An enterprise-oriented whole-link business flow conversion data intelligent monitoring method and system

CN122819684APending Publication Date: 2026-09-25SHENZHEN ZHANQUN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611227266.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-13
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0003]本申请提供一种面向企业全链路业务流转数据智能监测方法及系统,用于针对解决现有技术中无法有效识别权限有效但业务流转路径非法的越权数据流转的技术问题

Benefits of technology

本申请获取预设时间段内的业务流转日志,所述业务流转日志包含业务单据标识、操作主体标识及操作时间戳;构建组织架构时态图,所述组织架构时态图由多个带有生效时间区间的授权边组成;将所述业务流转日志抽象为流转边,所述流转边的起点为操作主体所属的组织节点,终点为业务单据当前所处的业务节点;针对每一流转边,在所述组织架构时态图中执行时空可达性查询,判断在所述流转边对应的操作时间戳下,所述流转边的起点至终点是否存在有效授权路径,若不存在,则将所述流转边标记为影子流转边;统计预设监测窗口内的影子流转边数量,当所述影子流转边数量超过预设阈值时,输出权限越界告警信息。本发明解决现有技术中无法有效识别权限有效但业务流转路径非法的越权数据流转的技术问题,通过基于组织架构时态图对业务流转路径进行动态授权校验,达到精准识别非法流转路径并实现业务数据流转合规监测的技术效果。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122819684A_ABST
    Figure CN122819684A_ABST
Patent Text Reader

Abstract

The application discloses a kind of enterprise-oriented whole-link business flow transfer data intelligent monitoring method and system, it is related to data processing technical field, comprising: obtaining the business flow transfer log in preset time period, extract business document, operation subject and time information;According to the authorized edge with effective time interval, the organization architecture time graph is constructed;Business flow transfer log is mapped into the transfer edge by the node where business document is located by the organization node of operation subject is directed;In combination with the operation time stamp of transfer edge, execute space-time accessibility query, judge whether there is effective authorized path from starting point to terminal, and mark the transfer edge without effective path as shadow transfer edge;The number of shadow transfer edge in monitoring window is counted, and when exceeding preset threshold, output permission out-of-bound alarm.The application solves the technical problem that the over-authorization data flow transfer of which permission is effective but business flow transfer path is illegal cannot be effectively identified in the prior art, to achieve the technical effect of accurately identifying illegal flow transfer path and realizing business data flow transfer compliance monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, specifically to a method and system for intelligent monitoring of data in the entire business flow of an enterprise. Background Technology

[0002] Enterprise business data typically needs to flow between different organizations, positions, and business nodes. Monitoring methods often rely on static permission configurations for accounts or positions, primarily verifying whether the operating entity possesses the corresponding permissions. However, due to factors such as job changes, expired temporary authorizations, organizational restructuring, or account theft, authorization status may change. Relying solely on permission configurations is insufficient to dynamically verify the actual flow path from the operating entity's organizational node to the business node at the time of the business operation. This can easily lead to situations where the operating entity appears to have valid permissions, but the corresponding business data flow path has deviated from the valid authorization relationship, making it difficult to identify unauthorized data flows in a timely and accurate manner. Summary of the Invention

[0003] This application provides a method and system for intelligent monitoring of enterprise end-to-end business flow data, which addresses the technical problem in existing technologies that cannot effectively identify unauthorized data flows with valid permissions but illegal business flow paths.

[0004] In view of the above problems, this application provides a method and system for intelligent monitoring of enterprise end-to-end business flow data.

[0005] The first aspect of this application provides a method for intelligent monitoring of enterprise end-to-end business flow data, the method comprising: Obtain business flow logs within a preset time period. The business flow logs include business document identifiers, operation subject identifiers, and operation timestamps. Construct an organizational structure temporal graph, which consists of multiple authorization edges with effective time intervals. Abstract the business flow logs into flow edges, where the starting point of each flow edge is the organizational node to which the operation subject belongs, and the ending point is the business node where the business document is currently located. For each flow edge, perform a spatiotemporal reachability query in the organizational structure temporal graph to determine whether a valid authorization path exists from the starting point to the ending point of the flow edge under the operation timestamp corresponding to the flow edge. If no valid path exists, mark the flow edge as a shadow flow edge. Count the number of shadow flow edges within a preset monitoring window. When the number of shadow flow edges exceeds a preset threshold, output an access control outage alarm.

[0006] A second aspect of this application provides an intelligent monitoring system for enterprise end-to-end business flow data, the system comprising: The data acquisition module is used to acquire business flow logs within a preset time period. The business flow logs include business document identifiers, operation subject identifiers, and operation timestamps. The graph construction module is used to construct an organizational structure temporal graph, which consists of multiple authorization edges with effective time intervals. The abstraction module is used to abstract the business flow logs into flow edges. The starting point of each flow edge is the organizational node to which the operation subject belongs, and the ending point is the business node where the business document is currently located. The judgment module is used to perform a spatiotemporal reachability query in the organizational structure temporal graph for each flow edge, and to determine whether there is a valid authorization path from the starting point to the ending point of the flow edge under the operation timestamp corresponding to the flow edge. If not, the flow edge is marked as a shadow flow edge. The alarm information output module is used to count the number of shadow flow edges within a preset monitoring window. When the number of shadow flow edges exceeds a preset threshold, an over-limit permission alarm message is output.

[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages: This application obtains business flow logs within a preset time period. The business flow logs include business document identifiers, operation subject identifiers, and operation timestamps. It constructs an organizational structure temporal graph, which consists of multiple authorization edges with effective time intervals. The business flow logs are abstracted as flow edges, with the starting point of each flow edge being the organizational node to which the operation subject belongs, and the ending point being the business node where the business document is currently located. For each flow edge, a spatiotemporal reachability query is performed in the organizational structure temporal graph to determine whether a valid authorization path exists from the starting point to the ending point of the flow edge under the corresponding operation timestamp. If no valid path exists, the flow edge is marked as a shadow flow edge. The number of shadow flow edges within a preset monitoring window is counted. When the number of shadow flow edges exceeds a preset threshold, an out-of-bounds permission alarm is output. This invention solves the technical problem in the prior art of failing to effectively identify unauthorized data flow with valid permissions but illegal business flow paths. By dynamically verifying the authorization of business flow paths based on the organizational structure temporal graph, it achieves the technical effect of accurately identifying illegal flow paths and realizing compliant monitoring of business data flow. Attached Figure Description

[0008] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0009] Figure 1 This application provides a schematic diagram of a method for intelligent monitoring of enterprise end-to-end business flow data. Figure 2 This is a schematic diagram of the structure of an intelligent monitoring system for enterprise end-to-end business flow data, provided as an embodiment of this application.

[0010] Figure labeling: Data acquisition module 11, graph construction module 12, abstraction module 13, judgment module 14, alarm information output module 15. Detailed Implementation

[0011] This application provides an intelligent monitoring method and system for enterprise end-to-end business flow data. It addresses the technical problem in existing technologies that cannot effectively identify unauthorized data flows with valid permissions but illegal business flow paths. By dynamically verifying the authorization of business flow paths based on the organizational structure temporal diagram, it achieves the technical effect of accurately identifying illegal flow paths and realizing compliance monitoring of business data flow.

[0012] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0013] It should be noted that any variation of the terms "comprising" and "having" is intended to cover non-exclusive inclusion, for example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such processes, methods, products, or devices.

[0014] Example 1, as Figure 1 As shown, this application provides an intelligent monitoring method for enterprise end-to-end business flow data, the method comprising: Step S100: Obtain the business flow log within a preset time period. The business flow log includes the business document identifier, the operation subject identifier, and the operation timestamp.

[0015] In this embodiment, based on the start and end times corresponding to a preset time period, log records whose operation times fall within that time range are selected from the log storage area of ​​the enterprise business system. A business document identifier, an operation subject identifier, and an operation timestamp are extracted from each log record to obtain the business flow log within the preset time period. The business document identifier uniquely identifies the business document being operated on, the operation subject identifier uniquely identifies the subject performing the corresponding business operation, and the operation timestamp represents the actual time of occurrence of the corresponding business operation. This allows each business operation to be matched according to the business document, operation subject, and occurrence time.

[0016] Step S200: Construct an organizational structure temporal diagram, which consists of multiple authorization edges with effective time intervals.

[0017] In this embodiment, firstly, permission change records in the human resources system are collected, and the start time and end time of permission expiration corresponding to each permission change record are read to determine the effective time interval of a single authorization edge; then, the reporting relationship between organizational nodes within the enterprise is extracted and the reporting relationship is defined as the initial connection line; subsequently, the effective time interval is written into the attribute field of the initial connection line, so that the initial connection line is converted into an authorization edge with an effective time interval; finally, all authorization edges are summarized, and the pointing relationship between different organizational nodes is established based on the organizational node identifier, thereby generating an organizational structure temporal diagram that represents the authorization relationship of organizational nodes and its effective time range.

[0018] Furthermore, the method provided in the application embodiments also includes: The authorized edge indicates that at the time corresponding to the operation timestamp, the source organization node has the right to transfer business data to the target organization node.

[0019] In this embodiment, the authorization edge in the organizational structure temporal diagram is defined according to the business flow permission relationship. The authorization edge represents the business data flow permission relationship between the source organizational node and the target organizational node at the time corresponding to the operation timestamp. The source organizational node represents the organizational node that initiates the business data flow operation, and the target organizational node represents the organizational node that receives the business data flow. The operation timestamp is used to determine the specific time when the business data flow occurs, and the authorization edge is used to indicate whether the source organizational node has the permission to perform business data flow to the target organizational node at that time. By mapping the authorization relationship to the operation timestamp, the authorization edge can reflect the dynamic permission relationship between organizational nodes at different time stages.

[0020] Furthermore, the method provided in the application embodiments, in constructing the organizational structure temporal diagram, further includes: Collect permission change records from the human resources system, read the start time and end time of permission validity in each record, and generate the effective time interval for a single authorization edge; extract the reporting relationship between any two organizational nodes within the enterprise, and define the reporting relationship as an initial connection line; write the effective time interval into the attribute field of the initial connection line to generate an authorization edge with the effective time interval; summarize all authorization edges, establish the pointing relationship between nodes according to the organizational node identifier, and generate an organizational structure temporal diagram.

[0021] In this embodiment, permission change records in the human resources system are first collected, and the start time and end time of permission validity are read from each permission change record. For the same permission change record, the start time of permission validity is determined as the start point of the interval, and the end time of permission validity is determined as the end point of the interval. An effective time interval corresponding to a single authorization edge is generated from the start point and the end point of the interval, and a correspondence between permission change records and effective time intervals is established.

[0022] Next, the reporting relationships between any two organizational nodes within the enterprise are extracted, and the corresponding two organizational nodes and their pointing relationships are determined based on the reporting relationships. These reporting relationships are defined as initial connection lines. The starting point of the initial connection line corresponds to the source organizational node, and the ending point corresponds to the target organizational node. Based on the organizational node identifier corresponding to the permission change record, the effective time interval is matched with the corresponding initial connection line, and the start time of permission effectiveness and the end time of permission expiration are written into the attribute fields of the initial connection line, giving the initial connection line a corresponding effective time interval, thus generating an authorization edge with an effective time interval.

[0023] Subsequently, all authorized edges with effective time intervals are aggregated. The source organization node identifier and target organization node identifier corresponding to each authorized edge are read, and each organization node is determined according to the organization node identifier. Based on the start point, end point, and direction of each authorized edge, a node pointing relationship is established between the corresponding source organization node and target organization node. At the same time, the start time of permission effectiveness and the end time of permission expiration in the attribute fields of each authorized edge are retained. The organizational structure temporal diagram is generated by the organization nodes, authorized edges, node pointing relationships, and the effective time intervals corresponding to each authorized edge.

[0024] Step S300: Abstract the business flow log into a flow edge, where the starting point of the flow edge is the organization node to which the operation subject belongs, and the ending point is the business node where the business document is currently located.

[0025] In this embodiment, the operation subject identifier in the business flow log is first read, and the source organization node to which the operation subject identifier belongs is queried according to the preset organizational structure mapping table. Then, the business document identifier in the same business flow log is read, and the target business node corresponding to the current business link of the business document identifier is queried. Subsequently, with the source organization node as the starting point and the target business node as the ending point, a directed line segment from the source organization node to the target business node is established, and the directed line segment is defined as a flow edge, thereby converting the business flow log into a flow edge that represents the flow relationship between the organization node to which the operation subject belongs and the business node to which the business document is currently located.

[0026] Furthermore, in the method provided in the application embodiment, the business flow log is abstracted into a flow edge, which further includes: Read the operation subject identifier in the business flow log, and query the source organization node to which the operation subject identifier belongs based on the preset organizational structure mapping table; read the business document identifier in the business flow log, and query the target business node corresponding to the current business link of the business document identifier; establish a directed line segment from the source organization node to the target business node, and define it as a flow edge.

[0027] In this embodiment, the operation subject identifier in the business flow log is first read, and then used as a query field to input a preset organizational structure mapping table. The organizational structure mapping table records the correspondence between operation subject identifiers and organizational node identifiers. By matching the operation subject identifier in the organizational structure mapping table, the organizational node identifier corresponding to the operation subject identifier is read, and the organizational node corresponding to the organizational node identifier is determined as the source organizational node. Here, the operation subject identifier is the identifier information representing the entity executing the business operation in the business flow log, and the source organizational node is the organizational node to which the operation subject corresponding to the operation subject identifier belongs in the organizational structure.

[0028] Next, the business document identifiers in the same business flow log are read, and the current business status record of the corresponding business document is queried based on the business document identifier. The current business stage of the business document is determined from the current business status record. Then, based on the correspondence between business stages and business nodes, the business node corresponding to the current business stage is queried, and the queried business node is determined as the target business node. Here, the business document identifier is the identification information that distinguishes different business documents, the business stage is the current processing stage of the business document in the business process, and the target business node is the business node corresponding to the current business stage of the business document.

[0029] After determining the source organization node and target business node corresponding to the same business flow log, a directed line segment is established with the source organization node as the starting point and the target business node as the ending point, pointing from the source organization node to the target business node. This directed line segment is defined as a flow edge, with the starting point of the flow edge corresponding to the source organization node to which the operating entity belongs, and the ending point corresponding to the target business node corresponding to the current business stage of the business document. Each business flow log is processed sequentially according to the above method to obtain the flow edge corresponding to each business flow log.

[0030] Step S400: For each flow edge, perform a spatiotemporal reachability query in the organizational structure temporal graph to determine whether there is a valid authorized path from the start point to the end point of the flow edge under the operation timestamp corresponding to the flow edge. If not, mark the flow edge as a shadow flow edge.

[0031] In this embodiment, the operation timestamp associated with each flow edge is read, and the operation timestamp is used as a time filtering condition to filter authorized edges whose effective time interval includes the operation timestamp in the organizational structure temporal diagram. The filtered authorized edges constitute a set of valid authorized edges. Based on the set of valid authorized edges, the path traversal starts from the starting point of the flow edge and performs path traversal on the pointing relationship of each authorized edge to detect whether there is a connected path starting from the starting point of the flow edge and reaching the ending point of the flow edge. If a connected path is detected, it is determined that there is a valid authorized path under the operation timestamp. If no connected path is detected, it is determined that there is no valid authorized path under the operation timestamp, and a shadow flow edge mark is written into the data record corresponding to the flow edge, thus identifying the flow edge as a shadow flow edge. Here, the shadow flow edge indicates that under the corresponding operation timestamp, there is no connected path composed of valid authorized edges between the source organization node to which the operation subject belongs and the target business node where the business document is currently located.

[0032] The spatiotemporal reachability of each flow edge is queried sequentially in the above manner to obtain the results of the determination of the effective authorized path corresponding to each flow edge, and to filter out the shadow flow edges that do not have effective authorized paths in the temporal graph of the organizational structure.

[0033] Furthermore, in the method provided in the application embodiment, for each flow edge, a spatiotemporal reachability query is performed in the organizational structure temporal graph to determine whether a valid authorized path exists from the start point to the end point of the flow edge under the operation timestamp corresponding to the flow edge, and the method further includes: Read the operation timestamp associated with the flow edge; in the organizational structure temporal graph, filter out the authorized edges whose effective time interval contains the operation timestamp, and form a set of valid authorized edges by the filtered authorized edges; perform path traversal based on the set of valid authorized edges, and detect whether there is a connected path that starts from the starting point of the flow edge and reaches the ending point of the flow edge; if the connected path exists, it is determined that there is a valid authorized path; otherwise, it is determined that there is no valid authorized path.

[0034] In this embodiment, firstly, based on the correspondence between the flow edge and the business flow log, the business flow log for generating the flow edge is determined, and the operation timestamp associated with the flow edge is read from the business flow log. The operation timestamp is the actual time when the operating entity performs the corresponding business operation and is associated with the flow edge. Using the operation timestamp as a time filtering condition, the start time of permission activation and the end time of permission deactivation recorded in the attribute fields of each authorized edge in the organizational structure temporal diagram are read, and the effective time interval corresponding to each authorized edge is determined by the start time of permission activation and the end time of permission deactivation.

[0035] Next, the operation timestamp is compared sequentially with the effective time interval corresponding to each authorized edge. If the operation timestamp is not earlier than the start time of permission effectiveness and not later than the end time of permission expiration, the effective time interval of the corresponding authorized edge is determined to include the operation timestamp, and the authorized edge is retained. If the operation timestamp is not within the effective time interval of the corresponding authorized edge, the authorized edge is excluded. After filtering all authorized edges in the organizational structure temporal diagram, the retained authorized edges are summarized, and the filtered authorized edges constitute the set of valid authorized edges. Each authorized edge in the set of valid authorized edges is an authorized edge that is in an effective state at the time corresponding to the operation timestamp.

[0036] Then, the starting point of the flow edge is determined as the current traversal node, and a candidate authorized edge starting from the current traversal node is searched in the set of valid authorized edges. The node moves to the next organization node along the pointing relationship of the candidate authorized edge, and the next organization node is updated to the current traversal node. The process of searching for candidate authorized edges, moving nodes, and updating the current traversal node is repeated until the current traversal node is consistent with the endpoint of the flow edge, or until all reachable nodes in the set of valid authorized edges have been traversed. When the current traversal node is consistent with the endpoint of the flow edge during the traversal process, it is determined that there is a connected path between the starting point and the endpoint of the flow edge.

[0037] After traversing the path based on the set of valid authorized edges, if there exists a connected path that starts from the starting point of the flowing edge and reaches the ending point of the flowing edge, it indicates that the starting point and the ending point can be connected through an authorized edge that is in an active state under the operation timestamp associated with the flowing edge, thus determining that there is a valid authorized path; if after traversing all reachable nodes in the set of valid authorized edges, there is still no connected path that starts from the starting point of the flowing edge and reaches the ending point of the flowing edge, it indicates that there is no valid authorized edge combination connecting the starting point and the ending point under the operation timestamp, thus determining that there is no valid authorized path.

[0038] Furthermore, in the method provided in the application embodiment, the method of performing path traversal based on the set of valid authorized edges and detecting whether there is a connected path starting from the starting point of the flowing edge and reaching the ending point of the flowing edge also includes: The starting point of the flow edge is determined as the current traversal node; in the set of valid authorized edges, a candidate authorized edge starting from the current traversal node is searched; the node moves along the candidate authorized edge to the next organization node and updates the next organization node to the current traversal node; this process is repeated until the current traversal node is consistent with the endpoint of the flow edge, or all reachable nodes in the set of valid authorized edges have been traversed; if the current traversal node is consistent with the endpoint of the flow edge during the traversal, then the existence of the connected path is determined.

[0039] In this embodiment, the starting point of the flow edge is determined as the current traversed node, and a set of nodes to be traversed and a set of nodes already traversed are established. The starting point of the flow edge is written into the set of nodes to be traversed, and the set of nodes already traversed is initially empty. During each path traversal, an organization node is read from the set of nodes to be traversed as the current traversed node, and the organization node identifier of the current traversed node is compared with the node identifier corresponding to the endpoint of the flow edge. When the two are consistent, the path traversal stops, and it is determined that there is a connected path from the starting point of the flow edge to the endpoint of the flow edge. When the two are inconsistent, the current traversed node is written into the set of nodes already traversed, and the organization node identifier corresponding to the starting point of each authorized edge is read from the set of valid authorized edges. Authorized edges whose organization node identifier corresponding to the starting point is consistent with the organization node identifier of the current traversed node are determined as candidate authorized edges.

[0040] For each candidate authorization edge found, the next organization node corresponding to the endpoint of the candidate authorization edge is read along the pointing relationship of the candidate authorization edge. If the next organization node has not yet been written to the traversed node set, the next organization node is written to the untraversed node set, and the correspondence between the current traversed node, the candidate authorization edge, and the next organization node is recorded; if the next organization node has already been written to the traversed node set, path traversal is not repeated for the next organization node. After processing all candidate authorization edges corresponding to the current traversed node, the next organization node is read from the untraversed node set and updated to the current traversed node, and the search for candidate authorization edges starting from the updated current traversed node continues.

[0041] The above process is repeated, involving reading the current traversed node, searching for candidate authorized edges, determining the next organizational node, and updating the current traversed node, until the current traversed node matches the endpoint of the flowing edge, or the set of nodes to be traversed is empty. When the current traversed node matches the endpoint of the flowing edge, based on the correspondence between the current traversed node, candidate authorized edges, and the next organizational node recorded during the traversal process, a sequence of nodes and authorized edges is determined, which sequentially pass through each candidate authorized edge from the starting point of the flowing edge to the endpoint of the flowing edge. The node sequence and the authorized edge sequence constitute a connected path. When the set of nodes to be traversed is empty and the current traversed node still does not match the endpoint of the flowing edge, it indicates that all reachable nodes in the set of valid authorized edges have been traversed, and there is no connected path from the starting point of the flowing edge to the endpoint of the flowing edge.

[0042] Furthermore, in the method provided in the application embodiments, before outputting the permission out-of-bounds alarm information, it further includes: Extract the operation subject identifier associated with the shadow flow edge, query the preset job permission configuration table based on the operation subject identifier to obtain the corresponding job sensitivity level; match the preset risk coefficient table according to the job sensitivity level to obtain the risk weight value corresponding to the shadow flow edge; establish the correspondence between the shadow flow edge and the risk weight value to generate a weighted shadow flow edge.

[0043] In this embodiment, the operation subject identifier associated with the shadow flow edge is first extracted. Based on the association between the shadow flow edge and the corresponding business flow log, the business flow log that generated the shadow flow edge is read, and the operation subject identifier is obtained from the business flow log. The operation subject identifier is identification information that distinguishes different business operation subjects and corresponds to the job information that performs the corresponding business operation. The operation subject identifier is used as a query condition input into a pre-set job permission configuration table. Matching is performed according to the correspondence between the operation subject identifier and the job sensitivity level in the job permission configuration table, and the job sensitivity level corresponding to the operation subject identifier is read. The job permission configuration table records at least the operation subject identifier and its corresponding job sensitivity level. The job sensitivity level is used to characterize the sensitivity of the corresponding job in business data flow permissions. The job permission configuration table is shown in Table 1.

[0044] Table 1. Job Permission Configuration Table ; Next, the job sensitivity levels obtained from the query are input into a preset risk coefficient table as matching conditions. Each job sensitivity level recorded in the risk coefficient table is compared, and the risk coefficient matching the job sensitivity level is read. This risk coefficient is then determined as the risk weight value corresponding to the shadow flow edge. The risk coefficient table records the correspondence between different job sensitivity levels and different risk weight values. When a job sensitivity level matches a job sensitivity level in the risk coefficient table, the risk weight value corresponding to that job sensitivity level is extracted, and a relationship is established between the operating entity identifier, the job sensitivity level, and the risk weight value.

[0045] After obtaining the risk weight value corresponding to the shadow circulation edge, the identification information of the shadow circulation edge is associated with the risk weight value, and the risk weight value is written into the attribute field corresponding to the shadow circulation edge to establish the correspondence between the shadow circulation edge and the risk weight value. Each shadow circulation edge is processed in the above manner to associate each shadow circulation edge with the corresponding operation subject identifier, job sensitivity level, and risk weight value, thereby generating a weighted shadow circulation edge.

[0046] Step S500: Count the number of shadow transition edges within the preset monitoring window. When the number of shadow transition edges exceeds a preset threshold, output permission over-limit alarm information.

[0047] In this embodiment, based on the start and end times corresponding to the preset monitoring window, the operation timestamp associated with each shadow flow edge is read, and the shadow flow edges whose operation timestamps are located between the start and end times are determined as shadow flow edges within the preset monitoring window. The preset monitoring window is the time range for performing shadow flow edge statistics. The shadow flow edges within the preset monitoring window are counted one by one to obtain the number of shadow flow edges, and the number of shadow flow edges is compared with a preset threshold. When the number of shadow flow edges is greater than the preset threshold, a permission out-of-bounds alarm message is generated and output to indicate that the number of shadow flow edges appearing in the preset monitoring window has reached the permission out-of-bounds alarm condition. When the number of shadow flow edges does not exceed the preset threshold, no permission out-of-bounds alarm message is output.

[0048] In one implementation, the shadow flow edge can be further generated as a weighted shadow flow edge, and when outputting the permission out-of-bounds alarm information, the risk weight value corresponding to the weighted shadow flow edge is written into the permission out-of-bounds alarm information, so that the permission out-of-bounds alarm information includes the operation subject identifier and risk weight value of the corresponding shadow flow edge.

[0049] Furthermore, the method provided in the application embodiments also includes: In response to the monitoring object being a new acquisition entity, the system obtains the established standard business flow path of the parent company, which includes a preset standard node sequence; reads the business field names generated by the new acquisition entity and splits them into independent lexical units; calculates the text overlap between the lexical units and each node in the standard node sequence, and selects the standard node with the highest text overlap as the mapping target node; establishes the correspondence between each business field name and the mapping target node, generating a field mapping table; based on the field mapping table, converts the organizational relationships within the new acquisition entity into authorization edges, generating a temporal diagram of the organizational structure adapted to the new acquisition entity.

[0050] In this embodiment, in response to the monitoring object being a newly acquired entity, the established standard business flow path is read from the parent company's business process configuration data. Following the flow order of each business link within the standard business flow path, the standard node identifier and standard node name corresponding to each business link are read sequentially. The read standard nodes are then arranged in the flow order to form a preset standard node sequence. The standard business flow path is a business path within the parent company where node definitions and flow order configurations have been completed. The standard node sequence is composed of multiple standard nodes from the standard business flow path, with each standard node corresponding to a business link within the parent company.

[0051] Next, the system reads the business field names recorded in the business data tables, business process configuration data, or business flow logs from the business system of the newly acquired entity. Taking each business field name as the processing object, it performs text normalization processing, standardizing the character format, letter case, and delimiters. Based on spaces, underscores, hyphens, numeric boundaries, or word boundaries from a pre-defined business dictionary, the business field names are split into one or more independent lexical units, and a relationship is established between the business field name and its corresponding lexical unit. For example, when a business field name is formed by combining multiple business-meaning words, each business-meaning word is saved as an independent lexical unit.

[0052] For each business field name, the corresponding vocabulary units are sequentially compared with the node names of each standard node in the standard node sequence. Standard node vocabulary units are generated using the same splitting method as the business field names. The number of identical vocabulary units between the vocabulary units corresponding to the business field names and the standard node vocabulary units is counted, and the text overlap is calculated based on the number of identical vocabulary units and the number of vocabulary units participating in the comparison. The text overlap between the same business field name and each standard node in the standard node sequence is calculated in the same manner. The text overlap is compared, and the standard node with the highest text overlap is selected as the mapping target node corresponding to the business field name. When multiple standard nodes have the same text overlap, the standard node with the highest order in the standard node sequence is selected as the mapping target node.

[0053] Process all business field names generated by the newly acquired entity one by one, record each business field name, its corresponding mapping target node identifier, and the correspondence between them, and summarize all correspondences to generate a field mapping table. The field mapping table includes at least the business field name and the mapping target node identifier, so that the business field names used by the newly acquired entity can establish a correspondence with the standard nodes in the parent company's standard business flow path.

[0054] Based on the field mapping table, the organizational relationships within the newly acquired entity are retrieved. Each organizational relationship includes at least two organizational nodes with a business data flow relationship and the pointing relationship between them. For each organizational relationship, the business field name associated with that relationship is retrieved, and the corresponding mapping target node is queried in the field mapping table. The business node corresponding to the organizational relationship is determined based on the retrieved mapping target node. Simultaneously, according to the initiator and receiver of the flow recorded in the organizational relationship, the source and target organizational nodes corresponding to the authorization edge are determined, and an authorization edge pointing from the source organizational node to the target organizational node is established. Field mapping and authorization edge transformation are performed on each organizational relationship within the newly acquired entity. All transformed authorization edges are summarized, and pointing relationships between organizational nodes are established according to the organizational node identifier. The effective time interval of each authorization edge is written into the attribute field of the authorization edge. The organizational nodes, authorization edges, pointing relationships between nodes, and effective time intervals of the authorization edges are used to generate a temporal diagram of the organizational structure adapted to the newly acquired entity.

[0055] Furthermore, in the method provided in the application embodiments, after generating the temporal diagram of the organizational structure adapted to the new acquired entity, it further includes: Extract the actual flow edges generated by the newly acquired entity, count the frequency of the actual flow edges passing through each node in the organizational structure temporal graph, and generate a measured node frequency distribution; read the preset benchmark frequency of each node in the standard business flow path and generate a benchmark node frequency distribution; compare the difference between the measured node frequency distribution and the benchmark node frequency distribution under the same node one by one, and when the cumulative sum of the difference values ​​exceeds the preset deviation limit, it is determined to be a docking anomaly.

[0056] In this embodiment, when extracting the actual flow edges generated by the newly acquired entity, the business flow logs of the newly acquired entity are read. The corresponding source organization node is determined based on the operation entity identifier in each business flow log, and the target business node corresponding to the current business stage of the business document is determined based on the business document identifier and field mapping table. An actual flow edge is then established by pointing from the source organization node to the target business node. Subsequently, using the node identifiers in the organizational structure temporal diagram as the statistical basis, the nodes traversed by each actual flow edge are read one by one. When an actual flow edge traverses a corresponding node, the measured frequency corresponding to that node is increased by one. When multiple actual flow edges traverse the same node, the measured frequency of that node is continuously accumulated. After completing the statistics of all actual flow edges, the node identifiers and their corresponding measured frequencies are recorded according to the node order in the organizational structure temporal diagram, generating a measured node frequency distribution.

[0057] The system reads all nodes included in the standard business flow path and queries the pre-configured preset baseline frequency for each node according to its node identifier. The preset baseline frequency is the number of times the corresponding node is traversed in the standard business flow path. Following the same node order as the measured node frequency distribution, the system arranges each node identifier and its corresponding preset baseline frequency to generate a baseline node frequency distribution. For nodes not actually traversed by the flow edge, the measured frequency corresponding to that node is recorded as zero, ensuring that the measured node frequency distribution and the baseline node frequency distribution can correspond based on the same node identifier.

[0058] Based on node identifiers, the system matches identical nodes in the measured node frequency distribution with those in the baseline node frequency distribution, reads the measured frequency and the preset baseline frequency corresponding to the same node, and calculates the difference between the two. In one executable method, the absolute value of the difference between the measured frequency and the preset baseline frequency is determined as the difference value of the corresponding node, and the difference values ​​of each node are accumulated in node order to obtain the cumulative sum of the difference values. The cumulative sum of the difference values ​​is compared with a preset deviation limit. When the cumulative sum of the difference values ​​is greater than the preset deviation limit, the docking status of the new merger entity is judged as docking abnormal; when the cumulative sum of the difference values ​​does not exceed the preset deviation limit, no docking abnormality judgment is made.

[0059] In summary, the embodiments of this application have at least the following technical effects: This application obtains business flow logs within a preset time period. The business flow logs include business document identifiers, operation subject identifiers, and operation timestamps. It constructs an organizational structure temporal graph, which consists of multiple authorization edges with effective time intervals. The business flow logs are abstracted as flow edges, with the starting point of each flow edge being the organizational node to which the operation subject belongs, and the ending point being the business node where the business document is currently located. For each flow edge, a spatiotemporal reachability query is performed in the organizational structure temporal graph to determine whether a valid authorization path exists from the starting point to the ending point of the flow edge under the corresponding operation timestamp. If no valid path exists, the flow edge is marked as a shadow flow edge. The number of shadow flow edges within a preset monitoring window is counted. When the number of shadow flow edges exceeds a preset threshold, an out-of-bounds permission alarm is output. This invention solves the technical problem in the prior art of failing to effectively identify unauthorized data flow with valid permissions but illegal business flow paths. By dynamically verifying the authorization of business flow paths based on the organizational structure temporal graph, it achieves the technical effect of accurately identifying illegal flow paths and realizing compliant monitoring of business data flow.

[0060] Example 2 is based on the same inventive concept as the intelligent monitoring method for enterprise end-to-end business flow data in the aforementioned examples, such as... Figure 2As shown, this application provides an intelligent monitoring system for enterprise end-to-end business flow data. The system and method embodiments in this application are based on the same inventive concept. The system includes: The data acquisition module 11 is used to acquire business flow logs within a preset time period. The business flow logs include business document identifiers, operation subject identifiers, and operation timestamps. The graph construction module 12 is used to construct an organizational structure temporal graph, which consists of multiple authorization edges with effective time intervals. The abstraction module 13 is used to abstract the business flow logs into flow edges. The starting point of each flow edge is the organizational node to which the operation subject belongs, and the ending point is the business node where the business document is currently located. The judgment module 14 is used to perform a spatiotemporal reachability query in the organizational structure temporal graph for each flow edge, and to determine whether there is a valid authorization path from the starting point to the ending point of the flow edge under the operation timestamp corresponding to the flow edge. If not, the flow edge is marked as a shadow flow edge. The alarm information output module 15 is used to count the number of shadow flow edges within a preset monitoring window. When the number of shadow flow edges exceeds a preset threshold, an over-limit permission alarm message is output.

[0061] Furthermore, the system is also used to implement the following functions: The authorized edge indicates that at the time corresponding to the operation timestamp, the source organization node has the right to transfer business data to the target organization node.

[0062] Furthermore, the system is also used to implement the following functions: Collect permission change records from the human resources system, read the start time and end time of permission validity in each record, and generate the effective time interval for a single authorization edge; extract the reporting relationship between any two organizational nodes within the enterprise, and define the reporting relationship as an initial connection line; write the effective time interval into the attribute field of the initial connection line to generate an authorization edge with the effective time interval; summarize all authorization edges, establish the pointing relationship between nodes according to the organizational node identifier, and generate an organizational structure temporal diagram.

[0063] Furthermore, the system is also used to implement the following functions: Read the operation subject identifier in the business flow log, and query the source organization node to which the operation subject identifier belongs based on the preset organizational structure mapping table; read the business document identifier in the business flow log, and query the target business node corresponding to the current business link of the business document identifier; establish a directed line segment from the source organization node to the target business node, and define it as a flow edge.

[0064] Furthermore, the system is also used to implement the following functions: Read the operation timestamp associated with the flow edge; in the organizational structure temporal graph, filter out the authorized edges whose effective time interval contains the operation timestamp, and form a set of valid authorized edges by the filtered authorized edges; perform path traversal based on the set of valid authorized edges, and detect whether there is a connected path that starts from the starting point of the flow edge and reaches the ending point of the flow edge; if the connected path exists, it is determined that there is a valid authorized path; otherwise, it is determined that there is no valid authorized path.

[0065] Furthermore, the system is also used to implement the following functions: The starting point of the flow edge is determined as the current traversal node; in the set of valid authorized edges, a candidate authorized edge starting from the current traversal node is searched; the node moves along the candidate authorized edge to the next organization node and updates the next organization node to the current traversal node; this process is repeated until the current traversal node is consistent with the endpoint of the flow edge, or all reachable nodes in the set of valid authorized edges have been traversed; if the current traversal node is consistent with the endpoint of the flow edge during the traversal, then the existence of the connected path is determined.

[0066] Furthermore, the system is also used to implement the following functions: Extract the operation subject identifier associated with the shadow flow edge, query the preset job permission configuration table based on the operation subject identifier to obtain the corresponding job sensitivity level; match the preset risk coefficient table according to the job sensitivity level to obtain the risk weight value corresponding to the shadow flow edge; establish the correspondence between the shadow flow edge and the risk weight value to generate a weighted shadow flow edge.

[0067] Furthermore, the system is also used to implement the following functions: In response to the monitoring object being a new acquisition entity, the system obtains the established standard business flow path of the parent company, which includes a preset standard node sequence; reads the business field names generated by the new acquisition entity and splits them into independent lexical units; calculates the text overlap between the lexical units and each node in the standard node sequence, and selects the standard node with the highest text overlap as the mapping target node; establishes the correspondence between each business field name and the mapping target node, generating a field mapping table; based on the field mapping table, converts the organizational relationships within the new acquisition entity into authorization edges, generating a temporal diagram of the organizational structure adapted to the new acquisition entity.

[0068] Furthermore, the system is also used to implement the following functions: Extract the actual flow edges generated by the newly acquired entity, count the frequency of the actual flow edges passing through each node in the organizational structure temporal graph, and generate a measured node frequency distribution; read the preset benchmark frequency of each node in the standard business flow path and generate a benchmark node frequency distribution; compare the difference between the measured node frequency distribution and the benchmark node frequency distribution under the same node one by one, and when the cumulative sum of the difference values ​​exceeds the preset deviation limit, it is determined to be a docking anomaly.

[0069] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0070] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A method for intelligent monitoring of enterprise end-to-end business flow data, characterized in that, The method includes: Obtain business flow logs within a preset time period, wherein the business flow logs include business document identifiers, operation entity identifiers, and operation timestamps; Construct an organizational structure temporal diagram, which consists of multiple authorization edges with effective time intervals; The business flow log is abstracted as a flow edge, where the starting point of the flow edge is the organization node to which the operation subject belongs, and the ending point is the business node where the business document is currently located. For each flow edge, a spatiotemporal reachability query is performed in the organizational structure temporal graph to determine whether there is a valid authorized path from the start point to the end point of the flow edge under the operation timestamp corresponding to the flow edge. If not, the flow edge is marked as a shadow flow edge. The number of shadow transition edges within the preset monitoring window is counted. When the number of shadow transition edges exceeds a preset threshold, an access violation alarm message is output.

2. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 1, characterized in that, The authorized edge indicates that at the time corresponding to the operation timestamp, the source organization node has the right to transfer business data to the target organization node.

3. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 1, characterized in that, Constructing an organizational structure temporal diagram includes: Collect permission change records from the human resources system, read the start time of permission effectiveness and the end time of permission expiration from each permission change record, and generate the effective time interval corresponding to a single authorization edge; Extract the reporting relationship between any two organizational nodes within the enterprise, and define the reporting relationship as the initial connection line; Write the effective time interval into the attribute field of the initial connection line to generate an authorized edge with the effective time interval; Summarize all authorized edges and establish the pointing relationships between nodes according to the organization node identifier to generate an organizational structure temporal diagram.

4. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 1, characterized in that, The business flow log is abstracted into flow edges, including: Read the operation subject identifier in the business flow log, and query the source organization node to which the operation subject identifier belongs based on the preset organizational structure mapping table; Read the business document identifier from the business flow log and query the target business node corresponding to the current business process of the business document identifier; Establish a directed line segment pointing from the source organization node to the target business node, and define it as a flow edge.

5. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 1, characterized in that, For each flow edge, a spatiotemporal reachability query is performed in the organizational structure temporal graph to determine whether a valid authorized path exists from the start point to the end point of the flow edge under the operation timestamp corresponding to the flow edge, including: Read the operation timestamp associated with the flow edge; In the organizational structure temporal diagram, authorized edges whose effective time intervals contain the operation timestamp are selected, and the selected authorized edges constitute a set of valid authorized edges; Based on the set of valid authorized edges, perform path traversal to detect whether there is a connected path that starts from the starting point of the flowing edge and reaches the ending point of the flowing edge. If the connected path exists, it is determined that a valid authorized path exists; otherwise, it is determined that a valid authorized path does not exist.

6. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 5, characterized in that, Based on the set of valid authorized edges, a path traversal is performed to detect whether there exists a connected path that starts from the starting point of the flowing edge and reaches the ending point of the flowing edge, including: The starting point of the flowing edge is determined as the current traversed node; In the set of valid authorized edges, search for candidate authorized edges that start from the currently traversed node; Move along the candidate authorization edge to the next organization node, and update the next organization node to the currently traversed node; This process of searching and moving continues until the current traversed node matches the endpoint of the flowing edge, or until all reachable nodes in the set of valid authorized edges have been traversed. If the current traversed node matches the endpoint of the flowing edge during the traversal process, then the existence of the connected path is determined.

7. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 1, characterized in that, Before outputting the permission out-of-bounds alert message, it also includes: Extract the operation subject identifier associated with the shadow flow edge, and query the preset job permission configuration table based on the operation subject identifier to obtain the corresponding job sensitivity level; Based on the job sensitivity level, a preset risk coefficient table is matched to obtain the risk weight value corresponding to the shadow flow edge; Establish the correspondence between the shadow flow edge and the risk weight value, and generate a weighted shadow flow edge.

8. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 1, characterized in that, The method further includes: In response to the monitoring object being a newly acquired entity, the standard business flow path of the established parent company is obtained, and the standard business flow path includes a preset standard node sequence; Read the business field names generated by the new acquisition entity and break them down into independent lexical units; Calculate the text overlap between the vocabulary unit and each node in the standard node sequence, and select the standard node with the highest text overlap as the mapping target node; Establish the correspondence between each of the business field names and the mapping target nodes, and generate a field mapping table; Based on the field mapping table, the organizational relationships within the new acquired entity are converted into authorization edges, generating a temporal diagram of the organizational structure adapted to the new acquired entity.

9. The intelligent monitoring method for enterprise end-to-end business flow data as described in claim 8, characterized in that, After generating the temporal diagram of the organizational structure adapted to the newly acquired entity, the process also includes: Extract the actual flow edges generated by the newly acquired entity, count the frequency of the actual flow edges passing through each node in the temporal graph of the organizational structure, and generate the measured node frequency distribution. Read the preset baseline frequency of each node in the standard business flow path and generate the baseline node frequency distribution; The difference between the measured node frequency distribution and the reference node frequency distribution at the same node is compared one by one. When the cumulative sum of the difference values ​​exceeds the preset deviation limit, it is determined to be a docking anomaly.

10. A smart monitoring system for enterprise end-to-end business flow data, characterized in that, The system is used to execute the intelligent monitoring method for enterprise end-to-end business flow data as described in any one of claims 1-9, and the system includes: The data acquisition module is used to acquire business flow logs within a preset time period. The business flow logs include business document identifiers, operation subject identifiers, and operation timestamps. The graph construction module is used to construct an organizational structure temporal graph, which consists of multiple authorization edges with effective time intervals; The abstract module is used to abstract the business flow log into flow edges, where the starting point of the flow edge is the organization node to which the operation subject belongs, and the ending point is the business node where the business document is currently located. The judgment module is used to perform a spatiotemporal reachability query in the organizational structure temporal graph for each flow edge, and to determine whether there is a valid authorized path from the start point to the end point of the flow edge under the operation timestamp corresponding to the flow edge. If not, the flow edge is marked as a shadow flow edge. The alarm information output module is used to count the number of shadow flow edges within a preset monitoring window. When the number of shadow flow edges exceeds a preset threshold, an over-permission alarm message is output.