each object within the risk monitoring time window based on the set risk strategy and determining the object risk type of each object within the risk monitoring time window includes: Determine a target object corresponding to a target risk request behavior, wherein the target risk request behavior is any one of the risk request behaviors of each object; Counting risk behaviors of the target object based on the risk monitoring time window and the target risk request behavior; If the risk behavior count reaches the risk threshold, determining the object risk type of the target object as risky; If the risk behavior count does not reach the risk threshold, the risk behavior count of the target object continues to be performed within the risk monitoring time window until the risk monitoring time window is reached.
3. The object risk determination method according to claim 2, characterized in that: The counting of risk behaviors of the target object based on the risk monitoring time window and the target risk request behavior includes: Determine the time of the target risk request behavior; If the target risk request behavior is the first risk request behavior of the target object, determining the behavior time of the target risk request behavior as the start time of the risk monitoring time window, and counting the risk behaviors of the target object; If the target risk request behavior is not the first risk request behavior of the target object, the risk behavior counting of the target object continues.
4. The object risk determination method according to any one of claims 1 to 3, characterized in that: The step of constructing and storing a risk object set for each risk object having a risk according to the object risk type includes: Determining the volume of risky business, and determining an appropriate storage system based on the volume of business; The risk object set is constructed for each risk object with risk according to the object risk type, and the risk object set is stored in the adapted storage system.
5. The object risk determination method according to any one of claims 1 to 3, characterized in that: The method is applied to a distributed risk determination system. Based on a set risk strategy, risk monitoring is performed on the risk request behavior of each object within a risk monitoring time window, and the object risk type of each object within the risk monitoring time window is determined, including: Dividing the objects into at least one group of objects to be monitored; dispatching the at least one group of objects to be monitored to at least one risk determination node in the distributed risk determination system; The target risk determination node is used to perform risk monitoring on the risk request behavior of the target object group within the risk monitoring time window, and the object risk type of each object in the target object group within the risk monitoring time window is determined, wherein the target risk determination node is any risk determination node in the distributed risk determination system, and the target object group is the group of objects to be monitored that is scheduled to the target risk determination node.
6. The object risk determination method according to any one of claims 1 to 3, characterized in that: The method further comprises: In response to a risk policy configuration request, obtaining risk policy information indicated by the risk policy configuration request, wherein the risk policy information includes at least one of the risk monitoring time window, the risk threshold, and the risk release condition; Based on the risk strategy information, the set risk strategy is generated.
7. The object risk determination method according to any one of claims 1 to 3, characterized in that: After collecting risky business log data of at least one risky business node, the method further includes at least one of the following: Based on the key fields corresponding to the risk monitoring, the risk business log data is cleaned, and other fields except the key fields in the risk business log data are screened out to obtain first update log data; Based on the key fields corresponding to the risk monitoring and / or the set risk strategy, filtering out invalid log data in the risk business log data to obtain second update log data; Based on the key fields corresponding to risk monitoring and / or the set risk strategy, determine whether there is log data with missing set fields in the risk business log data. If so, complete the set fields of the log data with missing set fields to obtain third updated log data.
8. The object risk determination method according to any one of claims 1 to 3, characterized in that: After constructing and storing a risk object set for each risk object having a risk according to the object risk type, the method further includes: Determine a corresponding risk control method based on the risk business, wherein the risk control method is used to indicate the control strategy for each risk object under the risk business; The control strategy is executed on each risk object in the risk object set based on the risk control method.
9. An object risk control method, characterized in that: The method comprises: In response to a risk business request of a target object, determining whether the target object is a risk object based on a risk object set, wherein the risk object set is constructed based on the object risk determination method according to any one of claims 1 to 8; If the target object is not a risk object, executing the risk service request of the target object; In a case where the target object is a risky object, the risky service request of the target object is intercepted.
10. An object risk determination device, characterized in that: The device comprises: a collection module configured to collect risk business log data of at least one risk business node, wherein the risk business log data records risk request behaviors of each object at each risk business node; a monitoring module configured to perform risk monitoring on the risk request behavior of each object within a risk monitoring time window based on a set risk strategy, and determine an object risk type of each object within the risk monitoring time window; The construction module is configured to construct and store a risk object set according to each risk object with risk type.
11. An object risk control device, characterized in that: The device comprises: a determination module configured to, in response to a risk business request of a target object, determine whether the target object is a risk object based on a risk object set, wherein the risk object set is constructed based on the object risk determination method according to any one of claims 1 to 8; a first execution module, configured to execute the risk service request of the target object if the target object is not a risk object; The interception module is configured to intercept the risky service request of the target object if the target object is a risky object.
12. A computing device, characterized in that include: memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the object risk determination method according to any one of claims 1 to 8 or the object risk control method according to claim 9 are implemented.
13. A computer-readable storage medium, characterized in that It stores computer-executable instructions, which, when executed by a processor, implement the steps of the object risk determination method described in any one of claims 1 to 8 or the object risk control method described in claim 9.
14. A computer program product, characterized in that The method comprises a computer program / instruction, which, when executed by a processor, implements the steps of the object risk determination method according to any one of claims 1 to 8 or the object risk control method according to claim 9.
Citation Information
Cited By
Object set sealing convergence risk management method and device and storage medium
CN122507659A