Visual financial data dynamic analysis method and system
By collecting and evaluating network access data in real time in a visualized financial cloud platform, an exposure index R1 and a response strategy strength R2 are constructed. This solves the problem that existing systems cannot identify the network exposure risks of financial data in real time, realizes dynamic hardening control and strategy optimization, and improves the security of data access and the efficiency of resource allocation.
Patent Information
- Application Number
- CN202511433037.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-09
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2045-10-09
AI Technical Summary
Existing visual financial systems cannot assess the network exposure risk of financial data during access in real time and quantitatively. This allows high-risk users to bypass encrypted links to access sensitive data. Furthermore, it is difficult to identify abnormal paths and data exposure trends in complex network environments, which affects the quality of data security defense.
By setting up a detection program in the visualized financial cloud platform, network access data is collected in real time, an exposure index R1 is constructed and a risk assessment is conducted, a path hardening mechanism is triggered, dynamic hardening control is carried out in combination with the response strategy strength R2, and resource investment is optimized through the summary result evaluation function R3.
It enables real-time risk quantification and visualization of financial data access, enhances the protection capabilities of high-risk paths, ensures adaptive matching between strategies and risks, possesses self-diagnosis and strategy optimization capabilities, and enhances the security of data access and the efficiency of resource allocation.
Smart Images

Figure CN120910481A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data analysis, in particular to a visualized financial data dynamic analysis method and system. BACKGROUND
[0002] With the wide deployment of enterprise information systems in cloud platforms, hybrid offices and remote access scenarios, financial data has gradually evolved into dynamic data assets with cross-terminal, cross-path, multi-role concurrent access. Under this background, a single access behavior may lead to potential exposure of data in the access process due to complex access paths, unstable network conditions, diverse device environments, or non-uniform encryption configurations. How to make real-time, quantitative and visualized judgments on the exposure intensity of financial data in the network in each access has become one of the important research directions to protect the security of core digital assets of enterprises.
[0003] At present, in the visualized financial system, the monitoring of financial data access is mostly concentrated on the access operation behavior layer, such as who accesses what and how the access frequency is, but there is a lack of effective perception means for the exposure risk of the network path itself in the access process. Common methods such as access log auditing or static permission checking can only determine whether the access is legal and record the access operation itself, but cannot reveal the real-time exposure risk of data in the access channel due to insecure network paths, deteriorated transmission environment, incomplete path encryption or untrusted access source, etc. This leads to the fact that the management system cannot adjust the access strategy or make security response decisions based on the network dynamic environment, and it is also impossible to present the visual state of potential risks in real time and intuitively on the financial layer; The above problems are mainly caused by the fact that the existing system decouples access control and network security in architecture, does not take the security posture of the access data path as part of the real-time visualized analysis, and lacks fusion modeling and risk index calculation of access environment parameters, encryption state, path node complexity and other multi-source heterogeneous risk factors. This mechanism defect will directly lead to the following security risks: first, high-risk accessors may bypass the normal trust recognition system through low-encryption links and access sensitive data without being warned; second, the system is difficult to identify network-side security signals such as abnormal path aggregation and data exposure trend aggregation in a timely manner, leading to data exposure in the access process without early warning; third, in the complex network environment change scenarios such as remote office and mobile device access, traditional static analysis cannot adapt to the rapid response demand, thereby affecting the overall defense quality and risk disposal capability of the financial data system. SUMMARY
[0004] In view of the deficiencies of the prior art, the present application provides a visualized financial data dynamic analysis method and system, which solves the problems mentioned in the background art.
[0005] To achieve the above object, the present application is implemented by the following technical solutions: comprising the following steps: S1, by setting a detection program in the visual financial cloud platform, real-time collection of each financial data access record network access data, and preprocessing network access data, obtaining standardized data set; S2, based on the standardized data set, the exposure index R1 is calculated and output, and the exposure risk interval threshold is set to preliminarily compare and evaluate the exposure index R1, and the trigger path reinforcement mechanism is triggered based on the preliminary comparison and evaluation result; S3, after triggering the path reinforcement mechanism, the exposure index R1 is calculated and output to measure the original risk score of the current visitor; S4, according to the response strategy intensity R2, different path reinforcement strategy rule sets are divided, and the related control content is executed according to different path reinforcement strategy rule sets; S5, based on the exposure index R1 and the response strategy intensity R2, the summary result evaluation function R3 is calculated and output, and the comprehensive evaluation threshold Rth is set to perform secondary comparison and evaluation to judge the rationality of the current response resource input.
[0006] Preferably, the S1 comprises S11 and S12; S11, setting a monitoring program in the visual financial cloud platform, real-time monitoring of user access to each visual financial data access record network access data; The network access data includes access source IP credit value Esrc, network quality attenuation factor Pqos, user behavior deviation Tact, financial data sensitivity Nsen, route intermediate node exposure number Vpath and encryption integrity factor Wcrypto; S12, preprocessing the obtained network access data to obtain a standardized data set; The preprocessing includes missing value processing, legality verification and normalization processing; The missing value processing and legality verification are performed by legality boundary verification on all network access data, and the illegal data is processed; The legality boundary verification is performed by eliminating the access source IP credit value Esrc, user behavior deviation Tact, financial data sensitivity Nsen and encryption integrity factor Wcrypto not belonging to [0, 1], and using the historical mean of the current parameter to complete; At the same time, the data of network quality attenuation factor Pqos≤0 and route intermediate node exposure number Vpath≤0 are eliminated, and the default minimum value is used to complete; The normalization processing is performed on the network access data after the missing value processing and the validity check, and the Min-Max normalization method is used to eliminate the dimensional influence in the network access data, so as to obtain a standardized data set.
[0007] Preferably, the S2 comprises S21 and S22. The S21 calculates an exposure index R1 based on the standardized data set, and the exposure index R1 measures the exposure risk intensity of a single financial data access behavior. The exposure index R1 is calculated by the following algorithm formula. ; In the formula, log represents a logarithmic function.
[0008] Preferably, the S22 extracts a statistical distribution of the exposure index R1 of each access in history, sets an exposure risk interval threshold according to the quantile of the statistical distribution of the exposure index R1, and the exposure risk interval threshold comprises a first exposure risk threshold F1 and a second exposure risk threshold F2, wherein the first exposure risk threshold F1 takes the 50% quantile of the statistical distribution of the exposure index R1, and the second exposure risk threshold F2 takes the 85% quantile of the statistical distribution of the exposure index R1, that is, the first exposure risk threshold F1 is a warning boundary, and the second exposure risk threshold F2 is a danger boundary. The exposure index R1 obtained in real time is preliminarily compared and evaluated with the exposure risk interval threshold, the data exposure of the single financial data access behavior is judged, and a path reinforcement mechanism is triggered based on the preliminary comparison and evaluation result, and the specific evaluation content is as follows. When the exposure index R1 is less than the first exposure risk threshold F1, it indicates that there is no exposure risk in accessing the visualized financial data by the current visitor, and at this time, no operation is needed for normal release. When the first exposure risk threshold F1 is less than or equal to the exposure index R1 and the exposure index R1 is less than the second exposure risk threshold F2, it indicates that there is an abnormality in accessing the visualized financial data by the current visitor, at this time, a yellow triangular warning icon is superimposed in the visualized financial data layer, and the standardized data set of the current visitor is recorded in the security log pool, after 5 minutes, the exposure index R1 of the current visitor is re-analyzed, and the preliminary comparison and evaluation is performed again, if the abnormality still exists in the second time, the warning is skipped and the current visitor is limited to access, and the path reinforcement mechanism is triggered. When the exposure index R1 is greater than or equal to the second exposure risk threshold F2, the current visitor is immediately limited to access, and the path reinforcement mechanism is directly triggered.
[0009] Preferably, the S3 comprises S31. S31, after triggering the path reinforcement mechanism, based on the exposure index R1 obtained, the user behavior deviation Tact in the standard data set, the number of exposure of the intermediate nodes in the routing Vpath and the encryption integrity factor Wcrypto, the response strategy strength R2 is calculated and output, and the original risk score of the current visitor is measured; The response strategy strength R2 is calculated and output by the following algorithm formula; ; In the formula, e represents the exponential function, represents the global control coefficient, which is used to adjust the response strength dimension of the whole formula output, and the specific value is set by the user, which is dimensionless.
[0010] Preferably, the S4 includes S41 and S42; S41, based on the response strategy strength R2 of the current visitor, the path reinforcement strategy rule set is combined and divided, which includes RSP-A, RSP-B, RSP-C and RSP-D, and is combined and divided by the following method; When the response strategy strength R2∈[6.0,7.5], it is divided into RSP-A; When the response strategy strength R2∈[7.5,8.5], it is divided into RSP-B; When the response strategy strength R2∈[8.5,9.8], it is divided into RSP-C; When any two types of path reinforcement strategy rules are met and the response strategy strength R2≥9.8, it is divided into RSP-D.
[0011] Preferably, S42, based on the divided path reinforcement strategy rule set, the related control content is executed to reinforce the access path of the current visual financial data, and the specific related control content is as follows; When it is divided into RSP-A, the access interface is switched to an end-to-end encryption mode, and the access path is optimized, only 2-hop path is reserved, and the load balancing gateway is disabled; When it is divided into RSP-B, the device binding authentication is started, the hardware is bound with the visual financial data platform fingerprint, and one kind of access verification mechanism is added; When it is divided into RSP-C, the access permission is automatically degraded to read-only mode, and secondary verification code verification is performed; When it is divided into RSP-D, the temporary access buffer is opened, the original financial data is not directly read, the financial data operation is executed for 5 minutes, then the access log is synchronized and written, and uploaded to the security monitoring for manual review.
[0012] Preferably, the S5 includes S51 and S52; S51, after the path reinforcement mechanism is executed, the exposure index R1 and the response strategy strength R2 of all visitors are recalculated, and the summary calculation output summary result evaluation function R3 is obtained by summarizing and summing up, and the response effect of the path reinforcement mechanism is comprehensively measured; The summary result evaluation function R3 is calculated by the following algorithm formula; ; In the formula, n represents the total number of access records in the statistical period, R1 i represents the exposure index of the i th access request, R2 i represents the response strategy strength of the i th access request.
[0013] Preferably, S52, based on the critical point of the user according to the security defense demand, the comprehensive evaluation threshold Rth is set, and the real-time obtained comprehensive evaluation threshold Rth is compared and evaluated with the summary result evaluation function R3, and the current security state and resource use efficiency in the whole time window after the path reinforcement mechanism is executed are comprehensively analyzed, and the specific evaluation content is as follows; When the summary result evaluation function R3 is less than the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement mechanism is reasonable, and the existing strategy is maintained; When the summary result evaluation function R3 is greater than or equal to the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement mechanism is unreasonable, at this time, a red warning is generated, prompting the operation and maintenance personnel to reconstruct the path reinforcement strategy rule set.
[0014] A visual financial data dynamic analysis system, comprising an access data detection processing module, an exposure analysis module, a response strategy analysis module, a path reinforcement strategy execution module and a comprehensive response analysis module; The access data detection processing module sets a detection program in the visual financial cloud platform, collects network access data of each financial data access record in real time, and pre-processes the network access data to obtain a standardized data set; The exposure analysis module calculates the exposure index R1 based on the standardized data set, sets the exposure risk interval threshold, and preliminarily compares and evaluates the exposure index R1, and then triggers the path reinforcement mechanism based on the preliminary comparison and evaluation result; The response strategy analysis module calculates the response strategy strength R2 based on the exposure index R1 after triggering the path reinforcement mechanism, and measures the original risk score of the current visitor; The path reinforcement strategy execution module divides the response strategy strength R2 into different path reinforcement strategy rule sets according to the response strategy strength R2, and executes related control contents according to different path reinforcement strategy rule sets; The comprehensive response analysis module outputs a summary result evaluation function R3 by performing summary calculation based on the obtained exposure index R1 and response strategy strength R2, and sets a comprehensive evaluation threshold Rth for secondary comparison and evaluation to judge the rationality of the current response resource input.
[0015] The application provides a visual financial data dynamic analysis method and system. (1) The method can quantize the network exposure risk intensity of the access in real time when the access occurs by setting a monitoring program in the visual financial cloud platform, collecting the access source IP credit value Esrc, network quality attenuation factor Pqos, user behavior deviation degree Tact, financial data sensitivity Nsen, exposure number of intermediate nodes Vpath and encryption integrity factor Wcrypto of each access record, constructing a standardized data set, combining a nonlinear risk weighting algorithm to output an exposure index R1, and comparing and evaluating the R1 output result with the set risk interval threshold in real time, and presenting and triggering the path reinforcement mechanism in the form of a warning icon on the visual financial chart, which effectively improves the identification ability and response preposition of the high-risk access path, and enhances the visual protection ability of the financial data in the access path.
[0016] (2) After the exposure index R1 of the single access behavior is identified and the preliminary risk partition is judged, the method further calculates the response strategy strength R2, and divides the access behavior into a path reinforcement strategy rule set according to the response strategy strength R2. Each strategy rule set corresponds to different access reinforcement control contents, such as end-to-end encryption mode switching, binding authentication mechanism starting, access permission automatic degradation and access data delay decoupling. The mechanism can dynamically select the reinforcement response scheme according to the current behavior, path and environmental factors of the visitor, so as to improve the protection accuracy and sensitivity of the high-risk access path, avoid resource waste caused by excessive reinforcement of the low-risk access, and realize the adaptive matching and on-demand configuration between the strategy and the risk.
[0017] (3) The method constructs a summary result evaluation function R3 by weighting and summarizing the exposure index R1 and the response strategy strength R2 of all visitors in the statistical period, to quantify the overall effectiveness of the system in a certain time window. By comparing the summary result evaluation function R3 with the user-set comprehensive evaluation threshold Rth, it is determined whether the current path reinforcement mechanism is reasonable. If the summary result evaluation function R3 is lower than the threshold, the existing strategy is maintained. If the summary result evaluation function R3 is higher than the threshold, a red warning is triggered, prompting to reconstruct the path reinforcement strategy rule set. The mechanism builds a complete technical closed-loop path from access risk identification, strategy control execution, to overall protection result evaluation, enabling the system to have self-diagnosis ability and strategy self-optimization ability in long-term operation, ensuring that the platform can still run stably, safely and efficiently when facing complex dynamic access behaviors. BRIEF DESCRIPTION OF DRAWINGS
[0018] Figure 1 A visual financial data dynamic analysis method step schematic diagram of the present application; Figure 2 A visual financial data dynamic analysis system flowchart of the present application; Figure 3 A network access data dynamic radar chart of the present application. DETAILED DESCRIPTION
[0019] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0020] Embodiment 1 Please refer to Figure 1 and Figure 3 The present application provides a visual financial data dynamic analysis method. To achieve the above purpose, the present application is implemented by the following technical solutions: comprising the following steps: S1, by setting a detection program in the visual financial cloud platform, real-time collecting network access data of each financial data access record, and pre-processing the network access data to obtain a standardized data set; S2, based on the standardized data set, calculating and outputting the exposure index R1, and setting the exposure risk interval threshold to preliminarily compare and evaluate the exposure index R1, and then triggering the path reinforcement mechanism based on the preliminary comparison and evaluation result; S3, after triggering the path reinforcement mechanism, calculating and outputting the response strategy strength R2 based on the exposure index R1 to measure the original risk score of the current visitor; S4, dividing into different path reinforcement strategy rule sets according to the response strategy strength R2, and performing relevant control content according to different path reinforcement strategy rule sets; S5, based on the obtained exposure index R1 and response strategy strength R2, performing summary calculation to output a summary result evaluation function R3, setting a comprehensive evaluation threshold Rth for secondary comparison and evaluation, and judging the rationality of the current response resource input.
[0021] In this embodiment, the method first deploys a network access monitoring program in the S1 step based on the visual financial cloud platform, collects and pre-processes six types of network access data involved in each financial data access record in real time, and constructs a standardized data set; in the S2 step, the exposure index R1 of a single access behavior is output by fusing a multi-factor nonlinear weighted risk modeling algorithm, and a preliminary risk partition evaluation is performed in real time combined with the exposure risk interval threshold set based on the historical access distribution, and the path reinforcement mechanism is triggered under the condition of medium and high risk; in the S3 step, the response strategy strength R2 is further calculated based on the exposure index R1 and the key parameters in the standard data set, which is used to measure the defense control strength required by the current visitor; in the S4 step, the system dynamically divides the path reinforcement strategy rule set according to the R2 value, and implements end-to-end encryption, permission degradation, device binding and other diversified security control strategies for the access path; finally, in the S5 step, the summary result evaluation function R3 is calculated by multiplying the exposure index R1 and the response strategy strength R2 record by record, and compared with the comprehensive evaluation threshold Rth set by the user, to realize the whole cycle efficiency feedback and strategy self-regulation of the path reinforcement mechanism. Through the cooperative implementation of the above steps, the potential network exposure risk of each financial data access request can be accurately identified without changing the existing hardware architecture, and the response level is dynamically divided and the security strategy is adaptively reinforced based on the risk level, and finally the rationality of the access protection resource input is evaluated through the closed-loop evaluation of the summary index, so as to achieve the technical targets of improving access security awareness, strengthening the accuracy of strategy response, optimizing resource allocation efficiency and building a data defense intelligent closed loop. The method significantly improves the dynamic protection capability of enterprise financial data in complex network environment, and provides an innovative security solution for fine, visual and closed-loop control of high-sensitive data access control.
[0022] Embodiment 2 Please refer to Figure 1 and Figure 3 Specifically, S1 includes S11 and S12; S11, setting a monitoring program in the visual financial cloud platform to monitor the network access data of each visual financial data access record accessed by the user in real time; The network access data includes an access source IP reputation value Esrc, a network quality attenuation factor Pqos, a user behavior deviation degree Tact, a financial data sensitivity Nsen, a number of exposed intermediate nodes Vpath in routing, and an encryption integrity factor Wcrypto; The access source IP reputation value Esrc is obtained by using an IP detection program to obtain an IP address from an HTTP request header of the visitor, performing real-time query on the IP address by using an IP reputation library, and calling a third-party API to extract the access source IP reputation value Esrc; The network quality attenuation factor Pqos is obtained by using a Ping command in a network detection program and a packet capture tool Wireshark to obtain TCP network delay RTT and packet loss rate Db between the client and the visual financial cloud platform, and performing calculation and output based on the TCP network delay RTT and the packet loss rate Db, and the specific calculation formula is: Wherein RTTmax represents an upper limit value of the TCP network delay, which is set by the user according to the business requirement; The user behavior deviation degree Tact is obtained by setting a JS point user operation monitoring program in a front-end Web page and a mobile APP of the visual financial cloud platform, recording a behavior sequence of the visitor, using ELKStack to analyze the behavior sequence, and using a clustering analysis algorithm to calculate a deviation score of the current behavior sequence from a historical normal behavior sequence; The financial data sensitivity Nsen is obtained by setting a static classification mark for the sensitivity of the financial data in the visual financial cloud platform, automatically calling the static classification mark of the financial data involved in the current request when the financial data is accessed, and assigning the financial data sensitivity Nsen; The number of exposed intermediate nodes Vpath in routing is obtained by using an ICMP TTL tracking tool to record the number of intermediate hops, i.e., the number of exposure points, that the data needs to pass through from the client to the server; The encryption integrity factor Wcrypto is obtained by starting TLShandshakelogging on the gateway and the proxy, and periodically scanning the channel encryption strength by using a tool ssllabs-scan; S12, preprocessing the obtained network access data to obtain a standardized data set; The preprocessing includes missing value processing, legality verification, and normalization processing; The missing value processing and the legality verification are performed by performing legality boundary verification on all the network access data, and processing the illegal data; The legality boundary verification is performed by excluding the access source IP reputation value Esrc, the user behavior deviation degree Tact, the financial data sensitivity Nsen, and the encryption integrity factor Wcrypto that do not belong to [0, 1], and using the historical mean of the current parameters to complete. Meanwhile, data with network quality attenuation factor Pqos≤0 and route intermediate node exposure number Vpath≤0 are removed, and a default minimum value is used to complete the removal; The normalization processing is performed on the network access data after the missing value processing and the legality verification, and the Min-Max normalization method is used to eliminate the dimension influence in the network access data, so as to obtain a standardized data set.
[0023] In this embodiment, the method is implemented by the joint execution of the S11 and S12 sub-steps included in the S1 step. The system first sets a multi-source monitoring program in the visual financial cloud platform, and collects network access behavior data generated when a user accesses visual financial data around six parameter dimensions with attack surface representativeness and network link state correlation, including access source IP reputation value Esrc, network quality attenuation factor Pqos, user behavior deviation degree Tact, financial data sensitivity Nsen, route intermediate node exposure number Vpath and encryption integrity factor Wcrypto. Among them, the access source reputation value is obtained by combining the IP reputation library and the third-party API, the network quality index is obtained by means of Ping and Wireshark tools to obtain the delay and packet loss rate, the behavior deviation degree is dynamically calculated based on JS burying and clustering algorithm, the data sensitivity is extracted by calling static classification marking of access resources, the path exposure number is quantified by ICMP-TTL tracking, and the encryption integrity factor is obtained by TLS handshake log and channel encryption scanning, forming a multi-dimensional, fine-grained and high real-time access parameter set. Then in the S12 sub-step, the standardization processing procedure is performed on the collected data. First, the illegal data is removed and the missing data is repaired according to the historical mean or the default minimum value through the legality boundary verification and the missing value completion mechanism; then, the dimensionless processing is performed on all effective parameter values by using the Min-Max normalization method, so as to obtain a unified standardized data set which can be used for subsequent modeling analysis. Through the implementation of the above S1 step, the present application not only realizes the real-time capture of the full-path security features of the user financial data access link, but also ensures the availability of the data quality and the consistency of the model input through the standardized data processing mechanism, significantly improves the precision and reliability of the subsequent exposure index R1, response strategy strength R2 and summary result evaluation function R3 and other algorithm modules, and finally achieves the comprehensive technical target of "multi-dimensional security feature accurate extraction, risk index quantitative analysis and intelligent prevention and control strategy support" for the financial data access behavior, which provides a solid foundation for building a financial security management and control system with dynamic visual analysis capability and strategy adaptability.
[0024] Embodiment 3 Please refer to Figure 1 , in particular: S2 includes S21 and S22; S21, calculating an exposure index R1 based on the standardized dataset, measuring the exposure risk intensity of a single financial data access behavior; The exposure index R1 is calculated by the following algorithm formula: ; In the formula, log represents the logarithmic function; represents whether the starting point of the access path connection of the visitor is trustworthy. If the visitor has high credibility, such as coming from a registered VPN or encrypted end-to-end, the product is close to 1, and the remaining 1 minus the product is close to 0, indicating that the risk is low; If the IP reputation is poor and the encryption is poor, the product is small, and the risk compensation factor is large. The square amplification processing is used to form an exponential risk increase mechanism for the combination of poor reputation and poor encryption; represents abnormal behavior operations in the high-sensitive data domain, i.e., a sharp increase in exposure risk, with a quadratic emphasis on the nonlinear impact of deviation, avoiding underestimation of small deviations; represents network instability, high latency, and packet loss, which also non-linearly increases the probability of data leakage. The square amplification indicates that the risk is accelerated when the link is poor. represents that the more hops there are, the more opportunities there are for data to be hijacked. The use of logarithm indicates that the path risk grows but tends to be saturated, with nonlinear increase but limited growth. The physical meaning of the formula is that the exposure risk of financial data is the risk that certain financial information may be abnormally aware or misused due to the comprehensive reasons of access path, behavior, network, security settings, etc. when being accessed. Identifying and managing it is not only an important part of security protection, but also an important means of enterprise compliance, risk control, and digital asset protection.
[0025] S22, extracting the exposure index R1 statistical distribution of each access in history, setting an exposure risk interval threshold according to the quantile of the exposure index R1 statistical distribution, the exposure risk interval threshold including a first exposure risk threshold F1 and a second exposure risk threshold F2, wherein the first exposure risk threshold F1 takes the 50% quantile of the exposure index R1 statistical distribution, and the second exposure risk threshold F2 takes the 85% quantile of the exposure index R1 statistical distribution, i.e., the first exposure risk threshold F1 is the early warning boundary, and the second exposure risk threshold F2 is the danger boundary; In the preliminary comparison and evaluation of the exposure index R1 obtained in real time and the exposure risk interval threshold, the data exposure of a single financial data access behavior is judged, and the trigger path reinforcement mechanism is triggered based on the preliminary comparison and evaluation result. The specific evaluation content is as follows: When the exposure index R1 is less than the first exposure risk threshold F1, it indicates that there is no exposure risk for the current visitor to access the visualized financial data, the risk is acceptable, the access source is reliable, the path encryption is complete, and the behavior is reasonable, so no operation is needed for normal release; When the first exposure risk threshold F1 is less than the exposure index R1 and the second exposure risk threshold F2, it indicates that there is an abnormality in the current visitor's access to the visualized financial data, i.e., there is a certain abnormality, such as slight network degradation, slight deviation in behavior, and sensitive data, so a yellow triangular warning icon is superimposed on the visualized financial data layer, and the standardized data set of the current visitor is recorded in the security log pool. After 5 minutes, the exposure index R1 of the current visitor is reanalyzed and a preliminary comparison and evaluation is performed again. If there is still an abnormality the second time, the current visitor's access is restricted and the path reinforcement mechanism is triggered. When the exposure index R1 is greater than or equal to the second exposure risk threshold F2, it indicates that the access source is poor, the encryption is insufficient, the path is complex, the data is sensitive, and the behavior deviation is significant, so the current visitor's access is immediately restricted and the path reinforcement mechanism is directly triggered.
[0026] In this embodiment, the method is implemented by the joint execution of S21 and S22 sub-steps in S2. Based on the obtained standardized network access data set, the system first constructs an exposure index R1 based on a nonlinear composite risk modeling algorithm, which is used to measure the potential exposure intensity of a single financial data access behavior in the network path. The exposure index R1 formula is constructed by comprehensively considering multiple dimensions such as access source reputation and encryption quality, behavior deviation on high-sensitivity data, link degradation degree, and path hop saturation characteristics, combining polynomial and logarithmic functions to realize exponential amplification of abnormal combination risk and saturation weakening of acceptable behavior, fully reflecting the exposure risk change law of data access behavior in a complex network environment, and effectively solving the problems of single factor judgment failure and risk sensitivity deficiency in traditional methods. In S22 sub-step, the full access distribution characteristics of historical exposure index R1 value are further extracted, and dynamic risk interval thresholds are set according to quantile method, including the first exposure risk threshold F1 as the early warning boundary, i.e. the median, and the second exposure risk threshold F2 as the dangerous boundary, which are used for preliminary comparative evaluation of real-time exposure index R1 value, and rapid judgment of the risk level of access behavior. In the evaluation result, a three-section response logic is implemented: normal release in low-risk state, issuing a visual layer warning and delaying evaluation in medium-risk state, and directly limiting access and triggering subsequent path reinforcement mechanism in high-risk state, realizing a fast closed-loop judgment from identification, warning to control. Through the implementation of S2 step, the present application realizes real-time quantitative identification and level evaluation of the risk intensity of each financial data access record, significantly improves the response proactivity and control accuracy of financial data security protection, and at the same time, the adaptive setting of evaluation threshold based on historical distribution enhances the adaptability to the dynamic change of risk in different network environments, further improving the data access risk control ability and strategy scheduling intelligence level of the whole platform.
[0027] Embodiment 4 Please refer to Figure 1 , specifically: S3 includes S31; S31, after triggering the path reinforcement mechanism, the exposure index R1 obtained is combined with the user behavior deviation degree Tact in the standard data set, the exposure number Vpath of the routing intermediate node, and the encryption integrity factor Wcrypto to calculate and output the response strategy strength R2, and measure the original risk score of the current visitor; The response strategy strength R2 is calculated and output by the following algorithm formula; ; In the formula, e represents an exponential function, represents a global control coefficient, which is used to adjust the response strength dimension of the whole formula output, and the specific value is set by the user, which is dimensionless; The calculation logic and physical meaning of the formula is that, first represents a Sigmoid risk activation function, Sigmoid is a smooth nonlinear activation function that can compress any real number to the interval (0, 1), which is used here to map the result of adding the user behavior deviation degree Tact and the exposure number of the routing intermediate node Vpath to an activation degree, and after the two are added, 1 is subtracted to make the normal level, such as a 2-hop path plus a slight deviation = 1, as a 0-point input, so that the Sigmoid function outputs 0.5 at 1, which has symmetry and sensitivity; represents the encryption incompleteness degree of the current path, if the encryption degree is high, the encryption integrity factor Wcrypto tends to 0, which can offset the activation term, if the encryption is poor, it tends to 1, and the risk is maximally amplified; Finally, all are given to the global control coefficient for adjustment to adapt to different sensitivity requirements.
[0028] In this embodiment, through the specific implementation of S31 in S3, after triggering the path reinforcement mechanism, further based on the exposure index R1 obtained, and combined with the three key parameters in the standardized data set closely related to path security and user behavior: user behavior deviation degree Tact, routing intermediate node exposure number Vpath and encryption integrity factor Wcrypto, a comprehensive scoring mechanism of response strategy strength R2 is constructed to make a more fine quantitative evaluation of the original security risk level of the current visitor. This calculation model introduces a nonlinear activation function Sigmoid as the risk activation core, sums the user behavior deviation degree Tact and the routing intermediate node exposure number Vpath, and then centralizes it, so that it is sensitive to the normal level and quickly rises when it is abnormally deviated, which reflects the collaborative risk response ability to "behavior deviation plus hop number increase"; at the same time, the encryption integrity factor Wcrypto is introduced as a negative adjustment term, which is used to reflect the inhibition ability of path encryption integrity to the overall risk, so that the activation strength of the well-encrypted path is naturally lowered, thereby realizing the dynamic "compensation weight reduction" of the risk control effect. In addition, a global control coefficient is set to adapt to the strategy sensitivity requirements in different business scenarios, so that the model has flexible adjustment ability and is suitable for multiple types of access environments. Finally, the output of the response strategy strength R2 is not only a quantitative index of the user access risk level, but also a core basis for dividing the subsequent path reinforcement strategy rule set. Through the implementation of S3, the invention effectively breaks through the problem that the traditional static rule or simple scoring method cannot distinguish the risk intensity level, and significantly improves the accurate perception and judgment ability of the strategy response mechanism to high-risk access behavior.
[0029] Embodiment 5 Please refer toFigure 1 Specifically, S4 includes S41 and S42. S41, based on the response strategy strength R2 of the current visitor, the path reinforcement strategy rule set is combined and divided, including RSP-A, RSP-B, RSP-C and RSP-D, which is combined and divided in the following way; When the response strategy strength R2 ∈ [6.0, 7.5], it means that the path structure is complex, and the encryption quality is poor, which is divided into RSP-A; When the response strategy strength R2 ∈ [7.5, 8.5], it means that the user behavior deviates seriously, and the source is untrusted, which is divided into RSP-B; When the response strategy strength R2 ∈ [8.5, 9.8], it means that the data is highly sensitive and the network is significantly abnormal, which is divided into RSP-C; When any two types of path reinforcement strategy rules are met and the response strategy strength R2 ≥ 9.8, it means that multiple dimensions are triggered together, and the risk is amplified synergistically, which is divided into RSP-D.
[0030] S42, based on the divided path reinforcement strategy rule set, the relevant control content is executed to reinforce the access path of the current visual financial data, and the specific relevant control content is as follows; When divided into RSP-A, switch the access interface to end-to-end encryption mode, and optimize the access path, only keep 2-hop path, disable load balancing gateway; When divided into RSP-B, start device binding authentication, bind hardware with visual financial data platform fingerprint, and increase one kind of access verification mechanism; When divided into RSP-C, the access permission is automatically downgraded to read-only mode, and the secondary verification code verification is performed; When divided into RSP-D, open temporary access buffer, do not directly read original financial data, financial data operation is executed for 5 minutes, then write access log and upload to security monitoring for manual review.
[0031] In this embodiment, the S4 step of the method forms a set of dynamic path security control mechanisms with layered response capabilities by constructing a mapping relationship between the response policy strength R2 and the path reinforcement policy rule set. Specifically, S41 performs interval division based on the response policy strength R2 output value, assigns the access behavior to RSP-A to RSP-D four types of policy levels, and realizes gradient control from light protection to deep reinforcement. Among them, each type of rule division not only considers single index anomaly, but also considers the composite risk brought by multi-dimensional index interaction anomaly, especially RSP-D for identifying extremely high-risk access requests caused by multi-factor resonance, providing a precise entry for high-intensity protection. In S42, differential control operations are performed for each type of path reinforcement policy rule set: for example, the RSP-A policy switches the access interface for end-to-end encryption and simplifies the hop count, effectively reducing the path exposure surface; the RSP-B policy introduces a device binding and behavior verification dual mechanism to strengthen the identity trustworthiness from the source; the RSP-C policy restricts the operation permission of abnormal users through read-only permission and verification code dual protection; and the RSP-D policy starts the access isolation mechanism, which buffers and delays writing through temporary buffering and delay writing, realizes the audit buffering of access behavior in data sensitive access scenarios, and greatly enhances the data access transparency and traceability.
[0032] Embodiment 6 Please refer to Figure 1 Specifically, S5 includes S51 and S52; S51, after the execution of the path reinforcement mechanism, the exposure index R1 and the response policy strength R2 of all access users are recalculated, and the summary calculation output summary result evaluation function R3 is obtained by summation, to comprehensively measure the response effect of the path reinforcement mechanism; The summary result evaluation function R3 is calculated by the following algorithm formula; ; In the formula, n represents the total number of access records in the statistical period, R1 i represents the exposure index of the i th access request, R2 i represents the response policy strength of the i th access request.
[0033] S52, based on the critical point of the user according to the security defense demand, the comprehensive evaluation threshold Rth is set, and the real-time obtained comprehensive evaluation threshold Rth is compared and evaluated with the summary result evaluation function R3, and the current security state and resource use efficiency in the entire time window after the execution of the path reinforcement mechanism are comprehensively analyzed, and the specific evaluation content is as follows; When the summary result evaluation function R3 is less than the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement mechanism is reasonable, and the existing policy is maintained; When the summary result evaluation function R3 is greater than or equal to the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement mechanism is unreasonable, and a red warning is generated to prompt the operation and maintenance personnel to reconstruct the path reinforcement strategy rule set.
[0034] In this embodiment, the method obtains the summary result evaluation function R3 by introducing the interaction of the exposure index R1 and the response strategy strength R2, constructs a quantifiable security control effectiveness feedback mechanism, and realizes closed-loop verification and dynamic optimization of the path reinforcement effect. Specifically, S51 obtains the summary result evaluation function R3 by multiplying and averaging the exposure index R1 and the response strategy strength R2 in all access records in the statistical period. The evaluation function can comprehensively measure the matching degree between the overall risk strength and the response resource input of the system after the execution of the protection strategy, and avoid one-time risk judgment distortion. In S52, the summary result evaluation function R3 is compared with the comprehensive evaluation threshold Rth preset by the user. If the summary result evaluation function R3 is less than the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement strategy is reasonable in overall resource input and excellent in protection effect, and no adjustment is needed. If the summary result evaluation function R3 is greater than or equal to the comprehensive evaluation threshold Rth, it is determined that the matching degree of the strategy execution effect and the resource is poor, the system generates a red warning prompt, and drives the strategy reconstruction module to guide the optimization and update of the path protection strategy in an automatic or semi-automatic manner.
[0035] Embodiment 7 Please refer to Figure 1 and Figure 2 A visual financial data dynamic analysis system includes an access data detection processing module, an exposure analysis module, a response strategy analysis module, a path reinforcement strategy execution module, and a comprehensive response analysis module. The access data detection processing module sets a detection program in the visual financial cloud platform, collects network access data of each financial data access record in real time, and pre-processes the network access data to obtain a standardized data set. The exposure analysis module calculates and outputs the exposure index R1 based on the standardized data set, preliminarily compares and evaluates the exposure risk interval threshold and the exposure index R1, and triggers the path reinforcement mechanism based on the preliminary comparison and evaluation result. The response strategy analysis module calculates and outputs the response strategy strength R2 based on the exposure index R1 after triggering the path reinforcement mechanism, and measures the original risk score of the current visitor. The path reinforcement strategy execution module divides the response strategy strength R2 into different path reinforcement strategy rule sets according to the response strategy strength R2, and executes the related control content according to the different path reinforcement strategy rule sets. The comprehensive response analysis module performs a summary calculation to output a summary result evaluation function R3 based on the obtained exposure index R1 and response strategy strength R2, and sets a comprehensive evaluation threshold Rth for secondary comparison and evaluation to determine the rationality of the current response resource input.
[0036] While embodiments of the present application have been shown and described, it is to be understood that the embodiments described are merely divergences of the principles and spirit of the present application, and various changes, modifications, substitutions and variations can be made thereto without departing from the principles and spirit of the present application.
Claims
1. A method of visualizing dynamic analysis of financial data, characterized by: The method comprises the following steps: S1, by setting a detection program in a visual financial cloud platform, real-time collection of each financial data access record network access data, and preprocessing of network access data, obtaining a standardized data set; S2, based on the standardized data set, the exposure index R1 is calculated and output, and the exposure risk interval threshold is compared and evaluated, and the trigger path reinforcement mechanism is triggered based on the preliminary comparison and evaluation result; S3, after triggering the path reinforcement mechanism, the exposure index R1 is calculated and output to measure the original risk score of the current visitor; S4, according to the response strategy strength R2, different path reinforcement strategy rule sets are divided, and related control contents are executed according to different path reinforcement strategy rule sets; S5, based on the exposure index R1 and the response strategy strength R2, the summary result evaluation function R3 is calculated and output, and the comprehensive evaluation threshold Rth is set for secondary comparison and evaluation to judge the rationality of the current response resource input.
2. The method of visualizing dynamic analysis of financial data according to claim 1, wherein: The S1 comprises S11 and S12; S11, setting a monitoring program in the visual financial cloud platform, real-time monitoring of user access to each visual financial data access record network access data; The network access data includes access source IP credit value Esrc, network quality attenuation factor Pqos, user behavior deviation Tact, financial data sensitivity Nsen, route intermediate node exposure number Vpath and encryption integrity factor Wcrypto; S12, preprocessing the obtained network access data to obtain a standardized data set; The preprocessing includes missing value processing, legality verification and normalization processing; The missing value processing and legality verification are performed by legality boundary verification on all network access data, and the illegal data is processed; The legality boundary verification is performed by excluding the access source IP credit value Esrc, user behavior deviation Tact, financial data sensitivity Nsen and encryption integrity factor Wcrypto not belonging to [0, 1], and using the historical mean of the current parameter to complete; At the same time, the data of network quality attenuation factor Pqos≤0 and route intermediate node exposure number Vpath≤0 are excluded, and the default minimum value is used for completion; The normalization processing is performed by using the Min-Max normalization method to eliminate the dimension influence in the network access data after the missing value processing and legality verification, to obtain a standardized data set.
3. The method of visualizing dynamic analysis of financial data according to claim 2, wherein: The S2 comprises S21 and S22; S21, based on the standardized data set, the exposure index R1 is calculated and output to measure the exposure risk strength of single financial data access behavior; The exposure index R1 is calculated and output by the following algorithm formula: ; In the formula, log represents the logarithmic function.
4. The method of visualizing dynamic analysis of financial data of claim 3, wherein: S22, extract the exposure index R1 statistical distribution of each access history, set the exposure risk interval threshold according to the quantile of the exposure index R1 statistical distribution, the exposure risk interval threshold includes a first exposure risk threshold F1 and a second exposure risk threshold F2, wherein the first exposure risk threshold F1 takes the 50% quantile of the exposure index R1 statistical distribution, and the second exposure risk threshold F2 takes the 85% quantile of the exposure index R1 statistical distribution, that is, the first exposure risk threshold F1 is a pre-warning boundary, and the second exposure risk threshold F2 is a dangerous boundary; In the preliminary comparative evaluation of the real-time exposure index R1 and the exposure risk interval threshold, the data exposure of single financial data access behavior is judged, and the trigger path reinforcement mechanism is triggered based on the preliminary comparative evaluation result. The specific evaluation content is as follows: When the exposure index R1 is less than the first exposure risk threshold F1, it indicates that there is no exposure risk in accessing the visual financial data for the current visitor, and no operation is required for normal release; When the first exposure risk threshold F1 is less than the second exposure risk threshold F2, it indicates that there is an abnormality in accessing the visual financial data for the current visitor, at which time a yellow triangular pre-warning icon is superimposed in the visual financial data layer, and the standardized data set of the current visitor is recorded in the security log pool. After 5 minutes, the exposure index R1 of the current visitor is reanalyzed, and a second preliminary comparative evaluation is performed. If the second time still has an abnormality, skip the warning and limit the current visitor's access, and trigger the path reinforcement mechanism; When the exposure index R1 is greater than or equal to the second exposure risk threshold F2, the current visitor's access is immediately limited, and the path reinforcement mechanism is directly triggered.
5. The method of visualizing dynamic analysis of financial data according to claim 4, wherein: The S3 includes S31; S31, after triggering the path reinforcement mechanism, the exposure index R1 is obtained, and the user behavior deviation Tact, the number of exposure of the intermediate nodes Vpath and the encryption integrity factor Wcrypto in the standard data set are combined to calculate the response strategy strength R2, and the original risk score of the current visitor is measured; The response strategy strength R2 is calculated by the following algorithm formula: ; In the formula, e represents an exponential function, represents a global control coefficient, used to adjust the response intensity dimension of the whole formula output, and the specific value is set by the user, which is dimensionless.
6. The method of visualizing dynamic analysis of financial data of claim 5, wherein: The S4 includes S41 and S42; S41, based on the response strategy strength R2 of the current visitor, the path reinforcement strategy rule set is combined and divided, which includes RSP-A, RSP-B, RSP-C and RSP-D, and is combined and divided by the following way; When the response strategy strength R2 is in [6.0, 7.5], it is divided into RSP-A; When the response strategy strength R2 is in [7.5, 8.5], it is divided into RSP-B; When the response strategy strength R2 is in [8.5, 9.8], it is divided into RSP-C; When any two types of path reinforcement strategy rules are met and the response strategy strength R2 is greater than or equal to 9.8, it is divided into RSP-D.
7. The method of visualizing dynamic analysis of financial data of claim 6, wherein: S42, based on the divided path reinforcement strategy rule set, the related control content is executed to reinforce the access path of the current visual financial data, and the specific related control content is as follows; When divided into RSP-A, the access interface is switched to end-to-end encryption mode, and the access path is optimized to only keep a 2-hop path, and the load balancing gateway is disabled; When divided into RSP-B, the device binding authentication is started, the hardware is bound with the visual financial data platform fingerprint, and a kind of access verification mechanism is added; When divided into RSP-C, the access permission is automatically degraded to read-only mode, and secondary verification code verification is performed; When divided into RSP-D, the temporary access buffer is started, the original financial data is not directly read, the financial data operation is executed for 5 minutes, then the access log is synchronized and written, and uploaded to the security monitoring for manual review.
8. The method of visualizing dynamic analysis of financial data of claim 6, wherein: The S5 includes S51 and S52; S51, after the path reinforcement mechanism is executed, the exposure index R1 and the response strategy strength R2 of all visitors are recalculated, and the summary calculation output summary result evaluation function R3 is obtained by summation, and the response effect of the path reinforcement mechanism is comprehensively measured; The summary result evaluation function R3 is calculated by the following algorithm formula; ; In the formula, n represents the total number of access records in a statistical period, R1 i represents the exposure index of the ith access request, R2 i represents the response strategy strength of the ith access request.
9. The method of visualizing dynamic analysis of financial data of claim 8, wherein: S52, based on the critical point of the user according to the security defense demand, the comprehensive evaluation threshold Rth is set, and the real-time obtained comprehensive evaluation threshold Rth is compared with the summary result evaluation function R3 for secondary comparison and evaluation, and the current security state and resource use efficiency in the entire time window after the path reinforcement mechanism is executed are comprehensively analyzed, and the specific evaluation content is as follows; When the summary result evaluation function R3 is less than the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement mechanism is reasonable, and the existing strategy is maintained; When the summary result evaluation function R3 is greater than or equal to the comprehensive evaluation threshold Rth, it indicates that the current path reinforcement mechanism is unreasonable, a red warning is generated at this time, and the path reinforcement strategy rule set is prompted to be reconstructed by the operation and maintenance personnel.
10. A visualized financial data dynamic analysis system applied to the visualized financial data dynamic analysis method of any one of claims 1-9, characterized in that: It includes an access data detection processing module, an exposure analysis module, a response strategy analysis module, a path reinforcement strategy execution module, and a comprehensive response analysis module; The access data detection processing module sets a detection program in the visual financial cloud platform, collects network access data of each financial data access record in real time, and pre-processes the network access data to obtain a standardized data set; The exposure analysis module calculates the exposure index R1 based on the standardized data set, compares the exposure risk interval threshold with the exposure index R1 for preliminary comparison and evaluation, and triggers the path reinforcement mechanism based on the preliminary comparison and evaluation result; The response strategy analysis module calculates the response strategy strength R2 based on the exposure index R1 after triggering the path reinforcement mechanism, and measures the original risk score of the current visitor; The path reinforcement strategy execution module divides the response strategy strength R2 into different path reinforcement strategy rule sets according to the response strategy strength R2, and executes related control content according to different path reinforcement strategy rule sets; The comprehensive response analysis module calculates the summary result evaluation function R3 based on the obtained exposure index R1 and response strategy strength R2, and sets the comprehensive evaluation threshold Rth for secondary comparison and evaluation to judge the rationality of the current response resource input.
Citation Information
Patent Citations
Safety monitoring method and system thereof
CN108111487A
Method and device for automatically banning IP (Internet Protocol) aiming at network attack
CN114598525A
Dynamic data authority control method and device based on access behavior
CN115378718A
Network access security control system based on EBPF
CN118368108A
Cross-domain network security policy automatic generation and protection policy collaboration method and system
CN119449428A