Method for monitoring business risk based on private number service

By collecting multi-dimensional data to generate dynamic entities, a mapping relationship between privacy numbers, dynamic entities, and business scenarios is constructed. Risk entity pairs are identified and real-time risk scores are generated, solving the problem of difficulty in identifying cross-number and cross-terminal behavior patterns in existing technologies, and realizing efficient risk monitoring of privacy number services.

CN122120381APending Publication Date: 2026-05-29优保在线(山西)科技有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
优保在线(山西)科技有限公司
Filing Date
2026-03-13
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies struggle to identify behavioral patterns of the same entity changing phone numbers or frequently switching terminal devices in privacy number services. They also fail to accurately identify the risks associated with the same number being used by different entities or changes in the entity's behavioral patterns, leading to a decline in the accuracy of risk monitoring.

Method used

The system collects terminal device identifiers, call behavior data, and service type tags. Through cross-correlation analysis, it generates dynamic entities, constructs a mapping relationship between privacy numbers, dynamic entities, and service scenarios, builds a time-series communication graph, identifies risk entity pairs, and generates real-time risk scores by combining the risk characteristics of dynamic entities.

Benefits of technology

It enables effective association of multiple private numbers used by the same entity, accurately identifies changes in behavioral patterns, improves the accuracy of entity identification, enhances the ability to detect illegal and irregular activities, can deeply uncover gang-related fraud and complex risks, and reduces the false judgment rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120381A_ABST
    Figure CN122120381A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of private number service risk monitoring, and specifically discloses a private number service-based business risk monitoring method, which comprises the following steps: collecting terminal device identifiers, call behavior data and business type labels; performing cross-correlation analysis on the terminal device identifiers and the call behavior data, clustering to generate dynamic entities, and performing scene correlation analysis on the business type labels to construct a private number-dynamic entity-business scene correlation mapping relationship; constructing a time sequence communication graph based on the correlation mapping relationship and historical communication events, identifying risk entity pairs, and realizing deep mining of gang fraud behaviors; extracting risk features based on the risk entity pairs to determine a risk mode, and generating a dynamic entity risk score in combination with historical behavior data; during real-time communication, calculating a real-time risk score according to the risk score of the dynamic entity to which the private number belongs, executing corresponding intervention instructions, and improving the real-time performance of risk response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of privacy number business risk monitoring technology, and relates to a method for monitoring business risks based on privacy number services. Background Technology

[0002] Privacy number services isolate real numbers and enable anonymous communication by assigning temporary or permanent privacy numbers to both parties in a call, effectively preventing user privacy leaks and harassing phone calls. With the expansion of application scenarios, privacy number communication traffic continues to grow, and communication behaviors are showing a trend towards diversification and higher frequency. At the same time, some criminals exploit the anonymity of privacy numbers to engage in illegal and irregular activities such as fraud and malicious marketing, posing potential risks to platform operations and user security. Therefore, how to effectively monitor communication behaviors within privacy number services has become a key issue in ensuring business security.

[0003] Currently, the industry's risk monitoring methods for privacy number services mainly rely on static rules and post-event complaint data. For example, Chinese invention patent CN115796322A discloses a method, system, device, and storage medium for monitoring customer privacy numbers. This method retrieves historical complaint accounts and numbers, combines a number tagging database and machine learning models to predict complaint risks and detect anomalies, and freezes or replaces high-risk accounts.

[0004] However, existing technologies based on static data and rule-based judgments have the following obvious limitations:

[0005] First, the scheme mainly relies on historical complaint data and number tagging information, without collecting multi-dimensional data such as terminal device identification and call behavior. As a result, it is impossible to associate multiple private numbers used by the same subject through terminal device identification, making it difficult to identify the behavior patterns of criminals who evade detection by changing numbers and frequently switching terminal devices.

[0006] Second, this scheme typically treats private numbers as fixed and unchanging analytical units, failing to consider that the same number may be used by different entities at different times, and also failing to objectively classify call subjects based on call behavior characteristics. When the same number is used by multiple entities or the behavior pattern of the same entity changes significantly, it cannot accurately identify the changes in the behavior subject, thus leading to a decrease in the accuracy of risk monitoring. Summary of the Invention

[0007] In view of this, in order to solve the problems mentioned in the background technology above, a business risk monitoring method based on privacy number services is proposed.

[0008] The objective of this invention can be achieved through the following technical solution: This invention provides a business risk monitoring method based on privacy number services, including:

[0009] Collect terminal device identifiers, call behavior data, and service type tags related to private number calls.

[0010] Cross-correlation analysis is performed on terminal device identifiers and call behavior data to generate dynamic entities through clustering. Scenario correlation analysis is also performed on business type tags to construct a correlation mapping relationship between privacy numbers, dynamic entities, and business scenarios.

[0011] Based on the association mapping relationship and historical communication events, a time-series communication graph is constructed, and risk entity pairs are identified from the time-series communication graph.

[0012] Based on the risk entity pairs, the risk characteristics of each dynamic entity are extracted to determine its risk pattern, and combined with the historical behavior data of the dynamic entities, a real-time risk score for each dynamic entity is generated.

[0013] The system obtains the privacy number involved when a real-time communication event occurs, determines the dynamic entity to which the privacy number belongs based on the association mapping relationship, calculates the real-time risk score of the privacy number according to the risk score of each dynamic entity, and executes the corresponding risk intervention instruction accordingly.

[0014] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention performs cross-correlation analysis on terminal device identification and call behavior data, clusters to generate dynamic entities, and then constructs the association mapping relationship between privacy number-dynamic entity-business scenario, effectively associating multiple privacy numbers used by the same subject, solving the problem that it is difficult to identify the cross-number and cross-terminal behavior patterns of the same subject due to the single data dimension.

[0015] (2) This invention divides the behavior time series by a fixed-length time window, extracts the behavior feature vector, calculates the similarity between windows and divides and merges stages based on a preset threshold, thereby realizing the objective quantitative generation of dynamic entities, thus automatically identifying the change points of behavior patterns, accurately dividing the dynamic entities corresponding to different behavior stages, solving the problem that the same number cannot be accurately identified when it is used by multiple entities or when the behavior pattern of the same entity changes, and improving the accuracy of behavior entity identification.

[0016] (3) This invention performs scenario association analysis on business type tags, statistically analyzes the call time distribution, call duration distribution and call frequency distribution of each dynamic entity under each business type, calculates the overall matching degree of business type, analyzes the business type transition sequence to calculate the scenario change mutation degree, and calculates the scenario association degree based on the matching degree and mutation degree, thereby accurately identifying abnormal situations where call behavior does not match the business scenario, effectively discovering behaviors that use normal business scenarios to disguise illegal and irregular activities, and enhancing the ability to perceive hidden risks from the business dimension.

[0017] (4) This invention constructs a time-series communication graph with dynamic entities as nodes and communication events as edges, and identifies risky entity pairs from it. At the same time, through multi-level mutation analysis of entity pairs, nodes and subgraph dimensions, it breaks through the current limitation of only being able to analyze isolated accounts, and realizes in-depth mining and multi-granularity early warning of complex risks such as gang fraud and large-scale harassment.

[0018] (5) This invention obtains the basic risk level by comprehensively considering the behavioral deviation, scenario risk level, and historical risk accumulation. At the same time, it calculates the associated risk level based on the number of risk entities involved in dynamic entities, the average risk level, and the diversity of risk types. The basic risk level and associated risk level are then integrated to generate a real-time risk score for dynamic entities. By stratifying and integrating behavioral risk and associated risk, this invention solves the problem of high misjudgment rate caused by relying on a single rule or static threshold. Attached Figure Description

[0019] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 This is a schematic diagram showing the connections between the steps of the method of the present invention.

[0021] Figure 2 This is a schematic diagram illustrating the connection of the association mapping relationship in this invention.

[0022] Figure 3 This is a schematic diagram showing the connection steps of the dynamic entity risk scoring calculation method of the present invention. Detailed Implementation

[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0024] This invention achieves business risk monitoring for privacy number services by collecting multi-dimensional data, performing dynamic entity recognition and time-series communication graph construction, and conducting risk analysis. Specifically, the method first collects multi-dimensional data related to privacy number calls; then, it performs cross-correlation analysis on terminal device identification and call behavior data to generate dynamic entities; next, it constructs a time-series communication graph based on the dynamic entities and identifies risky entity pairs through graph analysis; finally, it generates dynamic entity risk scores based on the risk characteristics of entity pairs, and calculates the real-time risk score of the privacy number based on the privacy number-dynamic entity mapping relationship in real-time communication events, executing corresponding intervention commands. This solves the problems of existing technologies relying on static rules, having single data dimensions, difficulty in identifying group risks, and delayed response.

[0025] Please see Figure 1 As shown, the business risk monitoring method based on privacy number service provided by the present invention includes the following steps S1 to S5.

[0026] S1. Collect terminal device identifiers, call behavior data, and service type tags related to private number calls.

[0027] This step aims to obtain the foundational data sources for subsequent analysis, covering multidimensional information that may reflect abnormal behavior during the communication process. The collected data includes at least: private phone number, terminal device identifier, call behavior data, and service type tags. Call behavior data includes call start time, end time, call duration, and call frequency.

[0028] The above data can be obtained in real time or in batches through the call detail records of the privacy number service platform, the signaling monitoring system, and the business system interface, and stored in a distributed data warehouse for subsequent analysis and retrieval.

[0029] S2. Perform cross-correlation analysis on terminal device identification and call behavior data, cluster to generate dynamic entities, and perform scenario correlation analysis on service type tags to construct a correlation mapping relationship between privacy number, dynamic entity, and service scenario.

[0030] This step involves the fusion and analysis of multi-dimensional data to associate scattered phone numbers with dynamic entities and establish a mapping relationship between phone numbers, entities, and business scenarios. This provides a data association foundation at the subject level for subsequent risk analysis. Please refer to [link to relevant documentation]. Figure 2 As shown.

[0031] S2-1, Cross-association analysis: Clustering generates dynamic entities

[0032] S2-1-1. Associate the terminal device identifier with the call behavior data on the same timeline to form the original data of the terminal device-behavior combination for each call record.

[0033] S2-1-2. Arrange the original data of terminal device-behavior combinations belonging to the same terminal device identifier in chronological order to form the behavior time series of each terminal device.

[0034] S2-1-3. Divide the behavioral time series into fixed-length time windows, perform statistical calculations on the call behavior data of each time window, and extract the behavioral feature vector within each time window.

[0035] Specifically, the process of extracting the behavioral feature vector includes: First, dividing the behavioral time series into a series of continuous and non-overlapping time windows using fixed-length time windows. Then, collecting all call behavior data falling within each time window (including call start time, call duration, and call frequency) and performing statistical calculations to generate behavioral feature vectors for each time window. The statistical calculations include at least: calculating the call time distribution within the window to form a time distribution vector; calculating the statistical characteristics of call duration within the window (mean, standard deviation, quantiles, etc.); and calculating the statistical characteristics of call frequency within the window (daily average frequency, frequency standard deviation, peak value, etc.). Finally, concatenating the above features yields the behavioral feature vector for that window.

[0036] It should be noted that during the initial operation phase of the system, there may be insufficient historical data to construct a complete behavioral time series. In this case, a shorter time window (such as 1 day) can be used to accumulate data temporarily. Once sufficient data is available, the window length can be gradually adjusted to the target length (such as 7 days) to ensure the accuracy and stability of dynamic entity clustering.

[0037] S2-1-4. Calculate the similarity of behavioral features within each time window, and classify adjacent time windows with behavioral feature similarity greater than or equal to a preset similarity threshold as candidate behavioral stages, and use adjacent time windows with behavioral feature similarity less than a preset similarity threshold as stage boundaries. The behavioral feature vector similarity is calculated using the cosine similarity calculation formula.

[0038] Preferably, a preset similarity threshold is used to determine whether adjacent time windows belong to the same behavioral stage. The preset similarity threshold can be set based on historical statistics, specifically including: selecting a batch of normal user devices with stable behavior from historical call data, calculating the similarity of behavioral feature vectors for all adjacent time windows, and obtaining the statistical distribution of the similarity. The lower quantile of this distribution (such as the 5th or 10th percentile) is taken as the preset similarity threshold. For example, if statistics show that 95% of normal adjacent windows have a similarity greater than 0.75, then the preset similarity threshold can be set to 0.75.

[0039] S2-1-5. Calculate the average behavioral feature vector of all time windows within each candidate behavioral stage as the representative vector of that stage.

[0040] S2-1-6. If the similarity of behavioral features between the representative vectors of two adjacent candidate behavioral stages is greater than or equal to the preset similarity threshold, then the two stages will be merged into the same dynamic entity; otherwise, the two stages will be divided into different dynamic entities.

[0041] S2-1-7. For newly emerging terminal devices in the system, before their behavioral time series length is sufficient to form a complete time window for cluster analysis, this method temporarily marks them as a candidate dynamic entity. This candidate dynamic entity will not participate in the risk entity pair mining and identification based on stable behavioral patterns in step S3. However, during the real-time risk monitoring stage, if a call from a privacy number is associated with this candidate dynamic entity, an initial risk score (e.g., a preset neutral risk value of 0.5) will be assigned to the candidate entity.

[0042] When the length of its behavioral time series meets the analysis requirements, the system incorporates all its historical call data into the analysis of step S2-1, generating a formal dynamic entity and calculating its first formal risk score. To ensure the continuity of the score, this first formal risk score can be calculated by fusing the historical real-time risk scores from the candidate stage with the basic risk level obtained from the formal analysis. Specifically, the average of the historical real-time risk scores from the candidate stage can be calculated, and then the average can be fused with the basic risk level to obtain the risk score, thus avoiding abrupt changes in the risk score due to entity state transitions.

[0043] S2-2, Scene Association Analysis: Calculate the scene association degree of each dynamic entity.

[0044] Based on the service type labels of each dynamic entity during each call, the behavioral characteristics of each dynamic entity are statistically analyzed according to the service type labels to obtain the call time distribution, call duration distribution and call frequency distribution of each dynamic entity under each service type.

[0045] The mean values ​​of the call time period distribution, call duration distribution, and call frequency distribution of each dynamic entity under each business type are calculated to obtain the baseline values ​​of the call time period, call duration, and call frequency for each dynamic entity under each business type.

[0046] The above distribution is compared with the corresponding benchmark value, and the overall matching degree of business type of each dynamic entity is calculated accordingly.

[0047] Furthermore, the specific calculation process for the overall matching degree of the business type is as follows:

[0048] First, the call behavior distribution of dynamic entities under business types is constructed in the following ways: Call time period distribution: Divide a day of 24 hours into 24 time periods, and count the proportion of calls of dynamic entities under business types that fall into each time period to obtain the time period distribution vector; Call duration distribution: Divide the call duration into several intervals, and count the proportion of calls in each interval to obtain the duration distribution vector; Call frequency distribution: Count the average daily call frequency of entities under business types.

[0049] Then, the similarity between the distribution of dynamic entities under business types and the baseline is calculated. For example, time period similarity and duration similarity can be calculated using cosine similarity, and frequency similarity can be calculated using normalized Euclidean distance. Then, the time period similarity, duration similarity, and frequency similarity are averaged to obtain the type matching degree of dynamic entities under business types.

[0050] Finally, since dynamic entities may involve multiple business types, the overall business type matching degree is calculated by averaging the type matching degrees of the dynamic entity across various business types.

[0051] Arrange the call records of dynamic entities in chronological order, extract the service type tag for each call record, and obtain the service type transition sequence. ,in For the first A dynamic entity, For the first The service type of this call This represents the total number of calls made by the dynamic entity.

[0052] The number of times the service type changes between two consecutive calls is counted, and then the abruptness of the scenario change is calculated. , , where the denominator This represents the total number of adjacent call pairs. The value range for this indicator is... :when When, it means that all calls of the entity are focused on the same business type and there has never been a scenario switch; when This indicates that each adjacent call of the entity switches between different service types, and the scenario changes extremely frequently. The larger the value, the more frequently the entity switches between different business types, and the weaker the correlation between its behavior and fixed business scenarios.

[0053] Based on the overall matching degree of business types and the abruptness of scene changes for each dynamic entity, the scene correlation degree of each dynamic entity is calculated. The scene correlation degree can be expressed by the formula... Calculate, where For the first The scene relevance of a dynamic entity For the first The overall business type matching degree of each dynamic entity ensures that entities with high overall business type matching degree and low mutability have high scenario relevance. Specifically, the overall business type matching degree and scenario change mutability need to be normalized to [value missing]. The interval is then substituted into the formula to calculate the scene relevance. The normalization of the overall matching degree of business types can be achieved using maximum-min normalization, while the normalization of the abrupt change degree of scene transformation can be handled using an exponential function or a piecewise function.

[0054] S2-3. Constructing the association mapping relationship between privacy number, dynamic entity, and business scenario.

[0055] S2-3-1. Match each call record with the behavioral characteristics of each dynamic entity to determine the dynamic entity corresponding to each call record.

[0056] S2-3-2. Based on the matching results, count the dynamic entities associated with each privacy number in each time period, and establish the attribution relationship between privacy numbers and dynamic entities.

[0057] S2-3-3. Obtain the scene relevance of each dynamic entity and associate it with the attribution relationship to form a relationship mapping between privacy number, dynamic entity and business scenario.

[0058] S3. Based on the association mapping relationship and historical communication events, construct a time-series communication graph, and identify risky entity pairs from the time-series communication graph.

[0059] S3-1. Constructing a timing communication diagram

[0060] Construct a communication graph with each dynamic entity as a node and each communication event between any two dynamic entities as an edge. Each edge must contain at least the following attributes: communication timestamp, communication duration, and service type.

[0061] Based on the timestamps, multiple edges between the same pair of nodes are arranged in chronological order to form a time-series communication graph. Multiple edges at different times can exist between the same pair of nodes, reflecting the historical evolution of the communication relationship. The graph can be stored using a time-series graph database or an adjacency list with a time index.

[0062] S3-2, Identifying Risky Entities

[0063] Two dynamic entities with communication events in the time-series communication graph are treated as entity pairs, and the communication edge sequence is extracted from each entity pair. Anomaly detection is performed on each entity pair in the following two dimensions:

[0064] (1) Detection of communication distribution anomalies

[0065] The number of communications between each entity pair, the average call duration, and the concentrated call time period are compared with preset benchmark parameters to determine whether the following anomalies exist:

[0066] Anomaly in communication frequency distribution: The number of communications between entity pairs deviates significantly from the historical baseline per unit time. For example, a pair of entities may communicate 10 times in one hour, while the historical average is 1 time.

[0067] Abnormal communication duration distribution: The average call duration between entity pairs deviates significantly from the normal pattern (e.g., abnormally concentrated or abnormally dispersed).

[0068] Abnormal communication time distribution: The call time between entity pairs is concentrated in irregular time periods (such as 2 am to 5 am). The preset benchmark parameter can be dynamically calculated based on the statistical distribution of all entity pairs or the historical behavior of the entity pair itself. For example, three times the standard deviation of the historical mean can be used as the preset benchmark parameter.

[0069] (2) Detection of sudden communication anomalies

[0070] A sliding window analysis is performed along the timeline on entity pairs and the overall communication graph to determine if any sudden anomalies exist. This includes detection at three different granularities:

[0071] Entity Pair Dimension: Extract the communication frequency, average call duration, and service type distribution of entity pairs within a preset time window (e.g., the most recent hour), and calculate their rate of change relative to the previous time window (e.g., the previous hour). If the rate of change of any dimension exceeds a preset mutation threshold, the entity pair is determined to have a sudden communication anomaly.

[0072] Node dimension: Extract the new connection establishment rate of dynamic entity nodes within a preset time window, i.e., the number or rate of communication edges established with new dynamic entities, and compare it with the node's historical maximum value. If the current new connection establishment rate exceeds its historical maximum value, it is determined that the node has a sudden communication anomaly.

[0073] Subgraph Dimension: The overall communication graph is divided into connected subgraphs. The number of nodes and edge density of each subgraph within a preset time window are extracted, and their growth rate relative to the preceding window is calculated. If the growth rate of the number of nodes or the growth rate of edge density of any subgraph exceeds a preset outbreak threshold, it is determined that the subgraph has a sudden communication anomaly, which may indicate that a group is carrying out large-scale activities.

[0074] If any dimension (abnormal communication distribution or sudden anomaly) is determined to be abnormal, the entity pair is marked as a risk entity pair and its risk type is recorded. The risk type includes one or more of the following: abnormal communication frequency, abnormal communication duration, abnormal communication time period, and entity pair mutation.

[0075] Furthermore, each risk entity pair is assigned a risk level upon being marked, which quantifies the severity of the risk for that entity pair. The risk level can be comprehensively assessed based on factors such as the degree of abnormal deviation (e.g., the magnitude of the rate of change, the deviation factor), the number of abnormal types, etc., for example, divided into levels 1-5 (level 1 being low risk, level 5 being high risk), or normalized to... The risk level is a range. This risk level will be used in subsequent calculations of dynamic entity association risk.

[0076] S4. Based on the risk entity pairs, extract the risk characteristics of each dynamic entity to determine its risk pattern, and combine the historical behavior data of the dynamic entities to generate a real-time risk score for each dynamic entity.

[0077] This step involves performing risk analysis on each dynamic entity based on the labeled risk entity pairs and quantifying its risk level.

[0078] S4-1. Determine the risk model of each dynamic entity.

[0079] For each dynamic entity, obtain all risk entity pairs it participates in and the risk type corresponding to each risk entity pair.

[0080] The frequency of the dynamic entity's participation in each risk type is statistically analyzed, and the risk type with the highest participation frequency is taken as the risk mode of the dynamic entity.

[0081] S4-2. Generate real-time risk scores for each dynamic entity.

[0082] By integrating risk indicators from multiple dimensions, a weighted fusion method is used to calculate the real-time risk score for each dynamic entity. Please refer to [link / reference]. Figure 3 As shown, it specifically includes:

[0083] Behavioral Deviation: This involves extracting the call time distribution, call duration distribution, and call frequency distribution of dynamic entities from their historical behavioral data, comparing these distributions with preset baseline parameters, and calculating the behavioral deviation. The deviation can be measured using Euclidean distance, Mahalanobis distance, or distributional dissimilarity, and normalized to [value missing]. Interval.

[0084] Specifically, the calculation process for the behavioral deviation is as follows:

[0085] For dynamic entities, their similarity to their historical baseline is calculated in three dimensions: time period similarity and duration similarity, which are the cosine similarity between the call time period distribution of the current time window and the time period distribution of the historical baseline, respectively; and frequency similarity, which is the average daily call frequency of the current time window. Similarity to historical baseline frequency It can be calculated using the following formula: ,in This represents frequency similarity.

[0086] Calculate behavioral deviation , In the formula and These are time period similarity and duration similarity, respectively.

[0087] Scenario risk level: Calculate the scenario risk level based on the dynamic entity scenario correlation degree. The lower the scenario correlation degree, the higher the scenario risk score (e.g., take the reciprocal or complement of the scenario correlation degree).

[0088] Historical risk accumulation: The ratio of the number of times a dynamic entity is marked as a risk entity pair within a historical time window to the total number of times, and the ratio of the two is used as the historical risk accumulation.

[0089] Basic risk level: The basic risk level is calculated by averaging the behavioral deviation, scenario risk level, and historical risk accumulation.

[0090] Association Risk Degree: Based on the risk entity pairs corresponding to the dynamic entity, calculate the association risk degree of the dynamic entity.

[0091] Furthermore, calculating the association risk level of dynamic entities includes:

[0092] Obtain the total number of risk entity pairs involved by dynamic entities, as an indicator of the number of risk pairs.

[0093] For each risk entity pair involving a dynamic entity, obtain its risk level, and calculate the average risk level of all risk entity pairs as a risk level indicator.

[0094] The number of different risk types involved in a dynamic entity is used as an indicator of risk diversity.

[0095] The risk level, risk grade, and risk diversity indicators are weighted and fused to obtain the associated risk degree of the dynamic entity.

[0096] Furthermore, the formula for calculating the dynamic entity association risk degree is as follows:

[0097] In the formula For the degree of association risk of dynamic entities, For risk versus quantity indicators, As an average risk level indicator, As a risk diversity indicator, , , These are the weighting coefficients for risk relative to quantity, average risk level, and risk diversity, used to quantify the impact of different dimensions on associated risks, and satisfying the following conditions: For example, it can be set to , , .in, This indicates that the indicators are normalized so that their values ​​are within a certain range. Within the range.

[0098] Based on this, by weighted fusion calculation of the association risk of each dynamic entity, on the one hand, the weight allocation can reflect the actual weight of the impact of risk participation scale (risk pair quantity), risk severity (average risk level) and risk type diversity on different dimensions of dynamic entity association risk, reflecting the difference in contribution of each dimension to the degree of participation of the entity in the risk network; on the other hand, it can directly integrate the information of the three dimensions of risk pair quantity, average risk level and risk type diversity, and comprehensively consider the impact of the three on the association risk of dynamic entities.

[0099] The weights can be set based on business risk appetite and actual operational experience, or obtained through statistical analysis of historical risk data. For example, first collect the number of risk pairs, average risk level, risk type diversity, and records of entities subsequently confirmed as high-risk for each dynamic entity within a historical period. Calculate the correlation coefficients between the three indicators and the high-risk outcome. Determine the contribution of each indicator to the high-risk outcome through regression analysis or principal component analysis. After normalization, the contribution is converted into the weight coefficients of the three indicators, with the total weight being 1. This allows for precise quantification of the associated risk level of the dynamic entity.

[0100] The basic risk level and the associated risk level are multiplied to generate a real-time risk score for the dynamic entity.

[0101] It should be noted that the real-time risk score of dynamic entities can be updated in batches at preset intervals, such as recalculating it daily at midnight based on the previous day's historical data, to balance computational resource consumption with the timeliness of risk response. Simultaneously, for dynamic entities that trigger significant anomalies (such as being added as a risk entity pair, or experiencing explosive growth in participation in risk-related networks), the system can trigger an immediate recalculation mechanism to update their risk scores in real time, ensuring a rapid response to sudden risks. In subsequent real-time communication events, the real-time risk score of the privacy number will be calculated based on the latest batch score of its associated dynamic entities.

[0102] S5. Obtain the privacy number involved when the real-time communication event occurs, determine the dynamic entity to which the privacy number belongs based on the association mapping relationship, calculate the real-time risk score of the privacy number according to the risk score of each dynamic entity, and execute the corresponding risk intervention instruction accordingly.

[0103] This step enables real-time risk decision-making, quickly assessing the risk of the current private number each time a call occurs.

[0104] Based on the association mapping relationship between the privacy number, dynamic entity, and business scenario, query and obtain each dynamic entity to which the privacy number belongs and its corresponding risk score.

[0105] It should be noted that if the queried privacy number does not exist in the associated mapping relationship (e.g., a newly assigned number), the cold start risk assessment process for the new number will be triggered, which specifically includes:

[0106] First, assign a temporary dynamic entity identifier to the number.

[0107] Secondly, its initial comprehensive risk score is determined. This score no longer uses a fixed default value, but rather a dynamic initialization strategy, as detailed below:

[0108] If the number has not yet generated any calls, it is temporarily assigned a preset neutral risk score (e.g., 0.5) as the initial benchmark for risk tolerance.

[0109] If the number has already had its first call, retrieve the dynamic entity associated with that first call. For each dynamic entity, determine its type:

[0110] If the other party is a formal dynamic entity that has been generated through step S2, its comprehensive risk score is obtained, and the initial risk score of the new number is adjusted accordingly: if there is a high-risk entity (e.g., a score higher than 0.8), the initial risk score of the new number is increased from the preset neutral value (e.g., 0.5) (e.g., increased to 0.6); if all other parties are low-risk, the neutral value is maintained or slightly decreased.

[0111] If the other party is also a candidate dynamic entity corresponding to the new number, its own risk score is still unstable. At this time, it will not be adjusted according to the risk value of the other party, but will maintain the preset neutral risk score.

[0112] Based on the risk patterns of each dynamic entity, the weight of each dynamic entity's impact on the overall risk of privacy numbers is determined.

[0113] Based on the risk scores and influence weights of each dynamic entity, a weighted fusion calculation is performed to obtain the real-time risk score of the privacy number. , In the formula, The number of dynamic entities associated with the privacy number. , For the first The influence weight of each dynamic entity For the first Risk score for each dynamic entity.

[0114] After obtaining the real-time risk score of the privacy number, it is compared with a preset risk threshold, and corresponding risk intervention instructions are executed. Intervention instructions may include: allowing access (low risk), adding verification (medium risk), limiting traffic (medium-high risk), blocking calls, or freezing the number (high risk), etc. Intervention instructions can be sent to the privacy number service platform or communication gateway for execution in real time.

[0115] Through steps S1 to S5 above, this invention constructs a complete risk monitoring process for privacy number services. By integrating multi-dimensional data, dynamic entity recognition, time-series graph analysis, and multi-level risk quantification, it achieves accurate identification and real-time response to complex risks such as concealed abnormal entities and organized fraud, effectively improving the business security level of privacy number services.

[0116] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.

[0117] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0118] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.

[0119] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0120] Finally, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A business risk monitoring method based on privacy number services, characterized in that: The method includes: Collect terminal device identifiers, call behavior data, and service type tags related to private number calls; Cross-correlation analysis is performed on terminal device identification and call behavior data to generate dynamic entities through clustering, and scenario correlation analysis is performed on business type tags to construct a correlation mapping relationship between privacy number, dynamic entity, and business scenario. Based on the association mapping relationship and historical communication events, a time-series communication graph is constructed, and risk entity pairs are identified from the time-series communication graph; Based on the risk entity pairs, the risk characteristics of each dynamic entity are extracted to determine its risk pattern, and combined with the historical behavior data of the dynamic entities, a real-time risk score for each dynamic entity is generated. The system obtains the privacy number involved when a real-time communication event occurs, determines the dynamic entity to which the privacy number belongs based on the association mapping relationship, calculates the real-time risk score of the privacy number according to the risk score of each dynamic entity, and executes the corresponding risk intervention instruction accordingly.

2. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The clustering that generates dynamic entities includes: By associating terminal device identifiers with call behavior data along the same timeline, raw data combining terminal device and behavior is generated for each call record. Arrange the original data of terminal devices and behaviors belonging to the same terminal device identifier in chronological order to form the behavior time series of each terminal device. The behavioral time series is divided into fixed-length time windows, and the call behavior data of each time window is statistically calculated to extract the behavioral feature vector within each time window. Calculate the similarity of behavioral features within each time window, and classify adjacent time windows with behavioral feature similarity greater than or equal to a preset similarity threshold as candidate behavioral stages, and use adjacent time windows with behavioral feature similarity less than a preset similarity threshold as stage boundaries. Calculate the average behavioral feature vector of all time windows within each candidate behavioral stage as the representative vector of that stage; If the similarity of behavioral features between the representative vectors of two adjacent candidate behavioral stages is greater than or equal to a preset similarity threshold, then the two stages are merged into the same dynamic entity; otherwise, the two stages are divided into different dynamic entities.

3. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The scenario association analysis of business type tags includes: Based on the service type labels of each dynamic entity in each call, the behavioral characteristics of each dynamic entity are statistically analyzed according to the service type labels to obtain the call time distribution, call duration distribution and call frequency distribution of each dynamic entity under each service type. The mean values ​​of the call time period distribution, call duration distribution, and call frequency distribution of each dynamic entity under each business type are calculated to obtain the baseline values ​​of the call time period, call duration, and call frequency of each dynamic entity under each business type. The above distribution is compared with the corresponding benchmark value, and the overall matching degree of business type of each dynamic entity is calculated accordingly. Arrange the call records of dynamic entities in chronological order, extract the business type label of each call record, and obtain the business type transition sequence; The number of times the service type changes between two consecutive calls is counted, and then the abruptness of the scenario change is calculated. Based on the overall matching degree of business types and the abruptness of scene changes of each dynamic entity, the scene correlation degree of each dynamic entity is calculated.

4. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The construction of the association mapping relationship between privacy number, dynamic entity, and business scenario includes: Match each call record with the behavioral characteristics of each dynamic entity to determine the dynamic entity corresponding to each call record; Based on the matching results, the dynamic entities associated with each privacy number in each time period are counted, and the attribution relationship between privacy numbers and dynamic entities is established. Obtain the scenario relevance of each dynamic entity and associate it with the attribution relationship to form a relationship mapping between privacy number, dynamic entity, and business scenario.

5. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The identified risk entity pairs include: Two dynamic entities with communication events in the time-series communication graph are taken as entity pairs, and the communication edge sequence in each entity pair is extracted; The number of communications between each entity pair, the average call duration, and the concentrated call time period are compared with preset benchmark parameters to determine whether there are any communication distribution anomalies. Sliding window analysis is performed along the time axis on entity pairs and the overall communication graph to determine whether there are any sudden communication anomalies. Based on the detection results of communication distribution anomalies and communication burst anomalies, if either dimension is determined to be anomaly, the entity pair is marked as a risk entity pair and its risk type is recorded.

6. The business risk monitoring method based on privacy number service according to claim 5, characterized in that: The determination of whether a sudden communication anomaly exists includes: Extract the communication frequency, average call duration, and service type distribution of entity pairs within a preset time window, and calculate their rate of change relative to the preceding time window. If the rate of change of any dimension exceeds a preset mutation threshold, it is determined that the entity pair has a sudden communication anomaly. Extract the new connection establishment rate of dynamic entity nodes within a preset time window, compare it with the node's historical maximum value, and if the current new connection establishment rate exceeds a preset threshold, determine that the node has a sudden communication anomaly. The overall communication graph is divided into connected subgraphs. The number of nodes and edge density of each subgraph within a preset time window are extracted, and their growth rate relative to the previous window is calculated. If the growth rate of the number of nodes or the growth rate of edge density of any subgraph exceeds the preset burst threshold, it is determined that the subgraph has a communication burst anomaly. If any of the above mutation patterns are identified, it is determined that there is a sudden communication anomaly.

7. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The determination of the risk model for each dynamic entity includes: For each dynamic entity, obtain all risk entity pairs it participates in and the risk type corresponding to each risk entity pair; The frequency of the dynamic entity's participation in each risk type is statistically analyzed, and the risk type with the highest participation frequency is taken as the risk mode of the dynamic entity.

8. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The generation of real-time risk scores for each dynamic entity includes: Extract the call time distribution, call duration distribution, and call frequency distribution of dynamic entities from their historical behavior data, and compare them with preset benchmark parameters to calculate the behavior deviation. Calculate the scenario risk level based on the dynamic entity scenario correlation degree; The number of times a dynamic entity is marked as a risk entity pair within a historical time window is compared with the total number of times, and the ratio of the two is used as the historical risk accumulation degree. The baseline risk level is obtained by averaging the behavioral deviation, scenario risk, and historical risk accumulation. Based on the risk entity pairs corresponding to dynamic entities, calculate the association risk degree of dynamic entities; The basic risk level and the associated risk level are multiplied to generate a real-time risk score for the dynamic entity.

9. The business risk monitoring method based on privacy number service according to claim 8, characterized in that: The calculation of the association risk degree of the dynamic entity includes: Obtain the total number of risk entity pairs involved by dynamic entities, as an indicator of the number of risk pairs; For each risk entity pair involved in a dynamic entity, obtain its risk level, and calculate the average risk level of all risk entity pairs as a risk level indicator. The number of different risk types involved in a dynamic entity is used as an indicator of risk diversity. The risk level, risk grade, and risk diversity indicators are weighted and fused to obtain the associated risk degree of the dynamic entity.

10. The business risk monitoring method based on privacy number service according to claim 1, characterized in that: The real-time risk score for calculating the privacy number includes: Based on the association mapping relationship between the privacy number, dynamic entity, and business scenario, query and obtain each dynamic entity to which the privacy number belongs and its corresponding risk score; Based on the risk patterns of each dynamic entity, the weight of each dynamic entity's impact on the overall risk of privacy numbers is determined. Based on the risk scores and influence weights of each dynamic entity, a weighted fusion calculation is performed to obtain the real-time risk score of the privacy number.

Citation Information

Patent Citations

  • Method, system and device for monitoring private number of customer, and storage medium

    CN115796322A