Financial host process management method and device, electronic equipment and storage medium

By establishing an information asset data lake in the financial mainframe, collecting dynamic characteristics of processes and generating business fingerprints, and determining the responsibility matrix, the problems of lagging information asset management and monitoring blind spots have been solved, and the consistency between accounts and reality and the efficiency of supervision have been improved.

CN121919862APending Publication Date: 2026-04-24CHINA CONSTR BANK CO LTD GUANGDONG BRANCH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA CONSTR BANK CO LTD GUANGDONG BRANCH
Filing Date
2026-01-13
Publication Date
2026-04-24

Smart Images

  • Figure CN121919862A_ABST
    Figure CN121919862A_ABST
Patent Text Reader

Abstract

The invention discloses a process management method and device of a financial host, electronic equipment and a storage medium. The method comprises the following steps: establishing an information asset data lake corresponding to a target financial center; collecting process dynamic characteristics of a financial host in the target financial center based on the information asset data lake; generating a service fingerprint according to the process dynamic characteristics, and determining a three-level responsibility matrix according to the service fingerprint; and performing process management on the financial host based on the three-level responsibility matrix and the service fingerprint. Based on the technical scheme, the process dynamic characteristics of the financial host are collected, the corresponding service fingerprint is generated, the responsibility matrix is determined according to the service fingerprint, and process management is realized according to the responsibility matrix, so that the financial security defense line is enhanced, account-reality conformity of information asset management is realized, and the supervision efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a process management method, apparatus, electronic device, and storage medium for a financial host. Background Technology

[0002] With the development of financial technology, banking operations are highly dependent on IT systems, and asset management has shifted from physical hardware to logical processes.

[0003] However, existing information asset management mainly relies on manual data entry, and updates often lag behind business changes, failing to reflect the current operating status of the server, resulting in discrepancies between accounts and actual data. Furthermore, commercial APM software is expensive and complex to deploy, typically only covering the core transaction chain and failing to cover all auxiliary processes, system services, and maintenance tools, resulting in monitoring blind spots and a lack of logical ability to automatically map underlying processes to individuals. Summary of the Invention

[0004] This invention provides a process management method, apparatus, electronic device, and storage medium for financial mainframes. By collecting the dynamic characteristics of the processes of the financial mainframes and generating corresponding business fingerprints, a responsibility matrix is ​​determined based on the business fingerprints, and process management is achieved based on the responsibility matrix. This strengthens the financial security defense, ensures consistency between accounts and actual assets in information asset management, and improves regulatory efficiency.

[0005] According to one aspect of the present invention, a process management method for a financial mainframe is provided, comprising:

[0006] Establish an information asset data lake corresponding to the target financial center;

[0007] Based on the information asset data lake, the process dynamic characteristics of the financial mainframes in the target financial center are collected;

[0008] A business fingerprint is generated based on the process dynamic characteristics, and a three-level responsibility matrix is ​​determined based on the business fingerprint;

[0009] Process governance of the financial host is performed based on the three-level responsibility matrix and the business fingerprint.

[0010] According to another aspect of the present invention, a process management apparatus for a financial mainframe is provided, comprising:

[0011] The data lake creation module is used to create an information asset data lake corresponding to the target financial center;

[0012] The process feature extraction module is used to collect the process dynamic features of the financial hosts in the target financial center based on the information asset data lake;

[0013] The responsibility matrix determination module is used to generate a business fingerprint based on the process dynamic characteristics and determine a three-level responsibility matrix based on the business fingerprint.

[0014] The process governance module is used to perform process governance on the financial host based on the three-level responsibility matrix and the business fingerprint.

[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0016] At least one processor; and

[0017] A memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores a computer program that can be executed by the at least one processor, which is then executed by the at least one processor to enable the at least one processor to perform the process management method of the financial host according to any embodiment of the present invention.

[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions, the computer instructions being configured to cause a processor to execute and implement the process management method of the financial host according to any embodiment of the present invention.

[0020] The technical solution of this invention establishes an information asset data lake corresponding to a target financial center; collects the process dynamic characteristics of financial hosts in the target financial center based on the information asset data lake; generates business fingerprints based on the process dynamic characteristics; and determines a three-level responsibility matrix based on the business fingerprints; and performs process governance on the financial hosts based on the three-level responsibility matrix and the business fingerprints. Based on the above technical solution, by collecting the process dynamic characteristics of financial hosts and generating corresponding business fingerprints, determining the responsibility matrix based on the business fingerprints, and implementing process governance based on the responsibility matrix, the financial security defense line is strengthened, the consistency between accounts and reality in information asset management is achieved, and regulatory efficiency is improved.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart of a process management method for a financial host provided in an embodiment of the present invention;

[0024] Figure 2 This is a flowchart of determining a three-level responsibility matrix provided in an embodiment of the present invention;

[0025] Figure 3 This is a flowchart of process management provided in an embodiment of the present invention;

[0026] Figure 4 This is a flowchart of a process management method for a financial host provided in an embodiment of the present invention;

[0027] Figure 5 A schematic diagram of the structure of a process management device for a financial host provided in an embodiment of the present invention;

[0028] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0029] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0031] Figure 1This is a flowchart illustrating a process management method for a financial host according to an embodiment of the present invention. This embodiment is applicable to situations where a responsibility matrix is ​​determined by collecting the dynamic characteristics of the processes of a financial host, and process management is implemented based on the responsibility matrix. This method can be executed by a process management device of the financial host, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method specifically includes the following steps:

[0032] S110. Establish an information asset data lake corresponding to the target financial center.

[0033] The target financial center can be a financial cluster area with functions such as financial transactions, information exchange, and risk management, which can be used to carry out financial business and data flow within the business area. Information assets can be understood as financial data resources generated, collected, or stored by the financial center during its operation. An information asset data lake can be a distributed data storage architecture used for centralized storage and management of various information assets.

[0034] Specifically, this involves establishing an information asset data lake corresponding to the target financial center. For example, this could involve obtaining the target financial center's business scope, data type list, and data management requirements; selecting a suitable distributed storage framework based on these requirements; building the data lake infrastructure; configuring storage nodes, compute nodes, and network communication components; deploying hardware resources and the software environment; constructing data access channels; and using ETL tools to process and store the target financial center's data to obtain the corresponding information asset data lake.

[0035] S120. Collect the process dynamic characteristics of financial mainframes in the target financial center based on the information asset data lake.

[0036] The financial host can be a server device used to host financial business operations. Process dynamic characteristics can be features collected during the real-time execution of the process.

[0037] Specifically, the data collection process dynamics of financial mainframes in the target financial center are based on the information asset data lake. For example, the collection scope, process feature dimensions, and collection frequency requirements for the financial mainframes can be determined according to a pre-defined collection strategy within the information asset data lake. Adaptive data collection probes are then deployed on each financial mainframe in the target financial center to collect dynamic data on all running processes within the financial mainframes, including data on process startup status, resource usage, and interactive behavior. The collected feature data is then standardized and feature extracted to obtain dynamic process features. It should be noted that key field names matching the dynamic features can be pre-defined. Based on these key field names, features characterizing the process's running state are extracted from the standardized data, forming structured dynamic process features.

[0038] Based on the above technical solution, the dynamic characteristics of the processes of financial hosts in the target financial center are collected based on the information asset data lake, including: reading the process memory mapping file of the financial host through the data acquisition probe; obtaining the startup parameter strings of the process and its parent process based on the memory mapping file, and collecting the environmental information of the process during runtime to form an environmental fingerprint; and obtaining the process dynamic characteristics based on the startup parameter string and the environmental fingerprint.

[0039] The data acquisition probe can be a dedicated data acquisition component deployed on a financial host. This probe can be a lightweight probe that directly calls the GNU C Library, eliminating dependencies on other third-party libraries to reduce resource consumption. The process memory mapping file can be a file used to record process memory allocation and data storage addresses. The startup parameter string can be the parameter information passed in when the process and its parent process start, which can be used to represent the process's startup configuration and running purpose. Environment information can be understood as the system environment parameters during process runtime. The environment fingerprint can be a feature identifier generated based on the process's runtime environment information.

[0040] Specifically, the data acquisition probe reads the process memory-mapped files of the financial host, then obtains the startup parameter strings of the process and its parent process based on the memory-mapped files, and collects the environment information of the process runtime to form an environment fingerprint. Based on the startup parameter strings and environment fingerprints, the dynamic characteristics of the process are obtained. For example, by starting the data acquisition probe, a process memory-mapped file read instruction is triggered, and the memory-mapped files of all processes in the financial host are obtained at a preset period. By parsing the memory-mapped files, the startup parameter strings of the process and its corresponding parent process are extracted, and the system environment parameters of the process runtime are collected. After standardizing the environment parameters, an environment fingerprint is generated. The startup parameter strings are associated with the environment fingerprint to obtain the process dynamic characteristic data relative to the current process. It should be noted that after the process dynamic characteristic data is collected, the completeness and validity of the collected process dynamic characteristic data can be verified. The verified process dynamic characteristic data is transmitted to the information asset data lake for data storage in a preset format, which can be JSON format. During the data acquisition process, a collection log can be generated to record the collection process and data status. If problems such as probe communication abnormalities or data parsing failures occur during the collection process, corresponding abnormal records are generated in the collection log.

[0041] S130. Generate business fingerprints based on process dynamic characteristics, and determine a three-level responsibility matrix based on business fingerprints.

[0042] Among them, the business fingerprint can be a feature marker generated based on the dynamic characteristics of the process, used to identify the operational status of financial business. The three-level responsibility matrix can be understood as a responsibility division matrix generated according to a preset business hierarchy, which can include system level, application level, and personnel level. This three-level responsibility matrix can be used to determine the responsibility attribution and control boundaries of each link in the financial business.

[0043] Specifically, business fingerprints are generated based on process dynamic characteristics, and a three-tier responsibility matrix is ​​determined based on these business fingerprints. For example, process dynamic characteristic data can be obtained, and feature extraction dimensions, weight allocation, and fingerprint encoding rules can be determined according to preset business fingerprint generation rules. Based on the above, the data in the process dynamic characteristics is associated and matched with business scenarios according to the business fingerprint generation rules. Key features are weighted and standardized to generate business fingerprints, and the association between business fingerprints and corresponding process dynamic characteristics and business scenarios is established. Then, based on the business scenarios and hierarchical attributes corresponding to the business fingerprints, the corresponding responsible entities are matched, and the control responsibilities and authority scope of each level are determined. According to the three-tier hierarchical structure, the responsibilities, control processes, and collaboration mechanisms of each responsible entity are sorted out to form a three-tier responsibility matrix.

[0044] Based on the above technical solution, a three-level responsibility matrix is ​​determined according to business fingerprints, including: querying the information asset data lake based on the address identifier in the business fingerprint to obtain administrator information, and using the administrator information as the first-level responsibility information; determining the combined query key based on the business fingerprint, and querying the application attribution information from the information asset data lake based on the combined query key, and using the application attribution information as the second-level responsibility information; determining the personnel attribution information based on the application attribution information, and using the personnel attribution information as the third-level responsibility information; and constructing a three-level responsibility matrix based on the first-level responsibility information, the second-level responsibility information, and the third-level responsibility information.

[0045] The address identifier can be a feature within the business fingerprint used to locate the physical or network location of the financial host. Administrator information can be understood as the information of the personnel or team responsible for the operation and maintenance of the financial host. The combined query key can be a composite search identifier generated based on the multi-dimensional features of the business fingerprint. Application affiliation information can be understood as the information of the department and business line to which the application system corresponding to the business belongs. Personnel affiliation information can be the information of the specific personnel directly responsible for the operation and maintenance of the business application. Primary responsibility information can be the responsibility information corresponding to the operation and maintenance of the financial host. Secondary responsibility information can be the responsibility information corresponding to the business application. Tertiary responsibility information can be the responsibility information corresponding to the specific personnel performing the task.

[0046] Specifically, based on the address identifier in the business fingerprint, administrator information is retrieved from the information asset data lake and designated as primary responsibility information. A combined query key is then determined based on the business fingerprint, and application attribution information is retrieved from the information asset data lake using this combined query key. This application attribution information is designated as secondary responsibility information. After determining the application attribution information, personnel attribution information is determined based on the application attribution information and designated as tertiary responsibility information. For example, the target business fingerprint can be retrieved, its address identifier information parsed, and used as a search keyword to access the information asset data lake's search engine. This retrieves the administrator information of the corresponding host and marks it as primary responsibility information. Based on the multi-dimensional features in the business fingerprint, a unique combined query key is generated according to preset combination rules, ensuring that the query key accurately corresponds to a specific business application. The combined query key is then passed to the information asset data lake to match the corresponding business line, department, and other information, marking it as secondary responsibility information. Based on the application attribution attribute in the secondary responsibility information, a related query is performed from the data lake to retrieve the specific personnel information responsible for the operation and maintenance of that application, marking it as tertiary responsibility information. Construct a responsibility matrix framework, with a hierarchical structure of first-level, second-level, and third-level, and fill the corresponding responsibility information into the specified dimensions of the matrix to clarify the control scope and responsibility boundaries of the responsible entities at each level.

[0047] For example, such as Figure 2As shown, the process can involve: L1 layer collision (operating system layer): using the IP address as the key, retrieving host information corresponding to the current thread in the CMDB (Configuration Management Database) of the data lake to identify the system administrator. L2 layer collision (application layer): using "IP + port" or "IP + instance characteristics" as the combined key, searching the middleware ledger and application configuration tables in the data lake to identify the corresponding business system name and its affiliated department. L3 layer collision (personnel layer): based on the identified system's affiliated department, querying the organizational structure tree to associate the system's primary and backup maintenance personnel and development interface personnel.

[0048] Based on the above technical solution, personnel affiliation information is determined according to application affiliation information, including: determining the target department based on application affiliation information and determining the organizational structure tree corresponding to the target department; and determining the personnel affiliation information corresponding to the current thread based on the organizational structure tree.

[0049] The target department can be the specific department responsible for managing the business application, as clearly defined in the application attribution information. The organizational structure tree can be understood as a hierarchical structure representing the division of labor and responsibilities within each department. The current thread can be the running business execution thread corresponding to the business fingerprint. Personnel attribution information includes the primary and backup operations and maintenance (O&M) personnel and the development interface personnel. The primary and backup O&M personnel can be understood as the primary and backup personnel responsible for the daily O&M and troubleshooting of the business application. The development interface personnel can be the liaison personnel responsible for the business application's development iterations and technical support.

[0050] Specifically, the target department is determined based on the application's attribution information, and the corresponding organizational structure tree is then identified. Based on this organizational structure tree, the personnel attribution information corresponding to the current thread is determined. For example, by parsing the application's attribution information to obtain the department identifier field, the corresponding target department is located based on this field. The complete organizational structure tree of that target department is then retrieved. The identifier information of the current business thread is extracted from the organizational structure tree and matched against the job responsibilities within it, clarifying the business module and the scope of operations and maintenance (O&M) and development responsibilities corresponding to that thread. Based on the matching results, the primary and backup responsible persons for the daily operations and maintenance of that business module, as well as the corresponding development liaisons, are selected from the organizational structure tree, forming personnel attribution information that includes the primary and backup O&M responsible persons and development liaisons.

[0051] S140. Process governance of financial mainframes is performed based on a three-level responsibility matrix and business fingerprints.

[0052] Among them, process governance can be a technical process for tracking the operation trajectory, responsibility attribution, and related business links of financial mainframe processes by associating business characteristics and responsibility systems. It can be used to locate the root cause of process anomalies and the responsible party.

[0053] Specifically, process governance of financial mainframes is based on a three-tier responsibility matrix and business fingerprints. For example, a mapping relationship can be established between the business fingerprint corresponding to the target financial mainframe and the three-tier responsibility matrix. The responsibility level and responsible entity information corresponding to the business fingerprint can be determined, and historical data on process dynamic characteristics, business operation logs, and responsible entity operation records stored in the information asset data lake can be obtained. Based on the core features in the business fingerprint, matching process operation trajectory data is retrieved from the data lake to determine the full lifecycle behavior chain corresponding to the current process, including startup, operation, and interaction. Combining the first, second, and third-tier responsibility information in the three-tier responsibility matrix, the host administrator, application-related department, and specific responsible personnel corresponding to the process are traced sequentially. The operational permissions and control responsibilities of each responsible entity during process operation are clarified. The process behavior chain is cross-compared with the responsible entity's operation records to identify abnormal nodes in process operation and their corresponding responsible links, generating a process governance report.

[0054] Based on the above technical solution, process governance of the financial host is carried out based on a three-level responsibility matrix and business fingerprints, including: determining a process whitelist based on business fingerprints and the three-level responsibility matrix; monitoring the running status of application processes in the process whitelist in real time and generating a difference report when a process exits abnormally or the system restarts; and adding new processes to the process graylist and classifying them based on process characteristics when new processes are detected.

[0055] The process whitelist is a pre-defined list of legitimate processes that can run normally on the financial host, used to distinguish between legitimate and abnormal processes. The difference report can be understood as a document recording changes in process running status, configuration parameters, etc., before and after an abnormal process exit or system restart. Newly added processes are newly started processes appearing on the financial host that are not on the process whitelist. The process graylist is a set of processes whose legitimacy cannot be determined temporarily and requires further verification. Classification and judgment can be understood as the process of identifying the legitimacy and risk level of newly added processes based on their characteristics.

[0056] Specifically, based on the business fingerprint and three-level responsibility matrix corresponding to the target financial host, the process feature dimensions in the business fingerprint and the control scope in the responsibility matrix are analyzed. Combined with the legitimate process feature library stored in the information asset data lake, processes that meet business requirements and have clearly defined responsible parties are selected to generate a process whitelist. For application processes within the whitelist, data such as running status, resource usage, and interaction behavior are collected in real time. When abnormal process exit or system restart is detected, the process running data before and after the anomaly is compared, and differences are extracted and a structured difference report is generated. If a new process is detected that is not in the whitelist, it is added to the process graylist and marked as pending verification. The dynamic characteristics of the graylist processes are extracted, and classification is performed based on these characteristics.

[0057] Based on the above technical solutions, classification and judgment are performed based on process characteristics, including: determining whether a new process is a compliant process based on the user who initiated it, the initiation path, and the business identifier corresponding to the new process; determining whether a new process is a shadow asset based on the tool attributes and unreported characteristics corresponding to the new process; and determining whether a new process is a security threat based on the legality of the initiation path and the network connection status corresponding to the new process.

[0058] Among these, compliance processes can be those that conform to the operating specifications of financial mainframes, have undergone proper registration, and have clearly defined responsible parties. Shadow assets can be understood as tool-like processes or assets that have not been registered as required and are deployed and operated privately. Security threats can be processes with malicious behavior characteristics that may damage financial mainframes or business data. Tool attributes can be understood as the tool-like functional characteristics of newly added processes, which can be used to distinguish business processes from tool processes. Unregistered characteristics can be the attribute of newly added processes that have not completed registration and filing in the information asset data lake. Startup path legality can be the degree to which the path where the startup file of a newly added process is located complies with security specifications. Network connection status can be understood as the network interaction behavior characteristics of newly added processes, used to determine whether the process has malicious data transmission behavior.

[0059] Specifically, such as Figure 3As shown, newly added processes are retrieved from the gray list, and core features such as the launching user, launching path, business identifier, tool attributes, and network connection status of each process are extracted to establish a process feature set. A compliance process judgment rule base is loaded, and the launching user permissions, launching path compliance, and business identifier validity of newly added processes are compared with the rules to determine whether they are compliant processes. Compliant processes are removed from the gray list and included in the white list. For non-compliant processes, tool attributes and reporting status information are extracted and matched with the registered asset database in the information asset data lake. If a process has tool attributes but has not completed reporting, it is determined to be a shadow asset, marked with a compliance risk level, and associated with the corresponding responsible entity. For the remaining unclassified processes, the launching path is checked to see if it complies with security control specifications, and the target address of the network connection and whether there are any anomalies in the transmission behavior are analyzed. These are compared with a malicious process feature database to determine whether they pose a security threat.

[0060] The technical solution of this invention establishes an information asset data lake corresponding to a target financial center; collects the process dynamic characteristics of financial hosts in the target financial center based on the information asset data lake; generates business fingerprints based on the process dynamic characteristics; and determines a three-level responsibility matrix based on the business fingerprints; and performs process governance on the financial hosts based on the three-level responsibility matrix and the business fingerprints. Based on the above technical solution, by collecting the process dynamic characteristics of financial hosts and generating corresponding business fingerprints, determining the responsibility matrix based on the business fingerprints, and implementing process governance based on the responsibility matrix, the financial security defense line is strengthened, the consistency between accounts and reality in information asset management is achieved, and regulatory efficiency is improved.

[0061] In one possible implementation of the present invention Figure 4 A flowchart illustrating a process management method for a financial host provided in an embodiment of the present invention is shown below. Figure 4 As shown, the steps for establishing an information asset data lake corresponding to the target financial center in this embodiment further include:

[0062] S410. Acquire multi-source heterogeneous data corresponding to the target financial center, and perform data transformation on the multi-source heterogeneous data to obtain standardized asset data.

[0063] Multi-source heterogeneous data can be collections of various data sources from different business systems and storage architectures within the target financial center. Data transformation can be understood as the process of processing multi-source heterogeneous data according to a unified standard. Standardized asset data can be financial asset data that conforms to a unified format specification.

[0064] Specifically, it involves acquiring multi-source heterogeneous data corresponding to the target financial center and transforming the multi-source heterogeneous data to obtain standardized asset data.

[0065] For example, three types of core data sources are accessed and cleaned, transformed, and loaded: Infrastructure source: basic attributes including IP address, MAC address, and operating system (OS) version are extracted from virtualization platforms and hardware ledgers; Business application source: business attributes such as system abbreviation, system level, and service period requirements are extracted from unified regulatory reporting platform, core system master table, and middleware management ledger; Organizational structure source: personnel attributes such as department code, job responsibilities, and A / B role rotation status are extracted. The collected multi-source heterogeneous data is cleaned to remove invalid, duplicate, and erroneous data, retain valid data content, and perform format conversion, structure reorganization, and field mapping operations on the preprocessed heterogeneous data according to a preset standardized conversion rule library, converting data of different formats and structures into a standardized form that conforms to a unified standard.

[0066] S420. Establish an asset knowledge graph based on standardized asset data and host identification information.

[0067] The host identification information includes address identifiers and business identifiers. An asset knowledge graph can be a visualized network of financial assets and their relationships, built upon standardized asset data and linked by host identification information. Address identifiers can be understood as characteristic information used to locate the physical or network location of a financial host. Business identifiers can be characteristic information used to distinguish the types of services carried by a financial host.

[0068] Specifically, an asset knowledge graph is established based on standardized asset data and host identification information. For example, a graph database model is built with "IP address" and "business system ID" as dual core entities. This establishes connections between scattered asset data. By parsing the address and business identifiers in the host identifiers, a preliminary mapping between identifier information and standardized asset data is established. Based on asset attributes and business affiliation information in the standardized asset data, asset features are extracted and corresponding graph nodes are generated. Simultaneously, host identification information is used as the core association attribute of the nodes, and the relationships between asset nodes, such as business associations, operational associations, and data interaction associations, are determined, generating association edges between nodes. This results in a graph database model with "IP address" and "business system ID" as dual core entities.

[0069] S430. Obtain historical asset information corresponding to the target financial center, and generate an asset historical state database based on the historical asset information and asset knowledge graph.

[0070] Historical asset information can include historical data such as asset allocation, operational status, and change records generated and stored during the target financial center's past operations. The historical asset status database can be a database that integrates historical asset information with asset knowledge graph relationships, organizing asset status according to a time dimension.

[0071] Specifically, a time dimension is introduced into the asset knowledge graph to record snapshots of every asset attribute change, building a historical state database. This allows for querying asset responsibility information at any point in time, meeting the needs of audit retrospection and historical fault determination. For example, this can be achieved by acquiring historical asset information from a target financial center, preprocessing the collected historical asset information to remove redundant and erroneous data, unifying data formats and field definitions to ensure data validity and consistency, and establishing a mapping between historical asset information and graph nodes based on asset nodes, relationships, and attribute information in the asset knowledge graph. The preprocessed historical asset information is then sorted by time dimension, binding the asset information at each time point to the corresponding graph node to determine the changes in the asset's status, attributes, and relationships at different historical periods, thereby obtaining the asset historical state database.

[0072] S440, based on standardized asset data, asset knowledge graph and asset historical status database, constitutes an information asset data lake.

[0073] Specifically, an information asset data lake is constructed based on standardized asset data, an asset knowledge graph, and an asset historical status database. For example, standardized asset data can be categorized by asset type and business affiliation and stored in the data lake's basic data partition. The asset knowledge graph is imported into the data lake's association analysis partition, establishing real-time association channels between graph nodes and standardized asset data, and configuring graph retrieval, visualization, and dynamic update functions. The asset historical status database is stored in the data lake's historical data partition by time dimension and asset category, establishing cross-partition association mappings between historical data and the asset knowledge graph and standardized asset data.

[0074] The technical solution of this invention establishes a unified data lake management platform, integrating functional modules such as data access, storage, retrieval, and analysis. It configures data security protection, access control, and quality monitoring mechanisms to ensure the stable operation and data security of the data lake. Full-function testing is then conducted on the completed information asset data lake to verify the reliability of data storage, the accuracy of related queries, and the effectiveness of management functions.

[0075] The technical solution of this invention establishes an information asset data lake corresponding to a target financial center; collects the process dynamic characteristics of financial hosts in the target financial center based on the information asset data lake; generates business fingerprints based on the process dynamic characteristics; and determines a three-level responsibility matrix based on the business fingerprints; and performs process governance on the financial hosts based on the three-level responsibility matrix and the business fingerprints. Based on the above technical solution, by collecting the process dynamic characteristics of financial hosts and generating corresponding business fingerprints, determining the responsibility matrix based on the business fingerprints, and implementing process governance based on the responsibility matrix, the financial security defense line is strengthened, the consistency between accounts and reality in information asset management is achieved, and regulatory efficiency is improved.

[0076] Figure 5 This is a schematic diagram of the structure of a process management device for a financial host provided in an embodiment of the present invention. Figure 5 As shown, the device includes: a data lake establishment module 510, a process feature extraction module 520, a responsibility matrix determination module 530, and a process governance module 540.

[0077] Data Lake Establishment Module 510 is used to establish an information asset data lake corresponding to the target financial center;

[0078] The process feature extraction module 520 is used to collect the process dynamic features of the financial host in the target financial center based on the information asset data lake;

[0079] The responsibility matrix determination module 530 is used to generate a business fingerprint based on the process dynamic characteristics and determine a three-level responsibility matrix based on the business fingerprint.

[0080] The process governance module 540 is used to perform process governance on the financial host based on the three-level responsibility matrix and the business fingerprint.

[0081] Based on the above technical solution, the data lake establishment module is used to acquire multi-source heterogeneous data corresponding to the target financial center, and to perform data transformation on the multi-source heterogeneous data to obtain standardized asset data; to establish an asset knowledge graph based on the standardized asset data and host identification information, wherein the host identification information includes address identification and business identification; to acquire historical asset information corresponding to the target financial center, and to generate an asset historical state database based on the historical asset information and the asset knowledge graph; and to construct the information asset data lake based on the standardized asset data, the asset knowledge graph, and the asset historical state database.

[0082] Based on the above technical solution, the process feature extraction module is used to read the process memory mapping file of the financial host through the data acquisition probe; obtain the startup parameter strings of the process and its parent process based on the memory mapping file, and collect the environmental information of the process during runtime to form an environmental fingerprint; and obtain the process dynamic features based on the startup parameter strings and the environmental fingerprint.

[0083] Based on the above technical solution, the responsibility matrix determination module is used to query the information asset data lake based on the address identifier in the business fingerprint to obtain administrator information, and use the administrator information as first-level responsibility information; determine a combination query key based on the business fingerprint, and query the application attribution information from the information asset data lake according to the combination query key, and use the application attribution information as second-level responsibility information; determine personnel attribution information according to the application attribution information, and use the personnel attribution information as third-level responsibility information; and construct the third-level responsibility matrix based on the first-level responsibility information, second-level responsibility information, and third-level responsibility information.

[0084] Based on the above technical solution, the responsibility matrix determination module is used to determine the target department based on the application attribution information and determine the organizational structure tree corresponding to the target department; and to determine the personnel attribution information corresponding to the current thread based on the organizational structure tree, wherein the personnel attribution information includes the main and backup operation and maintenance person in charge and the development interface person.

[0085] Based on the above technical solution, the process governance module is used to determine a process whitelist based on the business fingerprint and the three-level responsibility matrix; for application processes in the process whitelist, the module monitors the process running status in real time and generates a difference report when a process exits abnormally or the system restarts; when a new process is detected, the module adds the new process to the process graylist and classifies it based on process characteristics.

[0086] Based on the above technical solution, the process governance module is used to determine whether the newly added process is a compliant process based on the launching user, launching path, and business identifier corresponding to the newly added process; to determine whether the newly added process is a shadow asset based on the tool attributes and unreported characteristics corresponding to the newly added process; and to determine whether the newly added process is a security threat based on the legality of the launching path and the network connection status corresponding to the newly added process.

[0087] The technical solution of this invention establishes an information asset data lake corresponding to a target financial center; collects the process dynamic characteristics of financial hosts in the target financial center based on the information asset data lake; generates business fingerprints based on the process dynamic characteristics; and determines a three-level responsibility matrix based on the business fingerprints; and performs process governance on the financial hosts based on the three-level responsibility matrix and the business fingerprints. Based on the above technical solution, by collecting the process dynamic characteristics of financial hosts and generating corresponding business fingerprints, determining the responsibility matrix based on the business fingerprints, and implementing process governance based on the responsibility matrix, the financial security defense line is strengthened, the consistency between accounts and reality in information asset management is achieved, and regulatory efficiency is improved.

[0088] The process management device for a financial host provided in this embodiment of the invention can execute the process management method for a financial host provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0089] Figure 6 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0090] like Figure 6 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0091] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0092] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as process governance methods in a financial host.

[0093] In some embodiments, the process management method of the financial host can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the process management method of the financial host described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to execute the process management method of the financial host by any other suitable means (e.g., by means of firmware).

[0094] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0095] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0096] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0097] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0098] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0099] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0100] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0101] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A process management method for a financial mainframe, characterized in that, include: Establish an information asset data lake corresponding to the target financial center; Based on the information asset data lake, the process dynamic characteristics of the financial mainframes in the target financial center are collected; A business fingerprint is generated based on the process dynamic characteristics, and a three-level responsibility matrix is ​​determined based on the business fingerprint; Process governance of the financial host is performed based on the three-level responsibility matrix and the business fingerprint.

2. The method according to claim 1, characterized in that, The establishment of an information asset data lake corresponding to the target financial center includes: Acquire multi-source heterogeneous data corresponding to the target financial center, and perform data transformation on the multi-source heterogeneous data to obtain standardized asset data; An asset knowledge graph is established based on the standardized asset data and host identification information, wherein the host identification information includes address identifier and service identifier; Obtain historical asset information corresponding to the target financial center, and generate an asset historical state database based on the historical asset information and the asset knowledge graph; The information asset data lake is constructed based on the standardized asset data, the asset knowledge graph, and the asset historical state database.

3. The method according to claim 1, characterized in that, The process dynamic characteristics of the financial mainframes in the target financial center collected based on the information asset data lake include: The data acquisition probe reads the process memory-mapped file of the financial host. Based on the memory-mapped file, the startup parameter strings of the process and its parent process are obtained, and the environmental information of the process during runtime is collected to form an environmental fingerprint; Based on the startup parameter string and the environment fingerprint, the dynamic characteristics of the process are obtained.

4. The method according to claim 1, characterized in that, The step of determining the three-level responsibility matrix based on the business fingerprint includes: Based on the address identifier in the business fingerprint, the administrator information is obtained by querying the information asset data lake, and the administrator information is used as first-level responsibility information. Based on the business fingerprint, a combined query key is determined, and application ownership information is obtained from the information asset data lake according to the combined query key, and the application ownership information is used as secondary responsibility information; Based on the application attribution information, personnel attribution information is determined, and this personnel attribution information is used as third-level responsibility information; The three-level responsibility matrix is ​​constructed based on the first-level responsibility information, second-level responsibility information, and third-level responsibility information.

5. The method according to claim 4, characterized in that, The step of determining personnel affiliation information based on the application affiliation information includes: The target department is determined based on the application attribution information, and the organizational structure tree corresponding to the target department is determined. Based on the organizational structure tree, the personnel affiliation information corresponding to the current thread is determined, wherein the personnel affiliation information includes the main and backup operation and maintenance personnel and the development interface personnel.

6. The method according to claim 1, characterized in that, The process governance of the financial host based on the three-level responsibility matrix and the business fingerprint includes: A process whitelist is determined based on the business fingerprint and the three-level responsibility matrix; For application processes in the process whitelist, monitor the process running status in real time and generate a difference report when the process exits abnormally or the system restarts. If a new process is detected, the new process is added to a process gray list and classified based on process characteristics.

7. The method according to claim 6, characterized in that, The classification and determination based on process characteristics includes: Based on the launching user, launching path, and business identifier corresponding to the newly added process, determine whether the newly added process is a compliant process; Based on the tool attributes and unreported characteristics corresponding to the newly added process, determine whether the newly added process is a shadow asset; Based on the legality of the startup path corresponding to the newly added process and the network connection status, it is determined whether the newly added process is a security threat.

8. A process management device for a financial mainframe, characterized in that, include: The data lake creation module is used to create an information asset data lake corresponding to the target financial center; The process feature extraction module is used to collect the process dynamic features of the financial hosts in the target financial center based on the information asset data lake; The responsibility matrix determination module is used to generate a business fingerprint based on the process dynamic characteristics and determine a three-level responsibility matrix based on the business fingerprint. The process governance module is used to perform process governance on the financial host based on the three-level responsibility matrix and the business fingerprint.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the process management method of the financial host according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the process management method of the financial host according to any one of claims 1-7.