A system risk grading method, device and related product based on key risk coupling enhancement

By constructing a set of risk indicators, calculating basic risk values ​​and lifecycle corrections, and screening key risk subsets, the problems of inconsistency and subjectivity in risk classification of bank information systems have been solved, realizing quantitative and traceable risk level assessment, and adapting to rapid system iteration and lifecycle changes.

CN122490153APending Publication Date: 2026-07-31LONGYING ZHIDA (BEIJING) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
LONGYING ZHIDA (BEIJING) TECH CO LTD
Filing Date
2026-04-20
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing technologies for risk classification in banking information systems suffer from problems such as inconsistent classification standards, strong subjectivity, inability to quantify, and inability to adapt to rapid system iteration and life cycle changes. In particular, they lack effective handling of the superposition and coupling amplification effects of multiple risk factors.

Method used

Construct a set of risk indicators, determine the weight coefficient of each risk indicator, collect risk indicator hit data from the system, calculate the basic risk value, screen key risk subsets, calculate the coupled and enhanced comprehensive risk value, and adjust it according to the life cycle stage to finally determine the risk level.

Benefits of technology

It enables the quantitative and automatic risk classification of bank information systems, improving the objectivity, accuracy, and consistency of the classification and adapting to changes in the system's lifecycle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122490153A_ABST
    Figure CN122490153A_ABST
Patent Text Reader

Abstract

This application provides a system risk rating method, apparatus, and related products based on key risk coupling enhancement, relating to the field of risk assessment technology. The method constructs a set of risk indicators and determines the weight coefficients corresponding to each risk indicator; collects risk indicator hit data of the system to be evaluated and calculates the basic risk value of the system based on the weight coefficients corresponding to each risk indicator in the risk indicator set; identifies the key risk subset in the risk indicator set and calculates the coupled enhancement comprehensive risk value of the system to be evaluated; matches the stage correction coefficient corresponding to the life cycle stage of the system to be evaluated and corrects the coupled enhancement comprehensive risk value to obtain the final risk value; and determines the risk control level corresponding to the system to be evaluated based on the final risk value. This application achieves quantitative and automatic rating of system risks, effectively improving the objectivity, accuracy, and consistency of risk rating.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of risk assessment technology, and in particular to a system risk rating method, apparatus and related products based on enhanced coupling of key risks. Background Technology

[0002] As the digital transformation of the financial industry continues to deepen, the online and intelligent levels of banking services are constantly improving. Bank information systems now cover all business scenarios, including fund transfers, loan approvals, foreign exchange transactions, customer information collection, biometric authentication, and integration with third-party systems. Different systems exhibit significant differences in business importance, fund security risks, data compliance risks, and internet exposure. To achieve refined management of information technology risks, the banking industry generally adopts a tiered management model, matching differentiated security control strategies to the risk level of each information system. These strategies include code review depth, penetration testing intensity, online approval processes, and operational monitoring levels. Currently, risk assessment of bank information systems primarily employs three mainstream technical solutions: qualitative judgment based on human experience, rule-triggered solutions based on a single key factor, and scoring schemes based on linear weighted multi-indicator calculations.

[0003] The aforementioned existing technical solutions suffer from numerous intractable technical flaws. Qualitative judgment schemes based on human experience heavily rely on the professional experience of reviewers, resulting in inconsistent grading standards, strong subjectivity, and significant differences in grading results among different reviewers. Furthermore, they lack a traceable quantitative calculation process, making them unsuitable for business scenarios involving rapid system iteration. Rule-triggered schemes based on single key factors complete grading only through a single risk item, ignoring the weight differences of different risk factors and failing to reflect the cumulative and coupled amplification effects of multiple risk factors, leading to rather crude grading results. Scoring schemes based on linear weighting of multiple indicators only achieve linear superposition of risks, lack regulatory guidance in weight setting, fail to prioritize fund security risks and data compliance risks, and do not consider the non-linear amplification effects triggered by key risk combinations, thus failing to meet the increasingly stringent information technology regulatory requirements of the banking industry.

[0004] Therefore, how to conduct scientific, unified, and quantifiable risk classification of the banking system has become an urgent technical problem to be solved. Summary of the Invention

[0005] In view of the above problems, this application is made to provide a system risk rating method, apparatus, and related products based on enhanced key risk coupling to overcome or at least partially solve the above problems. The technical solution is as follows: Firstly, a system risk rating method based on enhanced coupling of key risks is provided, the method comprising: Construct a set of risk indicators and determine the weight coefficient for each risk indicator in the set; Collect risk indicator hit data of the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set; Identify the key risk subset in the risk indicator set and calculate the comprehensive risk value of coupling enhancement of the system to be evaluated; Determine the lifecycle stage of the system to be evaluated and match the stage correction coefficient corresponding to the lifecycle stage. The comprehensive risk value of coupling enhancement is corrected based on the stage correction coefficient to obtain the final risk value of the system to be evaluated. According to the preset risk level classification rules, the risk control level of the system to be evaluated is determined based on the final risk value.

[0006] In one possible implementation, risk indicator hit data of the system to be evaluated is collected, and based on the weight coefficient corresponding to each risk indicator in the risk indicator set, the basic risk value of the system to be evaluated is calculated, including: A risk presence coefficient is set for each risk indicator in the risk indicator set. The risk presence coefficient is determined based on the hit status of the corresponding risk indicator of the system to be evaluated. Calculate the baseline risk value of the system to be evaluated. The formula for calculating the baseline risk value satisfies: (1) In equation (1), The base risk value is given by n, where n is the total number of risk indicators in the risk indicator set. The weight coefficient is the value corresponding to the i-th risk indicator in the set of risk indicators. Let be the risk existence coefficient corresponding to the i-th risk indicator in the risk indicator set.

[0007] In one possible implementation, a risk presence coefficient is set for each risk indicator in the risk indicator set, including: When the risk status of the corresponding risk indicator in the system to be evaluated is fully present, the risk presence coefficient is 1. When the risk status of the corresponding risk indicator in the system to be evaluated is partially present, the risk presence coefficient is 0.5. When the risk status of the corresponding risk indicator in the system to be evaluated is non-existent, the risk existence coefficient is 0.

[0008] In one possible implementation, a key risk subset is identified from the set of risk indicators, and the combined risk value of enhanced coupling of the system to be evaluated is calculated, including: Select risk indicators from the risk indicator set that meet the preset key threshold for their impact on system security, and form a key risk subset; Calculate the risk presence coefficient corresponding to each risk indicator in the key risk subset, and then calculate the sum of the key risk presence degrees. Calculate the comprehensive risk value of coupling enhancement for the system to be evaluated. The formula for calculating the comprehensive risk value of coupling enhancement satisfies: (2) In equation (2), To enhance the overall risk value, The preset coupling enhancement coefficient, The sum of the degree of existence of key risks. For a subset of key risks, This represents the total number of risk indicators within the key risk subset.

[0009] In one possible implementation, the combined risk value of enhanced coupling is corrected based on a stage correction coefficient to obtain the final risk value of the system to be evaluated, including: Calculate the final risk value of the system to be evaluated. The formula for calculating the final risk value satisfies: (3) In equation (3), C is the final risk value. This is the stage correction factor corresponding to the life cycle stage of the system to be evaluated. The value of is greater than or equal to 1.

[0010] In one possible implementation, the risk control level of the system to be evaluated is determined based on the final risk value according to a preset risk level classification rule, including: Set multiple consecutive final risk value ranges, with each final risk value range corresponding to a risk control level; Match the final risk value of the system to be evaluated to the range of final risk values ​​to determine the corresponding risk control level; Risk management levels include at least high risk, medium risk, and low risk.

[0011] Secondly, a system risk rating device based on enhanced coupling of key risks is provided, the device comprising: The indicator construction unit is used to construct a set of risk indicators and determine the weight coefficient corresponding to each risk indicator in the set of risk indicators. The basic calculation unit is used to collect the risk indicator hit data of the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set. The coupling enhancement calculation unit is used to determine the key risk subset in the risk indicator set and calculate the coupling enhancement comprehensive risk value of the system to be evaluated. The lifecycle determination unit is used to determine the lifecycle stage of the system to be evaluated and match the stage correction coefficient corresponding to the lifecycle stage. The final risk calculation unit is used to correct the comprehensive risk value of coupling enhancement based on the stage correction coefficient to obtain the final risk value of the system to be evaluated. The risk rating unit is used to determine the risk control level of the system to be evaluated based on the final risk value according to the preset risk level classification rules.

[0012] Thirdly, an electronic device is provided, comprising a processor and a memory, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the system risk rating method based on key risk coupling enhancement as described in any of the preceding claims.

[0013] Fourthly, a storage medium is provided that stores a computer program, wherein the computer program is configured to execute the system risk rating method based on key risk coupling enhancement as described above at runtime.

[0014] Fifthly, a computer program product is provided, including a computer program configured to execute the system risk rating method based on key risk coupling enhancement as described above at runtime.

[0015] By employing the above technical solutions, the system risk rating method, apparatus, and related products based on key risk coupling enhancement provided in this application embodiment involve: constructing a set of risk indicators and determining the weight coefficients corresponding to each risk indicator; collecting risk indicator hit data of the system to be evaluated and calculating the basic risk value of the system to be evaluated; determining the key risk subset in the risk indicator set and calculating the coupled enhancement comprehensive risk value of the system to be evaluated; matching the stage correction coefficient corresponding to the life cycle stage of the system to be evaluated and correcting the coupled enhancement comprehensive risk value to obtain the final risk value; and determining the risk control level corresponding to the system to be evaluated based on the final risk value. This application embodiment achieves quantitative and automatic system risk rating, effectively improving the objectivity, accuracy, and consistency of risk rating. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below.

[0017] Figure 1 A flowchart of a system risk rating method based on enhanced coupling of key risks provided in an embodiment of this application is shown; Figure 2A flowchart of a system risk rating method based on enhanced coupling of key risks provided in a specific embodiment of this application is shown; Figure 3 The diagram shows the structure of the system risk rating device based on enhanced coupling of key risks provided in an embodiment of this application; Figure 4 A structural diagram of an electronic device provided in an embodiment of this application is shown. Detailed Implementation

[0018] Exemplary embodiments of the present application will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the scope of the present application to those skilled in the art.

[0019] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such use can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the term "comprising" and its variations should be interpreted as open-ended terms meaning "including but not limited to."

[0020] Through analysis, the inventors discovered that in the scenario of risk level assessment for information systems in the financial industry, existing technologies mainly achieve risk classification through three methods: manual experience judgment, single-factor triggering rules, or simple linear weighted scoring. Manual judgment relies on the subjective experience of reviewers, resulting in inconsistent standards and difficulty in traceability. Single-factor rules only trigger level adjustments based on isolated conditions such as "whether it involves fund transactions," ignoring the coupled amplification effect of multiple risk factors. Although simple linear weighting introduces quantitative scoring, the weight setting lacks regulatory guidance and does not prioritize fund risks and data compliance risks. Furthermore, it cannot adapt to risk fluctuations at different lifecycle stages, such as new system launches and major version changes. This points to the direction for technical optimization of risk classification in banking systems: it is necessary to build a quantifiable, traceable, and dynamically adaptable risk calculation model without relying on manual experience intervention or using nonlinear combination enumeration, thereby achieving a leap from linear scoring to nonlinear coupled assessment.

[0021] To address the aforementioned technical problems, embodiments of this application provide a system risk rating method based on enhanced coupling of key risks, such as... Figure 1 As shown, the system risk rating method based on enhanced coupling of key risks may include the following steps S101 to S106: Step S101: Construct a set of risk indicators and determine the weight coefficient corresponding to each risk indicator in the set of risk indicators.

[0022] In one possible implementation, the aforementioned risk indicator set can be understood as a multi-dimensional risk indicator system constructed for risk assessment of various information systems. It may include risk indicators in dimensions such as business risk, data compliance risk, and internet exposure risk. This embodiment does not limit the types and number of risk indicators.

[0023] In another possible implementation, the aforementioned weighting coefficient can be understood as the importance coefficient corresponding to each risk indicator set according to regulatory requirements, the degree of risk impact, and historical risk event data. The value of the weighting coefficient is positively correlated with the degree of impact of the risk indicator on system security. This embodiment does not restrict the value setting of the weighting coefficient.

[0024] Step S102: Collect the risk indicator hit data of the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set.

[0025] In one possible implementation, the aforementioned risk indicator hit data can be understood as the relevant data of the actual risk indicators existing in the system to be evaluated, reflecting the matching status between the system to be evaluated and each indicator in the risk indicator set.

[0026] In another possible implementation, the aforementioned basic risk value can be understood as a static risk value calculated by the system to be evaluated based on the weight coefficients of each risk indicator and the hit status, which is the basic reference value for risk rating.

[0027] Step S103: Determine the key risk subset in the risk indicator set and calculate the coupling enhancement comprehensive risk value of the system to be evaluated.

[0028] In one possible implementation, the aforementioned key risk subset can be understood as a subset of risk indicators that have a significant impact on the security of the system to be evaluated, selected from the set of risk indicators. This subset is the core set of indicators that can trigger major risks in the system to be evaluated.

[0029] In another possible implementation, the aforementioned coupled enhanced comprehensive risk value can be understood as a risk value calculated by superimposing the coupling amplification effect between key risk factors on the basis of the basic risk value, reflecting the comprehensive impact of multiple key risks superimposed.

[0030] Step S104: Determine the life cycle stage of the system to be evaluated and match the stage correction coefficient corresponding to the life cycle stage.

[0031] In one possible implementation, the aforementioned lifecycle stages encompass the entire process of the system to be evaluated from launch to operation and maintenance, including at least the new launch stage, the major version change stage, and the stable operation stage.

[0032] In another possible implementation, the aforementioned stage correction coefficient can be understood as a correction coefficient set according to the risk characteristics of the life cycle stage of the system to be evaluated, used to reflect the risk differences at different stages.

[0033] Step S105: Correct the comprehensive risk value of coupling enhancement based on the stage correction coefficient to obtain the final risk value of the system to be evaluated.

[0034] In one possible implementation, the aforementioned final risk value can be understood as the risk value of the coupled enhanced comprehensive risk value after life cycle stage correction, which is the core basis for risk rating of the system to be evaluated.

[0035] In another possible implementation, the above correction operation involves multiplying the coupled enhanced comprehensive risk value with the matched stage correction coefficient to achieve differentiated quantification of system risk at different life cycle stages.

[0036] Step S106: Determine the risk control level of the system to be evaluated based on the final risk value according to the preset risk level classification rules.

[0037] In one possible implementation, the aforementioned risk level classification rule can be understood as a level matching rule based on the final risk value range preset according to risk control requirements. Fuzzy clustering or decision tree models can be used, and the classification threshold can be dynamically adjusted according to historical classification results. This embodiment does not limit the specific algorithm of the risk level classification rule.

[0038] This embodiment constructs a set of risk indicators and determines the weight coefficients corresponding to each risk indicator; collects risk indicator hit data of the system to be evaluated and calculates the basic risk value of the system to be evaluated; determines the key risk subset in the risk indicator set and calculates the coupling enhancement comprehensive risk value of the system to be evaluated; matches the stage correction coefficient corresponding to the life cycle stage of the system to be evaluated and corrects the coupling enhancement comprehensive risk value to obtain the final risk value; and determines the risk control level corresponding to the system to be evaluated based on the final risk value, thereby realizing the quantitative and automatic classification of system risk and effectively improving the objectivity, accuracy and consistency of risk classification.

[0039] This application embodiment provides a possible implementation method. In step S102 above, risk indicator hit data of the system to be evaluated is collected, and the basic risk value of the system to be evaluated is calculated based on the weight coefficient corresponding to each risk indicator in the risk indicator set. Specifically, it may include the following steps A1 to A2: Step A1: Set a risk presence coefficient for each risk indicator in the risk indicator set. The risk presence coefficient is determined based on the hit status of the corresponding risk indicator of the system to be evaluated. Step A2, calculate the basic risk value of the system to be evaluated. The formula for calculating the basic risk value satisfies: (1) In equation (1), The base risk value is given by n, where n is the total number of risk indicators in the risk indicator set. The weight coefficient is the value corresponding to the i-th risk indicator in the set of risk indicators. Let be the risk existence coefficient corresponding to the i-th risk indicator in the risk indicator set.

[0040] This embodiment sets a risk existence coefficient for each risk indicator in the risk indicator set, transforming the qualitative hit status of the system to be evaluated for each risk indicator into a quantifiable numerical expression. It aggregates and quantifies the scattered and multidimensional risk indicator hit data into a unified basic risk value, providing a standardized and traceable quantitative input basis for subsequent coupled enhancement calculations and risk rating.

[0041] This application embodiment provides a possible implementation method, in which step A1 above sets a risk existence coefficient for each risk indicator in the risk indicator set, which may specifically include the following steps: When the risk status of the corresponding risk indicator in the system to be evaluated is fully present, the risk presence coefficient is 1. When the risk status of the corresponding risk indicator in the system to be evaluated is partially present, the risk presence coefficient is 0.5. When the risk status of the corresponding risk indicator in the system to be evaluated is non-existent, the risk existence coefficient is 0.

[0042] This embodiment sets a discretized risk presence coefficient for each risk indicator in the risk indicator set, quantifying the hit status of the system to be evaluated for each risk into three levels. This discretization method avoids subjective judgment fluctuations caused by continuous value taking while maintaining distinguishable evaluation granularity, making the calculation of basic risk values ​​more stable and reproducible.

[0043] This application embodiment provides a possible implementation method. The above step S103, which determines the key risk subset in the risk indicator set and calculates the comprehensive risk value of coupling enhancement of the system to be evaluated, may specifically include the following steps: Select risk indicators from the risk indicator set that meet the preset key threshold for their impact on system security, and form a key risk subset; Calculate the risk presence coefficient corresponding to each risk indicator in the key risk subset, and then calculate the sum of the key risk presence degrees. Calculate the comprehensive risk value of coupling enhancement for the system to be evaluated. The formula for calculating the comprehensive risk value of coupling enhancement satisfies: (2) In equation (2), To enhance the overall risk value, The preset coupling enhancement coefficient, The sum of the degree of existence of key risks. For a subset of key risks, This represents the total number of risk indicators within the key risk subset.

[0044] In this embodiment, the preset key threshold can be understood as a critical value for determining the importance of risk indicators based on regulatory compliance requirements, information system security control standards, and historical major risk event causal analysis. It is used to accurately identify core risk items that have a decisive impact on the overall security of the system from all risk indicators. For example, in the scenario of risk assessment of bank information systems, the preset key threshold can be set to a risk indicator weight ratio of not less than 0.2. Through coupled enhanced calculation, the nonlinear amplification effect generated by the superposition of multiple key risks is accurately quantified, making the risk calculation results more consistent with the risk transmission law in the actual operation of the system to be assessed.

[0045] This application embodiment provides a possible implementation method. Step S105 above corrects the comprehensive risk value of coupling enhancement based on the stage correction coefficient to obtain the final risk value of the system to be evaluated. Specifically, it may include the following steps: Calculate the final risk value of the system to be evaluated. The formula for calculating the final risk value satisfies: (3) In equation (3), C is the final risk value. This is the stage correction factor corresponding to the life cycle stage of the system to be evaluated. The value of is greater than or equal to 1.

[0046] This embodiment introduces a lifecycle stage correction coefficient to nonlinearly correct the comprehensive risk value of enhanced coupling, thereby quantifying the dynamic differences in risk of the system at different stages into a multiplicative factor. This allows the risk value of the system to be evaluated to be appropriately amplified when it is newly launched or has just undergone major changes, while the risk value of the system during the stable operation period remains at the benchmark level. Finally, it outputs a comprehensive rating basis that can reflect the static risk superposition and coupling effect and adapt to the risk fluctuations of the system to be evaluated throughout its entire lifecycle.

[0047] This application embodiment provides a possible implementation method. Step S106 above determines the risk control level of the system to be evaluated according to the final risk value based on a preset risk level classification rule. Specifically, it may include the following steps: Set multiple consecutive final risk value ranges, with each final risk value range corresponding to a risk control level; Match the final risk value of the system to be evaluated to the range of final risk values ​​to determine the corresponding risk control level; Risk management levels include at least high risk, medium risk, and low risk.

[0048] This embodiment transforms the abstract final risk value into an operable risk control level by setting multiple sets of continuous final risk value intervals. Specifically, the risk value interval is used as the dividing granularity, and each interval is pre-associated with a corresponding risk control level, thereby realizing the mapping from continuous values ​​to discrete levels, which facilitates the subsequent implementation of differentiated safety control measures based on the level.

[0049] The above introduces Figure 1 The embodiments shown have various implementation methods for each stage. The following will further explain the system risk rating method based on key risk coupling enhancement of this application through specific embodiments.

[0050] like Figure 2 As shown in the figure, this specific embodiment takes a bank's personal online banking system as the object to be evaluated, and the implementation process is described below.

[0051] I. Risk Indicator System Construction Phase 1. Constructing a Risk Indicator Set: The risk indicator set constructed in this embodiment includes four risk indicators: fund transaction risk, customer core information processing risk, internet exposure risk, and third-party system integration risk. 2. Determine the weighting coefficients for each risk indicator. The following weighting coefficients are set for the risk indicators: the weighting coefficient for fund transaction risk is 0.4, the weighting coefficient for customer core information processing risk is 0.3, the weighting coefficient for internet exposure risk is 0.2, and the weighting coefficient for third-party system integration risk is 0.1.

[0052] II. Basic Risk Value Calculation Stage 1. Identify the business functions and technical characteristics of the system to be evaluated. The system to be evaluated is a bank's personal online banking system, which has the business functions and technical characteristics of personal fund transfer, customer identity information storage, external Internet access, and connection with third-party payment institutions. 2. Set the risk existence coefficient corresponding to each risk indicator. Based on the hit status of the risk indicators of the system to be evaluated, a risk presence coefficient is set for each risk indicator: The risk of fund transactions is fully present, and the risk coefficient is set to 1. The risk of processing core customer information exists, and the risk coefficient is 1. The risks of internet exposure to the outside world are fully present, with a risk coefficient of 1. There is a full existence of risk in connecting with third-party systems, with a risk coefficient of 1. 3. Calculate the basic risk value of the system to be evaluated. Combining the weight coefficients and risk existence coefficients corresponding to the above risk indicators, the basic risk value of the system to be evaluated is calculated to be 1.0.

[0053] III. Calculation Stage of Coupling Enhancement Integrated Risk Value 1. Determine the key risk subset. In this embodiment, the preset key threshold is that the risk indicator weight coefficient is not less than 0.2. Risk indicators that meet the preset key threshold are selected from the risk indicator set to form a key risk subset. The key risk subset includes three indicators: fund transaction risk, customer core information processing risk, and Internet external exposure risk. The total number of risk indicators in the key risk subset is 3. 2. Calculate the total presence degree of key risks by statistically analyzing the risk presence coefficients corresponding to each risk indicator in the key risk subset. The total presence degree of key risks is calculated to be 3. 3. Setting the coupling enhancement coefficient: In this specific embodiment, the preset coupling enhancement coefficient is 0.5; 4. Calculate the comprehensive risk value of coupling enhancement. Combining the basic risk value, coupling enhancement coefficient, sum of the existence degree of key risks, and the total number of risk indicators in the key risk subset, the comprehensive risk value of coupling enhancement of the system to be evaluated is calculated to be 2.5.

[0054] IV. Final Risk Value Calculation Stage 1. Determine the lifecycle stage of the system to be evaluated. The system to be evaluated is a new system that has been online for less than 3 months, and its lifecycle stage is determined to be the new launch stage. 2. Matching Phase Correction Coefficient: The phase correction coefficient corresponding to the newly launched matching phase is 1.2. 3. The final risk value is calculated by combining the coupled enhanced comprehensive risk value with the stage correction coefficient obtained by matching. The final risk value of the system to be evaluated is 3.0.

[0055] V. Risk Control Level Determination Stage 1. Preset Risk Level Classification Rules: The preset risk level classification rules in this embodiment are as follows: a final risk value greater than or equal to 2.5 corresponds to a high risk level, a final risk value of 1.0-2.5 corresponds to a medium risk level, and a final risk value less than 1.0 corresponds to a low risk level. 2. Determine the risk control level range to match the final risk value of the system to be evaluated, determine that the risk control level of the system to be evaluated is high risk, and output the control level result of the system.

[0056] This specific embodiment achieves quantitative and automatic risk classification of the banking system through basic risk weighted calculation, key risk coupling enhancement calculation, and life cycle stage correction, effectively improving the objectivity, accuracy, and consistency of risk classification.

[0057] It should be noted that the sequence numbers of the steps in the above embodiments do not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. In practical applications, all the above possible implementation methods can be arbitrarily combined in a combined manner to form possible embodiments of this application, which will not be described in detail here.

[0058] Based on the system risk assessment method based on key risk coupling enhancement provided in the above embodiments, and based on the same inventive concept, this application also provides a system risk assessment device based on key risk coupling enhancement.

[0059] Figure 3 This is a structural diagram of the system risk rating device based on enhanced coupling of key risks provided in an embodiment of this application. Figure 3 As shown, the system risk rating device based on key risk coupling enhancement may specifically include an indicator construction unit 210, a basic calculation unit 220, a coupling enhancement calculation unit 230, a life cycle determination unit 240, a final risk calculation unit 250, and a risk rating unit 260.

[0060] The indicator construction unit 210 is used to construct a set of risk indicators and determine the weight coefficient corresponding to each risk indicator in the set of risk indicators. The basic calculation unit 220 is used to collect the risk indicator hit data of the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set. The coupling enhancement calculation unit 230 is used to determine the key risk subset in the risk indicator set and calculate the coupling enhancement comprehensive risk value of the system to be evaluated. Lifecycle determination unit 240 is used to determine the lifecycle stage of the system to be evaluated and match the stage correction coefficient corresponding to the lifecycle stage. The final risk calculation unit 250 is used to correct the comprehensive risk value of coupling enhancement based on the stage correction coefficient to obtain the final risk value of the system to be evaluated. Risk rating unit 260 is used to determine the risk control level of the system to be evaluated based on the final risk value according to the preset risk level classification rules.

[0061] This application embodiment provides a possible implementation, wherein the basic computing unit 220 is further configured to: A risk presence coefficient is set for each risk indicator in the risk indicator set. The risk presence coefficient is determined based on the hit status of the corresponding risk indicator of the system to be evaluated. Calculate the baseline risk value of the system to be evaluated. The formula for calculating the baseline risk value satisfies: (1) In equation (1), The base risk value is given by n, where n is the total number of risk indicators in the risk indicator set. The weight coefficient is the value corresponding to the i-th risk indicator in the set of risk indicators. Let be the risk existence coefficient corresponding to the i-th risk indicator in the risk indicator set.

[0062] This application embodiment provides a possible implementation, wherein the basic computing unit 220 is further configured to: When the risk status of the corresponding risk indicator in the system to be evaluated is fully present, the risk presence coefficient is 1. When the risk status of the corresponding risk indicator in the system to be evaluated is partially present, the risk presence coefficient is 0.5. When the risk status of the corresponding risk indicator in the system to be evaluated is non-existent, the risk existence coefficient is 0.

[0063] This application embodiment provides a possible implementation, wherein the coupling enhancement computing unit 230 is further configured to: Select risk indicators from the risk indicator set that meet the preset key threshold for their impact on system security, and form a key risk subset; Calculate the risk presence coefficient corresponding to each risk indicator in the key risk subset, and then calculate the sum of the key risk presence degrees. Calculate the comprehensive risk value of coupling enhancement for the system to be evaluated. The formula for calculating the comprehensive risk value of coupling enhancement satisfies: (2) In equation (2), To enhance the overall risk value, The preset coupling enhancement coefficient, The sum of the degree of existence of key risks. For a subset of key risks, This represents the total number of risk indicators within the key risk subset.

[0064] This application embodiment provides a possible implementation, wherein the final risk calculation unit 250 is further configured to: Calculate the final risk value of the system to be evaluated. The formula for calculating the final risk value satisfies: (3) In equation (3), C is the final risk value. This is the stage correction factor corresponding to the life cycle stage of the system to be evaluated. The value of is greater than or equal to 1.

[0065] This application embodiment provides a possible implementation, wherein the risk rating unit 260 is further configured to: Set multiple consecutive final risk value ranges, with each final risk value range corresponding to a risk control level; Match the final risk value of the system to be evaluated to the range of final risk values ​​to determine the corresponding risk control level; Risk management levels include at least high risk, medium risk, and low risk.

[0066] Based on the same inventive concept, embodiments of this application also provide an electronic device, including a processor and a memory, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the system risk rating method based on key risk coupling enhancement of any of the above embodiments.

[0067] In an exemplary embodiment, an electronic device is provided, such as Figure 4 As shown, Figure 4 The illustrated electronic device 300 includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the electronic device 300 may also include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one type, and the structure of this electronic device 300 does not constitute a limitation on the embodiments of this application.

[0068] Processor 301 may be a CPU (Central Processing Unit), GPU (Graphics Processing Unit), DSP (Digital Signal Processor), ASIC (Application Specific Integrated Circuit), FPGA, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 301 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0069] Bus 302 may include a pathway for transmitting information between the aforementioned components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 302 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0070] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device capable of storing static information and instructions, RAM (Random Access Memory) or other type of dynamic storage device capable of storing information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.

[0071] The memory 303 stores computer program code that executes the scheme of this application, and its execution is controlled by the processor 301. The processor 301 executes the computer program code stored in the memory 303 to implement the content shown in the foregoing method embodiments.

[0072] Among them, electronic devices include, but are not limited to: mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 4 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0073] Based on the same inventive concept, this application also provides a storage medium storing a computer program, wherein the computer program is configured to execute the system risk rating method based on key risk coupling enhancement of any of the above embodiments when running.

[0074] Based on the same inventive concept, this application also provides a computer program product, including a computer program configured to execute the system risk rating method based on key risk coupling enhancement of any of the above embodiments at runtime.

[0075] Those skilled in the art will clearly understand that the specific working process of the systems, devices, and modules described above can be referred to the corresponding process in the foregoing method embodiments. For the sake of brevity, it will not be repeated here.

[0076] Those skilled in the art will understand that the technical solution of this application, or all or part of it, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several program instructions to cause an electronic device (e.g., a personal computer, server, or network device) to execute all or part of the steps of the methods described in the embodiments of this application when running the program instructions. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, portable hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0077] Alternatively, all or part of the steps of the foregoing method embodiments can be implemented by hardware (such as electronic devices like personal computers, servers, or network devices) associated with program instructions. The program instructions can be stored in a computer-readable storage medium. When the program instructions are executed by the processor of the electronic device, the electronic device executes all or part of the steps of the methods described in the embodiments of this application.

[0078] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that within the spirit and principles of this application, modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein; and these modifications or substitutions do not cause the corresponding technical solutions to leave the protection scope of this application.

Claims

1. A system risk rating method based on enhanced coupling of key risks, characterized in that, The method includes: Construct a set of risk indicators and determine the weight coefficient for each risk indicator in the set; Collect risk indicator hit data of the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set; Identify the key risk subset in the risk indicator set and calculate the comprehensive risk value of coupling enhancement of the system to be evaluated; Determine the lifecycle stage of the system to be evaluated and match the stage correction coefficient corresponding to the lifecycle stage. The comprehensive risk value of coupling enhancement is corrected based on the stage correction coefficient to obtain the final risk value of the system to be evaluated. According to the preset risk level classification rules, the risk control level of the system to be evaluated is determined based on the final risk value.

2. The method according to claim 1, characterized in that, Collect risk indicator hit data for the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set, including: A risk presence coefficient is set for each risk indicator in the risk indicator set. The risk presence coefficient is determined based on the hit status of the corresponding risk indicator of the system to be evaluated. Calculate the baseline risk value of the system to be evaluated. The formula for calculating the baseline risk value satisfies: (1) In equation (1), The base risk value is given by n, where n is the total number of risk indicators in the risk indicator set. The weight coefficient is the value corresponding to the i-th risk indicator in the set of risk indicators. Let be the risk existence coefficient corresponding to the i-th risk indicator in the risk indicator set.

3. The method according to claim 2, characterized in that, Assign a risk presence coefficient to each risk indicator in the risk indicator set, including: When the risk status of the corresponding risk indicator in the system to be evaluated is fully present, the risk presence coefficient is 1. When the risk status of the corresponding risk indicator in the system to be evaluated is partially present, the risk presence coefficient is 0.

5. When the risk status of the corresponding risk indicator in the system to be evaluated is non-existent, the risk existence coefficient is 0.

4. The method according to claim 2, characterized in that, Identify the key risk subset from the risk indicator set and calculate the comprehensive risk value of coupling enhancement of the system to be evaluated, including: Select risk indicators from the risk indicator set that meet the preset key threshold for their impact on system security, and form a key risk subset; Calculate the risk presence coefficient corresponding to each risk indicator in the key risk subset, and then calculate the sum of the key risk presence degrees. Calculate the comprehensive risk value of coupling enhancement for the system to be evaluated. The formula for calculating the comprehensive risk value of coupling enhancement satisfies: (2) In equation (2), To enhance the overall risk value, The preset coupling enhancement coefficient, The sum of the degree of existence of key risks. For a subset of key risks, This represents the total number of risk indicators within the key risk subset.

5. The method according to claim 4, characterized in that, The overall risk value of enhanced coupling is corrected based on the stage correction coefficient to obtain the final risk value of the system to be evaluated, including: Calculate the final risk value of the system to be evaluated. The formula for calculating the final risk value satisfies: (3) In equation (3), C is the final risk value. This is the stage correction factor corresponding to the life cycle stage of the system to be evaluated. The value of is greater than or equal to 1.

6. The method according to claim 1, characterized in that, According to the preset risk level classification rules, the risk control level corresponding to the system to be evaluated is determined based on the final risk value, including: Set multiple consecutive final risk value ranges, with each final risk value range corresponding to a risk control level; Match the final risk value of the system to be evaluated to the range of final risk values ​​to determine the corresponding risk control level; Risk management levels include at least high risk, medium risk, and low risk.

7. A system risk rating device based on enhanced coupling of key risks, characterized in that, The device includes: The indicator construction unit is used to construct a set of risk indicators and determine the weight coefficient corresponding to each risk indicator in the set of risk indicators. The basic calculation unit is used to collect the risk indicator hit data of the system to be evaluated, and calculate the basic risk value of the system to be evaluated based on the weight coefficient corresponding to each risk indicator in the risk indicator set. The coupling enhancement calculation unit is used to determine the key risk subset in the risk indicator set and calculate the coupling enhancement comprehensive risk value of the system to be evaluated. The lifecycle determination unit is used to determine the lifecycle stage of the system to be evaluated and match the stage correction coefficient corresponding to the lifecycle stage. The final risk calculation unit is used to correct the comprehensive risk value of coupling enhancement based on the stage correction coefficient to obtain the final risk value of the system to be evaluated. The risk rating unit is used to determine the risk control level of the system to be evaluated based on the final risk value according to the preset risk level classification rules.

8. An electronic device, characterized in that, It includes a processor and a memory, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the system risk rating method based on key risk coupling enhancement as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium stores a computer program, wherein the computer program is configured to execute the system risk rating method based on key risk coupling enhancement as described in any one of claims 1 to 6 when it runs.

10. A computer program product, comprising a computer program, characterized in that, The computer program is configured to execute the system risk rating method based on key risk coupling enhancement as described in any one of claims 1 to 6 at runtime.