A Business Anomaly Monitoring Method and System Based on Dynamic Graph Computation
By generating a business graph structure through dynamic graph calculation, evaluating the rationality of nodes and dynamically processing weights, the problem of insufficient accuracy in mapping business relationships in ERP reports is solved. This enables precise location and tracing of abnormal nodes, improving the flexibility and accuracy of the monitoring system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING NANBEI TIANDI TECH CO LTD
- Filing Date
- 2025-12-17
- Publication Date
- 2026-08-04
AI Technical Summary
In existing technologies, the accuracy of business relationship mapping in ERP reports is insufficient, resulting in low precision in anomaly tracing and impact assessment, and low accuracy in business anomaly monitoring.
Based on dynamic graph computation, by generating a business graph structure, the rationality of nodes is dynamically evaluated, node weights and update frequencies are dynamically adjusted, and dynamic control of monitoring resources is achieved by combining node level and risk assessment.
It improved the accuracy of the business graph structure and the efficiency of resource utilization, enhanced the ability to locate and trace abnormal nodes, and improved the flexibility and accuracy of the monitoring system.
Smart Images

Figure CN121349751B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of business monitoring data processing technology, and in particular to a business anomaly monitoring method and system based on dynamic graph calculation. Background Technology
[0002] Dynamic graph computation is a computational method for processing relational networks that change over time. It abstracts business entities (such as customers, suppliers, and orders) into "nodes" and the relationships between them (such as transactions, logistics, and capital flows) into "edges," continuously tracking the evolution of this network structure and attributes. In business anomaly monitoring, it identifies abnormal patterns hidden in complex relationships by analyzing this dynamic graph in real time: for example, community detection algorithms can detect suddenly disbanded supplier clusters, indicating supply chain risks; centrality analysis can identify a sharp drop in the transaction volume of a key customer, suggesting customer churn; or real-time comparison of network snapshots can reveal abnormal loops in a payment path, potentially pointing to fraudulent activities. Compared to traditional methods that only focus on numerical indicators, dynamic graph computation can gain a holistic perspective from the perspective of relationships, discovering systemic risks and hidden anomalies that are not visible in isolated data points earlier and more accurately, thus achieving proactive intelligent risk management.
[0003] Existing business anomaly monitoring methods integrate multi-dimensional structured or unstructured data such as business system logs, transaction records, performance metrics, and user behavior through a data acquisition module. After data cleaning, normalization, and feature engineering, key features such as time-series trends, association rules, and statistical distributions are extracted. Then, based on preset thresholds, statistical models (such as mean-variance, sliding window, and hypothesis testing), deep learning models (such as isolated forest, LSTM, and autoencoders), or rule engines (customized logical rules based on business scenarios), an anomaly identification system is constructed. This system achieves real-time capture of abnormal events by comparing the deviation between the normal baseline and real-time data, detecting abnormal data distribution, or matching preset anomaly patterns. Finally, a closed loop is formed through alarm triggering, anomaly classification, and root cause analysis. Furthermore, historical data is used to continuously optimize model parameters or rule configurations to adapt to dynamic changes in business scenarios, thereby improving the accuracy and robustness of monitoring.
[0004] For example, a business management system disclosed in Chinese invention patent publication number CN118674389A includes: a template editing module for creating and uploading work report masks; a template maintenance module for revising received work report masks and setting task deadlines; a template review module for reviewing revised work report masks; a data monitoring module for sharing approved work report masks and extracting and storing the returned work report mask data; and a data analysis module for comparing the returned work report mask data with historical data, calculating the difference based on the project, marking the difference, and then compiling and uploading a report message.
[0005] For example, the Chinese invention patent with publication number CN118229395A discloses a method, apparatus, computer equipment, and storage medium for analyzing monitoring indicator anomalies, which includes: acquiring monitoring reports to be submitted in the current monitoring week; the monitoring reports include multiple monitoring indicators; for each monitoring indicator in the monitoring reports, determining a target ledger model containing detailed business indicators from multiple business ledger models based on the detailed business indicators associated with the monitoring indicators; and performing anomaly analysis on the monitoring indicators based on the detailed business data corresponding to the target ledger model in the current monitoring period and the previous historical monitoring period, and determining the anomaly analysis results of the monitoring indicators.
[0006] However, in the process of implementing the inventive technical solution in the embodiments of this application, it was found that the above-mentioned technology has at least the following technical problems: In existing technologies, during the business monitoring process of ERP reports, the weights of business associations are often set to fixed values. However, changes in real-time interaction parameters directly alter the actual strength of the association between business entities. Furthermore, the degree of impact and risk transmission probability of different nodes on related businesses vary significantly due to their different rationality statuses. This results in insufficient accuracy in mapping business associations, which in turn affects the accuracy of anomaly tracing and impact assessment, leading to low accuracy in business anomaly monitoring. Summary of the Invention
[0007] To address the issue that in ERP report business monitoring, the weights of business relationships are often set to fixed values, while real-time interaction parameters directly alter the actual strength of the relationship between business entities. Furthermore, different node states significantly impact related businesses and the probability of risk transmission, leading to insufficient accuracy in mapping business relationships and consequently affecting the precision of anomaly tracing and impact assessment. This results in low accuracy in business anomaly monitoring. Therefore, this invention provides a business anomaly monitoring method and system based on dynamic graph calculation. The technical solution is as follows: On one hand, this invention provides a business anomaly monitoring method based on dynamic graph calculation. This method includes: generating a business graph structure based on real-time business interaction data and business association attributes from ERP reports; dynamically evaluating the rationality of nodes based on basic node stability parameters and associated business parameters; and dynamically adjusting nodes based on node update resource usage and report granularity mode according to the node rationality dynamic evaluation results; dynamically processing node weights based on business interaction parameters of each associated business and the node rationality dynamic evaluation results; dynamically evaluating business impact based on the node weight dynamic processing results and node level; and dynamically evaluating node risk based on the business impact dynamic evaluation results and node dynamic stability parameters, and performing monitoring and dynamic control processing based on the node risk dynamic evaluation results.
[0008] On the other hand, this invention provides a business anomaly monitoring system based on dynamic graph calculation. This system includes: a node dynamic adjustment module, a business impact assessment module, and a monitoring dynamic control module. The node dynamic adjustment module generates a business graph structure based on real-time business interaction data and business association attributes from ERP reports, performs dynamic evaluation of node rationality based on node basic stability parameters and associated business parameters, and executes node dynamic adjustment based on node update resource usage and report granularity mode according to the node rationality dynamic evaluation results. The business impact assessment module dynamically processes node weights based on business interaction parameters of each associated business and the node rationality dynamic evaluation results, and performs dynamic evaluation of business impact based on the node weight dynamic processing results and node level. The monitoring dynamic control module dynamically evaluates node risks based on the business impact dynamic evaluation results and node dynamic stability parameters, and performs monitoring dynamic control processing based on the node risk dynamic evaluation results.
[0009] Beneficial effects The beneficial effects of the technical solutions provided in the embodiments of the present invention include at least the following: 1. This invention constructs a dynamic business graph structure based on real-time business interaction data from ERP reports, and performs dynamic evaluation of node rationality, dynamic weight processing, and dynamic risk assessment by comprehensively considering node basic stability parameters, related business parameters, and business interaction parameters. This enables adaptive adjustment of node update frequency and weight, as well as dynamic allocation of monitoring resources, thereby achieving an optimal balance between resource consumption and business needs, improving the accuracy of the business graph structure, and enhancing the ability to accurately locate and trace abnormal nodes.
[0010] 2. This invention establishes an anomaly identification mechanism that balances node stability and business context changes by combining node basic stability parameters with related business parameters for multi-step rationality assessment and introducing a related business activity index to dynamically adjust the judgment threshold. Furthermore, based on node status and resource occupancy, the node update frequency is adjusted differentially through mapping table matching, realizing on-demand allocation of monitoring resources and accurate response to abnormal nodes, effectively improving system resource utilization efficiency and anomaly monitoring accuracy.
[0011] 3. This invention dynamically assigns weights by integrating multi-dimensional business interaction parameters and node rationality assessment results, and introduces a business impact coefficient for node levels, thereby constructing a comprehensive assessment system that reflects both real-time interaction characteristics and node importance; thus, it achieves accurate quantification of connection relationships in the business graph structure and intelligent identification of key impact nodes, laying a data foundation for subsequent risk classification and precise resource allocation.
[0012] 4. This invention constructs a two-layer quantitative system of node anomaly risk index and comprehensive risk index by dynamically integrating node stability parameters and business impact assessment results, thereby achieving accurate characterization and graded early warning of node risk levels; furthermore, based on risk level matching differentiated monitoring strategies, it realizes adaptive optimization of monitoring resources and rapid location and handling of abnormal nodes, significantly improving the accuracy and timeliness of system risk management. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 A flowchart of a service anomaly monitoring method based on dynamic graph calculation provided in this application embodiment; Figure 2 A flowchart of the node rationality evaluation process for the business anomaly monitoring method based on dynamic graph calculation provided in this application embodiment; Figure 3 This is a schematic diagram of the structure of a business anomaly monitoring system based on dynamic graph calculation provided in an embodiment of this application. Detailed Implementation
[0015] The following provides explanations for some of the terms used in this application. It should be noted that these explanations are for the convenience of those skilled in the art and do not constitute a limitation on the scope of protection claimed in this application.
[0016] The embodiments of this application involve at least one, including one or more; wherein, multiple means two or more.
[0017] References to "one embodiment," "in some examples," or "some embodiments" as described in the embodiments of this application mean that one or more embodiments of this specification include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in some examples," "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.
[0018] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0019] like Figure 1 The diagram shows a flowchart of a business anomaly monitoring method based on dynamic graph computation provided in this application. The method includes the following steps: generating a business graph structure based on real-time business interaction data and business association attributes from ERP reports; dynamically evaluating the rationality of nodes based on basic node stability parameters and associated business parameters; and dynamically adjusting nodes based on the node update resource usage and report granularity mode according to the dynamic evaluation results. In the business graph structure, nodes represent business entities, edges represent the interaction relationships between business entities, and dynamic node adjustment means dynamically adjusting the node update frequency in the business graph structure to maintain the optimal balance between resource consumption and business needs. The report granularity... The modes include coarse-grained, medium-grained, and fine-grained modes, each corresponding to different levels of data aggregation and update cycles. For example, coarse-grained modes are represented by ERP management dashboard reports or monthly comprehensive settlement reports, which have a high level of data aggregation and present core operational indicators to decision-makers, such as monthly sales gross profit analysis reports and ending inventory balance summary reports. They have a long update cycle, such as once every 24 hours or at the end of each month, and low system resource consumption. Medium-grained modes are represented by ERP departmental operational reports, such as daily production work order progress reports and purchase order execution status reports, which have a moderate level of data aggregation and present process-level key performance indicators to management, such as daily work order completion rate and expected arrival of materials in transit. The update cycle is moderate, such as every 4-8 hours or after a change in key business status, effectively balancing resource consumption and real-time business monitoring. Fine-grained data is represented by ERP business logs or transaction-level voucher details, such as sales order line item logs, real-time material voucher lists, and accounting voucher posting logs. Data aggregation is low, displaying original or near-original business transaction records, such as the materials, batches, quantities, and storage locations for each sales shipment, and the operator, time, and equipment number for each production material input. The update cycle is short, such as near real-time updates at the second or minute level. System resource consumption is high, used for precise location of abnormal transactions and end-to-end traceability. Based on nodes... The system dynamically processes node weights based on the business interaction parameters and node rationality assessment results of related businesses. Based on the dynamic processing results of node weights and node levels, it dynamically assesses the business impact. Dynamic node weight processing means dynamically adjusting the weight values of the edges connecting nodes to related business entities in the business graph structure to improve the accuracy of the business graph structure. Based on the dynamic assessment results of business impact and node dynamic stability parameters, it dynamically assesses node risks. Based on the dynamic assessment results of node risks, it performs dynamic monitoring and control processing. Dynamic monitoring and control processing means dynamically adjusting the report granularity mode and node update frequency to optimize monitoring resource allocation and enhance the ability to locate and trace abnormal nodes.
[0020] In this embodiment, the present invention provides global and dynamic technical support for ERP system business monitoring and risk management by constructing a business graph structure with ERP business entities as nodes and business interaction relationships as edges. First, dynamic evaluation of node rationality based on node basic stability parameters and associated business parameters can accurately identify invalid, redundant, or abnormal business nodes in the business graph, ensuring the effectiveness and reliability of the business graph structure from the source and laying a solid foundation for subsequent evaluation and control. Second, by combining node update resource usage with three levels of differentiated report granularity (coarse, medium, and fine), precise adaptation of node update frequency is achieved, effectively solving the pain point of resource waste and mismatch between business needs in the traditional fixed update mode of ERP reports, achieving an optimal balance between resource consumption and business monitoring requirements. Finally, dynamic processing of node weights based on associated business interaction parameters and node rationality evaluation results dynamically optimizes... The weight configuration of the nodes connecting edges in the business graph significantly improves the accuracy of the mapping of the business graph structure to the actual business interaction relationships, providing precise data support for subsequent business impact assessment. Combining the node weight processing results with the dynamic assessment of business impact at the node level, it is possible to quickly locate key business nodes and their associated radiation range, clearly define the areas that business anomalies may affect, and provide clear targets for risk prevention and control. The dynamic assessment of node risk based on the business impact assessment results and the dynamic stability parameters of nodes enables real-time perception and accurate judgment of potential risks of business nodes. The subsequent dynamic monitoring and control processing, through dynamic optimization of the report granularity mode and node update frequency, not only achieves the tilting allocation of monitoring resources to high-risk and high-value nodes, avoiding ineffective resource occupation, but also strengthens the ability to quickly locate, accurately trace, and track the entire chain of abnormal nodes, greatly improving the ERP system's response speed and handling efficiency for business anomalies. It not only transforms ERP report monitoring from a static, fixed mode to a dynamic, adaptive mode, significantly improving the flexibility, accuracy, and resource utilization efficiency of the monitoring system, but also effectively enhances enterprises' ability to predict, locate, and trace business anomalies in the ERP system through hierarchical and tiered assessment and targeted control of business impact and risks. This provides more reliable technical support for enterprise operational decisions and helps enterprises achieve refined management and proactive risk prevention.
[0021] like Figure 2The diagram shows a flowchart of the node rationality assessment process for the business anomaly monitoring method based on dynamic graph calculation provided in this application embodiment. The basic node stability parameters include the node anomaly false alarm rate, the node anomaly false alarm rate, and the number of historical node changes. The steps for dynamic node rationality assessment based on the node's basic stability parameters and related business parameters include: Step 1: Determine whether the node anomaly false alarm rate exceeds a preset false alarm rate threshold. If so, directly mark the node as an anomaly node; otherwise, proceed to Step 2. Step 2: Determine whether the node anomaly false alarm rate exceeds a preset false alarm rate threshold. If so, directly mark the node as an anomaly node; otherwise, proceed to Step 3. Step 3: Match the number of historical node changes with a preset fluctuation level mapping table to obtain the corresponding node fluctuation. The system classifies nodes into levels and obtains corresponding basic change frequency thresholds based on their fluctuation levels. The fluctuation level mapping table is a standardized mapping relationship table that stores the number of changes of each historical node, its corresponding fluctuation level, and the node change frequency threshold matched by that fluctuation level, based on the fluctuation characteristics of industry business, such as the peak fluctuation of Double Eleven in the retail industry and the monthly production fluctuation of the manufacturing industry, and the responsiveness of the ERP system, such as the server CPU utilization threshold and data processing latency threshold, as well as the results of historical anomaly case backtracking. Based on the associated business parameters of the node, the basic change frequency threshold is dynamically adjusted to obtain the adjusted change frequency threshold. It is then determined whether the change frequency of the current node is less than or equal to the adjusted change frequency threshold. If so, the node is marked as a normal node; otherwise, the node is marked as an abnormal node.
[0022] In this embodiment, the node anomaly false alarm rate and node anomaly false alarm rate are the ratios of the number of historical false alarms and the number of historical false alarms of a node to the total number of historical broadcasts of the node, respectively. The number of historical node changes is the average number of state changes of the node in each historical detection time period, obtained through statistics from the ERP system node logs. The node rationality dynamic evaluation mechanism of this invention achieves accurate, efficient, and dynamic identification of the rationality of ERP business graph nodes by constructing a full-process evaluation system that includes multi-dimensional parameter selection, tiered judgment logic, and scenario-based threshold adaptation. This improves the evaluation accuracy, scenario adaptability, and practical reliability in multiple dimensions. First, the core stability parameters are selected as node anomaly false alarm rate, false alarm rate, and historical node change frequency. This comprehensively covers the two key dimensions of node monitoring accuracy and operational stability, avoiding the assessment bias caused by the one-sidedness of parameters in traditional single-dimensional assessments, and ensuring the comprehensiveness and scientific nature of the assessment from the source. Second, a tiered judgment logic is adopted, which first uses key indicators for rapid screening and then accurately judges potential risks. Nodes that seriously affect the effectiveness of monitoring are directly marked by the false alarm rate and false alarm rate thresholds (excessive false alarm rate will lead to undetected abnormal business, and excessive false alarm rate will cause resource waste and misjudgment). Then, nodes that meet the basic stability standards are further refined for assessment. This not only enables the rapid identification and handling of seriously abnormal nodes, but also avoids the efficiency loss caused by over-assessment, significantly improving the operational efficiency of the assessment process. The fluctuation level mapping table, through deep integration of industry business fluctuation characteristics, ERP system response capabilities, and historical anomaly case backtracking results, constructs a standardized and industry-adaptable mapping relationship, solving the problem of traditional fixed thresholds. The assessment addresses the pain points of being detached from industry scenarios and the actual carrying capacity of the system, making the quantitative assessment of the number of historical node changes more targeted. Based on the business parameters associated with nodes, the basic change frequency threshold is dynamically adjusted, fully considering the interactive impact between nodes and related businesses. For example, core business nodes have high complexity and frequent interactions, and their change frequency thresholds need to be adapted to business characteristics, avoiding the rigid threshold setting problem caused by isolated node assessments. This makes the threshold standard more aligned with actual business operation scenarios. By comparing the current node change frequency with the adjusted change frequency threshold, the system achieves accurate identification of node operating status, effectively filtering out abnormal nodes with potential risks due to fluctuations exceeding reasonable ranges, while accurately identifying stable and normal nodes. This provides highly reliable assessment results for subsequent business graph structure optimization, dynamic node adjustment, and risk control, fundamentally solving problems such as missed judgments, misjudgments, and assessment lags in traditional node assessments. This ensures the effectiveness and reliability of the ERP business graph structure and lays a solid foundation for full-process business monitoring and risk management.
[0023] Furthermore, the associated business parameters include upstream business trigger frequency, downstream business processing volume, and total data interaction volume. The steps for dynamically adjusting the basic change frequency threshold based on the associated business parameters of this node include: obtaining preset associated business reference parameters and associated business proportion parameters. The associated business reference parameters include the critical values for upstream business trigger frequency, downstream business processing volume, and total data interaction volume; the associated business proportion parameters include the proportions of upstream business trigger frequency, downstream business processing volume, and total data interaction volume; performing proportion convergence calculations on the associated business parameters and associated business reference parameters (i.e., ratio calculations); then weighting the proportion convergence calculation results using the associated business proportion parameters; and finally coupling the weighted results to obtain the node's key value. The associated business activity index is a comprehensive quantitative indicator used to dynamically adjust the node's change frequency threshold. If the associated business activity index of a node exceeds the preset associated business activity threshold, the deviation between the node's associated business activity index and the associated business activity threshold is compared with the associated business activity index to obtain the associated business deviation ratio. Based on the change frequency threshold adjustment ratio obtained by matching the associated business deviation ratio with the change frequency threshold adjustment ratio mapping table, the base change frequency threshold is dynamically adjusted upward. The change frequency threshold adjustment ratio mapping table is a standardized mapping relationship table that stores the deviation ratio range of each associated business and its corresponding change frequency threshold adjustment ratio. If the associated business activity index of a node does not exceed the preset associated business activity threshold, the base change frequency threshold is maintained.
[0024] The activity index of related businesses is obtained in the following ways: ; In the formula, This indicates the activity index of related businesses. , and These represent the percentage of upstream business trigger frequency, the percentage of downstream business processing volume, and the percentage of total data interaction volume, respectively. , and These represent the upstream business trigger frequency, downstream business processing volume, and total data interaction volume, respectively. The upstream business trigger frequency is the frequency of preceding business events that trigger the business process of this node, such as the number of times a purchase request triggers the warehousing node. The downstream business processing volume is the number of subsequent business events triggered by this node, such as the number of times the warehousing node triggers inventory accounting. The total data interaction volume is the total amount of data flowing through all associated edges of this node in the business graph structure. , and These represent the critical values for upstream business trigger frequency, downstream business processing volume, and total data interaction volume, respectively.
[0025] In this embodiment, the present invention is based on a dynamic adjustment mechanism for the basic change frequency threshold of associated business parameters. By constructing a closed-loop adjustment system that covers the entire link parameters, performs standardized quantitative calculations, and dynamically adapts to different scenarios, the threshold standard is accurately matched with the actual operating status of the business, thereby improving the scientific nature of the adjustment, the adaptability of the scenario, and the support for evaluation in multiple dimensions. The algorithm selects upstream business trigger frequency, downstream business processing volume, and total data interaction volume as core parameters for related businesses, comprehensively covering key dimensions such as the interaction intensity and data flow scale between nodes and upstream and downstream businesses. This avoids the one-sidedness of traditional threshold adjustment, which relies solely on node parameters while ignoring the impact of related businesses, ensuring the comprehensiveness and relevance of the adjustment basis. Pre-set related business reference parameters and related business proportion parameters provide a standardized benchmark for the quantitative analysis of parameters across various dimensions, solving the problem of lacking a unified reference for parameters in different business scenarios and providing a unified logical foundation for subsequent calculations and adjustments. The algorithm quantifies and compares related business parameters with reference parameters through proportion convergence calculations, then uses the related business proportion parameters for weighting, and finally obtains a comprehensive related business activity index through coupling calculations. This achieves the systematic integration of multi-dimensional, dispersed parameters, transforming fragmented business interaction data into quantities that can be directly used for threshold adjustment. The standardized indicators avoid the limitations of single-parameter evaluation, significantly improving the scientific rigor and accuracy of adjustment criteria. Employing a dynamic logic of activity index threshold judgment and deviation ratio adaptation adjustment, when the activity index of a related business exceeds a preset threshold, a precise adjustment ratio is obtained by matching the deviation ratio with the adjustment ratio mapping table. This dynamically increases the basic change frequency threshold, ensuring that the change frequency threshold of active business nodes can adapt to their high-frequency interaction and high-data-volume business characteristics, avoiding abnormal omissions due to threshold rigidity. When the activity index does not reach the threshold, the basic threshold is maintained, ensuring that the evaluation criteria of stable business nodes are not excessively interfered with, effectively balancing the flexibility and stability of threshold adjustment. The standardized change frequency threshold adjustment ratio mapping table provides a unified basis for matching the deviation ratio and the adjustment ratio, avoiding subjectivity and randomness in the adjustment process, and ensuring the consistency and reliability of threshold adjustment across different nodes and scenarios. This invention achieves a shift from a fixed, static to a dynamically adaptable basic change frequency threshold by deeply integrating the parameters of the entire business chain and standardized quantitative calculation logic. It fully considers the impact of the activity level of the node's associated business on its reasonable fluctuation range, and ensures the accuracy and consistency of the adjustment through standardized processes. It effectively solves the problem of evaluation deviation caused by the disconnect between traditional fixed thresholds and the actual operating status of the business, and provides a threshold standard that is more in line with the business scenario for the dynamic evaluation of node rationality. It further improves the accuracy and reliability of node anomaly identification, and lays a solid foundation for subsequent business graph structure optimization, risk assessment and monitoring and control.
[0026] Furthermore, based on the dynamic evaluation results of node rationality, the steps for dynamically adjusting nodes based on node update resource usage and report granularity mode include: if the node is a normal node, determine whether the node update resource usage rate exceeds a preset usage rate threshold; otherwise, no additional processing is performed. If it does, the difference between the node update resource usage rate and the preset usage rate threshold is then compared with the threshold to obtain the resource usage excess ratio. This excess ratio is then matched with a preset update frequency reduction ratio mapping table. Based on the matched update frequency reduction ratio, the node update frequency is dynamically adjusted to obtain the adjusted node update frequency. The update frequency reduction ratio mapping table stores the range of resource usage excess ratios and their corresponding update frequency reduction ratios. The system uses a standardized mapping table. The occupancy threshold is set based on the capacity of system resources (such as CPU and memory), and the mapping table can be adjusted according to resource usage. If a node is an abnormal node, the report granularity mode is matched with a preset granularity update frequency mapping table to obtain the corresponding basic update frequency. The granularity update frequency mapping table is a standardized mapping table that stores the relationship between each report granularity mode and its corresponding basic update frequency. The node fluctuation level is matched with a preset level adjustment coefficient mapping table to obtain the update frequency adjustment coefficient. The level adjustment coefficient mapping table is a standardized mapping table that stores the relationship between each node fluctuation level and its corresponding level adjustment coefficient. The level adjustment coefficient is used to multiply the basic update frequency to obtain the adjusted node update frequency.
[0027] In this embodiment, the node dynamic adjustment mechanism of the present invention, based on node rationality assessment results, node update resource occupancy, and report granularity mode, achieves optimal matching between node update frequency and business needs and system resources by constructing a closed-loop adjustment system with state-based precise control, multi-dimensional parameter adaptation, and standardized dynamic adaptation. This results in multi-dimensional synergistic efficiency improvements in resource utilization, enhanced anomaly monitoring, and improved scenario adaptability. For normal nodes, adjustment logic is designed to judge resource occupancy thresholds, quantify the proportion of exceeding limits, and dynamically adjust accordingly. By comparing the node update resource occupancy rate with a preset occupancy rate threshold set based on system resource capacity such as CPU and memory, targeted adjustments are made only to normal nodes with excessive resource occupancy. This avoids ineffective intervention in normal nodes with reasonable resource occupancy, ensuring the stability of their original business monitoring rhythm. Furthermore, through standardized matching of the resource occupancy excess ratio and update frequency reduction ratio mapping table, precise reduction of the update frequency is achieved. The mapping table supports dynamic adjustment based on real-time system resource usage. This ensures that the reduction ratio effectively lowers the resource consumption of nodes exceeding the limit without excessively reducing it and affecting the effectiveness of business monitoring. It fundamentally solves the pain point of wasted or insufficient resource usage by normal nodes under the traditional fixed update frequency mode, significantly improving the overall utilization rate of system resources. For abnormal nodes, a two-dimensional adjustment logic of matching the basic frequency with the report granularity and correcting the fluctuation level coefficient is adopted. First, the coarse, medium, and fine report granularity modes are accurately associated with their corresponding basic update frequencies through a granularity update frequency mapping table. This ensures that the monitoring frequency of abnormal nodes matches the business positioning of their respective report granularity. For example, the fine granularity mode corresponds to... High-frequency updates support anomaly tracing, while a coarse-grained mode corresponds to a reasonable frequency to balance resources. A level adjustment coefficient mapping table matches node fluctuation levels with corresponding adjustment coefficients. These coefficients are then multiplied by the base update frequency, achieving precise adaptation between the update frequency of abnormal nodes and their own fluctuation risks. Abnormal nodes with higher fluctuation levels have larger adjustment coefficients and higher update frequencies, enabling more intensive capture of node state changes. Abnormal nodes with lower fluctuation levels maintain a relatively reasonable update frequency, avoiding excessive resource skew. This effectively solves the problem of traditional abnormal node monitoring having a single frequency and being unable to adapt to different fluctuation risks, significantly improving the monitoring sensitivity and response speed of abnormal nodes. This invention constructs unified and reusable adjustment rules through a standardized mapping table. This avoids subjectivity and randomness in the adjustment process, ensuring consistency and reliability of adjustment logic across different nodes and scenarios. Furthermore, the flexible adjustment characteristics of the mapping table, such as resource occupancy thresholds set based on system resource capacity and the ability to adapt the mapping table according to resource usage, enable the adjustment mechanism to adapt to differences in resource configuration and business scenarios across different ERP systems, such as retail industry peaks and manufacturing production fluctuations. This demonstrates strong scenario adaptability and scalability.By optimizing and adjusting resources for normal nodes and precisely enhancing monitoring of abnormal nodes, the system resources were rationally allocated among nodes in different states. Saved resources were directed towards abnormal nodes, ensuring both the continuity and stability of normal business monitoring and strengthening the full-cycle tracking and data collection of abnormal nodes. This provided sufficient and accurate data support for subsequent business impact assessments, risk assessments, and monitoring and control, ultimately achieving the triple goals of optimal resource consumption, effective business monitoring, and timely anomaly response. This significantly improved the operational efficiency of the ERP business graph structure and the overall reliability of the monitoring system.
[0028] Furthermore, the business interaction parameters include interaction frequency, interaction time, and rule matching degree. The steps for dynamically processing node weights based on the business interaction parameters of each associated business of the node and the dynamic evaluation results of node rationality include: matching the dynamic evaluation results of node rationality with the weight correction coefficient mapping table to obtain the corresponding weight correction coefficient. The weight correction coefficient mapping table is a standardized mapping relationship table storing different node states and their corresponding weight correction coefficients; obtaining preset business interaction reference parameters and business interaction proportion parameters. The business interaction reference parameters include the interaction frequency threshold, the interaction time threshold, and the rule matching degree threshold. The business interaction proportion parameters include the interaction frequency proportion, the interaction time proportion, and the rule matching degree proportion; performing proportion convergence calculations on the business interaction parameters of each associated business of the node with the corresponding business interaction reference parameters, then weighting the proportion convergence calculation results using the business interaction proportion parameters, and then coupling the weighting results to obtain the basic weight values of each associated business of the node; and correcting the corresponding basic weight values using the weight correction coefficients of each associated business of the node to obtain the final weight values of each associated edge of the node.
[0029] The basic weight values for each associated business of a node are obtained as follows: ; In the formula, This represents the basic weight value of the i-th associated business of the node. , and These represent the percentage of interaction frequency, the percentage of interaction time, and the percentage of rule matching degree, respectively. , and These represent the interaction frequency, interaction time, and rule matching degree of the i-th associated business of a node, respectively. Interaction frequency refers to the total number of business interaction events between the node and its associated business entities within a preset time window, obtained through ERP log statistics. Interaction time refers to the average time required to complete a single business interaction, obtained by averaging the differences between the start and end timestamps of the interaction event. Rule matching degree refers to the degree of conformity between the current business interaction and predefined standardized business process rules; its value is calculated by the rule engine matching the interaction data with the business rule base, quantified using a similarity algorithm (such as cosine similarity). , and These represent the critical values for interaction frequency, interaction time, and rule matching degree, respectively, where i is the ID of each associated business, i=1,2,3,...,N, and N is the total number of associated businesses.
[0030] In this embodiment, the node weight dynamic processing mechanism of the present invention realizes the dynamic adaptation and precise calibration of the weight of the associated edges of nodes in the business graph structure by constructing a full-process optimization system of business interaction feature quantification, precise correction of node state and standardized weight generation. Its core technical effect is reflected in the multi-dimensional improvement of the scientific nature of weight assignment, scenario adaptability and business mapping accuracy. Interaction frequency, interaction time, and rule matching degree are selected as core business interaction parameters, comprehensively covering three key dimensions: the density, efficiency, and compliance adaptability of interactions between nodes and related businesses. This avoids the one-sidedness of traditional fixed weights that rely solely on a single interaction indicator, ensuring the comprehensiveness and relevance of weight evaluation from the source, and enabling weights to truly reflect the core characteristics of business interactions. By standardizing the matching of dynamic evaluation results of node rationality with a weight correction coefficient mapping table, and introducing a weight correction coefficient corresponding to the node's own state, the limitation of traditional weight assignment ignoring the node's own operating state is broken. For example, the weight of related businesses of abnormal nodes needs to be specifically corrected based on their rationality evaluation results, avoiding distortion of related edge weights due to node abnormalities. This ensures that weight assignment considers both business interaction characteristics and node stability, significantly improving the scenario adaptability and accuracy of weights. Pre-set business interaction reference parameters and business interaction proportion parameters provide a unified standardized benchmark for the quantitative analysis of business interaction parameters in various dimensions, solving the problem of a lack of unified reference standards for interaction parameters in different business scenarios. This approach ensures the standardization of the proportion convergence calculation. Simultaneously, it achieves a quantitative comparison between business interaction parameters and reference parameters through proportion convergence calculation, then uses the business interaction proportion parameters for weighting, and finally integrates them through coupling calculation to obtain the basic weight values of each related business. This transforms fragmented interaction data into a systematic and quantifiable weight indicator, avoiding the limitations of single-parameter weighting and enabling the basic weights to comprehensively reflect the importance of each interaction dimension. By using weight correction coefficients to specifically correct the basic weight values, it achieves deep integration of basic weights with the node's own operating state. The generated final weight values accurately match the actual characteristics of business interactions and adapt to the reasonable state of the nodes, effectively solving the pain point that traditional fixed weights cannot dynamically respond to changes in business interactions and fluctuations in node states. This significantly improves the accuracy of the business graph structure in mapping actual business relationships, providing highly reliable core data support for subsequent weight-based dynamic assessment of business impact, further strengthening the decision-making value of the business graph in business monitoring and risk assessment, and ensuring the accuracy and reliability of subsequent business impact assessment and risk judgment results.
[0031] Furthermore, the steps for dynamically assessing business impact based on the dynamic processing results of node weights and node levels include: summing the final weight values of each associated edge of a node to obtain a comprehensive node weight index; matching the node level with a preset business impact coefficient mapping table to obtain the corresponding business impact coefficient, wherein the business impact coefficient mapping table is a standardized mapping relationship table storing different node levels and their corresponding business impact coefficients; and multiplying the comprehensive node weight index using the business impact coefficient to obtain a comprehensive business impact index.
[0032] In this embodiment, the present invention, based on the dynamic processing results of node weights and the dynamic business impact assessment mechanism of node levels, achieves accurate and objective quantification of the scope and degree of influence of business nodes by constructing a standardized assessment system that quantifies association strength, adapts node value, and generates comprehensive indicators. Its core technical effect is reflected in the multi-dimensional improvement of the comprehensiveness, accuracy, and decision support of the assessment. By statistically analyzing the final weight values of each associated edge of a node and summing them, a comprehensive node weight index is obtained. This fully integrates edge weight data that reflects the true characteristics of business interactions after dynamic correction. This final weight has been optimized by combining core interaction parameters such as business interaction frequency, time consumption, and rule matching degree with the node's rationality assessment results. It can accurately map the closeness, importance, and compliance adaptability of interactions between nodes and associated businesses, making the comprehensive node weight index the core quantitative basis for measuring the association radiation strength of nodes in the business graph, avoiding the misjudgment of association strength caused by traditional assessments relying solely on a single interaction dimension. Secondly, by linking node levels with a preset business impact system... The data mapping table is used for standardized matching, introducing the hierarchical value attributes of the nodes themselves, such as the business impact coefficients corresponding to different levels of core business nodes, supporting business nodes, and auxiliary business nodes. This breaks the limitation of measuring business impact solely by interaction intensity, and fully considers the inherent importance of nodes in the enterprise ERP business system. For example, core business nodes such as sales order management nodes and core inventory nodes have higher levels and corresponding higher business impact coefficients. Their business impact under the same interaction intensity is significantly higher than that of auxiliary business nodes. This ensures that the evaluation results can take into account both the correlation strength and inherent value of nodes, and solves the problem of traditional evaluations that emphasize interaction while neglecting hierarchy. This addresses the pain point of underestimating the influence of core nodes or overestimating the influence of non-core nodes. By generating a comprehensive business influence index through the product of the business influence coefficient and the node's comprehensive weight index, a deep integration and quantitative coupling of the intensity of related radiation and the value of node hierarchy are achieved. This comprehensive index can fully and accurately reflect the actual impact of nodes on the overall business system, reflecting both the scope of influence transmitted by nodes through related businesses and highlighting the influence weight corresponding to the node's own hierarchy, avoiding the one-sidedness of single-dimensional evaluation. Simultaneously, the standardized business influence coefficient mapping table provides a unified and reusable benchmark for the influence coefficients of nodes at different levels, ensuring that different business... The consistency and objectivity of the assessment logic across different business scenarios and node types avoid assessment biases caused by subjective experience judgments, thereby improving the reliability and comparability of assessment results. The comprehensive business impact index provides a highly accurate quantitative basis for subsequent dynamic risk assessment and monitoring and control of nodes. It helps the system quickly locate high-impact nodes, clarify the core scope and key links that may be affected when business anomalies occur, and provide a clear decision-making guide for subsequent resource allocation and precise handling of anomalies. This significantly improves the targeting and efficiency of business risk prevention and control in the ERP system, and further strengthens the scientific nature and practicality of the entire business monitoring and risk management system.
[0033] Furthermore, the node dynamic stability parameters include the volatility of associated edge weights, node stability, and historical anomaly frequency. The steps for dynamic node risk assessment based on the business impact dynamic assessment results and node dynamic stability parameters include: obtaining preset node dynamic stability reference parameters and node dynamic stability proportion parameters. The node dynamic stability reference parameters include the critical values of associated edge weight volatility, node stability, and historical anomaly frequency; the node dynamic stability proportion parameters include the proportion of associated edge weight volatility, the proportion of node stability, and the proportion of historical anomaly frequency; performing proportion convergence calculations on the associated edge weight volatility, node stability, and historical anomaly frequency with their respective critical values; then weighting the proportion convergence calculation results using the node dynamic stability proportion parameters; and finally coupling the weighted results to obtain the node anomaly risk index, which is a quantifiable indicator used to dynamically assess the current comprehensive risk level of a node; and finally, performing dynamic node risk assessment based on the business impact dynamic assessment results and the node anomaly risk index.
[0034] The node anomaly risk index is obtained as follows: ; In the formula, This represents the node anomaly risk index. , and These represent the proportions of associated edge weight volatility, node stability, and historical anomaly frequency, respectively. , and These represent the volatility of associated edge weights, node stability, and historical anomaly frequency, respectively. The volatility of associated edge weights refers to the rate of change of the weight values between the node and other associated nodes, obtained by real-time monitoring of weight values and comparison with weight thresholds. Node stability is a comprehensive metric indicating the health of a node's key performance indicators such as CPU, memory, and load within a specific time window, calculated through a performance monitoring system using weighted averages. Historical anomaly frequency refers to the number of times the node is in an abnormal state within a preset historical period, obtained through statistical analysis of historical alarms and log records. , and These represent the critical values for the volatility of associated edge weights, node stability, and historical anomaly frequency, respectively.
[0035] In this embodiment, the present invention achieves accurate, comprehensive, and dynamic quantification of the risk level of ERP business graph nodes based on the dynamic assessment results of business impact and the dynamic stability parameters of nodes. This significantly improves the completeness of the assessment dimensions, the accuracy of the quantification results, the scientific nature of the judgment logic, and the effectiveness of decision support. This study selects the volatility of associated edge weights, node stability, and historical anomaly frequency as core node dynamic stability parameters. This comprehensively covers three key dimensions: the volatility characteristics of node relationships, the node's own operational stability, and historical risk accumulation. These three parameters form a complementary and synergistic evaluation matrix. The volatility of associated edge weights reflects the dynamic changes in business interaction relationships; node stability reflects the reliability of the node's own operation; and historical anomaly frequency provides historical data support for risk assessment. This effectively avoids the risk omissions or misjudgments caused by single parameters in traditional risk assessments, ensuring the comprehensiveness and systematic nature of the assessment from the source. Pre-set node dynamic stability reference parameters and node dynamic stability percentage parameters provide a unified standardized benchmark for the quantitative analysis of each stability dimension. This solves the problem of a lack of unified evaluation standards for stability parameters under different business scenarios and node types, ensuring the standardization and consistency of subsequent calculation processes and avoiding evaluation bias caused by subjective experience. Through percentage convergence calculation, each dynamic stability parameter is quantitatively compared with its corresponding critical value, accurately reflecting the degree to which each parameter deviates from the reasonable range. The node dynamic stability percentage parameter is then used to weight the calculation results. Finally, through coupled calculations, the node anomaly risk index is obtained, transforming fragmented... The stability data is transformed into directly quantifiable risk indicators, achieving both differentiated emphasis on various stability dimensions and comprehensive quantification of risk levels. This shifts risk assessment from qualitative description to quantitative analysis, significantly improving the accuracy and objectivity of the assessment results. By combining dynamic business impact assessment results with node anomaly risk indices for collaborative analysis, the current comprehensive risk level of a node is considered, along with the scope and extent of its impact on the overall business system. This effectively addresses the one-sidedness of traditional risk assessments, which often prioritize risk severity over impact scope or vice versa. For example, a node with high risk but low impact may be treated differently from a node with high risk. High-risk and high-impact nodes can be accurately identified, providing a clear basis for subsequent differentiated monitoring and control. The quantitative risk assessment results generated by this invention provide highly reliable decision support for subsequent dynamic monitoring and control, helping the system quickly locate high-risk and high-impact key nodes, clarify the key targets and priorities for risk prevention and control, and make subsequent adjustments to the granularity mode of reports and the frequency of node updates more targeted. This avoids the ineffective allocation of monitoring resources and strengthens the prevention and control of high-priority risk nodes, significantly improving the scientific nature and efficiency of risk prevention and control in the ERP system, and providing a strong guarantee for the stable operation of enterprise business.
[0036] Furthermore, the steps for dynamic node risk assessment based on the dynamic assessment results of business impact and the node anomaly risk index include: matching the comprehensive business impact index with a preset business impact ratio mapping table to obtain the corresponding business impact ratio. The business impact ratio mapping table is a standardized mapping relationship table storing the range of each comprehensive business impact index and its corresponding business impact ratio; using the complement of the business impact ratio and 1 as the node anomaly ratio; determining whether the comprehensive business impact index exceeds the preset business impact critical index. If so, no additional processing is performed; otherwise, the comprehensive business impact index is multiplied based on a preset attenuation coefficient (e.g., 0.5) to reduce its impact; obtaining the preset node anomaly critical index; performing ratio calculations between the comprehensive business impact index and the node anomaly risk index and the business impact critical index and the node anomaly critical index, respectively; and then performing weighted coupling processing using the comparison results of the business impact ratio and the node anomaly ratio to obtain the node comprehensive risk index. The node comprehensive risk index is used to quantify the overall risk level of the node to support the formulation of subsequent differentiated handling strategies.
[0037] In this embodiment, the node risk dynamic assessment of the present invention achieves scientific quantification and accurate judgment of the overall risk level of nodes by constructing a refined assessment system with dynamic weight adaptation, precise impact calibration, and standardized quantitative coupling, thereby improving the comprehensiveness, accuracy, and differentiated handling support capabilities of risk assessment in multiple dimensions. The business impact ratio is obtained through standardized matching with a pre-defined business impact ratio mapping table. The complement of this ratio and 1 is used as the node anomaly ratio, constructing a complementary weight system for the two core assessment dimensions: business impact and anomaly risk. This avoids assessment bias caused by the rigidity of a single-dimensional weight and ensures a reasonable weight allocation between the two in comprehensive risk assessment, making the assessment logic more aligned with the dual risk perception logic of risk level and impact scope. By determining whether the business impact ratio exceeds a pre-defined threshold, indicators that do not exceed the threshold are multiplied using a pre-defined attenuation coefficient. This effectively avoids the problem of overestimating the risk level of nodes with low business impact. For example, even if a non-core business node has some anomaly risk, its impact on the overall business is limited. By reducing its business impact weight through the attenuation coefficient, the risk assessment results are matched with the actual business value of the node, significantly improving the scenario adaptability and accuracy of the assessment. By calculating the ratios of the business impact ratio and the node anomaly risk index with their corresponding threshold indicators, the two indicators are transformed into relative quantitative values of a unified dimension. Then, the business impact ratio and the node anomaly ratio are used to calculate the relative quantitative values of the nodes. By employing weighted coupling processing, a systematic integration of indicators across different dimensions is achieved. This process retains the core information of each indicator while ensuring the objectivity and consistency of the assessment process through standardized calculation rules, avoiding biases caused by subjective experience. The standardized business impact ratio mapping table and critical indicator settings provide a unified assessment benchmark for nodes of different types and levels, ensuring the comparability and reliability of assessment results. This addresses the pain points of inconsistent standards and difficulty in horizontal comparison of results in traditional risk assessments. The generated node comprehensive risk index can accurately quantify the overall risk level of nodes, clearly distinguishing nodes of different risk types and providing a clear quantitative basis for the formulation of subsequent differentiated handling strategies. For example, nodes with high comprehensive risk indices can have their monitoring resources prioritized, update frequency increased, and report granularity improved, while nodes with low comprehensive risk indices can have their monitoring intensity appropriately reduced to save resources. This effectively solves the problem of resource waste or omission of key risks caused by the one-size-fits-all approach of traditional risk assessments, significantly improving the targeting and resource utilization efficiency of risk management. This provides core technical support for ERP systems to achieve refined and dynamic risk prevention and control.
[0038] Furthermore, the steps for monitoring and dynamic control based on the node risk dynamic assessment results include: comparing the node comprehensive risk index with preset first and second thresholds for node comprehensive risk; if the node comprehensive risk index is less than or equal to the first threshold, no additional processing is performed; if the node comprehensive risk index is greater than the first threshold but less than or equal to the second threshold, the difference between the second threshold and the node comprehensive risk index is marked as the node risk deviation index. The node risk deviation index is then matched with a preset risk level mapping table to obtain the corresponding risk level. Based on the risk level, the reporting granularity mode and node update frequency of the node are directly adjusted to match the control strategy corresponding to the risk level. The risk level mapping table is a standardized mapping table that stores the risk deviation index range of each node and its corresponding risk level. Each risk level is associated with a predefined report granularity mode and node update frequency. If the node's comprehensive risk index is greater than the second threshold of the node's comprehensive risk, the report granularity and node update frequency are adjusted to the highest granularity mode and the maximum update frequency, respectively. For core nodes, i.e., nodes whose node level exceeds the critical level, risk warnings and interaction rate limiting are implemented. Risk warnings include system pop-ups, email notifications, SMS alarms, etc., and pre-set maintenance personnel are notified to handle the situation. Interaction rate limiting only allows core business interaction requests to pass through, and non-core business interaction requests are placed in a queue. For non-core nodes, i.e., nodes whose node level does not exceed the critical level, non-critical business is suspended, and a detailed diagnostic process is triggered.
[0039] In this embodiment, the present invention utilizes a dynamic monitoring and control mechanism based on the dynamic assessment results of node risks. This mechanism achieves optimal allocation of monitoring resources, rapid and accurate risk management, and multiple guarantees for business continuity. Its core technical effectiveness is reflected in the synergistic improvement of control accuracy, resource utilization efficiency, risk prevention capabilities, and business stability. By comparing the node's comprehensive risk index with preset first and second thresholds in a gradient manner, a tiered response logic is constructed: no intervention for low-risk nodes, tiered control for medium-risk nodes, and enhanced handling for high-risk nodes. This avoids the resource waste or delayed handling of high-risk nodes caused by the one-size-fits-all approach of traditional monitoring and control. Low-risk nodes maintain their original configuration, reducing interference from ineffective interventions on business operations. Medium-risk nodes match their risk level through a risk deviation index and precisely adjust the report granularity mode and node update frequency according to a predefined control strategy, ensuring precise matching between monitoring intensity and risk level. This guarantees the effectiveness of risk monitoring while avoiding excessive resource investment. High-risk nodes directly utilize the highest granularity report and maximum update frequency, enabling precise anomaly location, full-link tracing, and real-time tracking through fine-grained data collection and high-frequency updates, significantly improving the risk handling response speed of high-risk nodes. Based on a differentiated handling strategy that distinguishes between core and non-core nodes according to node level, this approach further enhances the targeted nature of business continuity assurance and risk management. For core nodes exceeding the critical level, risk warnings are issued through multiple channels such as system pop-ups, email notifications, and SMS alerts to ensure immediate response from maintenance personnel. Simultaneously, an interactive rate limiting mechanism prioritizes core business interaction requests while queuing non-core requests, effectively preventing business interruptions due to core node overload and minimizing core business losses. For non-core nodes, non-critical business operations are suspended, and a detailed diagnostic process is triggered. This quickly identifies the root cause of risks while preventing the spread of risks to non-core businesses without affecting the normal operation of core businesses, achieving a balance between precise risk management and minimal business disruption. The entire control mechanism, through a standardized risk level mapping table, predefined control strategies, and node level classification standards, ensures the standardization and consistency of the control process, avoiding handling deviations caused by subjective decisions. Furthermore, the tiered risk thresholds and differentiated handling methods allow monitoring resources to be precisely allocated to medium- and high-risk nodes and core nodes, solving the pain points of uneven allocation and lack of focus in traditional monitoring resources and achieving optimal utilization efficiency of monitoring resources. This invention not only achieves dynamic adaptation across the entire process from risk identification to handling, significantly improving the ability to locate, trace, and handle abnormal nodes, but also minimizes the impact of risks on the overall business system by prioritizing core business protection and accurately investigating non-core business. It constructs a monitoring and protection system that makes risks preventable, controllable, and quickly manageable, providing strong technical support for the stable operation of the ERP system and the continuous development of enterprise business.
[0040] like Figure 3The diagram shown is a structural schematic of a business anomaly monitoring system based on dynamic graph computation provided in this application embodiment. It includes: a node dynamic adjustment module, a business impact assessment module, and a monitoring dynamic control module. The node dynamic adjustment module generates a business graph structure based on real-time business interaction data and business association attributes from ERP reports. It then performs dynamic evaluation of node rationality based on basic node stability parameters and associated business parameters. Based on the node rationality evaluation results, it performs dynamic node adjustment according to node update resource usage and report granularity mode. In the business graph structure, nodes represent business entities, and edges represent the interaction relationships between business entities. Node dynamic adjustment means dynamically adjusting the node update frequency in the business graph structure to maintain an optimal balance between resource consumption and business needs. The system comprises two modules: a balance module and a business impact assessment module. The business impact assessment module dynamically processes node weights based on the business interaction parameters of each associated business and the dynamic evaluation results of node rationality. It then performs dynamic business impact assessment based on the node weight dynamic processing results and node level. Dynamic node weight processing means dynamically adjusting the weight values of the edges connecting nodes to their associated business entities in the business graph structure to improve the accuracy of the business graph structure. The monitoring dynamic control module performs dynamic node risk assessment based on the business impact dynamic evaluation results and node dynamic stability parameters. It then performs dynamic monitoring control processing based on the node risk dynamic evaluation results. Dynamic monitoring control processing means dynamically adjusting the report granularity mode and node update frequency to optimize monitoring resource allocation and enhance the ability to locate and trace abnormal nodes.
[0041] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)). Where there is no conflict, the solutions in the above embodiments can be combined.
[0042] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0043] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0044] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0045] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0046] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope and intent of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and variations.
Claims
1. A method for business exception monitoring based on dynamic graph computation, characterized in that, Includes the following steps: Based on real-time business interaction data and business association attributes from ERP reports, a business graph structure is generated. The rationality of nodes is dynamically evaluated based on basic stability parameters and associated business parameters. Based on the results of the dynamic evaluation of node rationality, dynamic adjustment of nodes is performed based on node update resource usage and report granularity mode. In the business graph structure, nodes are business entities, edges are the interaction relationships between business entities, and the dynamic adjustment of nodes means dynamically adjusting the update frequency of nodes in the business graph structure to maintain the optimal balance between resource consumption and business needs. Dynamic processing of node weights is performed based on the business interaction parameters of each associated business of the node and the dynamic evaluation results of node rationality. Dynamic evaluation of business impact is performed based on the dynamic processing results of node weights and node level. The dynamic processing of node weights means dynamically adjusting the weight values of the connection edges between the node and each associated business entity in the business graph structure to improve the accuracy of the business graph structure. The business interaction parameters include interaction frequency, interaction time, and rule matching degree. The steps for dynamically processing node weights based on the business interaction parameters of each associated business and the dynamic evaluation results of node rationality include: The dynamic evaluation results of node rationality are matched with the weight correction coefficient mapping table to obtain the corresponding weight correction coefficient. The weight correction coefficient mapping table is a standardized mapping relationship table that stores different node states and their corresponding weight correction coefficients. Obtain preset business interaction reference parameters and business interaction ratio parameters. The business interaction reference parameters include interaction frequency threshold, interaction time threshold, and rule matching degree threshold. The business interaction ratio parameters include interaction frequency ratio, interaction time ratio, and rule matching degree ratio. The business interaction parameters of each associated business of the node are respectively compared with the corresponding business interaction reference parameters to calculate the proportion of closeness. Then, the proportion of closeness calculation results are weighted using the business interaction proportion parameters. Finally, the weighted results are coupled to obtain the basic weight values of each associated business of the node. The basic weight values of each associated edge of a node are adjusted by using the weight adjustment coefficients of each associated business of the node, so as to obtain the final weight values of each associated edge of the node. Dynamic risk assessment of nodes is performed based on the dynamic assessment results of business impact and the dynamic stability parameters of nodes. Based on the dynamic risk assessment results of nodes, dynamic monitoring and control processing is carried out. The dynamic monitoring and control processing refers to dynamically adjusting the report granularity mode and node update frequency to optimize the allocation of monitoring resources and enhance the ability to locate and trace abnormal nodes.
2. The method of claim 1, wherein the method further comprises: The basic stability parameters of the nodes include the node anomaly false alarm rate, the node anomaly false alarm rate, and the number of historical node changes. The steps for dynamically evaluating the rationality of nodes based on their basic stability parameters and associated business parameters include: Step 1: Determine whether the node's false negative rate exceeds the preset false negative rate threshold. If so, mark the node as an abnormal node; otherwise, proceed to Step 2. Step 2: Determine whether the false alarm rate of a node exceeds the preset false alarm rate threshold. If so, mark the node as an abnormal node directly; otherwise, proceed directly to Step 3. Step 3: Match the number of changes of historical nodes with the preset fluctuation level mapping table to obtain the corresponding node fluctuation level, and obtain the corresponding basic change frequency threshold based on the node fluctuation level. The fluctuation level mapping table is a standardized mapping relationship table that stores the number of changes of each historical node, its corresponding fluctuation level, and the node change frequency threshold matched by the fluctuation level. Based on the associated business parameters of the node, the basic change frequency threshold is dynamically adjusted to obtain the adjusted change frequency threshold. It is then determined whether the change frequency of the current node is less than or equal to the adjusted change frequency threshold. If so, the node is marked as a normal node; otherwise, the node is marked as an abnormal node.
3. The method of claim 2, wherein the method further comprises: The associated business parameters include upstream business trigger frequency, downstream business processing volume, and total data interaction volume. The steps for dynamically adjusting the basic change frequency threshold based on the associated service parameters of the node include: Obtain preset related business reference parameters and related business proportion parameters. The related business reference parameters include the upstream business trigger frequency threshold, the downstream business processing volume threshold, and the total data interaction volume threshold. The related business proportion parameters include the upstream business trigger frequency proportion, the downstream business processing volume proportion, and the total data interaction volume proportion. The related business parameters are respectively compared with the related business reference parameters to calculate the proportion convergence. Then, the proportion parameters of the related business are used to assign weights to the proportion convergence calculation results. Finally, the weighted results are coupled to obtain the related business activity index of the node. The related business activity index is a comprehensive quantitative indicator used to dynamically adjust the node change frequency threshold. If the activity index of the associated business of the node exceeds the preset activity threshold of the associated business, then the deviation value of the activity index of the associated business of the node from the activity threshold of the associated business is compared with the activity index of the associated business to obtain the deviation ratio of the associated business. Based on the deviation ratio of the associated business and the change frequency threshold adjustment ratio mapping table, the change frequency threshold is dynamically adjusted upward. The change frequency threshold adjustment ratio mapping table is a standardized mapping relationship table that stores the deviation ratio range of each associated business and its corresponding change frequency threshold adjustment ratio. If the activity index of the associated business of the node does not exceed the preset activity threshold of the associated business, the basic change frequency threshold will be maintained.
4. The business anomaly monitoring method based on dynamic graph calculation as described in claim 3, characterized in that: The steps of dynamically adjusting nodes based on the node rationality assessment results, updating node resource usage, and report granularity mode include: If the node is a normal node, determine whether the node's update resource utilization rate exceeds the preset utilization rate threshold; otherwise, no additional processing is performed. If so, the difference between the node update resource occupancy rate and the preset occupancy rate threshold is then compared with the occupancy rate threshold to obtain the resource occupancy over-limit ratio. The resource occupancy over-limit ratio is matched with the preset update frequency reduction ratio mapping table. Based on the matched update frequency reduction ratio, the node update frequency is dynamically adjusted to obtain the adjusted node update frequency. The update frequency reduction ratio mapping table is a standardized mapping relationship table that stores each resource occupancy over-limit ratio range and its corresponding update frequency reduction ratio. If a node is an abnormal node, the report granularity mode is matched with the preset granularity update frequency mapping table to obtain the corresponding basic update frequency. The granularity update frequency mapping table is a standardized mapping relationship table that stores each report granularity mode and its corresponding basic update frequency. The node fluctuation level is matched with the preset level adjustment coefficient mapping table to obtain the update frequency adjustment coefficient. The level adjustment coefficient mapping table is a standardized mapping relationship table that stores the fluctuation level of each node and its corresponding level adjustment coefficient. The basic update frequency is processed using a level adjustment coefficient to obtain the adjusted node update frequency.
5. The business anomaly monitoring method based on dynamic graph calculation as described in claim 1, characterized in that: The steps for dynamically assessing the business impact based on the dynamic processing results of node weights and node levels include: The final weight values of each associated edge of the node are counted to obtain the node's comprehensive weight index; The node level is matched with a preset business impact coefficient mapping table to obtain the corresponding business impact coefficient. The business impact coefficient mapping table is a standardized mapping relationship table that stores different node levels and their corresponding business impact coefficients. The business impact coefficient is used to process the node comprehensive weight index to obtain the comprehensive business impact index.
6. The business anomaly monitoring method based on dynamic graph calculation as described in claim 5, characterized in that: The node dynamic stability parameters include the volatility of associated edge weights, node stability, and historical anomaly frequency. The steps for dynamically assessing node risk based on the dynamic assessment results of business impact and node dynamic stability parameters include: Obtain preset node dynamic stability reference parameters and node dynamic stability percentage parameters. The node dynamic stability reference parameters include critical values for the volatility of associated edge weights, critical values for node stability, and critical values for historical anomaly frequencies. The node dynamic stability percentage parameters include the percentage of the volatility of associated edge weights, the percentage of node stability, and the percentage of historical anomaly frequencies. The correlation edge weight volatility, node stability threshold, and historical anomaly frequency are respectively compared with the correlation edge weight volatility threshold, node stability threshold, and historical anomaly frequency threshold to calculate the proportion convergence. The proportion convergence calculation results are then weighted using the node dynamic stability proportion parameter. Finally, the weighted results are coupled to obtain the node anomaly risk index, which is a quantifiable indicator used to dynamically assess the current comprehensive risk level of a node. Dynamic assessment of node risk is conducted based on the results of dynamic assessment of business impact and node anomaly risk index.
7. The business anomaly monitoring method based on dynamic graph calculation as described in claim 6, characterized in that: The steps for dynamically assessing node risk based on the results of dynamic assessment of business impact and node anomaly risk index include: The comprehensive business impact index is matched with the preset business impact percentage mapping table to obtain the corresponding business impact percentage. The business impact percentage mapping table is a standardized mapping relationship table that stores the range of each comprehensive business impact index and its corresponding business impact percentage. The percentage of business impact plus the complement of 1 is used as the percentage of node anomalies; Determine whether the comprehensive business impact index exceeds the preset business impact threshold index. If so, no additional processing is performed; otherwise, the comprehensive business impact index is multiplied based on the preset attenuation coefficient. Obtain preset critical indicators for node anomalies; The comprehensive business impact index and the node anomaly risk index are respectively compared with the critical business impact index and the critical node anomaly index. Then, the results of the comparison between the business impact ratio and the node anomaly ratio are weighted and coupled to obtain the comprehensive node risk index. The comprehensive node risk index is used to quantify the overall risk level of the node to support the formulation of subsequent differentiated handling strategies.
8. The business anomaly monitoring method based on dynamic graph calculation as described in claim 7, characterized in that: The steps for monitoring and dynamic control based on the dynamic assessment results of node risks include: The node comprehensive risk index is compared with the preset first threshold and second threshold of node comprehensive risk, respectively. If the node's comprehensive risk index is less than or equal to the first threshold of the node's comprehensive risk, no additional processing will be performed. If the node's comprehensive risk index is greater than the first threshold of the node's comprehensive risk, but less than or equal to the second threshold of the node's comprehensive risk, then the difference between the second threshold of the node's comprehensive risk and the node's comprehensive risk index is marked as the node's risk deviation index. The node's risk deviation index is matched with a preset risk level mapping table to obtain the corresponding risk level. Based on the risk level, the node's report granularity mode and node update frequency are directly adjusted to match the control strategy corresponding to the risk level. The risk level mapping table is a standardized mapping relationship table that stores the range of each node's risk deviation index and its corresponding risk level. If the node comprehensive risk index is greater than the second threshold of node comprehensive risk, adjust the report granularity and node update frequency to the highest granularity mode and the maximum update frequency, respectively. For core nodes, implement risk warnings and interactive rate limiting; For non-core nodes, suspend non-critical services and trigger a detailed diagnostic process.
9. A system applying the business anomaly monitoring method based on dynamic graph calculation as described in any one of claims 1-8, characterized in that, include: Node dynamic adjustment module, business impact assessment module, and monitoring dynamic control module; The node dynamic adjustment module is used to generate a business graph structure based on real-time business interaction data and business association attributes from ERP reports, dynamically evaluate the rationality of nodes based on basic stability parameters and associated business parameters, and perform dynamic adjustment of nodes based on node update resource usage and report granularity mode according to the results of the dynamic evaluation of node rationality. In the business graph structure, nodes are business entities, edges are the interaction relationships between business entities, and the node dynamic adjustment means dynamically adjusting the node update frequency in the business graph structure to maintain the optimal balance between resource consumption and business needs. The business impact assessment module is used to dynamically process node weights based on the business interaction parameters of each associated business of the node and the dynamic assessment results of node rationality, and to dynamically assess business impact based on the dynamic processing results of node weights and node level. The dynamic processing of node weights means dynamically adjusting the weight values of the connection edges between the node and each associated business entity in the business graph structure to improve the accuracy of the business graph structure. The business interaction parameters include interaction frequency, interaction time, and rule matching degree. The steps for dynamically processing node weights based on the business interaction parameters of each associated business and the dynamic evaluation results of node rationality include: The dynamic evaluation results of node rationality are matched with the weight correction coefficient mapping table to obtain the corresponding weight correction coefficient. The weight correction coefficient mapping table is a standardized mapping relationship table that stores different node states and their corresponding weight correction coefficients. Obtain preset business interaction reference parameters and business interaction ratio parameters. The business interaction reference parameters include interaction frequency threshold, interaction time threshold, and rule matching degree threshold. The business interaction ratio parameters include interaction frequency ratio, interaction time ratio, and rule matching degree ratio. The business interaction parameters of each associated business of the node are respectively compared with the corresponding business interaction reference parameters to calculate the proportion of closeness. Then, the proportion of closeness calculation results are weighted using the business interaction proportion parameters. Finally, the weighted results are coupled to obtain the basic weight values of each associated business of the node. The basic weight values of each associated edge of a node are adjusted by using the weight adjustment coefficients of each associated business of the node, so as to obtain the final weight values of each associated edge of the node. The monitoring dynamic control module is used to perform dynamic risk assessment of nodes based on the dynamic assessment results of business impact and the dynamic stability parameters of nodes, and to perform monitoring dynamic control processing based on the dynamic risk assessment results of nodes. The monitoring dynamic control processing means dynamically adjusting the report granularity mode and node update frequency to optimize the allocation of monitoring resources and enhance the ability to locate and trace abnormal nodes.