A financial network security protection and control method, device, electronic device and medium

By dynamically partitioning the financial network based on node and edge transaction information, and utilizing blockchain and multi-constraint graph clustering algorithms to construct a cross-institutional threat collaborative control network, the shortcomings of existing financial network security protection systems are addressed. This achieves precise partitioning and real-time protection of the financial network, thereby improving security and protection effectiveness.

CN122137531APending Publication Date: 2026-06-02山西工程科技职业大学

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
山西工程科技职业大学
Filing Date
2026-04-17
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The existing financial network security protection system lacks a comprehensive consideration of the overall structure and business characteristics, making it difficult to accurately identify the security level differences of different business clusters and to quickly formulate targeted protection and control strategies, resulting in poor protection effectiveness and difficulty in dealing with complex network threats.

Method used

By acquiring financial network information, partitioning is performed based on node business type, edge transaction information, and dynamic partitioning rules. A cross-institutional threat collaborative control network is constructed using blockchain, attack information is encrypted, and protection and control strategies are determined. Initial partitioning is performed by combining multi-constraint graph clustering algorithms and feature matrices. Hardware firewalls and SDN technology are used to achieve security control in different areas. Partitioning is adjusted in real time, and attack information is filtered using neural network models.

Benefits of technology

It enables precise partition management and real-time network protection of financial networks, ensuring the security and traceability of attack information, effectively responding to complex network attacks, and improving the security and protection of financial networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137531A_ABST
    Figure CN122137531A_ABST
Patent Text Reader

Abstract

This invention relates to a financial network security protection and control method, device, electronic device, and medium, belonging to the technical field of finance. The method includes: acquiring financial network information; partitioning the financial network based on financial business types, transaction information, and dynamic partitioning rules to obtain multiple financial network regions; monitoring and protecting each financial network region and acquiring attack information; then constructing a cross-institutional threat collaborative control network based on blockchain technology; encrypting and uploading the attack information to the blockchain; determining a protection and control strategy based on the attack information; and performing defensive processing on financial network attacks based on the protection and control strategy. This application achieves the technical effects of improving financial network security, realizing efficient network partitioning, accurately identifying attack information, rationally formulating protection strategies, and effectively allocating and handling resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of finance, and in particular to a financial network security protection and control method, device, electronic device and medium. Background Technology

[0002] With the accelerated digital transformation of the financial industry, financial networks have become a key infrastructure supporting core businesses such as cross-border payments, high-frequency trading, and customer data management.

[0003] However, the security threats faced by financial networks are becoming increasingly complex and chain-like: attackers often leverage the business connections between financial institutions to launch multi-stage attacks, targeting high-value assets. Traditional financial network security protection systems are mostly built around a single institution as the boundary, achieving static protection through firewalls, intrusion detection systems (IDS), etc., issuing alerts once suspicious behavior is detected.

[0004] However, these existing technologies have significant shortcomings. Current protective measures lack a comprehensive consideration of the overall structure and business characteristics of financial networks, making it difficult to rationally partition financial networks and accurately identify the security level differences between different business clusters. Furthermore, when facing financial network attacks, they cannot quickly formulate targeted protection and control strategies based on effective attack information, resulting in poor protection effectiveness and an inability to effectively address the increasingly complex cybersecurity threats in the financial sector. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a financial network security protection and control method, device, electronic device and medium, which aims to solve at least one of the above-mentioned technical problems.

[0006] The technical solution of the present invention to solve the above-mentioned technical problems is as follows: Firstly, this application provides a financial network security protection and control method, which adopts the following technical solution: A financial network security protection and control method includes: Acquire financial network information, which includes multiple financial network nodes and edges between each financial network node. Each financial network node represents a financial business entity, and each edge represents transaction information between two financial network nodes connected to the edge. Based on the financial business type of each financial network node, the transaction information of each edge, and the dynamic partitioning rules, the financial network is partitioned to obtain multiple financial network regions. Each financial network region represents a cluster of financial businesses with the same security business level. For each of the financial network regions, network protection is performed on the financial network region based on the monitoring method corresponding to the financial network region, and financial network attack information is obtained; A cross-institutional threat collaborative control network is constructed based on blockchain technology. Attack information corresponding to each financial network region is encrypted and uploaded to the blockchain. For the attacked financial network region, a protection and control strategy is determined based on the attack information corresponding to the financial network region, and the financial network attack is defended based on the protection and control strategy.

[0007] The beneficial effects of this invention are as follows: by acquiring financial network information, a comprehensive understanding of the financial network architecture and transaction status can be achieved; by partitioning the financial network according to node business types, edge transaction information, and rules, business clusters with the same security business level can be grouped together, facilitating targeted management; by protecting each financial network area and acquiring attack information, network attacks can be detected in a timely manner; by constructing a cross-institutional threat collaborative control network based on blockchain and encrypting and uploading attack information to the chain, the security and traceability of attack information are ensured; at the same time, by determining protection and control strategies and handling defenses based on attack information, effective responses to financial network attacks can be made, thereby improving the security of the financial network.

[0008] Based on the above technical solution, the present invention can be further improved as follows.

[0009] Furthermore, the business type encoding generates a multi-dimensional vector based on transaction size and regulatory requirements. The transaction information includes transaction amount thresholds, customer privacy data types, and cross-border transaction identifiers. The financial network is partitioned based on the financial business type of each financial network node, the transaction information of each edge, and dynamic partitioning rules, resulting in multiple financial network regions, including: Based on each of the transaction details, determine the data sensitivity of each edge; Based on the financial business type code, compliance label and business criticality score of each financial network node, the initial inbound traffic and the data sensitivity of each edge, a feature moment is constructed, wherein the initial inbound traffic includes bandwidth utilization, packet characteristics and protocol type; Based on the multi-constraint graph clustering algorithm and the feature matrix, the financial network is initially partitioned, and the hard boundary core area is divided into multiple initial financial network regions. The initial financial network regions are either hard boundary core areas or soft boundary buffers. Hardware firewalls are deployed in the hard boundary core areas to implement access control, and SDN technology is used in the soft boundary buffers to implement micro-segmentation. Real-time acquisition of the current inbound traffic of the financial network node; For each initial financial network region, determine whether there is a financial network node whose current inbound traffic exceeds a set traffic threshold; For each initial financial network region, if there is a financial network node whose current inbound traffic exceeds a set traffic threshold, then incremental clustering is performed on the initial financial network region, and the node traffic feature dimension in the feature matrix is ​​updated to obtain the final financial network region.

[0010] The beneficial effects of adopting the above-mentioned further solutions are as follows: By generating multi-dimensional vectors of business type codes using transaction volume and regulatory requirements, and considering transaction information such as transaction amount thresholds, customer privacy data types, and cross-border transaction identifiers, the data sensitivity of edges can be accurately determined; by constructing a feature matrix combining financial business type codes, compliance labels, business criticality scores, initial inbound traffic, and edge data sensitivity, the characteristics of the financial network can be more comprehensively and accurately reflected; by using multi-constraint graph clustering algorithms and feature matrices for initial partitioning, hard-boundary core areas and soft-boundary buffer areas are defined, and different security controls are implemented using hardware firewalls and SDN technology respectively, enhancing the security and flexibility of partitioning; by acquiring current inbound traffic in real time, incremental clustering of initial financial network areas with abnormal traffic and updating the feature matrix, partitioning can be dynamically adjusted, making the financial network area division more in line with the actual situation and improving the effectiveness of financial network security protection.

[0011] Furthermore, for each of the financial network regions, based on the monitoring method corresponding to the financial network region, network protection is performed on the financial network region, and financial network attack information is obtained, including: For each of the financial network regions, obtain the access request for the financial network region; For each of the financial network zones, it is determined whether the access request contains attack information that attacks security control devices, including firewalls, network access control lists, and virtual honeypots. For each of the financial network areas, if the access request does not contain attack information that would attack the security control device, then the security control device is controlled to allow the access request to access the corresponding financial network area. For each of the financial network regions, if the access request contains attack information that attacks the security control device, the attack information is input into a preset financial attack feature neural network model to obtain financial network attack information.

[0012] The beneficial effects of adopting the above-mentioned further solution are: to obtain access requests to the financial network area, to determine whether the access request contains attack information against security control equipment, to allow normal access requests, and to input access requests containing attack information into a neural network model to obtain attack information, which can effectively filter out network attacks, provide targeted network protection for the financial network area and accurately obtain attack information.

[0013] Furthermore, the step of determining a protection and control strategy for the financial network area based on the attack information corresponding to the financial network area, and processing financial network attacks based on the protection and control strategy, includes: For the attacked financial network areas, the type and level of the financial network security incident are determined based on the financial network attack information; For the attacked financial network area, based on the type and level of the network security incident, determine whether the financial network area has historical financial network security incidents of the same level and type as the financial network security incident. For the attacked financial network area, if there are historical financial network security incidents of the same level and type as the aforementioned financial network security incident, then multiple first processing strategies are determined based on the historical financial network security incidents of the same level and type; Based on multiple first processing strategies, a first protection and control strategy for the financial network area is determined. The protection and control strategy is either a first protection and control strategy or a second protection and control strategy. The first protection and control strategy includes multiple first processing strategies ordered in sequence of use. Based on the usage sequence of the first prevention and control strategy, the first processing strategy is selected sequentially to defend against financial network security incidents until the network security incident is successfully processed. If there are no historical financial network security incidents of the same level and type as the aforementioned financial network security incident, then based on the type of the financial network security incident, determine multiple second processing strategies for that type; Based on multiple second processing strategies, a second protection and control strategy for the financial network area is determined, wherein the second protection and control strategy includes multiple second processing strategies ordered in sequence of use. Based on the usage sequence of the two prevention and control strategies, the second processing strategy is selected sequentially to defend against financial network security incidents until the network security incident is successfully processed. When the strategy fails a set number of times consecutively, the circuit breaker mechanism is triggered, and the alarm module is activated to switch to the manual review process.

[0014] The beneficial effects of adopting the above-mentioned further solution are as follows: First, the type and level of financial network security incidents are determined based on financial network attack information. Then, it is determined whether there are historical financial network security incidents of the same level and type. If so, multiple first-level handling strategies are determined based on historical events to form a first-level defense strategy. If not, multiple second-level handling strategies are determined based on the incident type to form a second-level defense strategy. The handling strategies are selected sequentially according to the strategy usage sequence for defense, which can effectively cope with different types of financial network attacks. Triggering the circuit breaker mechanism switches to a manual review process, ensuring the security of financial network security even when automatic strategies fail consecutively. It can accurately locate the attacked area within the entire financial network framework and effectively protect it, ensuring the stability and security of the financial network system.

[0015] Furthermore, determining at least one first processing strategy based on historical financial cybersecurity incidents of the same level and type includes: Obtain the frequency of use and results for each primary processing strategy; Calculate the success rate of each first processing strategy based on its usage frequency and results. Based on the success rate of each of the first processing strategies, the first processing strategies are sorted in descending order. Sort in a second descending order based on the frequency of use of each of the first processing strategies; Based on the first descending order and the second descending order of each of the first processing strategies, a usage sequence for each first processing strategy is determined, and based on the usage sequence of each first processing strategy, a protection control strategy for the financial network area is determined.

[0016] The beneficial effects of adopting the above-mentioned further solutions are: obtaining the usage frequency and results of the first processing strategy allows for the calculation of the success rate. These strategies are then sorted in descending order by success rate and usage frequency, thereby determining the sequence of processing strategies. This makes the protection and control strategies more scientific and reasonable, improving the efficiency and success rate of defending against and handling financial network security incidents. Furthermore, it enables the determination of protection and control strategies for financial network areas based on historical financial network security incidents of the same level and type.

[0017] Furthermore, the step of determining the protection and control strategy for the financial network area based on multiple second processing strategies includes: Obtain the usage frequency of each of the second processing strategies, and generate a third descending sort based on the usage frequency of each of the second processing strategies; Obtain the layout time based on each of the second processing strategies, and generate a fourth descending sort based on the layout time of each of the second processing strategies; Obtain evaluation information based on each of the second processing strategies, and generate a fifth descending sort based on the evaluation information of each of the second processing strategies; Based on the three descending order, the fourth descending order, and the fourth descending order, the usage sequence of each second processing strategy is determined, and based on the usage sequence of each second processing strategy, the protection and control strategy of the financial network area is determined.

[0018] The beneficial effects of adopting the above-mentioned further scheme are: by obtaining the usage frequency, deployment time and evaluation information of the second processing strategy and generating a descending order, it is possible to comprehensively consider multiple factors to determine the usage sequence of the second processing strategy, thereby determining the protection and control strategy for the financial network area, making the protection and control strategy more scientific and reasonable, and improving the efficiency and accuracy of handling financial network security incidents.

[0019] Furthermore, it also includes: When multiple financial network security incidents exist, the priority of each financial network security incident is determined; Allocate resources for handling each cybersecurity incident based on its priority. Determining the priority of each of the financial network security events includes: For a financial cybersecurity incident, a first impact score is determined based on the potential risk of the incident, wherein the potential risk is determined based on the type of the incident. For financial network security incidents, a second impact score for the financial network security incident in each financial network node is determined based on the type of the financial network security incident, the historical frequency of the incident of that type in each financial network node, and a preset frequency range. For financial network security incidents, a third impact score for each financial network node is determined based on the importance of each financial network node, the type of financial business, the security configuration, and the degree of impact of the financial network security incident on each financial network node. The priority of each financial cybersecurity incident is determined based on its first impact score, second impact score, and third impact score.

[0020] The beneficial effects of adopting the above-mentioned further solutions are: when there are multiple financial cybersecurity incidents, the priority of each incident can be determined by comprehensively considering factors such as potential risks, historical frequency, and node characteristics, and then resources can be rationally allocated according to the priority, thereby improving resource utilization efficiency and the ability to respond to financial cybersecurity incidents.

[0021] Secondly, this application provides a financial network security protection and control device, which adopts the following technical solution: A financial network security protection and control device, comprising: The acquisition module is used to acquire financial network information, which includes multiple financial network nodes and edges between each financial network node. Each financial network node represents a financial business entity, and each edge represents transaction information between two financial network nodes connected to the edge. The region partitioning module is used to partition the financial network based on the financial business type of each financial network node, the data sensitivity of the transaction information of each edge, and the dynamic partitioning rules, to obtain multiple financial network regions. The financial network regions represent financial business clusters with the same security business level. The financial network protection module is used to perform network protection for each financial network area based on the monitoring method corresponding to the financial network area, and to obtain financial network attack information. The protection and control strategy determination module is used to build a cross-institutional threat collaborative control network based on blockchain technology, encrypt and upload the attack information corresponding to each financial network area to the chain, and determine the protection and control strategy for each financial network area based on multiple attack information.

[0022] Thirdly, this application provides an electronic device that adopts the following technical solution: An electronic device includes a memory and a processor, wherein the memory stores a computer program capable of being loaded by the processor and executing the financial network security protection and control method according to any one of the first aspects.

[0023] Fourthly, this application provides a computer-readable storage medium, which adopts the following technical solution: A computer-readable storage medium storing a computer program capable of being loaded by a processor and executing the financial network security protection and control method described in any one of the first aspects.

[0024] Additional aspects and advantages of this application will be set forth in part in the description which follows, and will become apparent from the description or may be learned by practice of this application. Attached Figure Description

[0025] Figure 1 A flowchart illustrating a financial network security protection and control method according to an embodiment of the present invention; Figure 2 A block diagram of a financial network security protection and control device provided in one embodiment of the present invention; Figure 3 This is a block diagram of an electronic device provided in one embodiment of the present invention. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the appendices in the embodiments of this application will be described below. Figure 1 To be continued Figure 3 The technical solutions in the embodiments of this application are clearly and completely described. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0027] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.

[0028] This application provides a financial network security protection and control method, which can be executed by an electronic device, which can be a server or a mobile terminal device. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services. The mobile terminal device can be a laptop, a desktop computer, etc., but is not limited to these.

[0029] like Figure 1 As shown, a financial network security protection and control method mainly includes steps S1 to S4: Step S1: Obtain financial network information, which includes multiple financial network nodes and edges between each financial network node. Each financial network node represents a financial business entity, and each edge represents transaction information between two financial network nodes connected to the edge. In this embodiment of the application, transaction events are monitored through an API gateway (such as Kong), such as transactions in the payment clearing system, and customer transaction records and device logs are exported from the database (such as Oracle or MySQL) on a daily schedule.

[0030] Next, a financial network graph is constructed based on the collected transaction data of various financial business entities. The types of financial network nodes can include banks, securities institutions, payment platforms, clearing centers, etc., and the attributes of financial network nodes can include business type codes, compliance tags, and business criticality scores. Edge types can include transfers, securities transactions, and API calls. Edge attributes can include data sensitivity tags, transaction amounts, protocol types, and timestamps.

[0031] The financial network can also be divided into at least one financial network area according to the functions of the applications in the financial network. This can restrict the connection between different financial network areas, reduce the possibility of expanding the attack scope when one financial network area is attacked, and at the same time improve the speed of financial network security protection by dividing the network into zones.

[0032] Step S2: Based on the financial business type of each financial network node, the transaction information of each edge, and the dynamic partitioning rules, the financial network is partitioned to obtain multiple financial network regions. Each financial network region represents a financial business cluster with the same security business level. In this embodiment of the application, the transaction information includes a transaction amount threshold, customer privacy data types, and cross-border transaction identifiers.

[0033] Step S2 specifically includes the following sub-steps: Step S21: Determine the data sensitivity of each edge based on each of the transaction information; In this embodiment, the sensitivity of the edge is determined based on the transaction amount threshold, the customer privacy data type, and the cross-border transaction identifier. For example, the sensitivity score = weight 1 × amount level + weight 2 × privacy level + weight 3 × cross-border identifier.

[0034] Step S22: Based on the financial business type code, compliance label and business criticality score of each financial network node, the initial inbound traffic and the data sensitivity of each edge, construct feature moments. The initial inbound traffic includes bandwidth utilization, data packet characteristics and protocol type. The business type code generates a multi-dimensional vector based on transaction size and regulatory requirements. In this embodiment of the application, transaction volume (annual turnover) and regulatory requirements (such as whether derivatives are involved) are encoded as vectors. For example, if a bank's annual turnover exceeds a set threshold and derivatives are involved, then [1, 1, 0] can represent the code for this type of financial transaction.

[0035] Step S23: Based on the multi-constraint graph clustering algorithm and the feature matrix, the financial network is initially partitioned, and the hard boundary core area is divided into multiple initial financial network regions. The initial financial network regions are hard boundary core areas or soft boundary buffer areas. Hardware firewalls are deployed in the hard boundary core areas to implement access control, and SDN technology (Software-Defined Networking) is used in the soft boundary buffer areas to implement micro-segmentation. In this embodiment, the high-sensitivity zone (hard boundary) centrally processes large cross-border transactions, with hardware firewalls blocking unauthorized IPs. The medium-sensitivity zone (soft boundary) processes domestic transfers, and SDN (Software-Defined Networking) automatically isolates suspicious nodes during traffic surges. The low-sensitivity zone (such as query services) employs lightweight isolation to reduce operational costs.

[0036] Step S24: Obtain the current inbound traffic of the financial network node in real time; In this embodiment of the application, the inbound traffic of financial network nodes can be collected by sFlow (Sampled Flow, random sampling technology) or NetFlow (Network Flow, full traffic recording technology) and updated once every set time interval.

[0037] Step S25: For each of the initial financial network regions, determine whether there is a financial network node whose current inbound traffic is greater than a set traffic threshold. Step S26: For each initial financial network region, if there is a financial network node whose current inbound traffic is greater than a set traffic threshold, then incremental clustering is performed on the initial financial network region, the node traffic feature dimension in the feature matrix is ​​updated, and the final financial network region is obtained.

[0038] In this embodiment, for nodes exceeding the limit, their feature vectors are recalculated, traffic-related dimensions are updated, and the incremental DBSCAN algorithm (an unsupervised learning clustering algorithm) is used to adjust only the clustering results of the affected nodes and their neighborhoods.

[0039] After the initial partitioning, the traffic of node N1 in the hard boundary region suddenly increased to 900Mbps. The set traffic threshold was 800Mbps. Therefore, the bandwidth utilization of N1 in the updated feature matrix was 90%. After re-clustering, N1 was moved to the soft boundary region.

[0040] Step S3: For each financial network area, based on the monitoring method corresponding to the financial network area, perform network protection on the financial network area and obtain financial network attack information; In this embodiment of the application, for each financial network area, network protection is performed on the financial network area based on the monitoring method corresponding to the financial network area, and financial network attack information is obtained, including: For each of the financial network regions, obtain the access request for the financial network region; For each of the financial network zones, it is determined whether the access request contains attack information that attacks security control devices, including firewalls, network access control lists, and virtual honeypots. For each of the financial network areas, if the access request does not contain attack information that would attack the security control device, then the security control device is controlled to allow the access request to access the corresponding financial network area. For each of the financial network regions, if the access request contains attack information that attacks the security control device, the attack information is input into a preset financial attack feature neural network model to obtain financial network attack information.

[0041] In this embodiment, when an access request attempts to access the security control device corresponding to a financial network area, and the security control device shows no abnormalities, the current access request is secure and can be allowed to access the corresponding financial network area. However, if the access request attacks the security control device, then the access request is not allowed to access the financial network area, thus initially protecting the security of the financial network area.

[0042] Electronic devices train a neural network model corresponding to a financial network region using multiple attack information samples and corresponding financial network attack information samples. When attack information is input into the neural network model, the corresponding financial network attack information is obtained.

[0043] Step S4: Construct a cross-institutional threat collaborative control network based on blockchain technology, encrypt and upload the attack information corresponding to each financial network area to the blockchain, and for the attacked financial network area, determine the protection and control strategy for the financial network area based on the attack information corresponding to the financial network area, and perform defense processing on the financial network attack based on the protection and control strategy.

[0044] In this embodiment of the application, based on the attack information corresponding to the financial network area, a protection and control strategy for the financial network area is determined, and the financial network attack is processed based on the protection and control strategy, including: Step S41: For the attacked financial network area, determine the type and level of the financial network security incident based on the financial network attack information; In this embodiment, attack information is mapped to defense categories, such as DDoS defense and anti-malware, based on the MITRE D3FEND framework (structured defense technology knowledge base); combined with the attack payload characteristics of financial network attack information, NLP classification models are used for fine-grained classification to finally obtain the type of financial network security incident.

[0045] The CVSS 3.1 scoring system (standardized vulnerability scoring system) is adopted, and the basic score is adjusted based on financial business impact factors, such as transaction system downtime losses, and the level of financial network security incidents is determined based on the basic score.

[0046] Step S42: For the attacked financial network area, based on the type and level of the network security incident, determine whether the financial network area has historical financial network security incidents of the same level and type as the financial network security incident. Step S43: For the attacked financial network area, if there are historical financial network security incidents of the same level and type as the aforementioned financial network security incident, then determine multiple first processing strategies based on the historical financial network security incidents of the same level and type; Step S44: Based on multiple first processing strategies, determine a first protection control strategy for the financial network area. The protection strategy is either a first protection strategy or a second protection strategy. The first protection strategy includes multiple first processing strategies ordered by usage sequence. Step S45: Based on the usage sequence of the first prevention and control strategy, select the first processing strategy in sequence to defend against financial network security incidents until the network security incident is successfully processed. Step S46: If there are no historical financial network security events of the same level and type as the financial network security event, then based on the type of the financial network security event, determine multiple second processing strategies for that type. Step S47: Based on multiple second processing strategies, determine a second protection control strategy for the financial network area, wherein the second protection strategy includes multiple second processing strategies ordered in a usage sequence; Step S48: Based on the usage sequence of the two prevention and control strategies, the second processing strategy is selected sequentially to defend against financial network security incidents until the network security incident is successfully processed. Step S49: When the strategy fails a set number of times consecutively, the circuit breaker mechanism is triggered, and the alarm module is controlled to sound an alarm, so as to switch to the manual review process.

[0047] For example, if there are ≥3 consecutive failures, or if a key indicator (such as transaction system latency) exceeds the SLA (Service Level Agreement, such as 500ms) for 2 minutes, the Security Operations Center will be notified. The alarm content will include an attack source map (such as the attack path IP → domain name → C2 server) and policy execution logs.

[0048] By identifying the type and severity of financial network security incidents based on financial network attack information, and then determining whether historical financial network security incidents of the same severity and type exist, multiple primary handling strategies are determined based on historical events to form a primary defense strategy if they exist. If not, multiple secondary handling strategies are determined based on the incident type to form a secondary defense strategy. These strategies are then selected sequentially for defense, effectively addressing different types of financial network attacks. A circuit breaker mechanism is triggered to switch to a manual review process, ensuring financial network security even when automatic strategies fail consecutively. This allows for precise location and effective protection of attacked areas within the entire financial network framework, ensuring the stability and security of the financial network system.

[0049] Optionally, determining at least one first processing strategy based on historical financial cybersecurity incidents of the same level and type includes: Obtain the frequency of use and results for each primary processing strategy; Calculate the success rate of each first processing strategy based on its usage frequency and results. Based on the success rate of each of the first processing strategies, the first processing strategies are sorted in descending order. Sort in a second descending order based on the frequency of use of each of the first processing strategies; Based on the first descending order and the second descending order of each of the first processing strategies, a usage sequence for each first processing strategy is determined, and based on the usage sequence of each first processing strategy, a protection control strategy for the financial network area is determined.

[0050] In this embodiment, the usage records of each first processing strategy are obtained from the blockchain, low-frequency strategies are eliminated, the success rate of each first processing strategy after eliminating low-frequency strategies is calculated, and a first descending order is made based on the success rate of each first processing strategy after eliminating low-frequency strategies; a second descending order is made based on the usage frequency of each first processing strategy, and finally the usage sequence of each first processing strategy is determined, so that the protection and control strategy is more scientific and reasonable, and the efficiency and success rate of defense and handling of financial network security incidents are improved.

[0051] Optionally, determining the protection and control strategy for the financial network area based on multiple second processing strategies includes: Obtain the usage frequency of each of the second processing strategies, and generate a third descending sort based on the usage frequency of each of the second processing strategies; Obtain the layout time based on each of the second processing strategies, and generate a fourth descending sort based on the layout time of each of the second processing strategies; Obtain evaluation information based on each of the second processing strategies, and generate a fifth descending sort based on the evaluation information of each of the second processing strategies; Based on the three descending order, the fourth descending order, and the fourth descending order, the usage sequence of each second processing strategy is determined, and based on the usage sequence of each second processing strategy, the protection and control strategy of the financial network area is determined.

[0052] By generating descending order based on the usage frequency, deployment time, and evaluation information of the second processing strategy, multiple factors can be comprehensively considered to determine the usage sequence of the second processing strategy. This, in turn, determines the protection and control strategy for the financial network area, making the protection and control strategy more scientific and reasonable, and improving the efficiency and accuracy of handling financial network security incidents.

[0053] As an optional implementation of this application, the method further includes: When multiple financial network security incidents exist, the priority of each financial network security incident is determined; Allocate resources for handling each cybersecurity incident based on its priority. Determining the priority of each of the financial network security events includes: For a financial cybersecurity incident, a first impact score is determined based on the potential risk of the incident, wherein the potential risk is determined based on the type of the incident. For financial network security incidents, a second impact score for the financial network security incident in each financial network node is determined based on the type of the financial network security incident, the historical frequency of the incident of that type in each financial network node, and a preset frequency range. For financial network security incidents, a third impact score for each financial network node is determined based on the importance of each financial network node, the type of financial business, the security configuration, and the degree of impact of the financial network security incident on each financial network node. The priority of each financial cybersecurity incident is determined based on its first impact score, second impact score, and third impact score.

[0054] This application's embodiments achieve dynamic priority determination and optimized resource allocation for financial network security incidents through multi-dimensional impact assessment: First, a first impact score is calculated based on the potential risks mapped by the event type (e.g., a high-risk score corresponding to a DDoS attack). Second, a second impact score is quantified by combining the node's historical event frequency with a preset interval. Then, a third impact score is obtained by weighting the node's importance (using the PageRank algorithm to assess network topology value), security configuration compliance, and business impact. Finally, a priority score is generated by comprehensively considering the weights of the three factors (4:3:3). Based on this, differentiated defense resources are dynamically scheduled through Kubernetes (e.g., immediate circuit breaking and manual intervention for P0-level events). At the same time, a feedback mechanism is established to continuously optimize the node importance score and risk matrix, achieving precise allocation of defense resources.

[0055] This method comprehensively understands the financial network architecture and transaction status by acquiring financial network information; it partitions the financial network according to node business types, edge transaction information, and rules, grouping business clusters with the same security level together for targeted management; it provides network protection for each financial network area and acquires attack information, enabling timely detection of network attacks; and it constructs a cross-institutional threat collaborative control network based on blockchain and encrypts and uploads attack information to the chain, ensuring the security and traceability of attack information. Furthermore, it determines protection and control strategies based on attack information and performs defensive actions, effectively responding to financial network attacks and improving the security of the financial network.

[0056] Figure 2 A schematic diagram of a financial network security protection and control device 200 is shown.

[0057] like Figure 2 As shown, a financial network security protection and control device 200 mainly includes: The acquisition module 201 is used to acquire financial network information, which includes multiple financial network nodes and edges between each financial network node. Each financial network node represents a financial business entity, and each edge represents transaction information between two financial network nodes connected to the edge. The region partitioning module 202 is used to partition the financial network based on the financial business type of each financial network node, the data sensitivity of the transaction information of each edge, and the dynamic partitioning rules to obtain multiple financial network regions. The financial network regions represent financial business clusters with the same security business level. The financial network protection module 203 is used to perform network protection on each financial network area based on the monitoring method corresponding to the financial network area, and to obtain financial network attack information. The protection and control strategy determination module 204 is used to build a cross-institutional threat collaborative control network based on blockchain technology, encrypt and upload the attack information corresponding to each financial network area to the chain, and determine the protection and control strategy for each financial network area based on multiple attack information.

[0058] The actions performed by each module and unit in the financial network security protection control device of the rear wheel steering system in various embodiments of the present invention correspond to the steps in the financial network security protection control method in various embodiments of the present invention. For detailed functional descriptions of each module of the financial network security protection control device, please refer to the descriptions in the corresponding financial network security protection control methods shown above, which will not be repeated here.

[0059] In one example, the module in any of the above devices may be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.

[0060] For example, when modules in a device can be implemented via a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling programs. Alternatively, these modules can be integrated together as a system-on-a-chip (SOC).

[0061] In this application, various objects such as messages / information / devices / network elements / systems / apparatus / actions / operations / processes / concepts may be named. It is understood that these specific names do not constitute a limitation on the relevant objects. The names may be changed depending on the scenario, context, or usage habits. The understanding of the technical meaning of the technical terms in this application should be mainly determined from their functions and technical effects embodied / performed in the technical solution.

[0062] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0063] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0064] Figure 3 This is a structural block diagram of an electronic device 300 according to an embodiment of this application.

[0065] like Figure 3 As shown, the electronic device 300 includes a processor 301 and a memory 302, and may further include one or more of an information input / output (I / O) interface 303, a communication component 304, and a communication bus 305.

[0066] The processor 301 controls the overall operation of the electronic device 300 to complete all or part of the steps in the aforementioned financial network security protection control method. The memory 302 stores various types of data to support the operation of the electronic device 300. This data may include, for example, instructions for any application or method operating on the electronic device 300, as well as application-related data. The memory 302 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as one or more of Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.

[0067] I / O interface 303 provides an interface between processor 301 and other interface modules, such as keyboards, mice, and buttons. These buttons can be virtual or physical. Communication component 304 is used to test wired or wireless communication between electronic device 300 and other devices. Wireless communication includes Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, or 4G, or a combination thereof. Therefore, the corresponding communication component 304 may include a Wi-Fi component, a Bluetooth component, and an NFC component.

[0068] The communication bus 305 may include a path for transmitting information between the aforementioned components. The communication bus 305 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The communication bus 305 may be divided into an address bus, a data bus, a control bus, etc.

[0069] The electronic device 300 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to execute the financial network security protection and control method given in the above embodiments.

[0070] The following describes the computer-readable storage medium provided in the embodiments of this application. The computer-readable storage medium described below can be referred to in correspondence with the financial network security protection and control method described above.

[0071] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described financial network security protection and control method.

[0072] The computer-readable storage medium may include various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0073] The terms “comprising,” “including,” or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0074] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the foregoing application concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions claimed in this application.

Claims

1. A financial network security protection and control method, characterized in that, include: Acquire financial network information, which includes multiple financial network nodes and edges between each financial network node. Each financial network node represents a financial business entity, and each edge represents transaction information between two financial network nodes connected to the edge. Based on the financial business type of each financial network node, the transaction information of each edge, and the dynamic partitioning rules, the financial network is partitioned to obtain multiple financial network regions. Each financial network region represents a cluster of financial businesses with the same security business level. For each of the financial network regions, network protection is performed on the financial network region based on the monitoring method corresponding to the financial network region, and financial network attack information is obtained; A cross-institutional threat collaborative control network is constructed based on blockchain technology. Attack information corresponding to each financial network region is encrypted and uploaded to the blockchain. For the attacked financial network region, a protection and control strategy is determined based on the attack information corresponding to the financial network region, and the financial network attack is defended based on the protection and control strategy.

2. The financial network security protection and control method according to claim 1, characterized in that, The transaction information includes transaction amount thresholds, customer privacy data types, and cross-border transaction identifiers. Based on the financial business type of each financial network node, the transaction information of each edge, and dynamic partitioning rules, the financial network is partitioned to obtain multiple financial network regions, including: Based on each of the transaction details, determine the data sensitivity of each edge; Based on the financial business type code, compliance label and business criticality score of each financial network node, the initial inbound traffic and the data sensitivity of each edge, feature moments are constructed. The initial inbound traffic includes bandwidth utilization, packet characteristics and protocol type. The business type code generates a multi-dimensional vector based on transaction size and regulatory requirements. Based on the multi-constraint graph clustering algorithm and the feature matrix, the financial network is initially partitioned, and the hard boundary core area is divided into multiple initial financial network regions. The initial financial network regions are either hard boundary core areas or soft boundary buffers. Hardware firewalls are deployed in the hard boundary core areas to implement access control, and SDN technology is used in the soft boundary buffers to implement micro-segmentation. Real-time acquisition of the current inbound traffic of the financial network node; For each initial financial network region, determine whether there is a financial network node whose current inbound traffic exceeds a set traffic threshold; For each initial financial network region, if there is a financial network node whose current inbound traffic exceeds a set traffic threshold, then incremental clustering is performed on the initial financial network region, and the node traffic feature dimension in the feature matrix is ​​updated to obtain the final financial network region.

3. The financial network security protection and control method according to claim 1, characterized in that, For each of the financial network regions, based on the monitoring method corresponding to that financial network region, network protection is performed on the financial network region, and financial network attack information is obtained, including: For each of the financial network regions, obtain the access request for the financial network region; For each of the financial network zones, it is determined whether the access request contains attack information that attacks security control devices, including firewalls, network access control lists, and virtual honeypots. For each of the financial network areas, if the access request does not contain attack information that would attack the security control device, then the security control device is controlled to allow the access request to access the corresponding financial network area. For each of the financial network regions, if the access request contains attack information that attacks the security control device, the attack information is input into a preset financial attack feature neural network model to obtain financial network attack information.

4. The financial network security protection and control method according to claim 3, characterized in that, The process of determining a protection and control strategy for the financial network area based on attack information corresponding to the financial network area, and processing financial network attacks based on the protection and control strategy, includes: For the attacked financial network areas, the type and level of the financial network security incident are determined based on the financial network attack information; For the attacked financial network area, based on the type and level of the network security incident, determine whether the financial network area has historical financial network security incidents of the same level and type as the financial network security incident. For the attacked financial network area, if there are historical financial network security incidents of the same level and type as the aforementioned financial network security incident, then multiple first processing strategies are determined based on the historical financial network security incidents of the same level and type; Based on multiple first processing strategies, a first protection and control strategy for the financial network area is determined. The protection and control strategy is either a first protection and control strategy or a second protection and control strategy. The first protection and control strategy includes multiple first processing strategies ordered in sequence of use. Based on the usage sequence of the first prevention and control strategy, the first processing strategy is selected sequentially to defend against financial network security incidents until the network security incident is successfully processed. If there are no historical financial network security incidents of the same level and type as the aforementioned financial network security incident, then based on the type of the financial network security incident, determine multiple second processing strategies for that type; Based on multiple second processing strategies, a second protection and control strategy for the financial network area is determined, wherein the second protection and control strategy includes multiple second processing strategies ordered in sequence of use. Based on the usage sequence of the two prevention and control strategies, the second processing strategy is selected sequentially to defend against financial network security incidents until the network security incident is successfully processed. When the strategy fails a set number of times consecutively, the circuit breaker mechanism is triggered, and the alarm module is activated to switch to the manual review process.

5. A financial network security protection and control method according to claim 4, characterized in that, The determination of at least one first handling strategy based on historical financial cybersecurity incidents of the same level and type includes: Obtain the frequency of use and results for each primary processing strategy; Calculate the success rate of each first processing strategy based on its usage frequency and results. Based on the success rate of each of the first processing strategies, the first processing strategies are sorted in descending order. Sort in a second descending order based on the frequency of use of each of the first processing strategies; Based on the first descending order and the second descending order of each of the first processing strategies, a usage sequence for each first processing strategy is determined, and based on the usage sequence of each first processing strategy, a protection control strategy for the financial network area is determined.

6. A financial network security protection and control method according to claim 3, characterized in that, The determination of the protection and control strategy for the financial network area based on multiple second processing strategies includes: Obtain the usage frequency of each of the second processing strategies, and generate a third descending sort based on the usage frequency of each of the second processing strategies; Obtain the layout time based on each of the second processing strategies, and generate a fourth descending sort based on the layout time of each of the second processing strategies; Obtain evaluation information based on each of the second processing strategies, and generate a fifth descending sort based on the evaluation information of each of the second processing strategies; Based on the three descending order, the fourth descending order, and the fourth descending order, the usage sequence of each second processing strategy is determined, and based on the usage sequence of each second processing strategy, the protection and control strategy of the financial network area is determined.

7. A financial network security protection and control method according to claim 1, characterized in that, Also includes: When multiple financial network security incidents exist, the priority of each financial network security incident is determined; Allocate resources for handling each cybersecurity incident based on its priority. Determining the priority of each of the financial network security events includes: For a financial cybersecurity incident, a first impact score is determined based on the potential risk of the incident, wherein the potential risk is determined based on the type of the incident. For financial network security incidents, a second impact score for the financial network security incident in each financial network node is determined based on the type of the financial network security incident, the historical frequency of the incident of that type in each financial network node, and a preset frequency range. For financial network security incidents, a third impact score for each financial network node is determined based on the importance of each financial network node, the type of financial business, the security configuration, and the degree of impact of the financial network security incident on each financial network node. The priority of each financial cybersecurity incident is determined based on its first impact score, second impact score, and third impact score.

8. A financial network security protection and control device, characterized in that, include: The acquisition module is used to acquire financial network information, which includes multiple financial network nodes and edges between each financial network node. Each financial network node represents a financial business entity, and each edge represents transaction information between two financial network nodes connected to the edge. The region partitioning module is used to partition the financial network based on the financial business type of each financial network node, the data sensitivity of the transaction information of each edge, and the dynamic partitioning rules, to obtain multiple financial network regions. The financial network regions represent financial business clusters with the same security business level. The financial network protection module is used to perform network protection for each financial network area based on the monitoring method corresponding to the financial network area, and to obtain financial network attack information. The protection and control strategy determination module is used to build a cross-institutional threat collaborative control network based on blockchain technology, encrypt and upload the attack information corresponding to each financial network area to the chain, and determine the protection and control strategy for each financial network area based on multiple attack information.

9. An electronic device, characterized in that, Includes a processor, which is coupled to a memory; The processor is configured to execute a computer program stored in the memory to cause the electronic device to perform the method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, Includes a computer program or instructions that, when run on a computer, cause the computer to perform the method as described in any one of claims 1-7.