Call forwarding fraud behavior identification method and device
By collecting and analyzing signaling traffic in the telecommunications network, building an intelligent identification model, and monitoring abnormalities in call forwarding settings behavior in real time, it solves the problem of difficult to identify and prevent call forwarding fraud in the existing technology, and achieves the efficient and security improvement of the communication network.
Patent Information
- Application Number
- CN202510101441.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-09
AI Technical Summary
The prior art is difficult to effectively identify and prevent call-forwarding fraud in telecommunications networks, which makes it difficult to detect and warn fraud in a timely manner, and expands the scope of fraud.
Through precision acquisition and in-depth analysis of signaling traffic in the communication network, key features are extracted, intelligent identification models are built, abnormalities in call and forward setting behavior are monitored in real time, and potential fraud risks are promptly discovered and warned about.
It has achieved accurate precautions for fraud-related acts in call forwarding, greatly improved the security of the communication network, and provided solid guarantees for information and property security.
Smart Images

Figure CN119967088A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a method and device for identifying call forwarding fraudulent behavior. Background Art
[0002] Telecom network fraud poses a serious threat to social security and the safety of people's property. Fraudsters use call forwarding telecommunications services to carry out fraudulent activities and attempt to evade tracking through single or continuous call forwarding. Observation from the signaling call record often only shows the illusion of calling a single number. Through complex call forwarding settings, fraudsters can actually transfer fraudulent calls to multiple victims' mobile phones, thus evading conventional anti-fraud platform monitoring, greatly expanding the scope of fraud and increasing the harmfulness of fraud.
[0003] The underlying principle of fraudulent number identification under the existing call forwarding technology is based on call forwarding traffic signaling. The generation of call forwarding traffic signaling indicates that the fraudster has already forwarded fraudulent calls. The identification at this time belongs to the identification during and after the event, and there is a lag. Summary of the invention
[0004] The present application provides a method and device for identifying call forwarding fraudulent behavior, which can accurately collect signaling traffic in the communication network and deeply analyze the specific data of call forwarding settings; on this basis, combined with algorithms, key features are extracted from massive data to build an intelligent recognition model. The present invention can monitor abnormal situations of call forwarding setting behaviors in real time, promptly discover and warn of potential fraud risks, thereby achieving accurate prevention of call forwarding fraudulent behavior in advance. The application of the present invention will greatly improve the security of communication networks and provide solid protection for people's information and property security.
[0005] In a first aspect, an embodiment of the present application provides a method for identifying call forwarding fraudulent behavior, the method comprising:
[0006] The signaling collection server collects and parses the signaling set of the training number sample to obtain multiple key field tables; each key field table is sent to the call forwarding identification device; the signaling set includes UT interface original signaling, 4G S1MME signaling, 5GN1 N2 signaling and number call signaling;
[0007] The call transfer identification device extracts preset fraud-related features according to each key field table to obtain a feature data set; the LightGBM model is trained according to the feature data set to obtain a fraud-related identification model;
[0008] The signaling collection server collects and analyzes the signaling set of the current call forwarding number to obtain multiple current field tables; and sends each current field table to the call forwarding identification device;
[0009] The call transfer identification device extracts preset fraud-related features according to each current field table to obtain a current feature set; the current feature set is input into a fraud-related identification model to obtain an identification result.
[0010] Furthermore, the step of parsing the original signaling of the UT interface by the signaling collection server includes:
[0011] Detect whether there is a preset first operation and a preset second operation in the original signaling of the UT interface;
[0012] If so, detecting the first information and the second information in the original signaling of the UT interface;
[0013] The first information and the second information are placed into the key field table corresponding to the original signaling of the UT interface.
[0014] Further, detecting whether there is a preset first operation and a preset second operation in the original signaling of the UT interface includes:
[0015] Check whether the first line of the original signaling of the UT interface starts with PUT XCAP;
[0016] If yes, then there is a preset first operation in the original signaling of the UT interface;
[0017] Check whether the call transfer parameter in the original signaling of the UT interface is followed by a preset unconditional parameter;
[0018] If so, there is a preset second operation in the original signaling of the UT interface.
[0019] Further, detecting the first information and the second information in the original signaling of the UT interface includes:
[0020] Detecting the source called number after the preset first field in the original signaling of the UT interface as the first information;
[0021] The forwarding target number after the preset second field in the original signaling of the UT interface is detected as the second information.
[0022] Furthermore, the call forwarding parameter is call-forwarding; and the preset unconditional parameter is Unconditional.
[0023] Furthermore, the first field is preset as X-3GPP-Intended-Identity; and the second field is preset as forward-to and target.
[0024] Furthermore, the preset fraud-related features include whether the time for setting the call forwarding number is early in the morning, the frequency of setting the call forwarding number, the number of call forwarding numbers set, whether the time for setting the call forwarding number in the past is early in the morning, the frequency of setting the call forwarding number in the past, and the number of call forwarding numbers set in the past.
[0025] In a second aspect, an embodiment of the present application provides a device for identifying call forwarding fraudulent behavior, the device comprising:
[0026] The signaling collection server is used to collect and parse the signaling set of the training number sample, obtain multiple key field tables and send them to the call forwarding identification device; collect and parse the signaling set of the current call forwarding number, obtain multiple current field tables and send them to the call forwarding identification device; the signaling set includes UT interface original signaling, 4G S1MME signaling, 5G N1 N2 signaling and number call signaling;
[0027] The call transfer recognition device is used to extract preset fraud-related features according to each key field table to obtain a feature data set; train the LightGBM model according to the feature data set to obtain a fraud-related recognition model; extract preset fraud-related features according to each current field table to obtain the current feature set and input it into the fraud-related recognition model to obtain the recognition result.
[0028] Furthermore, the signaling collection server is specifically used to detect whether there is a preset first operation and a preset second operation in the original signaling of the UT interface; if so, detect the first information and the second information in the original signaling of the UT interface; and put the first information and the second information into the key field table corresponding to the original signaling of the UT interface.
[0029] Furthermore, the signaling collection server is specifically used to detect whether the first line of the original signaling of the UT interface starts with PUTXCAP; if so, there is a preset first operation in the original signaling of the UT interface; detect whether the call transfer parameter in the original signaling of the UT interface is followed by a preset unconditional parameter; if so, there is a preset second operation in the original signaling of the UT interface.
[0030] In summary, compared with the prior art, the technical solution provided in the embodiment of the present application has at least the following beneficial effects:
[0031] The embodiment of the present application provides a method for identifying call forwarding fraudulent behavior, which enables the signaling collection server to accurately collect signaling traffic in the communication network, deeply analyze the specific data of the call forwarding settings to extract the key field table, and enable the call forwarding identification device to find the preset fraudulent features in the massive data according to the key field table, and train to obtain a fraudulent identification model, so that the fraudulent identification model can identify whether there is a fraudulent risk based on the signaling generated when the user sets the call forwarding. The present application can monitor the abnormal situation of call forwarding setting behavior in real time through the fraudulent identification model, timely discover and warn potential fraudulent risks, thereby realizing the precise prevention of call forwarding fraudulent behavior in advance, greatly improving the security of the communication network. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1A flowchart of a device for identifying call forwarding fraudulent behavior provided as an exemplary embodiment of the present application.
[0033] Figure 2 A schematic diagram of signaling collection provided for an exemplary embodiment of the present application.
[0034] Figure 3 A structural diagram of a device for identifying call forwarding fraudulent behavior provided as an exemplary embodiment of the present application. DETAILED DESCRIPTION
[0035] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments.
[0036] Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative work shall fall within the scope of protection of this application.
[0037] See also Figure 1 , the embodiment of the present application provides a method for identifying call forwarding fraudulent behavior, the method comprising:
[0038] Step S1, the signaling collection server collects and parses the signaling set of the training number sample to obtain multiple key field tables; each key field table is sent to the call forwarding identification device; the signaling set includes UT interface original signaling, 4G S1MME signaling, 5G N1 N2 signaling and number call signaling.
[0039] See also Figure 2 The original signaling set of the UT interface is connected to the aggregation switch by means of optical splitting through an optical splitter, and then the aggregation switch aggregates the original signaling set to the signaling collection server for the next step of analysis.
[0040] In the key field table, the key field table obtained by parsing the 4G S1MME signaling includes:
[0041]
[0042] The key field table obtained by parsing the 5G N1 N2 signaling includes:
[0043]
[0044] The key fields table obtained by parsing the number call signaling includes:
[0045]
[0046] Among them, IMEI is the International Mobile Equipment Identity code and CI is the cell identification.
[0047] Step S2, the call forwarding identification device extracts preset fraud-related features according to each key field table to obtain a feature data set; and trains a LightGBM model according to the feature data set to obtain a fraud-related identification model.
[0048] Among them, the preset fraud-related features include:
[0049]
[0050]
[0051] The corresponding feature datasets include:
[0052]
[0053] During the training phase, the training number samples mainly include samples of work orders involved in the case and samples of formal employees of provincial operators. Therefore, labels can be set for the characteristics of each sample based on the source of the sample.
[0054] Specifically, the specific parameter adjustment and selection process of the LightGBM model is as follows:
[0055] First, initial parameter settings:
[0056] First, a set of basic parameters were set for preliminary training, including the number of trees n_estimators = 1000, the maximum depth of the tree max_depth = 5, the learning rate learning_rate = 0.27, and the number of leaf nodes num_leaves = 61. The initial selection of these parameters was based on previous experience and the results of preliminary experiments.
[0057] Second, parameter optimization:
[0058] Adjust num_leaves and class_weights: Experiment with the number of num_leaves and different class_weights to explore the sensitivity of the model to imbalanced classes. For example, we tried num_leaves of 128 and different class weight ratios such as [1,150] to [1,300] to observe the changes in recognition accuracy and false positive rate.
[0059] Adjust learning_rate and max_depth: By fine-tuning these key parameters, try to find the optimal model complexity and learning speed. In some configurations, adjust learning_rate slightly, such as from 0.3 to 0.4 or 0.2, and test the impact on model performance.
[0060] Model evaluation: After each parameter adjustment, the same training set and validation set are used to evaluate the model's accuracy, precision, false positive rate, and recall. These indicators help us understand the performance and generalization ability of the model under different parameter configurations.
[0061] Third, the final parameters are determined:
[0062] After multiple rounds of parameter adjustment and model evaluation, it was found that when n_estimators = 800, max_depth = 5, learning_rate = 0.27, num_leaves = 128, and class_weights = [1,300] were set, the model achieved a relatively balanced optimal result in terms of accuracy and recall, that is, 95.66% accuracy and 96.23% recall. At the same time, the purpose of this application is to achieve pre-emptive prevention, so it is particularly important to hit the work order before the incident. At this time, the pre-incident hit rate also reached the highest 95.54%, with significant results. Some of the parameter adjustment results are shown in the following table:
[0063]
[0064]
[0065] Step S3, the signaling collection server collects and analyzes the signaling set of the current call forwarding number to obtain multiple current field tables; and sends each current field table to the call forwarding identification device.
[0066] Among them, the data format of the current field table and the above-mentioned key field table is the same.
[0067] Step S4, the call forwarding identification device extracts preset fraud-related features according to each current field table to obtain a current feature set; and inputs the current feature set into a fraud-related identification model to obtain an identification result.
[0068] The above embodiment provides a method for identifying call forwarding fraudulent behavior, which enables the signaling collection server to accurately collect signaling traffic in the communication network, deeply analyze the specific data of the call forwarding settings to extract the key field table, and enable the call forwarding identification device to find the preset fraudulent features in the massive data according to the key field table, and train to obtain a fraudulent identification model, so that the fraudulent identification model can identify whether there is a fraudulent risk based on the signaling generated when the user sets the call forwarding. This application can monitor the abnormal situation of call forwarding setting behavior in real time through the fraudulent identification model, and timely discover and warn potential fraudulent risks, thereby realizing the precise prevention of call forwarding fraudulent behavior in advance, greatly improving the security of the communication network.
[0069] In some embodiments, the step of parsing the original signaling of the UT interface by the signaling collection server includes:
[0070] Step S11: Detect whether there is a preset first operation and a preset second operation in the original signaling of the UT interface.
[0071] Specifically, it is detected whether the first line of the original signaling of the UT interface starts with PUT XCAP; wherein the preset first operation is the PUT operation of the call forwarding setting, and if it exists, it will be located in the first line of the signaling message "HTTP PUT message" in the signaling flow of the call forwarding setting. If so, the preset first operation exists in the original signaling of the UT interface.
[0072] The following is an example of a partial signaling message with a preset first operation:
[0073] Put XCAP ROOT URI / simservs.ngn.etsi.org / users / sip:+8613911111111.
[0074] Then, it is detected whether the call forwarding parameter in the original signaling of the UT interface is followed by a preset unconditional parameter; if so, there is a preset second operation in the original signaling of the UT interface, wherein the preset second operation is to set an unconditional forwarding operation.
[0075] The following is an example of a partial signaling message with a preset second operation:
[0076] @bj.ims.mnc000.mcc460.3gppnetwork.org / simservs.xml / ~~ / simservs / communication-diversio n / ruleset / rule%5b@id=%22call-forwarding-Unconditional%22%5d HTTP / 1.1.
[0077] The call forwarding parameter is call-forwarding, and the preset unconditional parameter is Unconditional.
[0078] Step S12: If yes, detect the first information and the second information in the original signaling of the UT interface.
[0079] Specifically, the source called number after the preset first field in the original signaling of the UT interface is detected as the first information, and the forwarding target number after the preset second field in the original signaling of the UT interface is detected as the second information.
[0080] Specifically, an MSISDN number is identified from the SIP number format as the source called number, for example: X-3GPP-Intended-Identity:sip:+8613911111111@bj.ims.mnc000.mcc460.3gppnetwork.org, where "13911111111" is the first information, and an MSISDN number is identified from the TEL number format as the forwarding target number, for example: <forward-to> <target> Tel:13922222222< / target> < / forward-to> , where "13922222222" is the second information.
[0081] The preset first field is X-3GPP-Intended-Identity; the preset second field is forward-to and target.
[0082] Step S13: put the first information and the second information into a key field table corresponding to the original signaling of the UT interface.
[0083] Specifically, the key field table corresponding to the original signaling of the UT interface is as follows:
[0084]
[0085] See also Figure 3 Another embodiment of the present application provides a device for identifying call forwarding fraudulent behavior, the device comprising:
[0086] The signaling collection server 101 is used to collect and parse the signaling set of the training number sample, obtain multiple key field tables and send them to the call forwarding identification device; collect and parse the signaling set of the current call forwarding number, obtain multiple current field tables and send them to the call forwarding identification device; the signaling set includes UT interface original signaling, 4G S1MME signaling, 5G N1 N2 signaling and number call signaling.
[0087] The call forwarding identification device 102 is used to extract preset fraud-related features according to each key field table to obtain a feature data set; train the LightGBM model according to the feature data set to obtain a fraud-related identification model; extract preset fraud-related features according to each current field table to obtain a current feature set and input it into the fraud-related identification model to obtain an identification result.
[0088] In some embodiments, the signaling collection server is specifically used to detect whether there is a preset first operation and a preset second operation in the original signaling of the UT interface; if so, detect the first information and the second information in the original signaling of the UT interface; and put the first information and the second information into the key field table corresponding to the original signaling of the UT interface.
[0089] In some embodiments, the signaling collection server is specifically used to detect whether the first line of the original signaling of the UT interface starts with PUT XCAP; if so, there is a preset first operation in the original signaling of the UT interface; detect whether the call transfer parameter in the original signaling of the UT interface is followed by a preset unconditional parameter; if so, there is a preset second operation in the original signaling of the UT interface.
[0090] For the specific limitations of a device for identifying call forwarding fraudulent behavior provided in this embodiment, please refer to the above embodiment of a method for identifying call forwarding fraudulent behavior, which will not be repeated here.
[0091] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0092] The above-mentioned embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the attached claims.
Claims
1. A method for identifying call forwarding fraudulent behavior, characterized in that: The method comprises: The signaling collection server collects and parses the signaling set of the training number sample to obtain multiple key field tables; each of the key field tables is sent to the call forwarding identification device; the signaling set includes UT interface original signaling, 4G S1MME signaling, 5G N1 N2 signaling and number call signaling; The call forwarding identification device extracts preset fraud-related features according to each key field table to obtain a feature data set; a LightGBM model is trained according to the feature data set to obtain a fraud-related identification model; The signaling collection server collects and analyzes the signaling set of the current call forwarding number to obtain multiple current field tables; and sends each of the current field tables to the call forwarding identification device; The call forwarding identification device extracts preset fraud-related features according to each of the current field tables to obtain a current feature set; and inputs the current feature set into the fraud-related identification model to obtain an identification result.
2. The method for identifying call forwarding fraudulent behavior according to claim 1, characterized in that: The step of the signaling collection server parsing the original signaling of the UT interface includes: Detecting whether a preset first operation and a preset second operation exist in the original signaling of the UT interface; If yes, detecting the first information and the second information in the original signaling of the UT interface; The first information and the second information are placed into a key field table corresponding to the original signaling of the UT interface.
3. The method for identifying call forwarding fraudulent behavior according to claim 2, characterized in that: The detecting whether there is a preset first operation and a preset second operation in the original signaling of the UT interface includes: Detect whether the first line of the original signaling of the UT interface starts with PUT XCAP; If yes, the preset first operation exists in the original signaling of the UT interface; Detecting whether the call transfer parameter in the original signaling of the UT interface is followed by a preset unconditional parameter; If so, the preset second operation exists in the original signaling of the UT interface.
4. The method for identifying call forwarding fraudulent behavior according to claim 2, characterized in that: The detecting the first information and the second information in the original signaling of the UT interface includes: Detecting a source called number after a preset first field in the original signaling of the UT interface as the first information; The forwarding target number after the preset second field in the original signaling of the UT interface is detected as the second information.
5. The method for identifying call forwarding fraudulent behavior according to claim 3, characterized in that: The call forwarding parameter is call-forwarding; the preset unconditional parameter is Unconditional.
6. The method for identifying call forwarding fraudulent behavior according to claim 4, characterized in that: The preset first field is X-3GPP-Intended-Identity; the preset second field is forward-to and target.
7. The method for identifying call forwarding fraudulent behavior according to claim 1, characterized in that: The preset fraud-related features include whether the time for setting the call forwarding number is early morning, the frequency of setting the call forwarding number, the number of set call forwarding numbers, whether the time for setting the call forwarding number in history is early morning, the frequency of setting the call forwarding number in history, and the number of set call forwarding numbers in history.
8. A device for identifying call forwarding fraudulent behavior, characterized in that: The device comprises: A signaling collection server is used to collect and parse the signaling set of the training number sample, obtain multiple key field tables and send them to the call forwarding identification device; collect and parse the signaling set of the current call forwarding number, obtain multiple current field tables and send them to the call forwarding identification device; the signaling set includes UT interface original signaling, 4G S1MME signaling, 5G N1 N2 signaling and number call signaling; The call transfer identification device is used to extract preset fraud-related features according to each key field table to obtain a feature data set; train the LightGBM model according to the feature data set to obtain a fraud-related identification model; extract preset fraud-related features according to each current field table to obtain a current feature set and input it into the fraud-related identification model to obtain an identification result.
9. The device for identifying call forwarding fraudulent behavior according to claim 8, characterized in that: The signaling collection server is specifically used to detect whether there is a preset first operation and a preset second operation in the original signaling of the UT interface; if so, detect the first information and the second information in the original signaling of the UT interface; and put the first information and the second information into a key field table corresponding to the original signaling of the UT interface.
10. The device for identifying call forwarding fraudulent behavior according to claim 9, characterized in that: The signaling collection server is specifically used to detect whether the first line of the original signaling of the UT interface starts with PUT XCAP; If yes, the preset first operation exists in the original signaling of the UT interface; detecting whether the call transfer parameter in the original signaling of the UT interface is followed by a preset unconditional parameter; If so, the preset second operation exists in the original signaling of the UT interface.