A transaction anomaly monitoring method and system based on big data fusion
By extracting stable features and traffic feedback features from interaction behavior data in the transaction chain, abnormal transaction risks can be identified, solving the problem of untimely updates to risk detection rules in existing technologies and achieving more accurate and flexible transaction security assessment.
Patent Information
- Application Number
- CN202511334939.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-18
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-09-18
AI Technical Summary
In existing technologies, risk detection rules in the transaction chain are not updated in a timely manner, and cannot adapt to the unique differences between different user terminals and changes in transaction scenarios, resulting in poor security risk detection performance.
By retrieving interactive behavior data in the transaction chain, stable characteristics of switching action events are extracted. Combined with the page refresh frequency, anomaly representation values of events are calculated to determine whether abnormal risk behaviors are close to the transaction payment node. Based on traffic feedback characteristics, transaction transmission anomaly representation parameters are calculated to perform data transmission analysis and parameter standard threshold adjustment.
It improves the accuracy and reliability of transaction security assessment, reduces misjudgments or omissions, enhances the adaptability and flexibility of transaction security detection, and ensures the integrity of transaction data.
Smart Images

Figure CN120851881B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and in particular to a transaction anomaly monitoring method and system based on big data fusion. BACKGROUND
[0002] With the rapid development of information technology such as the Internet and mobile payment, payment scenarios are becoming increasingly diverse, and transaction methods are becoming more convenient and diverse, such as online shopping, mobile payment, cross-border payment, etc. However, the risks that follow are also increasing, so advanced technical means are needed to monitor and identify security risks in the transaction link in real time.
[0003] The development of big data, artificial intelligence and other related technologies can process and analyze a large amount of transaction data, and then mine the interaction data generated based on transaction behavior, identify potential risks in the transaction process in a timely manner, and improve the accuracy and efficiency of security risk detection and identification.
[0004] Chinese patent CN113516480A discloses a payment risk identification method, device and equipment, which comprises: if the first preset processing node in the payment processing link is executed for the target user's current payment transaction event, the deep interest network model is used to determine the target user's predicted payment behavior data based on the target user's historical payment transaction data and the current payment environment data; a preset risk identification model is used to identify the risk of the current payment transaction event based on the predicted payment behavior data, and a corresponding predicted payment risk identification result is obtained; when the second preset processing node is executed in the current payment transaction event, the target user's real payment behavior data generated in the execution process of the current payment transaction event is obtained; and based on the predicted payment behavior data, the real payment behavior data and the predicted payment risk identification result, the target payment risk identification result corresponding to the current payment transaction event is determined.
[0005] However, the existing technology still has the following problems: the risk existing in the transaction link is mainly detected and identified by the predetermined detection rule, and this kind of detection method has the problem of not being timely for updating the predetermined detection rule, and cannot adapt to the uniqueness difference between different user terminals and the change of transaction scenarios, and has low flexibility, and the security risk detection effect is not good under the condition of large data transmission amount and complex scene change. SUMMARY
[0006] To solve the problems in the prior art, the present application provides a transaction anomaly monitoring method and system based on big data fusion.
[0007] The present application adopts the following technical solutions.
[0008] The first aspect of the present application provides a transaction abnormality monitoring method based on big data fusion, comprising:
[0009] S1, calling interaction behavior data in a transaction link, determining whether to trigger a switching action event according to the interaction behavior data and extracting stable features of the switching action event;
[0010] S2, calculating an event abnormality representation value of the transaction behavior based on the stable features and a page refresh frequency, identifying and marking abnormal risk behaviors according to the event abnormality representation value;
[0011] S3, judging whether a node where the abnormal risk behavior is located is adjacent to a transaction payment node, if yes, calculating a transaction transmission abnormality representation parameter based on a traffic feedback feature;
[0012] S4, when the transaction transmission abnormality representation parameter is greater than or equal to a parameter standard threshold value, determining that the transaction is abnormal, outputting abnormal information and performing data transmission analysis on the abnormal risk behaviors of the adjacent transaction payment nodes to adjust the parameter standard threshold value.
[0013] Preferably, the stable features include an event switching speed in a predetermined time domain segment and an event switching frequency.
[0014] Preferably, in S2, the calculation of the event abnormality representation value of the transaction behavior based on the stable features and the page refresh frequency comprises:
[0015] taking a sum of a ratio of the event switching speed to an event switching speed threshold value and a ratio of the event switching frequency to an event switching frequency threshold value as a first security feature;
[0016] taking a ratio of the page refresh frequency to a page refresh frequency threshold value as a second security feature;
[0017] weighting and summing the first security feature and the second security feature as the event abnormality representation value.
[0018] Preferably, in S2, the identification and marking of the abnormal risk behaviors according to the event abnormality representation value comprises:
[0019] if the event abnormality representation value is greater than or equal to an event abnormality representation threshold value, marking the corresponding transaction behavior as an abnormal risk behavior.
[0020] Preferably, in S3, the judgment of whether the node where the abnormal risk behavior is located is adjacent to the transaction payment node comprises:
[0021] calling a plurality of path nodes corresponding to a preselected stored transaction jump path to determine a path node corresponding to the node where the abnormal risk behavior is located;
[0022] If the next adjacent path node corresponding to the current path node is a payment node, it is determined that the node where the abnormal risk behavior occurs is adjacent to the transaction payment node.
[0023] Preferably, in S3, the transaction transmission abnormality characterization parameter is calculated based on the traffic feedback features, including:
[0024] The traffic feedback features include the uniformity of traffic time intervals and the reception delay duration of the target data at the receiving end, wherein the uniformity of traffic time intervals is the time difference between the data packets received continuously by the receiving end;
[0025] The ratio of the uniformity threshold value to the uniformity of the traffic time intervals is taken as the first transmission abnormality feature;
[0026] The ratio of the reception delay duration to the reception delay duration threshold value is taken as the second transmission abnormality feature;
[0027] The sum of the first transmission abnormality feature and the second transmission abnormality feature is taken as the transaction transmission abnormality characterization parameter.
[0028] Preferably, in S4, the abnormal risk behavior of the adjacent transaction payment node is analyzed for data transmission to adjust the parameter standard threshold value, including:
[0029] S4.1, the corresponding transaction transmission abnormality characterization parameter records of the user end at each time from the adjacent transaction payment node to the transaction payment node are called to calculate the average of the corresponding transaction transmission abnormality characterization parameters of the user end at each time from the adjacent transaction payment node to the transaction payment node in several transactions;
[0030] S4.2, the sensitive interval and the reference duration corresponding to the sensitive interval are determined based on the average of the transaction transmission abnormality characterization parameters;
[0031] S4.3, the reference interval is constructed based on the current time of the node and the reference duration, and the corresponding sensitive interval is associated;
[0032] S4.4, the traffic feedback features in the reference interval and the historical traffic feedback features in the corresponding sensitive interval are obtained, and the feedback deviation value is determined based on the obtained features to adjust the parameter standard threshold value.
[0033] Preferably, in S4.2, the sensitive interval and the reference duration corresponding to the sensitive interval are determined based on the average of the transaction transmission abnormality characterization parameters, including:
[0034] The time domain variation curve of the transaction transmission abnormality characterization parameter is constructed based on the average, and the slope of the corresponding curve segment in each time domain interval is determined;
[0035] If the slope corresponding to the time domain interval is greater than the preset slope threshold, the corresponding time domain interval is determined as a sensitive interval.
[0036] The time length from the starting moment of the sensitive interval to the time domain change curve is taken as the reference duration corresponding to the sensitive interval.
[0037] Preferably, in S4.3, the control interval is constructed based on the time at which the current node is located and the reference duration, and the corresponding sensitive interval is associated, including:
[0038] The time at which the current node is located is determined, the reference duration is extended after the time, the starting moment of the control interval is determined, the control interval is constructed, wherein the control interval has the same interval length as the sensitive interval corresponding to the reference duration, and the control interval is associated with the corresponding sensitive interval.
[0039] Preferably, in S4.4, the traffic feedback features in the control interval and the historical traffic feedback features in the corresponding sensitive interval are obtained, and the feedback deviation value is determined based on the obtained features, including:
[0040] The traffic feedback features of the control interval are obtained, including the uniformity mean of the traffic time interval of the corresponding transaction behavior of the receiving end and the mean of the receiving delay duration of the receiving end for the target data;
[0041] The historical traffic feedback features in the corresponding sensitive interval are obtained, including the historical uniformity mean of the traffic time interval of the corresponding transaction behavior and the historical receiving delay duration mean of the receiving end for the target data;
[0042] A first deviation value is calculated according to the uniformity mean of the traffic time interval and the historical uniformity mean;
[0043] A second deviation value is calculated according to the receiving delay duration mean of the receiving end for the target data and the historical receiving delay duration mean;
[0044] The sum of the first deviation value and the second deviation value is determined as the feedback deviation value.
[0045] Preferably, the parameter standard threshold value and the feedback deviation value are in a negative correlation relationship.
[0046] Preferably, it further includes S5, integrity verification is performed on the target data received by the receiving end in the transaction link.
[0047] The second aspect of the application provides a system applying the transaction anomaly monitoring method based on big data fusion, and the system includes:
[0048] The feature extraction module is configured to retrieve interaction behavior data in a transaction link, determine whether to trigger a switching action event according to the interaction behavior data, and extract stable features of the switching action event.
[0049] The behavior marking module is connected with the feature extraction module and is configured to calculate an event abnormality representation value of a transaction behavior based on the stable features and a page refresh frequency, and identify and mark an abnormal risk behavior according to the event abnormality representation value.
[0050] The transaction detection module is connected with the behavior marking module and is configured to determine whether a node where the abnormal risk behavior is located is adjacent to a transaction payment node, and if so, calculate a transaction transmission abnormality representation parameter based on a traffic feedback feature.
[0051] The response adjustment module is connected with the transaction detection module, determines that a transaction is abnormal when the transaction transmission abnormality representation parameter is greater than or equal to a parameter standard threshold value, outputs abnormal information, and performs data transmission analysis on the abnormal risk behavior of the adjacent transaction payment node to adjust the parameter standard threshold value.
[0052] The third aspect of the present application provides a terminal, comprising a processor and a storage medium; the storage medium is used for storing instructions; the processor is used for operating according to the instructions to execute the steps of the method.
[0053] The fourth aspect of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to realize the steps of the method.
[0054] Compared with the prior art, the present application has at least the following beneficial effects:
[0055] The present application determines whether to trigger a switching action event by calling interaction behavior data in a transaction link, extracts stable features for the switching action event, determines an event abnormality representation value of a transaction behavior based on the stable features and a page refresh frequency, marks an abnormal risk behavior, detects and identifies the corresponding transaction behavior based on the marked result, analyzes the data transmission of the transaction behavior in response to the comparison result of a transaction transmission abnormality representation parameter and a parameter standard threshold value, and verifies the integrity of the received target data, thereby improving the evaluation accuracy and reliability of transaction security under the premise of ensuring the transaction security detection effect.
[0056] Further, the application considers the features presented by the behavior mode of the switching action event in the unit time domain segment and the event abnormality degree of the transaction behavior evaluated by the refresh frequency of the user end to the page, and then reflects the transaction security degree. Specifically, under normal circumstances, the user end will spend a certain time to read and understand the information presented by the page in the process of implementing the transaction proposal to payment, and the faster switching operation of the page can reflect the behavior possibility of affecting the transaction security in the current stage; higher switching frequency can reflect the risk of the user end trying to find some hidden information or bypass the security verification link in the payment process; and in the process of implementing the transaction behavior, the user end may refresh the page to obtain new transaction information, in which case, in order to facilitate the identification of transaction information content, the refresh operation frequency implemented will not be too high, and too high refresh frequency can represent the risk of interfering with the normal transaction process. Therefore, by comprehensively evaluating the above interaction behaviors in the transaction link, the event abnormality characteristic value of the transaction behavior is determined to represent the security risk degree of the transaction behavior, to provide accurate and reliable data support for subsequent abnormal risk identification and marking of the transaction behavior, so that the application can improve the evaluation accuracy and reliability of the transaction security under the premise of ensuring the transaction security detection effect.
[0057] Further, the application focuses on the key sensitive stage of transaction risk, that is, the stage corresponding to the transaction payment node. There is a large amount of sensitive information in the data to be processed in this stage. Under normal transaction, the data flow received by the receiving end has certain stability and regularity, and the time interval is relatively uniform. The change of the uniformity of the time interval is analyzed to analyze the transaction abnormality; at the same time, the transaction is carried out in a stable network environment, and the transmission and processing of data are at a relatively stable and uniform speed. Based on the fact that the stage is a high-sensitive stage with transaction risk, the degree of the receiving end being attacked by malicious attacks increases. The transmission abnormality degree of the related transaction data reflected by the above features is considered to determine the transaction transmission abnormality characteristic parameter, which provides more convincing basis for subsequent comparison with the parameter standard threshold to determine whether the transaction is abnormal, so that the application can improve the evaluation accuracy and reliability of the transaction security under the premise of ensuring the transaction security detection effect.
[0058] Further, the application considers that the transaction habits and traffic patterns of different user terminals have certain uniqueness, and the data representation of the data transmission layer in the entire process from the current transaction node to the transaction payment node is determined to be strong. By comparing the relevant historical data of the user terminal, the characteristics of different user terminals are fully adapted, making the detection of transaction security more personalized, accurately identifying the abnormal situation of the current transaction, reducing the misjudgment or omission caused by general standards, and improving the accuracy and sensitivity of abnormal detection. Therefore, the sensitive interval and the matching of the control interval are determined, so that the system can flexibly select the appropriate historical data interval for comparison and analysis based on the current transaction node, and the deviation evaluation based on the matching provides data support for subsequent adjustment of the parameter standard threshold, ensuring effective monitoring of abnormal transactions, enhancing the adaptability and flexibility of transaction security detection, so that the application can improve the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0059] The application verifies the integrity of the target data received by the transaction link receiving end, that is, whether the target data is tampered with, lost or replaced in the transmission and processing process, and ensures transaction security and improves the accuracy of abnormal detection through double verification. BRIEF DESCRIPTION OF DRAWINGS
[0060] Figure 1 The figure is a schematic diagram of the steps of the transaction abnormality monitoring method based on big data fusion of the application embodiment.
[0061] Figure 2 The figure is a logic decision diagram for marking transaction behavior of the application embodiment.
[0062] Figure 3 The figure is a logic decision diagram for detecting and identifying the corresponding transaction behavior of the application embodiment.
[0063] Figure 4 The figure is a logic decision diagram for determining whether it is close to the transaction payment node of the application embodiment. DETAILED DESCRIPTION
[0064] In order to make the purpose, technical scheme and advantages of the application clearer, the technical scheme of the application will be described clearly and completely below in combination with the drawings in the application embodiment. The embodiments described in the application are only a part of the embodiments of the application, not all embodiments. Based on the spirit of the application, other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the application.
[0065] As shown in Figure 1 The application embodiment 1 provides a transaction abnormality monitoring method based on big data fusion, which includes:
[0066] S1, retrieve interaction behavior data in the transaction link, determine whether to trigger a switching action event according to the interaction behavior data and extract stable features of the switching action event;
[0067] Further preferably, the interaction behavior data in the transaction link is called to determine whether to trigger a switching action event and to extract stable features of the switching action event, wherein the stable features include event switching speed and event switching frequency in a predetermined time domain segment;
[0068] The interaction behavior data refers to a series of relevant transaction data generated between the user end and the receiving end during the transaction behavior, which includes stable features of the switching action event, traffic feedback features, page refresh frequency, and a plurality of path nodes corresponding to the transaction jump path, etc.
[0069] The switching action event refers to the behavior of the user end switching from one page, function, commodity or service option to another, which will not be described again.
[0070] S2, calculate an event abnormality representation value of the transaction behavior based on the stable features and the page refresh frequency, and identify and mark abnormal risk behaviors according to the event abnormality representation value;
[0071] Further preferably, the event abnormality representation value of the transaction behavior is determined based on the stable features and the page refresh frequency to mark the transaction behavior, including:
[0072] (1) determining the event abnormality representation value of the transaction behavior based on the stable features and the page refresh frequency:
[0073] The sum of the ratio of the event switching speed to the event switching speed threshold value and the ratio of the event switching frequency to the event switching frequency threshold value is taken as the first security feature;
[0074] The ratio of the page refresh frequency to the page refresh frequency threshold value is taken as the second security feature;
[0075] The first security feature and the second security feature are weighted and summed as the event abnormality representation value.
[0076] Specifically, in the actual network transaction process, the switching operation of the user end on the page can more intuitively reflect the abnormality degree of the user end operation behavior, and further reflect the degree of transaction security interference, therefore, in the implementation, the stable features of the switching action event, i.e. the event switching speed and the event switching frequency in the predetermined time domain segment, are given priority, so the first security feature calculated based on the stable features is given a slightly higher weight, therefore, for example, when weighted and summed, the weight of the first security feature is set to 0.6 and the weight of the second security feature is set to 0.4.
[0077] In this embodiment, the purposes of setting the event switching speed threshold, the event switching frequency threshold and the page refresh frequency threshold are all to represent the situation that the operation behavior of the user terminal in the predetermined time domain segment is relatively abnormal and the transaction security level is relatively low. By calling the operation behavior history data of a plurality of user terminals in the same time domain segment, the time switching speed history data, the time switching frequency history data and the page refresh frequency history data are extracted, and the event switching speed average value, the event switching frequency average value and the page refresh frequency average value are respectively solved.
[0078] Based on the purposes of setting the above three thresholds, the event switching speed threshold is determined as the product of the event switching speed average value and the speed offset coefficient; the event switching frequency threshold is determined as the product of the event switching frequency average value and the frequency deviation coefficient; and the page refresh frequency threshold is determined as the product of the page refresh frequency average value and the frequency deviation coefficient; wherein the speed offset coefficient is selected in the interval [1.05, 1.1], the frequency deviation coefficient is selected in the interval [1.1, 1.15], and the frequency deviation coefficient is selected in the interval [1.15, 1.25];
[0079] It can be understood that when the network transaction proceeds to the payment stage, based on the abnormal situation of the operation behavior of the user terminal, the risk of affecting the transaction security caused by the abnormal situation is more representative. Therefore, in specific implementation, the time domain segment corresponding to the transaction behavior reaching the transaction order generation node to the transaction payment node is determined as the predetermined time domain segment, which will not be repeated here.
[0080] Specifically, the application considers the characteristics presented by the behavior mode of switching action events in a unit time domain segment in combination with the event abnormality degree of transaction behavior evaluated by the refresh frequency of the user end to the page, and the transaction security degree reflected thereby. Under normal circumstances, the user end will spend a certain amount of time reading and understanding the information presented by the page during the implementation of the transaction proposal to payment, and faster switching operations on the page can reflect the possibility of behavior affecting transaction security at the current stage, for example, there are automated programs simulating user operations, maliciously brushing, brushing, or attempting to break through transaction security limits, etc.; and a higher switching frequency can reflect the risk that the user end is trying to find some hidden information or bypass the security verification link in the payment process; and during the implementation of the transaction behavior, the user end may refresh the page to obtain new transaction information, in which case, in order to facilitate the identification of transaction information content, the refresh operation frequency implemented will not be too high, and a too high refresh frequency can indicate a risk of interfering with the normal transaction process, for example, automatically refreshing the page according to malicious scripts to interfere with the transaction process or steal user information, etc. Therefore, by comprehensively evaluating the above-mentioned interaction behaviors in the transaction link to determine the event abnormality representation value of the transaction behavior, the security risk degree of the transaction behavior is represented, and data support is provided for subsequent marking of the transaction behavior. The application can improve the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0081] (2) as shown in Figure 2 marking the transaction behavior, comprising,
[0082] if the event abnormality representation value of the transaction behavior is greater than or equal to the event abnormality representation threshold value, the transaction behavior is marked as an abnormal risk behavior;
[0083] if the event abnormality representation value of the transaction behavior is less than the event abnormality representation threshold value, the transaction behavior does not need to be marked;
[0084] The event abnormality representation threshold value is selected in the interval [1.68, 1.74].
[0085] S3, judging whether the abnormal risk behavior is adjacent to a transaction payment node, if so, calculating a transaction transmission abnormality representation parameter based on the flow feedback feature; that is, performing subsequent operations on the abnormal risk behavior determined to be adjacent to the transaction payment node, otherwise, not operating;
[0086] Further preferably, based on the result of the marking, the corresponding transaction behavior is detected and identified, comprising determining the node where the transaction behavior is located, determining whether it is adjacent to a transaction payment node, and determining a transaction transmission abnormality representation parameter based on the flow feedback feature at the time.
[0087] (1) as shown inFigure 3 As shown, if the transaction behavior is marked as abnormal risk behavior, the corresponding transaction behavior is detected and identified.
[0088] (2) As shown in the following formula, it is determined whether the current node is adjacent to the transaction payment node: Figure 4
[0089] The pre-stored transaction jump path corresponding to the path node is called.
[0090] The current path node corresponding to the current node is determined.
[0091] If the next adjacent path node corresponding to the current path node is a payment node, it is determined that the current node is adjacent to the transaction payment node.
[0092] If the next adjacent path node corresponding to the current path node is not a payment node, it is determined that the current node is not adjacent to the transaction payment node.
[0093] (3) At the current time, the traffic feedback feature is obtained to determine the transaction transmission abnormality characteristic parameter:
[0094] The ratio of the uniformity threshold value to the uniformity of the traffic time interval is taken as the first transmission abnormality feature.
[0095] The ratio of the reception delay duration to the reception delay duration threshold value is taken as the second transmission abnormality feature.
[0096] The sum of the first transmission abnormality feature and the second transmission abnormality feature is taken as the transaction transmission abnormality characteristic parameter.
[0097] In this embodiment, the purpose of setting the uniformity threshold value and the reception delay duration threshold value is to represent the case that there is a large abnormal risk in data transmission, and the safety and integrity of the target data received by the receiving end are greatly affected. By calling the historical traffic data of a plurality of user terminals at the stage corresponding to the adjacent transaction payment node, the uniformity historical data and the reception delay duration historical data of the traffic time interval are extracted, and the uniformity mean value and the reception delay duration mean value are solved.
[0098] Based on the purpose of setting the above two threshold values, the uniformity threshold value is determined as the product of the uniformity mean value and the uniformity deviation coefficient, and the reception delay duration threshold value is determined as the product of the reception delay duration mean value and the delay offset coefficient. The uniformity deviation coefficient is selected in the interval [1.2, 1.3], and the delay offset coefficient is selected in the interval [1.5, 1.8].
[0099] Specifically, the uniformity of the time interval of the flow refers to the time difference between the data packets received by the receiving end in succession. For example, if the receiving end receives a data packet every 5s, the time interval between the two data packets is 5s. Normally, the receiving end receives data according to certain logic and frequency, and the time interval is relatively stable. Therefore, in this embodiment, the uniformity of the time interval of the flow is analyzed. If it is found that the time interval of the data packet reception is abnormally frequent or abnormally sparse, and under the premise that it does not conform to any known normal application program behavior, it indicates that the possibility of malicious attack on data transmission increases.
[0100] wherein the length of the time interval exceeding the uniformity is taken as the receiving delay length of the receiving end for the target data.
[0101] Specifically, the present application analyzes the key sensitive stage of transaction risk, i.e., the stage near the transaction payment node. A large amount of sensitive information, such as key financial information and personal identity information, needs to be processed in this stage. The information is highly concentrated and is a link with higher attack value in the entire transaction link for attackers. Therefore, the present application focuses on analyzing the above-mentioned stage. During normal transaction, the data flow received by the receiving end has certain stability and regularity, and the time interval is relatively uniform. The transaction anomaly is analyzed by analyzing the change of the time interval uniformity. For example, the flow time interval suddenly becomes long, which may be caused by network congestion, signal interference or failure of some nodes in the transmission link, resulting in discontinuous data transmission. The interval is too short and irregular, which may be caused by malicious programs sending a large amount of data in a short time to try to interfere with the normal transaction process, or it may be caused by attackers trying to find system vulnerabilities. At the same time, in a stable network environment, the transmission and processing of data are at a relatively stable and uniform speed. Based on the fact that the stage is a high-sensitive stage with transaction risk, the degree of inclination of the receiving end to malicious attack increases. For example, the attacker implements malicious attack, intercepts or tampers with related transaction data, etc., which causes the receiving end to spend more time to process abnormal data, and further causes the delay of receiving and processing of target data. The transmission anomaly of the related transaction data reflected by the above-mentioned features is determined to determine the transaction transmission anomaly characteristic parameter. For subsequent comparison with the parameter standard threshold value, the present application provides more convincing basis for determining whether the transaction is abnormal. Under the premise of ensuring the effect of transaction security detection, the present application can improve the evaluation accuracy and reliability of transaction security.
[0102] S4, when the transaction transmission anomaly characteristic parameter is greater than or equal to the parameter standard threshold value, it is determined that the transaction is abnormal, and abnormal information is output (such as issuing an abnormal alarm, prompting the corresponding interaction behavior data, abnormal risk behavior, etc.); the abnormal risk behavior near the transaction payment node is analyzed to analyze the data transmission, so as to adjust the parameter standard threshold value.
[0103] Further preferably, if the transaction transmission abnormality representation parameter is greater than or equal to the parameter standard threshold value, the data transmission of the transaction behavior is analyzed; in this embodiment, the purpose of setting the parameter standard threshold value is to represent the case that the transaction data has a larger abnormal risk in the transmission process, the transaction transmission abnormality representation parameter historical data of several times of normal completion of transaction data transmission is called, the mean value of the transaction transmission abnormality representation parameter is solved, and based on the purpose of setting the parameter standard threshold value, the parameter standard threshold value is determined as the product of the mean value of the transaction transmission abnormality representation parameter and the parameter offset coefficient, wherein the parameter offset coefficient is selected in the interval [1.24, 1.3].
[0104] The process of analyzing the data transmission of the transaction behavior includes:
[0105] S4.1, calling the transaction transmission abnormality representation parameter records corresponding to each time point of the user end from the adjacent transaction payment node to the transaction payment node to obtain the mean value of the transaction transmission abnormality representation parameter corresponding to each time point of the user end from the adjacent transaction payment node to the transaction payment node in several times of completed transaction process;
[0106] S4.2, determining the sensitive interval and the corresponding reference duration, including:
[0107] Based on the mean value of the transaction transmission abnormality representation parameter, a time domain variation curve (i.e. a curve of the mean value of the transaction transmission abnormality representation parameter changing with time) is constructed, and the slope of the corresponding curve segment in each time domain interval is determined;
[0108] If there is a time domain interval corresponding to a slope greater than a preset slope threshold value, the time domain interval is determined as the sensitive interval;
[0109] The time length from the sensitive interval to the starting time of the time domain variation curve is determined as the reference duration;
[0110] S4.3, selecting a control interval based on the current node time and the reference duration, including:
[0111] Determine the current node time, and determine the starting time of the control interval by delaying the reference duration after the time, to construct the control interval;
[0112] The corresponding relationship between the control interval and the sensitive interval is constructed;
[0113] Wherein, the interval length of the control interval and the sensitive interval is the same.
[0114] S4.4, extracting the flow feedback feature in the control interval and matching the historical flow feedback feature in the corresponding sensitive interval to determine the feedback deviation value to adjust the parameter standard threshold value.
[0115] (1) determining the feedback deviation value, comprising:
[0116] obtaining the traffic feedback characteristics of the control interval, including the average uniformity of the traffic time interval corresponding to the transaction behavior and the average receiving delay duration of the target data received by the receiving end;
[0117] obtaining the historical traffic feedback characteristics in the sensitive interval, including the historical average uniformity of the traffic time interval corresponding to the transaction behavior and the historical average receiving delay duration of the target data received by the receiving end;
[0118] calculating the first deviation value of the average uniformity of the traffic time interval and the historical average uniformity, and the second deviation value of the average receiving delay duration of the target data and the historical average receiving delay duration;
[0119] determining the sum of the first deviation value and the second deviation value as the feedback deviation value.
[0120] In this embodiment, the deviation value is calculated by the following method, comprising,
[0121] calculating the absolute value of the difference between the average uniformity and the historical average uniformity as the first absolute value, and the ratio of the first absolute value to the historical average uniformity as the first deviation value;
[0122] Similarly, the absolute value of the difference between the average receiving delay duration and the historical average receiving delay duration is calculated as the second absolute value, and the ratio of the second absolute value to the historical average receiving delay duration is calculated as the second deviation value.
[0123] (2) adjusting the parameter standard threshold, comprising:
[0124] The parameter standard threshold and the feedback deviation value are negatively correlated.
[0125] In this embodiment, the feedback deviation value is compared with the preset first feedback deviation comparison threshold and the second feedback deviation comparison threshold:
[0126] When the feedback deviation value is greater than the second feedback deviation comparison threshold, the parameter standard threshold is determined as the first parameter standard threshold, and the first parameter standard threshold is set as 0.85 times of the parameter standard threshold;
[0127] When the feedback deviation value is greater than or equal to the first feedback deviation comparison threshold and less than or equal to the second feedback deviation comparison threshold, the parameter standard threshold is determined as the second parameter standard threshold, and the second parameter standard threshold is set as 0.9 times of the parameter standard threshold;
[0128] When the feedback deviation value is less than the first feedback deviation comparison threshold, it is determined that the parameter standard threshold is the third parameter standard threshold, and the third parameter standard threshold is set to be 0.95 times of the parameter standard threshold;
[0129] The first feedback deviation comparison threshold is 1.1 times of the feedback deviation threshold, and the second feedback deviation comparison threshold is 1.3 times of the feedback deviation threshold.
[0130] In the embodiment, the purpose of setting the feedback deviation threshold is to represent the case that the target data received by the receiving end is affected by the abnormal risk in the transmission process of the transaction data, and the security of the target data is low. The feedback deviation value historical data of several times of normal completion of transaction data transmission is called to solve the feedback deviation mean value. Based on the purpose of setting the feedback deviation threshold, the feedback deviation threshold is determined as the product of the feedback deviation mean value and the feedback offset coefficient, wherein the feedback offset coefficient is selected in the interval [1.15, 1.2].
[0131] Specifically, the application considers that the transaction habits and traffic patterns of different user ends have certain uniqueness, and the data representation of the data transmission level in the whole process from the current transaction node to the transaction payment node is determined to be strong. By comparing the relevant historical data of the user end, the characteristics of different user ends are fully adapted, so that the detection of transaction security is more personalized, the current transaction abnormality can be accurately identified, the misjudgment or omission caused by the general standard is reduced, the precision and sensitivity of the abnormal detection are improved, therefore, the sensitive interval and the matching interval are matched, so that the system can flexibly select the appropriate historical data interval for comparison and analysis according to the current transaction node, the deviation evaluation determined by matching provides data support for subsequent adjustment of the parameter standard threshold, ensures the effective monitoring of abnormal transactions, enhances the adaptability and flexibility of transaction security detection, and improves the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0132] S5, integrity verification is performed on the target data received by the receiving end in the transaction link.
[0133] Further preferably, the received target data is subjected to integrity verification, wherein the traffic feedback feature includes the uniformity of the traffic time interval for the transaction behavior and the receiving delay time length of the receiving end for the target data.
[0134] Specifically, the target data refers to the data directly related to the payment process. In the embodiment, the data packet composed of the directly related information such as transaction amount, transaction party identity information and account information, transaction time, transaction order information, security verification information, etc. is taken as the target data.
[0135] In the embodiment, the method for integrity verification is not limited, and can be any one of the methods capable of verifying the integrity of the target data in the prior art, which will not be described herein.
[0136] Embodiment 2 of the present application provides a system applying a transaction abnormality monitoring method based on big data fusion, comprising:
[0137] The feature extraction module is configured to call the interaction behavior data in the transaction link, determine whether to trigger a switching action event, extract stable features for the switching action event, and the stable features include event switching speed and event switching frequency in a predetermined time domain segment.
[0138] The behavior marking module is connected with the feature extraction module, configured to determine an event abnormality representation value of the transaction behavior based on the stable features and the page refresh frequency, and mark the transaction behavior.
[0139] The transaction detection module is connected with the behavior marking module, configured to detect and identify the corresponding transaction behavior based on the marking result, including determining a node where the transaction behavior is located, determining whether the node is adjacent to a transaction payment node, acquiring a traffic feedback feature at the time to determine a transaction transmission abnormality representation parameter.
[0140] The response adjustment module is connected with the transaction detection module, and in response to a comparison result of the transaction transmission abnormality representation parameter and a parameter standard threshold, calls transaction transmission abnormality representation parameter records of the user end at each time from the adjacent transaction payment node to the transaction payment node, determines a sensitive interval and a corresponding reference time length, selects a comparison interval based on the current time of the node and the reference time length, matches the traffic feedback feature in the comparison interval with the historical traffic feedback feature in the corresponding sensitive interval, determines a feedback deviation value, and adjusts the parameter standard threshold.
[0141] The target verification module performs integrity verification on the received target data.
[0142] The traffic feedback feature includes uniformity of a traffic time interval of the transaction behavior and a receiving delay time length of the receiving end for the target data.
[0143] In the embodiment, the interaction behavior data in the transaction link is pre-stored in the related database for the feature extraction module to call, which will not be described herein.
[0144] Specifically, the specific structure of the feature extraction module, the behavior marking module, the transaction detection module, the response adjustment module, and the target verification module is not limited, and each unit thereof can be composed of a logic component or a combination of logic components, and the logic component includes a field programmable processor, a computer, or a microprocessor in a computer.
[0145] Embodiment 3 of the present application provides a terminal, comprising a processor and a storage medium; the storage medium is used for storing instructions; the processor is used for operating according to the instructions to execute the steps of the method.
[0146] Embodiment 4 of the present application provides a computer readable storage medium, which stores a computer program, and the program is executed by a processor to realize the steps of the method.
[0147] Compared with the prior art, the present application has at least the following beneficial effects:
[0148] The present application determines whether to trigger a switching action event by calling the interaction behavior data in the transaction link, extracts stable features for the switching action event, determines the event anomaly representation value of the transaction behavior based on the stable features and the page refresh frequency, marks the transaction behavior for abnormal risk, detects and identifies the corresponding transaction behavior based on the marking result, analyzes the data transmission of the transaction behavior in response to the comparison result of the transaction transmission anomaly representation parameter and the parameter standard threshold, and verifies the integrity of the received target data, which can improve the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0149] Further, the present application considers the features presented by the behavior mode of the switching action event in the unit time domain segment and the event anomaly degree of the transaction behavior evaluated by the refresh frequency of the user terminal for the page, and further reflects the transaction security degree. Specifically, under normal circumstances, the user terminal will spend a certain time reading and understanding the information presented by the page during the implementation of the transaction proposal to payment, and the faster switching operation of the page can reflect the possibility of the behavior affecting the transaction security at the current stage; higher switching frequency can reflect the risk of the user terminal trying to find some hidden information or bypass the security verification link in the payment process; and during the implementation of the transaction behavior, the user terminal may refresh the page to obtain new transaction information, in which case the refresh operation frequency implemented to facilitate the identification of transaction information content will not be too high, and too high refresh frequency can represent the risk of interfering with the normal transaction process. Therefore, by comprehensively evaluating the above interaction behavior in the transaction link, the event anomaly representation value of the transaction behavior is determined to represent the security risk degree of the transaction behavior, to provide accurate and reliable data support for subsequent abnormal risk identification and marking of the transaction behavior, so that the present application can improve the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0150] Further, the application focuses on the key sensitive stage of transaction risk, that is, the stage near the transaction payment node, and a large amount of sensitive information exists in the data to be processed in this stage. In normal transactions, the data flow received by the receiving end has certain stability and regularity, and the time interval is relatively uniform. The change in the uniformity of the time interval is analyzed to analyze transaction abnormalities. At the same time, the transaction is carried out in a stable network environment, and the transmission and processing of data are at a relatively stable and uniform speed. Based on the fact that the stage is a high-sensitive stage with transaction risk, the degree of inclination of the receiving end to malicious attacks increases. The transmission abnormality of the related transaction data reflected by the above characteristics is determined to determine the transaction transmission abnormality characteristic parameter. For subsequent comparison with the parameter standard threshold, it provides more convincing basis for determining whether the transaction is abnormal, so that the application can improve the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0151] Further, the application considers that the transaction habits and traffic patterns of different user terminals have certain uniqueness, and the data representation of the data transmission layer in the whole process from the current transaction node to the transaction payment node is determined to be strong. By comparing the relevant historical data of the user terminal, the characteristics of different user terminals are fully adapted, so that the detection of transaction security is more personalized, and the abnormal situation of the current transaction can be accurately identified, the misjudgment or omission caused by the general standard is reduced, and the precision and sensitivity of abnormal detection are improved. Therefore, the sensitive interval and the matching of the control interval are determined, so that the system can flexibly select the appropriate historical data interval for comparison and analysis according to the current transaction node, and the deviation evaluation based on the matching provides data support for subsequent adjustment of the parameter standard threshold, ensures effective monitoring of abnormal transactions, enhances the adaptability and flexibility of transaction security detection, and improves the evaluation accuracy and reliability of transaction security under the premise of ensuring the effect of transaction security detection.
[0152] The present disclosure can be a system, a method, and / or a computer program product. The computer program product can include a computer readable storage medium having computer readable program instructions loaded thereon for causing a processor to implement various aspects of the present disclosure.
[0153] Computer readable storage media can be tangible storage media which can retain and store instructions for use by an instruction execution device. Computer readable storage media can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer readable storage media include the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.
[0154] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.
[0155] Computer readable program instructions for carrying out operations of the present disclosure can be assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate array (FPGA), or programmable logic array (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.
[0156] Finally, it should be noted that the above-mentioned embodiments are merely used to illustrate the technical solutions of the present application, rather than limiting the present application, and although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that the specific embodiments of the present application can be modified or replaced equivalently without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.
Claims
1. A method for monitoring transaction anomalies based on big data fusion, characterized in that, include: S1, retrieve the interaction behavior data in the transaction chain, determine whether a switching action event is triggered based on the interaction behavior data, and extract the stable features of the switching action event; S2, calculate the event anomaly representation value of the transaction behavior based on the stability characteristics and page refresh frequency, and identify and mark abnormal risk behaviors according to the event anomaly representation value; S3, determine whether the node where the abnormal risk behavior is located is close to the transaction payment node. If so, calculate the abnormal transaction transmission characterization parameters based on the traffic feedback characteristics. S4, when the abnormal transaction transmission characteristic parameter is greater than or equal to the parameter standard threshold, an anomaly is determined in the transaction, anomaly information is output, and data transmission analysis is performed on the abnormal risk behavior of nearby transaction payment nodes to adjust the parameter standard threshold; wherein, data transmission analysis on the abnormal risk behavior of nearby transaction payment nodes to adjust the parameter standard threshold includes: S4.1, call the corresponding transaction transmission anomaly representation parameter records of the user terminal at each time from the nearest transaction payment node to the transaction payment node, and calculate the average value of the transaction transmission anomaly representation parameters of the user terminal at each time from the nearest transaction payment node to the transaction payment node in several transaction processes; S4.2, Determine the sensitive interval and the reference duration corresponding to the sensitive interval based on the mean value of the abnormal transaction transmission characteristic parameters; S4.3, construct a reference interval based on the current node's current time and the reference duration, and associate it with the corresponding sensitive interval; S4.4 Obtain the flow feedback characteristics within the control interval and the historical flow feedback characteristics within the corresponding sensitive interval, and determine the feedback deviation value based on the obtained characteristics, so as to adjust the parameter standard threshold.
2. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: The stability features include the event switching speed and event switching frequency within a predetermined time domain.
3. The transaction anomaly monitoring method based on big data fusion according to claim 2, characterized in that: In S2, the event anomaly representation value of the transaction behavior is calculated based on the stability characteristics and page refresh frequency, including: The sum of the ratio of event switching speed to event switching speed threshold and the ratio of event switching frequency to event switching frequency threshold is taken as the first security feature; The ratio of page refresh rate to page refresh rate threshold is used as the second security feature; The weighted sum of the first security feature and the second security feature is used as the event anomaly characterization value.
4. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: In S2, abnormal risk behaviors are identified and marked based on the event anomaly representation value, including: If the event anomaly representation value is greater than or equal to the event anomaly representation threshold, the corresponding transaction behavior will be marked as an abnormal risk behavior.
5. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: In S3, determining whether the node where the abnormal risk behavior occurs is close to the transaction payment node includes: Call several path nodes corresponding to the pre-selected stored transaction jump path to determine the path node corresponding to the node where the abnormal risk behavior is located. If the next adjacent path node corresponding to the current path node is a payment node, then it is determined that the node where the abnormal risk behavior is located is adjacent to the transaction payment node.
6. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: In S3, transaction transmission anomaly characterization parameters are calculated based on traffic feedback characteristics, including: Obtain traffic feedback characteristics, including the uniformity of traffic time intervals and the reception delay of the receiver for the target data, where the uniformity of traffic time intervals is the time difference between consecutively received data packets at the receiver. The ratio of the uniformity threshold to the uniformity of the traffic time interval is used as the first transmission anomaly feature. The ratio of the received delay duration to the received delay duration threshold is used as the second transmission anomaly feature; The sum of the first transmission anomaly feature and the second transmission anomaly feature is used as the transaction transmission anomaly characterization parameter.
7. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: In S4.2, determining the sensitive interval and the corresponding reference duration based on the mean of the transaction transmission anomaly characterization parameters includes: Based on the mean of the abnormal transaction transmission parameters, construct its time-domain variation curve and determine the slope of the corresponding curve segment in each time-domain interval; If there is a time domain interval whose slope is greater than a preset slope threshold, then the corresponding time domain interval is determined as a sensitive interval. The time length from the sensitive interval to the start time of the time domain change curve is used as the reference duration corresponding to the sensitive interval.
8. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: In S4.3, a reference interval is constructed based on the current node's current time and the reference duration, and the corresponding sensitive interval is associated with it, including: Determine the current node's time, extend the reference duration after that time, and determine the start time of the comparison interval to construct the comparison interval. The comparison interval has the same length as the sensitive interval corresponding to the reference duration. Associate the comparison interval with the corresponding sensitive interval.
9. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: In S4.4, the flow feedback characteristics within the control interval and the historical flow feedback characteristics within the corresponding sensitive interval are obtained, and the feedback deviation value is determined based on the obtained characteristics, including: Obtain the traffic feedback characteristics of the control interval, including the average uniformity of the traffic time interval corresponding to the transaction behavior at the receiving end and the average reception delay of the receiving end for the target data. Obtain historical traffic feedback characteristics within the corresponding sensitive interval, including the historical average of the traffic time interval for the corresponding transaction behavior and the historical average of the receiving delay for the target data at the receiving end. The first deviation value is calculated based on the average uniformity of the obtained flow time intervals and the average historical uniformity. The second deviation value is calculated based on the average reception delay of the target data at the receiving end and the average historical reception delay. The sum of the first deviation value and the second deviation value is determined as the feedback deviation value.
10. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: The standard threshold value of the parameter is negatively correlated with the feedback deviation value.
11. The transaction anomaly monitoring method based on big data fusion according to claim 1, characterized in that: It also includes S5, which verifies the integrity of the target data received by the receiving end in the transaction chain.
12. A system for monitoring transaction anomalies based on big data fusion as described in any one of claims 1-11, characterized in that, The system includes: The feature extraction module is used to retrieve interaction behavior data in the transaction chain, determine whether a switching action event is triggered based on the interaction behavior data, and extract stable features of the switching action event. The behavior marking module, connected to the feature extraction module, is used to calculate the event anomaly representation value of the transaction behavior based on the stable features and the page refresh frequency, and to identify and mark abnormal risk behaviors based on the event anomaly representation value. The transaction detection module is connected to the behavior marking module to determine whether the node where the abnormal risk behavior is located is close to the transaction payment node. If so, the abnormal transaction transmission characterization parameters are calculated based on the traffic feedback characteristics. The response adjustment module, connected to the transaction detection module, determines that a transaction is abnormal when the abnormality characterization parameter of the transaction transmission is greater than or equal to the parameter standard threshold, outputs abnormal information, and performs data transmission analysis on the abnormal risk behavior of nearby transaction payment nodes in order to adjust the parameter standard threshold.
13. A terminal, comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is configured to operate according to the instructions to perform the steps of the method according to any one of claims 1-11.
14. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the steps of the method according to any one of claims 1-11.
Citation Information
Patent Citations
Payment risk identification method, device and equipment
CN113516480A
Payment order anomaly detection method based on standard deviation dynamic threshold
CN119004335A
Abnormal transaction prevention and control method and device, computer equipment and readable storage medium
CN120494971A