Transaction link risk intelligent monitoring method and system based on knowledge graph construction

By using knowledge graph-based dynamic analysis and real-time monitoring, the problems of slow response speed and information lag in existing power trading monitoring methods have been solved, enabling efficient and accurate risk identification and early warning of the power trading chain, and improving the stability and security of the system.

CN120653512BActive Publication Date: 2025-10-21STATE GRID JIANGSU ELECTRIC POWER CO LTD MARKETING SERVICE CENT
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511156290.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-19
Publication Date
2025-10-21
Estimated Expiration
2045-08-19

AI Technical Summary

Technical Problem

Existing power trading monitoring methods cannot reflect the dynamic changes of the system in real time. Reliance on static time records leads to slow response speed. Single point failures of relay servers affect overall monitoring. Log embedding is lagging and static link diagrams cannot reflect the dynamic interaction of nodes. The fusion of multi-source semantic information is insufficient, making it difficult to meet the real-time monitoring needs of high-frequency trading environments.

Method used

Build transaction links based on knowledge graphs, obtain multi-dimensional data of transaction platforms in real time, dynamically analyze transaction success rate, frequency and resource utilization, identify abnormal nodes by calculating fluctuation values ​​and synchronization, adjust monitoring thresholds to identify risk nodes, and realize dynamic monitoring and risk warning.

Benefits of technology

It improves the real-time and accuracy of transaction link monitoring, can timely detect potential risks, optimize resource allocation and response efficiency, ensure the stability and security of transaction links, and provide strong decision-making support.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120653512B_ABST
    Figure CN120653512B_ABST
Patent Text Reader

Abstract

The application discloses a transaction link risk intelligent monitoring method and system based on a knowledge graph, and the method comprises the following steps: constructing a knowledge graph by taking each transaction platform in a transaction link as a monitoring node; connecting the monitoring nodes based on a transaction success rate to form a graph edge; determining a temporary node according to the number of connected graph edges; determining a focus node according to the transaction frequency and target access frequency of the temporary node; determining an abnormal node according to the transaction success rate, resource utilization rate change fluctuation value and focus node; determining a risk node according to the transaction success rate of the abnormal node; verifying whether the risk node meets a preset node deviation range based on the transaction interruption rate of the risk node, and if yes, outputting the risk node, otherwise, adjusting the success fluctuation threshold or the standard synchronization degree to redetermine the risk node. The application can automatically adjust the monitoring threshold, optimize the sensitivity and ensure accurate early warning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data processing technology and relates to a method and system for intelligently monitoring transaction link risks based on a knowledge graph. Background Art

[0002] With the advancement of power market reforms, the complexity and real-time requirements of power trading are constantly increasing. Traditional power trading monitoring methods are no longer able to fully meet the requirements for efficient management and real-time monitoring of modern power trading systems. Especially with the dynamic changes in power supply and demand, any potential risks or anomalies could lead to power supply interruptions or a decline in user service experience. Therefore, an intelligent monitoring method is urgently needed to improve the efficiency and accuracy of transaction chain monitoring.

[0003] Prior art document 1 (CN111884824A) discloses a transaction link monitoring method, apparatus, device and storage medium, the method comprising: a user terminal generates a transaction identification code corresponding to a transaction request message according to a transaction request message triggered by a user, and saves a transaction record corresponding to the transaction request message in a relational database, the transaction record including the transaction identification code; the user terminal inserts the transaction identification code in the transaction record into the transaction request message to obtain a filled transaction request message, and sends the filled transaction request message to a transit server; the transit server connects to a private network according to the received filled transaction request message to send the filled transaction request message to a private network subsystem; the private network subsystem processes the filled transaction request message, generates a response message and sends the response message to the user terminal via the transit server, the response message including the transaction identification code; and records the time when the user terminal, the transit server and the private network subsystem receive the transaction identification code according to the transaction identification code, so as to monitor the user terminal, the transit server and the private network subsystem.

[0004] The above-mentioned transaction link monitoring method has the following problems: this method relies too much on recording the time when the transaction identification code is received by the user terminal, the transit server and the dedicated network subsystem based on the transaction identification code, which makes it difficult to reflect the dynamic changes of each link in the system in real time. Especially in a high-frequency trading environment, potential delays or anomalies cannot be discovered in time; this method transmits messages through the transit server. If the transit server has insufficient processing capacity or fails, it will affect the overall monitoring effect; this method is mainly based on static time records and has a low response speed to complex trading environments.

[0005] Prior art document 2 (CN115904872A) discloses a transaction link monitoring method, system and storage medium, including: presetting specific text content as a burying point output to a log file to form a burying point-specific log file; on each business system node running instance, reading the burying point-specific log file, and judging its content line by line to determine whether the current line content contains a log burying point mark; if not, returning to the previous step; if so, extracting the subsequent content of the log burying point mark, transmitting it to the database as collected data, and processing it and saving the processing results to the collected data detail table; automatically generating a transaction link diagram based on the data in the table, and combining the attached information to realize transaction link presentation, business volume statistics, monitoring detail query, rule alarm and other processing, which is used for business transaction link monitoring.

[0006] The above-mentioned transaction link monitoring method has the following problems: the method over-relies on log embedding, which has a lag and is difficult to meet the real-time monitoring needs of system behavior; the method statically constructs the link graph, and the static link graph cannot reflect the dynamic interaction relationship between nodes that evolves over time; relying solely on serial numbers to construct the link graph lacks multi-source semantic information fusion and is difficult to reflect the actual transaction path; fixed rules are difficult to adapt to the diversity of abnormal behaviors and are prone to false positives and missed reports. Summary of the Invention

[0007] To address the deficiencies in the prior art, the present invention provides a method and system for intelligently monitoring transaction link risks based on a knowledge graph, which improves monitoring accuracy and response speed by dynamically analyzing multi-dimensional data of transaction links and dynamically adjusting thresholds.

[0008] The present invention adopts the following technical solutions.

[0009] The first aspect of the present invention proposes a method for intelligently monitoring transaction link risks based on a knowledge graph, comprising:

[0010] Build a knowledge graph with each trading platform in the transaction chain as the monitoring node, and obtain the transaction success rate, transaction frequency, target access frequency, transaction interruption rate and resource utilization rate of each monitoring node in real time;

[0011] Calculate the transaction success fluctuation value of any two monitoring nodes based on the transaction success rate, and connect the corresponding two monitoring nodes whose transaction success fluctuation value is less than the success fluctuation threshold to form a graph edge;

[0012] The monitoring nodes whose number of graph edge connections exceeds the connection number threshold are determined as temporary nodes;

[0013] For each temporary node, the change synchronization degree is calculated based on its transaction frequency and target access frequency, and the temporary node with a change synchronization degree less than the standard synchronization degree is determined as a focus node;

[0014] For each node of interest, calculate the fluctuation value of its transaction success rate and resource utilization rate respectively, and identify abnormal nodes based on the fluctuation value of transaction success rate and resource utilization rate;

[0015] Conduct risk and abnormal edge analysis based on the transaction success rate of each abnormal node to identify risky nodes;

[0016] Based on the transaction interruption rate of the risk node, verify whether the risk node meets the preset node deviation range. If so, output the risk node; otherwise, adjust the success fluctuation threshold or standard synchronization degree to re-determine the risk node until the risk node meets the preset node deviation range.

[0017] Preferably, the calculation of transaction success fluctuation values ​​of any two monitoring nodes based on transaction success rates includes:

[0018] For any two monitoring nodes, the standard deviation of their total transaction success rates within the preset connection time is calculated as the transaction success fluctuation value of the corresponding two monitoring nodes.

[0019] Preferably, the step of calculating the change synchronization degree for each temporary node based on its transaction frequency and target access frequency includes:

[0020] (1) For each temporary node, calculate the standard deviation of all transaction frequencies and the standard deviation of target access frequencies at each moment from the initial moment to the preset attention period. The standard deviation of transaction frequency is used as the transaction frequency fluctuation value, and the standard deviation of target access frequency is used as the access frequency fluctuation value. The two sets of transaction frequency fluctuation values ​​and access frequency fluctuation values ​​are constructed.

[0021] (2) Based on the set of transaction frequency fluctuation values, a change curve of the transaction frequency fluctuation values ​​within a preset focus period is drawn to form a transaction frequency fluctuation curve;

[0022] Draw a change curve of the access frequency fluctuation value within a preset attention period according to the set of access frequency fluctuation values ​​to form an access frequency fluctuation curve;

[0023] The similarity between the transaction frequency fluctuation curve and the access frequency fluctuation curve is calculated as the change synchronization degree.

[0024] Preferably, for each node of interest, respectively calculating the transaction success rate fluctuation value and resource utilization rate fluctuation value thereof includes:

[0025] For each node of interest, calculate the difference in its transaction success rate at adjacent moments within the preset anomaly determination time, obtain several success rate change rates, calculate the standard deviation of all obtained success rate change rates from the initial moment to each moment within the preset anomaly determination time, and use the standard deviation of the success rate change rate as the success rate change fluctuation value to form a transaction success rate change fluctuation value set;

[0026] For each node of interest, the difference in resource utilization at adjacent moments within the preset abnormality determination duration is calculated to obtain several utilization change rates. The standard deviation of all utilization change rates obtained from the initial moment to each moment within the preset abnormality determination duration is calculated, and the standard deviation of the utilization change rate is used as the utilization change fluctuation value to form a set of resource utilization change fluctuation values.

[0027] Preferably, the determining of abnormal nodes according to the transaction success rate fluctuation value and the resource utilization rate fluctuation value includes:

[0028] 1) For each node of interest, normalize the success rate change fluctuation value in the transaction success rate change fluctuation value set and the utilization rate change fluctuation value in the resource utilization rate change fluctuation value set to obtain the first change standard value and the second change standard value;

[0029] Calculate the correlation coefficient between the first change standard value and the second change standard value to obtain the change consistency;

[0030] 2) When the change consistency is less than the preset standard consistency, the corresponding focus node is determined to be an abnormal node.

[0031] Preferably, the risk and abnormal edge analysis based on the transaction success rate of each abnormal node to determine the risk node includes:

[0032] For each abnormal node, calculate the standard deviation of its total transaction success rate within the preset risk determination period as the first risk determination fluctuation value;

[0033] Calculate the relative deviation (AB) / B of the first risk determination fluctuation values ​​of any two abnormal nodes as the first fluctuation deviation value;

[0034] When the first fluctuation deviation value is greater than the preset first standard deviation value and a graph edge exists between two corresponding abnormal nodes, the corresponding graph edge is marked as an abnormal edge;

[0035] When the first fluctuation deviation value is greater than the first preset standard deviation value and there is no graph edge between the two corresponding abnormal nodes, the corresponding two abnormal nodes are connected to form an abnormal edge;

[0036] Other cases are cases where abnormal edges are excluded;

[0037] The risk node is determined based on the number of abnormal edges within the next preset risk determination time.

[0038] Preferably, determining the risk node according to the number of abnormal edges within the next preset risk determination time period includes:

[0039] For each abnormal node, calculate the standard deviation of the success rate of all transactions within the next preset risk determination period to form the second risk determination fluctuation value;

[0040] Calculate the relative deviation of the second risk determination fluctuation values ​​of any two abnormal nodes to form a second fluctuation deviation value;

[0041] When the second fluctuation deviation value is less than the preset second standard deviation value and an abnormal edge exists between the corresponding two abnormal nodes, deleting the corresponding abnormal edge;

[0042] Calculate the standard deviation of the number of abnormal edges at each moment within the next preset risk determination period as the abnormal quantity fluctuation value;

[0043] When the abnormal quantity fluctuation value is greater than the preset abnormal quantity fluctuation threshold, the corresponding two abnormal nodes are determined to be risk nodes.

[0044] Preferably, the transaction interruption rate based on the risk node verifies whether the risk node meets the preset node deviation range, and if so, outputs the risk node; otherwise, adjusts the success fluctuation threshold or standard synchronization degree, including:

[0045] For each risk node, calculate the standard deviation of its transaction interruption rate within the preset adjustment period as the interruption rate fluctuation value;

[0046] When the interruption rate fluctuation value is greater than the preset interruption rate fluctuation threshold, the corresponding risk node is marked;

[0047] Calculate the relative deviation between the number of risk nodes marked within the preset adjustment period and the total number of risk nodes to form the node deviation;

[0048] When the node deviation is greater than the maximum value of the preset node deviation range, the success fluctuation threshold is increased according to the relative deviation between the node deviation and the maximum value of the preset node deviation range and the preset adjustment coefficient, as the adjusted success fluctuation threshold;

[0049] When the node deviation is less than the minimum value of the preset node deviation range, the standard synchronization degree is reduced according to the minimum value of the preset node deviation range and the relative deviation of the node deviation and the preset adjustment coefficient to obtain an adjusted standard synchronization degree;

[0050] In other cases, it is considered that the preset node deviation range is met and the risk node is output.

[0051] The second aspect of the present invention proposes an intelligent transaction link risk monitoring system based on a knowledge graph, comprising:

[0052] The data acquisition module is used to build a knowledge graph using each trading platform in the transaction chain as a monitoring node, and obtain the transaction success rate, transaction frequency, target access frequency, transaction interruption rate and resource utilization rate of each monitoring node in real time;

[0053] A node connection module is used to calculate the transaction success fluctuation value of any two monitoring nodes based on the transaction success rate, and connect the corresponding two monitoring nodes whose transaction success fluctuation value is less than the success fluctuation threshold to form a graph edge;

[0054] A temporary node determination module is used to determine a monitoring node whose number of graph edge connections exceeds a connection number threshold as a temporary node;

[0055] A focus node determination module is used to calculate the change synchronization degree of each temporary node based on its transaction frequency and target access frequency, and determine the temporary node with a change synchronization degree less than the standard synchronization degree as a focus node;

[0056] The abnormal node determination module is used to calculate the transaction success rate change fluctuation value and resource utilization rate change fluctuation value of each concerned node, and determine the abnormal node based on the transaction success rate change fluctuation value and resource utilization change fluctuation value;

[0057] The risk node determination module is used to perform risk and abnormal edge analysis based on the transaction success rate of each abnormal node and determine the risk node;

[0058] The verification module is used to verify whether the risk node meets the preset node deviation range based on the transaction interruption rate of the risk node. If so, the risk node is output; otherwise, the success fluctuation threshold or standard synchronization degree is adjusted to re-determine the risk node until the risk node meets the preset node deviation range.

[0059] A third aspect of the present invention provides a terminal, comprising a processor and a storage medium; the storage medium is used to store instructions; and the processor is used to operate according to the instructions to execute the steps of the method.

[0060] A fourth aspect of the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the method when executed by a processor.

[0061] Compared with existing technologies, the present invention offers the following advantages: through dynamic monitoring based on a knowledge graph, it analyzes key indicators of each trading platform in the transaction chain in real time and intelligently identifies potential risks based on the mutual influence between the platforms. It can automatically adjust monitoring thresholds and optimize sensitivity based on changes in factors such as transaction frequency and success rate, resource utilization, and transaction processing capacity, ensuring accurate early warnings. When platform performance anomalies occur, it can promptly adjust monitoring strategies to improve the accuracy and response speed of risk identification. This not only enhances the effectiveness of risk warnings, but also ensures the stability and security of the transaction chain through real-time adjustments and comprehensive analysis, providing strong decision-making support and effectively resolving the problems of low monitoring accuracy and slow response speed caused by static time recording and single-point reliance on transit servers.

[0062] Furthermore, by identifying similarities in transaction success rates between platforms, connections can be established between them. Connecting two nodes when transaction success rate fluctuations are below a preset threshold indicates that these platforms are performing stably and maintaining consistency over time. This is crucial for subsequent risk analysis and monitoring, effectively building a network of node relationships within the transaction chain. Through correlation based on volatility analysis, behavioral patterns between platforms are more clearly presented, ensuring comprehensive monitoring of the entire transaction chain and timely identification of potential risk points.

[0063] Furthermore, by comparing pre-set connection thresholds, we can identify nodes with high relevance within the transaction chain. These nodes occupy a crucial position in the system and significantly impact the overall chain performance. Setting connection thresholds helps the system accurately identify platforms with strong dependencies on other nodes, avoiding indiscriminate treatment of all platforms. This allows the monitoring system to prioritize key nodes and take timely action when anomalies arise.

[0064] Furthermore, by deeply analyzing the fluctuations in transaction frequency and target access frequency of temporary nodes, we can accurately determine which nodes exhibit high volatility and instability, thereby triggering the system's special attention. By using fluctuation values ​​and synchronization calculations, we can filter out potentially abnormal or high-risk nodes from a large number of temporary nodes. The calculation of change synchronization not only captures the correlation between transaction frequency and target access frequency, but also effectively identifies nodes with inconsistent behavior. This ensures the system's accurate identification of abnormal nodes and timely alerts, improving the accuracy of risk monitoring and optimizing resource allocation and risk response efficiency.

[0065] Furthermore, by calculating the fluctuations in transaction success rate and resource utilization, this method can dynamically reflect the performance fluctuations of key nodes in the system, thereby identifying nodes with abnormal fluctuations. The fluctuations in success rate and utilization rate, as two core indicators, are interrelated and together reveal the instability of a node's transaction and resource management. When both fluctuations are abnormal, it indicates a significant performance issue at the node, impacting the stability of the entire link.

[0066] Furthermore, by standardizing the fluctuations in transaction success rates and resource utilization, discrepancies between different metrics and units are eliminated, making anomaly detection more objective and accurate. By calculating the consistency of changes, we can effectively capture the fluctuations in success rates and resource utilization, ensuring more sensitive and accurate identification of abnormal nodes. This enables timely identification of potential risk nodes, providing accurate alerts and warnings, preventing overall service quality degradation caused by system anomalies and improving system stability and availability.

[0067] Furthermore, by calculating the standard deviation and volatility deviation values, it is possible to accurately identify and mark potential risk nodes in the transaction chain, effectively reveal abnormal nodes with large fluctuations in transaction success rates and their interrelationships, and promptly discover factors that may affect the stability of the transaction chain. The use of graph edge analysis can not only enhance the logical correlation between nodes, but also help the system dynamically adjust the risk monitoring threshold, improve warning accuracy, and avoid false positives and missed reports.

[0068] Furthermore, by calculating the second risk determination fluctuation value and the second fluctuation deviation value, we can accurately capture the fluctuations of abnormal edges in the transaction chain, better identifying and removing invalid or non-risky abnormal edges. At the same time, by standardizing the calculation of abnormal quantity fluctuations, we can comprehensively assess the risk concentration in the transaction chain. Changes in transaction success rate, fluctuation deviation value, and abnormal edges directly influence the identification of risk nodes, ensuring that the determination of risk nodes is based on reasonable data fluctuations and correlations rather than isolated individual indicators, enabling more accurate and flexible risk assessment.

[0069] Furthermore, by adjusting the success fluctuation threshold based on changes in the transaction interruption rate of risky nodes, we can effectively respond to dynamic changes in the trading environment, making the system more adaptable and avoiding system imbalances caused by transaction interruptions. At the same time, adjusting the standard synchronization degree can also help maintain the coordination of the transaction chain and avoid abnormal fluctuations caused by excessive node deviation.

[0070] Furthermore, the knowledge graph visualizes each monitoring node and its associated information within the transaction chain, enabling comprehensive monitoring of the entire chain. This layer-by-layer screening improves the accuracy of risk identification and ensures the system's timely response to potential issues. Furthermore, by dynamically adjusting the success fluctuation threshold and standard synchronization, the system's sensitivity can be flexibly adjusted in different situations, improving its adaptability to complex transaction chains. This allows for the effective identification of potential risk nodes, prompting alerts to be issued, minimizing transaction interruptions and losses, and enhancing the stability and security of the transaction chain. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] Figure 1 This is a flowchart of the transaction link risk intelligent monitoring method based on the knowledge graph constructed in this embodiment;

[0072] Figure 2 A decision logic diagram for forming a graph edge for this embodiment;

[0073] Figure 3 A decision logic diagram for determining the focus node for this embodiment;

[0074] Figure 4 This is a schematic diagram of the transaction link risk intelligent monitoring system built based on the knowledge graph in this embodiment. DETAILED DESCRIPTION

[0075] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. The embodiments described in this application are only part of the embodiments of the present invention, not all of them. Based on the spirit of the present invention, other embodiments obtained by ordinary technicians in this field without making creative efforts are all within the scope of protection of the present invention.

[0076] Embodiment 1 of the present invention provides a transaction link risk intelligent monitoring method based on knowledge graph construction, such as Figure 1 Shown, including:

[0077] S1: Build a knowledge graph with each trading platform in the transaction chain as a monitoring node, and obtain the transaction success rate, transaction frequency, target access frequency, transaction interruption rate, and resource utilization rate of each monitoring node in real time;

[0078] Furthermore, multiple trading platforms collaborate within the transaction chain to enhance load capacity and ensure smooth transaction processing. The transaction chain refers to the entire process from user initiation to final transaction completion, encompassing all involved transaction links. To monitor the operational status of each trading platform in real time, the system builds a comprehensive monitoring framework using a basic knowledge graph.

[0079] During the initial construction of the basic knowledge graph, all trading platforms are treated as independent nodes, each representing the basic attributes and status information of a platform or system. Initially, these nodes are unconnected because sufficient data analysis has not yet been performed to identify relationships or mutual influences between them. As real-time data is collected and analyzed, the system begins to calculate correlations between platforms based on metrics such as transaction success rates and transaction frequencies. Graph edges then connect related platform nodes, forming a dynamically updated, complete knowledge graph that reflects the relationships between platforms in the transaction chain.

[0080] This graph automatically captures key performance indicators for each trading platform (monitoring node) in real time through each trading platform's monitoring interface or log system. These indicators include transaction success rate (the percentage of transactions successfully completed), transaction frequency (the number of transactions per unit time), target access frequency (the frequency of user access to the platform), transaction interruption rate (the percentage of transactions not completed due to failures), and resource utilization (platform resource consumption, specifically CPU utilization). Monitoring and analyzing this data helps the system assess the health of each platform in the trading chain in real time, identifying potential issues and implementing optimization adjustments.

[0081] Trading platforms may include core banking systems, third-party payment platforms, securities trading systems, e-commerce platforms, cross-border payment and clearing platforms, digital currency exchanges, trading modules of enterprise ERP systems, and highway ETC settlement platforms. These platforms serve as monitoring nodes, and their transaction frequency, visit volume, resource usage and other indicators change significantly during peak business periods. They are an important data foundation for achieving refined monitoring and risk identification.

[0082] S2: Calculate the transaction success fluctuation value of any two monitoring nodes based on the transaction success rate, and connect the corresponding two monitoring nodes whose transaction success fluctuation value is less than the success fluctuation threshold to form a graph edge;

[0083] Further preferably, two monitoring nodes are connected according to their transaction success rates and a preset success fluctuation threshold to form several graph edges, such as Figure 2 Shown, including:

[0084] Calculate the standard deviation of all transaction success rates within the preset connection time to form the transaction success fluctuation value;

[0085] When the transaction success fluctuation value is less than the preset success fluctuation threshold, two monitoring nodes are connected to form several graph edges.

[0086] The preset connection duration refers to the length of the time window used when calculating the fluctuation value of the transaction success rate between trading platforms. It depends on the platform's transaction processing cycle and the expected monitoring accuracy. It is usually set between 1 hour and 24 hours. In this embodiment, it is set to 6 hours. It can balance real-time monitoring and data stability, ensure that abnormal fluctuations in the short term can be discovered in a timely manner, and avoid overreacting to occasional short-term fluctuations.

[0087] First, the standard deviation of the transaction success rate of the monitoring node (i.e., the trading platform) within the preset connection time is calculated to obtain the transaction success fluctuation value.

[0088] Next, the system compares this fluctuation value with a preset success fluctuation threshold. If the fluctuation value is less than the threshold, it indicates that the transaction success rate fluctuations of the two monitoring nodes remain within a normal range, and the trading performance between the platforms is relatively consistent. The system then connects the two nodes, forming an edge in the graph to indicate the correlation between their transaction success rates.

[0089] By identifying similarities in transaction success rates between platforms, connections can be established between them. Connecting two nodes when transaction success rate fluctuations are below a preset threshold indicates that these platforms are performing stably and maintaining consistency over time. This is crucial for subsequent risk analysis and monitoring, effectively building a network of node relationships within the transaction chain. Through correlation based on volatility analysis, behavioral patterns between platforms are more clearly presented, ensuring comprehensive monitoring of the entire transaction chain and timely identification of potential risk points.

[0090] The preset success fluctuation threshold is a preset standard value used to measure the fluctuation range of the transaction success rate of the trading platform. It depends on the platform's historical trading data and the expected trading fluctuation range. The initial value is usually set between 0% and 10%. In this embodiment, it is set to 5%, which can promptly identify the platform's performance bottlenecks or abnormal fluctuations.

[0091] S3: Determine monitoring nodes whose number of graph edge connections exceeds the connection number threshold as temporary nodes, including:

[0092] When the number is greater than a preset connection number threshold, the monitoring node is determined to be a temporary node to determine a number of temporary nodes.

[0093] The preset connection number threshold refers to the standard value of the number of connections used to determine whether a monitoring node should be regarded as a temporary node when constructing a transaction link knowledge graph. It depends on the degree of dependence between platforms and the relationship density of the nodes that the system wants to focus on. It is usually set between 3 and 10. In this embodiment, it is set to 5, which can ensure that the system gives priority to those nodes with strong associations and influences in the link, thereby improving the ability to identify potential risks and optimizing the allocation of monitoring resources.

[0094] By calculating the number of connections (i.e., the number of graph edges) between each monitoring node (i.e., trading platform) and other nodes, if a node's number of connections exceeds a preset threshold, it is considered a temporary node. These temporary nodes typically indicate strong connections with multiple other nodes in the transaction chain and may be key nodes affecting the stability and performance of the transaction chain. Therefore, further risk analysis and optimization are performed based on these temporary nodes.

[0095] By comparing the pre-set connection threshold, we can identify nodes with high relevance within the transaction chain. These nodes occupy a crucial position in the system and significantly impact the overall chain performance. Setting the connection threshold helps the system accurately identify platforms with strong dependencies on other nodes, avoiding indiscriminate treatment of all platforms. This allows the monitoring system to prioritize key nodes and take timely action when anomalies occur.

[0096] Further preferably, a number of temporary nodes are determined according to the number of graph edges connecting each monitoring node;

[0097] S4: For each temporary node, calculate the change synchronization degree based on its transaction frequency and target access frequency, and determine the temporary node with a change synchronization degree less than the standard synchronization degree as a focus node;

[0098] Further preferably, several nodes of interest are determined according to the transaction frequency, target access frequency and preset standard synchronization of each temporary node, such as Figure 3 Shown, including:

[0099] Calculate the standard deviation of all transaction frequencies at each moment from the initial moment to the preset focus period to form a set of transaction frequency fluctuation values;

[0100] Calculate the standard deviation of all target access frequencies at each moment from the initial moment to the preset attention duration to form the access frequency fluctuation value;

[0101] Based on the set of transaction frequency fluctuation values, a change curve of the transaction frequency fluctuation values ​​within a preset focus period is drawn to form a transaction frequency fluctuation curve;

[0102] Draw a change curve of the access frequency fluctuation value within a preset attention period according to the set of access frequency fluctuation values ​​to form an access frequency fluctuation curve;

[0103] Calculate the cosine similarity of the transaction frequency fluctuation curve and the access frequency fluctuation curve to form the change synchronization;

[0104] When the change synchronization degree is less than the preset standard synchronization degree, the temporary node is determined to be a focus node, so as to determine a number of focus nodes.

[0105] After determining the temporary nodes, the stability and reliability of the nodes are evaluated by calculating the fluctuations of the transaction frequency and target access frequency of these temporary nodes within the preset attention period.

[0106] First, the standard deviation of transaction frequency and target access frequency is calculated to form transaction frequency fluctuation value and access frequency fluctuation value.

[0107] Next, the change curves of these two fluctuation values ​​are drawn to obtain the transaction frequency fluctuation curve and the access frequency fluctuation curve respectively.

[0108] By calculating the cosine similarity of the two curves, we can obtain an indicator to measure the synchronization of their changes - the change synchronization.

[0109] Finally, when the change synchronization degree is less than the preset standard synchronization degree, the temporary node is determined to be a focus node for further monitoring and processing.

[0110] The preset focus period refers to a period of time set during the system monitoring process. It depends on system requirements, data change characteristics, and industry standards. It is usually set between 5 hours and 3 days. In this embodiment, it is set to 24 hours. It can effectively capture the fluctuation patterns of transaction and access activities, ensure that the evaluation results reflect the actual operating conditions, and avoid misjudgments due to abnormal fluctuations in a short period of time.

[0111] By deeply analyzing the fluctuations in transaction frequency and target access frequency of temporary nodes, we can accurately determine which nodes exhibit high volatility and instability, thereby triggering the system's special attention. By calculating fluctuation values ​​and synchronization, we can filter out potentially abnormal or high-risk nodes from a large number of temporary nodes. The calculation of change synchronization not only captures the correlation between transaction frequency and target access frequency, but also effectively identifies nodes with inconsistent behavior. This ensures the system's accurate identification of abnormal nodes and timely alerts, improving the accuracy of risk monitoring and optimizing resource allocation and risk response efficiency.

[0112] The preset standard synchronization degree is a standard value used to measure the synchronization of changes in transaction frequency and target access frequency. It depends on the transaction volume and user access pattern of the platform under normal circumstances, as well as the capacity and processing power of the platform. The initial value is usually set between 0.7 and 1.0. In this embodiment, it is set to 0.85, which can effectively identify potential resource allocation problems or system failures.

[0113] S5: For each node of interest, calculate the transaction success rate change fluctuation value and resource utilization rate change fluctuation value, and determine the abnormal node based on the transaction success rate change fluctuation value and resource utilization change fluctuation value;

[0114] Further preferably, several abnormal nodes are determined based on the transaction success rate and resource utilization rate of each concerned node, including:

[0115] Calculate the difference in transaction success rates at adjacent moments within the preset abnormality determination time period to obtain the success rate change rate;

[0116] Calculate the standard deviation of all success rate change rates from the initial moment to each moment within the preset abnormality determination time period, and use the standard deviation of the success rate change rate as the success rate change fluctuation value to form a transaction success rate change fluctuation value set;

[0117] Calculate the difference in resource utilization between adjacent moments within the preset abnormality determination duration to obtain the utilization change rate;

[0118] Calculate the standard deviation of all utilization rate change rates from the initial moment to each moment within the preset abnormality determination time period, and use the standard deviation of the utilization rate change rate as the utilization rate change fluctuation value to form a resource utilization rate change fluctuation value set;

[0119] Several abnormal nodes are determined based on the success rate change fluctuation value and the utilization rate change fluctuation value.

[0120] The preset anomaly determination duration is the time window used to analyze and determine whether a node has abnormal fluctuations. It depends on business needs, system stability requirements, and data processing capabilities. It is usually set between 10 minutes and 2 hours to accurately capture abnormal trends. In this embodiment, it is set to 30 minutes, which can effectively monitor node performance fluctuations while avoiding misjudgments caused by short-term fluctuations.

[0121] Based on the transaction success rate and resource utilization of each focused node, the system first calculates the rate of change between success rates and resource utilization at adjacent moments within a preset anomaly detection period. The system then calculates the standard deviation of these two rates of change to produce the success rate fluctuation and utilization rate fluctuation values. Based on these two fluctuation values, nodes with significantly larger fluctuations are identified as anomalous nodes. This detailed analysis of the dynamic changes in transaction success rates and resource utilization identifies potentially problematic nodes, providing a basis for further risk warning and optimization.

[0122] By calculating the fluctuations in transaction success rate and resource utilization, this method dynamically reflects the performance fluctuations of key nodes in the system, thereby identifying nodes with abnormal fluctuations. The success rate fluctuation and utilization rate fluctuation are two core indicators that are interrelated and together reveal the instability of a node's transaction and resource management. When both fluctuations are abnormal, it indicates a significant performance issue at the node, impacting the stability of the entire link.

[0123] Specifically, several abnormal nodes are determined based on the success rate change fluctuation value and the utilization rate change fluctuation value, including:

[0124] Normalizing the success rate change fluctuation values ​​in the transaction success rate change fluctuation value set to obtain a first change standard value;

[0125] Normalizing the utilization rate change fluctuation values ​​in the resource utilization rate change fluctuation value set to obtain a second change standard value;

[0126] Calculate the Pearson correlation coefficient between the first change standard value and the second change standard value to obtain the change consistency;

[0127] When the change consistency is less than a preset standard consistency, the focus node is determined to be an abnormal node, so as to determine a number of abnormal nodes.

[0128] The preset standard consistency refers to the threshold standard set when judging whether the transaction success rate and resource utilization fluctuations are consistent. It depends on the system's business needs and specific risk tolerance. It is usually set between 0.5 and 0.8. In this embodiment, it is set to 0.7. It can effectively distinguish abnormal nodes with large differences in success rate and resource utilization fluctuations, ensuring that the system can identify potential risks in a timely manner, avoid excessive alarms or missed reports, and improve monitoring accuracy and system response speed.

[0129] When identifying abnormal nodes, the fluctuation values ​​of transaction success rate and resource utilization are first normalized to obtain standardized change values. This allows data of different units and magnitudes to be measured uniformly, eliminating the impact of dimensionality on the calculation. Next, the correlation coefficient of these two normalized values ​​is calculated to form a change consistency. If the change consistency is lower than the preset standard consistency, it indicates a significant difference in the fluctuations between transaction success rate and resource utilization, and the corresponding monitoring node is then determined to be an abnormal node. Ultimately, the system uses this method to identify abnormal nodes, providing data for subsequent risk prevention and adjustment.

[0130] By standardizing the fluctuations in transaction success rates and resource utilization, we eliminate discrepancies between different metrics and units, making anomaly detection more objective and accurate. By calculating the consistency of changes, we can effectively capture the fluctuations in success rates and resource utilization, ensuring more sensitive and accurate identification of abnormal nodes. This enables timely identification of potential risk nodes, providing accurate alerts and warnings, preventing overall service quality degradation caused by system anomalies and improving system stability and availability.

[0131] S6: Perform risk and abnormal edge analysis based on the transaction success rate of each abnormal node to determine the risk node;

[0132] Further preferably, several risk nodes are determined based on the transaction success rates of any two abnormal nodes, including:

[0133] When determining several abnormal nodes, calculate the standard deviation of all transaction success rates of each abnormal node within the preset risk determination time period to form a first risk determination fluctuation value;

[0134] Calculate the relative deviation (AB) / B of the risk determination fluctuation values ​​of any two abnormal nodes to form the first fluctuation deviation value;

[0135] When the first fluctuation deviation value is greater than the preset first standard deviation value and a graph edge exists between two abnormal nodes, marking the graph edge as an abnormal edge;

[0136] When the first fluctuation deviation value is greater than the first preset standard deviation value and there is no graph edge between the two abnormal nodes, the two abnormal nodes are connected to form an abnormal edge;

[0137] Other cases are cases where abnormal edges are excluded;

[0138] A number of risk nodes are determined based on the number of abnormal edges within the next preset risk determination time.

[0139] The preset risk determination time period refers to the time interval used to evaluate fluctuations in the node transaction success rate when identifying risk nodes. It depends on the timeliness requirements of the system's response to risk changes and the characteristics of the business process. It is usually set between 1 and 5 hours. In this embodiment, it is set to 1.5 hours. It can effectively capture rapid fluctuations in the transaction chain in a short period of time, promptly discover potential risk nodes, and ensure that the system can respond and adjust quickly.

[0140] After identifying several abnormal nodes, the first risk determination fluctuation value is calculated by calculating the standard deviation of the transaction success rate within the preset risk determination period. Next, the relative deviation of the risk determination fluctuation values ​​between any two abnormal nodes is calculated to obtain a first fluctuation deviation value. If this value is greater than the preset first standard deviation value and a graph edge exists between the two abnormal nodes, the edge is marked as an abnormal edge. If there is no graph edge between the two nodes, the two abnormal nodes are connected to form an abnormal edge. Finally, by analyzing the number of abnormal edges, several risky nodes are identified within the next preset risk determination period.

[0141] By calculating the standard deviation and volatility deviation values, we can accurately identify and mark potential risk nodes in the transaction chain, effectively reveal abnormal nodes with large fluctuations in transaction success rates and their interrelationships, and promptly discover factors that may affect the stability of the transaction chain. Using graph edge analysis can not only enhance the logical correlation between nodes, but also help the system dynamically adjust risk monitoring thresholds, improve early warning accuracy, and avoid false positives and missed reports.

[0142] Specifically, several risk nodes are determined based on the number of abnormal edges within the next preset risk determination time, including:

[0143] Calculate the standard deviation of all transaction success rates of each abnormal node within the next preset risk determination time period to form a second risk determination fluctuation value;

[0144] Calculate the relative deviation of the second risk determination fluctuation values ​​of any two abnormal nodes to form a second fluctuation deviation value;

[0145] When the second fluctuation deviation value is less than the preset second standard deviation value and an abnormal edge exists between two abnormal nodes, deleting the corresponding abnormal edge;

[0146] Calculate the standard deviation of the number of abnormal edges at each moment within the next preset risk determination period to form the abnormal number fluctuation value;

[0147] When the abnormal quantity fluctuation value is greater than a preset abnormal quantity fluctuation threshold, it is determined that the corresponding two abnormal nodes are both risk nodes, so as to determine a number of risk nodes.

[0148] The preset second standard deviation value is a threshold used to measure fluctuations between abnormal nodes in the transaction chain. It depends on the fluctuation characteristics of historical data, the actual business scenario, and the risk tolerance. It is usually set between 0.1 and 0.5. In this embodiment, it is set to 0.2, which can effectively distinguish between normal fluctuations and more significant abnormal fluctuations, thereby more accurately identifying risky nodes in the transaction chain.

[0149] The preset abnormal number fluctuation threshold is a standard for evaluating changes in the number of abnormal edges. It depends on the amount of data, the relative stability between nodes, and the needs of the business scenario. It is usually set between 5 and 20. In this embodiment, it is set to 10. This can ensure that changes in the number of abnormalities in the short term will not overly sensitively affect the final risk node identification, thereby reducing misjudgments caused by sudden or accidental events and maintaining the stability of the system.

[0150] During the preset risk determination period, the standard deviation of the transaction success rate of abnormal nodes is calculated to obtain a second risk determination fluctuation value, and then a second fluctuation deviation value is formed based on the fluctuation between abnormal nodes. For abnormal edges whose second fluctuation deviation value is less than the preset second standard deviation value, if the edge exists between two abnormal nodes, the abnormal edge is deleted. At the same time, the standard deviation of the number of abnormal edges is calculated to obtain an abnormal number fluctuation value. When this fluctuation value exceeds the preset abnormal number fluctuation threshold, the abnormal nodes associated with these abnormal edges are determined to be risk nodes, thereby identifying several risk nodes. The relationship between the transaction success rate, fluctuation value, and number of abnormal edges is effectively used to dynamically adjust the risk assessment to further optimize the identification of risk nodes.

[0151] By calculating the second risk determination fluctuation value and the second fluctuation deviation value, we can accurately capture the fluctuations of abnormal edges in the transaction chain, better identifying and removing invalid or non-risky abnormal edges. Furthermore, by standardizing the calculation of abnormal quantity fluctuations, we can comprehensively assess the risk concentration in the transaction chain. Changes in transaction success rate, fluctuation deviation value, and abnormal edges directly influence the identification of risk nodes, ensuring that risk node determination is based on reasonable data fluctuations and correlations rather than isolated individual indicators, enabling more accurate and flexible risk assessment.

[0152] S7: Based on the transaction interruption rate of the risk node, verify whether the risk node meets the preset node deviation range. If so, output the risk node. Otherwise, adjust the success fluctuation threshold or standard synchronization degree to re-determine the risk node until the risk node meets the preset node deviation range, including:

[0153] Calculate the standard deviation of the transaction interruption rate to form the interruption rate fluctuation value;

[0154] When the interruption rate fluctuation value is greater than the preset interruption rate fluctuation threshold, the risk node is marked once to form several marked nodes;

[0155] Calculate the relative deviation between the number of marked nodes and the number of risk nodes to form the node deviation;

[0156] When the node deviation is greater than the maximum value of the preset node deviation range, the successful fluctuation threshold is increased according to the relative deviation between the node deviation and the maximum value of the preset node deviation range and the preset adjustment coefficient to form an adjusted successful fluctuation threshold; for example: R'=R×[1+r×(V-Vmax) / Vmax], where R' is the adjusted successful fluctuation threshold, R is the successful fluctuation threshold, r is the preset adjustment coefficient, Vmax is the maximum value of the preset node deviation range, and V is the node deviation.

[0157] When the node deviation is less than the minimum value of the preset node deviation range, the preset standard synchronization degree is reduced based on the minimum value of the preset node deviation range, the relative deviation of the node deviation, and the preset adjustment coefficient to form an adjusted standard synchronization degree. For example: S' = S × [1-r × (Vmin-V) / V], where S' is the adjusted standard synchronization degree, S is the standard synchronization degree, r is the preset adjustment coefficient, Vmin is the minimum value of the preset node deviation range, and V is the node deviation.

[0158] In other cases, it is considered that the preset node deviation range is met, that is, it is within the reasonable range of the preset standard, and the risk node can be output without making any adjustments.

[0159] The preset node deviation range is used to define the interval of allowable node deviation, which depends on the system's setting of risk node deviation tolerance. It is usually set between 0% and 10%. In this embodiment, it is set to 1% to 5%. It can maintain a certain degree of flexibility while avoiding excessive deviations that affect system performance, ensuring the stability of the system under changing conditions.

[0160] The preset adjustment coefficient is a proportional factor used when adjusting system parameters. It determines the adjustment range of the successful fluctuation threshold or standard synchronization when the node deviation exceeds the preset range. It depends on the system's sensitivity to parameter adjustment and the required effect after adjustment. It is usually set between 1 and 10. In this embodiment, it is set to 3. While ensuring flexible adjustment, it can avoid excessive system reaction caused by too frequent adjustments, ensuring a smoother and more effective adjustment process.

[0161] By analyzing the relative deviation between the transaction interruption rate of risky nodes, the number of marked nodes, and the number of risky nodes, the system dynamically adjusts preset parameters (such as the success fluctuation threshold and standard synchronization). First, the standard deviation of the transaction interruption rate is calculated to obtain the interruption rate fluctuation value. If the interruption rate fluctuation value exceeds the preset fluctuation threshold, the risky node is marked. Next, by comparing the relative deviation between the number of marked nodes and the number of risky nodes, a decision is made as to whether to adjust the preset parameters. If the node deviation exceeds the preset range, the success fluctuation threshold is increased by adjusting the coefficient; otherwise, the standard synchronization is reduced.

[0162] By adjusting the success fluctuation threshold based on changes in the transaction interruption rate of risky nodes, we can effectively respond to dynamic changes in the trading environment, making the system more adaptable and avoiding system imbalances caused by transaction interruptions. Furthermore, adjusting the standard synchronization degree can help maintain the coordination of the transaction chain and avoid abnormal fluctuations caused by excessive node deviation.

[0163] The risk node may be re-determined to issue an alert based on the adjusted success fluctuation threshold or the adjusted standard synchronization degree.

[0164] When risk nodes that meet the preset node deviation range are determined based on the adjustment of the successful fluctuation threshold or the adjustment standard synchronization, an alarm module can be used to issue an alarm to all risk nodes, that is, to transmit the alarm through real-time communication methods including but not limited to SMS, email, and system interface notifications, to ensure that the risk nodes can be quickly noticed and processed, thereby effectively reducing potential transaction link interruptions or losses.

[0165] In summary, the present invention gradually builds and updates a monitoring graph by monitoring the key indicators of each trading platform in real time. First, the system generates graph edges by connecting the transaction success rates of each platform, forming associations between platforms. Then, based on the number of edges connecting the nodes in the graph, temporary nodes are identified, and the synchronization of their transaction frequency and access frequency is analyzed to determine the nodes of interest. Next, the transaction success rate and resource utilization of the nodes of interest are used to identify abnormal nodes, and by calculating the fluctuations and deviations between nodes, risky nodes are finally screened out. Based on the number of risky nodes and their transaction interruption rate, the system will adjust the success fluctuation threshold or synchronization degree to optimize monitoring sensitivity, promptly identify potential risks, and issue alarm notifications.

[0166] Through dynamic monitoring based on knowledge graphs, key indicators of each trading platform in the transaction chain are analyzed in real time, and potential risks are intelligently identified based on the mutual influence between platforms. The system automatically adjusts monitoring thresholds and optimizes sensitivity based on changes in factors such as transaction frequency and success rate, resource utilization, and transaction processing capacity, ensuring accurate early warnings. When platform performance anomalies occur, monitoring strategies can be adjusted promptly to improve the accuracy and response speed of risk identification. This not only enhances the effectiveness of risk warnings, but also ensures the stability and security of the transaction chain through real-time adjustments and comprehensive analysis, providing strong decision-making support and effectively solving the problems of low monitoring accuracy and slow response speed caused by static time recording and single-point reliance on transit servers.

[0167] The second embodiment of the present invention provides a transaction link risk intelligent monitoring system based on the knowledge graph, which can determine the precise risk nodes through dynamic layer-by-layer judgment and issue an alarm. Figure 4 Shown, including:

[0168] The data acquisition module is used to obtain in real time the transaction success rate, transaction frequency, target access frequency, transaction interruption rate, and resource utilization rate of each monitoring node in the basic knowledge graph constructed with each trading platform as the monitoring node in the transaction chain;

[0169] A node connection module, connected to the data acquisition module, is used to connect two monitoring nodes according to their transaction success rates and a preset success fluctuation threshold to form a number of graph edges;

[0170] A temporary node determination module, connected to the node connection module, is used to determine a number of temporary nodes based on the number of graph edges connecting each monitoring node;

[0171] A focus node determination module, which is connected to the data acquisition module and the temporary node determination module respectively, and is used to determine a number of focus nodes based on the transaction frequency, target access frequency and preset standard synchronization degree of each temporary node;

[0172] An abnormal node determination module, which is connected to the data acquisition module and the focus node determination module respectively, and is used to determine a number of abnormal nodes based on the transaction success rate and resource utilization rate of each focus node;

[0173] A risk node determination module, which is connected to the data acquisition module, the abnormal node determination module, and the node connection module, and is used to determine a number of risk nodes based on the transaction success rate of any two abnormal nodes;

[0174] The verification module is used to verify whether the risk node meets the preset node deviation range based on the transaction interruption rate of the risk node. If so, the risk node is output; otherwise, the success fluctuation threshold or standard synchronization degree is adjusted to re-determine the risk node until the risk node meets the preset node deviation range; specifically, it involves an adjustment module, which is connected to the risk node determination module and the data acquisition module respectively, and is used to adjust the preset success fluctuation threshold according to the number of risk nodes within the preset adjustment period and the transaction interruption rate of each risk node to form an adjusted success fluctuation threshold, or adjust the preset standard synchronization degree to form an adjusted standard synchronization degree; the alarm module is connected to the risk node determination module to issue an alarm for all determined risk nodes.

[0175] The collaborative work of multiple modules enables real-time monitoring and risk management of transaction chains. First, the acquisition module acquires various indicators of monitoring nodes in real time. Then, the connection module connects monitoring nodes based on transaction success rates and preset success fluctuation thresholds, forming graph edges in the basic knowledge graph. The temporary node determination module further identifies temporary nodes based on the number of connections. The focus node determination module identifies focus nodes based on transaction frequency and target access frequency. Next, the abnormal node determination module identifies abnormal nodes based on transaction success rates and resource utilization. The risk node determination module calculates risk nodes based on transaction success rates and, with the help of the adjustment module, adjusts the associated success fluctuation thresholds or standard synchronization levels. Finally, the alarm module issues an alarm after a risk node is identified.

[0176] Through the knowledge graph, each monitoring node and its associated information within the transaction chain is visualized, enabling comprehensive monitoring of the transaction chain. The layered screening of each module improves the accuracy of risk identification and ensures the system's timely response to potential issues. Furthermore, by dynamically adjusting the success fluctuation threshold and standard synchronization, the system's sensitivity can be flexibly adjusted in different situations, improving its adaptability to complex transaction chains. This allows for the effective identification of potential risk nodes, rapid alert issuance, reduced transaction interruptions and losses, and enhanced transaction chain stability and security.

[0177] Embodiment 3 of the present invention provides a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the method.

[0178] Embodiment 4 of the present invention provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the method when executed by a processor.

[0179] Compared with existing technologies, the present invention offers the following advantages: through dynamic monitoring based on a knowledge graph, it analyzes key indicators of each trading platform in the transaction chain in real time and intelligently identifies potential risks based on the mutual influence between the platforms. It can automatically adjust monitoring thresholds and optimize sensitivity based on changes in factors such as transaction frequency and success rate, resource utilization, and transaction processing capacity, ensuring accurate early warnings. When platform performance anomalies occur, it can promptly adjust monitoring strategies to improve the accuracy and response speed of risk identification. This not only enhances the effectiveness of risk warnings, but also ensures the stability and security of the transaction chain through real-time adjustments and comprehensive analysis, providing strong decision-making support and effectively resolving the problems of low monitoring accuracy and slow response speed caused by static time recording and single-point reliance on transit servers.

[0180] Furthermore, by identifying similarities in transaction success rates between platforms, connections can be established between them. Connecting two nodes when transaction success rate fluctuations are below a preset threshold indicates that these platforms are performing stably and maintaining consistency over time. This is crucial for subsequent risk analysis and monitoring, effectively building a network of node relationships within the transaction chain. Through correlation based on volatility analysis, behavioral patterns between platforms are more clearly presented, ensuring comprehensive monitoring of the entire transaction chain and timely identification of potential risk points.

[0181] Furthermore, by comparing pre-set connection thresholds, we can identify nodes with high relevance within the transaction chain. These nodes occupy a crucial position in the system and significantly impact the overall chain performance. Setting connection thresholds helps the system accurately identify platforms with strong dependencies on other nodes, avoiding indiscriminate treatment of all platforms. This allows the monitoring system to prioritize key nodes and take timely action when anomalies arise.

[0182] Furthermore, by deeply analyzing the fluctuations in transaction frequency and target access frequency of temporary nodes, we can accurately determine which nodes exhibit high volatility and instability, thereby triggering the system's special attention. By using fluctuation values ​​and synchronization calculations, we can filter out potentially abnormal or high-risk nodes from a large number of temporary nodes. The calculation of change synchronization not only captures the correlation between transaction frequency and target access frequency, but also effectively identifies nodes with inconsistent behavior. This ensures the system's accurate identification of abnormal nodes and timely alerts, improving the accuracy of risk monitoring and optimizing resource allocation and risk response efficiency.

[0183] Furthermore, by calculating the fluctuations in transaction success rate and resource utilization, this method can dynamically reflect the performance fluctuations of key nodes in the system, thereby identifying nodes with abnormal fluctuations. The fluctuations in success rate and utilization rate, as two core indicators, are interrelated and together reveal the instability of a node's transaction and resource management. When both fluctuations are abnormal, it indicates a significant performance issue at the node, impacting the stability of the entire link.

[0184] Furthermore, by standardizing the fluctuations in transaction success rates and resource utilization, discrepancies between different metrics and units are eliminated, making anomaly detection more objective and accurate. By calculating the consistency of changes, we can effectively capture the fluctuations in success rates and resource utilization, ensuring more sensitive and accurate identification of abnormal nodes. This enables timely identification of potential risk nodes, providing accurate alerts and warnings, preventing overall service quality degradation caused by system anomalies and improving system stability and availability.

[0185] Furthermore, by calculating the standard deviation and volatility deviation values, it is possible to accurately identify and mark potential risk nodes in the transaction chain, effectively reveal abnormal nodes with large fluctuations in transaction success rates and their interrelationships, and promptly discover factors that may affect the stability of the transaction chain. The use of graph edge analysis can not only enhance the logical correlation between nodes, but also help the system dynamically adjust the risk monitoring threshold, improve warning accuracy, and avoid false positives and missed reports.

[0186] Furthermore, by calculating the second risk determination fluctuation value and the second fluctuation deviation value, we can accurately capture the fluctuations of abnormal edges in the transaction chain, better identifying and removing invalid or non-risky abnormal edges. At the same time, by standardizing the calculation of abnormal quantity fluctuations, we can comprehensively assess the risk concentration in the transaction chain. Changes in transaction success rate, fluctuation deviation value, and abnormal edges directly influence the identification of risk nodes, ensuring that the determination of risk nodes is based on reasonable data fluctuations and correlations rather than isolated individual indicators, enabling more accurate and flexible risk assessment.

[0187] Furthermore, by adjusting the success fluctuation threshold based on changes in the transaction interruption rate of risky nodes, we can effectively respond to dynamic changes in the trading environment, making the system more adaptable and avoiding system imbalances caused by transaction interruptions. At the same time, adjusting the standard synchronization degree can also help maintain the coordination of the transaction chain and avoid abnormal fluctuations caused by excessive node deviation.

[0188] Furthermore, the knowledge graph visualizes each monitoring node and its associated information within the transaction chain, enabling comprehensive monitoring of the entire chain. This layer-by-layer screening improves the accuracy of risk identification and ensures the system's timely response to potential issues. Furthermore, by dynamically adjusting the success fluctuation threshold and standard synchronization, the system's sensitivity can be flexibly adjusted in different situations, improving its adaptability to complex transaction chains. This allows for the effective identification of potential risk nodes, prompting alerts to be issued, minimizing transaction interruptions and losses, and enhancing the stability and security of the transaction chain.

[0189] The present disclosure may be a system, method and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0190] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punched card or raised structure in a groove on which instructions are stored, and any suitable combination thereof. As used herein, a computer-readable storage medium is not to be construed as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through an electrical wire.

[0191] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.

[0192] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, the state information of the computer-readable program instructions is used to personalize an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), so that the electronic circuit can execute the computer-readable program instructions, thereby implementing various aspects of the present disclosure.

[0193] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. The intelligent monitoring method for transaction link risks based on knowledge graph is characterized by: include: Build a knowledge graph with each trading platform in the transaction chain as the monitoring node, and obtain the transaction success rate, transaction frequency, target access frequency, transaction interruption rate and resource utilization rate of each monitoring node in real time; Calculating transaction success fluctuation values ​​of any two monitoring nodes based on the transaction success rate, and connecting two corresponding monitoring nodes whose transaction success fluctuation values ​​are less than a success fluctuation threshold to form a graph edge; the calculating transaction success fluctuation values ​​of any two monitoring nodes based on the transaction success rate includes: For any two monitoring nodes, calculate the standard deviation of their total transaction success rates within the preset connection time, and use it as the transaction success fluctuation value of the corresponding two monitoring nodes; The monitoring nodes whose number of graph edge connections exceeds the connection number threshold are determined as temporary nodes; For each temporary node, the change synchronization degree is calculated based on its transaction frequency and target access frequency, and the temporary node with a change synchronization degree less than the standard synchronization degree is determined as a focus node; the calculation of the change synchronization degree for each temporary node based on its transaction frequency and target access frequency includes: (1) For each temporary node, calculate the standard deviation of all transaction frequencies and the standard deviation of target access frequencies at each moment from the initial moment to the preset attention period. The standard deviation of transaction frequency is used as the transaction frequency fluctuation value, and the standard deviation of target access frequency is used as the access frequency fluctuation value. The two sets of transaction frequency fluctuation values ​​and access frequency fluctuation values ​​are constructed. (2) Based on the set of transaction frequency fluctuation values, a change curve of the transaction frequency fluctuation value within the preset attention period is drawn to form a transaction frequency fluctuation curve; based on the set of access frequency fluctuation values, a change curve of the access frequency fluctuation value within the preset attention period is drawn to form an access frequency fluctuation curve; the similarity between the transaction frequency fluctuation curve and the access frequency fluctuation curve is calculated as the change synchronization degree; For each node of interest, the transaction success rate fluctuation value and resource utilization rate fluctuation value are calculated respectively, and abnormal nodes are determined based on the transaction success rate fluctuation value and resource utilization rate fluctuation value; the calculation of the transaction success rate fluctuation value and resource utilization rate fluctuation value for each node of interest includes: For each node of interest, calculate the difference in its transaction success rate at adjacent moments within the preset anomaly determination time, obtain several success rate change rates, calculate the standard deviation of all obtained success rate change rates from the initial moment to each moment within the preset anomaly determination time, and use the standard deviation of the success rate change rate as the success rate change fluctuation value to form a transaction success rate change fluctuation value set; For each node of interest, calculate the difference in resource utilization between adjacent moments within the preset abnormality determination duration to obtain several utilization rate change rates. Calculate the standard deviation of all utilization rate change rates obtained from the initial moment to each moment within the preset abnormality determination duration. Use the standard deviation of the utilization rate change rate as the utilization rate change fluctuation value to form a resource utilization change fluctuation value set. Conduct risk and abnormal edge analysis based on the transaction success rate of each abnormal node to identify risky nodes; Based on the transaction interruption rate of the risk node, verify whether the risk node meets the preset node deviation range. If so, output the risk node; otherwise, adjust the success fluctuation threshold or standard synchronization degree to re-determine the risk node until the risk node meets the preset node deviation range.

2. The method for intelligently monitoring transaction link risks based on knowledge graph construction according to claim 1 is characterized by: Determining abnormal nodes based on transaction success rate fluctuation values ​​and resource utilization rate fluctuation values ​​includes: 1) For each node of interest, normalize the success rate change fluctuation value in the transaction success rate change fluctuation value set and the utilization rate change fluctuation value in the resource utilization rate change fluctuation value set to obtain the first change standard value and the second change standard value; Calculate the correlation coefficient between the first change standard value and the second change standard value to obtain the change consistency; 2) When the change consistency is less than the preset standard consistency, the corresponding focus node is determined to be an abnormal node.

3. The method for intelligently monitoring transaction link risks based on knowledge graph construction according to claim 1 is characterized in that: The risk and abnormal edge analysis based on the transaction success rate of each abnormal node to determine the risk node includes: For each abnormal node, calculate the standard deviation of its total transaction success rate within the preset risk determination period as the first risk determination fluctuation value; Calculate the relative deviation of the first risk determination fluctuation values ​​of any two abnormal nodes as the first fluctuation deviation value; When the first fluctuation deviation value is greater than the preset first standard deviation value and a graph edge exists between two corresponding abnormal nodes, the corresponding graph edge is marked as an abnormal edge; When the first fluctuation deviation value is greater than the first preset standard deviation value and there is no graph edge between the two corresponding abnormal nodes, the corresponding two abnormal nodes are connected to form an abnormal edge; Other cases are cases where abnormal edges are excluded; The risk node is determined based on the number of abnormal edges within the next preset risk determination time.

4. The method for intelligently monitoring transaction link risks based on knowledge graph construction according to claim 3 is characterized by: Determining the risk node according to the number of abnormal edges within the next preset risk determination time period includes: For each abnormal node, calculate the standard deviation of the success rate of all transactions within the next preset risk determination period to form the second risk determination fluctuation value; Calculate the relative deviation of the second risk determination fluctuation values ​​of any two abnormal nodes to form a second fluctuation deviation value; When the second fluctuation deviation value is less than the preset second standard deviation value and an abnormal edge exists between the corresponding two abnormal nodes, deleting the corresponding abnormal edge; Calculate the standard deviation of the number of abnormal edges at each moment within the next preset risk determination period as the abnormal quantity fluctuation value; When the abnormal quantity fluctuation value is greater than the preset abnormal quantity fluctuation threshold, the corresponding two abnormal nodes are determined to be risk nodes.

5. The method for intelligently monitoring transaction link risks based on knowledge graph construction according to claim 1 is characterized in that: The transaction interruption rate based on the risk node verifies whether the risk node meets the preset node deviation range. If so, the risk node is output; otherwise, the success fluctuation threshold or standard synchronization degree is adjusted, including: For each risk node, calculate the standard deviation of its transaction interruption rate within the preset adjustment period as the interruption rate fluctuation value; When the interruption rate fluctuation value is greater than the preset interruption rate fluctuation threshold, the corresponding risk node is marked; Calculate the relative deviation between the number of risk nodes marked within the preset adjustment period and the total number of risk nodes to form the node deviation; When the node deviation is greater than the maximum value of the preset node deviation range, the success fluctuation threshold is increased according to the relative deviation between the node deviation and the maximum value of the preset node deviation range and the preset adjustment coefficient, as the adjusted success fluctuation threshold; When the node deviation is less than the minimum value of the preset node deviation range, the standard synchronization degree is reduced according to the minimum value of the preset node deviation range and the relative deviation of the node deviation and the preset adjustment coefficient to obtain an adjusted standard synchronization degree; In other cases, it is considered that the preset node deviation range is met and the risk node is output.

6. A transaction link risk intelligent monitoring system built based on a knowledge graph, running the method described in any one of claims 1 to 5, characterized in that: The system comprises: The data acquisition module is used to build a knowledge graph using each trading platform in the transaction chain as a monitoring node, and obtain the transaction success rate, transaction frequency, target access frequency, transaction interruption rate and resource utilization rate of each monitoring node in real time; A node connection module is used to calculate the transaction success fluctuation value of any two monitoring nodes based on the transaction success rate, and connect the corresponding two monitoring nodes whose transaction success fluctuation value is less than the success fluctuation threshold to form a graph edge; A temporary node determination module is used to determine a monitoring node whose number of graph edge connections exceeds a connection number threshold as a temporary node; A focus node determination module is used to calculate the change synchronization degree of each temporary node based on its transaction frequency and target access frequency, and determine the temporary node with a change synchronization degree less than the standard synchronization degree as a focus node; The abnormal node determination module is used to calculate the transaction success rate change fluctuation value and resource utilization rate change fluctuation value of each concerned node, and determine the abnormal node based on the transaction success rate change fluctuation value and resource utilization change fluctuation value; The risk node determination module is used to perform risk and abnormal edge analysis based on the transaction success rate of each abnormal node and determine the risk node; The verification module is used to verify whether the risk node meets the preset node deviation range based on the transaction interruption rate of the risk node. If so, the risk node is output; otherwise, the success fluctuation threshold or standard synchronization degree is adjusted to re-determine the risk node until the risk node meets the preset node deviation range.

7. A terminal comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is configured to operate according to the instructions to execute the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Transaction link monitoring method, device and equipment, and storage medium

    CN111884824A

  • Transaction link monitoring method and system and storage medium

    CN115904872A

  • Financial transaction anomaly detection and risk assessment method and device based on artificial intelligence

    CN119693111A

  • Network security threat perception identification response method based on security knowledge graph

    CN120301665A