Risk assessment method and assessment system for multi-dimensional big data analysis

Through multi-dimensional big data analysis methods, financial, production and Internet data are mapped into standardized event streams, early warning signs are generated and risk evolution chain diagrams are constructed, which solves the problem that traditional systems cannot associate data in real time and realizes automatic identification and real-time intervention of cross-system risks.

CN120706887APending Publication Date: 2025-09-26SHENZHEN BANGKEBANG TECH CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510802097.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

Traditional systems are unable to link financial, production and internet public opinion data in real time, resulting in the omission of cross-system risk transmission paths, making it difficult for enterprises to build a proactive risk control system.

Method used

Through multi-dimensional big data analysis methods, financial, production and Internet data are mapped into standardized event streams with time tags, and enhanced event streams with dimension tags are generated. Early warning signs are triggered and risk transmission intensity indicators are calculated. A risk evolution chain diagram is constructed and a graphical intervention plan is generated.

Benefits of technology

It realizes the automatic identification of cross-system risk transmission chains, shortens the risk event response cycle, reduces the cross-system docking cost, and improves the real-time and accuracy of risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120706887A_ABST
    Figure CN120706887A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of enterprise risk management, and relates to a multi-dimensional big data analysis risk assessment method and system, and the method comprises the following steps: obtaining enterprise financial data, production operation data and Internet public data; generating an enhanced event stream with dimension marks; an operation early warning identifier is generated when the operation dimension behavior meets a preset continuity condition, and a public opinion early warning identifier is generated when the public opinion dimension behavior meets a preset negative emotion condition; outputting a cross-dimension risk event report when the index exceeds a preset combination threshold value; tracing a historical enhanced event stream according to the cross-dimension risk event report, and constructing a risk evolution link diagram containing a source data event and an early warning event according to a time inverted sequence; and matching a preset response rule base to generate a graphical intervention scheme containing the risk hotspot position and the processing priority. The problem that a static billboard can only display isolated event points and lacks dynamic description of a risk space-time conduction path is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of enterprise risk management and relates to a risk assessment method and assessment system for multi-dimensional big data analysis. Background Art

[0002] Financial systems, production equipment, and internet public opinion data are typically stored on independent platforms, using different communication protocols and data formats. When equipment failure occurs in a production workshop, traditional systems generate operational alerts, unable to correlate the incident with potential supply chain and capital chain anomalies or market sentiment. This data silo phenomenon results in over 70 percent of cross-system risk transmission paths being missed, and companies often suffer cascading losses due to a failure to promptly address complex risks.

[0003] Traditional solutions rely on single-dimensional threshold alerts. The finance department sets transaction amount fluctuation thresholds to trigger funding alerts, production systems identify operational anomalies based on device status codes, and public opinion monitoring tools identify negative news through keyword matching. When potential risk correlations are discovered, the security team must manually retrieve log records from different systems, compare them, and reconstruct the chain of events using spreadsheets. This approach is fundamentally flawed when dealing with high-frequency, real-time data streams.

[0004] Based on the above problems, static dashboards can only display isolated event points and lack dynamic depiction of the risk transmission path in time and space. These defects make it difficult for enterprises to build an active risk control system in a complex operating environment. Summary of the Invention

[0005] In a first aspect, the present invention provides a risk assessment method for multi-dimensional big data analysis, which adopts the following technical solutions:

[0006] A risk assessment method for multi-dimensional big data analysis includes the following steps:

[0007] S1. Obtain enterprise financial data, production and operation data, and publicly available data on the internet, and map these three types of raw data into standardized event streams with time stamps.

[0008] S2. Financial data-related events are marked as capital dimension behaviors, production and operation data events are marked as operation dimension behaviors, and internet data events are marked as public opinion dimension behaviors, generating an enhanced event stream with dimension tags.

[0009] S3: When the behavior in the capital dimension meets the preset fluctuation threshold, a capital warning mark is generated; when the behavior in the operation dimension meets the preset continuity condition, an operation warning mark is generated; when the behavior in the public opinion dimension meets the preset negative sentiment condition, a public opinion warning mark is generated;

[0010] S4. When two or more warning signs from different dimensions appear within a preset time window, dimension association verification is triggered and the risk transmission intensity index is calculated. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output;

[0011] S5. Based on the cross-dimensional risk event report, the historical event flow is traced back and a risk evolution chain diagram containing source data events and warning events is constructed in reverse chronological order;

[0012] S6. Analyze the node distribution characteristics of the risk evolution link diagram, match the preset response rule library, and generate a graphical intervention plan that includes the risk hotspot location and processing priority.

[0013] A further solution of the present invention maps the three types of raw data into a standardized event stream with a time stamp, comprising the following steps:

[0014] Respectively obtain the account income and expenditure details of the financial system database, the operation warning messages of the production equipment message queue, and the text content of the Internet data interface;

[0015] Convert account income and expenditure details into standard income and expenditure events containing account ID, transaction value, income and expenditure direction, and timestamp; reconstruct operation warning messages into device operation events containing device code, exception type, and timestamp; parse text content into Internet events containing title, content, and timestamp;

[0016] Perform time stamp synchronization on the three types of events, align their original time points to the Coordinated Universal Time standard, arrange them in ascending time order, and output a standardized event stream.

[0017] A further solution of the present invention generates an enhanced event stream with dimension tags, comprising the following steps:

[0018] When there is a preset bank account code prefix, it is marked as a capital dimension behavior; when the equipment code conforms to the preset production equipment numbering rules, it is marked as an operation dimension behavior; when the title text hits the preset risk keyword library and there is no account / equipment code, it is marked as a public opinion dimension behavior;

[0019] Add dimension tag key-value pairs to the standardized event stream to generate an enhanced event stream with dimension tags.

[0020] A further solution of the present invention generates a capital warning mark when the capital dimension behavior meets a preset fluctuation threshold, generates an operation warning mark when the operation dimension behavior meets a preset continuity condition, and generates a public opinion warning mark when the public opinion dimension behavior meets a preset negative emotion condition, including the following steps:

[0021] Calculate the absolute value of the difference between the current transaction amount and the historical average expenditure value. When it exceeds the preset fluctuation threshold calculated based on the historical standard deviation, the capital warning indicator is triggered;

[0022] When abnormal events with the same device code occur more than three times in a row within a preset time segment, the operation warning indicator is triggered;

[0023] When the negative sentiment intensity of the title text exceeds the preset critical value and the frequency of risk keywords is greater than once, the public opinion warning sign is triggered.

[0024] A further solution of the present invention triggers dimension association verification and calculates a risk transmission strength index. When the index exceeds a preset combination threshold, a cross-dimensional risk event report is output, including the following steps:

[0025] Establish a warning indicator timeline to monitor continuous warning events. When warning indicators of different dimensions appear within a preset time window and have the same enterprise entity identifier, activate dimension association verification.

[0026] The risk transmission intensity index is calculated by multiplying the warning intensity values ​​of each dimension. The warning intensity value includes the capital fluctuation ratio, the normalized value of the duration of the operational failure, and the absolute value of the negative sentiment of public opinion.

[0027] When the risk transmission intensity index exceeds the preset combination threshold, a cross-dimensional risk event report containing a set of associated dimension types is output.

[0028] A further solution of the present invention is to construct a risk evolution link diagram including source data events and warning events in reverse chronological order, including the following steps:

[0029] Based on the enterprise entity identifier in the cross-dimensional risk event report, query the historical enhanced event stream database to obtain the source data event;

[0030] Arrange the source data events and warning events in reverse order by timestamp, and construct a risk evolution chain diagram with the earliest source event as the starting point and the cross-dimensional risk event as the end point.

[0031] A further solution of the present invention is to generate a graphical intervention plan including risk hotspot locations and treatment priorities by matching a preset response rule library, including the following steps:

[0032] The spatial density and temporal concentration of warning nodes of the same dimension in the statistical risk evolution link diagram are calculated. The temporal concentration is the inverse of the time difference between the earliest and latest nodes.

[0033] Match the spatial density and temporal concentration with the dimensional combination pattern of the preset response rule base, and calculate the processing priority by multiplying the cumulative risk transmission intensity and the time attenuation coefficient;

[0034] The geometric center coordinates of the high-density node cluster are used as the risk hotspot location, and a graphical intervention plan with priority classification is synthesized.

[0035] A further solution of the present invention is to generate the aging attenuation coefficient, comprising the following steps:

[0036] Obtain the hourly difference between the current moment and the latest warning time mark, add one to the difference and take the inverse as the attenuation coefficient; the graphical intervention plan superimposes a three-dimensional thermal layer on the risk evolution chain diagram.

[0037] In a second aspect, the present invention provides a risk assessment system for multi-dimensional big data analysis, which adopts the following technical solutions:

[0038] The data acquisition module is used to acquire enterprise financial data, production and operation data, and public internet data, and map these three types of raw data into standardized event streams with time stamps.

[0039] The dimension identification module is used to mark financial data-related events as capital dimension behaviors, production and operation data events as operation dimension behaviors, and internet data events as public opinion dimension behaviors, thereby generating enhanced event streams with dimension tags.

[0040] Anomaly detection module, used to generate a capital warning indicator when capital dimension behavior meets the preset fluctuation threshold, generate an operation warning indicator when operation dimension behavior meets the preset continuity condition, and generate a public opinion warning indicator when public opinion dimension behavior meets the preset negative sentiment condition;

[0041] The correlation analysis module is used to execute dimension correlation verification and calculate the risk transmission intensity index when warning signs of two or more different dimensions appear within a preset time window. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output;

[0042] The link construction module is used to perform historical enhancement of event flows based on cross-dimensional risk event reports, and to construct a risk evolution link diagram containing source data events and warning events in reverse chronological order;

[0043] The decision generation module is used to analyze the node distribution characteristics of the risk evolution link diagram, match the preset response rule library, and generate a graphical intervention plan that includes the risk hotspot location and processing priority.

[0044] In summary, the present invention has the following beneficial technical effects:

[0045] 1. Automatically identify single-dimensional risk characteristics such as abnormal income and expenditure in funds, operational obstacles in operations, and negative content in public opinion. This mechanism, based on correlation analysis of multi-dimensional early warning indicators within a preset time window, breaks through the limitations of traditional single-point monitoring. This mechanism can accurately locate cross-system risk transmission chains, such as "production interruptions leading to abnormal capital chains," providing enterprises with complex risk evolution paths that traditional risk control methods cannot capture.

[0046] 2. By multiplying the cumulative risk transmission intensity by the time-attenuation coefficient, a calculation generates a processing priority, ensuring that resource scheduling decisions reflect both the severity of the risk and the urgency of the response. This technology transforms delayed decision-making driven by human experience into real-time intervention driven by data, significantly shortening the response cycle for high-risk incidents.

[0047] 3. A pre-set dimension tagging rule library automatically identifies bank account code characteristics, device physical address rules, and public opinion keyword libraries, eliminating the need for manual configuration of data associations. This design ensures data timeliness while significantly reducing the cost of cross-system integration engineering implementation. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. The drawings are used to provide a further understanding of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0049] Figure 1 A schematic diagram of the flow chart in the embodiment of the present application is disclosed.

[0050] Figure 2 The present invention discloses a schematic structural diagram in an embodiment of the present application. DETAILED DESCRIPTION

[0051] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0052] The following is combined with Figure 1-Figure 2 The preferred embodiments of the present invention are described in detail.

[0053] Refer to the attached Figure 1 As shown, the present invention proposes a risk assessment method for multi-dimensional big data analysis, comprising the following steps:

[0054] S1. Obtain enterprise financial data, production and operation data, and publicly available data on the internet, and map these three types of raw data into standardized event streams with time stamps.

[0055] S2. Financial data-related events are marked as capital dimension behaviors, production and operation data events are marked as operation dimension behaviors, and internet data events are marked as public opinion dimension behaviors, generating an enhanced event stream with dimension tags.

[0056] S3: When the behavior in the capital dimension meets the preset fluctuation threshold, a capital warning mark is generated; when the behavior in the operation dimension meets the preset continuity condition, an operation warning mark is generated; when the behavior in the public opinion dimension meets the preset negative sentiment condition, a public opinion warning mark is generated;

[0057] S4. When two or more warning signs from different dimensions appear within a preset time window, dimension association verification is triggered and the risk transmission intensity index is calculated. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output;

[0058] S5. Based on the cross-dimensional risk event report, the historical event flow is traced back and a risk evolution chain diagram containing source data events and warning events is constructed in reverse chronological order;

[0059] S6. Analyze the node distribution characteristics of the risk evolution link diagram, match the preset response rule library, and generate a graphical intervention plan that includes the risk hotspot location and processing priority.

[0060] In one embodiment of the present invention, step S1 includes the following steps:

[0061] A service agent with multi-protocol adaptability is deployed, accessing the database port of the enterprise financial system, the equipment message queue in the production workshop, and the application program interface port of the internet data platform. Simultaneously, the detailed account income and expenditure stream transmitted by the financial system is converted into standard income and expenditure events, each of which contains the complete transaction account entity, the symbol for the direction of the value change, and the precise time recorded by the server. Messages such as abnormal temperature warnings sent by equipment in the production workshop are extracted, including key equipment numbers and the time the warning was generated, to reconstruct equipment operation events. Public internet data is obtained through a crawler configuration interface, and its text content is analyzed and extracted from the title release time area. The release date information is located in the webpage source file, and structured extraction is performed according to a preset date format template.

[0062] The independent data streams after the above three types of processing perform a unified time mark synchronization step to align the original time points of all events with the Coordinated Universal Time standard; output a continuous event sequence carrying the synchronized standard time mark, forming a standardized event stream with time continuity.

[0063] Among them, the service agent with multi-protocol adaptability refers to a software entity that can simultaneously read the data table records of the SQL relational database of the financial system through the open database connection protocol, subscribe to the binary message packages of the production system through the advanced message queuing protocol, and request the external interface JSON object through the hypertext transfer security protocol.

[0064] Standard income and expenditure events are fixed-structure data combinations converted from financial data. They contain four necessary elements: an account identification string, a floating-point value for numerical changes, a Boolean marker representing income or expenditure, and a time string in the ISO8601 format of the International Organization for Standardization.

[0065] Equipment operation events are standardized structures reconstructed from production data. They contain a string encoding the device's physical address, a label classifying the anomaly type, and the Unix timestamp of the triggering moment recorded by the device's sensors. Time stamp synchronization is unified by subtracting a preset time zone offset from the original local system time value in each event and converting it to Coordinated Universal Time. The standardized event stream is an ordered sequence arranged in ascending order of the converted Coordinated Universal Time. Each element in the sequence is stored as a dictionary of key-value pairs.

[0066] For example, a company deploys the service agent program, connects to the MySQL database of the financial system using an account and password, selects "Transaction Details Table" as the input source, and automatically reads newly added records for the day containing the account name "CNY_ACCT001", the change amount "-85000.00", and the transaction type "Payment".

[0067] The record is mapped to a standard income and expenditure event "{account:"CNY_ACCT001", amount:85000.00, isIncome:false, timestamp:"2023-07-29T09:30:15Z"}"; at the same time, the agent establishes a connection with the RabbitMQ message queue of the production workshop, and receives the temperature warning message "{deviceId:"PLC_Line3", alertCode:"TEMP_OVER", occurTime:1690623120}" sent by the device "PLC_Line3" at 17:32 local time. After the time zone conversion, the device operation event is reconstructed into "{deviceID:"PLC_Line3", alertType:"Overheating shutdown", timestamp:"2023-07-29T09:32:00Z"}"; when the announcement titled "A city issues power restriction notice" is captured from the public news site, by parsing the source code "<spanclass='publish-time'> Extract the release time from the "2023-07-29 09:28" field and convert it to generate the event "{title:"Power Restriction Notice Summary",content:"Industrial Area Peak-Shifting Power Supply...",timestamp:"2023-07-29T01:28:00Z"}";

[0068] Events generated by these three different sources are ultimately added to the event stream queue and sorted by time stamp to form a standardized event stream [public opinion events... → financial events... → equipment events...]. Each node in this event stream carries the universal time indication for subsequent processing steps.

[0069] In one embodiment of the present invention, step S2 includes the following steps:

[0070] Receive the standardized event stream output by step S1, and parse the key-value pairs of each dictionary structure element in the event stream; when the key-value pair contains an account identification string field, check whether the field has a preset bank account code prefix; if a successful prefix match is detected, mark the event as a fund dimension behavior; when the key-value pair contains a device physical address code field, check whether the field complies with the preset production equipment numbering rules; if the equipment number is verified to be valid by the rules, mark the event as an operation dimension behavior; when a title text field appears in the key-value pair and the account identification and device code fields are missing, execute the preset keyword matching process; if the title text hits any entry in the risk keyword library, mark the event as a public opinion dimension behavior; and finally generate an enhanced event stream containing behavior dimension tags.

[0071] The standardized event stream inherits from the ordered event sequence defined in step S1. Each event maintains a key-value dictionary structure and must carry a UTC timestamp. The default bank account code prefix is ​​a combination of pre-defined string features, such as "CNY_ACCT" for a RMB settlement account and "USD_LOAN" for a USD loan account. The account identifier string field refers to the value corresponding to the fixed account key in the standard income and expenditure event generated in step S1. Its structure follows the formula "currency code_account type+numeric number."

[0072] The device physical address code field refers to the deviceID key value inherited from the device operation event in step S1. Its physical address consists of a three-digit sequence: workshop number, production line number, and equipment serial number. The production equipment numbering rule and the preset code verification expression require that the character arrangement pattern must be "three-digit workshop code + hyphen + two-digit production line code + hyphen + four-digit equipment serial number."

[0073] The risk keyword library is a preloaded text file containing a collection of terms. Each line stores a separate keyword, such as "strike," "recall," or "lawsuit." The title text field contains the string corresponding to the standard key name "title" for the internet event in step S1.

[0074] For example, following the standardized event stream generated by the verification example in step S1, when parsing the financial event "{account:"CNY_ACCT001",amount:85000.00,isIncome:false,timestamp:"2023-07-29T09:30:15Z"}", the account key value contains the prefix "CNY_ACCT", which matches the preset bank account code feature, thus marking the fund dimension behavior;

[0075] When parsing the production event "{deviceID:"PLC_Line3",alertType:"Overheat Shutdown",timestamp:"2023-07-29T09:32:00Z"}", the deviceID key value "PLC_Line3" does not conform to the "three-digit-two-digit-four-digit" numbering rule (it should be "101-02-0003"). Since rule validation failed, the operation dimension is not marked. When parsing the public opinion event "{title:"Power Restriction Notice Summary",content:"Industrial Area Peak-Shifting Power Supply...",timestamp:"2023-07-29T01:28:00Z"}", the keyword "power restriction" in the title text "Power Restriction Notice Summary" is detected and hits the risk vocabulary, marking the public opinion dimension behavior. The final enhanced event flow retains the original event structure but adds dimension tags, for example, the public opinion event is updated to "{...,dimension:"public_opinion"}".

[0076] In one embodiment of the present invention, step S3 includes the following steps:

[0077] The enhanced event stream output by step S2 is scanned and processed independently by dimension. When the event is marked as a financial dimension behavior, its transaction amount value and expenditure direction flag are extracted, and the difference between the amount value and the average expenditure value of the account in the past thirty natural days is calculated. If the absolute value of the difference exceeds the preset fluctuation threshold, the financial warning mark is triggered; when the event is marked as an operation dimension behavior, the abnormal type label value in the equipment operation event is detected. If the label value persists in three consecutive event time segments and the interval between each time segment is less than five minutes, the operation warning mark is triggered; when the event is marked as a public opinion dimension behavior, the sentiment polarity analysis of the title text field content is performed. If the negative sentiment intensity score exceeds the critical value and the risk keyword in the text appears more than once, the public opinion warning mark is triggered.

[0078] The warning indicators generated in each dimension are associated with the original event as independent metadata.

[0079] 1. Fund abnormality determination shall satisfy the following formula:

[0080] Sfund =|A current -μ 30 |>θ fund

[0081] Among them, A current Indicates the current transaction amount (unit: yuan), extracted from the timestamp of the device event; μ 30 Indicates the average expenditure of the account in the past 30 days (unit: yuan), calculated by rolling historical data; θ fund represents the fluctuation threshold (unit: yuan), which satisfies the following formula:

[0082] θ fund =σ 90 ×k

[0083] Among them, σ 90 The standard deviation of spending over the past 90 days (in RMB), calculated using historical data. k represents a dimensionless multiplier (default value: 2.5), a preset parameter.

[0084] 2. Operation abnormality determination satisfies the following formula:

[0085] S ops =(T last -T first ≤600)∧(N alerts ≥3)

[0086] Among them, T first Indicates the timestamp of the first abnormal event (unit: second), extracted from the timestamp of the device event. last Indicates the timestamp of the last abnormal event (unit: seconds), extracted from the latest record in the event stream. N alerts Indicates the number of consecutive abnormal events within 5 minutes, obtained by counting in the time window.

[0087] 3. Public opinion anomaly determination satisfies the following formula:

[0088] (|P|>P crit )∧(F≥1)

[0089] Where P is the sentiment polarity score, ranging from [-1, 1], output by the pre-trained NLP model. F is the frequency of risk keywords, calculated by matching the risk vocabulary. crit is the negative sentiment threshold (default -0.6), preset parameters.

[0090] The enhanced event stream inherits the output of step S2 and is an event sequence that adds the behavioral dimension tag with the dimension key to the standardized event stream. The average expenditure value is calculated by aggregating the amount values ​​of all expenditure events marked as occurring in a specified account within a time interval, adding these amounts, and dividing by the number of valid events to obtain the arithmetic mean.

[0091] The preset fluctuation threshold is a configurable parameter set based on the standard deviation of historical transaction data. Its dimension is the same as the transaction amount. The historical standard deviation, the fluctuation level of the account's historical expenditure amount, is pre-calculated. This fluctuation level is then multiplied by a 2.5x magnification factor. The resulting product is the amount fluctuation warning line that needs to be monitored. If the absolute difference between a single expenditure amount and the historical average exceeds this warning line, it is considered an abnormal expenditure.

[0092] Time segments are intervals of 150 seconds before and after the timestamp of the device operation event. Sentiment polarity analysis uses a pre-trained text classification model to determine the sentiment of the input string, outputting a floating-point number between -1 and 1, with lower values ​​indicating greater negativity. Frequency of risk keyword occurrence: This method traverses all word segmentation results in the title text field and counts the number of terms that fully match the risk keyword library.

[0093] For example, for the enhanced event stream generated in step S2, when processing the event "{account:"CNY_ACCT001",amount:85000.00,isIncome:false,dimension:"fu nd",timestamp:"2023-07-29T09:30:15Z"}" during fund dimension detection, the average expenditure of the account over the past 30 days is calculated to be 42,000 yuan, with a historical standard deviation of 18,000 yuan. The fluctuation threshold is 18,000 × 2.5 = 45,000 yuan. The difference between the current amount of 85,000 yuan and the average is 43,000 yuan, which does not exceed the threshold, so no warning is triggered.

[0094] For operational dimension detection, suppose three consecutive equipment downtime events with timestamps of "2023-07-29T09:32:00Z", "09:34:15Z", and "09:36:40Z" are received (with intervals less than 3 minutes). Because the abnormal state continues to meet the time continuity condition, the operational warning flag is triggered.

[0095] Public opinion detection: Analyzing the title "Power Restriction Notice Summary," the sentiment analysis score is -0.82 (critical value -0.6). The keyword "power restriction" appears in the risk vocabulary with a frequency of 1. Meeting both conditions triggers a public opinion alert. Additional alert metadata is output for the event, such as "{...,fund_alert:false,ops_alert:true,opinion_alert:true}."

[0096] In one embodiment of the present invention, step S4 includes the following steps:

[0097] Establish an event stream with warning metadata output by the warning identification timeline processing step S3, and continuously monitor the recent consecutive warning events. When two or more warning identifications of different dimensions are detected to appear within the preset time window, and the associated corporate entity identifications are consistent, activate the cross-dimensional association verification module. All warning events involved in the time period are grouped according to dimension type, and the risk transmission intensity index is calculated. This index is equal to the product of the original warning intensity values ​​of each dimension. If the risk transmission intensity exceeds the preset combination threshold, a cross-dimensional risk event report is output, in which the associated dimension type set and the core risk transmission path are marked.

[0098] The risk transmission intensity satisfies the following formula:

[0099] R=S fund ×S ops ×S opinion

[0100] Among them, R represents the risk transmission intensity; S fund Indicates the intensity of capital warning; S ops = indicates the intensity of operational warning; S opinion =|P|×F represents the intensity of public opinion warning; R>R th Trigger alarm (R th Default is 1.5).

[0101] The alert indicator timeline represents a queue of metadata-based events arranged in UTC timestamp order, with events from the last six hours saved by default. The preset time window represents a configurable fixed time length parameter (default is 30 minutes) used to define the detection range of associated events.

[0102] The corporate entity identifier, inherited from the entID key value in the standardized event in step S1, represents the unique code of the legal entity to which the event belongs. The risk transmission intensity is a dimensionless indicator obtained by multiplying the native warning values ​​of each dimension, reflecting the cumulative effect of multi-dimensional risks.

[0103] The original warning intensity is the internally calculated value of each dimension's warning in step S3. For the capital dimension, this is the volatility ratio; for the operations dimension, it is the normalized value of the outage duration in minutes; and for the public opinion dimension, it is the absolute value of the intensity of negative sentiment. Core risk transmission path: This is a directional relationship chain generated by the chronological order of warning occurrences and the dimension type, such as "operational failure → capital anomaly."

[0104] For example, a device failure event lasting 5 minutes and 10 seconds was detected in the production and operation dimension of an enterprise, generating an operation warning indicator (intensity value 0.85, i.e. 310 seconds / 600 seconds). Subsequently, at 09:46, an abnormal expenditure warning was triggered in the capital dimension of the same enterprise (intensity value 2.7, with the single expenditure amount exceeding the historical average by 270%). Since the time difference between these two warning events in different dimensions is only 14 minutes (within the preset 30-minute correlation window) and they belong to the same enterprise entity ENT_789, the system automatically triggers cross-dimensional correlation verification:

[0105] Multiplying the operational warning intensity of 0.85 by the funding warning intensity of 2.7 yields a risk transmission intensity of 2.295 (exceeding the preset threshold of 1.5). This generates a "cross-dimensional risk event" report, confirming the risk correlation between the operational and funding dimensions, marking the risk transmission path as "equipment failure → abnormal expenditure," and ultimately outputting a structured risk event record {eventType:"cross-dimensional risk",entID:"ENT_789",dimSet:["ops","fund"],path:"ops_to_fund"}.

[0106] In one embodiment of the present invention, step S5 includes the following steps:

[0107] In response to the cross-dimensional risk event report output in step S4, extract the entire set of warning events involved and their behavioral time stamps. Tracing the source data events based on the enterprise entity identifier, querying the historical enhanced event stream database, retrieve all relevant event records prior to the earliest warning time point. Arrange the retrieved source data events in reverse order by timestamp and align them with the warning event time point, constructing a timeline risk evolution chain diagram starting from the earliest source event, passing through all source events, and ultimately leading to the cross-dimensional risk event. This chain diagram is presented as a directed sequence diagram of event nodes and propagation paths.

[0108] The cross-dimensional risk event report refers to the standardized data structure output from step S4, which contains metadata such as the enterprise entity identifier, a list of associated dimension sets, and the risk transmission path. The warning event set refers to a single abnormal event with warning metadata generated in step S3, and its types include financial warning events, operational warning events, or public opinion warning events.

[0109] The behavior timestamp refers to the timestamp key value of each event in the enhanced event stream, using the Coordinated Universal Time format, which is used for event sorting and time alignment. The enterprise entity identifier refers to the entID attribute in the standardized event in step S1, which represents the unique code of the enterprise entity and is used for cross-event correlation.

[0110] Source data events refer to event records in the historical enhanced event stream with timestamps prior to the warning time point, and their dimensions are the same as the cross-dimensional event type. The historical enhanced event stream database refers to the enhanced event stream sequence processed in step S2 and stored persistently, with metadata such as timestamps and dimension tags. The timeline risk evolution link diagram refers to a visual link structure arranged in reverse chronological order. Nodes represent source data events and warning events, and edges represent risk transmission path relationships.

[0111] For example, the receiving step S4 outputs a cross-dimensional risk event report: {entID:"ENT_789",dimSet:["ops","fund"],path:"ops_to_fund"}. This report is derived from two warning events: an operations warning event with a timestamp of 2023-07-29T09:32:00Z (containing the warning metadata ops_alert:true), and a funding warning event with a timestamp of 2023-07-29T09:46:00Z (containing the warning metadata fund_alert:true).

[0112] Using the enterprise entity ID "ENT_789," the historical enhanced event stream database is searched for three source data events before the earliest warning time of 2023-07-29T09:32:00Z for this entity: the equipment operation log event with a timestamp of 09:00:00Z (marked as an operational activity), the energy procurement transaction event with a timestamp of 09:15:00Z (marked as a funding activity), and the equipment maintenance interruption event with a timestamp of 09:22:00Z (marked as an operational activity). These source data events are sorted in reverse timestamp order: starting with the equipment maintenance interruption event at 09:22:00Z, transitioning to the maintenance log event at 09:30:00Z, and finally triggering the warning event at 09:32:00Z. Meanwhile, the funding event is initiated by the procurement event at 09:15:00Z and terminated by the warning event at 09:46:00Z.

[0113] The link graph is constructed and output as a sequence structure: equipment maintenance interruption (09:22:00Z) → equipment shutdown (09:32:00Z) → abnormal expenditure (09:46:00Z), with additional time axis coordinates to identify the time stamp and dimension type of each event.

[0114] In one embodiment of the present invention, step S6 includes the following steps:

[0115] The generated risk evolution chain diagram with a timeline is parsed to extract its node sequence and behavior time stamp distribution characteristics. All warning event nodes in the chain diagram are traversed, and the spatial density and temporal concentration of nodes of the same dimension type are calculated. The statistical results are input into the response rule matching engine and compared with the characteristic patterns in the preset response rule library for similarity. For successfully matched rule entries, intervention instructions are generated using the processing priority calculation function. This function multiplies the node's cumulative risk transmission strength by the time attenuation coefficient to obtain the processing priority value.

[0116] The final synthesis includes a graphical intervention plan that includes the coordinates of the risk hotspot location, dimension type labels, and priority levels. The hotspot location is highlighted based on the center coordinates of the high-density node cluster in the link diagram.

[0117] The behavioral time stamp refers to the UTC timestamp carried by each node in the risk evolution link diagram in step S5 and is used to calculate temporal concentration. Spatial density is calculated as the number of warning nodes of the same dimension per unit coordinate area of ​​the link diagram, with the density boundary defined using kernel density estimation. Temporal concentration refers to the dimensionless value obtained by taking the inverse of the difference between the earliest and latest node timestamps, reflecting the temporal clustering of warning events.

[0118] The preset response rule library has a predefined rule data structure. Each rule contains three matching conditions: dimension type combination mode, spatial density threshold, and time concentration threshold. The processing priority calculation function satisfies the following formula:

[0119] Priority = C × D

[0120] Where C represents the cumulative risk transmission intensity, which is the cumulative value of the risk transmission intensity of historical warning events at the same node in step S4. D represents the time decay coefficient, which is a natural fraction calculated by subtracting the number of hours from the latest warning time stamp from the current time. The difference between the current time and the latest warning time stamp is converted into the number of hours, and the reciprocal of this number is added to one to form the decay coefficient. If this product exceeds the activation threshold set by the rule, the corresponding action instruction is triggered.

[0121] The coordinates of risk hotspot locations, the geometric center of high-density node clusters, are calculated by taking the arithmetic mean of the coordinates of nodes of the same dimension. A graphical intervention plan inherits the interactive view of the original link graph topology, adds a 3D thermal layer to mark hotspots, and dynamically renders color depth based on priority values.

[0122] For example, in the risk evolution chain diagram, three warning nodes were detected: Yuwei warning node A (time 10:00:00Z, coordinates (30, 50), risk intensity 0.9), capital dimension warning node B (time 10:15:00Z, coordinates (32, 52), risk intensity 1.2), and capital dimension warning node C (time 10:20:00Z, coordinates (33, 53), risk intensity 0.8). Spatial analysis revealed that the capital dimension node formed a density hotspot at coordinates (32.5, 52.5) ​​(2 nodes / unit, exceeding the threshold of 1.5). Simultaneously, the capital dimension warning time concentration reached 12 (the reciprocal calculated value of the 5-minute time difference, exceeding the threshold of 10), triggering the "Dual Capital Nodes + Density > 1.5 + Concentration > 10" action rule. In the processing priority calculation, the system accumulates the capital dimension risk intensity to 2.0, and calculates the time attenuation coefficient of 0.86 based on the 10-minute time difference (1 / 6 hour) between the current time 10:30:00Z and the latest warning; the final priority value is 1.72 (super-activation threshold 1.5).

[0123] Based on this, a graphical intervention plan is output: an orange hot zone is marked at the coordinates (32.5, 52.5) ​​and labeled "double-point of abnormal capital flow", and a red second-level alarm mark is attached (priority 1.72 belongs to the 1.5-2.0 risk range).

[0124] See attached Figure 2 As shown, the present invention also proposes a risk assessment system for multi-dimensional big data analysis, including the following modules:

[0125] The data acquisition module is used to acquire enterprise financial data, production and operation data, and public internet data, and map these three types of raw data into standardized event streams with time stamps.

[0126] The dimension identification module is used to mark financial data-related events as capital dimension behaviors, production and operation data events as operation dimension behaviors, and internet data events as public opinion dimension behaviors, thereby generating enhanced event streams with dimension tags.

[0127] Anomaly detection module, used to generate a capital warning indicator when capital dimension behavior meets the preset fluctuation threshold, generate an operation warning indicator when operation dimension behavior meets the preset continuity condition, and generate a public opinion warning indicator when public opinion dimension behavior meets the preset negative sentiment condition;

[0128] The correlation analysis module is used to execute dimension correlation verification and calculate the risk transmission intensity index when warning signs of two or more different dimensions appear within a preset time window. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output;

[0129] The link construction module is used to perform historical enhancement of event flows based on cross-dimensional risk event reports, and to construct a risk evolution link diagram containing source data events and warning events in reverse chronological order;

[0130] The decision generation module is used to analyze the node distribution characteristics of the risk evolution link diagram, match the preset response rule library, and generate a graphical intervention plan that includes the risk hotspot location and processing priority.

[0131] It should be noted that the formulas described above can translate physical quantities of different attributes into unitless standard values ​​or superimposable parameters of the same dimension through the principle of dimensional consistency and mathematical standardization (e.g., normalization, dimensionless parameter conversion, or unit system unification). This eliminates the interference of different dimensions on the operational logic, allowing the formulas to retain the distribution characteristics of the original data while maintaining mathematical rationality and adaptability to objective laws. The above are merely exemplary embodiments of the present invention and are not intended to limit the scope of the present invention.

[0132] The modules can be implemented in whole or in part through software, hardware, or a combination thereof, supporting hardware embedded in or independent of a processor in a computer device, and also supporting software stored in a memory in a computer device, so that the processor can call and execute operations corresponding to the modules.

[0133] It should be noted that the human body information (including but not limited to human device information and personal information, etc.) and data (including but not limited to data used for analysis, stored data and displayed data, etc.) involved in the present invention are all information and data authorized by the human body or fully authorized by all parties. The collection, use and processing of relevant data require relevant legal standards.

[0134] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A risk assessment method for multi-dimensional big data analysis, characterized in that: The following steps are involved: S1. Obtain enterprise financial data, production and operation data, and publicly available data on the internet, and map these three types of raw data into standardized event streams with time stamps. S2. Financial data-related events are marked as capital dimension behaviors, production and operation data events are marked as operation dimension behaviors, and internet data events are marked as public opinion dimension behaviors, generating an enhanced event stream with dimension tags. S3: When the behavior in the capital dimension meets the preset fluctuation threshold, a capital warning mark is generated; when the behavior in the operation dimension meets the preset continuity condition, an operation warning mark is generated; when the behavior in the public opinion dimension meets the preset negative sentiment condition, a public opinion warning mark is generated; S4. When two or more warning signs from different dimensions appear within a preset time window, dimension association verification is triggered and the risk transmission intensity index is calculated. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output; S5. Based on the cross-dimensional risk event report, the historical event flow is traced back and a risk evolution chain diagram containing source data events and warning events is constructed in reverse chronological order; S6. Analyze the node distribution characteristics of the risk evolution link diagram, match the preset response rule library, and generate a graphical intervention plan that includes the risk hotspot location and processing priority.

2. The risk assessment method for multi-dimensional big data analysis according to claim 1 is characterized in that: Mapping the three types of raw data into standardized event streams with time stamps includes the following steps: Respectively obtain the account income and expenditure details of the financial system database, the operation warning messages of the production equipment message queue, and the text content of the Internet data interface; Convert account income and expenditure details into standard income and expenditure events containing account ID, transaction value, income and expenditure direction, and timestamp; reconstruct operation warning messages into device operation events containing device code, exception type, and timestamp; parse text content into Internet events containing title, content, and timestamp; Perform time stamp synchronization on the three types of events, align their original time points to the Coordinated Universal Time standard, arrange them in ascending time order, and output a standardized event stream.

3. The risk assessment method for multi-dimensional big data analysis according to claim 1 is characterized in that: Generating an enhanced event stream with dimension tags includes the following steps: When there is a preset bank account code prefix, it is marked as a capital dimension behavior; when the equipment code conforms to the preset production equipment numbering rules, it is marked as an operation dimension behavior; when the title text hits the preset risk keyword library and there is no account / equipment code, it is marked as a public opinion dimension behavior; Add dimension tag key-value pairs to the standardized event stream to generate an enhanced event stream with dimension tags.

4. The risk assessment method for multi-dimensional big data analysis according to claim 1 is characterized in that: When the behavior in the capital dimension meets the preset fluctuation threshold, a capital warning mark is generated; when the behavior in the operation dimension meets the preset continuity condition, an operation warning mark is generated; when the behavior in the public opinion dimension meets the preset negative sentiment condition, a public opinion warning mark is generated, including the following steps: Calculate the absolute value of the difference between the current transaction amount and the historical average expenditure value. When it exceeds the preset fluctuation threshold calculated based on the historical standard deviation, the capital warning indicator is triggered; When abnormal events with the same device code occur more than three times in a row within a preset time segment, the operation warning indicator is triggered; When the negative sentiment intensity of the title text exceeds the preset critical value and the frequency of risk keywords is greater than once, the public opinion warning sign is triggered.

5. The risk assessment method for multi-dimensional big data analysis according to claim 1 is characterized in that: Trigger dimension association verification and calculate the risk transmission strength index. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output, including the following steps: Establish a warning indicator timeline to monitor continuous warning events. When warning indicators of different dimensions appear within a preset time window and have the same enterprise entity identifier, activate dimension association verification. The risk transmission intensity index is calculated by multiplying the warning intensity values ​​of each dimension. The warning intensity value includes the capital fluctuation ratio, the normalized value of the duration of the operational failure, and the absolute value of the negative sentiment of public opinion. When the risk transmission intensity index exceeds the preset combination threshold, a cross-dimensional risk event report containing a set of associated dimension types is output.

6. The risk assessment method for multi-dimensional big data analysis according to claim 1 is characterized in that: Constructing a risk evolution chain diagram containing source data events and warning events in reverse chronological order includes the following steps: Based on the enterprise entity identifier in the cross-dimensional risk event report, query the historical enhanced event stream database to obtain the source data event; Arrange the source data events and warning events in reverse order by timestamp, and construct a risk evolution chain diagram with the earliest source event as the starting point and the cross-dimensional risk event as the end point.

7. The risk assessment method for multi-dimensional big data analysis according to claim 1 is characterized in that: The preset response rule base is matched to generate a graphical intervention plan that includes the risk hotspot location and treatment priority, including the following steps: The spatial density and temporal concentration of warning nodes of the same dimension in the statistical risk evolution link diagram are calculated. The temporal concentration is the inverse of the time difference between the earliest and latest nodes. Match the spatial density and temporal concentration with the dimensional combination pattern of the preset response rule base, and calculate the processing priority by multiplying the cumulative risk transmission intensity and the time attenuation coefficient; The geometric center coordinates of the high-density node cluster are used as the risk hotspot location, and a graphical intervention plan with priority classification is synthesized.

8. The risk assessment method for multi-dimensional big data analysis according to claim 7 is characterized in that: Generating the aging attenuation coefficient includes the following steps: Obtain the hourly difference between the current moment and the latest warning time mark, add one to the difference and take the inverse as the attenuation coefficient; the graphical intervention plan superimposes a three-dimensional thermal layer on the risk evolution chain diagram.

9. A risk assessment system for multi-dimensional big data analysis, characterized in that: Includes the following modules: The data acquisition module is used to acquire enterprise financial data, production and operation data, and public internet data, and map these three types of raw data into standardized event streams with time stamps. The dimension identification module is used to mark financial data-related events as capital dimension behaviors, production and operation data events as operation dimension behaviors, and internet data events as public opinion dimension behaviors, thereby generating enhanced event streams with dimension tags. Anomaly detection module, used to generate a capital warning indicator when capital dimension behavior meets the preset fluctuation threshold, generate an operation warning indicator when operation dimension behavior meets the preset continuity condition, and generate a public opinion warning indicator when public opinion dimension behavior meets the preset negative sentiment condition; The correlation analysis module is used to execute dimension correlation verification and calculate the risk transmission intensity index when warning signs of two or more different dimensions appear within a preset time window. When the index exceeds the preset combination threshold, a cross-dimensional risk event report is output; The link construction module is used to perform historical enhancement of event flows based on cross-dimensional risk event reports, and to construct a risk evolution link diagram containing source data events and warning events in reverse chronological order; The decision generation module is used to analyze the node distribution characteristics of the risk evolution link diagram, match the preset response rule library, and generate a graphical intervention plan that includes the risk hotspot location and processing priority.

Citation Information

Cited By

  • Intelligent financial risk analysis method based on big data

    CN121189834A

  • A Big Data-Based Intelligent Analysis Method for Financial Risk

    CN121189834B

  • Intelligent finance and tax management method and system based on vector driving and storage medium

    CN121504640A

  • Cross-border e-commerce risk monitoring system and method based on data analysis

    CN121563243A

  • Cross-border e-commerce risk monitoring system and method based on data analysis

    CN121563243B