Flow abnormity monitoring and identifying method and system
By building a process audit network diagram and identifying anomalies in business processes, the problem of process mismatch in the process management system is solved, and the efficiency and flexibility of the system are improved.
Patent Information
- Application Number
- CN202510789881.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-26
AI Technical Summary
During use, the existing business process management system cannot accurately identify whether the pre-set process is skipped or modified reasonably, resulting in a mismatch between actual execution and system processes and reduced efficiency.
By acquiring data on target audit processes and historical audit transactions, we construct a process audit network diagram, identify process anomalies, and adopt a holistic audit path approach to avoid misjudgments.
It improves the efficiency of the business process management system, avoids some processes that require special processing from being misjudged as abnormal, and enhances the flexibility and accuracy of process management.
Smart Images

Figure CN120706855A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of enterprise management, and in particular to a process anomaly monitoring and identification method and system. Background Art
[0002] As the scale of enterprises expands, enterprises often need to use business process management systems to standardize and automate office work. At present, general business process management systems use pre-set processes and submit them for review in the order of the processes. This leads to some enterprises not strictly handling processes or needing to flexibly adjust processes when initially using the above-mentioned business process management systems. In this process, it is impossible to accurately determine which pre-set processes are skipped or modified reasonably, and which pre-set processes are skipped or modified abnormally. As a result, the actual execution of some business processes does not match the system processes, resulting in a reduction in the efficiency of the business process management system during actual use.
[0003] The above content is only used to assist in understanding the technical solution of the present invention and does not constitute an admission that the above content is prior art. Summary of the Invention
[0004] The main purpose of the present invention is to provide a process anomaly monitoring and identification method and system, aiming to improve the efficiency of business process management systems during actual use. To achieve the above purpose, the present invention provides a process anomaly monitoring and identification method, characterized in that the process anomaly monitoring and identification method includes the following steps:
[0005] Acquire audit data of the target audit process to be identified and historical audit transactions before the current moment, the audit data including: audit process data and transaction data of the historical audit transactions;
[0006] Determine a process audit network diagram based on the transaction data and the audit process data;
[0007] The process anomaly identification result is determined based on the target audit process and the process audit network diagram.
[0008] Optionally, the step of determining a process audit network diagram based on the transaction data and the audit process data includes:
[0009] generating a corresponding transaction type according to the transaction data;
[0010] Determine an audit process path for each transaction type according to the audit process data and the transaction type, and obtain a plurality of audit process paths;
[0011] A process audit network diagram is generated based on the multiple audit process paths.
[0012] Optionally, the transaction data includes: tag information and transaction content, and the step of generating a corresponding transaction type according to the transaction data includes:
[0013] Determining a first type of marker according to the marker information;
[0014] Extracting the transaction content and generating corresponding second-category tags;
[0015] The transaction type is determined according to the first type mark and the second type mark.
[0016] Optionally, the step of determining the audit process path for each transaction type according to the audit data and the transaction type includes:
[0017] Determine each audit node passed during the audit process according to the audit process data and the transaction type;
[0018] Determine the path vertices of the audit process path according to the audit node and the transaction type, and obtain a plurality of the path vertices;
[0019] Determine the connection relationship between any two path vertices according to the audit process of the audit process data to obtain a plurality of connection relationships;
[0020] The audit process path corresponding to each transaction type is generated according to the multiple connection relationships.
[0021] Optionally, the step of generating a process audit network diagram according to the plurality of audit process paths includes:
[0022] Splitting each of the review process paths into a plurality of triplets;
[0023] The process audit network diagram is generated according to all the triples.
[0024] Optionally, after the step of generating the process audit network diagram according to all the triples, the step further includes:
[0025] Determining a weight value of each path in the process audit network diagram according to the number of triples;
[0026] The weight value is positively correlated with the number of corresponding triplets.
[0027] Optionally, the step of determining the process anomaly identification result according to the target audit process and the process audit network diagram includes:
[0028] Determine the corresponding target path and target path vertex according to the target review process;
[0029] The process anomaly identification result is determined according to the process audit network diagram, the target path and the target path vertices.
[0030] Optionally, the step of determining the process anomaly identification result according to the process audit network diagram, the target path, and the target path vertex includes:
[0031] Comparing the target path vertex with a preset path vertex preset in the process audit network diagram of the target audit process to obtain a comparison result;
[0032] Reviewing the network diagram and the target path according to the process to determine reachability data of the target path;
[0033] The process anomaly identification result is determined according to the comparison result and the reachability data.
[0034] Optionally, before the step of obtaining the audit data of the target audit process to be identified and the historical audit transactions before the current moment, the step further includes:
[0035] Obtain the enterprise's demand information and build an audit transaction based on the demand information.
[0036] In addition, to achieve the above-mentioned purpose, the present invention further provides a process anomaly monitoring and identification system, characterized in that the process anomaly monitoring and identification system includes:
[0037] An acquisition module, configured to acquire audit data of a target audit process to be identified and historical audit transactions before the current moment, wherein the audit data includes audit process data and transaction data of the historical audit transactions;
[0038] A construction module, configured to determine a process audit network diagram based on the transaction data and the audit process data;
[0039] An identification module is used to determine the process anomaly identification result based on the target audit process and the process audit network diagram.
[0040] The present invention proposes a process anomaly monitoring and identification method, which obtains the audit data of the target audit process to be identified and the historical audit transactions before the current moment, and determines the process audit network diagram based on the transaction data and the audit process data, and determines the process anomaly identification result based on the target audit process and the process audit network diagram. Compared with the traditional method of hard matching between transactions and nodes, the method can accurately determine whether the audit process is abnormal through the overall audit path, avoid processes that are mistakenly judged as abnormal due to the need for special processing procedures, thereby effectively improving the efficiency of the business process management system during actual use. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 It is a structural diagram of a device for monitoring and identifying process anomalies in a hardware operating environment according to an embodiment of the present invention;
[0042] Figure 2 This is a flow chart of a first embodiment of a method for monitoring and identifying process anomalies according to the present invention;
[0043] Figure 3 A schematic flow chart of a second embodiment of the process anomaly monitoring and identification method of the present invention;
[0044] Figure 4 1 is a flow chart of a third embodiment of the process anomaly monitoring and identification method of the present invention;
[0045] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0046] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0047] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of a process anomaly monitoring and identification device in a hardware operating environment involved in an embodiment of the present invention.
[0048] like Figure 1 As shown, the process anomaly monitoring and identification device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, an interactive device 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The interactive device 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the interactive device 1003 may also be connected to the communication bus through a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 may be a high-speed random access memory (RAM) memory, or a stable non-volatile memory (NVM), such as a disk memory. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.
[0049] Those skilled in the art will understand that Figure 1The structure shown in does not constitute a limitation on the process abnormality monitoring and identification device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0050] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating system, a data storage module, a network communication module, a user interface module, and a process anomaly monitoring and identification program.
[0051] exist Figure 1 In the process anomaly monitoring and identification device shown, the network interface 1004 is mainly used for data communication with other devices; the interactive device 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the process anomaly monitoring and identification device of the present invention can be set in the process anomaly monitoring and identification device, and the process anomaly monitoring and identification device calls the process anomaly monitoring and identification program stored in the memory 1005 through the processor 1001, and executes the process anomaly monitoring and identification method provided by the embodiment of the present invention.
[0052] The embodiment of the present invention provides a process abnormality monitoring and identification method, referring to Figure 2 , Figure 2 This is a flow chart of a first embodiment of a process anomaly monitoring and identification method according to the present invention.
[0053] In this embodiment, the process anomaly monitoring and identification method includes:
[0054] Step S1, obtaining audit data of a target audit process to be identified and historical audit transactions before the current moment, wherein the audit data includes audit process data and transaction data of the historical audit transactions;
[0055] In this embodiment, the target audit process includes: various nodes in the process, auditors, the process flow, process tags, etc. The process tags may include priority tags, such as first priority, second priority, and third priority, where the first priority level is more urgent than the second priority level, which in turn is more urgent than the third priority level. Furthermore, it includes information about the reviewers, generally including reviewers of various levels. It should be noted that in this embodiment, the audit data is primarily divided into two categories. The audit process data includes data recorded in the audit process, and may optionally include reviewers, review nodes, review times, and review order. Furthermore, the transaction data primarily includes data on transactions whose data has been reviewed in historical audits before the current time. Optionally, the transaction data is generally document data, such as contracts, financial statements, project documents, corporate rules and regulations, process documents, technical documentation, etc. Optionally, some transactions often require review of various types of non-single document data, such as supplier qualification review, purchase application review, customer qualification review, production plan review, quality control review, and project management review.
[0056] Step S2, determining a process audit network diagram based on the transaction data and the audit process data;
[0057] In this embodiment, a process audit network diagram is generated using audit data from historical audit transactions prior to the current moment. Specifically, each type of process audit is organized into a single audit process diagram. Specifically, the process audit network diagram includes vertices and edges. Vertices may be audit nodes, and edges represent the direction of flow within the audit process. Preferably, the edges are directed edges.
[0058] Step S3: determining the process anomaly identification result according to the target audit process and the process audit network diagram.
[0059] In this embodiment, optionally, by extracting data of the target audit process and generating a corresponding audit path, it is determined whether the audit path exists in the process audit network diagram. When the audit path exists in the process audit network diagram, the process anomaly identification result is determined to be no anomaly. When the audit path does not exist in the process audit network diagram, the process anomaly identification result is determined to be an anomaly.
[0060] In this embodiment, by obtaining the audit data of the target audit process to be identified and the historical audit transactions before the current moment, and determining the process audit network diagram based on the transaction data and the audit process data, and determining the process anomaly identification result based on the target audit process and the process audit network diagram, compared with the traditional method of hard matching of transactions and nodes, it can accurately determine whether the audit process is abnormal through the overall audit path, and avoid processes that are mistakenly judged as abnormal due to the need for special processing procedures, thereby effectively improving the efficiency of the business process management system during actual use.
[0061] Further, based on the above first embodiment, a second embodiment of a process abnormality monitoring and identification method of the present application is proposed. In this embodiment, referring to Figure 3 The step of determining the process audit network diagram based on the transaction data and the audit process data includes:
[0062] Step S21, generating a corresponding transaction type according to the transaction data;
[0063] In this embodiment, the transaction type is determined by obtaining all tags of the transaction data and extracting information corresponding to keywords of the audited content.
[0064] Step S22, determining an audit process path for each transaction type according to the audit process data and the transaction type, to obtain a plurality of audit process paths;
[0065] It should be noted that since transaction data and the audit data are associated, that is, in the process of recording the audit data of historical audit transactions, the audit process data and the transaction data are matched. Therefore, after the corresponding transaction type is generated based on the transaction data, the transaction type and the audit process data are corresponding. Therefore, the audit process path of each transaction type can be determined based on the audit process data and the transaction type. Among them, one transaction type can correspond to one or more audit process paths, and the number of transaction types is also more than one. Therefore, multiple audit process paths can be obtained.
[0066] Step S23: generating a process audit network diagram according to the plurality of audit process paths.
[0067] Specifically, the process audit network graph is constructed by determining corresponding vertices and directed edges of a plurality of the audit process paths.
[0068] Since there is a path rollback process caused by rejection or return modification during the audit process, in other embodiments, the difference between the normal audit process path and the path generated by rejection and return modification can be distinguished, and only the normal audit process path is used to generate the process audit network diagram. Specifically, the normal audit process path and the path generated by rejection and return modification in the audit process path are identified, and the path generated by rejection and return modification is deleted to obtain the normal audit process path as the process audit network diagram. It should be noted that the transaction type corresponding to the target audit process is not constant. During the audit process, the transaction type may be changed due to the adjustment of the priority identifier or content.
[0069] In this embodiment, by generating corresponding transaction types from the transaction data, the same type of approval transactions can be divided into one or more transaction types. For the same transaction type, its review process path can be effectively determined, and the process review network diagram can be determined through multiple review process paths. After constructing the process review network diagram, a variety of selectable review nodes and branches for a transaction type in the review process can be determined. Compared with the traditional single process path, it has higher flexibility in the actual review process, thereby improving the convenience of the review.
[0070] Furthermore, based on the first or second embodiment above, a third embodiment of a process anomaly monitoring and identification method of the present application is proposed. In this embodiment, the transaction data includes: tag information and transaction content, and the step of generating a corresponding transaction type based on the transaction data includes:
[0071] Determining a first type of marker according to the marker information;
[0072] Extracting the transaction content and generating corresponding second-category tags;
[0073] The transaction type is determined according to the first type mark and the second type mark.
[0074] In this embodiment, it should be noted that the tag information here is generally a tag that is already clearly defined in the transaction data, such as a priority tag and a department tag. This tag information can generally be directly obtained when the transaction data is acquired. Therefore, the first-category tag can be directly determined based on the tag information. Of course, in other embodiments, the first-category tag can also be extracted based on the transaction content. For example, when the keyword extracted from the transaction content is a word such as "urgent," the first-category tag corresponding to "urgent" can be determined. The second-category tag is extracted by identifying the transaction content. Examples include key customer information, approval instructions, and contract types. The approval instruction here can be an approval instruction from the general manager or a corresponding authorized reviewer. The transaction type corresponding to the transaction content is determined based on the first-category tag and the second-category tag. A single combination of the same first-category tag and the same second-category tag corresponds one-to-one to the transaction type. Specifically, a tag-to-transaction type mapping table is constructed, which includes tag combinations of multiple tags. A tag combination can include both first-category tags and second-category tags. There is no limit on the number of tags in a tag combination. That is, a tag combination can include only one first-category tag or one second-category tag, or it can include multiple first-category tags and second-category tags. Each tag combination corresponds to one of the transaction types.
[0075] In this embodiment, the first category of tags is determined by the tag information; the transaction content is extracted and the corresponding second category of tags is generated; the transaction type is determined based on the first category of tags and the second category of tags, thereby increasing the number of transaction types obtained by classification, thereby effectively distinguishing between multiple different transaction types.
[0076] Further, refer to Figure 4 The step of determining the audit process path of each transaction type according to the audit process data and the transaction type includes:
[0077] Step S221, determining each audit node passed in the audit process according to the audit process data and the transaction type;
[0078] Specifically, in practice, during the audit process, a reviewer may be at different review nodes in different audit processes. Multiple reviewers may also be assigned to a single review node, and reviewers may process the review content at that node in parallel. Therefore, in this embodiment, the process of determining the review node requires identifying the reviewer and the review content they are processing. This allows the reviewer's opinions during the review process to be used to determine the review node for a known transaction type.
[0079] Step S222, determining the path vertices of the audit process path according to the audit node and the transaction type, and obtaining a plurality of the path vertices;
[0080] It should be noted that the audit nodes here can be: entry nodes, decision nodes, audit nodes, execution nodes, etc. The entry node can be the initiator of the audit content, the decision node can be the department head, manager, chief engineer, etc., and the audit node can be a formal audit of other departments. In this embodiment, there is no restriction on whether there is a machine audit. Specifically, the audit node and the transaction type are combined to form a path vertex. It should be noted that the path vertex here is not directly equal to the audit node. Due to the different transaction types being audited, the corresponding path vertex is actually different. Optionally, the transaction types can include sales contract review, supplier contract review, and emergency supplier contract review. Generally, the legal department needs to set up a subject qualification review node in the process. Both sales contract review and supplier contract review need to go through the subject qualification review node. However, due to the different transaction types, the subject qualification review node of the sales contract review and the subject qualification review node of the supplier contract review correspond to different path nodes. In addition, the supplier contract review and the emergency supplier contract review do not have the same path nodes.
[0081] Step S223, determining a connection relationship between any two path vertices according to the audit process of the audit process data, and obtaining a plurality of connection relationships;
[0082] In this embodiment, whether there is a connection relationship between any two of the path vertices is determined based on the audit process data. The connection relationship can be unidirectional or bidirectional. Specifically, the audit process data in the audit data is extracted, and the audit transfer direction between the path vertices in the audit process is determined based on the audit process data. That is, after completing the audit of the first path vertex, the audit is jumped to the second path vertex, and then it is determined that there is a connection relationship between the first path vertex and the second path vertex, and the direction of the connection relationship is from the first path vertex to the second path vertex. It should be clarified that in the audit process, parallel processes at the same level generally jump to more than one parallel node at the same time after the previous node ends or passes. The processing order on the parallel nodes is not restricted, but all parallel nodes need to pass before jumping to the next node. For this process, in this embodiment, the direction of the connection relationship between the two path vertices is determined by the time sequence of the parallel process nodes. The reason for this operation in this embodiment is that for parallel nodes, the order of processing data is not limited. For example, including parallel audit node A and audit node B, in the audit data of a part of historical audit transactions, it may be that audit node A completes the audit first and audit node B completes the audit later. At this time, a one-way connection relationship can be generated from the path vertex corresponding to audit node A to the path vertex corresponding to audit node B. In the audit data of another part of historical audit transactions, it may be that audit node B completes the audit first and audit node A completes the audit later. At this time, a one-way connection relationship can be generated from the path vertex corresponding to audit node B to the path vertex corresponding to audit node A. Further, after obtaining the process audit network diagram, by calculating the strongly connected components, it can be determined whether audit node A and audit node B belong to a substantially parallel audit relationship. Specifically, when the audit node A and audit node B belong to the same strongly connected component, it is determined that the audit node A and audit node B belong to a parallel audit relationship.
[0083] Step S224: generating the audit process path corresponding to each transaction type according to the plurality of connection relationships.
[0084] It should be noted that the audit process path generated in step S224 has completed the standardization of the path vertices on the path.
[0085] In this embodiment, each audit node passed through during the audit process is determined using the audit process data and the transaction type. The path vertices of the audit process path are then determined based on the audit nodes and transaction types, resulting in multiple path vertices. This effectively standardizes and differentiates the points on the audit process path, meaning that the same audit node will have different path vertices for different transaction types. This differentiation process effectively distinguishes which transactions can execute a certain type of audit path, thereby ensuring that the subsequently generated audit process path is clear. This differentiation increases the number of branching paths in the audit process path, thereby reducing the mismatch between the actual execution of some business processes and the system process.
[0086] Furthermore, based on any of the above embodiments, a fourth embodiment of a process anomaly monitoring and identification method of the present application is proposed, wherein the step of generating a process audit network diagram based on the plurality of audit process paths includes:
[0087] Splitting each of the review process paths into a plurality of triplets;
[0088] The process audit network diagram is generated according to all the triples.
[0089] Specifically, the path vertex in the process audit network diagram is determined based on the first element and the third element of the triple data. If the corresponding path vertex already exists, it does not need to be created. If the corresponding path vertex does not exist, the corresponding path vertex is created. A directed edge is established between the path vertex corresponding to the first element of the triple data and the path vertex corresponding to the third element. If a directed edge with the same direction already exists between the path vertex corresponding to the first element of the triple data and the path vertex corresponding to the third element, the corresponding weight value of the edge is adjusted. Optionally, all the triplets can be directly input into a Neo4j graph database. Common Neo4j graph databases include: JanusGraph, HugeGraph, Dgraph, etc. In this embodiment, the type of graph database is not limited. The process audit network diagram can be directly generated through the Neo4j graph database.
[0090] Furthermore, after the step of generating the process audit network diagram according to all the triples, the step further includes:
[0091] Determining a weight value of each path in the process audit network diagram according to the number of triples;
[0092] The weight value is positively correlated with the number of corresponding triplets.
[0093] Specifically, the number of triplets corresponding to the directed edges between two path vertices is counted, and the larger the number of triplets corresponding to the directed edges between the two path vertices, the larger the corresponding weight value. For example: the process audit network diagram includes a first path vertex and a second path vertex, and the first directed edge statistics of the triplets corresponding to the directed edges from the first path vertex to the second path vertex are counted. The larger the directed edge statistics are during the statistical process, the more it indicates that the process audited in the audit data of the historical audit transactions is mainly from the first path vertex to the second path vertex. The second directed edge statistics of the triplets corresponding to the directed edges from the second path vertex to the first path vertex are counted. When the second directed edge statistics are zero, it means that the process audited in the audit data of the historical audit transactions will not jump to the first path vertex after completing the second path vertex. When the target audit process jumps to the first path vertex after the second path vertex, it can be determined that there is an abnormality in the target audit process. This type of abnormality can be called a review order abnormality. When the number of triplets corresponding to the directed edges between the two path vertices increases, the weight value can be increased by the administrator, or it can be determined based on the number of triplets of all directed edges originating from the first path vertex. Specifically, if the number of triplets of all directed edges originating from the first path vertex is N, and the number of first directed edges is K, the weight value can be the result of dividing K by N. That is, as K increases, the weight value of the corresponding path also increases.
[0094] Furthermore, based on any of the above embodiments, a fifth embodiment of a process anomaly monitoring and identification method of the present application is proposed, wherein the step of determining the process anomaly identification result according to the target audit process and the process audit network diagram includes:
[0095] Determine the corresponding target path and target path vertex according to the target review process;
[0096] The process anomaly identification result is determined according to the process audit network diagram, the target path and the target path vertices.
[0097] Specifically, the identification data and the corresponding keyword data in the target audit process are extracted, the identification data and the first type of mark are matched, and the keyword data and the second type of mark are matched, so as to determine that the target audit process corresponds to the transaction type. The target path vertex is determined according to the transaction type corresponding to the target audit process and the audit node in the target audit process, and the target path is determined according to the audit sequence of the target audit process and the target path vertex. It should be noted that the target path vertex here needs to correspond to the path vertex of the process audit network diagram, which is actually completed by matching the above-mentioned identification data and the first type of mark, and matching the keyword data and the second type of mark. In addition, in contrast, the target path here can be a path that does not exist in the process audit network diagram.
[0098] In this embodiment, the corresponding target path and target path vertex are determined through the target review process, so that the target path and target path vertex can be accurately determined.
[0099] Furthermore, the step of determining the process anomaly identification result according to the process audit network diagram, the target path, and the target path vertex includes:
[0100] Comparing the target path vertex with a preset path vertex preset in the process audit network diagram of the target audit process to obtain a comparison result;
[0101] It should be noted that the comparison results here are used to determine whether the necessary approval nodes exist in the target audit process. Based on the comparison results, it can be determined whether the target audit process has been approved by the corresponding approval nodes. The reachability data is used to determine whether the audit process of the target audit process is the same as the audit path before the current moment, thereby avoiding the decline in audit efficiency caused by setting an unreasonable audit sequence. For example, if the contract terms are reviewed first and then the subject qualifications are reviewed, it may be necessary to change the subject qualifications and review the contract terms again after discovering problems with the subject qualifications. This error in the audit process is an anomaly in the target process to be identified. For the target audit process, for some parallel processes, the calculation of strongly connected components can effectively identify that the processes are parallel, thus avoiding this type of anomaly misidentification during the audit process. In this embodiment, determining strongly connected components can help understand the relationship between each process and optimize the calculation steps of the reachability data. For example, when all vertices of the target path belong to the same strongly connected component, the reachability data can be directly determined to be reachable. Currently, there is no restriction on the type of algorithm for calculating strongly connected components. Common algorithms such as Tarjan algorithm and Kosaraju algorithm can be used to calculate strongly connected components.
[0102] That is, it should be noted that the core goal of constructing a process audit network diagram is to determine which processes are actually parallel and which are serial through the transaction data of historical audit transactions, so as to effectively avoid reducing the probability of misidentification during the process of identifying process anomalies. In this way, the user actively proposes the target audit process and identifies whether it is abnormal, so that the user can flexibly set the process when using the business process management system without having to audit according to a fixed audit route. This allows users to increase the frequency of using the business process management system while improving the user experience of using the business process management system.
[0103] Reviewing the network diagram and the target path according to the process to determine reachability data of the target path;
[0104] The process anomaly identification result is determined according to the comparison result and the reachability data.
[0105] When the target path vertices include all preset path vertices preset in the process audit network diagram of the target audit process, a first comparison result is determined; when the target path vertices do not include all preset path vertices preset in the process audit network diagram of the target audit process, a second comparison result is determined;
[0106] Specifically, for different situations, the steps of comparing the target path vertex with the preset path vertex of the target audit process in the process audit network diagram to obtain a comparison result and determining the reachability data of the target path based on the process audit network diagram and the target path can independently determine the process anomaly identification result, or can also jointly determine the process anomaly identification result. This is actually related to the rigor of process management in the company's management process.
[0107] In this embodiment, the reachability data refers to whether a corresponding path exists for the target path in the process audit network diagram. When a corresponding path exists for the target path in the process audit network diagram, the reachability data is reachable, indicating that the target audit process is free of anomalies.
[0108] When the comparison result is the first comparison result, and the reachability data is reachable, it is determined that there is no abnormality in the target audit process; when the comparison result is the second comparison result, or when the reachability data is unreachable, it is determined that there is an abnormality in the target audit process. In other embodiments, the total probability of the path can also be calculated, and the process abnormality identification result can be determined based on the total probability. Specifically, according to the weight value of each path, the selection probability of the target path corresponding to the target audit process among all the selectable paths is determined, that is, in the audit data corresponding to the historical audit transactions, the more paths that are the same as the target path corresponding to the target audit process, the greater the hanging probability here. Thus, by setting the probability threshold corresponding to the selection probability, it is distinguished whether the process abnormality identification result is abnormal or normal.
[0109] Furthermore, before the step of obtaining the audit data of the target audit process to be identified and the historical audit transactions before the current moment, the step further includes:
[0110] Obtain the enterprise's demand information and build an audit transaction based on the demand information.
[0111] Since different enterprises have different needs, it is necessary to build corresponding audit transactions based on the enterprise's demand information.
[0112] In addition, a process anomaly monitoring and identification system is also proposed, and the process anomaly monitoring and identification system includes:
[0113] An acquisition module, configured to acquire audit data of a target audit process to be identified and historical audit transactions before the current moment, wherein the audit data includes audit process data and transaction data of the historical audit transactions;
[0114] A construction module, configured to determine a process audit network diagram based on the transaction data and the audit process data;
[0115] An identification module is used to determine the process anomaly identification result based on the target audit process and the process audit network diagram.
[0116] The process anomaly monitoring and identification system can implement the steps of any of the above-mentioned process anomaly monitoring and identification method embodiments.
[0117] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.
[0118] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0119] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0120] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A process anomaly monitoring and identification method, characterized in that: The process anomaly monitoring and identification method comprises the following steps: Acquire audit data of the target audit process to be identified and historical audit transactions before the current moment, the audit data including: audit process data and transaction data of the historical audit transactions; Determine a process audit network diagram based on the transaction data and the audit process data; The process anomaly identification result is determined based on the target audit process and the process audit network diagram.
2. The process anomaly monitoring and identification method according to claim 1, characterized in that: The step of determining the process audit network diagram according to the transaction data and the audit process data includes: generating a corresponding transaction type according to the transaction data; Determine an audit process path for each transaction type according to the audit process data and the transaction type, and obtain a plurality of audit process paths; A process audit network diagram is generated based on the multiple audit process paths.
3. The process anomaly monitoring and identification method according to claim 2, characterized in that: The transaction data includes: tag information and transaction content, and the step of generating a corresponding transaction type according to the transaction data includes: Determining a first type of marker according to the marker information; Extracting the transaction content and generating corresponding second-category tags; The transaction type is determined according to the first type mark and the second type mark.
4. The process anomaly monitoring and identification method according to claim 2, characterized in that: The step of determining the audit process path of each transaction type according to the audit data and the transaction type includes: Determine each audit node passed during the audit process according to the audit process data and the transaction type; Determine the path vertices of the audit process path according to the audit node and the transaction type, and obtain a plurality of the path vertices; Determine the connection relationship between any two path vertices according to the audit process of the audit process data to obtain a plurality of connection relationships; The audit process path corresponding to each transaction type is generated according to the multiple connection relationships.
5. The process anomaly monitoring and identification method according to claim 2, characterized in that: The step of generating a process audit network diagram according to the plurality of audit process paths includes: Splitting each of the review process paths into a plurality of triplets; The process audit network diagram is generated according to all the triples.
6. The process anomaly monitoring and identification method according to claim 5, characterized in that: After the step of generating the process audit network diagram according to all the triples, the method further includes: Determining a weight value of each path in the process audit network diagram according to the number of triples; The weight value is positively correlated with the number of corresponding triplets.
7. The process anomaly monitoring and identification method according to any one of claims 1 to 7, characterized in that: The step of determining the process anomaly identification result according to the target audit process and the process audit network diagram includes: Determine the corresponding target path and target path vertex according to the target review process; The process anomaly identification result is determined according to the process audit network diagram, the target path and the target path vertices.
8. The process anomaly monitoring and identification method according to claim 7, characterized in that: The step of determining the process anomaly identification result according to the process audit network diagram, the target path, and the target path vertex includes: Comparing the target path vertex with a preset path vertex preset in the process audit network diagram of the target audit process to obtain a comparison result; Reviewing the network diagram and the target path according to the process to determine reachability data of the target path; The process anomaly identification result is determined according to the comparison result and the reachability data.
9. The process anomaly monitoring and identification method according to any one of claims 1 to 6, characterized in that: Before the step of obtaining the audit data of the target audit process to be identified and the historical audit transactions before the current moment, the method further includes: Obtain the enterprise's demand information and build an audit transaction based on the demand information.
10. A process anomaly monitoring and identification system, characterized in that: The process anomaly monitoring and identification system includes: An acquisition module, configured to acquire audit data of a target audit process to be identified and historical audit transactions before the current moment, wherein the audit data includes audit process data and transaction data of the historical audit transactions; A construction module, configured to determine a process audit network diagram based on the transaction data and the audit process data; An identification module is used to determine the process anomaly identification result based on the target audit process and the process audit network diagram.
Citation Information
Patent Citations
Abnormal early warning method for automatic engineering price auditing data
CN114780619A
Preloading method and device based on request path and electronic equipment
CN116009983A
Official document approval method based on large language model
CN117151623A
Project evaluation and review method and system fused with natural language processing
CN118780767A
Method and system for pattern discovery and real-time anomaly detection based on knowledge graph
US20200073932A1