Short message management and control method and device, storage medium and electronic equipment
By obtaining the geographical location characteristics of the terminal address that sends spam text messages, clustering algorithms are used to identify high-incidence areas and count the sending frequency, which solves the problem of insufficient flexibility in spam text message identification in existing technologies and achieves precise prevention and efficient filtering of spam text messages.
Patent Information
- Application Number
- CN202511456313.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2026-01-23
AI Technical Summary
Existing technologies lack flexibility and accuracy in identifying and combating spam text messages, making it difficult to cope with the ever-changing network environment and emerging forms of harmful information.
By obtaining the sending terminal addresses of text messages marked as spam, clustering algorithms are used based on geographic location characteristics to identify high-incidence areas, and the sending frequency is counted and controlled to achieve precise prevention and control of text messages.
It improves the flexibility and accuracy of identifying spam text messages, can proactively prevent new or variant spam text messages, reduce false positives and false negatives, and enhance the security of the communication environment.
Smart Images

Figure CN121397480A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to a short message management method and device, a storage medium and an electronic device. BACKGROUND
[0002] With the rapid development of mobile communication technology, especially the popularization of 5th Generation Wireless Systems (5G) message services, short message interactions between users are increasingly rich in content and form. At the same time, the problem of spam short messages is becoming increasingly prominent, not only interfering with normal communication and affecting user experience, but also spreading illegal and harmful information such as false information and fraudulent content, posing a serious threat to network space content security.
[0003] Currently, the identification and management of spam short messages mainly rely on keyword matching filtering mechanisms and user-initiated reporting techniques, relying on users to discover and submit suspicious messages, and the platform takes disposal measures on related numbers or content after verification.
[0004] However, the related technology can only identify and block known types of spam information to a certain extent, usually relying on a pre-set keyword library and user's lag response, which lacks flexibility and is difficult to cope with changing network environments and emerging forms of harmful information, resulting in low accuracy of identifying spam short messages. SUMMARY
[0005] Therefore, the present application provides a short message management method and device, a storage medium and an electronic device, which mainly aims to improve the technical problem of low identification accuracy and lack of flexibility in identifying spam short messages.
[0006] In a first aspect, the present application provides a short message management method, comprising: obtaining the sending terminal address of a short message marked as spam; determining a plurality of target areas corresponding to the spam short message based on the geographical location characteristics of the sending terminal address through a clustering algorithm; statistically analyzing the frequency of sending short messages by sending terminals in the target areas within a preset time period; controlling the short messages sent in the target areas based on the frequency of sending short messages by the sending terminals.
[0007] In a second aspect, the present application provides a short message management device, comprising: an acquisition module configured to obtain the sending terminal address of a short message marked as spam; The determining module is configured to determine, based on geographical location features of the sending terminal address, a plurality of target regions corresponding to the spam short message through a clustering algorithm. The statistical module is configured to count, within a preset time period, a frequency of sending short messages by the sending terminal in the target region. The control module is configured to control short messages sent in the target region based on the frequency of sending short messages by the sending terminal.
[0008] In a third aspect, the present application provides a computer readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method of the first aspect.
[0009] In a fourth aspect, the present application provides an electronic device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the method of the first aspect when executing the computer program.
[0010] In a fifth aspect, the present application provides a computer program product having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method of the first aspect.
[0011] According to the technical solution described above, the short message control method, device, storage medium, and electronic device provided by the present application first acquire the address of a sending terminal of a short message marked as spam. Then, based on geographical location features of the sending terminal address, a plurality of target regions corresponding to the spam short message are determined through a clustering algorithm. Within a preset time period, the frequency of sending short messages by the sending terminal in the target region is counted. Based on the frequency of sending short messages by the sending terminal, short messages sent in the target region are controlled. Compared with the prior art, the present application filters and classifies and aggregates the geographical location of the address of the sending terminal of the spam short message, monitors the sending frequency in the region after identifying the high-incidence region, realizes the monitoring and effective filtering of the short message, and thus realizes the active and accurate prevention and control of the new or variant spam short message, improving the identification flexibility and accuracy of the spam short message.
[0012] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented in accordance with the content of the description, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0013] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present application and, together with the specification, serve to explain the principles of the present application.
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings required by the embodiments or prior art description will be briefly introduced as follows. Obviously, those skilled in the art can obtain other drawings according to these drawings without any creative effort.
[0015] Figure 1 A flowchart of a short message management method provided by an embodiment of the present application is shown; Figure 2 A flowchart of another short message management method provided by an embodiment of the present application is shown; Figure 3 A flowchart of an example provided by an embodiment of the present application is shown; Figure 4 A structural diagram of a short message management device provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0016] The embodiments of the present application will be described in more detail below with reference to the accompanying drawings. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.
[0017] In some examples, the main strategy of spam short message recognition generally relies on keyword matching filtering mechanism and user active reporting to identify and prevent. Among them, the keyword matching filtering mechanism realizes the effective identification and filtering of bad information through the steps of constructing keyword library, selecting appropriate matching algorithm, text preprocessing and matching process. User active reporting is to improve the identification and management of spam short messages through multiple links such as user identification behavior, reporting channel, information processing and feedback. Although these technical means play an important role in short message monitoring and filtering, they inevitably have certain limitations and deficiencies: the keyword filtering mechanism has insufficient flexibility, which usually depends on the preset keyword library, which makes it difficult to cope with the changing network environment and emerging bad information forms. With the development of technology and the evolution of language, new bad information forms emerge in an endless stream, and the update of keyword library often lags behind these changes; the keyword filtering mechanism has a high misjudgment rate, especially for those information that uses variant vocabulary, metaphor, abbreviation or intentional spelling error to evade detection, the keyword matching filtering mechanism often has difficulty in effectively identifying; the user active reporting mechanism has a long response lag and consumes a lot of manpower and time cost.
[0018] In order to improve the technical problems of insufficient recognition flexibility and low recognition accuracy of current spam short messages. The present embodiment provides a short message management method, which can be applied to a 5G message system or a content security management platform in a mobile communication network, such as Figure 1As shown, the method comprises: Step 101, obtaining the sending terminal address of the short message marked as spam short message.
[0019] For example, the short message refers to a text or multimedia message transmitted through a mobile communication network or a 5G message platform, and the sending terminal address specifically refers to the Internet Protocol (IP) address used by the user equipment sending the message in the network, which is used to uniquely identify the network source location of the message.
[0020] For example, the short message confirmed as spam short message after review can be marked, the sending terminal address in the short message marked as spam short message can be extracted, and these addresses can be summarized and constructed as a spam information sending terminal IP address library.
[0021] Step 102, determining a plurality of target regions corresponding to the spam short message based on the geographical location characteristics of the sending terminal address through a clustering algorithm.
[0022] In some examples, the geographical location characteristics refer to the geographical spatial location information associated with the sending terminal IP address, which can be specifically represented by the latitude and longitude coordinates obtained after IP address resolution. Based on the constructed spam information sending terminal IP address library, the IP addresses in the library can be clustered and analyzed according to the geographical location characteristics by using a K-means clustering algorithm. By mapping each IP address to its corresponding geographical location coordinates, the clustering division is performed by taking the coordinates as feature vectors, forming a plurality of region clusters that are gathered in geographical space. These region clusters are identified and delimited as high-risk regions where spam short message sending behaviors frequently occur.
[0023] For example, after determining the high-risk region, all IP address segments in the region can be checked. After determining the geographical location range of the high-risk region of the spam short message, based on the boundary coordinate information of the region, the mapping database of IP address and geographical location is queried to obtain all IP address segments covering the geographical range. This process realizes the expansion from the known spam source to the entire high-risk region, and all IP addresses in the region that may be involved in illegal sending are included in the key monitoring range.
[0024] Step 103, in a preset time period, counting the frequency of sending short messages by the sending terminal in the target region.
[0025] In some examples, the time-sliced statistical sending frequency of the IP address segment is to count the total number of short messages sent by the monitored IP address segment in a preset time period.
[0026] Step 104, based on the frequency of sending short messages by the sending terminal, controlling the short messages sent in the target region.
[0027] Exemplarily, the system periodically aggregates the message sending behaviors of each IP address segment by time period, and when the statistical frequency exceeds a preset threshold, the subsequent message sending of the IP address segment is triggered for manual review process, so as to realize timely intervention on the potential spam message propagation behavior.
[0028] Compared with the prior art, by applying the technical solution of the embodiment, first, the sending terminal address of the short message marked as spam is acquired; then, based on the geographical location characteristics of the sending terminal address, a plurality of target regions corresponding to the spam message are determined by a clustering algorithm; within a preset time period, the frequency of sending short messages by the sending terminal in the target region is counted; and then, based on the frequency of sending short messages by the sending terminal, the short messages sent in the target region are controlled. By screening and classifying and aggregating the geographical location of the address of the spam message sending terminal, the high-risk area is identified, and the sending frequency in the area is monitored, so as to realize the monitoring and effective filtering of the short message, thereby realizing the active and accurate prevention and control of the new or variant spam message, and improving the identification flexibility and accuracy of the spam message.
[0029] In order to further illustrate the specific implementation process of the method of the embodiment, the embodiment provides a method as shown in Figure 2 The method comprises the following steps: Step 201, acquiring the sending terminal address of the short message marked as spam.
[0030] The sending terminal IP address extraction is the basic link of the method. For the short message confirmed as spam through the content review process, the system parses and extracts the corresponding sending terminal IP address from the message. The confirmation basis of these messages includes two cases: one is that the message content hits the platform preset automatic detection strategy of spam message, and is confirmed as spam by manual review; the other is that the message is submitted through the user's active reporting channel, and is confirmed as spam by manual judgment and verification. Only the message meeting any of the above conditions is regarded as a valid sample, and the sending terminal IP address is extracted into the sample pool, and the sending terminal IP address is included in a specially constructed spam information sending terminal IP address library. The library serves as the data basis for subsequent geographical location analysis and regional clustering, ensuring the accuracy and reliability of the analysis object, and providing original data support for identifying high-risk sending sources.
[0031] Step 202, acquiring the geographical location coordinates corresponding to the sending terminal address.
[0032] For example, the IP addresses in the sending terminal IP address library are classified based on the K-means clustering algorithm, and are clustered and divided according to the geographical location characteristics. Specifically, each IP address can be parsed by a GeoIP database tool to be mapped to the corresponding latitude and longitude coordinates, and is converted into a geographical location feature vector that can be used for clustering calculation.
[0033] In step 203, the feature vectors corresponding to the geographic position coordinates are clustered by using a clustering algorithm to generate a plurality of region clusters that are gathered in geographic positions.
[0034] For example, the data points corresponding to the geographic position coordinates can be regarded as feature vectors, the longitude and latitude can be regarded as coordinate points in a two-dimensional space, the K-means clustering algorithm can be used for grouping processing, each data point can be divided into a region to which a nearest clustering center belongs, and the position of the clustering center can be updated according to the coordinate mean value of the data points in each iteration until the clustering result converges, thereby generating a plurality of region clusters that are continuously and densely distributed in the geographic space, wherein each region cluster corresponds to a potential high incidence range of spam short messages.
[0035] Optionally, step 203 can specifically include: based on the distance between the geographic position coordinates, using a clustering algorithm to group process the feature vectors, and dividing the sending terminal addresses with a spatial distribution less than a distance threshold into the same geographic region; and dynamically adjusting the coverage range of the corresponding geographic region according to the concentration degree of the geographic position coordinates in each group to form a plurality of region clusters with boundary definitions.
[0036] For example, in the clustering process, the distribution density and concentration degree of the geographic position coordinates in each group can be combined to dynamically determine the coverage radius and boundary range of the region, so that the high-density gathering region has a smaller range definition, and the sparse distribution region can be appropriately expanded in boundary, thereby finally generating a plurality of region clusters with clear geographic boundaries to accurately reflect the spatial gathering characteristics of the spam short message sending behavior.
[0037] Optionally, the above-mentioned based on the distance between the geographic position coordinates, using a clustering algorithm to group process the feature vectors, and dividing the sending terminal addresses with a spatial distribution less than a distance threshold into the same geographic region can specifically include: taking a randomly selected geographic position coordinate as an initial clustering center, and assigning the geographic position coordinates of each sending terminal address to a group corresponding to the clustering center with the nearest coordinate spatial distance of the geographic position; in the process of each iteration, the position of the clustering center of the current group is recalculated and updated based on the arithmetic mean value of all geographic position coordinates in the current group.
[0038] For example, the clustering centers are first initialized, K data points are randomly selected as initial clustering centers, and the feature vectors of each IP address are assigned to a category to which the nearest clustering center belongs according to the spatial distance between the geographic position feature vectors.
[0039] For example, in the IP address classification process, the K-means clustering algorithm is used to process the extracted sending terminal IP addresses. In the initial stage, K IP address corresponding geographical location feature vectors are randomly selected as clustering centers, and each feature vector represents the longitude and latitude coordinates of an IP address. The system calculates the spatial distance between each data point and each clustering center based on the earth spherical distance model, and assigns each IP address feature vector to the category corresponding to the nearest clustering center to form a preliminary clustering group.
[0040] In some examples, the above clustering grouping process continues in iterations. After each assignment is completed, the positions of the clustering centers are recalculated based on the geographical location coordinates of all data points in the current category, and the center point coordinates are updated by arithmetic mean. The new clustering center is the mean value of the corresponding dimension of the data points in each dimension, until the clustering result tends to be stable, and finally forms several highly geographically concentrated regional clusters for identifying high incidence areas of spam short messages.
[0041] For example, for each IP address corresponding geographical location feature vector, the spatial distance between it and each clustering center can be calculated using the Haversine formula as the measurement standard:
[0042] wherein, is the distance between IP address vector points, is the radius of the earth. and are the latitudes of the first IP address and the second IP address, respectively, and are the longitudes of the first IP address and the second IP address, respectively, is the difference between the latitudes of the two IP addresses, is the difference between the longitudes of the two IP addresses.
[0043] For example, according to the calculated spherical distance between each IP address feature vector and the clustering center, each IP address is assigned to the category corresponding to the nearest clustering center to form a preliminary geographical clustering group. At the same time, based on the spatial distribution density of IP addresses within each group, i.e. the sparsity or density of individuals, the coverage radius of the corresponding area is dynamically determined. A smaller radius is set for areas with dense distribution, and the radius is correspondingly expanded for areas with sparse distribution, to reasonably define the geographical range of each spam short message high incidence area.
[0044] Step 204, determining the regional cluster as the target area corresponding to the spam short message.
[0045] In some examples, after the region cluster generated by clustering is determined as the target region corresponding to the spam short message, a reverse search operation can be performed to expand the monitoring range: first, the geographical boundary of each target region is confirmed, and the geographical fence of the region is determined by calibrating a plurality of latitude and longitude coordinate points covered thereby; then, based on the mapping relationship between IP addresses and geographical positions, an IP geographical position database is queried to retrieve all IP address segments located within the geographical fence, and these IP address segments are collectively included in a key monitoring set as objects for subsequent sending behavior analysis and control.
[0046] In some embodiments, a density-based clustering algorithm (such as DBSCAN) can also be used to automatically identify the clustered region according to the distribution density of IP addresses in the geographical space, without the need to pre-set the number of clusters, so as to effectively identify high-incidence regions of any shape and exclude sparse outliers. Alternatively, a hierarchical clustering algorithm can be used to construct a clustering tree structure from bottom to top or from top to bottom, to merge or divide IP addresses layer by layer according to a geographical distance threshold, to form a region division result with hierarchical relationship, and then to generate a plurality of target regions with clear geographical range for subsequent IP address segment reverse search and sending frequency monitoring.
[0047] Step 205: In a preset time period, the frequency of sending short messages by the sending terminal in the target region is counted.
[0048] In some examples, as shown in Figure 3 First, the IP address of the sending terminal is extracted from the marked spam short message, and clustering analysis is performed based on the geographical position characteristics to identify the high-incidence region, and then all IP address segments within the region are reverse searched to be included in the key monitoring range, and the sending frequency of short messages of each IP segment is counted by time slicing to realize quantitative monitoring of the sending behavior in the region.
[0049] Optionally, step 205 can specifically include: in a preset time period, the short message sending behavior of each sending terminal belonging to one or more address segments covered by the target region is summarized to obtain the total number of sent short messages; based on the preset time period and the total number of short messages, the frequency of sending short messages by the sending terminal in the target region is determined.
[0050] For example, the time-slicing counting of the sending frequency in the region refers to segmenting and counting the IP address segments included in the key monitoring according to a preset time period to record the message sending situation in each time period in real time; specifically including: taking a fixed time length (such as 1 hour) as a counting period, and in each period, the total number of short messages sent by the sending terminals from all IP address segments in the target region is summarized to form the frequency data sliced by time as the basis for subsequent judgment of whether to trigger the control strategy.
[0051] Step 206, based on the frequency of sending short messages by the sending terminal, the short messages sent in the target area are controlled.
[0052] Optionally, step 206 can specifically include: comparing the frequency of sending short messages by the sending terminal with a preset frequency threshold; if the frequency of sending short messages by the sending terminal exceeds the preset frequency threshold, triggering an audit process for subsequent short messages sent in the target area.
[0053] For example, according to the comparison between the statistical sending frequency data and the system preconfigured frequency threshold, if the sending frequency of a certain IP address segment in a specified time period does not reach the threshold, it is considered as normal sending behavior, and no intervention measures are taken; when the sending frequency reaches or exceeds the set threshold, the system automatically pushes the subsequent short messages and related data sent by the IP address segment to the artificial audit link, and the auditor determines whether the content is a spam message, if it is confirmed as a spam message, the IP address segment or the corresponding message is executed. Disposal operation such as interception, speed limit or ban.
[0054] In some examples, the audit process can also include configuring automatic execution of preliminary disposal measures according to the risk level, such as temporarily limiting the speed of the relevant IP address segment or sending number, increasing the detection intensity of the content filtering rule, or including it in the high-risk behavior list for continuous monitoring; for the spam messages confirmed by artificial audit, further execute message interception, sending permission ban or associated account marking, and feedback the processing result to the model training link to optimize the subsequent identification strategy.
[0055] Compared with the prior art, the embodiment extracts the IP address of the sending terminal from the confirmed spam short message, combines the geographic location information, uses the clustering algorithm to realize the spatial clustering analysis, and identifies the high-risk area where the spam message sending behavior is concentrated. By mapping the IP address to the geographic location coordinates, based on the iterative calculation of the clustering center and the spatial vector distance measurement, the control area with geographical boundary is delimited, and the precise identification mechanism for the high-risk area is formed. After determining the high-risk area, further through the matching of the geographic fence and the IP geographic location database, the all IP address segments covered in the area are retrieved and obtained, the monitoring range is expanded from individual illegal IP to the entire associated network area. On this basis, the sending behavior of these IP address segments is statistically counted in time slices, when the sending frequency exceeds the preset threshold, the audit process is triggered, and speed limit, ban or other disposal measures can be taken for the relevant IP address segment, so as to realize the closed-loop control from individual traceability to regional governance.
[0056] Further, as a specific implementation of the method shown in Figure 1 and Figure 2 , the embodiment provides a short message control device, such as Figure 4As shown, the device comprises: an acquisition module 31, a determination module 32, a statistics module 33, and a control module 34.
[0057] The acquisition module 31 is configured to acquire the sending terminal address of the short message marked as spam short message. The determination module 32 is configured to determine a plurality of target areas corresponding to the spam short message based on the geographical location characteristics of the sending terminal address through a clustering algorithm. The statistics module 33 is configured to count the frequency of sending short messages by the sending terminal in the target area within a preset time period. The control module 34 is configured to control the short messages sent in the target area based on the frequency of sending short messages by the sending terminal.
[0058] In some examples of the embodiment, the determination module 32 is specifically configured to acquire geographical location coordinates corresponding to the sending terminal address; utilize a clustering algorithm to cluster and divide feature vectors corresponding to the geographical location coordinates, to generate a plurality of region clusters that are geographically aggregated; and determine the region clusters as the target areas corresponding to the spam short message.
[0059] In some examples of the embodiment, the determination module 32 is specifically further configured to adopt a clustering algorithm to group process the feature vectors based on the distance between the geographical location coordinates, and classify the sending terminal addresses with a spatial distribution less than a distance threshold into the same geographical region; and dynamically adjust the coverage range of the corresponding geographical region according to the concentration degree of the geographical location coordinates in each group, to form a plurality of region clusters with boundary definitions.
[0060] In some examples of the embodiment, the determination module 32 is specifically further configured to take a randomly selected geographical location coordinate as an initial clustering center, and assign the geographical location coordinate of each sending terminal address to the group corresponding to the clustering center with the closest coordinate spatial distance to the geographical location; and in the process of each iteration, recompute and update the clustering center position of the current group based on the arithmetic mean of all geographical location coordinates in the current group.
[0061] In some examples of the embodiment, the statistics module 33 is specifically configured to aggregate the short message sending behaviors of each sending terminal belonging to one or more address segments covered by the target area within the preset time period, to obtain the total number of sent short messages; and determine the frequency of sending short messages by the sending terminal in the target area based on the preset time period and the total number of short messages.
[0062] In some examples of the embodiment, the management module 34 is specifically configured to compare the frequency of sending short messages of the sending terminal with a preset frequency threshold, and if the frequency of sending short messages of the sending terminal exceeds the preset frequency threshold, trigger the review process of the short messages subsequently sent in the target area.
[0063] It should be noted that the short message management device provided in the embodiment, other corresponding descriptions of the functions involved in each functional unit can be referred to the corresponding descriptions in Figure 1 and Figure 2 , which will not be repeated here.
[0064] Based on the above method as shown in Figure 1 and Figure 2 , accordingly, the embodiment also provides a computer readable storage medium having a computer program stored thereon, which is executed by a processor to implement the above method as shown in Figure 1 and Figure 2 .
[0065] Based on such understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a U disk, a mobile hard disk, etc.), including a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the method of each implementation scenario of the present application.
[0066] Based on the above method as shown in Figure 1 and Figure 2 , and Figure 4 the virtual device embodiment, in order to achieve the above purpose, the embodiment of the present application also provides an electronic device, such as a personal computer, a server, a notebook computer, a smart robot, etc. The device includes a storage medium and a processor; the storage medium is used to store a computer program; the processor is used to execute the computer program to implement the above method as shown in Figure 1 and Figure 2 .
[0067] Optionally, the above-mentioned entity device can also include a user interface, a network interface, a camera, a radio frequency (Radio Frequency, RF) circuit, a sensor, an audio circuit, a WI-FI module, etc. The user interface can include a display screen (Display), an input unit such as a keyboard (Keyboard), etc. The optional user interface can also include a USB interface, a card reader interface, etc. The network interface can optionally include a standard wired interface, a wireless interface (such as a WI-FI interface), etc.
[0068] Those skilled in the art can understand that the above-mentioned entity device structure provided by the embodiment does not constitute a limitation on the entity device, and can include more or fewer components, or combine certain components, or different component arrangements.
[0069] The storage medium can also include an operating system, a network communication module. The operating system is a program for managing hardware and software resources of the above-mentioned entity device, supporting the running of information processing programs and other software and / or programs. The network communication module is used to realize the communication between the components in the storage medium and the communication with other hardware and software in the information processing entity device.
[0070] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary general hardware platform, or by hardware. By applying the scheme of the embodiment, compared with the prior art, the area monitoring based on the clustering analysis of the sending terminal IP address and the geographical position characteristics in the embodiment, by spatial clustering of the IP addresses of the confirmed spam short messages, identifies the highly concentrated high-risk areas in the geography, and then uses the clustering algorithm to perform vector calculation and grouping division on the geographical position coordinates corresponding to the IP addresses, can dynamically define the control area with boundary definition, compared with the traditional way of relying on keyword matching or user reporting, improves the identification ability of new, variant and large-scale sending behavior, reduces the misjudgment and omission caused by semantic changes or evasion means, and enhances the accuracy of content security control. After determining the high-risk area, combined with the IP geographical position database, all IP address segments in the geographical range are inquired, the monitoring object is expanded from a single illegal IP to the entire associated network area, and comprehensive coverage of potential risk sources is realized. The embodiment focuses the audit resources, filtering strategy and ban measures on the high-risk area, and can trigger manual audit or automatic flow limiting and other pre-intervention means when the frequency is abnormal, improves the governance efficiency, strengthens the active prevention and control ability of the source of the spam message, effectively improves the control accuracy, makes the user feel the clean and orderly communication environment, analyzes the user behavior mode, and combines the sending terminal IP address information, which can more accurately identify the potential spam short message sender, further improves the filtering effect, and improves the user communication experience.
[0071] It has to be noted that, in the present document, relational terms are intended only to convey a possible relationship between elements or
[0072] The above description is merely that of the specific embodiments of the application and as such is not to be taken in a limiting sense. Various modifications and co nti n uations will be evident to those skilled in the art that do not depart from the spirit and scope of the application as defined by the appended claims. The specific embodiments presented, therefore, are not to be considered in a limiting sense, but are presented for purposes of illustration only in conformance with the above-stated description. It is not the intention to limit the application to the described embodiments but rather the intention is to cover all modifications and alternatives coming within the spirit and scope of the claims.
Claims
1. A method for managing short messages, characterized by, The method comprises the following steps: obtaining the sending terminal address of the short message marked as spam short message; determining a plurality of target areas corresponding to the spam short message based on the geographical location features of the sending terminal address through a clustering algorithm; statistically counting the frequency of sending short messages by the sending terminal in the target area within a preset time period; controlling the short messages sent in the target area based on the frequency of sending short messages by the sending terminal.
2. The method of claim 1, wherein, The method of determining a plurality of target areas corresponding to the spam short message based on the geographical location features of the sending terminal address through a clustering algorithm comprises the following steps: obtaining the geographical location coordinates corresponding to the sending terminal address; using a clustering algorithm to cluster and divide the feature vectors corresponding to the geographical location coordinates to generate a plurality of region clusters that are gathered in geographical location; determining the region clusters as the target areas corresponding to the spam short message.
3. The method of claim 2, wherein, The method of using a clustering algorithm to cluster and divide the feature vectors corresponding to the geographical location coordinates to generate a plurality of region clusters that are gathered in geographical location comprises the following steps: based on the distance between the geographical location coordinates, using a clustering algorithm to group process the feature vectors, and classifying the sending terminal addresses with a spatial distribution less than a distance threshold into the same geographical region; dynamically adjusting the coverage range of the corresponding geographical region according to the concentration degree of the geographical location coordinates in each group to form a plurality of region clusters with boundary definition.
4. The method of claim 3, wherein, The method of using a clustering algorithm to group process the feature vectors based on the distance between the geographical location coordinates and classifying the sending terminal addresses with a spatial distribution less than a distance threshold into the same geographical region comprises the following steps: taking a randomly selected geographical location coordinate as an initial clustering center, and assigning the geographical location coordinate of each sending terminal address to the group corresponding to the clustering center with the closest coordinate spatial distance to the geographical location; in the process of each iteration, based on the arithmetic mean of all geographical location coordinates in the current group, recalculating and updating the clustering center position of the current group.
5. The method of claim 1, wherein, The method of statistically counting the frequency of sending short messages by the sending terminal in the target area within a preset time period comprises the following steps: within the preset time period, aggregating the short message sending behaviors of each sending terminal belonging to one or more address segments covered by the target area to obtain the total number of sent short messages; based on the preset time period and the total number of short messages, determining the frequency of sending short messages by the sending terminal in the target area.
6. The method of claim 1, wherein, The method of controlling the short messages sent in the target area based on the frequency of sending short messages by the sending terminal comprises the following steps: comparing the frequency of sending short messages by the sending terminal with a preset frequency threshold; if the frequency of sending short messages by the sending terminal exceeds the preset frequency threshold, triggering the review process of the subsequent sent short messages in the target area.
7. A device for managing short messages, characterized in that The method comprises the following steps: an obtaining module configured to obtain the sending terminal address of the short message marked as spam short message; a determining module configured to determine a plurality of target areas corresponding to the spam short message based on the geographical location features of the sending terminal address through a clustering algorithm; The statistical module is configured to count the frequency of sending short messages by the sending terminal in the target area within a preset time period. The management and control module is configured to manage and control the short messages sent in the target area based on the frequency of sending short messages by the sending terminal.
8. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, when executed by a processor, implements the method of any one of claims 1 to 6.
9. An electronic device comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, The processor, when executing the computer program, implements the method of any one of claims 1 to 6.
10. A computer program product having stored thereon a computer program, characterized in that, The computer program product, when executed by a processor, implements the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Method and system for controlling rubbish short message
CN101472247A
Fraud number detection method and device and storage medium
CN110139280A
A method and device for determining location information
CN110677504A
Positioning method and device based on IP address, computer equipment and storage medium
CN118524087A
Method and system for barring of short message service (SMS)
WO2025013012A1