An asset management data whole-process information tracing method and system

CN121961615BActive Publication Date: 2026-06-26HANGZHOU FEIZHIYUN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU FEIZHIYUN INFORMATION TECH CO LTD
Filing Date
2026-03-31
Publication Date
2026-06-26

Smart Images

  • Figure CN121961615B_ABST
    Figure CN121961615B_ABST
Patent Text Reader

Abstract

The application discloses a kind of asset management data's whole-process information traceability method and system, it is related to data processing technical field.The method comprises the following steps: in response to obtaining at least one first operation data chain, determining the operation correlation degree of the first interaction group formed between the first operation party and the first operated object based on the first data change proportion of the first operation command in the first operation data chain;Determine the importance of the first candidate operation intention in the first interaction group based on the first operation word of the first operation command and the first data change proportion;Based on the operation correlation degree of the first interaction group, and the importance of each first candidate operation intention, construct the intention weight set of the first interaction group;With the first operation party and the first operated object as nodes, with intention weight set as edge, construct the data flow chart of the first operation data chain, so as to carry out operation traceability based on data flow chart.The application can improve traceability accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, specifically to a method and system for tracing the entire process of asset management data. Background Technology

[0002] In an asset management environment, accurate tracing of user actions and determination of responsibility are crucial. As asset management scales up and operational scenarios become more complex, accurately reconstructing the operational chain and clarifying the relationship between the operational subject and object have become key to ensuring asset security and meeting audit requirements.

[0003] Existing bastion host technology continuously monitors and records user actions related to asset management data, collecting key information such as operators, operation times, operation commands, and target assets. It integrates and analyzes discrete operation logs to reconstruct the operation chain and contextual relationships. In the event of a security incident or audit, it traces back the established operation chain to pinpoint the initiator of the operation command, the execution process, and related links, achieving operation tracing and accountability.

[0004] However, in complex asset management scenarios, the execution of operation commands often involves multi-level jumps and indirect calls, which makes it difficult to accurately and completely establish directed connections between nodes when constructing a traceability data structure relationship network, resulting in poor traceability accuracy. Summary of the Invention

[0005] This invention provides a method and system for tracing the entire process of asset management data, which can improve the accuracy of tracing.

[0006] A first aspect of this invention provides a method for tracing the entire process of asset management data, comprising:

[0007] In response to acquiring at least one first operation data chain, the degree of operation association between the first operator and the first operated object is determined based on the first data change ratio of the first operation command in the first operation data chain; the first operation data chain includes a plurality of first operation commands, and the first operation command includes the first operator, the first operated object, the first operation term and the first data change ratio.

[0008] The importance of the first candidate operation intent in the first interaction group is determined based on the ratio of the first operation term and the first data change of the first operation command; the first candidate operation intent is determined based on the first operation term.

[0009] Based on the operational relevance of the first interaction group and the importance of each first candidate operation intent, an intent weight set for the first interaction group is constructed; the intent weight set includes the operation intent weight of each first candidate operation intent in the first interaction group.

[0010] Using the first operator and the first operated object as nodes and the intention weight set as edges, a data flow graph of the first operation data chain is constructed to enable operation tracing based on the data flow graph.

[0011] Furthermore, the present invention also proposes determining the operational correlation degree of the first interaction group formed between the first operator and the first operated object based on the first data change ratio of the first operation command in the first operation data chain, including:

[0012] Obtain the target operation command corresponding to the first interaction group in each first operation data chain;

[0013] The absolute value of the kurtosis of the target data change ratio corresponding to each target operation command is taken after calculating the data distribution kurtosis to obtain the operation correlation degree of the first interaction group.

[0014] Furthermore, the present invention also proposes to construct an intent weight set for the first interaction group based on the operation relevance of the first interaction group and the importance of each corresponding first candidate operation intent, including:

[0015] Multiply the operation relevance of the first interaction group by the importance of the first candidate operation intent to obtain the operation intent weight of the first candidate operation intent;

[0016] Based on the operation intent weights of each first candidate operation intent, construct the intent weight set of the first interaction group.

[0017] Furthermore, the present invention also proposes determining the importance of a first candidate operation intent in a first interaction group based on the ratio of the first operation term to the first data change in the first operation command, including:

[0018] Perform semantic analysis on the first operation term to determine at least one first candidate operation intent associated with the first operation term;

[0019] Based on the first data change ratio of the first operation command, determine the subsequent impact of the first operated object executing the corresponding first operation command;

[0020] Based on the subsequent impact of the first operation command executed on the first operated object, the criticality of the first candidate operation intent in the first interaction group is determined;

[0021] The importance of the first candidate operation intent in each first interaction group is determined based on the criticality of the first candidate operation intent.

[0022] Furthermore, the present invention also proposes to perform semantic analysis on the first operation term to determine at least one first candidate operation intent associated with the first operation term, including:

[0023] Semantic analysis is performed on the first operational term to obtain the keywords of the first operational term;

[0024] Word vectors are trained on each keyword of the first operation term to obtain the word vectors of each keyword;

[0025] Cluster the word vectors of each keyword to obtain at least one first candidate operation intent associated with the first operation term.

[0026] Furthermore, the present invention also proposes determining the subsequent impact of the first operated object executing the corresponding first operation command based on the first data change ratio of the first operation command, including:

[0027] Obtain the data chain length of the first operation data chain, the average of the first change ratios of each first data before the first operation command, and the average of the second change ratios of each first data after the first operation command.

[0028] Based on the data chain length, the average of the first change ratio, and the average of the second change ratio, the subsequent impact of the first operated object executing the corresponding first operation command is determined.

[0029] Furthermore, the present invention also proposes determining the importance of the first candidate operation intent in the first interaction group based on the criticality of the first candidate operation intent in each first interaction group, including:

[0030] Obtain the criticality of each target; the criticality of a target is the criticality of the target operation intent in the target interaction group, the target interaction group is any first interaction group, and the target operation intent is any first candidate operation intent in the target interaction group;

[0031] The importance of each target's criticality is averaged to obtain the importance of the target's operational intent in the target interaction group.

[0032] Furthermore, the present invention also proposes that, after constructing a data flow graph of the first operation data chain with the first operator and the first operated object as nodes and the intention weight set as edges, it further includes:

[0033] In response to the acquisition of a newly generated second operation data chain, the abnormality of the second operation data chain is determined based on the second operation command in the second operation data chain;

[0034] In response to the fact that the anomaly degree of the second operation data chain is greater than the preset anomaly degree threshold, the second operation data chain is stored as an anomaly chain in the anomaly operation library.

[0035] Furthermore, the present invention also proposes determining the anomaly degree of the second operation data chain based on the second operation command in the second operation data chain, including:

[0036] Based on the second operation command in the second operation data chain, determine the operation intent weight of the second candidate operation intent in the second interaction group formed by the second operator and the second operated object in the second operation data chain, as well as the criticality of the second candidate operation intent in the second interaction group.

[0037] Based on the weight of the second candidate operation intention and the criticality of the second candidate operation intention, the deviation of the second interaction group is determined.

[0038] The anomaly degree of the second operational data chain is determined based on the deviation degree of the second interaction group.

[0039] A second aspect of this invention provides a full-process information traceability system for asset management data, comprising:

[0040] The correlation determination module is used to determine the operational correlation of the first interaction group formed between the first operator and the first operated object based on the first data change ratio of the first operation command in the first operation data chain in response to the acquisition of at least one first operation data chain; the first operation data chain includes a number of first operation commands, and the first operation command includes the first operator, the first operated object, the first operation term and the first data change ratio.

[0041] The importance determination module is used to determine the importance of the first candidate operation intent in the first interaction group based on the ratio of the first operation term and the first data change of the first operation command; the first candidate operation intent is determined based on the first operation term.

[0042] The weight determination module is used to construct an intent weight set for the first interaction group based on the operation relevance of the first interaction group and the importance of each corresponding first candidate operation intent; the intent weight set includes the operation intent weight of each first candidate operation intent in the first interaction group;

[0043] The flow graph construction module is used to construct a data flow graph of the first operation data chain with the first operator and the first operated object as nodes and the intention weight set as edges, so as to enable operation tracing based on the data flow graph.

[0044] The present invention has the following beneficial effects:

[0045] In the full-process information traceability method for asset management data provided in this embodiment of the invention, firstly, in response to the acquired first operation data chain, the operation correlation degree of the first interaction group consisting of the first operator and the first operated object is determined based on the first data change ratio of the first operation command, which can more accurately grasp the actual relationship between the operation subject and the object; then, the importance of the first candidate operation intent in the first interaction group is determined based on the first operation term and the first data change ratio, which can deeply explore the intent information behind the operation; then, an intent weight set is constructed based on the operation correlation degree and the importance of each first candidate operation intent, which can comprehensively consider operation correlation and intent factors; finally, a data flow graph is constructed with the operator and the operated object as nodes and the intent weight set as edges. In this way, the construction method of this data flow graph fully considers multiple factors such as operation correlation and operation intent, and can more accurately and completely establish the connection relationship between nodes, thereby improving the accuracy of operation traceability. Attached Figure Description

[0046] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0047] Figure 1 This is a flowchart illustrating a method for tracing the entire process of asset management data, provided in one embodiment of the present invention.

[0048] Figure 2 This is a schematic diagram illustrating the process of determining the importance of a candidate operation intent according to an embodiment of the present invention.

[0049] Figure 3 This is a schematic diagram of the structure of a full-process information traceability system for asset management data provided in an embodiment of the present invention. Detailed Implementation

[0050] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a full-process information traceability method and system for asset management data proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0052] In asset management environments, the frequent occurrence of multi-level jumps and indirect calls during the execution of operational commands makes it difficult to accurately and completely establish directed connections between nodes in the operational traceability data structure network. Consequently, the accuracy of operational traceability is reduced, and the complete reconstruction of the operational chain and the accurate delineation of responsible parties are affected.

[0053] For example, in a financial institution's asset management platform, operations personnel may perform database configuration modifications via a bastion host. This operation, triggered by an automated script, calls third-party API services, indirectly affecting the status of several related assets. While the direct operation commands and target assets are captured in the logs, the indirect call paths within the operation chain are not clearly reflected. Furthermore, during a security incident, the complete association between the initial operator and the final manipulated object cannot be accurately identified, leading to confusion between the operator and the object of the operation, and unclear definitions of the relationship between the parties.

[0054] If these issues are not addressed, missing connections and incorrect orientations will exist in the operational tracing data structure, making it impossible to reconstruct the operational context during security incident investigations and compliance audits. This could lead to errors in attribution of responsibility and failures in security vulnerability tracking, thereby threatening asset security and system integrity, while also increasing compliance risks.

[0055] In this regard, such as Figure 1 As shown, this invention provides a flowchart of a method for tracing the entire process of asset management data. This method can be applied to electronic devices and includes the following steps S110 to S140:

[0056] S110, in response to acquiring at least one first operation data chain, based on the first data change ratio of the first operation command in the first operation data chain, determine the operation correlation degree of the first interaction group formed between the first operator and the first operated object; the first operation data chain includes a plurality of first operation commands, and the first operation command includes the first operator, the first operated object, the first operation term and the first data change ratio.

[0057] S120, based on the ratio of the first operation term and the first data change of the first operation command, determine the importance of the first candidate operation intent in the first interaction group; the first candidate operation intent is determined based on the first operation term.

[0058] S130, Based on the operation relevance of the first interaction group and the importance of each first candidate operation intent, construct an intent weight set for the first interaction group; the intent weight set includes the operation intent weight of each first candidate operation intent in the first interaction group;

[0059] S140, with the first operator and the first operated object as nodes and the intention weight set as edges, construct a data flow graph of the first operation data chain so as to enable operation tracing based on the data flow graph.

[0060] For ease of understanding, the following explains some key terms in this embodiment:

[0061] The first operational data chain refers to a sequence of related operational commands during asset management. This data chain records the complete process of operating on a specific asset or data, such as a continuous record of operations like creating, modifying, and deleting a file.

[0062] The first operation command refers to the basic unit constituting the first operation data chain, representing a specific action performed by the operator on the operated object. This command includes information such as the operator, the operated object, the operation terms, and the proportion of data change caused by the operation.

[0063] First data change ratio: This refers to the degree or magnitude of change in the relevant data of the operated object after the first operation command is executed. This ratio can quantify the impact of the operation on the asset status, such as changes in file size or increases or decreases in the number of database records.

[0064] First operator: refers to the entity that executes the first operation command, which can be a user, system process, or automated script, etc.

[0065] The first object to be operated on: refers to the target of the first operation command, which can be assets, data, system configuration, etc.

[0066] The first interaction group refers to the pair of operational entities formed between the first operator and the first operated object. This interaction group represents the smallest unit of action of the operation and is used to analyze the relationship between the operator and the operated object.

[0067] Operational relevance: refers to the closeness or correlation of the operational behaviors between the first operator and the first operated object in the first interaction group. This relevance reflects the frequency, intensity, or importance of a specific operator's operation on a specific operated object.

[0068] First operation term: This refers to the textual information in the first operation command that describes the operation behavior, such as "modify file", "delete record", "update configuration", etc. This term is the basis for understanding the operation intent.

[0069] First candidate operational intent: refers to the potential operational purpose that may represent the true intent of the first operator, obtained based on the analysis of the first operational term. One operational term may correspond to multiple candidate operational intents.

[0070] Importance: This refers to the criticality or influence of a particular candidate operational intent within the first interaction group on the overall operational behavior. This importance reflects the potential impact of that candidate operational intent on asset management processes or security status.

[0071] Intent Weight Set: For a specific first interaction group, this set contains all first candidate operation intents and their corresponding operation intent weights. This set quantifies the relative importance of different operation intents within the current first interaction group.

[0072] Operation Intent Weight: This refers to the numerical value assigned to each first candidate operation intent in the intent weight set, which is used to represent the relative importance or influence of the first candidate operation intent in a specific first interaction group.

[0073] Data flow diagram: This refers to a graphical structure constructed with the first operator and the first operated object as nodes and the set of intent weights as edges. This diagram intuitively shows the flow path, operational relationships, and weights of operational intents of asset management data between different operators and operated objects, thereby supporting operation traceability.

[0074] Operational tracing: This refers to analyzing data flow diagrams to trace the source, process, and impact of asset management data operations in reverse, in order to clarify responsibilities, identify anomalies, or conduct audits.

[0075] This embodiment provides a method for tracing the entire process of asset management data. This method achieves accurate tracing of complex operational behaviors by constructing a data flow diagram.

[0076] First, in response to acquiring at least one first operation data chain, the operational correlation degree of the first interaction group formed between the first operator and the first operated object is determined based on the first data change ratio of the first operation commands in the first operation data chain. A first operation data chain can be viewed as a series of operation records arranged in chronological order, where each first operation command records in detail the operator, the operated object, the operation term, and the data change ratio caused by the operation. For example, when user A performs multiple file operations on server B, these operations form a first operation data chain. To determine the operational correlation degree of the first interaction group formed by user A and server B, statistical analysis can be performed on the first data change ratios in all relevant first operation commands. This operational correlation degree reflects the activity level of the operational behavior between user A and server B.

[0077] Secondly, based on the first operation term and the first data change ratio of the first operation command, the importance of the first candidate operation intent in the first interaction group is determined. The first candidate operation intent is the potential operation purpose inferred from the first operation terms of all first operation commands related to the first interaction group. To determine the importance of these first candidate operation intents, the first data change ratio of all first operation commands related to the first interaction group can be analyzed.

[0078] Next, based on the operational relevance of the first interaction group and the importance of each corresponding first candidate operational intent, an intent weight set for the first interaction group is constructed. The intent weight set includes all first candidate operational intents in the first interaction group and their corresponding operational intent weights. For example, if the interaction group between user A and server B has a high operational relevance, and the first candidate operational intent "system optimization" is determined to have a high importance, then the operational relevance and importance can be simply summed to obtain the operational intent weight for "system optimization" in the first interaction group. In this way, a quantified weight value can be calculated for each first candidate operational intent, thus forming a complete intent weight set.

[0079] Finally, using the first operator and the first operated object as nodes, and the intent weight set as edges, a data flow graph of the first operation data chain is constructed to enable operation tracing based on this data flow graph. In the data flow graph, each first operator and the first operated object is abstracted as a node. For example, user A is a node, and server B is also a node. User A's first candidate operation intent on server B, and the operation intent weight contained in the first candidate operation intent, are represented as the edge connecting the user A node and the server B node. This edge not only indicates the direction of the operation (from the operator to the operated object) but also carries the rich semantic information provided by the intent weight set. In this way, a directed graph containing nodes and weighted edges can be constructed, which clearly shows the flow path and operation intent of asset management data between different entities, thus providing an intuitive and structured basis for subsequent operation tracing.

[0080] The following example will provide a more detailed explanation of the above technical solution:

[0081] Suppose that in an asset management system, it is necessary to trace user operations on servers. Specifically, user A logs into the target server (server C) through a jump server (jump server B) and modifies a critical configuration file (file D) on server C. This operation generates a series of operation logs, which constitute the first operation data chain.

[0082] First, the system responds by acquiring the first operation data chain. This data chain contains multiple first operation commands, such as "User A logs into jump server B," "User A connects to server C through jump server B," and "User A modifies file D on server C." Each first operation command records the operator, the operated object, the operation term, and the percentage of data change caused by the operation. For example, in the command "User A modifies file D on server C," the operator is user A, the operated object is file D, the operation term is "modify configuration file," and the first data change percentage might be the checksum change value of file D.

[0083] Next, based on the first data change ratio of the first operation command in the first operation data chain, the system determines the operational correlation degree of the first interaction group formed between the first operator and the first operated object. Specifically, the system will identify multiple first interaction groups, such as "User A-Jump Host B", "User A-Server C", "Jump Host B-Server C", "User A-File D", etc. For the "User A-File D" interaction group, the system will calculate the average data change ratio of User A's operations on File D over a period of time. For example, if User A modifies File D multiple times in a short period of time, and each modification results in a large data change ratio of File D, then the operational correlation degree of the "User A-File D" interaction group will be determined to be high.

[0084] Then, based on the ratio of the first operation term to the first data change in the first operation command, the system determines the importance of the first candidate operation intent in the first interaction group. Taking "User A modifies file D on server C" as an example, its operation term is "modify configuration file". The system will associate "modify configuration file" with multiple first candidate operation intents according to the preset term-intent mapping table, such as "system maintenance", "security configuration update" or "troubleshooting", and at the same time, the system will assign importance to these first candidate operation intents.

[0085] Subsequently, the system constructs an intent weight set for the first interaction group based on the operational relevance of the first interaction group and the importance of each corresponding first candidate operation intent. For example, for the "User A - File D" interaction group, if its operational relevance is high and the "Security Configuration Update" intent has high importance, the system will simply sum the two to obtain the operation intent weight of "Security Configuration Update" in this interaction group. Similarly, other candidate intents such as "System Maintenance" will also have their corresponding operation intent weights calculated. Finally, an intent weight set is formed that includes intents such as "Security Configuration Update" and "System Maintenance" and their corresponding weights.

[0086] Finally, the system constructs a data flow graph for the first operation data chain, using the first operator and the first operated object as nodes and the intent weight set as edges. In this example, user A, jump server B, server C, and file D will all be nodes in the graph. The login operation from user A to jump server B, the connection operation from jump server B to server C, and the modification operation from user A to file D will all be edges in the graph. The edge connecting the user A node and the file D node will carry the intent weight set calculated above. This data flow graph intuitively shows the complete path of user A operating on file D on server C through jump server B, as well as the possible intents and their weights behind the operation. When operation tracing is required, such as discovering that file D has been abnormally modified, the data flow graph can clearly trace user A as the operator, jump server B as the intermediate link, server C as the host environment, and the possible intents corresponding to the operation (e.g., "security configuration update" or "system maintenance"), thereby achieving accurate reconstruction and responsibility identification of complex operation chains.

[0087] Based on the above examples, the technical solution of this embodiment demonstrates a significant technical contribution in addressing the operation tracing problem in complex asset management scenarios. Existing technologies often struggle to accurately and completely establish a data structure relationship network when handling operations involving multi-level jumps and indirect calls, leading to insufficient tracing accuracy. For example, in the scenario where user A modifies file D on server C through jump server B, traditional methods may only record logs of user A logging into jump server B and jump server B connecting to server C, but it is difficult to effectively quantify and correlate the direct operational intent and correlation strength between user A and file D.

[0088] This embodiment effectively overcomes the limitations of existing technologies by introducing the concepts of operation relevance, the importance of the first candidate operation intent, and the intent weight set, and constructing a data flow graph based on these. Specifically:

[0089] First, by determining the degree of operational correlation between the first operator and the first operated object, this embodiment can quantify the intensity of interaction between the operator and the object. In the example above, by calculating the proportion of data changes of user A to file D, a high degree of operational correlation can be obtained for the "user A-file D" interaction group, which reflects the closeness of the operational behavior between the two more effectively than simply recording operation logs.

[0090] Secondly, by determining the importance of the first candidate operation intent based on the operation term and the proportion of data changes, this embodiment can delve deeper into the potential purpose behind the operation behavior. In the example, the operation term "modify configuration file" is associated with intents such as "system maintenance" and "security configuration update" and assigned importance, so that the tracing goes beyond "what was done" and further explores "why it was done", thus providing deeper contextual information.

[0091] Furthermore, by combining the relevance of operations with the importance of intents to construct an intent weight set, this embodiment endows the edges of the data flow graph with rich semantic and quantitative information. In the example, the edge connecting user A and file D is no longer a simple presence or absence relationship, but includes intents such as "security configuration update" and "system maintenance" and their corresponding weights. These weighted edges enable the data flow graph to more accurately reflect the nature and impact of operations, especially in multi-level jumps and indirect call scenarios, more clearly revealing the true relationship between the operator and the final operated object.

[0092] Therefore, the data flow graph constructed in this embodiment, with the operator and the operated object as nodes and the set containing intent weights as edges, forms a semantically rich and structured tracing model. This model can effectively handle multi-level jumps and indirect calls in complex operation chains. By quantifying operation correlation and operation intent, it achieves accurate reconstruction and in-depth analysis of operation behavior. Compared with existing technologies that rely solely on discrete logs for simple correlation, this embodiment can provide more insightful operation path and intent analysis, significantly improving the accuracy and efficiency of information tracing throughout the entire asset management data process, and providing more solid technical support for responsibility definition and security auditing.

[0093] In this embodiment, firstly, in response to the acquired first operation data chain, the operation correlation degree of the first interaction group consisting of the first operator and the first operated object is determined based on the first data change ratio of the first operation command, which can more accurately grasp the actual relationship between the operation subject and the object. Next, the importance of the first candidate operation intent in the first interaction group is determined based on the first operation term and the first data change ratio, which can delve deeper into the intent information behind the operation. Then, an intent weight set is constructed based on the operation correlation degree and the importance of each first candidate operation intent, which can comprehensively consider operation correlation and intent factors. Finally, a data flow graph is constructed with the operator and the operated object as nodes and the intent weight set as edges. Thus, this data flow graph construction method fully considers multiple factors such as operation correlation and operation intent, and can more accurately and completely establish the connection relationship between nodes, thereby improving the accuracy of operation tracing.

[0094] In some embodiments of the present invention described above, a method is proposed to determine the operational correlation degree of the first interaction group formed between the first operator and the first operated object based on the first data change ratio of the first operation command in the first operation data chain. If the operational correlation degree is determined solely based on a single or simple first data change ratio, it may not adequately reflect the integrity and stability of the operation, and is easily affected by occasional data fluctuations, leading to an inaccurate assessment of the operational correlation degree, which in turn affects the reliability of subsequent operation intent identification and tracing results.

[0095] In this regard, the present invention further proposes that S110 includes:

[0096] Obtain the target operation command corresponding to the first interaction group in each first operation data chain;

[0097] The absolute value of the kurtosis of the target data change ratio corresponding to each target operation command is taken after calculating the data distribution kurtosis to obtain the operation correlation degree of the first interaction group.

[0098] In this embodiment, the target operation commands corresponding to the first interaction group in each first operation data chain are obtained. This step aims to accurately filter out all operation commands related to a specific operator and the operated object (i.e., the first interaction group) from historical operation records. The purpose is to provide a comprehensive and accurate dataset for subsequent statistical analysis. Specifically, an operation log database can be established, recording detailed information for each operation, including the operator, the operated object, the operation term, and the data change ratio. When it is necessary to calculate the operation correlation degree of a certain first interaction group, the system can query this database and retrieve all relevant operation commands based on the identifiers of the first operator and the first operated object.

[0099] The kurtosis calculation is performed on the proportion of target data changes corresponding to each target operation command. This step involves statistical analysis of the proportion of data changes associated with the acquired target operation commands to quantify the concentration or dispersion of these data changes. Kurtosis is an important indicator of the shape of data distribution, describing how "peaked" or "flat" the data distribution is. A high kurtosis value usually means that the data is concentrated around the mean, indicating a certain consistency or specific pattern in the operation behavior. Conversely, a low kurtosis value may indicate a more dispersed data distribution. Various statistical methods can be used to calculate kurtosis; for example, Pearson's kurtosis coefficient or Fisher's kurtosis coefficient can be used.

[0100] The operational relevance of the first interaction group is obtained by taking the absolute value of the aforementioned kurtosis calculation as the operational relevance of the first interaction group. This operational relevance value is a quantitative indicator that reflects the strength and stability of the intrinsic connection between the operational behaviors of a specific operator and the operated object. For example, a higher kurtosis value may be interpreted as the operational behaviors of the first interaction group having a high degree of consistency and predictability, thus corresponding to a higher operational relevance; while a lower kurtosis value may indicate that the operational behaviors are more random or scattered, corresponding to a lower operational relevance. This quantified operational relevance will serve as an important input parameter for subsequently constructing the intent weight set.

[0101] The present invention determines the operational correlation of the first interaction group more accurately by calculating the kurtosis of the data change ratio corresponding to the target operation command in the first operation data chain. Specifically, after acquiring at least one first operation data chain, to overcome the inaccuracies that may arise from simple data change ratios, this solution first acquires all target operation commands corresponding to the first interaction group consisting of a specific first operator and a first operated object from all relevant first operation data chains. This step ensures that the data foundation for subsequent analysis is comprehensive and targeted. Subsequently, the absolute value of the kurtosis of the target data change ratios contained in these target operation commands is calculated. Kurtosis, as a statistical measure, can effectively measure the concentration and tail characteristics of data distribution, i.e., whether the data change is highly concentrated within a certain range or exhibits a more dispersed pattern. By calculating kurtosis, the inherent laws and stability of the operational behavior of the first interaction group can be revealed more deeply. For example, a high kurtosis value indicates that the operational behavior of the first interaction group exhibits a high degree of consistency and pattern in data changes, suggesting a strong operational correlation. Conversely, a low kurtosis value may indicate that the operational behavior is more random or diverse, suggesting a relatively weak operational correlation. This method based on statistical kurtosis analysis, compared to directly using single or simply aggregated data change ratios, can more accurately and robustly quantify operational correlation, effectively avoiding the interference of occasional data fluctuations on correlation assessment. Therefore, the more accurate operational correlation obtained will serve as a reliable basis for constructing the intent weight set, thereby making the overall process of operational tracing based on data flow diagrams more precise and reliable, significantly improving the reliability and depth of asset management data tracing.

[0102] Specifically, the operational relevance of the first interaction group can be determined using the following formula 1:

[0103] Formula 1

[0104] In formula 1, Used to characterize the degree of operational association between the i-th operator and the j-th operated object in the interaction group. The set used to characterize the proportion of data changes between each operation command between the i-th operator and the j-th operated object. A function used to characterize the kurtosis.

[0105] The following example illustrates this. Suppose that in an asset management system, it is necessary to trace the actions of "User A" on "Asset B". First, the system will retrieve all operation commands related to "User A" on "Asset B" from historical operation records. These operation commands constitute the "target operation commands" of the "first interaction group". For example, these commands might include: "User A" adjusts the inventory quantity of "Asset B" from 100 to 90 on a certain day (data change ratio -10%), adjusts it to 95 the next day (data change ratio +5%), then performs a maintenance operation, updating the asset status from "normal" to "maintaining" (data change ratio 0%), and a scrap operation, adjusting the asset quantity from 95 to 0 (data change ratio -100%). The system will collect these data change ratios (e.g., -10%, +5%, 0%, -100%). It should be understood that parsing the operation log or Binlog will extract the values ​​of the operated fields (such as "inventory quantity") of "Asset B" before the operation was executed. and the value after the operation is performed For example, before adjustment After adjustment The percentage change in the data of this operation command ,For example (i.e., -10%). If In this case, the ratio should be set directly to 1 to avoid division by zero. Furthermore, for changes to non-numeric fields, they are mapped to the corresponding numerical change ratio according to preset business rules. These preset business rules include: pre-constructing a status mapping table or change level table, which defines the quantified values ​​(change ratios) corresponding to different non-numeric fields as they transition between different states. For example, a status change that renders an asset unusable (such as scrapping) is mapped to a change ratio of 1.0, a temporary status change (such as maintenance) is mapped to a change ratio of 0.1, and a change involving only descriptive information is mapped to a change ratio of 0.

[0106] Next, the system calculates the kurtosis of the collected data change ratio sequences. This calculation yields a kurtosis value, which quantifies the concentration of data changes caused by these operations. This value represents the "operational correlation" between "User A" and "Asset B." This operational correlation value is then used to construct subsequent intent weight sets, thereby more accurately analyzing "User A's" true operational intent and behavioral patterns regarding "Asset B."

[0107] Through the above technical solution, this invention overcomes the inaccuracy problem that traditional methods may have in determining operational correlation. By acquiring the target operation commands corresponding to a specific interaction group and calculating the kurtosis of the data variation ratio of these commands, the inherent statistical characteristics of the operation behavior can be more deeply explored, resulting in a more accurate and robust operational correlation. This correlation based on statistical kurtosis analysis can effectively filter out the influence of occasional or random data fluctuations, making the determined operational correlation more accurately reflect the long-term and stable interaction pattern between the operator and the operated object. Therefore, in the subsequent construction of the intent weight set and data flow graph, the accuracy of operation intent recognition and the reliability of data traceability can be significantly improved based on more reliable correlation information, providing more accurate decision support for asset management.

[0108] In some embodiments of the present invention described above, an intent weight set is proposed to be constructed based on the operation relevance of the first interaction group and the importance of the first candidate operation intent. However, in practical applications, how to effectively combine the operation relevance and the importance of the operation intent to quantitatively represent the actual weight of each candidate operation intent, thereby more accurately reflecting the true intent of the interaction between the operator and the operated object, and providing accurate edge weights for the subsequent construction of the data flow graph, remains a problem that needs to be solved.

[0109] In this regard, the present invention further proposes that S130 includes:

[0110] Multiply the operation relevance of the first interaction group by the importance of the first candidate operation intent to obtain the operation intent weight of the first candidate operation intent;

[0111] Based on the operation intent weights of each first candidate operation intent, construct the intent weight set of the first interaction group.

[0112] In this embodiment, the operational relevance of the first interaction group is multiplied by the importance of the first candidate operational intent to obtain the operational intent weight of the first candidate operational intent. This step aims to integrate two key indicators—the operational relevance of the first interaction group and the importance of the first candidate operational intent—into a single, comprehensive quantitative indicator, namely, the operational intent weight, through mathematical operations. Operational relevance reflects the closeness or frequency of interaction between the first operator and the first operated object, while importance measures the intrinsic value or potential impact of a specific operational intent. Through multiplication, it can be intuitively shown that when the relevance of an interaction group is high and the importance of a certain operational intent is also high, the weight of that operational intent will be amplified accordingly, and vice versa. In a specific implementation, the operational relevance value and the importance value can be directly multiplied to obtain the operational intent weight.

[0113] Based on the operation intent weights of each first candidate operation intent, an intent weight set for the first interaction group is constructed. This step aims to systematically organize and store all first candidate operation intents and their corresponding operation intent weights for a specific first interaction group, forming a complete intent weight set. This set is a key component in the subsequent construction of the data flow graph, providing quantified attribute information for the edges in the data flow graph.

[0114] The present invention obtains the operation intention weight of each first candidate operation intention directly and quantitatively by multiplying the operation relevance of the first interaction group with the importance of the first candidate operation intention. This multiplicative approach ensures that the operation intention weight not only reflects the inherent importance of the operation intention itself but also incorporates the closeness of the interaction between the operator and the operated object. For example, when the operation relevance is high, even if the importance of a certain operation intention is average, its final operation intention weight will be relatively high, indicating that the operation intention has stronger practical significance in this high-frequency interaction; conversely, if the operation relevance is low, even if the importance of the operation intention is high, its weight will be appropriately suppressed, avoiding excessive attention to infrequent interaction intentions. Subsequently, these operation intention weights of all first candidate operation intentions for a specific first interaction group are aggregated to form the intention weight set of that first interaction group. This intention weight set comprehensively reflects the combined influence of all potential operation intentions between the first operator and the first operated object, providing accurate and insightful quantitative basis for subsequently constructing a data flow graph with the intention weight set as edges. In this way, the edges in the data flow graph can more accurately represent the actual intensity and intention of the interaction between the operator and the operated object, thereby significantly improving the accuracy and effectiveness of information traceability throughout the entire asset management data process.

[0115] Specifically, the weight of the operational intent can be determined using the following formula 2:

[0116] Formula 2

[0117] In formula 2, The operation intent weight is used to characterize the x-th candidate operation intent between the i-th operator and the j-th operated object. Used to characterize the importance of the x-th candidate operation intent between the i-th operator and the j-th operated object. This is used to characterize the degree of operational association between the i-th operator and the j-th operated object in the interaction group.

[0118] The following is a concrete example to illustrate this. Assume there exists a first interaction group consisting of the first operating party, "Finance Department," and the first operated object, "Asset Ledger." Analysis determines the operational relevance of this first interaction group to be 0.85. For this interaction group, two main first candidate operational intentions are identified: "Asset Inbound" and "Asset Transfer." After importance determination, the importance of the intention "Asset Inbound" is 0.9, and the importance of the intention "Asset Transfer" is 0.6. According to the scheme of this invention, firstly, the operational intention weight of each first candidate operational intention is calculated: for the intention "Asset Inbound," its operational intention weight = operational relevance × importance = 0.85 × 0.9 = 0.765. For the intention "Asset Transfer," its operational intention weight = operational relevance × importance = 0.85 × 0.6 = 0.51. Subsequently, based on these calculated operational intention weights, a set of intention weights for this first interaction group is constructed. This set can be represented as: {"Asset Inbound": 0.765, "Asset Transfer": 0.51}. This set clearly quantifies the relative importance of the different operational intentions between the "finance department" and the "asset ledger," providing specific edge weight values ​​for the subsequent construction of the data flow diagram.

[0119] Through the above technical solution, this invention provides a clear and quantifiable method to combine operational relevance with the importance of operational intent, thereby obtaining more representative operational intent weights. This direct multiplication operation avoids fuzzy judgments or complex models, enabling the actual influence of each first candidate operational intent to be accurately calculated. By aggregating these quantified operational intent weights, the constructed intent weight set can more comprehensively and accurately reflect the true intent and intensity of the interaction between the first operator and the first operated object. This provides a solid and refined foundation for the subsequent construction of data flow diagrams, enabling clearer identification of key operational paths and potential risk points when tracing operations based on data flow diagrams, significantly improving the accuracy and efficiency of tracing.

[0120] In some embodiments of the present invention, a method for tracing the entire process of asset management data is proposed. However, when determining the importance of the first candidate operation intent in the first interaction group, this method relies solely on a single dimension—either operation terms or data change ratios—to assess the importance of the operation intent. This may not fully reflect the true intent of the operation and its impact on asset data, leading to biased tracing results. Therefore, how to comprehensively consider the semantic information of the operation command and its actual data impact to more accurately assess the importance of the operation intent is a current technological challenge.

[0121] In this regard, such as Figure 2 As shown, the present invention further proposes that S120 includes the following S121 to S124:

[0122] S121, Perform semantic analysis on the first operation term to determine at least one first candidate operation intent associated with the first operation term;

[0123] S122, based on the first data change ratio of the first operation command, determine the subsequent impact of the first operated object executing the corresponding first operation command;

[0124] S123, based on the subsequent impact of the first operated object executing the corresponding first operation command, determine the criticality of the first candidate operation intent in the first interaction group;

[0125] S124, based on the criticality of the first candidate operation intent in each first interaction group, determine the importance of the first candidate operation intent in the first interaction group.

[0126] In this embodiment, semantic analysis is performed on the first operation term to determine at least one first candidate operation intent associated with the first operation term. This step aims to reveal the underlying operation intent by gaining a deeper understanding of the meaning of the first operation term. Semantic analysis can be implemented using various techniques. For example, natural language processing techniques can be used to segment the operation term, tag it with parts of speech, and identify named entities to extract core keywords and infer related operation intents. Alternatively, a domain-specific ontology knowledge base or dictionary can be constructed to match the first operation term with predefined operation intents to identify at least one first candidate operation intent associated with the operation term.

[0127] Based on the first data change ratio of the first operation command, the subsequent impact of the first operated object executing the corresponding first operation command is determined. This step is used to quantify the actual impact of a specific operation on the data of the operated object. The subsequent impact can be calculated based on the first data change ratio.

[0128] Based on the subsequent impact of executing the corresponding first operation command on the first operated object, the criticality of the first candidate operation intent in the first interaction group is determined. This step aims to evaluate the importance or coreness of each first candidate operation intent in a specific operation context. The determination of criticality can be based on a mapping of subsequent impact, where the higher the subsequent impact, the higher the criticality of the corresponding first candidate operation intent. Specifically, for a first operation term in a first operation command corresponding to the first interaction group, if it has only one associated first candidate operation intent, the corresponding subsequent impact can be directly assigned to the criticality; if it has multiple associated first candidate operation intents, the corresponding subsequent impact is assigned to the criticality of the first candidate operation intent according to the semantic similarity between the first candidate operation intent and the first operation term (e.g., similarity calculation based on word vectors or pre-trained language models), according to weights.

[0129] Based on the criticality of the first candidate operation intent in each first interaction group, the importance of the first candidate operation intent in the first interaction group is determined. This step aims to comprehensively consider the criticality of all first candidate operation intents within the first interaction group, thereby deriving a final importance assessment for each first candidate operation intent. The determination of importance can employ various aggregation methods; for example, a weighted average of the criticality of all first candidate operation intents can be used. This approach comprehensively reflects the relative importance of each first candidate operation intent within the entire interaction group.

[0130] The present invention combines the semantic information of operation terms with the actual impact of operations on data to determine the importance of first candidate operation intentions in a first interaction group in a multi-dimensional and more accurate manner. Specifically, firstly, semantic analysis is performed on the first operation term to understand the potential meaning of the operation at the textual level, thereby identifying at least one first candidate operation intention associated with the operation term. This step provides basic semantic clues for subsequent intention evaluation. Secondly, based on the first data change ratio of the first operation command, the subsequent impact of the first operated object executing the corresponding first operation command is quantified. This step focuses on the actual effect of the operation, i.e., the degree of change at the data level, providing an objective basis for evaluating the actual importance of the operation. Next, the criticality of the first candidate operation intentions in the first interaction group is determined using the aforementioned subsequent impact as input. This means that the greater the impact of the operation on the data, the more critical the operation intention it represents. Finally, by comprehensively considering the criticality of each first candidate operation intention in the first interaction group, the importance of each first candidate operation intention is ultimately determined. Through this progressive and interconnected evaluation mechanism, this solution overcomes the limitations of single-dimensional evaluation, ensuring that the determined importance of operational intent not only reflects the surface semantics of the operation but also incorporates its profound impact on asset data. This lays a solid foundation for building a more accurate set of intent weights and data flow diagrams, significantly improving the accuracy and reliability of asset management data traceability.

[0131] The following example illustrates this. Suppose that in an asset management system, there exists a first operation command: "User A changes the status of device 'XYZ001' from 'in use' to 'scrap,' causing the asset value to change from 10,000 yuan to 0 yuan." First, semantic analysis is performed on the first operation term "modify." Using a natural language processing model, at least one first candidate operation intent associated with "modify" can be identified, such as "status change," "asset disposal," or "value adjustment." Second, based on the first data change ratio of "asset value changing from 10,000 yuan to 0 yuan" in the first operation command, the subsequent impact of executing the corresponding first operation command on the first operated object (asset number 'XYZ001') is determined. Since the asset value changes from 10,000 yuan to 0 yuan, this is a significant data change, and its change ratio can be calculated as 100%, thus determining a high subsequent impact. Next, based on the above high subsequent impact, the criticality of the first candidate operation intent in the first interaction group is determined. For example, the criticality of the intentions "Status Change" and "Asset Disposal" will significantly increase due to the complete zeroing of asset value, while the criticality of "Value Adjustment" will also increase accordingly. Finally, based on the criticality of the first candidate operation intention in each first interaction group, the importance of the first candidate operation intention in the first interaction group is determined. For example, the final importance of "Status Change," "Asset Disposal," and "Value Adjustment" can be obtained by weighted average or priority ranking. For example, "Asset Disposal" may be assigned the highest importance because it directly leads to the zeroing of asset value.

[0132] Through the above technical solution, this invention can comprehensively consider the semantic information of the operation terms and the actual impact of the operation on the data, thereby more comprehensively and accurately determining the importance of the first candidate operation intent in the first interaction group. This multi-dimensional and refined evaluation method effectively solves the problem of inaccurate intent identification or biased importance assessment that may be caused by single-dimensional evaluation in traditional methods. Therefore, the constructed intent weight set can more realistically reflect the deep intent of the operation, thus providing a more accurate and reliable tracing path and explanation when tracing the source of operations based on the data flow graph, greatly improving the depth and credibility of asset management data tracing.

[0133] In some embodiments of the present invention described above, it is necessary to determine the importance of the first candidate operation intent in the first interaction group based on the ratio of the first operation term to the first data change in the first operation command. Semantic analysis of the first operation term to determine the associated first candidate operation intent is a crucial step. However, simple semantic analysis alone may not accurately capture the deep semantic information contained in the operation term, resulting in insufficiently precise or comprehensive identification of candidate operation intents. This affects the accuracy of subsequent operation intent importance determination, and consequently, the effectiveness of data flow graph construction and operation tracing.

[0134] In this regard, the present invention further proposes that S121 includes:

[0135] Semantic analysis is performed on the first operational term to obtain the keywords of the first operational term;

[0136] Word vectors are trained on each keyword of the first operation term to obtain the word vectors of each keyword;

[0137] Cluster the word vectors of each keyword to obtain at least one first candidate operation intent associated with the first operation term.

[0138] In this embodiment, semantic analysis is performed on the first operational term to obtain its keywords. This step aims to extract the smallest unit with actual semantic content, i.e., keywords, from the original first operational term. These keywords are the basis for understanding the operational intent. For example, word segmentation algorithms in natural language processing can be used to decompose the operational term into independent words, and combined with stop word filtering, part-of-speech tagging, and other methods, keywords with actual meaning can be selected.

[0139] The first step involves training word vectors for each keyword in the first operation term, resulting in word vectors for each keyword. The purpose of this step is to convert discrete keywords into continuous, low-dimensional numerical vector representations, i.e., word vectors. Word vectors capture the semantic relationships between words, ensuring that semantically similar words are close in distance within the vector space. For example, classic word embedding models such as Word2Vec and GloVe can be used, trained on large-scale corpora, to generate a fixed-dimensional vector for each keyword.

[0140] Clustering the word vectors of each keyword yields at least one first candidate operational intent associated with the first operational term. This step aims to identify sets representing different operational intents by grouping the word vectors of the keywords. Since semantically similar word vectors are close in distance in the vector space, clustering algorithms can group these word vectors into one class, and each class can represent a potential operational intent. For example, clustering algorithms such as K-means and DBSCAN can be used to group word vectors based on distance or density.

[0141] The present invention employs multi-level semantic processing on the first operational term to more accurately identify its associated first candidate operational intent. First, semantic analysis is performed on the original first operational term, the core of which lies in decomposing complex textual information into easily processed and understood keywords. These keywords are the basic semantic units constituting operational intents. Subsequently, to quantify and capture the semantic relationships between these keywords, word vectors are trained for each keyword, transforming them into numerical representations in a high-dimensional vector space. This transformation allows the semantic information of words to be encoded, and semantically similar words exhibit proximity in the vector space. Finally, a clustering algorithm is used to group these word vectors. Since the clustering algorithm can group semantically related keyword vectors into the same category, each clustering result naturally represents a first candidate operational intent associated with the first operational term. Through this processing flow that progresses from shallow to deep, from discrete to continuous and then to aggregate, this solution can overcome the limitations of simple semantic analysis, more accurately and comprehensively identify the multiple operational intentions implied by the first operational term, thus laying a solid foundation for determining the importance of the first candidate operational intention, and thereby improving the accuracy and reliability of the entire asset management data traceability method.

[0142] Through the above technical solution, this invention enables a more in-depth and refined semantic analysis of the first operational term. By extracting keywords, training word vectors, and clustering word vectors, the complex semantic information contained in the operational term can be effectively captured, and multiple first candidate operational intentions associated with the term can be identified. This method avoids the problem of inaccurate or incomplete intent recognition that may be caused by simple semantic matching, and significantly improves the accuracy and coverage of first candidate operational intent recognition. Therefore, when determining the importance of the first candidate operational intent in the first interaction group, calculations can be performed based on a more precise intent set, thereby improving the reliability of intent determination in the entire asset management data tracing process, and making the results of operation tracing based on data flow diagrams more accurate and effective.

[0143] In some embodiments of the present invention described above, in order to accurately assess the importance of the first candidate operation intent, it is necessary to determine the subsequent impact of the first operated object executing the corresponding first operation command. However, how to comprehensively and objectively quantify this subsequent impact to reflect the actual impact of the operation command on the data chain is a problem that needs to be solved.

[0144] In this regard, the present invention further proposes that S122 includes:

[0145] Obtain the data chain length of the first operation data chain, the average of the first change ratios of each first data before the first operation command, and the average of the second change ratios of each first data after the first operation command.

[0146] Based on the data chain length, the average of the first change ratio, and the average of the second change ratio, the subsequent impact of the first operated object executing the corresponding first operation command is determined.

[0147] In this embodiment, obtaining the data chain length of the first operation data chain refers to obtaining the number of first operation commands contained in the first operation data chain. The purpose of the data chain length is to quantify the overall size or historical depth of the first operation data chain, which helps to assess the relative position and potential impact of a single first operation command within the entire data chain. For example, it can be obtained by traversing all the first operation commands in the first operation data chain and counting them.

[0148] Obtaining the average of the first data change percentages before the first operation command refers to averaging the percentage changes in the first data caused by all first operation commands in the first operation data chain before the first operation command occurs. This average is intended to reflect the normal level or trend of data change in the data chain before the first operation command occurs. This can be calculated by summing all the first data change percentages before the first operation command and then dividing by the number of first operation commands.

[0149] Obtaining the average of the second change ratios of the first data after the first operation command refers to obtaining the average of the change ratios of the first data caused by all first operation commands in the first operation data chain after the first operation command occurs. This average is intended to reflect the normal level or trend of data change in the data chain after the first operation command occurs. This can be calculated by summing all the change ratios of the first data after the first operation command and then dividing by the number of operation commands.

[0150] Based on the data chain length, the average of the first change ratio, and the average of the second change ratio, the subsequent impact of executing the corresponding first operation command on the first operated object is determined. The subsequent impact is an indicator that measures the sustained influence of the first operation command on the data state or behavioral pattern of the first operated object. By comprehensively considering the overall length of the data chain and the data change trend before and after the operation command, the actual impact of the operation command can be assessed more comprehensively.

[0151] Specifically, the degree of subsequent impact can be determined using the following formula 3:

[0152] Formula 3

[0153] In formula 3, Used to characterize the subsequent impact of the j-th operation command in the m-th operation data chain. The average of the second change ratios used to characterize the j-th operation command in the m-th operation data chain. The average first change ratio of the j-th operation command in the m-th operation data chain is used to characterize the m-th operation data chain. The data chain length used to characterize the m-th operation data chain The sequence number used to characterize the j-th operation command in the m-th operation data chain, i.e. .

[0154] in, This indicates the influence weight of the j-th operation command on the point where the proportion of subsequent data changes abruptly. The closer the distance, the greater the likelihood that the candidate operation intent corresponding to the operation term contained in the j-th operation command will affect the subsequent data chain. This represents the difference in the percentage change of data before and after the j-th operation command. The larger the difference, the greater the range of variation in the percentage change of data.

[0155] By employing the aforementioned technical solution, when determining the subsequent impact of the first operated object executing the corresponding first operation command, the overall scale of the first operation data chain and the data change trend before and after the operation command are comprehensively considered. This multi-dimensional and dynamic evaluation method makes the quantification of subsequent impact more comprehensive, objective, and accurate, avoiding the bias that may be caused by a single indicator. This not only improves the accuracy of the importance assessment of the first candidate operation intent but also lays the foundation for constructing a more reliable set of intent weights, thereby significantly improving the accuracy and reliability of the entire process of asset management data traceability, enabling the traceability results to more realistically reflect the deep intent and actual impact of the operation behavior.

[0156] In some of the embodiments of the present invention described above, after determining the criticality of the first candidate operation intent in the first interaction group, how to effectively synthesize these criticalities to obtain a more representative and stable importance is a problem that needs further consideration. If only a single criticality is relied upon, it may not be able to fully reflect the overall importance of the operation intent in different interaction contexts, thereby affecting the accuracy of the subsequent construction of the intent weight set and the data flow graph.

[0157] In this regard, the present invention further proposes that S124 includes:

[0158] Obtain the criticality of each target; the criticality of a target is the criticality of the target operation intent in the target interaction group, the target interaction group is any first interaction group, and the target operation intent is any first candidate operation intent in the target interaction group;

[0159] The importance of each target's criticality is averaged to obtain the importance of the target's operational intent in the target interaction group.

[0160] In this embodiment, obtaining the criticality of each target refers to obtaining the criticality values ​​calculated in different target interaction groups that are associated with the specific target operation intention. These target criticalities are determined based on the subsequent impact of executing the corresponding first operation command on the first operated object in the above method.

[0161] The importance of a target's operational intent within a target interaction group is determined by averaging the multiple target keys associated with that intent. This means that after obtaining multiple target keys related to a specific operational intent, the final importance of that intent is determined by calculating the average of these keys. The purpose of averaging is to smooth the data and reduce the influence of random or extreme values ​​of individual key values, thereby obtaining a more stable and representative importance. For example, an arithmetic mean can be used, summing all obtained target key value values ​​and then dividing by the number of target key value values.

[0162] The present invention obtains the final importance of the target operation intention by acquiring multiple target keyities in different target interaction groups for the same target operation intention and averaging these keyities. This processing method ensures that the determined importance no longer depends solely on a single interaction context, but comprehensively considers the criticality of the target operation intention in multiple contexts. Through this aggregation and averaging, the potential bias or fluctuation of individual keyities can be effectively eliminated, making the importance assessment more stable and objective. When this averaged importance is combined with the operation relevance to construct an intention weight set, it can more accurately reflect the true weight of the operation intention, thereby constructing a more accurate and reliable data flow diagram, greatly improving the accuracy and credibility of asset management data traceability.

[0163] The above technical solution effectively integrates the criticality of the same operational intent in different interaction contexts, resulting in a more representative and stable importance score for the operational intent. This avoids the importance assessment bias caused by the randomness or extremes that may exist due to a single criticality, making the subsequently constructed intent weight set more accurate, thereby improving the accuracy and reliability of the data flow diagram in operation tracing.

[0164] In some embodiments of the present invention described above, after constructing the data flow diagram of the first operational data chain, the method mainly focuses on tracing historical operations. However, in actual asset management, new operational behaviors may occur, which may deviate from normal business processes or expected patterns. If these anomalies are not identified and handled in a timely manner, they may pose potential risks to asset security and data integrity.

[0165] In this regard, the present invention further proposes that, after S140, the following steps are also included:

[0166] In response to the acquisition of a newly generated second operation data chain, the abnormality of the second operation data chain is determined based on the second operation command in the second operation data chain;

[0167] In response to the fact that the anomaly degree of the second operation data chain is greater than the preset anomaly degree threshold, the second operation data chain is stored as an anomaly chain in the anomaly operation library.

[0168] In this embodiment, "responding to the acquisition of a newly generated second operation data chain" means that after the initial data flow diagram is established, the system continuously receives and processes new asset management operation records. This second operation data chain is a data sequence generated subsequently in time, and its structure is similar to the first operation data chain used to construct the initial flow diagram, both containing a series of operation commands. Acquiring these new data chains can be achieved in various ways. For example, the system can be configured to monitor the operation logs in the asset management system in real time, and once a new operation occurs and is recorded, it immediately captures and forms the second operation data chain.

[0169] Determining the anomaly degree of the second operation data chain based on the second operation command within it refers to conducting a risk assessment of the operational behavior represented by the newly captured second operation data chain. The second operation command is the basic building block of the second operation data chain, and its content is similar to the first operation command, typically including key information such as the operator, the operated object, the operation term, and the proportion of data change. Various techniques can be used to determine the anomaly degree. For example, statistical methods can be used to analyze the characteristics of the second operation command in the second operation data chain and compare them with the statistical distribution of the normal operation pattern pre-learned or established by the system, calculating the degree of deviation as the anomaly degree.

[0170] Responding to an anomaly level in the second operational data chain exceeding a preset anomaly threshold means the system compares the calculated anomaly level with a pre-defined critical value. The preset anomaly threshold is the boundary used to distinguish between normal and abnormal operations. Its setting can be based on historical data analysis; for example, by statistically analyzing the anomaly levels of a large number of normal operational data chains and setting the threshold as the value where the anomaly level distribution is above a certain high percentile. Alternatively, it can be manually set based on business expert experience or risk management strategies to reflect the anomaly tolerance requirements under different business scenarios. When the anomaly level of the second operational data chain exceeds this threshold, the system will identify it as a potential abnormal operation.

[0171] Storing the second operation data chain as an anomaly chain in the anomaly operation database means that once the second operation data chain is determined to be an anomaly, the system marks it as an anomaly chain and records its complete information in a dedicated storage area. The anomaly operation database can be an independent database, a distributed file system, or a dedicated log storage service, used to centrally store all identified anomaly operation data chains. The stored content typically includes the original second operation data chain, the calculated anomaly degree, the specific rules or model information that triggered the anomaly determination, and the timestamp of the anomaly discovery. This aims to provide detailed data support for subsequent risk auditing, security analysis, anomaly pattern mining, and system behavior optimization.

[0172] Building upon the data flow diagram of the first operation data chain described above, this invention further introduces a real-time anomaly detection mechanism for newly generated second operation data chains. When the system receives a new second operation data chain, it immediately analyzes it and calculates the anomaly degree of the second operation data chain based on the second operation commands it contains. This anomaly degree quantifies the deviation between the current operation behavior and the system's known normal patterns. Subsequently, the system compares the calculated anomaly degree with a preset anomaly degree threshold. If the anomaly degree exceeds the threshold, it indicates that the second operation data chain may be abnormal, and the system will identify it as an anomaly chain and store it in a dedicated anomaly operation database. In this way, this invention provides comprehensive historical operation tracing capabilities while adding real-time monitoring and recording functions for potential abnormal behaviors. This enables the asset management system not only to trace past operations but also to promptly detect and isolate suspicious operations, thereby effectively improving the security and reliability of asset management data and compensating for the shortcomings of simply constructing a data flow diagram without an anomaly identification mechanism.

[0173] By constructing a data flow graph and further introducing an anomaly detection and storage mechanism for newly generated second-stage operation data chains, this invention effectively overcomes the shortcomings of traditional traceability methods in real-time risk identification. This solution not only provides a complete historical trajectory of asset management operations but also proactively identifies and isolates abnormal operations that deviate from normal behavior patterns. This enables the asset management system to promptly detect potential fraud, errors, or violations, thereby significantly improving the security and reliability of asset management data. Centralized storage of abnormal operation data chains also provides a valuable data foundation for subsequent auditing, risk analysis, and system optimization, contributing to the construction of a more robust and intelligent asset management data traceability system.

[0174] In some embodiments of the present invention described above, a data flow graph is constructed and responds to a newly generated second operation data chain. Based on the second operation command in the second operation data chain, the anomaly degree of the second operation data chain is determined and stored in an anomaly operation database. However, in practical applications, how to accurately and effectively determine the anomaly degree of the second operation data chain, especially when subtle deviations in operational behavior may indicate potential risks, is a problem that needs to be solved. Simply judging the anomaly degree may not be sufficient to capture the complexity of operational behavior and potential anomaly patterns, thus affecting the accuracy and timeliness of tracing.

[0175] In response, this invention further proposes determining the anomaly degree of the second operation data chain based on the second operation command in the second operation data chain, including:

[0176] Based on the second operation command in the second operation data chain, determine the operation intent weight of the second candidate operation intent in the second interaction group formed by the second operator and the second operated object in the second operation data chain, as well as the criticality of the second candidate operation intent in the second interaction group.

[0177] Based on the weight of the second candidate operation intention and the criticality of the second candidate operation intention, the deviation of the second interaction group is determined.

[0178] The anomaly degree of the second operational data chain is determined based on the deviation degree of the second interaction group.

[0179] In this embodiment, the second operation command is a specific operation record in the newly generated second operation data chain. It contains information such as the operator, the operated object, the operation terms, and the data change ratio, and is the basic data unit for analyzing anomalies. Its function is to provide the original operation behavior information to be analyzed, which can be obtained from log systems, blockchain records, or database transaction logs, or received through a real-time data stream processing system.

[0180] The second interaction group, formed between the second operator and the second operated object, refers to the combination of the subject (operator) and the object (operated object) performing the operation in the newly generated second operation data chain. This combination represents a specific interaction behavior, and its function is to define the smallest unit of anomaly analysis, attributing the operation behavior to a specific interaction subject. This can be achieved by directly extracting and combining the operator ID and the operated object ID from the second operation command.

[0181] The second candidate operation intent is a potential operation purpose or behavior category inferred from the second operation term in the second operation command. Its role is to abstract and summarize the deeper meaning of specific operation behaviors, providing a semantic basis for subsequent anomaly analysis. The specific acquisition method can refer to the acquisition of the first candidate operation intent described above, and will not be described in detail here.

[0182] The operation intent weight of the second candidate operation intent represents its importance or influence in the second interaction group. Its function is to quantify the contribution of different operation intents in assessing anomaly. The specific calculation method can refer to the calculation of the operation intent weight of the first candidate operation intent described above, and will not be described in detail here.

[0183] The criticality of the second candidate operational intent indicates the degree of its subsequent impact on the operated object. Its purpose is to measure the potential risks or importance of the operational intent. The specific calculation method can be referenced from the calculation of the criticality of the first candidate operational intent described above, and will not be detailed here.

[0184] Deviation refers to the average difference between the weight and criticality of the operational intent in all identical second interaction groups formed by the second operator and the second operated object. Its function is to quantify the degree of anomalousness of the current interaction group's operational behavior. Anomaly, on the other hand, refers to the degree of anomalousness of the entire second operation data chain. Its function is to provide a comprehensive indicator to determine whether the second operation data chain is an anomalous chain. This can be achieved by aggregating the deviations of all second interaction groups in the second operation data chain, such as by summing, averaging, or taking the maximum value and then normalizing the result to obtain the anomaly of the entire second operation data chain.

[0185] Specifically, the deviation can be determined using the following formula 4:

[0186] Formula 4

[0187] In formula 4, Used to characterize the deviation degree of the second interaction group formed between the i-th operator and the j-th operated object in the second operation data chain. The operation intent weight is used to characterize the x-th candidate operation intent between the i-th operator and the j-th operated object in the second operation data chain. The criticality used to characterize the x-th candidate operation intent between the i-th operator and the j-th operated object in the second operation data chain. This is used to characterize the total number of candidate operation intentions between the i-th operator and the j-th operated object in the second operation data chain.

[0188] After calculating the deviation degree of the second interaction group, the mean of the deviation degrees between all operators and operated objects in the new second operation data chain is normalized and recorded as the anomaly degree of the new second operation data chain. If the anomaly degree of the new second operation data chain is greater than 0.6, the new second operation data chain is saved as an anomaly chain in the anomaly operation database. This allows for faster identification of the problem source during tracing, avoiding the traditional method of integrating discrete information about the operators and operated objects.

[0189] Through the above technical solution, this invention enables a refined assessment of the anomaly degree of the second operational data chain based on operational intent weight and criticality. This allows the system to identify anomalous behaviors caused by subtle deviations in operational intent or its potential impact, behaviors that might otherwise be undetectable by traditional, coarse-grained anomaly detection methods. Therefore, this invention significantly improves the accuracy and reliability of anomaly detection, facilitating more effective risk management and enabling precise operational traceability of asset management data. This distinguishes between benign deviations and genuinely suspicious activities, reduces false alarms, and improves overall system efficiency.

[0190] Based on the end-to-end information traceability method for asset management data provided by this invention, the present invention further provides a specific embodiment of an end-to-end information traceability system for asset management data.

[0191] like Figure 3 As shown, a schematic diagram of the structure of a full-process information traceability system for asset management data is provided. The full-process information traceability system 300 for asset management data may include a correlation determination module 310, an importance determination module 320, a weight determination module 330, and a flow diagram construction module 340.

[0192] The correlation determination module 310 is used to determine the operational correlation of the first interaction group formed between the first operator and the first operated object based on the first data change ratio of the first operation command in the first operation data chain in response to obtaining at least one first operation data chain; the first operation data chain includes a number of first operation commands, and the first operation command includes the first operator, the first operated object, the first operation term and the first data change ratio.

[0193] The importance determination module 320 is used to determine the importance of the first candidate operation intent in the first interaction group based on the ratio of the change of the first operation term and the first data in the first operation command; the first candidate operation intent is determined based on the first operation term.

[0194] The weight determination module 330 is used to construct an intent weight set for the first interaction group based on the operation relevance of the first interaction group and the importance of each first candidate operation intent; the intent weight set includes the operation intent weight of each first candidate operation intent in the first interaction group.

[0195] The flow graph construction module 340 is used to construct a data flow graph of the first operation data chain with the first operator and the first operated object as nodes and the intention weight set as edges, so as to enable operation tracing based on the data flow graph.

[0196] In the full-process information traceability system for asset management data provided in this embodiment of the invention, firstly, in response to the acquired first operation data chain, the operation correlation degree of the first interaction group consisting of the first operator and the first operated object is determined based on the first data change ratio of the first operation command, which can more accurately grasp the actual relationship between the operation subject and the object; then, the importance of the first candidate operation intent in the first interaction group is determined based on the first operation term and the first data change ratio, which can deeply explore the intent information behind the operation; then, an intent weight set is constructed based on the operation correlation degree and the importance of each first candidate operation intent, which can comprehensively consider operation correlation and intent factors; finally, a data flow graph is constructed with the operator and the operated object as nodes and the intent weight set as edges. In this way, the construction method of this data flow graph fully considers multiple factors such as operation correlation and operation intent, and can more accurately and completely establish the connection relationship between nodes, thereby improving the accuracy of operation traceability.

[0197] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0198] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

Claims

1. A method for full-process information traceability of asset management data, characterized in that, The method includes: In response to acquiring at least one first operation data chain, the operation correlation degree of the first interaction group formed between the first operator and the first operated object is determined based on the first data change ratio of the first operation command in the first operation data chain; the first operation data chain includes a plurality of first operation commands, and the first operation command includes the first operator, the first operated object, the first operation term and the first data change ratio. Based on the ratio of the first operation term to the first data change in the first operation command, the importance of the first candidate operation intent in the first interaction group is determined; the first candidate operation intent is determined based on the first operation term. Based on the operational relevance of the first interaction group and the importance of each first candidate operation intent, an intent weight set for the first interaction group is constructed; the intent weight set includes the operation intent weight of each first candidate operation intent in the first interaction group. Using the first operator and the first operated object as nodes and the intent weight set as edges, a data flow graph of the first operation data chain is constructed to enable operation tracing based on the data flow graph.

2. The method for full-process information traceability of asset management data according to claim 1, characterized in that, The step of determining the operational correlation degree of the first interaction group formed between the first operator and the first operated object based on the first data change ratio of the first operation command in the first operation data chain includes: Obtain the target operation command corresponding to the first interaction group in each of the first operation data chains; The absolute value of the kurtosis of the target data change ratio corresponding to each target operation command is taken to obtain the operation correlation degree of the first interaction group.

3. The method for full-process information traceability of asset management data according to claim 1, characterized in that, The step of constructing an intent weight set for the first interaction group based on the operation relevance of the first interaction group and the importance of each corresponding first candidate operation intent includes: Multiply the operation relevance of the first interaction group by the importance of the first candidate operation intent to obtain the operation intent weight of the first candidate operation intent; Based on the operation intent weights of each of the first candidate operation intents, an intent weight set for the first interaction group is constructed.

4. The method for full-process information traceability of asset management data according to claim 1, characterized in that, The determination of the importance of the first candidate operation intent in the first interaction group based on the ratio of the change in the first operation term and the first data according to the first operation command includes: Perform semantic analysis on the first operation term to determine at least one first candidate operation intent associated with the first operation term; Based on the first data change ratio of the first operation command, determine the subsequent impact of the first operated object executing the corresponding first operation command; Based on the subsequent impact of the first operated object executing the corresponding first operation command, the criticality of the first candidate operation intent in the first interaction group is determined; The importance of the first candidate operation intent in each of the first interaction groups is determined based on the criticality of the first candidate operation intent.

5. The method for full-process information traceability of asset management data according to claim 4, characterized in that, The step of performing semantic analysis on the first operation term to determine at least one first candidate operation intent associated with the first operation term includes: Semantic analysis is performed on the first operation term to obtain the keywords of the first operation term; Word vectors are trained on each keyword of the first operation term to obtain the word vectors of each keyword; Cluster the word vectors of each keyword to obtain at least one first candidate operation intent associated with the first operation term.

6. The method for full-process information traceability of asset management data according to claim 4, characterized in that, Determining the subsequent impact of the first operated object executing the corresponding first operation command based on the first data change ratio of the first operation command includes: Obtain the data chain length of the first operation data chain, the average first change ratio of each of the first data changes before the first operation command, and the average second change ratio of each of the first data changes after the first operation command; Based on the data chain length, the average of the first change ratio, and the average of the second change ratio, the subsequent impact of the first operated object executing the corresponding first operation command is determined.

7. The method for full-process information traceability of asset management data according to claim 4, characterized in that, The determination of the importance of the first candidate operation intent in each of the first interaction groups based on the criticality of the first candidate operation intent includes: Obtain the keyness of each target; the keyness of the target is the keyness of the target operation intent in the target interaction group, the target interaction group is any one of the first interaction groups, and the target operation intent is any one of the first candidate operation intents in the target interaction group; The importance of each target key score is averaged to obtain the importance of the target operation intent in the target interaction group.

8. The method for full-process information traceability of asset management data according to claim 4, characterized in that, After constructing the data flow graph of the first operation data chain with the first operator and the first operated object as nodes and the intent weight set as edges, the method further includes: In response to acquiring a newly generated second operation data chain, the abnormality degree of the second operation data chain is determined based on the second operation command in the second operation data chain; In response to the fact that the abnormality of the second operation data chain is greater than a preset abnormality threshold, the second operation data chain is stored as an abnormal chain in the abnormal operation library.

9. The method for full-process information traceability of asset management data according to claim 8, characterized in that, The step of determining the anomaly degree of the second operation data chain based on the second operation command in the second operation data chain includes: Based on the second operation command in the second operation data chain, determine the operation intent weight of the second candidate operation intent in the second interaction group formed by the second operator and the second operated object in the second operation data chain, and the criticality of the second candidate operation intent in the second interaction group; Based on the operation intent weight and criticality of the second candidate operation intent, the deviation of the second interaction group is determined using the following formula: in, Used to characterize the deviation degree of the second interaction group formed between the i-th operator and the j-th operated object in the second operation data chain. The operation intent weight is used to characterize the x-th candidate operation intent between the i-th operator and the j-th operated object in the second operation data chain. The criticality used to characterize the x-th candidate operation intent between the i-th operator and the j-th operated object in the second operation data chain. Used to characterize the total number of candidate operation intentions between the i-th operator and the j-th operated object in the second operation data chain; The anomaly degree of the second operational data chain is determined based on the deviation degree of the second interaction group.

10. A full-process information traceability system for asset management data, characterized in that, The system includes: The correlation determination module is used to determine the operational correlation of a first interaction group formed between a first operator and a first operated object based on the first data change ratio of the first operation command in the first operation data chain in response to acquiring at least one first operation data chain; the first operation data chain includes a plurality of first operation commands, and the first operation command includes the first operator, the first operated object, the first operation term and the first data change ratio. The importance determination module is used to determine the importance of the first candidate operation intent in the first interaction group based on the ratio of the change between the first operation term and the first data in the first operation command; the first candidate operation intent is determined based on the first operation term. The weight determination module is used to construct an intent weight set for the first interaction group based on the operation relevance of the first interaction group and the importance of each first candidate operation intent; the intent weight set includes the operation intent weight of each first candidate operation intent in the first interaction group. The flow graph construction module is used to construct a data flow graph of the first operation data chain with the first operator and the first operated object as nodes and the intent weight set as edges, so as to enable operation tracing based on the data flow graph.