A service process intelligent optimization method and system based on multi-source data fusion
By using a business process intelligent optimization method that integrates multi-source data and employing a multi-node security incident prediction and multi-level security risk assessment model, the problem of traditional protection mechanisms being unable to predict and avoid security risks has been solved. This has enabled proactive early warning and dynamic protection of business processes, thereby improving process security.
Patent Information
- Application Number
- CN202511462468.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-14
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2045-10-14
AI Technical Summary
In existing technologies, the static and passive protection mechanisms of traditional business processes are difficult to predict and avoid security risks before execution, leading to business interruption or data leakage and affecting process security.
By using a business process intelligent optimization method that integrates multi-source data, we can predict security incidents at multiple nodes, construct a business process incident map, introduce a multi-level security risk assessment model for quantitative evaluation and global optimization, generate security adjustment strategies, and achieve proactive early warning and dynamic protection.
It significantly improves the security of business processes, enabling proactive early warning, dynamic protection during the process, and overall risk control, thereby reducing the risk of business interruption and data leakage.
Smart Images

Figure CN120931103B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, and particularly relates to a business process intelligent optimization method and system based on multi-source data fusion. BACKGROUND
[0002] At present, the existing business process usually depends on preset static strategy configuration and boundary protection equipment, and the protection mechanism thereof presents obvious hysteresis and isolation. The existing method usually runs based on a historical threat feature library or a fixed rule, cannot deeply fuse real-time business context and process logic, causes the defense system to be disconnected with the dynamic changing business execution process, and is difficult to cope with the increasingly complex internal business process and external threats. Meanwhile, due to the lack of a global perspective and active analysis capability for the business process chain, the existing method is difficult to effectively predict and avoid security risks before the business process is executed, and can only be triggered after the abnormality occurs or the attack succeeds, forcing enterprises to bear the high cost and uncertainty of post-repair, not only causing unplanned interruption of key business services, but also possibly causing large-scale data leakage due to the vulnerability chain that is not discovered in time, and finally affecting the security of the business process.
[0003] In summary, in the prior art, due to the static and passive protection mechanism in the traditional business process, it is difficult to predict and avoid security risks before execution, business interruption or data leakage is easy to occur, and the security of the business process is affected. SUMMARY
[0004] The purpose of the present application is to provide a business process intelligent optimization method and system based on multi-source data fusion, to solve the technical problem in the prior art that due to the static and passive protection mechanism in the traditional business process, it is difficult to predict and avoid security risks before execution, business interruption or data leakage is easy to occur, and the security of the business process is affected.
[0005] In view of the above problems, the present application provides a business process intelligent optimization method and system based on multi-source data fusion.
[0006] In a first aspect, the application provides a business process intelligent optimization method based on multi-source data fusion, which is realized by a business process intelligent optimization system based on multi-source data fusion. The business process intelligent optimization method based on multi-source data fusion comprises the following steps: obtaining a to-be-completed business process request of an enterprise network, wherein the to-be-completed business process request comprises to-be-completed business data corresponding to a to-be-completed business process chain; based on the to-be-completed business process chain, performing multi-node security accident prediction on the to-be-completed business data according to the enterprise network to obtain a business process accident graph; performing security configuration adjustment on the to-be-completed business process request according to the business process accident graph to obtain a business process security adjustment group; performing multi-level evaluation and optimization on the business process security adjustment group by using a multi-level security risk evaluation model to construct a multi-level security adjustment benchmark; performing multi-party evolution and global optimization on the business process security adjustment group according to the multi-level security adjustment benchmark based on the multi-level security risk evaluation model to obtain a security adjustment strategy; and performing business process security optimization management on the to-be-completed business process request according to the security adjustment strategy.
[0007] Optionally, node identification is performed according to the to-be-completed business process chain to determine a business process first node, a business process second node, and a business process Yth node, wherein Y is a positive integer; leakage accident prediction is performed on the to-be-completed business data according to the enterprise network based on the business process first node to obtain first leakage accident characteristics; malicious injection accident prediction is performed on the to-be-completed business data according to the enterprise network based on the business process first node to obtain first malicious injection accident characteristics; attack accident prediction is performed on the to-be-completed business data according to the enterprise network based on the business process first node to obtain first attack accident characteristics; the first leakage accident characteristics, the first malicious injection accident characteristics, and the first attack accident characteristics are added to the business process accident graph; and multi-dimensional security accident prediction is continuously performed on the to-be-completed business data based on the business process second node to the business process Yth node to update the business process accident graph.
[0008] Optionally, network equipment feature modeling is performed based on the first node of the business process to obtain a first node equipment model; network association modeling is performed based on the enterprise network on the first node of the business process to obtain a first node network model; the to-be-handled business data is simulated based on the first node equipment model and the first node network model to obtain first node business process simulation data; an accident tree model is trained according to a set of historical leakage events of the business process to obtain a leakage accident tree model; the leakage accident tree model is trained for perturbation enhancement according to the set of historical leakage events of the business process to generate a leakage accident prediction model; and the first node business process simulation data is input into the leakage accident prediction model to output the first leakage accident feature.
[0009] Optionally, security configuration parameter acquisition is performed on the to-be-handled business process request to obtain a current security configuration scheme; leakage accident suppression adjustment is performed on the current security configuration scheme based on the business process accident graph to obtain a first security configuration adjustment space; malicious injection accident suppression adjustment is performed on the current security configuration scheme based on the business process accident graph to obtain a second security configuration adjustment space; attack accident suppression adjustment is performed on the current security configuration scheme based on the business process accident graph to obtain a third security configuration adjustment space; and adjustment decision combination is performed on the first security configuration adjustment space, the second security configuration adjustment space, and the third security configuration adjustment space to generate the business process security adjustment group.
[0010] Optionally, full-process fitting is respectively performed on the to-be-handled business process request according to each business process security adjustment scheme in the business process security adjustment group to obtain each scheme request fitting data; the each scheme request fitting data is input into the multi-level security risk evaluation model to obtain a security risk evaluation heat map; leakage risk minimization optimization is performed on the business process security adjustment group based on the security risk evaluation heat map to obtain a first security adjustment benchmark; malicious injection risk minimization optimization is performed on the business process security adjustment group based on the security risk evaluation heat map to obtain a second security adjustment benchmark; attack risk minimization optimization is performed on the business process security adjustment group based on the security risk evaluation heat map to obtain a third security adjustment benchmark; and the first security adjustment benchmark, the second security adjustment benchmark, and the third security adjustment benchmark are encapsulated as the multi-level security adjustment benchmark.
[0011] Optionally, the multi-level security risk evaluation model includes a leakage risk evaluation model, a malicious injection risk evaluation model, and an attack risk evaluation model.
[0012] Optionally, based on the multi-level security risk evaluation model, evolution of the business process security adjustment group is performed according to a first security adjustment benchmark, to obtain a first security adjustment evolution analysis domain; based on the multi-level security risk evaluation model, evolution of the business process security adjustment group is performed according to a second security adjustment benchmark, to obtain a second security adjustment evolution analysis domain; based on the multi-level security risk evaluation model, evolution of the business process security adjustment group is performed according to a third security adjustment benchmark, to obtain a third security adjustment evolution analysis domain; the business process security adjustment group is screened according to the multi-level security risk constraint, to obtain a first security adjustment optimization space; the first security adjustment optimization space is expanded according to the first security adjustment evolution analysis domain, the second security adjustment evolution analysis domain and the third security adjustment evolution analysis domain, to obtain a second security adjustment optimization space; the second security adjustment optimization space is globally evaluated and optimized according to a multi-level security risk weight, to generate the security adjustment strategy.
[0013] Optionally, deviation of the business process security adjustment group is detected according to the first security adjustment benchmark, to obtain a first security adjustment deviation set; the first security adjustment deviation set is mutated, to obtain a first adjustment evolution feature set; the business process security adjustment group is adjusted according to the first adjustment evolution feature set, to obtain a first security adjustment evolution group; the first security adjustment evolution group is evaluated and optimized according to the multi-level security risk evaluation model based on the multi-level security risk constraint, to generate the first security adjustment evolution analysis domain.
[0014] Optionally, the multi-level security risk constraint includes a leakage risk constraint, a malicious injection risk constraint and an attack risk constraint.
[0015] In a second aspect, the application further provides a business process intelligent optimization system based on multi-source data fusion, which is used to execute the business process intelligent optimization method based on multi-source data fusion as described in the first aspect. The business process intelligent optimization system based on multi-source data fusion comprises: a request obtaining module, which is used to obtain a to-be-completed business process request of an enterprise network, wherein the to-be-completed business process request comprises to-be-completed business data corresponding to a to-be-completed business process chain; an accident prediction module, which is used to perform multi-node security accident prediction on the to-be-completed business data according to the enterprise network based on the to-be-completed business process chain, and obtain a business process accident graph; a configuration adjustment module, which is used to perform security configuration adjustment on the to-be-completed business process request according to the business process accident graph, and obtain a business process security adjustment group; an evaluation and optimization module, which is used to perform multi-level evaluation and optimization on the business process security adjustment group through a multi-level security risk evaluation model, and construct a multi-level security adjustment benchmark; a global optimization module, which is used to perform multi-party evolution and global optimization on the business process security adjustment group based on the multi-level security risk evaluation model according to the multi-level security adjustment benchmark, and obtain a security adjustment strategy; and a process optimization module, which is used to perform business process security optimization management on the to-be-completed business process request according to the security adjustment strategy.
[0016] The one or more technical solutions provided in the application have at least the following beneficial effects: by analyzing the to-be-completed business process chain where the to-be-completed business data is located, performing multi-node security accident prediction, identifying potential risks in advance, adjusting security configuration in real time according to the business process accident graph, introducing a multi-level security risk evaluation model to quantitatively evaluate and globally optimize the business process security adjustment group, ensuring that a globally optimal security adjustment strategy is obtained, and realizing proactive early warning, dynamic protection during the process, and controllable global risks, the security of the business process is significantly improved. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 FIG. 1 is a flowchart of a business process intelligent optimization method based on multi-source data fusion according to the application.
[0018] Figure 2 FIG. 2 is a structural schematic diagram of a business process intelligent optimization system based on multi-source data fusion according to the application.
[0019] Legend: request obtaining module 11, accident prediction module 12, configuration adjustment module 13, evaluation and optimization module 14, global optimization module 15, and process optimization module 16. DETAILED DESCRIPTION
[0020] The application provides a business process intelligent optimization method and system based on multi-source data fusion, which solves the technical problem in the prior art that it is difficult to predict and avoid security risks before execution due to the static and passive protection mechanism in the traditional business process, business interruption or data leakage is prone to occur, and the safety of the business process is affected. By analyzing the business process chain where the to-be-done business data is located, multi-node security accident prediction is performed, potential risks are identified in advance, security configuration is adjusted in real time according to the business process accident graph, a multi-level security risk evaluation model is introduced to quantitatively evaluate and globally optimize the business process safety adjustment group, and the globally optimal safety adjustment strategy is ensured, thereby realizing proactive early warning, dynamic protection during the process, and controllable global risk, and the safety of the business process is significantly improved.
[0021] Embodiment one, please refer to the attached Figure 1 The application provides a business process intelligent optimization method based on multi-source data fusion, wherein the business process intelligent optimization method based on multi-source data fusion is executed by a business process intelligent optimization system based on multi-source data fusion, and the business process intelligent optimization method based on multi-source data fusion specifically includes the following steps:
[0022] Obtaining a to-be-done business process request of an enterprise network, wherein the to-be-done business process request includes to-be-done business data corresponding to a to-be-done business process chain.
[0023] Specifically, the enterprise network refers to a network architecture for information exchange and resource sharing within a company, including a local area network, a virtual private network and the like, and supports interconnection and intercommunication between employees, departments and servers within the company. By deploying a process engine listener, an API gateway and the like in the enterprise network, a newly generated to-be-done business process request, that is, a business process request waiting for processing, is obtained, including various operations to be performed, such as financial approval, contract approval and the like. Employees or managers need to respond to these requests to continue the process. At the same time, data related to the to-be-done business process request is collected, such as approval records, file attachments, current approval status and the like.
[0024] The to-be-handled business process request includes to-be-handled business data corresponding to a to-be-handled business process chain. The to-be-handled business process chain is a series of ordered steps or nodes that are predefined and followed in processing the to-be-handled business process request, including the entire process from task initiation, various approval links, and final completion, indicating the flow and processing steps of the to-be-handled task in multiple links. The to-be-handled business data includes approval data, attachment files, and business-related data information, which are updated and changed continuously along with the advancement of each link in the process. For example, assuming that an employee submits a reimbursement approval including five approval nodes, i.e., the employee submits a reimbursement form, a department manager audits, a department manager audits, a financial audit, and financial confirmation and issuance. The extracted to-be-handled business data includes: a reimbursement amount of 1000 yuan, a reimbursement form submission personnel A, an approval state in the department manager audit, and an attachment of an invoice picture (size 500 KB).
[0025] Based on the to-be-handled business process chain, multi-node security incident prediction is performed on the to-be-handled business data according to the enterprise network, and a business process incident graph is obtained.
[0026] Further, the present application further includes the following steps: node identification is performed according to the to-be-handled business process chain, and a business process first node, a business process second node, and a business process Yth node are determined, Y being a positive integer; based on the business process first node, leakage incident prediction is performed on the to-be-handled business data according to the enterprise network, and a first leakage incident feature is obtained; based on the business process first node, malicious injection incident prediction is performed on the to-be-handled business data according to the enterprise network, and a first malicious injection incident feature is obtained; based on the business process first node, attack incident prediction is performed on the to-be-handled business data according to the enterprise network, and a first attack incident feature is obtained; the first leakage incident feature, the first malicious injection incident feature, and the first attack incident feature are added to the business process incident graph; based on the business process second node to the business process Yth node, multi-dimensional security incident prediction is continuously performed on the to-be-handled business data, and the business process incident graph is updated.
[0027] Further, the application further comprises the following steps: network device feature modeling based on the business process first node to obtain a first node device model; network correlation modeling based on the enterprise network for the business process first node to obtain a first node network model; analog processing of the to-be-done business data based on the first node device model and the first node network model to obtain first node business process simulation data; accident tree training according to a set of business process leakage history events to obtain a leakage accident tree model; perturbation enhancement training of the leakage accident tree model according to the set of business process leakage history events to generate a leakage accident prediction model; inputting the first node business process simulation data into the leakage accident prediction model to output the first leakage accident feature.
[0028] Specifically, each node of the to-be-done business process chain is identified, and a business process first node, a business process second node, and a business process Yth node are determined, Y being a positive integer. That is, the to-be-done business process chain gradually identifies each node of the business process, and determines the positions of these links in the entire process in order. In the business process, each link can be regarded as a node, and the business process node refers to each link or step executed in order in a business process. For example, the first node in the contract approval is contract submission, and the second node is the audit of the legal department. The number of nodes in the business process chain is dynamic and adjusted according to the complexity of the business process. For example, the financial approval process has 5 nodes, and the contract approval process has 7 nodes.
[0029] Network device modeling according to the business process first node, automatic collection of network device data associated with the business process first node from the enterprise network, establishment of a first node device model, including static and dynamic features such as device performance parameters, hardware configuration, operating system, middleware version, security patch level, installed protection software, open port, etc., comprehensive understanding of the security baseline and vulnerability of the business process first node itself. The network environment in which the business process first node is located is obtained, and a model related to network connection is constructed, i.e., a first node network model. Network correlation modeling can help understand the mutual connection of the business process first node with other business nodes, and how its network resources support the entire business process. The first node network model includes access control list, network topology connection, data transmission protocol, communication frequency, normal traffic baseline, etc., which depicts the social graph of the node in the network and clearly defines its exposure surface.
[0030] The first node device model and the first node network model are deployed into a separate sandbox environment to form a digital twin of the first node of the business process, and real pending business data is injected into the sandbox environment for simulation, thereby generating first node business process simulation data containing the complete behavior log of the business when it is processed at the node. Simulation processing refers to simulating the real production environment using the constructed first node device model and first node network model in a separate sandbox environment, inputting pending business data into the sandbox environment for running, observing the processing process and output results, which is a risk-free, simulated testing method. Considering the processing capacity of the node device, network delay, bandwidth and other factors, the execution of the business process at the first node of the business process is simulated to obtain first node business process simulation data reflecting the data flow, response time, device load and other information when the business process is executed at the first node of the business process.
[0031] A set of business process leakage history events, i.e. a set of all business process leakage events that have occurred in the past in the enterprise, including data leakage or security incidents caused by internal and external reasons, each event containing relevant trigger factors, leakage forms and consequences. At the same time, other enterprises' public historical leakage events can also be obtained to form a set of business process leakage history events. Each record in the set of business process leakage history events is a case, including but not limited to the following fields: event ID, occurrence time, involved business process / node, final accident phenomenon, root cause set, attack path, impact degree, processing process, etc. Fault tree analysis is a top-down deductive failure analysis method. Machine learning algorithms are used to learn the set of business process leakage history events and automatically build one or more logical trees. The root node is the top-level leakage accident, the leaf node is various basic events, i.e. various causes of the accident, and the middle is connected by logical gates and or not, representing the causal relationship and combination relationship between events. Fault tree is used to analyze the root cause of the accident and identify potential risk sources.
[0032] Each historical case in the set of business process leakage history events is converted into a feature vector. Random forest is used for fault tree training, analyzing thousands of such cases to automatically find out which combination of basic events is most likely to cause a leakage accident. For example, a rule is learned: if ([there is unencrypted transmission] is true) AND ([external attacker reachable] is true), then the probability of [network sniffing leading to leakage] is very high. All rules together constitute the leakage accident tree model, a complex rule set that can calculate the probability of an accident. Suppose a company has had an event of internal personnel leaking customer data, the leakage accident tree model contains the following nodes: the root node is the data leakage event, the first-level branch is the internal personnel operation error, the second-level branch under it is the permission configuration error and the employee unauthorized access to sensitive information, the other first-level branch is the external network attack, and the second-level branch under it is the malware infection and unpatched system vulnerability.
[0033] After completing the preliminary fault tree model, enter the perturbation enhancement training phase to enhance the robustness of the leakage accident tree model by adding perturbations, such as simulating new attack patterns, network anomalies, device failures, etc., to identify more possible leakage risks and generate a leakage accident prediction model. Random noise or changes are introduced based on the set of business process leakage history events to create new training samples, such as randomly discarding some event features, slightly modifying the occurrence order or timestamp of events, replacing synonyms, adjusting numerical values, etc. For example, randomly delete the configuration error feature in 10% of the cases, or mix up the timestamps in 20% of the cases. Use these imperfect data to retrain and fine-tune the preliminary leakage accident tree model to help the leakage accident tree model adapt to the uncertainties in the actual environment and improve its prediction ability for new risks.
[0034] The leakage data prediction model is obtained by fine-tuning the perturbed data set of the leakage accident tree model, and is not sensitive to feature missing, inaccurate information, etc. The robustness is greatly enhanced. The leakage data prediction model retains the core logic of the original accident tree model, but has stronger identification ability and prediction accuracy for unknown or slightly abnormal input patterns, reducing false positives and false negatives. For example, suppose there are 500 financial approval-related data leakage event records accumulated in the historical event library, learn from these 500 records to generate a preliminary leakage accident tree model, and one important rule is that there is an unpatched known high-risk vulnerability and the asset is exposed to the public network, resulting in a leakage probability > 85%. Apply perturbation strategy to the original 500 data to generate an enhanced training set containing 5000 samples, such as randomly discarding the feature that the development server can be accessed by the external network; change the database is cracked to the database is SQL injection to simulate the variation of attack means; randomly perturb the leakage data volume from 50000 to 48000 or 52000. Retrain and fine-tune the preliminary leakage accident tree model with the 5000 perturbed data to obtain the leakage accident prediction model. Input the first node business process simulation data, i.e. the configuration file permission is too large, the database connection is not encrypted, and the log record is in plaintext sensitive information, into the leakage accident prediction model, match it with the learned pattern, and output a quantitative prediction result: 3 features match the historical high leakage risk pattern, and the probability of predicting a log data leakage accident is 92.7%.
[0035] The first node business process simulation data obtained after simulation is input into the leakage accident prediction model for analysis, and the behavior log of the first node business process simulation data is analyzed, various abnormal patterns are matched, and the first leakage accident feature is output. The leakage accident feature is the result output by the leakage accident prediction model, and is not a simple yes / no judgment, but a set of structured and quantifiable risk features. For example, the accident type is sensitive data transmission in plaintext, the occurrence probability is 0.15, the potential leakage data volume is 500, and the main root cause is that server 1.0 support is not disabled and development environment configuration is mis-synchronized to production environment.
[0036] The process of malicious injection incident prediction and attack incident prediction is similar to the process of leakage incident prediction described above, and is not described in detail. Similarly, a set of malicious injection history events of the business process is obtained, and a malicious injection incident prediction model is trained to focus on predicting that the server executes unexpected commands or code due to external malicious input. Malicious injection can be tampering or obtaining sensitive data by external attackers through means such as injecting malicious code or SQL injection. According to the first node device model and the first node network model constructed for the first node of the business process, the to-be-processed business data is simulated to obtain first node business process simulation data. The malicious injection incident prediction model is used for fuzz testing and static analysis of the input data to attempt to construct malicious payloads and detect whether the node has injection-type vulnerabilities. The first node business process simulation data is input into the malicious injection incident prediction model for malicious injection incident prediction, thereby obtaining first malicious injection incident features.
[0037] Similarly, a set of attack incident history events of the business process is obtained, and an attack incident prediction model is trained to focus on predicting network attack behaviors initiated against vulnerabilities of the enterprise network itself, such as vulnerability exploitation, cracking, DDoS attacks, privilege escalation, etc. The attack incident prediction model is a correlation analysis combining the first node device model and the first node network model constructed for the first node of the business process, and the vulnerability library to evaluate the feasibility of being exploited by external attackers. The first node business process simulation data is input into the attack incident prediction model for attack incident prediction, thereby obtaining first attack incident features.
[0038] The incident features are structured results output by the prediction model, usually including incident type, occurrence probability, severity level, root cause analysis, potential impact range, etc. The first leakage incident features, the first malicious injection incident features, and the first attack incident features are added as attributes to the corresponding first node of the business process in the business process incident graph. The above process is executed in a loop, automatically moving to the second node of the business process, and repeating the process of simulation, leakage incident prediction, malicious injection incident prediction, attack incident prediction, and output of incident features, and updating the corresponding leakage incident features, malicious injection incident features, and attack incident features to the corresponding process nodes in the business process incident graph. This process continues until all business process nodes on the process chain have completed multi-dimensional security incident prediction, thereby obtaining a complete business process incident graph that clearly shows the distribution of risks at each node, different types, and their potential transmission relationships.
[0039] The business process accident graph is a graph structure data model, the nodes of the graph represent various processing nodes in the business process, and the edges of the graph represent the flow direction of risks or data. At each business node, a plurality of accident characteristics corresponding to the business node are attached, thereby forming a global and visual risk view. By performing multi-dimensional security prediction on each node and integrating the results into the business process accident graph, potential security threats can be identified from a global perspective, and the risk characteristics of each node can be clearly understood. Once an anomaly occurs, the security team can quickly locate the problem node and take appropriate emergency measures to reduce potential losses.
[0040] According to the business process accident graph, the to-be-performed business process request is adjusted in security configuration to obtain a business process security adjustment group.
[0041] Further, the application further includes the following steps: collecting security configuration parameters of the to-be-performed business process request to obtain a current security configuration scheme; based on the business process accident graph, the current security configuration scheme is adjusted in leakage accident suppression to obtain a first security configuration adjustment space; according to the business process accident graph, the current security configuration scheme is adjusted in malicious injection accident suppression to obtain a second security configuration adjustment space; according to the business process accident graph, the current security configuration scheme is adjusted in attack accident suppression to obtain a third security configuration adjustment space; the first security configuration adjustment space, the second security configuration adjustment space and the third security configuration adjustment space are combined in adjustment decision to generate the business process security adjustment group.
[0042] Specifically, security configuration parameters of the to-be-performed business process request are collected, that is, from various devices (servers, databases, middleware, network devices, security devices, etc.) in the enterprise network, security configuration data related to the to-be-performed business process request is collected, such as firewall rules, Web server SSL / TLS protocol version, database access control list, log level and desensitization rules, system service and port open state, etc. After all the collected security configuration parameters related to the current to-be-performed business process are summarized and structured, a current security configuration scheme is formed, which is used to ensure the security of the enterprise internal data.
[0043] Based on the business process accident graph, the security configuration scheme is evaluated, and the leakage accident suppression adjustment is optimized to reduce the risk of data leakage by adjusting permissions, access control, authentication, and other measures. Based on the leakage risk of each link in the business process accident graph, analyze possible vulnerabilities and weaknesses, and make corresponding optimization adjustments. For example, according to the business process accident graph, node A has a log leakage risk, with a probability of 85%, the leakage accident suppression adjustment module will query the corresponding adjustment knowledge base to generate the following adjustment options: upgrade the log level from DEBUG to INFO, enable log data desensitization function, set log file permissions to 600, etc. The first security configuration adjustment space is a plurality of schemes obtained by adjusting the current security configuration scheme based on the business process accident graph to reduce or prevent data leakage accidents.
[0044] Similarly, based on the business process accident graph, the current security configuration scheme is adjusted to prevent malicious injection accidents, such as code injection attacks. Malicious injection accidents usually refer to attackers injecting malicious code or data into the system, causing system function abnormalities or data leakage. According to the business process accident graph, the current security configuration scheme is adjusted to take measures such as strengthening input verification, increasing code auditing, and implementing firewall filtering to prevent malicious injection events. For example, in the financial approval process, suppose there is a risk of SQL injection on the server. By adjusting the input verification of database queries, direct execution of unchecked input data is prohibited, effectively preventing SQL injection attacks, forming part of the malicious injection accident suppression adjustment space. The second security configuration adjustment space is a plurality of schemes obtained by adjusting the current security configuration scheme based on the business process accident graph to prevent malicious injection attacks.
[0045] Similar to the previous two, the current security configuration scheme is adjusted based on the business process accident graph to reduce and prevent external attack risks. Attack accident suppression adjustment mainly reduces the risk of network attacks through network defense, traffic filtering, DDoS protection, and other means. According to the attack risk nodes in the business process accident graph, optimize the network firewall settings, intrusion detection system configuration, etc. to prevent attack events. For example, in the financial approval process, suppose abnormal traffic is detected on the external network, which may cause a DDoS attack. By adjusting the firewall strategy, increasing traffic filtering rules, and limiting access to suspicious IP addresses, the risk of DDoS attacks is reduced. The third security configuration adjustment space is a plurality of schemes obtained by adjusting the current security configuration scheme based on the business process accident graph to prevent attack events.
[0046] After the suppression adjustment of the leakage accident, the malicious injection accident and the attack accident is completed, the first security configuration adjustment space, the second security configuration adjustment space and the third security configuration adjustment space are combined to obtain a comprehensive business process security adjustment group. Each scheme takes into account the security requirements and potential risks of different nodes to achieve optimal security protection. The business process security adjustment group includes multiple business process security adjustment schemes, each combination is a potential solution, and each business process security adjustment scheme includes leakage accident suppression adjustment schemes, malicious injection accident suppression adjustment schemes, attack accident suppression adjustment schemes and the like for multiple process nodes. Through security configuration parameter collection of the to-be-processed business process request and multi-dimensional security accident suppression adjustment, a set of comprehensive and flexible security configuration schemes are generated to help enterprises implement precise security protection at each business process node, effectively reduce leakage, malicious injection and attack risks and protect the security of business processes of enterprises.
[0047] The business process security adjustment group is evaluated and optimized in multiple levels through a multi-level security risk evaluation model to construct a multi-level security adjustment benchmark.
[0048] Further, the application further includes the following steps: according to each business process security adjustment scheme in the business process security adjustment group, respectively fitting the to-be-processed business process request to obtain request fitting data of each scheme; inputting the request fitting data of each scheme into the multi-level security risk evaluation model to obtain a security risk evaluation heat map; minimizing the leakage risk of the business process security adjustment group according to the security risk evaluation heat map to obtain a first security adjustment benchmark; minimizing the malicious injection risk of the business process security adjustment group according to the security risk evaluation heat map to obtain a second security adjustment benchmark; minimizing the attack risk of the business process security adjustment group according to the security risk evaluation heat map to obtain a third security adjustment benchmark; and encapsulating the first security adjustment benchmark, the second security adjustment benchmark and the third security adjustment benchmark as the multi-level security adjustment benchmark.
[0049] Further, the application further includes the following steps: the multi-level security risk evaluation model includes a leakage risk evaluation model, a malicious injection risk evaluation model and an attack risk evaluation model.
[0050] Specifically, the multi-level security risk evaluation model includes a leakage risk evaluation model, a malicious injection risk evaluation model, and an attack risk evaluation model, each of which focuses on a specific type of security risk, such as data leakage, malicious injection, and network attack. Each model is a machine learning model that is trained and optimized using historical data and real-time data. The leakage risk evaluation model is used to assess the risk of data leakage that may occur in business processes; the malicious injection risk evaluation model is used to assess the risk of being maliciously injected, such as SQL injection, cross-site scripting, etc.; and the attack risk evaluation model is used to assess the risk of network attacks, such as DDoS attacks, denial-of-service attacks, etc. The multi-level security risk evaluation model is a quantitative evaluator that receives data after each security configuration scheme simulation run and outputs a set of three quantifiable risk indicators, namely leakage risk coefficient, malicious injection risk coefficient, and attack risk coefficient.
[0051] The input of the leakage risk evaluation model is the scheme request fitting data, which is a high-dimensional feature vector extracted from the massive logs and data generated by simulation runs through feature engineering. The output is the leakage risk coefficient, which is a continuous value between [0, 1]. The higher the value, the greater the risk. The true label during training comes from the analysis of historical events, for example, a simulation run that ultimately leads to leakage should have a risk coefficient close to 1; a completely safe run should have a risk coefficient close to 0.
[0052] According to the set of historical leakage events of business processes, a large number of different business process and security configuration combinations are simulated to generate multiple scheme request fitting data. Combined with real security events and penetration test results, each simulation run data is analyzed to assess a leakage risk score, i.e., a label. For example, in one run, a large number of plaintext passwords are recorded in the log, and eventually extracted by the tester, which is labeled as 0.95; in another run, all data is encrypted and there is no abnormality, which is labeled as 0.05. The original, unstructured simulation logs and data are converted into structured feature vectors through natural language processing, time series analysis, statistical analysis, etc. Due to the high dimensionality of the input features and the possible existence of complex nonlinear relationships, a gradient boosting decision tree model is usually selected for training.
[0053] The prepared labeled dataset is divided into training set, validation set and test set, such as 70%, 15%, 15%. The training set is input into the gradient boosting decision tree, which continuously learns the complex mapping relationship between input features and leakage risk coefficients. The validation set is used to adjust the parameters of the model, such as learning rate, tree depth, and leaf node number, to prevent overfitting and find the optimal model hyperparameters. The test set is used to evaluate the final performance of the model, calculate the accuracy, precision, recall and other indicators of the model. If the model effect is not good, adjust the parameters or use different algorithms for optimization. Set the convergence condition of the model, such as the change of the validation loss is less than 0.01 for 5 consecutive rounds or the accuracy of the training set reaches 95%, then stop training, get the leakage risk evaluation model.
[0054] The input of the malicious injection risk evaluation model is also the scheme request fitting data, and the output is the malicious injection risk coefficient. The training process is exactly the same as the leakage model, but the label of the training data is different, here the label comes from the historical injection attack test record, for example, a successful SQL injection simulation run, its injection risk coefficient should be labeled as 0.9. Use the gradient boosting decision tree similar to the leakage risk evaluation model, and use the historical attack data labeled as malicious or normal and the corresponding risk coefficient to train.
[0055] The input of the attack risk evaluation model is also the scheme request fitting data, and the output is the attack risk coefficient. The training process is the same. The label comes from the vulnerability scan result and penetration test report, for example, a service that exists known high-risk vulnerabilities and is exposed to the public network, its attack risk coefficient should be labeled as 0.95. In the training process, similar machine learning algorithms are used as the previous two models, based on historical attack data to train the model to identify potential network attack risks.
[0056] According to the business process security adjustment group, each business process security adjustment scheme is applied to the whole process fitting of the to-be-processed business process request, that is, for the selected to-be-processed business process request, each security configuration scheme in the business process security adjustment group is applied one by one. Each scheme corresponds to a different security optimization strategy, aiming to enhance the security of the whole process by adjusting the configuration of each link. According to each business process security adjustment scheme, the security of each link of the to-be-processed business process request is simulated. Whole process fitting means that each business process security adjustment scheme in the business process security adjustment group is applied to the whole process of the to-be-processed business process request, from start to finish, the security of each node is considered. The results of the simulation will give the fitting data under each scheme, showing the security effect of each scheme in the whole process. After each business process security adjustment scheme is fitted through the whole process, a set of fitting data is generated, which reflects the influence of each scheme on the security of the whole business process. Scheme request fitting data includes detailed logs and performance data generated during the whole process fitting of each business process security adjustment scheme, which is the input of the risk evaluation model, including network traffic packets, system call sequences, API response time, memory / CPU usage, log output, database query statements, etc.
[0057] The scheme request fitting data is input into the multi-level security risk evaluation model, which calculates and outputs three risk coefficients for each business process security adjustment scheme, namely leakage risk coefficient, malicious injection risk coefficient and attack risk coefficient. These results are summarized to generate a security risk evaluation heat map. The security risk evaluation heat map is a visual data presentation structure, essentially a evaluation result matrix, which clearly shows the score of each scheme in the business process security adjustment group in the three risk dimensions under the evaluation of the multi-level security risk evaluation model. Different risks are displayed by color depth. High-risk areas are usually marked in red, and low-risk areas are represented in green, helping to quickly identify the most dangerous areas and the safest schemes.
[0058] The leakage risk coefficient column in the security risk evaluation heat map is scanned to find the scheme corresponding to the minimum value, i.e., the scheme with the lowest leakage risk, and mark it as the first security adjustment benchmark; similarly, the malicious injection risk coefficient column in the security risk evaluation heat map is scanned to find the scheme corresponding to the minimum value, i.e., the scheme with the lowest malicious injection risk, and mark it as the second security adjustment benchmark; the attack risk coefficient column in the security risk evaluation heat map is scanned to find the scheme corresponding to the minimum value, i.e., the scheme with the lowest attack risk, and mark it as the third security adjustment benchmark. The first security adjustment benchmark, the second security adjustment benchmark, and the third security adjustment benchmark are packaged to obtain a multi-level security adjustment benchmark. Packaging refers to integrating different adjustment benchmarks to generate a final multi-level security adjustment benchmark. The first security adjustment benchmark minimizes leakage risk, configures encrypted communication, implements the principle of minimizing permissions, and strengthens monitoring of sensitive data access; the second security adjustment benchmark minimizes malicious injection risk, strengthens input verification, and uses firewalls and intrusion detection systems; and the third security adjustment benchmark minimizes attack risk, optimizes DDoS prevention measures, monitors abnormal traffic in real time, and performs regular security scans.
[0059] The multi-level security adjustment benchmark includes the structured objects of the three single-dimension optimal schemes, and is not a final scheme, but a benchmark set that defines the initial boundary of the Pareto front of the current optimization problem, providing an anchor point for comparison and a direction for search for the next global optimization. By way of example, assume that the business process security adjustment group contains 8 alternative security configuration schemes, i.e., S1 to S8. After simulation and model evaluation, the security risk evaluation heat map is obtained, and the data therefrom is extracted to obtain Table 1:
[0060]
[0061] Among them, the business process security adjustment scheme corresponding to the smallest leakage risk coefficient is S3, the business process security adjustment scheme corresponding to the smallest malicious injection risk coefficient is S5, and the business process security adjustment scheme corresponding to the smallest attack risk coefficient is S6. The three schemes S3, S5, and S6 are packaged to obtain a multi-level security adjustment benchmark. Through the heat map, the abstract security risk is converted into specific and comparable numerical values, making the advantages and disadvantages of each scheme clear at a glance, and determining the ideal points of the three single targets. Although there may be a scheme that achieves the extreme in all three dimensions, i.e., almost nonexistent in reality, the three benchmark points define the ideal target and direction of optimization.
[0062] Based on the multi-level security risk evaluation model, the business process security adjustment group is subjected to multi-party evolutionary expansion global optimization according to the multi-level security adjustment benchmark to obtain a security adjustment strategy.
[0063] Further, the application further comprises the following steps: based on the multi-level security risk evaluation model, evolution of the business process security regulation group is performed according to a first security regulation benchmark, and a first security regulation evolution analysis domain is obtained; based on the multi-level security risk evaluation model, evolution of the business process security regulation group is performed according to a second security regulation benchmark, and a second security regulation evolution analysis domain is obtained; based on the multi-level security risk evaluation model, evolution of the business process security regulation group is performed according to a third security regulation benchmark, and a third security regulation evolution analysis domain is obtained; the business process security regulation group is screened according to the multi-level security risk constraint, and a first security regulation optimization space is obtained; the first security regulation optimization space is expanded according to the first security regulation evolution analysis domain, the second security regulation evolution analysis domain and the third security regulation evolution analysis domain, and a second security regulation optimization space is obtained; the second security regulation optimization space is globally evaluated and optimized according to the multi-level security risk weight, and the security regulation strategy is generated.
[0064] Further, the application further comprises the following steps: deviation detection of the business process security regulation group is performed according to the first security regulation benchmark, and a first security regulation deviation set is obtained; the first security regulation deviation set is mutated, and a first regulation evolution feature set is obtained; the business process security regulation group is regulated according to the first regulation evolution feature set, and a first security regulation evolution group is obtained; the first security regulation evolution group is evaluated and optimized according to the multi-level security risk evaluation model based on the multi-level security risk constraint, and the first security regulation evolution analysis domain is generated.
[0065] Further, the application further comprises the following steps: the multi-level security risk constraint comprises a leakage risk constraint, a malicious injection risk constraint and an attack risk constraint.
[0066] Specifically, deviation detection of the business process security regulation group is performed based on the first security regulation benchmark, and potential problems are identified by comparing the differences between the existing security configuration and the expected optimal configuration. The first security regulation deviation set comprises a configuration difference list of all other business process security regulation schemes in the business process security regulation group relative to the first security regulation benchmark, that is, the gap between each business process security regulation scheme and the expected target.
[0067] The first set of security adjustment deviations is mutated, that is, adjusted or changed, to generate a new, higher-security adjustment scheme. By introducing new configuration or adjustment parameters, the deviation data is optimized to generate a more optimal set of adjustment features. For example, a record in the first set of security adjustment deviations is randomly selected, and the log level therein is modified from INFO to ERROR to a log level from INFO to WARN, creating a new feature through a small perturbation to form the first adjustment evolution feature set. The first adjustment evolution feature set is a new set of security adjustment features generated through the mutation process and contains adjusted configuration features after mutation.
[0068] According to the new set of security adjustment features generated through the mutation process, which contains adjusted configuration features after mutation, the business process security adjustment group is adjusted, that is, the adjusted features are re-applied to each business process security adjustment scheme in the previous business process security adjustment group to obtain a batch of completely new schemes, that is, the first security adjustment evolution group. The first security adjustment evolution group will provide more efficient security protection for the business process according to the adjusted configuration and the optimized features.
[0069] The first security adjustment evolution group is evaluated for security risk using a multi-level security risk evaluation model, and each scheme is comprehensively evaluated and optimized based on the constraints of leakage risk, malicious injection risk, and attack risk. The multi-level security risk constraints include leakage risk constraints, malicious injection risk constraints, and attack risk constraints. For example, the multi-level security risk constraints include leakage risk constraints to ensure that the leakage risk coefficient is less than 0.1, malicious injection risk constraints to ensure that the malicious injection risk coefficient is less than 0.3, and attack risk constraints to ensure that the attack risk coefficient is less than 0.4.
[0070] According to each new business process security adjustment scheme of the first security adjustment evolutionary group, the to-be-done business process request is fitted with the whole process respectively, and new scheme request fitting data is obtained. The new scheme request fitting data is input into the multi-level security risk evaluation model, and the leakage risk coefficient, malicious injection risk coefficient and attack risk coefficient corresponding to each new business process security adjustment scheme are obtained. According to the multi-level security risk constraint, the scheme that meets the leakage risk constraint, malicious injection risk constraint and attack risk constraint, that is, the scheme whose leakage risk coefficient, malicious injection risk coefficient and attack risk coefficient all meet the standard, is retained to form the first security adjustment evolutionary solution domain. For example, 20 new schemes of the first security adjustment evolutionary group are simulated and evaluated, and it is assumed that the risk coefficients of adjustment evolutionary scheme 1 are 0.05, 0.25 and 0.35, all of which meet the multi-level security risk constraint and are retained; the risk coefficients of adjustment evolutionary scheme 2 are 0.08, 0.40 and 0.25, the malicious injection risk does not meet the multi-level security risk constraint and is eliminated; the risk coefficients of adjustment evolutionary scheme 3 are 0.15, 0.20 and 0.30, the leakage risk does not meet the multi-level security risk constraint and is eliminated; and so on. Finally, 5 schemes that meet the multi-level security risk constraint are screened out, that is, adjustment evolutionary scheme 1, adjustment evolutionary scheme 4, adjustment evolutionary scheme 7, adjustment evolutionary scheme 12 and adjustment evolutionary scheme 19.
[0071] Similarly, the business process security adjustment group is adjusted according to the second security adjustment benchmark to obtain the second security adjustment evolutionary solution domain. The business process security adjustment group is adjusted according to the third security adjustment benchmark to obtain the third security adjustment evolutionary solution domain. The first security adjustment evolutionary solution domain, the second security adjustment evolutionary solution domain and the third security adjustment evolutionary solution domain respectively correspond to the security adjustment scheme set generated through the evolutionary process on the basis of executing the first security adjustment benchmark, the second security adjustment benchmark and the third security adjustment benchmark.
[0072] The business process security adjustment scheme that meets the multi-level security risk constraint is screened out from the business process security adjustment group to obtain the first security adjustment optimization space, which contains the optimal security adjustment configuration scheme under the condition of meeting all risk constraints. The first security adjustment optimization space is expanded according to the first security adjustment evolutionary solution domain, the second security adjustment evolutionary solution domain and the third security adjustment evolutionary solution domain, that is, the larger and better global feasible solution set formed by merging the schemes in the three evolutionary solution domains with the original feasible solution set, which contains the previously determined schemes and the new schemes generated by evolution. The second security adjustment optimization space is the optimization space obtained by expanding the first security adjustment optimization space in combination with the first security adjustment evolutionary solution domain, the second security adjustment evolutionary solution domain and the third security adjustment evolutionary solution domain.
[0073] According to all business process security regulation schemes in the second security regulation optimization space, the to-be-done business process request is fitted in the whole process respectively, the fitting data is input into the multi-level security risk evaluation model, and the leakage risk coefficient, the malicious injection risk coefficient and the attack risk coefficient corresponding to each business process security regulation scheme are obtained. The multi-level security risk weight is a predetermined weight, including the leakage risk weight, the malicious injection risk weight and the attack risk weight, which is adjusted according to the actual situation of the enterprise. For example, if the enterprise is most concerned about data compliance problems recently, the leakage risk weight can be set to 0.6; if facing a large number of external attacks, the attack risk weight can be set to 0.5.
[0074] The global security risk coefficient of each scheme is calculated, and the scheme with the minimum risk coefficient is selected as the final security regulation strategy. The global security risk coefficient = leakage risk weight * leakage risk coefficient + malicious injection risk weight * malicious injection risk coefficient + attack risk weight * attack risk coefficient. Exemplarily, assuming that the weights are as follows: the leakage risk weight is 0.4, the malicious injection risk weight is 0.3, and the attack risk weight is 0.3. The global security risk coefficient of each scheme is calculated, the leakage risk coefficient of scheme A is 0.02, the malicious injection risk coefficient is 0.18, and the attack risk coefficient is 0.20, so the global security risk coefficient is 0.122; the leakage risk coefficient of scheme B is 0.08, the malicious injection risk coefficient is 0.15, and the attack risk coefficient is 0.25, so the global security risk coefficient is 0.152. The global security risk coefficient of scheme A is lower, so scheme A is selected as the final security regulation strategy. By executing three different security regulation benchmarks and combining multi-level security risk evaluation, all kinds of risks are optimized comprehensively to ensure that each business process is optimized in multiple risk dimensions.
[0075] According to the security regulation strategy, the to-be-done business process request is managed for security optimization.
[0076] Specifically, the determined security regulation strategy is applied to the to-be-done business process request, including optimizing the business process from the aspects of leakage, malicious injection, attack, etc. For example, the to-be-done business data is protected through encryption algorithm, identity authentication, access control and other measures. During the execution of the to-be-done business process, a real-time monitoring mechanism is implemented to continuously detect the security of the whole process. If any abnormality or potential risk occurs, an automatic early warning is triggered. If potential vulnerabilities or risk points are found in the monitoring, automatic vulnerability repair is performed, or the problem is reported to the security team for further emergency response processing. Through the security optimization management of the to-be-done business process, it is ensured that the whole process always maintains high efficiency and safety during execution. When all security measures are in place, the business process can be executed smoothly without being disturbed by security threats.
[0077] In summary, the business process intelligent optimization method based on multi-source data fusion provided in the application has the following beneficial effects: by analyzing the business process chain where the to-be-completed business data is located, multi-node safety accident prediction is performed, potential risks are identified in advance, safety configuration is adjusted in real time according to the business process accident graph, a multi-level safety risk evaluation model is introduced to quantitatively evaluate and globally optimize the business process safety adjustment group, the globally optimal safety adjustment strategy is ensured, and proactive early warning, dynamic protection during the process, and controllable global risks are realized, thereby significantly improving the safety of the business process.
[0078] In the second embodiment, based on the same inventive concept as the business process intelligent optimization method based on multi-source data fusion in the first embodiment, the application further provides a business process intelligent optimization system based on multi-source data fusion. Please refer to the accompanying drawings Figure 2 The business process intelligent optimization system based on multi-source data fusion includes a request acquisition module 11 configured to obtain a to-be-completed business process request of an enterprise network, wherein the to-be-completed business process request includes to-be-completed business data corresponding to a to-be-completed business process chain; an accident prediction module 12 configured to perform multi-node safety accident prediction on the to-be-completed business data based on the to-be-completed business process chain according to the enterprise network, and obtain a business process accident graph; a configuration adjustment module 13 configured to perform safety configuration adjustment on the to-be-completed business process request according to the business process accident graph, and obtain a business process safety adjustment group; an evaluation and optimization module 14 configured to perform multi-level evaluation and optimization on the business process safety adjustment group through a multi-level safety risk evaluation model, and construct a multi-level safety adjustment benchmark; a global optimization module 15 configured to perform multi-party evolution and global optimization on the business process safety adjustment group based on the multi-level safety risk evaluation model according to the multi-level safety adjustment benchmark, and obtain a safety adjustment strategy; and a process optimization module 16 configured to perform business process safety optimization management on the to-be-completed business process request according to the safety adjustment strategy.
[0079] Further, the accident prediction module 12 in the business process intelligent optimization system based on multi-source data fusion is further used for: node identification according to the to-be-done business process chain, determination of a business process first node, a business process second node, and a business process Yth node, Y being a positive integer; based on the business process first node, leakage accident prediction of the to-be-done business data according to the enterprise network, to obtain first leakage accident features; based on the business process first node, malicious injection accident prediction of the to-be-done business data according to the enterprise network, to obtain first malicious injection accident features; based on the business process first node, attack accident prediction of the to-be-done business data according to the enterprise network, to obtain first attack accident features; addition of the first leakage accident features, the first malicious injection accident features, and the first attack accident features to the business process accident graph; based on the business process second node to the business process Yth node, continue to perform multi-dimensional security accident prediction on the to-be-done business data, and update the business process accident graph.
[0080] Further, the accident prediction module 12 in the business process intelligent optimization system based on multi-source data fusion is further used for: network equipment feature modeling based on the business process first node, to obtain a first node device model; network correlation modeling of the business process first node based on the enterprise network, to obtain a first node network model; analog processing of the to-be-done business data based on the first node device model and the first node network model, to obtain first node business process analog data; accident tree training according to a business process leakage historical event set, to obtain a leakage accident tree model; disturbance enhancement training of the leakage accident tree model according to the business process leakage historical event set, to generate a leakage accident prediction model; input of the first node business process analog data into the leakage accident prediction model, to output the first leakage accident features.
[0081] Further, the configuration adjustment module 13 in the business process intelligent optimization system based on multi-source data fusion is further used for: security configuration parameter collection on the to-be-done business process request, to obtain a current security configuration scheme; leakage accident suppression adjustment of the current security configuration scheme based on the business process accident graph, to obtain a first security configuration adjustment space; malicious injection accident suppression adjustment of the current security configuration scheme according to the business process accident graph, to obtain a second security configuration adjustment space; attack accident suppression adjustment of the current security configuration scheme according to the business process accident graph, to obtain a third security configuration adjustment space; adjustment decision combination on the first security configuration adjustment space, the second security configuration adjustment space, and the third security configuration adjustment space, to generate the business process security adjustment group.
[0082] Further, the evaluation and optimization module 14 in the business process intelligent optimization system based on multi-source data fusion is further configured to: according to each business process safety adjustment scheme in the business process safety adjustment group, respectively fit the to-be-processed business process request in the whole process to obtain each scheme request fitting data; input the each scheme request fitting data into the multi-level safety risk evaluation model to obtain a safety risk evaluation heat map; according to the safety risk evaluation heat map, perform leakage risk minimization optimization on the business process safety adjustment group to obtain a first safety adjustment benchmark; according to the safety risk evaluation heat map, perform malicious injection risk minimization optimization on the business process safety adjustment group to obtain a second safety adjustment benchmark; according to the safety risk evaluation heat map, perform attack risk minimization optimization on the business process safety adjustment group to obtain a third safety adjustment benchmark; and encapsulate the first safety adjustment benchmark, the second safety adjustment benchmark and the third safety adjustment benchmark as the multi-level safety adjustment benchmark.
[0083] Further, the evaluation and optimization module 14 in the business process intelligent optimization system based on multi-source data fusion is further configured to: the multi-level safety risk evaluation model includes a leakage risk evaluation model, a malicious injection risk evaluation model and an attack risk evaluation model.
[0084] Further, the global optimization module 15 in the business process intelligent optimization system based on multi-source data fusion is further configured to: based on the multi-level safety risk evaluation model, perform evolution of the business process safety adjustment group according to the first safety adjustment benchmark to obtain a first safety adjustment evolution analysis domain; based on the multi-level safety risk evaluation model, perform evolution of the business process safety adjustment group according to the second safety adjustment benchmark to obtain a second safety adjustment evolution analysis domain; based on the multi-level safety risk evaluation model, perform evolution of the business process safety adjustment group according to the third safety adjustment benchmark to obtain a third safety adjustment evolution analysis domain; according to the multi-level safety risk constraint, filter the business process safety adjustment group to obtain a first safety adjustment optimization space; according to the first safety adjustment evolution analysis domain, the second safety adjustment evolution analysis domain and the third safety adjustment evolution analysis domain, expand the first safety adjustment optimization space to obtain a second safety adjustment optimization space; according to the multi-level safety risk weight, perform global safety risk evaluation optimization on the second safety adjustment optimization space to generate the safety adjustment strategy.
[0085] Further, the global optimization module 15 in the business process intelligent optimization system based on multi-source data fusion is further used for: performing deviation detection on the business process safety adjustment group according to the first safety adjustment benchmark, to obtain a first safety adjustment deviation set; mutating the first safety adjustment deviation set, to obtain a first adjustment evolution feature set; adjusting the business process safety adjustment group according to the first adjustment evolution feature set, to obtain a first safety adjustment evolution group; performing safety risk evaluation optimization on the first safety adjustment evolution group according to the multi-level safety risk evaluation model based on the multi-level safety risk constraint, to generate a first safety adjustment evolution analysis domain.
[0086] Further, the global optimization module 15 in the business process intelligent optimization system based on multi-source data fusion is further used for: the multi-level safety risk constraint includes a leakage risk constraint, a malicious injection risk constraint, and an attack risk constraint.
[0087] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The foregoing Figure 1 The business process intelligent optimization method based on multi-source data fusion in Embodiment One and the specific examples are also applicable to the business process intelligent optimization system based on multi-source data fusion in the present embodiment. Through the foregoing detailed description of the business process intelligent optimization method based on multi-source data fusion, those skilled in the art can clearly understand the business process intelligent optimization system based on multi-source data fusion in the present embodiment. Therefore, for the sake of brevity of the specification, no further detailed description is given here.
[0088] The above description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
[0089] Obviously, for those skilled in the art, without departing from the principles of the present application, the present application can be improved and modified in several ways, and these improvements and modifications also fall within the protection scope of the present application.
Claims
1. A method for intelligent optimization of business processes based on multi-source data fusion, characterized in that, The method comprises the following steps: obtaining a pending business process request of an enterprise network, the pending business process request comprising pending business data corresponding to a pending business process chain; based on the pending business process chain, performing multi-node security incident prediction on the pending business data according to the enterprise network to obtain a business process incident graph; based on the business process incident graph, performing security configuration adjustment on the pending business process request to obtain a business process security adjustment group; performing multi-level evaluation and optimization on the business process security adjustment group through a multi-level security risk evaluation model to construct a multi-level security adjustment benchmark; based on the multi-level security risk evaluation model, performing multi-party evolutionary expansion and global optimization on the business process security adjustment group according to the multi-level security adjustment benchmark to obtain a security adjustment strategy; performing business process security optimization management on the pending business process request according to the security adjustment strategy; based on the pending business process chain, performing multi-node security incident prediction on the pending business data according to the enterprise network to obtain a business process incident graph, comprising: performing node identification according to the pending business process chain to determine a business process first node, a business process second node, and a business process Yth node, Y being a positive integer; based on the business process first node, performing leakage incident prediction on the pending business data according to the enterprise network to obtain first leakage incident characteristics; based on the business process first node, performing malicious injection incident prediction on the pending business data according to the enterprise network to obtain first malicious injection incident characteristics; based on the business process first node, performing attack incident prediction on the pending business data according to the enterprise network to obtain first attack incident characteristics; adding the first leakage incident characteristics, the first malicious injection incident characteristics, and the first attack incident characteristics to the business process incident graph; based on the business process second node to the business process Yth node, continuing to perform multi-dimensional security incident prediction on the pending business data to update the business process incident graph; based on the business process first node, performing leakage incident prediction on the pending business data according to the enterprise network to obtain first leakage incident characteristics, comprising: performing network equipment feature modeling based on the business process first node to obtain a first node equipment model; performing network association modeling based on the enterprise network on the business process first node to obtain a first node network model; performing simulation processing on the pending business data based on the first node equipment model and the first node network model to obtain first node business process simulation data; performing incident tree training according to a business process leakage historical event set to obtain a leakage incident tree model; performing disturbance enhancement training on the leakage incident tree model according to the business process leakage historical event set to generate a leakage incident prediction model; inputting the first node business process simulation data into the leakage incident prediction model to output the first leakage incident characteristics.
2. The method of claim 1, wherein the method further comprises: According to the business process accident atlas, the to-be-handled business process request is adjusted in security configuration, and a business process security adjustment group is obtained, including: Security configuration parameters of the to-be-handled business process request are collected, and a current security configuration scheme is obtained; Based on the business process accident atlas, the current security configuration scheme is adjusted in leakage accident suppression, and a first security configuration adjustment space is obtained; Based on the business process accident atlas, the current security configuration scheme is adjusted in malicious injection accident suppression, and a second security configuration adjustment space is obtained; Based on the business process accident atlas, the current security configuration scheme is adjusted in attack accident suppression, and a third security configuration adjustment space is obtained; The first security configuration adjustment space, the second security configuration adjustment space and the third security configuration adjustment space are combined in adjustment decision, and the business process security adjustment group is generated.
3. The method of claim 1, wherein the method further comprises: Through a multi-level security risk evaluation model, the business process security adjustment group is evaluated and optimized in multiple levels, and a multi-level security adjustment benchmark is constructed, including: According to each business process security adjustment scheme in the business process security adjustment group, the to-be-handled business process request is fitted in the whole process respectively, and request fitting data of each scheme is obtained; The request fitting data of each scheme is input into the multi-level security risk evaluation model, and a security risk evaluation heat map is obtained; According to the security risk evaluation heat map, the business process security adjustment group is optimized in leakage risk minimization, and a first security adjustment benchmark is obtained; According to the security risk evaluation heat map, the business process security adjustment group is optimized in malicious injection risk minimization, and a second security adjustment benchmark is obtained; According to the security risk evaluation heat map, the business process security adjustment group is optimized in attack risk minimization, and a third security adjustment benchmark is obtained; The first security adjustment benchmark, the second security adjustment benchmark and the third security adjustment benchmark are encapsulated as the multi-level security adjustment benchmark.
4. The method of claim 1, wherein the method further comprises: Based on the multi-level security risk evaluation model, the business process security adjustment group is evolved and expanded globally according to the multi-level security adjustment benchmark, and a security adjustment strategy is obtained, including: Based on the multi-level security risk evaluation model, the evolution of the business process security adjustment group is performed according to the first security adjustment benchmark, and a first security adjustment evolution analysis domain is obtained; Based on the multi-level security risk evaluation model, the evolution of the business process security adjustment group is performed according to the second security adjustment benchmark, and a second security adjustment evolution analysis domain is obtained; Based on the multi-level security risk evaluation model, the evolution of the business process security adjustment group is performed according to the third security adjustment benchmark, and a third security adjustment evolution analysis domain is obtained; The business process security adjustment group is screened according to multi-level security risk constraints, and a first security adjustment optimization space is obtained; The first security adjustment optimization space is expanded according to the first security adjustment evolution analysis domain, the second security adjustment evolution analysis domain and the third security adjustment evolution analysis domain, and a second security adjustment optimization space is obtained; According to the multi-level security risk weight, the second security adjustment optimization space is globally evaluated and optimized in terms of security risk, and the security adjustment strategy is generated.
5. The method of claim 4, wherein the method further comprises: According to the multi-level security risk evaluation model, evolution of the business process security adjustment group is performed according to the first security adjustment benchmark, and a first security adjustment evolution analysis domain is obtained, including: According to the first security adjustment benchmark, deviation detection is performed on the business process security adjustment group, and a first security adjustment deviation set is obtained. The first security adjustment deviation set is mutated to obtain a first adjustment evolution feature set. According to the first adjustment evolution feature set, the business process security adjustment group is adjusted to obtain a first security adjustment evolution group. According to the multi-level security risk evaluation model, the first security adjustment evolution group is evaluated and optimized in terms of security risk based on the multi-level security risk constraint, and the first security adjustment evolution analysis domain is generated.
6. The method of claim 4, wherein the method further comprises: The multi-level security risk constraint includes leakage risk constraint, malicious injection risk constraint and attack risk constraint.
7. The intelligent optimization method for business processes based on multi-source data fusion as described in claim 1, characterized in that, The multi-level security risk evaluation model includes leakage risk evaluation model, malicious injection risk evaluation model and attack risk evaluation model.
8. A multi-source data fusion based intelligent business process optimization system, characterized in that, The steps of the business process intelligent optimization method based on multi-source data fusion according to any one of claims 1-7 are implemented, and the business process intelligent optimization system based on multi-source data fusion includes: A request acquisition module is configured to obtain a pending business process request of an enterprise network, wherein the pending business process request includes pending business data corresponding to a pending business process chain. An accident prediction module is configured to perform multi-node security accident prediction on the pending business data based on the pending business process chain according to the enterprise network, and obtain a business process accident graph. A configuration adjustment module is configured to perform security configuration adjustment on the pending business process request according to the business process accident graph, and obtain a business process security adjustment group. An evaluation and optimization module is configured to perform multi-level evaluation and optimization on the business process security adjustment group by using a multi-level security risk evaluation model, and construct a multi-level security adjustment benchmark. A global optimization module is configured to perform multi-party evolution and expansion global optimization on the business process security adjustment group based on the multi-level security risk evaluation model and the multi-level security adjustment benchmark, and obtain a security adjustment strategy. A process optimization module is configured to perform business process security optimization management on the pending business process request according to the security adjustment strategy.
Citation Information
Patent Citations
Method and system for predicting and continuously monitoring electric power marketing risk
CN119313370A