Risk identification method and device, equipment, medium and program product

By acquiring and transforming historical logs through multi-source access interfaces, and combining time-series databases and sliding window models, the problems of storage limitations and low efficiency of manual verification in existing technologies are solved, achieving efficient and automated risk identification and early warning.

CN121639355APending Publication Date: 2026-03-10INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-09
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

Existing technologies suffer from limitations in storage capacity during risk identification, resulting in a lack of historical baseline data, making it difficult to compare trends. Furthermore, relying on manual log verification is inefficient and prone to missing abnormal patterns, leading to delayed risk response.

Method used

Historical target logs are obtained through multi-source access interfaces, transformed into quantitative indicators and stored in a time series database. A sliding window model is used for trend prediction analysis to generate a systemic risk profile. Based on the trend prediction data and the synergistic change characteristics of multiple quantitative indicators, automated risk identification is performed.

Benefits of technology

It enables efficient storage of historical data, improves the automation and accuracy of risk identification, can promptly detect systemic risks, reduces manual intervention, and enhances risk response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121639355A_ABST
    Figure CN121639355A_ABST
Patent Text Reader

Abstract

The invention provides a risk identification method which can be applied to the technical field of big data and artificial intelligence. The method comprises the steps that a historical target log is obtained through a multi-source access interface, the historical target log is converted into a quantitative index, and the historical target log is used for representing the operation state of a service system; constructing a historical snapshot sequence according to the quantitative index, and performing compression storage on the historical snapshot sequence by adopting a time sequence database; reading a historical snapshot sequence from the time sequence database, and performing trend prediction analysis on the quantitative index by using a sliding window model to obtain trend prediction data; and generating a systematic risk portrait based on the trend prediction data and the collaborative change characteristics of the plurality of quantitative indexes. The invention further provides a risk identification device and equipment, a medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the financial field, specifically to the fields of big data and artificial intelligence technologies, and more specifically to a risk identification method, apparatus, device, medium, and program product. Background Technology

[0002] Accurately identifying potential risks is one of the core challenges in ensuring the stability of business systems. However, current risk identification mechanisms based on monitoring platforms, log collection systems, and other auxiliary tools have significant limitations. First, due to storage capacity constraints, frequently collected monitoring metrics cannot be retained for long periods, resulting in a lack of historical baseline data for trend comparison and making it difficult to identify systemic risks caused by the gradual depletion of resources. Second, existing risk discovery mainly relies on manual verification of logs and metrics, which is not only inefficient but also prone to missing abnormal patterns in complex data, leading to delayed risk response. Summary of the Invention

[0003] In view of the above problems, this application provides a risk identification method, apparatus, equipment, medium and program product that improves the efficiency and intelligence of risk identification.

[0004] According to the first aspect of this application, a risk identification method is provided, comprising: acquiring historical target logs through a multi-source access interface and converting the historical target logs into quantitative indicators, wherein the historical target logs are used to characterize the operating status of the business system; constructing a historical snapshot sequence based on the quantitative indicators and compressing and storing the historical snapshot sequence using a time series database; reading the historical snapshot sequence from the time series database and performing trend prediction analysis on the quantitative indicators using a sliding window model to obtain trend prediction data; and generating a systemic risk profile based on the trend prediction data and the collaborative change characteristics of multiple quantitative indicators.

[0005] According to an embodiment of this application, the method further includes: automatically pulling a target snapshot at a target time point when the business system is put into production; comparing and analyzing the target snapshot with a historical snapshot sequence based on a predefined comparison strategy; and triggering a real-time alarm notification in response to an alarm condition that the target snapshot hits the comparison strategy.

[0006] According to an embodiment of this application, historical target logs are obtained through a multi-source access interface and converted into quantitative indicators, including: obtaining historical target logs from at least one data source through the multi-source access interface of a configurable data acquisition engine; and converting the historical target logs into quantitative indicators using a lightweight script engine embedded in the configurable data acquisition engine.

[0007] According to an embodiment of this application, the method further includes: determining whether there is a risk in the business system based on a systemic risk profile, and generating a risk analysis report based on the determination result, wherein the risk analysis report includes at least the risk level and its associated quantitative indicators.

[0008] According to an embodiment of this application, a time series database is used to compress and store historical snapshot sequences, including: assigning different compression strategies to different time segments based on the value density of quantitative indicators in the historical snapshot sequences, wherein the value density is calculated by the change frequency and fluctuation amplitude of the quantitative indicators; and performing compression and storage on the historical snapshot sequences according to the compression strategies assigned to each time segment.

[0009] According to an embodiment of this application, a sliding window model is used to perform trend prediction analysis on quantitative indicators to obtain trend prediction data. This includes: within the sliding window, performing collaborative analysis on multiple quantitative indicators through the sliding window model to obtain the correlation trend between the various quantitative indicators; and based on the correlation trend, predicting the evolution path and probability of business system risks within a future time window to obtain trend prediction data.

[0010] According to embodiments of this application, a systemic risk profile is generated based on trend prediction data and the synergistic change characteristics of multiple quantitative indicators, including: fusing trend prediction data with quantitative indicators to construct a multi-dimensional risk feature space; identifying at least one potential failure mode in the multi-dimensional risk feature space through a clustering algorithm; and integrating the identified failure mode, related quantitative indicators, and the contribution of the quantitative indicators to generate a systemic risk profile.

[0011] A second aspect of this application provides a risk identification device, comprising: an acquisition module for acquiring historical target logs through a multi-source access interface and converting the historical target logs into quantitative indicators, wherein the historical target logs are used to characterize the operating status of a business system; a storage module for constructing a historical snapshot sequence based on the quantitative indicators and compressing and storing the historical snapshot sequence using a time series database; a prediction module for reading the historical snapshot sequence from the time series database and performing trend prediction analysis on the quantitative indicators using a sliding window model to obtain trend prediction data; and a generation module for generating a systemic risk profile based on the trend prediction data and the collaborative change characteristics of multiple quantitative indicators.

[0012] A third aspect of this application provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.

[0013] A fourth aspect of this application also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.

[0014] The fifth aspect of this application also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method. Attached Figure Description

[0015] The above-mentioned contents, other objects, features and advantages of this application will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0016] Figure 1 The illustrations depict application scenarios of risk identification methods, apparatus, devices, media, and program products according to embodiments of this application.

[0017] Figure 2 A flowchart illustrating a risk identification method according to an embodiment of this application is shown schematically.

[0018] Figure 3 The diagram illustrates the architecture of a risk identification method according to an embodiment of this application.

[0019] Figure 4 A schematic diagram illustrating the structure of a risk identification device according to an embodiment of this application is shown; and

[0020] Figure 5 A block diagram schematically illustrates an electronic device suitable for implementing a risk identification method according to an embodiment of this application. Detailed Implementation

[0021] The embodiments of this application will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of this application. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of this application for ease of explanation. However, it will be apparent that one or more embodiments may be implemented without these specific details. Furthermore, descriptions of well-known structures and technologies are omitted in the following description to avoid unnecessarily obscuring the concepts of this application.

[0022] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application. The terms “comprising,” “including,” etc., as used herein indicate the presence of features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0023] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0024] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0025] In the technical solution of this application, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0026] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this application all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0027] Because traditional methods such as fixed threshold alarms and offline log analysis lack the ability to automatically analyze long-term trends and compare across periods, they are insufficient to meet the practical needs for early detection and warning of system performance degradation. Therefore, embodiments of this application provide a risk identification method, apparatus, device, medium, and program product.

[0028] Figure 1 The illustrations depict application scenarios of risk identification methods, apparatus, devices, media, and program products according to embodiments of this application.

[0029] like Figure 1As shown, application scenario 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0030] Users can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send data and instructions related to risk identification. Relevant personnel (such as personnel from risk assessment agencies, data management specialists, and risk verification personnel) can use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to perform risk identification business operations.

[0031] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with data transmission and processing capabilities and support access to the blockchain network, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0032] Server 105 can be a server that provides various services, such as a backend management server that supports risk identification-related requests submitted by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can further process the returned risk identification results, mapping them into risk analysis reports. It can also monitor and manage the acquired risk identification-related process information and feed the risk analysis reports back to the terminal devices.

[0033] It should be noted that the risk identification method provided in this application embodiment can generally be executed by server 105. Correspondingly, the risk identification device provided in this application embodiment can generally be located in server 105. The risk identification method provided in this application embodiment can also be executed by a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the risk identification device provided in this application embodiment can also be located in a server or server cluster that is different from server 105 and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.

[0034] It should be understood that Figure 1The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.

[0035] It should be noted that the risk identification method and apparatus of this application embodiment can be applied to the field of financial technology.

[0036] For example, in securities trading risk control scenarios, trading systems monitor abnormal trading behavior in real time through risk identification modules. When the system detects that an account has repeatedly engaged in abnormal operations such as high-frequency order cancellations and cross-market matching transactions within a short period of time, it can automatically retrieve the trader's historical violation records and current market liquidity data, completing a risk assessment within milliseconds. Once potential market manipulation is detected, the system can immediately trigger an alert and automatically restrict trading permissions, effectively preventing the spread of illegal trading risks.

[0037] For example, in the field of insurance underwriting, insurance companies utilize risk identification technology to integrate customer health data, asset distribution, and third-party credit information. When processing large policy applications from high-net-worth clients, the system can identify abnormal underwriting patterns through multi-dimensional data analysis, such as repeated insurance applications within a short period or a significant mismatch between the insured amount and asset status. This allows for timely warnings of potential transaction risks, and the system can dynamically adjust premium plans based on risk assessment results, thereby improving the accuracy of the insurance company's risk management.

[0038] In this process, risk identification faces challenges such as difficulties in feature alignment due to diverse data sources, insufficient real-time computing performance affecting response speed, and long model iteration cycles that make it difficult to adapt to new risk patterns. These problems may affect the accuracy and timeliness of risk assessment, thereby adversely impacting the business security of financial institutions. Therefore, the risk identification method, apparatus, equipment, and medium provided in the embodiments of this application can provide key technical support for building a precise and efficient risk prevention and control system.

[0039] It should be noted that the risk identification method and apparatus of this application are not only applicable to financial scenarios such as securities transaction monitoring and insurance underwriting, but can also be applied to multiple fields such as abnormal operation detection and corporate credit assessment. This application does not limit the specific application scenarios.

[0040] The following will be based on Figure 1 The described scene, through Figure 2 and Figure 3 The risk identification method according to the embodiments of this application will be described in detail.

[0041] Figure 2 A flowchart illustrating a risk identification method according to an embodiment of this application is shown.

[0042] like Figure 2As shown, the risk identification method in this embodiment includes operations S210 to S240.

[0043] When operating S210, historical target logs are obtained through multi-source access interfaces and converted into quantitative indicators. The historical target logs are used to characterize the operating status of the business system.

[0044] In embodiments of this application, the consent or authorization of operations and maintenance personnel can be obtained before acquiring historical target logs. For example, a request to acquire historical target logs can be sent to operations and maintenance personnel before operation S210. Operation S210 is executed only if the operations and maintenance personnel consent or authorize the acquisition of historical target logs.

[0045] Historical target logs can record quantifiable metrics for various aspects of the system, reflecting its operational status at different points in time. This includes not only recording operational parameters generated at each moment, such as response time for processing business requests, system resource utilization, and network transmission rate, but also various event information, such as system errors and significant operational changes. After acquiring the logs, log parsing scripts can convert them into quantifiable metrics based on preset rules and algorithms. These quantifiable metrics are numerical monitoring results, such as error rates and request volumes, reflecting the system's operational status in a more intuitive and accurate way.

[0046] In operation S220, a historical snapshot sequence is constructed based on quantitative indicators, and a time series database is used to compress and store the historical snapshot sequence.

[0047] A snapshot is a logical collection of all relevant quantitative metrics at a specific point in time. It's essentially a set of performance metrics monitored by the system at a particular moment, along with log parsing results. For example, multiple metrics collected at time T1, such as error rate, request volume, and memory usage, together constitute a system snapshot at that moment. By constructing a historical snapshot sequence, it's possible to record the changes in the system's operational status at different stages in chronological order.

[0048] To address the storage pressure brought by high-frequency data, time-series databases can be used to compress and store snapshot sequences. Firstly, time-series databases can reduce the storage space occupied by data through compression algorithms, significantly improving storage efficiency while preserving complete historical state information, enabling the system to store more historical data with limited storage resources. Secondly, this database can also support long-term data backtracking, effectively solving the problem of missing historical comparison data due to excessive data volume.

[0049] In operation S230, historical snapshot sequences are read from the time series database, and a sliding window model is used to perform trend prediction analysis on quantitative indicators to obtain trend prediction data.

[0050] Based on historical snapshot sequences, trend prediction algorithms, such as the sliding window model, can be used to detect potential deterioration trends. The sliding window model works by setting a window of a certain size and sliding it across the time series at specific step sizes. Within each window, the algorithm analyzes and processes the data of the quantitative indicators, calculating relevant statistical characteristics such as mean and variance. By observing the changes in these statistical characteristics across different windows, the potential trends in the quantitative indicators can be captured.

[0051] For example, when analyzing the quantitative metric of memory usage, suppose it is found to be growing at an average monthly rate of 5%. The sliding window model will make a scientific prediction based on this growth trend and conclude that memory usage may exceed the system's set threshold after 3 months.

[0052] When operating S240, a systemic risk profile is generated based on trend forecast data and the synergistic change characteristics of multiple quantitative indicators.

[0053] In the embodiments of this application, a corresponding operation entry point can be provided for operation and maintenance personnel, allowing them to choose to agree or reject the automated decision result. That is, before processing / making a systemic risk profile, the operation and maintenance personnel can input their agreement or rejection through the corresponding operation entry point. If the operation and maintenance personnel agree to the processing / decision, the systemic risk profile generation process / decision is performed, i.e., step S240 is executed. If the operation and maintenance personnel refuse to process / make a decision, the expert decision-making process is initiated.

[0054] In actual operation, the various components of a system are interconnected and influence each other; a change in one indicator may trigger a chain reaction in other indicators. Therefore, by comprehensively analyzing the synergistic changes of multiple indicators—that is, by correlating changes in multiple indicators—it is possible to more accurately determine whether there are systemic risks in the system. For example, when CPU utilization continues to rise while disk I / O latency also increases significantly, the system can comprehensively consider the changes in these two indicators to analyze the potential correlations and mutual influences between them.

[0055] The generated systemic risk profile integrates trend prediction data and collaborative change characteristics, providing a comprehensive and intuitive view of the various risks currently facing the system. This helps operations and maintenance personnel develop more effective and targeted risk response strategies. For example, if the risk profile indicates a potential risk due to insufficient memory, operations and maintenance personnel can promptly take measures such as increasing memory capacity and optimizing memory management strategies to mitigate the risk. If the risk is found to be caused by excessive disk I / O latency, they can check the disk hardware status and optimize disk read / write strategies.

[0056] For example, in a financial scenario, a securities firm, to mitigate systemic market risk, integrates historical trading logs, market data, macroeconomic indicators, and investor sentiment data through multi-source access interfaces, transforming this data into quantitative indicators such as volatility, turnover rate, leverage ratio, and industry index correlation. Then, it constructs a daily-level historical snapshot sequence and uses a time-series database for efficient compression and storage. Data is then retrieved from the database, and a sliding window model (window size set to 20 trading days, step size 5 days) is used to dynamically predict the trends of the quantitative indicators. This identifies a trend of continuously rising volatility in the technology sector and a strong positive correlation with the proportion of leveraged funds. Finally, combining the predicted data with the synergistic changes of multiple indicators (such as a simultaneous surge in leveraged funds when volatility exceeds a threshold and a sharp increase in cross-industry index correlation), a systemic risk profile is generated to indicate a high-leverage-driven liquidity crisis risk in the technology sector, providing early warning and decision-making basis for regulators and institutional investors.

[0057] Understandably, using a time-series database to compress and store historical snapshot sequences can effectively reduce data storage space and improve data storage efficiency. Furthermore, this database can support long-term retention of historical states, thus effectively solving the problem of missing historical data. Simultaneously, the sliding window model fully considers the time-series characteristics of the data, performs trend comparisons based on historical baseline data, and captures the changing patterns of indicators across different time periods, thereby generating more accurate trend prediction data. The systemic risk profile generated based on this trend prediction data and the synergistic change characteristics of multiple quantitative indicators comprehensively considers the dynamic changes and interrelationships of risk factors, enabling a more precise depiction of the overall characteristics of systemic risk. In addition, it automates the snapshot collection and analysis process, replacing tedious manual inspection work and significantly reducing labor costs.

[0058] In embodiments of this application, the method further includes: automatically pulling a target snapshot at a target time point when the business system is put into production; comparing and analyzing the target snapshot with a historical snapshot sequence based on a predefined comparison strategy; and triggering a real-time alarm notification in response to an alarm condition that the target snapshot hits the comparison strategy.

[0059] The comparison strategy can be defined by the user in the strategy configuration engine based on the actual operation of the business system and the risk tolerance. The strategy configuration engine provides users with a flexible and convenient rule definition interface, allowing users to formulate various comparison rules according to their own needs. For example, a user can set a rule "CPU (Central Processing Unit) utilization rate increases by more than 10% year-on-year," which means that when the CPU utilization rate in the current snapshot increases by more than 10% compared to the average utilization rate in the same period of the historical snapshot series, there may be potential risks. Another example is the rule "error log volume increases in 3 consecutive snapshots," which indicates that if the number of error logs in three consecutive target snapshots shows an increasing trend, the system may face failure risks.

[0060] It should be noted that the strategy engine has powerful open-source integration capabilities and can interface with various systems.

[0061] Once the business system is officially operational, it can automatically retrieve target snapshots based on pre-defined program logic, and automatically parse the data through scripting. The target time point for retrieval can be set according to the operational characteristics of the business system and risk monitoring needs to reflect the system's operational status at critical moments. Then, systemic risks can be analyzed and predicted based on strategies. That is, based on predefined comparison strategies, the target snapshot is compared with a historical snapshot sequence, i.e., the most recent N snapshots, to determine whether the difference between the current snapshot and historical snapshots meets the conditions for triggering a risk alarm. The value of N can be flexibly set according to the characteristics of the business system and the granularity of risk monitoring. By comparing with the most recent snapshots, a more comprehensive understanding of the changing trends of the system's operational status can be obtained, and the existence of current anomalies can be accurately determined. Once the quantitative indicators in the target snapshot meet the alarm conditions in the user-defined comparison rules, real-time alarm notifications can be quickly issued in various ways, such as via SMS, email, and system pop-ups, to ensure that risk management personnel can obtain risk information as soon as possible and take corresponding measures to respond to and handle risks, thereby effectively preventing further escalation of risks and impacting the normal operation of the business system.

[0062] Understandably, for gradual risks such as memory leaks and slow performance degradation, traditional threshold alarms cannot effectively capture their cumulative impact because the fluctuations at a single point in time are not significant. However, this application compares and analyzes the target snapshot with historical snapshot sequences. With the help of multi-period comparison function, it realizes cross-period dynamic comparison data to intelligently capture gradual problems that occur during system operation, promptly discover potential gradual deterioration, and thus achieve proactive early warning of production risks.

[0063] Based on the above embodiments, in this embodiment, historical target logs are obtained through a multi-source access interface and converted into quantitative indicators, including: obtaining historical target logs from at least one data source through the multi-source access interface of the configurable data acquisition engine; and converting historical target logs into quantitative indicators using a lightweight script engine embedded in the configurable data acquisition engine.

[0064] In some exemplary embodiments, a configurable data acquisition engine can be employed. This engine features a highly customizable multi-source access interface, allowing users to quickly adjust the accessed data sources and log types collected through simple configuration operations, based on actual business needs and changes in data sources. For example, when a business system adds a monitoring metric or introduces a new log system, corresponding settings can be made in the configuration file, and the data acquisition engine can automatically adapt and begin collecting relevant data. The multi-source access interface can seamlessly connect to at least one data source to achieve extensive collection of historical target logs. In practical applications, the types of data sources are diverse, including but not limited to various monitoring platforms and log systems. By connecting to a monitoring platform, the configurable data acquisition engine can obtain historical log information related to key performance indicators such as CPU utilization, memory usage, and network traffic. The log system can centrally store, manage, and analyze large amounts of log data. By connecting to it through the configuration interface, detailed system operation logs, error logs, etc., can be obtained. These logs contain rich information about the system's operating status.

[0065] The embedded lightweight script engine can read raw historical target logs and parse and calculate the log content according to pre-written script rules. Taking system error logs as an example, the raw logs may simply record the time, type, and brief description of the error. Through the script engine, these logs can be analyzed in depth, extracting key information and converting it into quantitative indicators. For example, the frequency of a certain type of error within a specific time period can be counted as a quantitative indicator; or the severity of the error can be determined based on keywords in the error description and assigned a corresponding value, forming another quantitative indicator.

[0066] Understandably, the multi-source access interface of the configurable data acquisition engine is highly flexible, while the lightweight script engine has high execution efficiency and can process a large amount of log data in a short time without significantly affecting the overall performance of the system.

[0067] In embodiments of this application, the method further includes: determining whether a business system has risks based on a systemic risk profile, and generating a risk analysis report based on the determination results, wherein the risk analysis report includes at least the risk level and its associated quantitative indicators.

[0068] Through data analysis techniques and model algorithms, we can uncover the inherent relationships and potential patterns among various types of data during the operation of business systems, integrate numerous scattered risk information into a whole, and ultimately form a systemic risk profile.

[0069] When assessing the potential risks of a business system, a systemic risk profile can be analyzed based on pre-defined risk assessment standards and thresholds. These standards and thresholds can be set and adjusted according to various factors, including the characteristics of the business system, historical operational data, and industry experience. For example, for financial business systems, indicators such as abnormal fund flows and sudden changes in transaction frequency can be used as important risk assessment criteria, with corresponding threshold ranges set. For industrial control systems, however, attention can be paid to indicators such as fluctuations in equipment operating parameters and anomalies in sensor data.

[0070] By comparing and analyzing a systemic risk profile with preset risk assessment standards and thresholds, it is possible to determine whether a business system is currently at risk. If certain key indicators in the risk profile exceed preset threshold ranges or exhibit abnormal trends, it can be determined that the business system has potential risks, and the type and potential scope of impact of these risks can be further identified. Simultaneously, a risk analysis report can be generated, which includes at least the risk level and its associated quantitative indicators. The risk level can be categorized based on the severity and scope of impact, such as low, medium, and high risk. Different risk levels correspond to different response strategies and processing priorities, allowing risk managers to quickly formulate appropriate countermeasures based on the risk level, improving the efficiency and effectiveness of risk management. The associated quantitative indicators reflect the specific manifestations and extent of the risk in the business system. For example, if the risk level is high, the report can indicate quantitative indicators such as persistently high CPU utilization, abnormal growth in memory usage, and a sharp increase in the number of error logs, and detail the trends of these indicators and instances where they exceed thresholds. Furthermore, a detailed description and analysis of the risk can be provided, including the causes of the risk, its potential scope and consequences, and its development trend.

[0071] Figure 3 The diagram illustrates the architecture of a risk identification method according to an embodiment of this application.

[0072] like Figure 3As shown, firstly, through a configurable data collection method, historical target logs can be collected from multiple data sources and processed to form a historical snapshot sequence. Then, these data can be stored in a time-series database as snapshots of specific time points. Next, a strategy comparison engine can be used to compare and analyze the currently acquired target snapshot with the historical snapshot sequence stored in the database based on comparison strategies to determine if any anomalies or potential risks have occurred in the system. Once an anomaly is detected, an alarm mechanism can be triggered immediately. Simultaneously, in-depth analysis of the historical data stored in the time-series database can be performed to discover data trends, periodic patterns, and potential patterns. Finally, based on the results of the historical data analysis, a detailed and accurate risk analysis report can be generated.

[0073] Understandably, generating detailed and comprehensive risk analysis reports can provide strong support for risk management in business systems, helping risk managers to identify, assess, and address potential risks in a timely manner, and ensuring the stable and secure operation of business systems.

[0074] Based on the above embodiments, in this embodiment, a time series database is used to compress and store historical snapshot sequences, including: assigning different compression strategies to different time segments based on the value density of quantitative indicators in the historical snapshot sequences, wherein the value density is calculated by the change frequency and fluctuation amplitude of the quantitative indicators; and performing compression and storage on the historical snapshot sequences according to the compression strategies assigned to each time segment.

[0075] The quantitative indicators included in the historical snapshot sequence have varying degrees of importance for business system analysis, and their value densities also differ. Value density can be calculated using the frequency and amplitude of change of the quantitative indicator. Frequency of change refers to the number of times the value of the quantitative indicator changes within a specific time frame. For example, when monitoring the CPU utilization of a business system, if the CPU utilization value changes 10 times in one minute, it has a higher frequency of change than if it only changes 2 times. Amplitude of change indicates the range of change in the value of the quantitative indicator over a period of time. Taking memory usage as an example, if its value fluctuates from 30% to 80% within a day, the amplitude of change is large; while if it consistently fluctuates between 40% and 50%, the amplitude of change is small. By weighting the frequency of change and amplitude of change (the weights can be adjusted according to business needs and indicator characteristics), the value density of the quantitative indicator can be obtained. For example, key indicators that have a significant impact on the stability of the business system can be assigned higher weights to highlight their importance in the value density calculation.

[0076] Based on the calculated value density of quantitative indicators, historical snapshot sequences can be divided into different time periods, and a corresponding compression strategy can be assigned to each time period. Specifically, if the value density of quantitative indicators is high within a certain time period, it indicates that the changes in the business system during that period are frequent and critical. Therefore, for high-value-density time periods, a lower compression ratio strategy can be used, or even no compression can be applied, to ensure data integrity and accuracy, facilitating subsequent in-depth mining and analysis of detailed information. For example, during periods of important business operations or system upgrades, the relevant quantitative indicator value density is high, and the original data can be retained or lightly compressed. Conversely, for time periods with low value density, it means that the business system is operating relatively stably, and the quantitative indicators change little. This type of data is used less frequently in subsequent analysis, and the requirement for detailed information is not high. Therefore, a higher compression ratio strategy can be used to save storage space to the greatest extent. For example, during off-peak hours of the business system or when the system is idle, the value density of quantitative indicators is low, and a high compression ratio algorithm can be used for compression storage.

[0077] Based on the compression strategy assigned to each time segment, a suitable compression algorithm can be selected to compress the historical snapshot sequence. Common compression algorithms include lossless compression algorithms and lossy compression algorithms. Lossless compression algorithms can ensure that the compressed data is completely consistent with the original data after decompression, and are suitable for high-value-density time segments where data accuracy is extremely important. Lossy compression algorithms, on the other hand, will lose some data information during the compression process, but can significantly improve the compression ratio, and are suitable for low-value-density time segments.

[0078] Once the compression algorithm is determined, the historical snapshot sequence can be compressed according to the assigned compression strategy. Time-series databases can store the compressed data in chronological order and establish corresponding index structures to facilitate quick querying and retrieval of data within a specific time range.

[0079] It is understandable that by allocating compression strategies based on the value density of quantitative indicators and executing compression and storage methods according to the strategies, efficient and reasonable storage of historical snapshot sequences can be achieved, saving storage space while meeting the needs of data analysis and processing in different business scenarios.

[0080] Based on the above embodiments, in this embodiment, a sliding window model is used to perform trend prediction analysis on quantitative indicators to obtain trend prediction data. This includes: within the sliding window, performing collaborative analysis on multiple quantitative indicators through the sliding window model to obtain the correlation trend between each quantitative indicator; and based on the correlation trend, predicting the evolution path and probability of business system risks within the future time window to obtain trend prediction data.

[0081] The sliding window model is a dynamic analysis method based on time series data. It sets a fixed-size window on the time axis, which slides forward continuously over time. At each window position, the model can process and analyze the data within the window to capture local features and trends.

[0082] In some exemplary embodiments, the size of the sliding window can be set according to the characteristics of the business system and the frequency of data changes. For example, for business systems with frequent data changes, a smaller window size can be set to capture subtle changes in the data more promptly; while for systems with relatively slow data changes, the window size can be appropriately increased to reduce noise interference and improve the stability of the analysis. The sliding step size of the window can also be adjusted according to actual needs; the smaller the step size, the finer the granularity of the analysis; the larger the step size, the higher the efficiency of the analysis.

[0083] Within each sliding window, the sliding window model can perform collaborative analysis on multiple quantitative indicators to uncover the intrinsic relationships and interaction mechanisms among them. For example, in an e-commerce system, an increase in order processing volume (one quantitative indicator) may lead to an increase in server CPU utilization (another quantitative indicator), along with a corresponding increase in network traffic. The sliding window model can identify such synchronous changes between indicators to determine the correlation trends. These correlation trends not only reflect the relationship between indicators within the current window but also how this relationship changes over time. For instance, during a certain period, CPU utilization and memory usage may exhibit a strong positive correlation—that is, as CPU utilization increases, memory usage also increases. However, during another period, due to system optimization or changes in business models, this positive correlation may weaken or even turn into a negative correlation.

[0084] Correlation trends can be displayed using correlation matrices or correlation graphs. A correlation matrix presents the correlation coefficients between various indicators in matrix form, and the strength of the correlation can be represented by the intensity of color or the magnitude of the value; a correlation graph, on the other hand, graphically displays the connection relationships and directions between indicators, making it easier for users to quickly understand the complex relationships between indicators.

[0085] Based on the identified correlation trends, the sliding window model can predict the evolution path and probability of business system risks within a future time window. The evolution path of a risk refers to a series of changes from its emergence to its development and the potential consequences, while the risk probability represents the likelihood of a certain risk occurring within a specific future timeframe.

[0086] For example, if correlation trend analysis reveals that CPU utilization is continuously rising and its positive correlation with memory usage is constantly strengthening, while network latency is also showing an abnormally increasing trend, then the model can predict that in the next few time windows, the business system may experience risks such as performance degradation and longer response times. Furthermore, as these indicators deteriorate further, the probability of system crashes will gradually increase.

[0087] Through the above analysis process, the sliding window model can ultimately generate trend prediction data, which can include the predicted values ​​of various quantitative indicators within the future time window, the description of the risk evolution path, and the estimation of risk probability.

[0088] Understandably, by using a sliding window model to conduct collaborative analysis of quantitative indicators, it is possible to accurately identify the correlations between indicators and make predictions based on these relationships. This allows for a more comprehensive consideration of various factors affecting risk and greatly improves the accuracy of risk prediction.

[0089] Based on the above embodiments, in this embodiment, a systemic risk profile is generated based on the trend prediction data and the synergistic change characteristics of multiple quantitative indicators. This includes: fusing the trend prediction data with the quantitative indicators to construct a multi-dimensional risk feature space; identifying at least one potential failure mode in the multi-dimensional risk feature space through a clustering algorithm; and integrating the identified failure mode, related quantitative indicators, and the contribution of the quantitative indicators to generate a systemic risk profile.

[0090] Since trend forecast data is based on predicted values ​​within a future time window, while quantitative indicators are measured values ​​at the current moment, to deeply integrate trend forecast data and quantitative indicators, it is essential to ensure the comparability of the two types of data across time. Therefore, time interpolation or extrapolation methods can be used to map the quantitative indicator data to the same time scale as the trend forecast data, ensuring that each point in time has both the current indicator value and its corresponding predicted value. Then, for each quantitative indicator, features such as its current value, predicted value, and the rate of change between the two can be extracted. Furthermore, considering the potential differences in the dimensions and numerical ranges of different quantitative indicators, the extracted features can be standardized, mapping each feature to a unified numerical range for subsequent comprehensive analysis in a multi-dimensional space.

[0091] After data fusion and feature extraction standardization, the system state at each time point can be represented by a multi-dimensional vector, with each dimension of the vector corresponding to a feature. Combining the multi-dimensional vectors from all time points forms a multi-dimensional risk feature space. In this space, data points represent the system state at different time points. Clustering algorithms can group system states with similar features into a single category, with each category potentially corresponding to a specific failure mode. Furthermore, to understand the impact of each quantitative indicator on potential failure modes, contribution calculation methods, such as those based on analysis of variance or on the feature importance of machine learning models, can be used to calculate the contribution of each quantitative indicator. Finally, the generated systemic risk profile can include key information such as identified potential failure modes, related quantitative indicators, and their corresponding contribution levels. This profile can be presented in various formats, including tables, charts, and text descriptions. For example, tables can list the name, description, related quantitative indicators, and their contribution levels for each potential failure mode; radar charts or heatmaps can visually display the distribution of the contribution levels of different quantitative indicators under different failure modes.

[0092] Understandably, by integrating trend forecasting data with multiple quantitative indicators to construct a multidimensional risk feature space, it is possible to comprehensively capture the complex characteristics of systemic risk from multiple angles and levels.

[0093] Based on the above-described risk identification method, this application also provides a risk identification device. The following will be combined with... Figure 4 The device is described in detail.

[0094] Figure 4 A schematic block diagram of a risk identification device according to an embodiment of this application is shown.

[0095] like Figure 4 As shown, the risk identification device 400 of this embodiment includes an acquisition module 410, a storage module 420, a prediction module 430, and a generation module 440.

[0096] The acquisition module 410 is used to acquire historical target logs through a multi-source access interface and convert the historical target logs into quantitative indicators, wherein the historical target logs are used to characterize the operating status of the business system. In one embodiment, the acquisition module 410 can be used to perform the operation S210 described above, which will not be repeated here.

[0097] The storage module 420 is used to construct a historical snapshot sequence based on quantitative indicators and to compress and store the historical snapshot sequence using a time series database. In one embodiment, the storage module 420 can be used to perform the operation S220 described above, which will not be repeated here.

[0098] The prediction module 430 is used to read historical snapshot sequences from a time series database and perform trend prediction analysis on quantitative indicators using a sliding window model to obtain trend prediction data. In one embodiment, the prediction module 430 can be used to perform the operation S230 described above, which will not be repeated here.

[0099] The generation module 440 is used to generate a systemic risk profile based on trend forecast data and the synergistic change characteristics of multiple quantitative indicators. In one embodiment, the generation module 440 can be used to perform the operation S240 described above, which will not be repeated here.

[0100] According to an embodiment of this application, the prediction module 430 can also be used to: automatically pull a target snapshot at a target time point when the business system is put into production; compare and analyze the target snapshot with the historical snapshot sequence based on a predefined comparison strategy; and trigger a real-time alarm notification in response to the alarm condition that the target snapshot hits the comparison strategy.

[0101] According to an embodiment of this application, the acquisition module 410 can be specifically used to: acquire historical target logs from at least one data source through the multi-source access interface of the configurable data acquisition engine; and convert the historical target logs into quantitative indicators using the lightweight script engine embedded in the configurable data acquisition engine.

[0102] According to an embodiment of this application, the generation module 440 can also be used to: determine whether there is a risk in the business system based on the systemic risk profile, and generate a risk analysis report based on the determination result, wherein the risk analysis report includes at least the risk level and its associated quantitative indicators.

[0103] According to an embodiment of this application, the storage module 420 can be specifically used to: allocate different compression strategies to different time segments based on the value density of quantified indicators in the historical snapshot sequence, wherein the value density is calculated by the change frequency and fluctuation amplitude of the quantified indicators; and perform compression and storage on the historical snapshot sequence according to the compression strategy allocated to each time segment.

[0104] According to an embodiment of this application, the prediction module 430 can be specifically used to: perform collaborative analysis on multiple quantitative indicators through a sliding window model within a sliding window to obtain the correlation trend between the quantitative indicators; and based on the correlation trend, predict the evolution path and probability of business system risks within a future time window to obtain trend prediction data.

[0105] According to an embodiment of this application, the generation module 440 can be specifically used to: integrate trend prediction data with quantitative indicators to construct a multi-dimensional risk feature space; identify at least one potential failure mode in the multi-dimensional risk feature space through a clustering algorithm; and integrate the identified failure mode, related quantitative indicators and the contribution of the quantitative indicators to generate a systemic risk profile.

[0106] According to embodiments of this application, any plurality of modules among the acquisition module 410, storage module 420, prediction module 430, and generation module 440 can be merged into one module, or any one of these modules can be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules can be combined with at least part of the functionality of other modules and implemented in one module. According to embodiments of this application, at least one of the acquisition module 410, storage module 420, prediction module 430, and generation module 440 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any appropriate combination of any of these three implementation methods. Alternatively, at least one of the acquisition module 410, storage module 420, prediction module 430, and generation module 440 can be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0107] Figure 5 A block diagram schematically illustrates an electronic device suitable for implementing a risk identification method according to an embodiment of this application.

[0108] like Figure 5 As shown, an electronic device 500 according to an embodiment of this application includes a processor 501, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 502 or a program loaded from a storage portion 508 into a random access memory (RAM) 503. The processor 501 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 501 may also include onboard memory for caching purposes. The processor 501 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of this application.

[0109] RAM 503 stores various programs and data required for the operation of electronic device 500. Processor 501, ROM 502, and RAM 503 are interconnected via bus 504. Processor 501 executes various operations of the method flow according to embodiments of this application by executing programs in ROM 502 and / or RAM 503. It should be noted that programs may also be stored in one or more memories other than ROM 502 and RAM 503. Processor 501 may also execute various operations of the method flow according to embodiments of this application by executing programs stored in one or more memories.

[0110] According to embodiments of this application, the electronic device 500 may further include an input / output (I / O) interface 505, which is also connected to a bus 504. The electronic device 500 may also include one or more of the following components connected to the input / output (I / O) interface 505: an input section 506 including a keyboard, mouse, etc.; an output section 507 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 508 including a hard disk, etc.; and a communication section 509 including a network interface card such as a LAN card, modem, etc. The communication section 509 performs communication processing via a network such as the Internet. A drive 510 is also connected to the input / output (I / O) interface 505 as needed. A removable medium 511, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 510 as needed so that computer programs read from it can be installed into the storage section 508 as needed.

[0111] This application also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of this application.

[0112] According to embodiments of this application, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, the computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this application, the computer-readable storage medium may include ROM 502 and / or RAM 503 and / or one or more memories other than ROM 502 and RAM 503 described above.

[0113] Embodiments of this application also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the risk identification method provided in the embodiments of this application.

[0114] When the computer program is executed by the processor 501, it performs the functions defined in the system / apparatus of this application embodiment. According to the embodiments of this application, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0115] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 509, and / or installed from a removable medium 511. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0116] In such an embodiment, the computer program can be downloaded and installed from a network via communication section 509, and / or installed from removable medium 511. When the computer program is executed by processor 501, it performs the functions defined in the system of this application embodiment. According to embodiments of this application, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0117] According to embodiments of this application, program code for executing the computer programs provided in the embodiments of this application can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. The program code can be executed entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0118] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0119] Those skilled in the art will understand that the features described in the various embodiments of this application can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this application. In particular, the features described in the various embodiments of this application can be combined and / or combined in various ways without departing from the spirit and teachings of this application. All such combinations and / or combinations fall within the scope of this application.

[0120] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A risk identification method, characterized by, The method comprises: acquiring historical target logs through a multi-source access interface, and converting the historical target logs into quantitative indicators, wherein the historical target logs are used to represent the running state of a business system; constructing a historical snapshot sequence according to the quantitative indicators, and compressively storing the historical snapshot sequence by using a time series database; reading the historical snapshot sequence from the time series database, and performing trend prediction analysis on the quantitative indicators by using a sliding window model to obtain trend prediction data; and generating a systemic risk portrait based on the trend prediction data and the collaborative change characteristics of the quantitative indicators.

2. The method of claim 1, wherein, The method further comprises: automatically pulling a target snapshot of a target time point when the business system is in production operation; comparing and analyzing the target snapshot with the historical snapshot sequence based on a predefined comparison strategy; and triggering real-time alarm notification in response to the target snapshot hitting an alarm condition of the comparison strategy.

3. The method according to claim 1 or 2, characterized in that, The method further comprises: acquiring the historical target logs from at least one data source through a multi-source access interface of a configured data collection engine; and converting the historical target logs into the quantitative indicators by using a lightweight script engine embedded in the configured data collection engine.

4. The method according to claim 1 or 2, characterized in that, The method further comprises: judging whether the business system has risks based on the systemic risk portrait, and generating a risk analysis report according to the judgment result, wherein the risk analysis report at least includes a risk level and its associated quantitative indicators.

5. The method of claim 1, wherein, The method further comprises: allocating different compression strategies to different time segments based on the value density of the quantitative indicators in the historical snapshot sequence, wherein the value density is calculated by the change frequency and fluctuation amplitude of the quantitative indicators; and performing compression and storage on the historical snapshot sequence according to the compression strategies allocated to the time segments.

6. The method according to claim 1 or 5, characterized in that, The method further comprises: performing collaborative analysis on the quantitative indicators by using the sliding window model within a sliding window to obtain the correlation trend between the quantitative indicators; and predicting the evolution path and probability of the business system risks in a future time window based on the correlation trend to obtain the trend prediction data.

7. The method of claim 1, wherein, The method further comprises: fusing the trend prediction data with the quantitative indicators to construct a multi-dimensional risk feature space; identifying at least one potential failure mode in the multi-dimensional risk feature space by using a clustering algorithm; and integrating the identified failure mode, related quantitative indicators and contribution degrees of the quantitative indicators to generate the systemic risk portrait.

8. A risk identification apparatus, characterized by, The device comprises: An acquisition module is configured to acquire a historical target log through a multi-source access interface and convert the historical target log into a quantitative index, where the historical target log is used to represent a running state of a business system; A storage module is configured to construct a historical snapshot sequence according to the quantitative index and compressively store the historical snapshot sequence in a time series database; A prediction module is configured to read the historical snapshot sequence from the time series database, perform trend prediction analysis on the quantitative index by using a sliding window model, and obtain trend prediction data; and A generation module is configured to generate a systemic risk portrait based on the trend prediction data and a cooperative change feature of a plurality of the quantitative indexes.

9. An electronic device comprising: one or more processors; memory for storing one or more computer programs, characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1-7.

10. A computer readable storage medium having stored thereon a computer program or instructions, characterized in that, The computer program or instruction is executed by the processor to implement the steps of the method according to any one of claims 1-7.

11. A computer program product comprising computer programs or instructions, characterized in that, The computer program or instruction is executed by the processor to implement the steps of the method according to any one of claims 1-7. The computer program or instruction is executed by the processor to implement the steps of the method according to any one of claims 1-7.