Fraud-related fund transaction link dynamic tracking method and system based on real-time stream computing

By employing real-time stream computing and dynamically adjusting the analysis strategy of detection nodes, the system addresses the shortcomings of existing systems in terms of real-time performance and accuracy. This enables precise interception and resource optimization in high-concurrency transaction scenarios, thereby enhancing the system's adaptability and resource utilization.

CN120975926BActive Publication Date: 2025-12-30NANJING XIAOREPTILE BIG DATA CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511509436.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-22
Publication Date
2025-12-30
Estimated Expiration
2045-10-22

AI Technical Summary

Technical Problem

Existing fraud-related fund tracking systems are inadequate in terms of real-time performance, accuracy, and adaptability. In particular, in high-concurrency transaction scenarios, their processing capacity is fixed and resource allocation is rigid, leading to data processing queue accumulation and computational delays. The model accuracy is reduced and lacks adaptive compensation, making it difficult to achieve accurate interception in cross-channel transaction links.

Method used

By adopting a real-time stream computing approach, a risk analysis intensity control model is constructed by collecting historical and dynamic data. The analysis strategy and resource allocation of the detection nodes are dynamically adjusted, and a model accuracy attenuation coefficient and a target risk identification confidence assessment mechanism are introduced to optimize the data processing path and resource configuration.

Benefits of technology

It significantly improves the system's real-time response capability and interception timeliness, maintains a high level of interception accuracy and hardware resource utilization, and builds an efficient, accurate, and adaptive real-time anti-fraud system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120975926B_ABST
    Figure CN120975926B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data analysis, and is a fraud-related fund transaction link dynamic tracking method and system based on real-time stream computing, comprising: collecting historical interception data of a fraud-related fund transaction tracking system and static data and multiple sets of dynamic data of risk detection nodes in a transaction link, calculating a model precision attenuation coefficient according to the historical interception data, determining a target risk identification confidence required to be reached in a current working period based on the model precision attenuation coefficient; constructing a risk analysis intensity control model to calculate multiple sets of risk detection intensity parameters; screening the multiple sets of risk detection intensity parameters through the target risk identification confidence, selecting the optimal target risk detection intensity parameter and dynamically configuring it. The present application solves the deficiencies of existing fraud-related fund tracking systems in real-time performance, accuracy and self-adaptive capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data analysis technology, and is a method and system for dynamic tracking of fraudulent fund transaction links based on real-time stream computing. Background Technology

[0002] In the current fintech field, real-time tracking and interception of fraudulent fund transactions has become a core industry requirement. Existing technologies typically employ detection systems based on rule engines or static machine learning models, which analyze transaction data streams layer by layer through a series of risk detection nodes. However, such systems face severe technical challenges in high-concurrency transaction scenarios: First, due to fixed node processing capabilities and rigid resource allocation strategies, the system cannot dynamically adjust processing intensity based on real-time data traffic, leading to data processing queue backlog and computational delays during peak transaction periods. Key fraud characteristics are not captured in time, thus missing the optimal interception window. Second, with the rapid evolution of fraud methods and the continuous accumulation of business data, risk identification models experience accuracy decay. Existing systems lack quantitative evaluation mechanisms and adaptive compensation strategies for model performance degradation, causing the overall interception accuracy to gradually decline over time. Third, the traditional architecture suffers from weak inter-node collaboration mechanisms and a lack of intelligent control over data flow paths, making it impossible to allocate appropriate analytical resources for different types of transactions. This results in low resource utilization and insufficient depth of detection for complex fraud patterns. Furthermore, existing solutions struggle to complete full-link risk assessment within strict time constraints when dealing with complex transaction chains involving multiple channels and jumps, often relying solely on simple threshold-triggered alarms, failing to achieve precise targeting. These issues collectively contribute to the deficiencies of existing fraud-related fund tracking systems in terms of real-time performance, accuracy, and adaptability. Summary of the Invention

[0003] The technical problem to be solved by this invention is to address the shortcomings of existing fraud-related fund tracking systems in terms of real-time performance, accuracy, and adaptability. This invention proposes a method and system for dynamic tracking of fraud-related fund transaction links based on real-time stream computing.

[0004] To achieve the above objectives, the technical solution of the present invention, a method for dynamically tracking fraudulent fund transactions based on real-time stream computing, includes the following steps:

[0005] Collect historical interception data from the fraud-related fund transaction tracking system, as well as static data and multiple sets of dynamic data from risk detection nodes in the transaction chain. The static data includes the baseline processing capability parameters of each detection node, and the dynamic data includes the performance data of each detection node under different working conditions.

[0006] Calculate the model accuracy attenuation coefficient based on the historical interception data, and determine the target risk identification confidence level to be achieved in the current work cycle based on the model accuracy attenuation coefficient.

[0007] The initial data flow characteristics of the transaction data stream are obtained, a risk analysis intensity control model is constructed, and the initial data flow characteristics, static data and multiple sets of dynamic data are input into the risk analysis intensity control model to calculate multiple sets of risk detection intensity parameters.

[0008] The target risk identification confidence level is used to filter the multiple sets of risk detection intensity parameters, select the optimal target risk detection intensity parameter, and dynamically configure the risk detection nodes in the fraudulent fund transaction tracking system according to the parameter.

[0009] Preferably, the risk detection node includes multiple risk detection sub-units, each of which contains four detection nodes, wherein the first and third detection nodes are distributed in the front-end processing area of ​​the transaction link in the order of processing, and the second and fourth detection nodes are distributed in the back-end processing area of ​​the transaction link in the order of processing.

[0010] The first detection node, the second detection node, and the fourth detection node adopt a basic detection strategy with fixed detection rules, while the third detection node adopts an adaptive detection strategy that can dynamically adjust the detection intensity.

[0011] After the transaction data stream enters from the entrance of the risk detection subunit, it passes through the first detection node, the second detection node, the third detection node and the fourth detection node in sequence, and generates the first feature extraction point, the second feature extraction point, the third feature extraction point and the fourth feature extraction point at each detection node respectively;

[0012] The first, second, and third detection nodes perform deep packet inspection and behavioral feature analysis on the transaction data streams, while the fourth detection node performs a final risk assessment on the transaction data streams and directs the processed data streams to the exit of the risk detection subunit.

[0013] Preferably, the static data includes: input reference processing delay. First node reference processing delay Export benchmark processing delay Among them, the input reference processing delay Export benchmark processing delay The value is equal to the baseline processing latency parameter of the transaction link system;

[0014] The multiple sets of dynamic data include a second processing delay set. Its collection strategy specifically includes:

[0015] S11: Obtain the actual location information of the second feature extraction point of the transaction data stream on the second detection node;

[0016] S12: Set the output data stream processing logic of the third detection node to be aligned with that of the second detection node;

[0017] S13: Set the detection intensity adjustment factor The strategy for the third detection node is adjusted so that the output data stream from the second detection node interacts with the third detection node at different detection intensities. The adjustment range of the detection intensity adjustment factor is as follows: ;

[0018] S14: Record the actual position of the third feature extraction point corresponding to each adjustment factor on the third detection node during the strategy adjustment process, forming a set of third feature extraction points;

[0019] S15: Measure the processing delay distance between the second feature extraction point and each third feature extraction point in the third feature extraction point set using performance monitoring equipment, and construct the second processing delay set. , where n is the number of adjustment factors.

[0020] Preferably, the multiple sets of dynamic data further include a third processing delay set. Its collection strategy specifically includes:

[0021] S16: Extract the set of third feature extraction points, and simulate the actual position of the fourth feature extraction point on the fourth detection node when the transaction data flow flows from each third feature extraction point to the fourth detection node.

[0022] S17: Simultaneously measure the processing delay distance between each third feature extraction point and its corresponding fourth feature extraction point in the third feature extraction point set using performance monitoring equipment, and construct the third processing delay set. ,in, This corresponds to the kth adjustment factor.

[0023] Preferably, obtaining the model accuracy attenuation coefficient includes the following steps:

[0024] S21: Extract historical interception data, including historical detection counts, historical transaction volume, and model recognition accuracy;

[0025] S22: Input the historical interception data into the model accuracy attenuation coefficient calculation strategy to calculate the model accuracy attenuation coefficient. The calculation strategy is as follows:

[0026] ;

[0027] Where I represents the number of historical detections, and i represents the index of the number of detections. These represent the historical transaction volume processed in the i-th detection and the model recognition accuracy, respectively. These represent the average historical transaction volume and the average model recognition accuracy, respectively. The accuracy rate is based on the most recent test. This represents the accuracy rate at the initial deployment of the model.

[0028] S23: Model accuracy attenuation coefficient Input the target risk identification confidence assessment strategy, calculate the target risk identification confidence level C, and the assessment strategy is as follows:

[0029] ;

[0030] in, This is the system's basic confidence threshold.

[0031] Preferably, the configuration of the risk analysis intensity control model includes the following strategies:

[0032] S31: Construct a data analysis effectiveness sub-model, the output formula of which is:

[0033] ;

[0034] Where L represents the system's basic load, and M represents the computing resources allocated to this node. This represents the analytical power value of the data flowing into the detection node. The analytical effectiveness value for the outflow detection node. Analyze the efficiency factor for nodes. This is the resource utility coefficient. This is the data quality degradation factor.

[0035] S32: Based on the initial data flow and initial analytical power of the transaction data stream. Calculate the inflow efficiency gain , The initial flow rate of the data stream when the transaction data stream enters the risk detection subunit;

[0036] S33: Input the initial data flow and initial analysis power into the data analysis power sub-model to obtain the first analysis power after passing the first detection node. Simultaneously, the first effectiveness gain is calculated based on the processing capacity of the first node. , This refers to the traffic after the transaction data stream passes through the first detection node;

[0037] S34: Combine the first data flow and the first analytical power. Input data analysis effectiveness sub-model, obtain the second analysis effectiveness after passing through the second detection node. Simultaneously, the second effectiveness gain set is calculated based on the second processing effectiveness set. ,in , This refers to the data flow of the transaction data stream after it passes through the second detection node.

[0038] Preferably, the configuration of the risk analysis intensity control model further includes:

[0039] S35: Transfer the second data traffic Second processing delay set The detection intensity input data for each third feature extraction point is used to analyze the effectiveness of the sub-model, and the third analysis effectiveness set after passing through the third detection node is obtained. ,in:

[0040] ;

[0041] in, This is the analytical efficiency factor corresponding to the k-th adjustment factor; Let k be the resource utility coefficient corresponding to the k-th adjustment factor. To dynamically allocate computing resources to the third detection node;

[0042] Simultaneously, based on the third processing delay set Calculate the third power gain set ;

[0043] in, , This refers to the data flow rate of the transaction data stream after passing through the third detection node under the k-th adjustment factor.

[0044] S36: Processing delay based on export reference and the third set of analytical effectiveness Calculate the set of export effectiveness gains ,in .

[0045] Preferably, the acquisition of the multiple sets of risk detection intensity parameters includes:

[0046] S41: Extracting Inflow Efficiency Gain First-efficiency gain Second effectiveness gain set Third effectiveness gain set and export efficiency gain set ;

[0047] S42: Calculate the expected total effectiveness gain set based on the above data. ;

[0048] in: Where k = 1, 2, ..., n.

[0049] Preferably, multiple sets of risk detection intensity parameters are screened based on the target risk identification confidence level, specifically including:

[0050] Preset confidence redundancy boundary The sum of the target risk identification confidence level C and the confidence redundancy boundary is calculated to obtain the safety confidence level. ;

[0051] Extract each predicted total effectiveness gain from the predicted total effectiveness gain set. To link it with security confidence By comparing the results, we obtain a set of effectiveness differences. ;

[0052] Sort the differences in the set of effectiveness differences in ascending order and select the top 10% of the sequence as candidate effectiveness gains;

[0053] Obtain the detection intensity adjustment factor of the third detection node corresponding to each alternative effectiveness gain to form the alternative risk detection intensity parameter;

[0054] The current detection intensity adjustment factor of the third detection node is monitored in real time, the absolute value of the difference between its adjustment amount and the adjustment amount of each alternative risk detection intensity parameter is calculated, and the parameter corresponding to the minimum adjustment amount is selected to configure the third detection node.

[0055] In addition, the real-time stream computing-based dynamic tracking system for fraudulent fund transactions of this invention includes the following modules:

[0056] The module includes a data acquisition module, a historical data evaluation module, a transaction chain status analysis module, and a tracking parameter configuration module.

[0057] The data acquisition module is used to collect historical intercepted data from the fraud-related fund transaction tracking system, as well as static data and multiple sets of dynamic data from risk detection nodes in the transaction chain. The static data includes the baseline processing capability parameters of each detection node, and the dynamic data includes the performance data of each detection node under different working conditions.

[0058] The historical data evaluation module calculates the model accuracy attenuation coefficient based on the historical interception data, and determines the target risk identification confidence level to be achieved in the current work cycle based on the model accuracy attenuation coefficient.

[0059] The transaction chain status analysis module is used to obtain the initial data flow characteristics of the transaction data stream, construct a risk analysis intensity control model, and input the initial data flow characteristics, static data, and multiple sets of dynamic data into the risk analysis intensity control model to calculate multiple sets of risk detection intensity parameters.

[0060] The tracking parameter configuration module filters the multiple sets of risk detection intensity parameters based on the target risk identification confidence level, selects the optimal target risk detection intensity parameter, and dynamically configures the risk detection nodes in the fraudulent fund transaction tracking system according to the parameter.

[0061] Compared with the prior art, the technical effects of the present invention are as follows:

[0062] 1. This invention collects transaction data traffic characteristics in real time and constructs a risk analysis intensity control model, which can dynamically adjust the analysis strategy and resource allocation of key detection nodes. In high-concurrency transaction scenarios, it can intelligently optimize the data processing path, effectively overcome the processing bottleneck caused by traditional fixed rule engines, and significantly reduce the computational latency caused by queue accumulation and resource competition. This ensures that fraudulent transactions are accurately identified and intercepted within a very short time window, thereby significantly improving the system's real-time response capability and interception timeliness.

[0063] 2. This invention introduces a model accuracy decay coefficient and target risk identification confidence assessment mechanism based on historical interception data, enabling the system to have the ability to quantitatively perceive and dynamically compensate for the performance decay of the risk identification model. By adaptively improving the overall strength of the analysis link or adjusting the resource allocation strategy, it effectively combats the model aging problem caused by the evolution of fraud patterns or changes in data distribution, and continuously maintains a high level of interception accuracy and system robustness.

[0064] 3. By establishing a multi-node collaborative control mechanism with analytical effectiveness as its core, this invention achieves global optimization decision-making under strict time constraints and limited resources. The system can automatically select the combination of detection parameters that meets the target confidence requirements and has the lowest resource consumption, avoiding excessive investment and waste of computing resources. While ensuring the risk control effect, it significantly improves the utilization rate of hardware resources and the overall energy efficiency ratio of the system, providing reliable technical support for financial institutions to build an efficient, accurate, and adaptive real-time anti-fraud system. Attached Figure Description

[0065] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0066] Figure 1 This is a flowchart illustrating the method for dynamic tracking of fraudulent fund transactions based on real-time stream computing according to the present invention.

[0067] Figure 2 This is a schematic diagram of the structure of the real-time stream computing-based dynamic tracking system for fraudulent fund transactions according to the present invention. Detailed Implementation

[0068] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0069] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0070] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0071] Example 1:

[0072] like Figure 1 As shown in the figure, the method for dynamic tracking of fraudulent fund transaction links based on real-time stream computing in this invention embodiment is as follows: Figure 1 As shown, the specific steps include the following:

[0073] Collect historical interception data from the fraud-related fund transaction tracking system, as well as static data and multiple sets of dynamic data from risk detection nodes in the transaction chain. The static data includes the baseline processing capability parameters of each detection node, and the dynamic data includes the performance data of each detection node under different working conditions.

[0074] The risk detection node includes multiple risk detection sub-units, each of which contains four detection nodes. The first and third detection nodes are distributed in the front-end processing area of ​​the transaction link in the order of processing, while the second and fourth detection nodes are distributed in the back-end processing area of ​​the transaction link in the order of processing.

[0075] The first detection node, the second detection node, and the fourth detection node adopt a basic detection strategy with fixed detection rules, while the third detection node adopts an adaptive detection strategy that can dynamically adjust the detection intensity.

[0076] After the transaction data stream enters from the entrance of the risk detection subunit, it passes through the first detection node, the second detection node, the third detection node and the fourth detection node in sequence, and generates the first feature extraction point, the second feature extraction point, the third feature extraction point and the fourth feature extraction point at each detection node respectively;

[0077] The first, second, and third detection nodes perform deep packet inspection and behavioral feature analysis on the transaction data streams, while the fourth detection node performs a final risk assessment on the transaction data streams and directs the processed data streams to the exit of the risk detection subunit.

[0078] The static data includes: input reference processing delay. First node reference processing delay Export benchmark processing delay Among them, the input reference processing delay Export benchmark processing delay The value is equal to the baseline processing latency parameter of the transaction link system;

[0079] The multiple sets of dynamic data include a second processing delay set. Its collection strategy specifically includes:

[0080] S11: Obtain the actual location information of the second feature extraction point of the transaction data stream on the second detection node;

[0081] S12: Set the output data stream processing logic of the third detection node to be aligned with that of the second detection node;

[0082] S13: Set the detection intensity adjustment factor The strategy for the third detection node is adjusted so that the output data stream from the second detection node interacts with the third detection node at different detection intensities. The adjustment range of the detection intensity adjustment factor is as follows: ;

[0083] S14: Record the actual position of the third feature extraction point corresponding to each adjustment factor on the third detection node during the strategy adjustment process, forming a set of third feature extraction points;

[0084] S15: Measure the processing delay distance between the second feature extraction point and each third feature extraction point in the third feature extraction point set using performance monitoring equipment, and construct the second processing delay set. , where n is the number of adjustment factors.

[0085] The multiple sets of dynamic data also include a third processing delay set. Its collection strategy specifically includes:

[0086] S16: Extract the set of third feature extraction points, and simulate the actual position of the fourth feature extraction point on the fourth detection node when the transaction data flow flows from each third feature extraction point to the fourth detection node.

[0087] S17: Simultaneously measure the processing delay distance between each third feature extraction point and its corresponding fourth feature extraction point in the third feature extraction point set using performance monitoring equipment, and construct the third processing delay set. ,in, This corresponds to the kth adjustment factor.

[0088] Calculate the model accuracy attenuation coefficient based on the historical interception data, and determine the target risk identification confidence level to be achieved in the current work cycle based on the model accuracy attenuation coefficient.

[0089] The model accuracy attenuation coefficient is obtained through the following steps:

[0090] S21: Extract historical interception data, including historical detection counts, historical transaction volume, and model recognition accuracy;

[0091] S22: Input the historical interception data into the model accuracy attenuation coefficient calculation strategy to calculate the model accuracy attenuation coefficient. The calculation strategy is as follows:

[0092] ;

[0093] Where I represents the number of historical detections, and i represents the index of the number of detections. These represent the historical transaction volume processed in the i-th detection and the model recognition accuracy, respectively. These represent the average historical transaction volume and the average model recognition accuracy, respectively. The accuracy rate is based on the most recent test. This represents the accuracy rate at the initial deployment of the model.

[0094] S23: Model accuracy attenuation coefficient Input the target risk identification confidence assessment strategy, calculate the target risk identification confidence level C, and the assessment strategy is as follows:

[0095] ;

[0096] in, This is the system's basic confidence threshold.

[0097] The initial data flow characteristics of the transaction data stream are obtained, a risk analysis intensity control model is constructed, and the initial data flow characteristics, static data and multiple sets of dynamic data are input into the risk analysis intensity control model to calculate multiple sets of risk detection intensity parameters.

[0098] The configuration of the risk analysis intensity control model includes the following strategies:

[0099] S31: Construct a data analysis effectiveness sub-model, the output formula of which is:

[0100] ;

[0101] Where L represents the system's basic load, and M represents the computing resources allocated to this node. This represents the analytical power value of the data flowing into the detection node. The analytical effectiveness value for the outflow detection node. Analyze the efficiency factor for nodes. This is the resource utility coefficient. This is the data quality degradation factor.

[0102] S32: Based on the initial data flow and initial analytical power of the transaction data stream. Calculate the inflow efficiency gain , The initial flow rate of the data stream when the transaction data stream enters the risk detection subunit;

[0103] S33: Input the initial data flow and initial analysis power into the data analysis power sub-model to obtain the first analysis power after passing the first detection node. Simultaneously, the first effectiveness gain is calculated based on the processing capacity of the first node. , This refers to the traffic after the transaction data stream passes through the first detection node;

[0104] S34: Combine the first data flow and the first analytical power. Input data analysis effectiveness sub-model, obtain the second analysis effectiveness after passing through the second detection node. Simultaneously, the second effectiveness gain set is calculated based on the second processing effectiveness set. ,in , This refers to the data flow of the transaction data stream after it passes through the second detection node.

[0105] S35: Transfer the second data traffic Second processing delay set The detection intensity input data for each third feature extraction point is used to analyze the effectiveness of the sub-model, and the third analysis effectiveness set after passing through the third detection node is obtained. ,in:

[0106] ;

[0107] in, This is the analytical efficiency factor corresponding to the k-th adjustment factor; Let k be the resource utility coefficient corresponding to the k-th adjustment factor. To dynamically allocate computing resources to the third detection node;

[0108] Simultaneously, based on the third processing delay set Calculate the third power gain set ;

[0109] in, , This refers to the data flow rate of the transaction data stream after passing through the third detection node under the k-th adjustment factor.

[0110] S36: Processing delay based on export reference and the third set of analytical effectiveness Calculate the set of export effectiveness gains ,in .

[0111] The target risk identification confidence level is used to filter the multiple sets of risk detection intensity parameters, select the optimal target risk detection intensity parameter, and dynamically configure the risk detection nodes in the fraudulent fund transaction tracking system according to the parameter.

[0112] The acquisition of the multiple sets of risk detection intensity parameters includes:

[0113] S41: Extracting Inflow Efficiency Gain First-efficiency gain Second effectiveness gain set Third effectiveness gain set and export efficiency gain set ;

[0114] S42: Calculate the expected total effectiveness gain set based on the above data. ;

[0115] in: Where k = 1, 2, ..., n.

[0116] Multiple risk detection intensity parameters are screened based on the target risk identification confidence level, specifically including:

[0117] Preset confidence redundancy boundary The sum of the target risk identification confidence level C and the confidence redundancy boundary is calculated to obtain the safety confidence level. ;

[0118] Extract each predicted total effectiveness gain from the predicted total effectiveness gain set. To link it with security confidence By comparing the results, we obtain a set of effectiveness differences. ;

[0119] Sort the differences in the set of effectiveness differences in ascending order and select the top 10% of the sequence as candidate effectiveness gains;

[0120] Obtain the detection intensity adjustment factor of the third detection node corresponding to each alternative effectiveness gain to form the alternative risk detection intensity parameter;

[0121] The current detection intensity adjustment factor of the third detection node is monitored in real time, the absolute value of the difference between its adjustment amount and the adjustment amount of each alternative risk detection intensity parameter is calculated, and the parameter corresponding to the minimum adjustment amount is selected to configure the third detection node.

[0122] Example 2:

[0123] like Figure 2 As shown in the figure, the real-time stream computing-based dynamic tracking system for fraudulent fund transactions in this invention is as follows: Figure 2 As shown, it includes the following modules:

[0124] The module includes a data acquisition module, a historical data evaluation module, a transaction chain status analysis module, and a tracking parameter configuration module.

[0125] The data acquisition module is used to collect historical intercepted data from the fraud-related fund transaction tracking system, as well as static data and multiple sets of dynamic data from risk detection nodes in the transaction chain. The static data includes the baseline processing capability parameters of each detection node, and the dynamic data includes the performance data of each detection node under different working conditions.

[0126] The historical data evaluation module calculates the model accuracy attenuation coefficient based on the historical interception data, and determines the target risk identification confidence level to be achieved in the current work cycle based on the model accuracy attenuation coefficient.

[0127] The transaction chain status analysis module is used to obtain the initial data flow characteristics of the transaction data stream, construct a risk analysis intensity control model, and input the initial data flow characteristics, static data, and multiple sets of dynamic data into the risk analysis intensity control model to calculate multiple sets of risk detection intensity parameters.

[0128] The tracking parameter configuration module filters the multiple sets of risk detection intensity parameters based on the target risk identification confidence level, selects the optimal target risk detection intensity parameter, and dynamically configures the risk detection nodes in the fraudulent fund transaction tracking system according to the parameter.

[0129] Example 3:

[0130] This embodiment provides an electronic device, including: a processor and a memory, wherein the memory stores a computer program that can be called by the processor;

[0131] The processor executes the aforementioned method for dynamically tracking fraudulent fund transactions based on real-time stream computing by calling computer programs stored in memory.

[0132] The electronic device can vary considerably depending on its configuration or performance. It may include one or more Central Processing Units (CPUs) and one or more memories, wherein the memory stores at least one computer program, which is loaded and executed by the processor to implement the real-time stream computing-based dynamic tracking method for fraudulent fund transactions provided in the above-described embodiment. The electronic device may also include other components for implementing its functions; for example, it may have wired or wireless network interfaces and input / output interfaces for data input and output. Details will not be elaborated upon in this embodiment.

[0133] Example 4:

[0134] This embodiment proposes a computer-readable storage medium on which an erasable and rewritable computer program is stored.

[0135] When the computer program runs on the computer device, it causes the computer device to execute the above-mentioned method for dynamic tracking of fraudulent fund transactions based on real-time stream computing.

[0136] For example, computer-readable storage media can be read-only memory (ROM), random access memory (RAM), compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage devices.

[0137] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0138] It should be understood that determining B based on A does not mean determining B solely based on A; it also means determining B based on A and / or other information.

[0139] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired network and / or wireless network. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives (SSDs).

[0140] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0141] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0142] In the several embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only one method, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0143] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0144] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0145] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0146] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. A method for dynamic tracking of money laundering transaction links based on real-time stream computing, characterized in that, The method comprises: Collecting historical interception data of the fraud-related fund transaction tracking system and static data and multiple sets of dynamic data of risk detection nodes in a transaction link, wherein the static data comprises reference processing capacity parameters of each detection node, and the dynamic data comprises performance data of each detection node in different working states; The static data includes: an entry reference processing time delay , a first node reference processing time delay , and an exit reference processing time delay , wherein the entry reference processing time delay and the exit reference processing time delay are equal to the reference processing time delay parameter of the transaction link system. The multiple sets of dynamic data include a second processing delay set The acquisition strategy specifically includes: S11: obtaining actual position information of a second feature extraction point of a transaction data stream on a second detection node; S12: setting the output data stream processing logic of a third detection node and the second detection node to remain aligned; S13: setting a detection intensity adjustment factor The third detection node is adjusted in strategy, and the output data stream of the second detection node interacts with the third detection node at different detection intensities, wherein the adjustment range of the detection intensity adjustment factor is ; S14: recording actual positions of third feature extraction points on the third detection node corresponding to each adjustment factor in the strategy adjustment process, to form a third feature extraction point set; S15: measuring the processing time delay distance between the second feature extraction point and each third feature extraction point in the third feature extraction point set through the performance monitoring device, and constructing a second processing time delay set wherein n is the number of adjustment factors; The multiple sets of dynamic data further include a third processing delay set The acquisition strategy specifically includes: S16: extracting the third feature extraction point set, simulating actual positions of fourth feature extraction points on a fourth detection node generated when the transaction data stream flows from each third feature extraction point to the fourth detection node; S17: synchronously measure the processing delay distance between each third feature extraction point and the corresponding fourth feature extraction point in the third feature extraction point set through the performance monitoring device, and construct a third processing delay set wherein, corresponding to the kth adjustment factor; calculating a model precision attenuation coefficient according to the historical interception data, and determining a target risk identification confidence required in a current working period based on the model precision attenuation coefficient; obtaining initial data flow characteristics of the transaction data stream, constructing a risk analysis intensity control model, inputting the initial data flow characteristics, static data and multiple sets of dynamic data into the risk analysis intensity control model, and calculating multiple sets of risk detection intensity parameters; screening the multiple sets of risk detection intensity parameters through the target risk identification confidence, selecting optimal target risk detection intensity parameters, and dynamically configuring risk detection nodes in the fraud-related fund transaction tracking system according to the parameters.

2. The method of claim 1, wherein the method further comprises: The risk detection nodes comprise multiple risk detection subunits, and each risk detection subunit comprises four detection nodes, wherein the first detection node and the third detection node are distributed in a front-end processing area of the transaction link in processing order, and the second detection node and the fourth detection node are distributed in a rear-end processing area of the transaction link in processing order; The first detection node, the second detection node and the fourth detection node adopt a basic detection strategy of a fixed detection rule, and the third detection node adopts an adaptive detection strategy of a dynamically adjustable detection intensity; After the transaction data stream enters the risk detection subunit, the transaction data stream sequentially passes through the first detection node, the second detection node, the third detection node and the fourth detection node, and first feature extraction points, second feature extraction points, third feature extraction points and fourth feature extraction points are respectively generated on the detection nodes. The first detection node, the second detection node and the third detection node perform deep packet detection and behavior feature analysis on the transaction data stream, and the fourth detection node performs final risk assessment on the transaction data stream, and guides the processed data stream to the outlet of the risk detection subunit.

3. The real-time stream computing based anti-fraud money transaction link dynamic tracking method according to claim 2, characterized in that, The acquisition of the model precision attenuation coefficient comprises the following steps: S21: extracting historical interception data, including historical detection times, historical processed transaction volume and model identification accuracy; S22: input the historical interception data into the model precision attenuation coefficient calculation strategy to calculate the model precision attenuation coefficient wherein the calculation strategy is: ; wherein I is the historical detection times, i is the detection times index, are the historical processing transaction volume and model identification accuracy of the i-th detection, respectively, are the historical processing transaction volume mean and model identification accuracy mean, respectively, is the accuracy of the last detection, is the accuracy when the model is initially deployed. S23: the model precision attenuation coefficient Input the target risk identification confidence assessment strategy, calculate the target risk identification confidence C, and the assessment strategy is: ; wherein, is a system base confidence threshold.

4. The real-time stream computing based anti-fraud money transaction link dynamic tracking method according to claim 3, characterized in that, The configuration of the risk analysis intensity control model comprises the following strategies: S31: constructing a data analysis efficiency submodel, and the output formula is: ; where L is the system base load, M is the computing resource allocated to the node, is the analysis efficacy value for the incoming flow detection node, is the analysis efficacy value for the outgoing flow detection node, is the node analysis efficiency factor, is the resource utility coefficient, is the data quality decay factor; S32: calculating the inflow gain of efficacy from the initial data flow of the transaction data flow and the initial analysis efficacy , initial flow of the data flow when the transaction data flow enters the risk detection subunit​ S33: input the initial data flow and the initial analysis effectiveness into the data analysis effectiveness sub-model to obtain the first analysis effectiveness after the first detection node , and calculate the first effectiveness gain according to the processing capacity of the first node , the flow of the transaction data stream after passing through the first detection node S34: obtaining the first analysis effectiveness of the first data flow inputting the data analysis effectiveness sub-model to obtain the second analysis effectiveness after the second detection node Meanwhile, a second effectiveness gain set is calculated according to the second processing effectiveness set Wherein , is the flow of the data flow after the transaction data flow passes through the second detection node.

5. The real-time stream computing based anti-fraud money transaction link dynamic tracking method according to claim 4, characterized in that, The configuration of the risk analysis intensity control model further comprises: S35: the second data flow is transmitted to the second processing node and the second processing delay set a detection intensity input data analysis effectiveness sub-model corresponding to each third feature extraction point is obtained, and a third analysis effectiveness set after the third detection node is obtained wherein: ; wherein, is the analysis efficiency factor corresponding to the kth adjustment factor; is the resource utility coefficient corresponding to the kth adjustment factor, is the computing resource dynamically allocated to the third detection node; while according to a third set of processing delays calculating a third set of effectiveness gains ; wherein, , is the flow of the data stream after the transaction data stream passes through the third detection node under the kth adjustment factor; S36: handle latency based on export reference and third analysis potency set , compute export potency gain set wherein .

6. The real-time stream computing based anti-fraud money transaction link dynamic tracking method according to claim 5, characterized in that, The acquisition of the multiple sets of risk detection intensity parameters comprises: S41: Extract inflow potency gains , first potency gains , second potency gain set , third potency gain set and exit potency gain set ; S42: Calculate a set of predicted total efficacy gains based on the above data ; wherein: ; wherein k = 1, 2,..., n.

7. The real-time stream computing based anti-fraud money transaction link dynamic tracking method according to claim 6, characterized in that, The multiple sets of risk detection intensity parameters are screened through the target risk identification confidence, and specifically comprises: Pre-set confidence redundancy boundary , calculate the sum of the target risk identification confidence C and the confidence redundancy boundary to obtain the security confidence ; extracting each predicted total efficacy gain in the set of predicted total efficacy gains comparing it to the safety confidence to obtain a set of efficacy difference values ; The difference values in the efficacy difference value set are arranged in ascending order, and the first 10% of the sequence are selected as the candidate efficacy gains; The detection intensity adjustment factor of the third detection node corresponding to each candidate efficacy gain is acquired to form a candidate risk detection intensity parameter; The current detection intensity adjustment factor of the third detection node is monitored in real time, the absolute value of the adjustment amount difference between the current detection intensity adjustment factor and each candidate risk detection intensity parameter is calculated, and the parameter corresponding to the minimum adjustment amount is selected to configure the third detection node.

8. A system for real-time stream computing based dynamic tracing of money transaction links for fraud, for implementing the method of real-time stream computing based dynamic tracing of money transaction links for fraud according to any one of claims 1 to 7, characterized in that, The system comprises the following modules: a data collection module, a historical data evaluation module, a transaction chain state analysis module, and a tracking parameter configuration module; The data collection module is used to collect historical interception data of the fraud-related fund transaction tracking system and static data and multiple sets of dynamic data of risk detection nodes in the transaction chain, wherein the static data comprises reference processing capacity parameters of each detection node, and the dynamic data comprises performance data of each detection node under different working states; The historical data evaluation module calculates a model precision attenuation coefficient according to the historical interception data, and determines a target risk identification confidence required to be reached in a current working period based on the model precision attenuation coefficient; The transaction chain state analysis module is used to acquire initial data flow characteristics of transaction data flow, construct a risk analysis intensity control model, input the initial data flow characteristics, static data, and multiple sets of dynamic data into the risk analysis intensity control model, and calculate multiple sets of risk detection intensity parameters; The tracking parameter configuration module screens the multiple sets of risk detection intensity parameters through the target risk identification confidence, selects an optimal target risk detection intensity parameter, and dynamically configures risk detection nodes in the fraud-related fund transaction tracking system according to the parameter.

Citation Information

Patent Citations

  • Tracking and tracing method and system based on RFID Internet of Things technology

    CN120632743A

  • Financial data risk control system and method based on big data

    CN120746695A