A method and system for analyzing and collecting evidence of fraudulent and harassing calls

By screening and analyzing user call sheet data, and using Internet enterprise labeling database and signaling protocol data, accurate identification and evidence collection of fraud and harassing calls is achieved, the problem of difficult to identify and deal with harmful numbers in the existing technology is solved, and the flexibility and timeliness of governance are improved.

CN114500744BActive Publication Date: 2025-08-22TIANJIN NAT CYBERNET SECURITY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210116464.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-07
Publication Date
2025-08-22
Estimated Expiration
2042-02-07

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively identify and collect fraudulent calls and harassing calls, and lacks the basis for accurately detecting and disposing of harmful numbers.

Method used

By obtaining user call order data, using call order data processing model and Internet enterprise marking database to filter out initial call data, perform automatic callback and monitoring and evidence collection of harmful classification numbers, and combine signaling protocol data and early warning analysis to achieve accurate identification and disposal of harmful numbers.

Benefits of technology

It improves the flexibility and timeliness of fraud and harassment phone control, realizes the accurate discovery and disposal of harmful phones, and provides evidence for harmful numbers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114500744B_ABST
    Figure CN114500744B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and system for analyzing and collecting evidence of fraudulent calls and harassing calls, comprising: obtaining user call bill data for screening to obtain initial call data; using the initial call data to obtain harmful classification number data; using the harmful classification number data to obtain data analysis and early warning results; wherein, the initial call data is initial calling call data and initial called call data. In order to effectively adapt to the development of network evolution and improve the flexibility and timeliness of fraudulent and harassing call management, it is urgent to establish an analysis and evidence collection system for fraudulent calls and harassing calls, realize the accurate discovery of harmful calls, and provide a basis for the disposal of harmful numbers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of big data analysis, and in particular to a method and system for analyzing and collecting evidence of fraudulent and harassing calls. Background Art

[0002] In recent years, with the development of communication technology, more and more criminals have used mobile phones, landlines, the Internet and other communication technologies to carry out illegal propaganda and financial fraud, causing economic losses to many telephone users, disrupting normal social order, and seriously endangering people's lives and property safety. After the fraud is discovered, in order to solve the problem of difficulty in providing evidence, a fraud call and harassment call analysis and evidence collection system is built to achieve accurate detection of harmful calls and provide a basis for the disposal of harmful numbers. Summary of the Invention

[0003] In view of the shortcomings of the existing technology, the present invention provides a method for analyzing and collecting evidence of fraudulent and harassing calls, which is characterized by comprising:

[0004] Obtain user call record data and filter it to obtain initial call data;

[0005] Obtaining harmful classification number data using the initial call data;

[0006] Obtaining data analysis and warning results using the harmful classification number data;

[0007] The initial call data includes initial calling call data and initial called call data.

[0008] Preferably, the obtaining of user call bill data and screening to obtain initial call data includes:

[0009] Using user call bill data and based on the call bill data processing model, obtain the call bill data processing results;

[0010] The call bill data processing result is used to obtain initial call data based on the harassment and fraud call feature library.

[0011] Preferably, the method of obtaining harmful classification number data using initial call data includes:

[0012] The harmful classification number data is obtained based on the tag database of the Internet company using the initial call data.

[0013] Preferably, the method of obtaining data analysis warning results using harmful classification number data includes:

[0014] Automatic call back processing is performed using harmful classification number data to obtain harmful classification number automatic call back processing data;

[0015] Using the harmful classification number automatic call back processing data to perform monitoring and evidence collection processing to obtain harmful classification number monitoring and evidence collection data;

[0016] The harmful classification number monitoring and evidence collection data is used to perform early warning analysis and processing to obtain data analysis and early warning results.

[0017] Furthermore, the method of using harmful classification number data to perform automatic callback processing to obtain harmful classification number automatic callback processing data includes:

[0018] After performing a call back operation using the call record corresponding to the harmful classification number data, the call back statistical feature data is obtained;

[0019] Using the callback statistical characteristic data to perform an evaluation to obtain a callback statistical characteristic data evaluation result;

[0020] Obtaining automatic callback processing data for harmful classification numbers based on function aggregation using the evaluation results of the callback statistical feature data;

[0021] The callback statistical characteristic data include the main called number, calling time, off-hook time, answering time, on-hook time and the number's location.

[0022] Furthermore, the monitoring and evidence collection data obtained by using the automatic callback processing data of harmful classification numbers includes:

[0023] Using the signaling protocol data corresponding to the automatic callback processing data of harmful classified numbers to perform initial signaling processing to obtain standard call detail data;

[0024] The standard call details data is used to screen based on a pre-set call list database to obtain harmful classification number monitoring and evidence collection data.

[0025] Furthermore, the data analysis and warning results obtained by using the harmful classification number monitoring and evidence collection data for early warning analysis include:

[0026] Using the harmful classification number monitoring and evidence data and the signaling data corresponding to the harmful classification number monitoring and evidence data, we conduct communication line expansion analysis, SMS call bill correlation analysis, and media signaling fusion analysis in turn to obtain the results of the harmful classification number's damage degree;

[0027] The harmful classification number hazard degree result is used to obtain a data analysis warning result based on a pre-set hazard degree classification.

[0028] Based on the same inventive concept, the present invention also provides a fraudulent call and harassing call analysis and early warning system, which is characterized by comprising:

[0029] Abnormal communication analysis module, used to obtain user call record data and filter it to obtain initial call data;

[0030] a tag verification module, configured to obtain harmful classification number data using the initial call data;

[0031] An analysis and warning module, configured to obtain data analysis and warning results using the harmful classification number data;

[0032] The initial call data includes initial calling call data and initial called call data.

[0033] Compared with the closest prior art, the present invention has the following beneficial effects:

[0034] Obtain user call bill data for screening to obtain initial call data; use the initial call data to obtain harmful classification number data; use the harmful classification number data to obtain data analysis and early warning results; wherein, the initial call data is the initial calling call data and the initial called call data. In order to effectively adapt to the development of network evolution and improve the flexibility and timeliness of fraud and harassing call management, it is urgent to establish an analysis and evidence collection system for fraudulent calls and harassing calls, to achieve accurate discovery of harmful calls and provide a basis for the disposal of harmful numbers. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 This is a flow chart of a fraudulent call and harassing call analysis and evidence collection method provided by the present invention;

[0036] Figure 2 This is a flow chart of a fraud call and harassing call analysis and early warning system provided by the present invention;

[0037] Figure 3 This is a practical application flow chart of a fraudulent call and harassing call analysis and evidence collection method provided by the present invention;

[0038] Figure 4 This is a practical application scheduling flow chart of a fraud call and harassing call analysis and evidence collection method provided by the present invention;

[0039] Figure 5 This is a flowchart of a practical application system of a fraudulent call and harassing call analysis and evidence collection method provided by the present invention. DETAILED DESCRIPTION

[0040] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0042] Example 1

[0043] The present invention provides a method for analyzing and collecting evidence of fraudulent and harassing calls, such as Figure 1 Shown, including:

[0044] Step 1: Obtain user call record data and filter it to obtain initial call data;

[0045] Step 2: Obtain harmful classification number data using the initial call data;

[0046] Step 3: Obtain data analysis warning results using the harmful classification number data;

[0047] The initial call data includes initial calling call data and initial called call data.

[0048] Step 1 specifically includes:

[0049] 1-1: Using user call record data and the call record data processing model, obtain the call record data processing results;

[0050] 1-2: Utilize the call bill data processing result to obtain initial call data based on the harassment and fraud call feature database.

[0051] Step 2 specifically includes:

[0052] 2-1: Use the initial call data to obtain harmful classification number data based on the tag database of the Internet company.

[0053] Step 3 specifically includes:

[0054] 3-1: Using harmful classification number data to perform automatic call back processing to obtain harmful classification number automatic call back processing data;

[0055] 3-2: Using the harmful classification number automatic call back processing data to perform monitoring and evidence processing to obtain harmful classification number monitoring and evidence data;

[0056] 3-3: Use the harmful classification number monitoring and evidence collection data to perform early warning analysis and processing to obtain data analysis and early warning results.

[0057] Step 3-1 specifically includes:

[0058] 3-1-1: After performing a call back operation using the call record corresponding to the harmful classification number data, the call back statistical feature data is obtained;

[0059] 3-1-2: Using the callback statistical characteristic data to perform an evaluation to obtain a callback statistical characteristic data evaluation result;

[0060] 3-1-3: Utilizing the evaluation results of the callback statistical feature data, based on function aggregation, to obtain automatic callback processing data for harmful classification numbers;

[0061] The callback statistical characteristic data include the main called number, calling time, off-hook time, answering time, on-hook time and the number's location.

[0062] Step 3-2 specifically includes:

[0063] 3-2-1: Use the signaling protocol data corresponding to the automatic callback processing data of harmful classified numbers to perform initial signaling processing to obtain standard call detail data;

[0064] 3-2-2: Utilize the standard call details data to filter based on a pre-set call list database to obtain harmful classification number monitoring and evidence collection data.

[0065] Step 3-3 specifically includes:

[0066] 3-3-1: Using the harmful classification number monitoring and evidence data and the signaling data corresponding to the harmful classification number monitoring and evidence data, we conduct communication line expansion analysis, SMS call record correlation analysis, and media signaling fusion analysis in turn to obtain the degree of harm caused by the harmful classification number;

[0067] 3-3-2: Utilize the hazard degree results of the harmful classification numbers to obtain data analysis warning results based on pre-set hazard degree classification.

[0068] In this embodiment, a method for analyzing and collecting evidence of fraudulent and harassing calls is provided. The pre-set risk level classification is based on a comprehensive assessment of two components: 1. The warning number's calling behavior (e.g., daily call volume, daily caller ratio, daily callee dispersion, and other indicators); and 2. The number of internet callers. For example, if the number 135*** receives 1,000 calls per day, 10,000 calls per month, a daily caller ratio of 98%, and 50 or more internet caller fraud comparisons, it is considered high risk.

[0069] In this embodiment, a method for analyzing and collecting evidence of fraudulent calls and harassing calls is provided. The call bill data processing model uses a decision tree algorithm for analysis and identification, mainly including a cat pool model, a high-frequency model, a high-risk channel model, a high-risk base station model, a silent card model, and a high-risk IMEI model.

[0070] In this embodiment, a method for analyzing and collecting evidence of fraudulent and harassing calls is provided. The internet enterprise's tag database is derived from two sources: 1. data obtained through cooperation with internet enterprises; and 2. real-time web crawling. This data is compared with model warning data, and the call list database is internet enterprise tag data corresponding to the internet enterprise's tag database.

[0071] Example 2

[0072] The present invention provides a fraudulent call and harassing call analysis and evidence collection system, such as Figure 2 Shown, including:

[0073] Abnormal communication analysis module, used to obtain user call record data and filter it to obtain initial call data;

[0074] a tag verification module, configured to obtain harmful classification number data using the initial call data;

[0075] An analysis and warning module, configured to obtain data analysis and warning results using the harmful classification number data;

[0076] The initial call data includes initial calling call data and initial called call data.

[0077] Example 3

[0078] The present invention provides a specific implementation method for analyzing and collecting evidence of fraudulent and harassing calls, such as Figure 3 Shown, including:

[0079] 1.1. Big Data Analysis System

[0080] A big data analysis method based on call behavior analysis processes and models massive amounts of call record data, identifying abnormal behaviors and associated features within the vast signaling record data, thereby screening out harassing and fraudulent phone numbers and violations. Harassing and fraudulent calls exhibit significant differences from normal user behavior, such as an imbalance in caller and callee ratios, high call frequency, one-way calls, and a lack of social connections between called users.

[0081] The system creates different classification labels for call numbers, and analyzes abnormal behavior characteristics mainly from the perspective of calling and called parties.

[0082] 1.2. Internet Mark Verification System

[0083] Fraudulent and harassing calls detected by the system are compared and verified with the labeled data of internet companies. The system crawls the web to classify and compare suspected fraudulent and harassing phone numbers with the terminal labeled data of internet companies, and issues early warnings for harmful classified numbers.

[0084] 1.3. Automatic Call Back System

[0085] 1.3.1. Callback Scheduling

[0086] To achieve the scheduling of callback tasks submitted by users in a reasonable and fair manner, it mainly includes task loading module, task scheduling module and task execution module. The logical architecture is as follows: Figure 3 shown.

[0087] The task scheduling subsystem completes the scheduling and execution monitoring of tasks and submitted task scripts submitted by users through the interface. It supports the interactive information setting of scheduling configuration monitoring parameters, including waiting in task queues, scheduling strategies, and other functions. The functional modules are as follows:

[0088] (1) Task loading

[0089] Tasks submitted through the interface system or other means are generally divided into periodic tasks or regularly triggered tasks. These tasks will only be added to the queue for scheduling when they reach the specified time period or the specified time point. Task loading is to realize such task preloading function.

[0090] (2) Task Scheduling

[0091] Task scheduling is a core functional module in the entire task scheduling subsystem, which mainly monitors the task execution time, execution cycle, etc.

[0092] (3) Task status tracking

[0093] The task tracking module is responsible for tracking various states of the entire life cycle of the task.

[0094] 1.3.2. Media Control

[0095] The main function of the media control module is to perform related operations on the media in the call test.

[0096] (1) Media playback

[0097] The audio files recorded by the system can be played through the interface.

[0098] (2) Media Editor

[0099] You can synthesize, mix, and edit media. You can read media files through IO streams, operate on them directly, and write the modified media files to new files. You can also edit, modify, and delete media files.

[0100] (3) Media status feedback

[0101] During the media playback process, there may be situations such as the media file format not being recognized or the file not being able to be opened. This module will monitor these conditions in real time and return the status to the software level for processing by the program.

[0102] 1.3.3. Data Statistics

[0103] The data statistics subsystem is used to provide summary data to the system and display information such as the amount of callback data on the page.

[0104] (1) Callback result statistics

[0105] The callback results are counted at different granularities, including the number of test calls to the same calling and called numbers, different regions, and the total number of outgoing calls.

[0106] (2) Data Collection

[0107] The main function is to collect call log records, including the calling and called numbers, call time, off-hook time, answer time, on-hook time, number location and other data, for evaluating the quality of callbacks.

[0108] (3) Effect evaluation statistics

[0109] The main function is to perform preliminary function aggregation and other statistics on the callback results, including the number of callbacks, number of answers, duration and other data.

[0110] 1.4. Monitoring and Evidence Collection System

[0111] The monitoring and evidence collection system mainly completes network access, data collection, data forwarding, configuration management, and detection and identification functions.

[0112] 1.4.1. Network Access

[0113] The network access module accesses the IMS core network in a parallel manner, accesses, diverts and aggregates signaling protocol data and media protocol data.

[0114] 1.4.2. Signaling Processing

[0115] The signaling processing module provides functions such as signaling protocol parsing, content filtering, feature extraction, content filling, and media information association to form standard call detail data.

[0116] 1.4.3. Call Detection

[0117] The call detection module extracts signaling features and performs real-time matching based on policies and configurations to detect harmful calls in real time. The system supports detection of numbers on black, white, and gray lists, counterfeit numbers, and very long and short numbers, enabling efficient, accurate, and flexible real-time detection.

[0118] 1.4.4. Media Processing

[0119] The media processing module completes the media stream introduced from the network access module, performs encoding and decoding, reorganization and harmful information forensics on the media stream, and encrypts the processed information.

[0120] 1.4.5. Policy Configuration Management

[0121] The policy configuration management module is responsible for receiving list policies, global policies and basic data issued from the business aggregation node, and provides functions such as maintenance, update, conflict detection and feedback of disposal results of various prevention policy data status.

[0122] 1.5. Comprehensive Analysis and Early Warning System

[0123] like Figure 4 shown.

[0124] 1.5.1. Media Analysis

[0125] Realize analysis functions such as media preprocessing, synthetic sound detection, and media transcription for media files.

[0126] (1) Media preprocessing

[0127] The system will pre-process audio samples through technologies such as media coding conversion, channel conversion, pre-emphasis, resampling, framing, windowing and media activity detection to improve the availability of samples.

[0128] (2) Synthetic sound detection

[0129] The system extracts feature vectors of positive and negative media samples and trains the SVM classification model. As the number of samples increases, the algorithm is adjusted to improve the model recognition accuracy.

[0130] (3) Media transcription

[0131] The system will extract features from audio samples, complete model building through sample feature model training and model testing, and realize media-to-text conversion by combining the model with stop word filtering and other functions.

[0132] 1.5.2. Semantic Analysis

[0133] Realize functions such as keyword information extraction, topic classification, and information clustering of media text content.

[0134] (1) Keyword information extraction

[0135] The system realizes the keyword information extraction and retrieval function of media transcription information. For keywords, the system realizes hierarchical configuration and sets keywords of bad and harmful categories and subcategories.

[0136] (2) Topic classification

[0137] The system calls the established classification model to conduct topic classification analysis on the information that has been transcribed by the media.

[0138] The system associates harmful media confirmed by the model with their corresponding mobile phone numbers. Confirmed harmful calls can be provided to relevant management departments for investigation and punishment, providing effective technical support for improving communication information security.

[0139] (3) Information clustering

[0140] Telephone fraud and harassment methods are constantly evolving, and regardless of the method, they can result in the leakage of personal information and financial loss. Therefore, building on existing fraud and harassment identification methods, we conduct in-depth analysis of all media transcriptions involving personal property and personal information to establish a new classification model for harmful telecommunications.

[0141] Analyze all uploaded media transcription information and perform feature identification on information containing keywords such as (bank card, money, ID number, account number, remittance, transfer, credit card, savings card, password, verification code...).

[0142] 1.5.3. Comprehensive analysis and early warning

[0143] The degree of harm is determined based on the results of media analysis, semantic analysis, and signaling analysis, and warnings and disposal are issued for highly suspected numbers whose harm level reaches the threshold.

[0144] (1) Comprehensive analysis of harmful information

[0145] The system integrates signaling and media analysis data to conduct comprehensive analysis, analyzes and mines suspected harmful numbers and media, and discovers more clues and further determines the extent of the harm through technical means such as caller and called party communication line expansion analysis, SMS call record correlation analysis, and media signaling fusion analysis.

[0146] (2) Graded warning

[0147] Suspected harmful numbers are graded according to the degree of harm, and corresponding early warning mechanisms are set up for different levels, supporting automatic disposal, manual disposal, monitoring and evidence collection, whitelist release, etc.

[0148] (3) Joint disposal

[0149] For harmful numbers confirmed by the system or manually, the system will be linked online with the existing number handling system to achieve real-time handling.

[0150] 1.6. Early Warning and Disposal Business Management System

[0151] It provides a friendly human-computer interaction interface, enables users to set automatic parameters for various analysis engines, and enables them to analyze and judge suspected information.

[0152] 1.6.1. Early warning management

[0153] Realize functions such as business process management, information analysis, analysis result data query, and data statistics.

[0154] 1.6.2. Disposal management

[0155] The system supports both manual and automatic handling. Automatic handling is achieved through linkage with the existing number handling system.

[0156] 1.6.3. Evidence Management

[0157] The system supports the management of key list numbers and evidence collection parameters.

[0158] 1.6.4. Callback Management

[0159] (1) Task Management

[0160] The page allows users to configure callback start time, end time, calling number, called number, media to be played, and other configurations. It also supports the import of task scripts on the page. After importing the task script, the callback task will be executed in real time.

[0161] (2) Callback real-time effect display

[0162] This module uses visual controls to display the callback effect in real time. The callback effect is just a display of the callback log, simulating a real-time dialing scenario, while displaying some basic information such as the calling number, called number, number location, callback time, etc.

[0163] (3) Callback log query

[0164] Every time a call is answered, a call log is generated and stored in the database as a test record, including basic call information, whether the call was answered, etc. This function can filter the log records by various conditions and display the detailed information of the call back log.

[0165] (4) Callback statistics display

[0166] The callback log statistics are displayed in pie charts, bar charts, lists, etc., so that users can understand the number of callbacks and the response results.

[0167] (5) System configuration

[0168] System configuration parameters such as numbers, seats, etc.; media configuration, configure media mixing, editing, audition and other functions.

[0169] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0170] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0171] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0172] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0173] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.

Claims

1. A method for analyzing and collecting evidence of fraudulent and harassing calls, characterized in that: include: S1. Obtain user call record data and filter it to obtain initial call data; S2. Obtain harmful classification number data using the initial call data; S3. Obtaining data analysis and warning results using the harmful classification number data; S3-1. Performing automatic call back processing using harmful classification number data to obtain harmful classification number automatic call back processing data; S3-1-1. After performing a call back operation using the call record corresponding to the harmful classification number data, obtain call back statistical feature data; S3-1-2. Evaluate the callback statistical characteristic data to obtain a callback statistical characteristic data evaluation result; S3-1-3. Obtaining automatic callback processing data for harmful classification numbers based on function aggregation using the evaluation results of the callback statistical feature data; Among them, the callback statistical feature data includes the main called number, call time, off-hook time, answer time, on-hook time and number location; S3-2, using the harmful classification number automatic call back processing data to perform monitoring and evidence collection processing to obtain harmful classification number monitoring and evidence collection data; S3-2-1. Perform initial signaling processing using the signaling protocol data corresponding to the automatic callback processing data for harmful classified numbers to obtain standard call detail data; S3-2-2. Filtering the standard call details data based on a pre-set call list database to obtain harmful classification number monitoring and evidence collection data; S3-3, using the harmful classification number monitoring and evidence collection data to perform early warning analysis and obtain data analysis and early warning results; S3-3-1. Use the harmful classification number monitoring and evidence data and the signaling data corresponding to the harmful classification number monitoring and evidence data to conduct communication line expansion analysis, SMS call record correlation analysis, and media signaling fusion analysis in sequence to obtain the results of the harmful classification number damage level; S3-3-2. Obtaining data analysis warning results based on a pre-set hazard level classification using the hazard level results of the harmful classification numbers; The initial call data includes initial calling call data and initial called call data.

2. The method according to claim 1, wherein: The obtaining of user call record data and screening to obtain initial call data includes: Using user call bill data and based on the call bill data processing model, obtain the call bill data processing results; The call bill data processing result is used to obtain initial call data based on the harassment and fraud call feature library.

3. The method according to claim 1, wherein: The method of obtaining harmful classification number data by utilizing initial call data includes: The harmful classification number data is obtained based on the tag database of the Internet company using the initial call data.

4. A fraudulent call and harassing call analysis and evidence collection system, characterized by: include: Abnormal communication analysis module, used to obtain user call record data and filter it to obtain initial call data; a tag verification module, configured to obtain harmful classification number data using the initial call data; An analysis and warning module, configured to obtain data analysis and warning results using the harmful classification number data; Automatic call back processing is performed using harmful classification number data to obtain harmful classification number automatic call back processing data; After performing a call back operation using the call record corresponding to the harmful classification number data, the call back statistical feature data is obtained; Using the callback statistical characteristic data to perform an evaluation to obtain a callback statistical characteristic data evaluation result; Obtaining automatic callback processing data for harmful classification numbers based on function aggregation using the evaluation results of the callback statistical feature data; Among them, the callback statistical feature data includes the main called number, call time, off-hook time, answer time, on-hook time and number location; Using the harmful classification number automatic call back processing data to perform monitoring and evidence collection processing to obtain harmful classification number monitoring and evidence collection data; Using the signaling protocol data corresponding to the automatic callback processing data of harmful classified numbers to perform initial signaling processing to obtain standard call detail data; Using the standard call details data to filter based on a pre-set call list database to obtain harmful classification number monitoring and evidence collection data; Using the harmful classification number monitoring and evidence collection data to perform early warning analysis and processing to obtain data analysis and early warning results; Using the harmful classification number monitoring and evidence data and the signaling data corresponding to the harmful classification number monitoring and evidence data, we conduct communication line expansion analysis, SMS call bill correlation analysis, and media signaling fusion analysis in turn to obtain the results of the harmful classification number's damage degree; Obtaining a data analysis warning result based on a pre-set hazard level classification using the hazard level result of the harmful classification number; The initial call data includes initial calling call data and initial called call data.

Citation Information

Patent Citations

  • Crank call interception method and system

    CN104735272A

  • Fraud phone pre-warning system and pre-warning method

    CN107342986A

  • A fraud phone identification method and system

    CN109698884A