Risk identification method and device and computer device

By integrating batch and stream processing technology, the system receives risk configuration information input by users, uses a batch engine to identify and adjust it, and generates streaming risk identification rules. This solves the problems of insufficient real-time performance and accuracy in traditional risk prevention and control, and enables efficient risk identification in the energy sales industry.

CN122288348APending Publication Date: 2026-06-26RICHFIT INFORMATION TECH +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RICHFIT INFORMATION TECH
Filing Date
2024-12-24
Publication Date
2026-06-26

Smart Images

  • Figure CN122288348A_ABST
    Figure CN122288348A_ABST
Patent Text Reader

Abstract

This specification relates to the field of computer technology, and more particularly to a risk identification method, apparatus, and computer device. The risk identification method includes: receiving risk configuration information input by a user; performing risk identification using a batch engine based on the risk configuration information to obtain a first batch of risk identification results; adjusting the risk configuration information based on the first batch of risk identification results; generating a first stream risk identification rule using a streaming engine based on the adjusted risk configuration information; and performing risk identification on streaming data according to the first stream risk identification rule to obtain a first stream risk identification result. The embodiments in this specification can improve the efficiency and effectiveness of risk prevention and control, and reduce losses caused by potential risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a risk identification method, apparatus, and computer equipment. Background Technology

[0002] Streaming business data refers to continuously generated and arriving business data. Streaming business data can include transaction data, log data, etc. In some application scenarios, streaming business data faces higher risks. Traditional risk control methods often rely on manual review and post-event analysis, lacking real-time and forward-looking capabilities, making it difficult to identify potential risks in a timely and accurate manner. Summary of the Invention

[0003] This specification provides a risk identification method, apparatus, and computer equipment to improve the efficiency and effectiveness of risk prevention and control, and reduce losses caused by potential risks.

[0004] This specification provides a risk identification method, including:

[0005] Receive risk configuration information input by the user;

[0006] Based on the risk configuration information, a batch engine is used to identify risks, resulting in the first batch of risk identification results.

[0007] Based on the results of the first batch of risk identification, the risk configuration information was adjusted;

[0008] Based on the adjusted risk configuration information, the first streaming risk identification rule is generated using the streaming engine.

[0009] Risk identification is performed on streaming data according to the first-stream risk identification rules to obtain the first-stream risk identification results.

[0010] This specification also provides a risk identification device, including:

[0011] The receiving unit is used to receive risk configuration information input by the user;

[0012] The first risk identification unit is used to identify risks based on risk configuration information using a batch engine, and obtain the first batch of risk identification results.

[0013] The adjustment unit is used to adjust the risk configuration information based on the results of the first batch of risk identification.

[0014] The generation unit is used to generate the first streaming risk identification rule based on the adjusted risk configuration information using the streaming engine.

[0015] The second risk identification unit is used to identify risks in streaming data according to the first streaming risk identification rules, and obtain the first streaming risk identification result.

[0016] This specification also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described risk identification method.

[0017] This specification also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described risk identification method.

[0018] This specification also provides a computer program product, which includes a computer program that, when executed by a processor, implements the above-described risk identification method.

[0019] The technical solution of this specification embodiment can receive risk configuration information input by a user; perform risk identification using a batch engine based on the risk configuration information to obtain the first batch of risk identification results; adjust the risk configuration information based on the first batch of risk identification results; generate a first streaming risk identification rule using a streaming engine based on the adjusted risk configuration information; and perform risk identification on streaming data based on the first streaming risk identification rule to obtain the first streaming risk identification result. Therefore, when it is necessary to generate streaming risk identification rules based on user-input risk configuration information, risk identification can first be performed using a batch engine based on the risk configuration information to verify the risk configuration information. If the verification fails, the risk configuration information can be adjusted based on the batch risk identification results to generate streaming risk identification rules based on the adjusted risk configuration information. The streaming risk identification rules can be deployed online to identify risks in streaming data. In this way, through the integrated batch and streaming technology, the deployed streaming risk identification rules can have a better risk identification effect, thereby improving the efficiency and effectiveness of risk prevention and control, and reducing losses caused by potential risks. Attached Figure Description

[0020] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. The drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a flowchart illustrating the risk identification method in the embodiments of this specification;

[0022] Figure 2 This is a schematic diagram of the risk identification process in the embodiments of this specification;

[0023] Figure 3 This is a schematic diagram of the risk identification device in the embodiments of this specification;

[0024] Figure 4 This is a schematic diagram of the risk identification process in the embodiments of this specification. Detailed Implementation

[0025] The technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. The specific embodiments described herein are only used to explain this disclosure, and not to limit this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure are within the scope of protection of this disclosure. In addition, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0026] The energy sales industry faces high risks due to its large transaction volume, numerous participants, and complex transaction chains. Traditional risk control methods often rely on manual review and post-event analysis, lacking real-time and forward-looking capabilities, making it difficult to identify potential risks in a timely and accurate manner. Therefore, there is an urgent need for a technological solution that can improve the efficiency and effectiveness of risk control.

[0027] Please see Figure 1 and Figure 2 This specification provides a risk identification method. The risk identification method can be applied to computer equipment such as servers. The risk identification method may include the following steps.

[0028] Step 11: Receive risk configuration information input by the user.

[0029] In some embodiments, the risk configuration information is used to configure risk identification rules. The risk configuration information can be in natural language. For example, the risk configuration information could be: identify accounts with a transaction amount greater than or equal to 500 within 5 days as risky accounts.

[0030] In some embodiments, the risk identification rules are used to identify risks associated with abnormal customer behavior.

[0031] The risk identification rules may include risk control indicators and risk control thresholds.

[0032] Risk control metrics refer to the calculation and statistics of a subject's actions within a certain time window under a single event. For example, "the number of unique logins from the same member via mobile APP in the past hour, after deduplication" is a risk control metric. The subject of the metric is the member, the time window is the past hour, the event is the member login, and the calculation and statistics are the number of unique logins from the same member's location.

[0033] A risk identification rule may include a combination of one or more risk identification conditions. Each risk identification condition may include a risk control indicator and a risk control threshold. The risk control indicator of the risk identification rule may include the risk control indicators of the one or more risk identification conditions. The risk control threshold of the risk identification rule may include the risk control thresholds of the one or more risk identification conditions.

[0034] Of course, risk identification rules can also include other information. For example, risk identification rules can also include rule names, rule codes, control policies, etc. Control policies can include blocking, allowing, facial recognition, etc.

[0035] In some embodiments, the risk identification rules include batch risk identification rules and streaming risk identification rules. Batch risk identification rules are used to identify risks in batches of data in the database. Streaming risk identification rules are used to identify risks in real-time from streaming data online. Batch data includes a number of business data, and streaming data includes real-time business data. Business data includes business data from the energy sales industry, such as registration data, login data, recharge data, payment data, electronic card activation data, etc., from the business system.

[0036] In some embodiments, risk management personnel can input risk configuration information into a computer device based on risk identification needs and their own experience. The risk control system of the computer device can provide a configuration interface. Risk management personnel can input risk configuration information into the configuration interface. The computer device can receive the risk configuration information input by the user.

[0037] In some embodiments, the risk configuration information may include indicator configuration information and threshold configuration information. Indicator configuration information is used to configure the indicators for risk identification rules. Threshold configuration information is used to configure the thresholds for risk identification rules. Of course, the risk configuration information may also include other information. For example, the risk configuration information may also include rule name, rule code, control strategy, etc. In some scenario examples, the risk control system of a computer device may include a decision asset management module. The decision asset management module may include a rule management module and an indicator management module. Risk control managers can input the threshold configuration information in the rule management module and the indicator configuration information in the indicator management module.

[0038] Step 12: Based on the risk configuration information, use the batch engine to identify risks and obtain the first batch of risk identification results.

[0039] In some embodiments, user-input risk configuration information can be converted into a unified semantics. This semantics is applicable to both batch and streaming engines and can be loaded by both. The streaming engine may include a streaming indicator engine and a streaming decision engine. The batch engine may include a batch indicator engine and a batch decision engine. The risk control system of the computer device can generate a first semantics applicable to both the streaming and batch decision engines based on the risk configuration information. The streaming and batch decision engines can dynamically load this unified first semantics and parse it into streaming risk identification rules and batch risk identification rules, respectively. The risk control system of the computer device can also generate a second semantics applicable to both the streaming and batch indicator engines based on the risk configuration information. The streaming and batch indicator engines can dynamically load this unified second semantics and parse it into streaming indicator calculation logic and batch query statements (e.g., SQL statements), respectively.

[0040] The aforementioned engine can be understood as a computer program or model.

[0041] The streaming decision engine can generate streaming rule judgment logic for real-time scenarios based on a unified first semantic. Furthermore, it can provide a risk identification interface for business events, allowing business systems to report event information according to a standard event format when calling this interface. The streaming decision engine can also call the streaming indicator engine to obtain streaming indicator calculation logic; it can perform calculations based on this logic, using the results as streaming risk indicators; and it can then determine whether these indicators meet the hit logic of the streaming risk identification rules. If the hit logic is met, the streaming decision engine can obtain the corresponding control policy, enabling the business system to proceed with the next business process according to the control policy.

[0042] The batch decision engine can generate batch rule judgment logic for batch running scenarios based on a unified first semantic. Furthermore, the batch decision engine can receive backtesting task scheduling from the rule backtesting module, and according to the risk control rule encoding required by the backtesting task, call the batch indicator engine to obtain batch query statements. It can calculate batch risk indicators based on the batch query statements, filter event details that conform to the rule logic based on the rule judgment logic, supplement the event details with the matched rule logic to generate backtest risk event details, and save them to the database.

[0043] The streaming metrics engine can update streaming computation tasks (such as Spark Streaming tasks) based on a unified second semantic. It can also receive event data pushed from the message queue via an ETL module (extract, transform, load), call Spark Streaming for real-time computation, and store the data in Redis. Furthermore, the streaming metrics engine can provide metric query functionality to the streaming decision engine, allowing users to retrieve risk control metrics from Redis.

[0044] The batch metrics engine can generate query statements supported by the Spark SQL framework (e.g., Spark SQL statements) based on a unified second semantic. The batch metrics engine can also receive calls from the batch decision engine, query the Hive database using the Spark SQL framework according to the metric codes queried by the batch decision engine, and return the query results to the batch decision engine.

[0045] In some embodiments, a batch indicator engine can be used to parse risk configuration information to obtain query statements; the first batch of business data can be queried from the database based on the query statements; and a batch decision engine can be used to identify risks in the first batch of business data to obtain the first batch of risk identification results. The first batch of business data may include several business data sets. This business data may be transaction data (e.g., energy sales data) or log data.

[0046] For example, a batch decision engine can be used to parse risk configuration information to obtain the first batch of risk identification rules (e.g., batch rule judgment logic); the first batch of risk identification rules can be used to identify risks in the first batch of business data to obtain the first batch of risk identification results.

[0047] The initial risk identification results can include several risk identification results. Each risk identification result corresponds to a piece of business data. This risk identification result can be categorized as risky, risk-free, or having a risk level. Alternatively, the risk identification result can also be the control strategy to be taken. Control strategies can include blocking, allowing passage, facial recognition, etc.

[0048] Step 13: Adjust the risk configuration information based on the results of the first batch of risk identification.

[0049] In some embodiments, it can be determined whether the first batch of risk identification results meets the set conditions; if not, the risk configuration information can be adjusted based on the first batch of risk identification results.

[0050] Each piece of business data in the first batch can be tagged. For each piece of business data, its tag can be compared with its risk identification result to determine if the risk identification result is correct. The number of correct risk identification results can be divided by the total number of risk identification results to obtain the identification accuracy rate of the first batch of business data. Based on the identification accuracy rate of the first batch of business data, it can be determined whether a set condition is met. For example, the set condition could be that the accuracy rate is greater than or equal to a threshold.

[0051] If not, it indicates that the risk configuration information entered by the user based on their own experience is inappropriate. Generating streaming risk identification rules based on the user-input risk configuration and then using these rules to identify risks in streaming data results in low accuracy. Therefore, the risk configuration information can be adjusted based on the first batch of risk identification results to improve the accuracy of risk identification.

[0052] It can analyze the deviation information of the first batch of risk identification results relative to the set conditions; and adjust the risk configuration information based on the deviation information. The deviation information can include the magnitude of the deviation. It can involve adjusting at least one of the risk control indicators and risk control thresholds. For example, risk configuration information, set conditions, and the first batch of risk identification results can be input into an artificial intelligence model. This AI model can analyze the deviation information of the first batch of risk identification results relative to the set conditions; and adjust the risk configuration information based on the deviation information. The AI ​​model can then display the adjusted deviation information.

[0053] The adjustment can be made to ensure that the initial risk identification results meet the set conditions.

[0054] For example, the adjustment direction can be adjusted to determine the calculation method for the risk control threshold and the deviation magnitude, such as subtracting the deviation magnitude from the risk control threshold or adding the deviation magnitude to the risk control threshold. Therefore, the deviation threshold and the deviation magnitude can be added or subtracted depending on the adjustment direction.

[0055] Step 14: Based on the adjusted risk configuration information, generate the first streaming risk identification rule using the streaming engine.

[0056] In some embodiments, a streaming decision engine can be used to parse the adjusted risk configuration information and generate streaming rule judgment logic in real-time scenarios, which serves as the first streaming risk identification rule.

[0057] Step 15: Perform risk identification on the streaming data according to the first streaming risk identification rules to obtain the first streaming risk identification results.

[0058] In some embodiments, the adjusted risk configuration information can be parsed using a streaming indicator engine to obtain the streaming indicator calculation logic; the streaming data can be calculated according to the streaming indicator calculation logic to obtain the first streaming risk control indicator; the first streaming risk identification rule can be used to identify risks in the first streaming risk control indicator to obtain the first streaming risk identification result.

[0059] In some embodiments, streaming data can refer to continuously generated and arriving business data. Streaming data may include transaction data, log data, etc. The first streaming risk identification result may be risky, risk-free, or a risk level, etc. Alternatively, the first streaming risk identification result may also be the control strategy to be taken. Control strategies may include blocking, allowing, facial recognition, etc.

[0060] In some embodiments, it can be determined whether the first risk identification result meets the set conditions; if so, a second streaming risk identification rule can be generated using the streaming engine based on the risk configuration information; the streaming data can be risk identified based on the second streaming risk identification rule to obtain the second streaming risk identification result.

[0061] If so, it means that the risk configuration information entered by the user based on their own experience is appropriate. Generating streaming risk identification rules based on the user-input risk configuration, and then using these rules to identify risks in streaming data, can achieve good accuracy. Therefore, a second streaming risk identification rule can be generated using the streaming engine based on the risk configuration information; this second rule can then be used to identify risks in streaming data, yielding the second streaming risk identification result.

[0062] For example, a streaming decision engine can be used to parse the risk configuration information and generate streaming rule judgment logic for real-time scenarios, serving as a second streaming risk identification rule. Similarly, a streaming indicator engine can be used to parse the risk configuration information and obtain streaming indicator calculation logic; streaming data can be calculated based on this logic to obtain a second streaming risk control indicator; and the second streaming risk identification rule can be used to identify risks in the second streaming risk control indicator to obtain the second streaming risk identification result.

[0063] In some embodiments, if the first streaming risk identification result indicates that the streaming data is at risk, a second batch of business data corresponding to the streaming data can be queried in the database; a batch decision engine can be used to identify risks in the second batch of business data to obtain a second batch risk identification result; and the first streaming risk identification result can be verified based on the second batch risk identification result. The database may include Hive, MySQL, etc.

[0064] The first-level streaming risk identification result can be either "at risk" or a specific risk level. Therefore, this result indicates that the streaming data poses a risk. Alternatively, the first-level streaming risk identification result can indicate that control measures are needed. These control measures can include blocking, allowing passage, facial recognition, etc. Thus, the first-level streaming risk identification result indicates that the streaming data poses a risk.

[0065] The second batch of business data includes several data sets. This business data can be transaction data (e.g., energy sales data) or log data. The second batch of business data corresponds to streaming data; the second batch of business data and the streaming data can correspond to the same customer, or the similarity between the second batch of business data and the streaming data can be greater than a threshold.

[0066] The adjusted risk configuration information can be parsed using a batch decision engine to obtain the second batch risk identification rules (e.g., batch rule judgment logic); the second batch risk identification rules can be used to identify risks in the second batch of business data to obtain the second batch risk identification results.

[0067] The second batch of risk identification results can include several risk identification results. Each risk identification result corresponds to a piece of business data. This risk identification result can be classified as risky, risk-free, or of a certain risk level. Alternatively, the risk identification result can also be the control strategy to be taken. Control strategies can include blocking, allowing passage, facial recognition, etc.

[0068] The system can retrieve the type of each risk identification result in the second batch risk identification results. Different risk identification results in the second batch risk identification results can have the same or different types. The system can select the type with the most corresponding risk identification results as the target type from multiple types. These multiple types include the types of all risk identification results in the second batch risk identification results. The system can determine whether the type of the first streaming risk identification results is the target type. If yes, it indicates that the first streaming risk identification results are accurate, and the streaming data can be controlled. If no, it indicates that the first streaming risk identification results are inaccurate, and a prompt can be sent to the user, allowing the user to manually verify the first streaming risk identification results.

[0069] The technical solution of this specification embodiment can receive risk configuration information input by a user; perform risk identification using a batch engine based on the risk configuration information to obtain the first batch of risk identification results; adjust the risk configuration information based on the first batch of risk identification results; generate a first streaming risk identification rule using a streaming engine based on the adjusted risk configuration information; and perform risk identification on streaming data based on the first streaming risk identification rule to obtain the first streaming risk identification result. Therefore, when it is necessary to generate streaming risk identification rules based on user-input risk configuration information, risk identification can first be performed using a batch engine based on the risk configuration information to verify the risk configuration information. If the verification fails, the risk configuration information can be adjusted based on the batch risk identification results to generate streaming risk identification rules based on the adjusted risk configuration information. The streaming risk identification rules can be deployed online to identify risks in streaming data. In this way, through the integrated batch and streaming technology, the deployed streaming risk identification rules can have a better risk identification effect, thereby improving the efficiency and effectiveness of risk prevention and control, and reducing losses caused by potential risks.

[0070] Please see Figure 4 The following describes a scenario example of an embodiment of this specification. This scenario example may include the following steps.

[0071] 1. Risk control managers configure business events that require risk control system intervention in the decision-making asset management module, filling in the event name and associated field information. The computer equipment converts the input from the risk control managers into a standard event definition format.

[0072] 2. Risk control managers create risk control indicators in the decision-making asset management module and design indicator logic according to the indicator configuration standard format on the operation interface. The computer equipment converts the input of risk control managers into unified indicator semantics.

[0073] 3. The batch indicator engine subscribes to the risk control indicators of the asset management module to unify semantics and converts them into Spark SQL statements.

[0074] 4. The streaming indicator engine subscribes to the unified semantics of risk control indicators in the decision-making asset management module, and updates the Spark Streaming streaming computing tasks according to the unified semantics of risk control indicators.

[0075] 5. Risk control managers create risk control rules in the decision-making asset management module. On the interface, they fill in the rule name, rule code, select the risk control indicators to be used, configure thresholds, and choose the rule control strategy to quickly complete the risk control rule configuration. The computer equipment converts the input from the risk control managers into a unified semantic representation of the risk control rules.

[0076] 6. The batch decision engine subscribes to risk control rules with unified semantics and parses them into batch rule judgment logic.

[0077] 7. In the rule backtesting module, risk control managers create rule backtesting scheduling tasks, select the rules to be backtested and the time range for backtesting.

[0078] 8. Rule backtesting task scheduling module, which schedules the batch decision engine to execute rule backtesting tasks.

[0079] 9. The batch decision engine calls the batch indicator engine to obtain risk control indicator information according to the risk control indicators and backtesting time range involved in the risk control rules in the backtesting task. Then, it filters out the historical business events that hit the risk control rules according to the rule logic, supplements the rule information, and generates rule backtesting details.

[0080] 10. After receiving the query request from the batch decision engine, the batch indicator engine supplements the time range in the corresponding Spark SQL template according to the indicator code and time range in the parameters, and then calls the Spark instance of the data platform to perform the indicator query.

[0081] 11. After the rule backtesting is completed, risk control managers will check whether the rule has been hit based on known black sample data, or select some risk events for backtesting by sampling to verify the accuracy of the risk control rule offline. The rule backtesting statistical reports will provide a comprehensive understanding of the control effect of the risk control rules to be implemented.

[0082] 12. Risk control management personnel analyze the results of rule backtesting and, if the rules meet expectations, implement the rules in the decision-making asset management module.

[0083] 13. After the rules are launched, the streaming decision engine subscribes to the unified semantics of the risk control rules and parses them into real-time rule judgment logic.

[0084] 14. During the event phase, the business system uses business event information as parameters to call the risk identification interface provided by the streaming decision engine to make risk judgments.

[0085] 15. When performing risk assessment, the streaming decision engine needs to query the real-time rule logic through the streaming indicator engine to determine the required streaming computing indicators. Upon receiving the query request from the streaming decision engine, the streaming indicator engine retrieves the indicator results from the Redis cache database and returns them to the streaming decision engine. The streaming decision engine then matches the indicator results with the rule logic to match the risk control rules applicable to the current business event, and returns the matched risk control rule encoding and control strategy to the business system.

[0086] 16. The business system executes control operations according to the risk control strategy returned by the risk identification interface.

[0087] 17. When risk control managers receive risk control complaints from the customer service center or feedback from business personnel during their daily risk control operations, they can initiate a new round of risk control rule optimization processes.

[0088] Risk control managers can readjust the rules and then use rule backtesting to quickly obtain updated rule backtesting details. They can then check if the readjusted rules, ready for deployment, can be identified based on the latest black sample data. Rule backtesting statistics reports provide a quick overview of the control effectiveness of the readjusted rules. If the control effect meets expectations, the readjusted rules are deployed to monitor risks in real-time during business processes. If the control effect does not meet requirements, the rule logic needs further adjustment, followed by rule backtesting, until the expected control effect is achieved.

[0089] An event can refer to a business process that is integrated with risk control. For example, member login, registration, and recharge are different events. Risk management personnel maintain the event names and associated business fields in the risk control system. For example, a login event may include business fields such as member ID, login time, login channel, login IP, and login method.

[0090] The rule backtesting module allows users to create rule backtesting schedules, configure the rules to be backtested and the time range, and once the schedule is activated, the computer will use the batch decision engine to perform rule backtesting. Furthermore, the module can query detailed rule backtesting data, allowing risk control managers to check if a rule has been triggered based on known black sample data. They can also sample some risk events for backtesting to verify the accuracy of risk control rules offline. In addition, the module provides rule statistical reports, displaying information such as the number of risk rule triggers, risk trigger rate, number of associated risky customers, risk amount, geographical distribution of risks, and temporal distribution of risk events. This allows risk control managers to comprehensively understand the management effectiveness of risk control rules before implementation.

[0091] Please see Figure 3 This specification also provides a risk identification device, comprising:

[0092] Receiving unit 31 is used to receive risk configuration information input by the user;

[0093] The first risk identification unit 32 is used to identify risks based on risk configuration information using a batch engine to obtain the first batch of risk identification results.

[0094] Adjustment unit 33 is used to adjust the risk configuration information based on the first batch of risk identification results;

[0095] The generation unit 34 is used to generate the first streaming risk identification rule based on the adjusted risk configuration information using the streaming engine.

[0096] The second risk identification unit 35 is used to identify risks in streaming data according to the first streaming risk identification rules and obtain the first streaming risk identification result.

[0097] This specification also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the above-described risk identification method.

[0098] This specification also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described risk identification method.

[0099] This specification also provides a computer program product, which includes a computer program that, when executed by a processor, implements the above-described risk identification method.

[0100] Those skilled in the art will understand that this specification can be provided as a method, system, or computer program product. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0101] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments thereof. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. The computer may be a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0102] The functional units in the embodiments of this specification can be integrated into one processing unit, or each functional unit can exist physically separately, or two or more functional units can be integrated into one processing unit.

[0103] Those skilled in the art will understand that the descriptions of the various embodiments in this specification have different focuses, and parts not described in detail in a certain embodiment can be referred to in the relevant descriptions of other embodiments. Furthermore, it is understood that those skilled in the art, after reading this specification, can conceive of any combination of some or all of the embodiments listed in this specification without creative effort, and such combinations are also within the scope of disclosure and protection of this specification.

[0104] Although this specification has been described through embodiments, those skilled in the art will understand that the above embodiments are merely illustrative of the core ideas of this specification. Those skilled in the art will appreciate that many variations and modifications are possible with this specification. It is intended that the appended claims encompass these variations and modifications without departing from the spirit of this specification.

Claims

1. A risk identification method, characterized in that, include: Receive risk configuration information input by the user; Based on the risk configuration information, a batch engine is used to identify risks, resulting in the first batch of risk identification results. Based on the results of the first batch of risk identification, the risk configuration information was adjusted; Based on the adjusted risk configuration information, the first streaming risk identification rule is generated using the streaming engine. Risk identification is performed on streaming data according to the first-stream risk identification rules to obtain the first-stream risk identification results.

2. The method according to claim 1, characterized in that, The batch engine includes a batch indicator engine and a batch decision engine; The use of a batch engine for risk identification includes: The risk configuration information is parsed using a batch indicator engine to obtain the query statement; The first batch of business data is retrieved from the database according to the query statement. The batch decision engine is used to identify risks in the first batch of business data to obtain the first batch of risk identification results.

3. The method according to claim 1, characterized in that, The adjustment of risk configuration information based on the first batch of risk identification results includes: Determine whether the results of the first batch of risk identification meet the set conditions; If not, adjust the risk configuration information based on the results of the first batch of risk identification.

4. The method according to claim 3, characterized in that, The adjustment of risk configuration information based on the first batch of risk identification results includes: Analyze the deviation information of the first batch of risk identification results relative to the set conditions; Adjust the risk configuration information based on the deviation information.

5. The method according to claim 1, characterized in that, The streaming engine includes a streaming decision engine; The generation of the first streaming risk identification rule using a streaming engine includes: The adjusted risk configuration information is parsed using a streaming decision engine to generate streaming rule judgment logic in real-time scenarios, which serves as the first streaming risk identification rule.

6. The method according to claim 1, characterized in that, The method further includes: Determine whether the results of the first risk identification meet the set conditions; If so, based on the risk configuration information, use the streaming engine to generate a second streaming risk identification rule; Risk identification is performed on streaming data according to the second streaming risk identification rules to obtain the second streaming risk identification results.

7. The method according to claim 6, characterized in that, The streaming engine includes a streaming metrics engine and a streaming decision engine; The generation of the second streaming risk identification rule using a streaming engine includes: The risk configuration information is parsed using a streaming decision engine to generate streaming rule judgment logic in real-time scenarios, which serves as the second streaming risk identification rule.

8. The method according to claim 1, characterized in that, The method further includes: If the first stream risk identification result indicates that the stream data is at risk, query the database for the second batch of business data corresponding to the stream data; The risk identification results of the second batch of business data are obtained by using a batch decision engine. The results of the first-order risk identification were verified based on the results of the second-order risk identification.

9. A risk identification device, characterized in that, include: The receiving unit is used to receive risk configuration information input by the user; The first risk identification unit is used to identify risks based on risk configuration information using a batch engine, and obtain the first batch of risk identification results. The adjustment unit is used to adjust the risk configuration information based on the results of the first batch of risk identification. The generation unit is used to generate the first streaming risk identification rule based on the adjusted risk configuration information using the streaming engine. The second risk identification unit is used to identify risks in streaming data according to the first streaming risk identification rules, and obtain the first streaming risk identification result.

10. A computer device, characterized in that, include: A memory, on which computer programs are stored; A processor for executing the computer program to implement the method according to any one of claims 1-8.