Method for fraud pattern recognition based on remote control applications and call patterns

By building a fraud identification model based on remote control applications and call patterns, and using IMEI data and call behavior analysis to identify new GOIP device telecommunications fraud, we solved the problem of identifying new GOIP device fraud and achieved efficient fraud detection and prevention.

CN115643580BActive Publication Date: 2025-09-26CHINA UNICOM (SHANDONG) IND INTERNET CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211400110.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-09
Publication Date
2025-09-26
Estimated Expiration
2042-11-09

AI Technical Summary

Technical Problem

Existing technologies make it difficult to effectively identify and prevent telecommunications fraud using new GOIP devices. These devices are simple to set up and easy to purchase, making them prone to large-scale outbreaks among students and other groups.

Method used

By obtaining the phone number data of those who use remotely controlled dangerous apps, filtering the IMEI data, removing duplicates and sorting them, a fraud identification model is constructed. Combined with call behavior analysis, undersampling, oversampling, cost-sensitive learning and other methods are used to adjust the threshold to build a fraud identification model with high accuracy and high recall rate.

Benefits of technology

It has achieved effective identification and prevention of new GOIP device frauds, timely detection of fraudsters, protection of potential victims, and strict prevention of telecommunications fraud crimes.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This invention belongs to the technical field of telecommunications fraud identification applications, and more particularly, relates to a method for identifying fraud patterns based on remote control applications and call patterns. This method, based on the characteristics of remote calls, summarizes and analyzes their behavior, constructs a reasonable fraud identification model, and thereby addresses new forms of GOIP telecommunications fraud, promptly detects fraudsters, and rigorously prevents and severely cracks down on telecommunications fraud and other illegal and criminal activities, thereby protecting potential victims.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of telecommunications fraud identification applications, and in particular relates to a method for identifying fraud patterns based on remote control applications and call patterns. Background Art

[0002] Telecom fraud refers to the criminal act of fabricating false information and setting up scams through telephone, Internet and text messages to commit remote, contactless fraud against victims, inducing victims to make payments or transfer money. The purpose of deception is usually achieved by impersonating others and counterfeiting and forging various legal guises and forms.

[0003] One of the most common new scams involves impersonating customer service representatives and making frequent calls within a short period of time. These calls resemble traditional GOIP calls, but IMEI analysis reveals that these are not GOIP device chips, but rather traditional phone models. These new GOIP calls involve two phones connected via an audio cable (similar to the internal audio cable used in traditional radios). One phone has a remote control app installed, while the other has WeChat or QQ installed.

[0004] Like traditional GOIPs, these new GOIPs, which are accessed by overseas fraud rings and conducted remotely, are highly efficient. However, compared to traditional GOIPs, these new GOIP devices are simple to set up (using two smartphones and a single audio cable), readily available for purchase, and easily deployed offline during large-scale outbreaks among groups like students. Therefore, detecting this form of telecom fraud remains a pressing technical challenge for those skilled in the art. Summary of the Invention

[0005] In response to the technical problems existing in the above-mentioned new GOIP device telecommunications fraud, the present invention proposes a method for fraud pattern recognition based on remote control applications and call patterns, which is simple to prevent, easy to operate and can effectively identify new GOIP device fraud.

[0006] In order to achieve the above-mentioned object, the technical solution adopted by the present invention is as follows: the present invention provides a method for identifying fraud patterns based on remote control applications and call patterns, comprising the following steps:

[0007] a. First, obtain the data of phone numbers that use more than two remote control dangerous apps, and filter out the IMEI data of all terminals used by the number based on the obtained number, and find the used numbers of all the obtained terminals to be merged;

[0008] b. Obtain the phone number used to remotely control dangerous apps, then filter the IMEI data of the terminal used by the obtained number and find the numbers used by all the obtained terminals to be merged;

[0009] c. Combine the number data obtained in steps a and b, remove duplicates, and sort in reverse order by the most recent use time and the IMEI number of the terminal used;

[0010] d. Obtain the relationship between the merged numbers through a recursive algorithm, group numbers with the same relationship and mark them;

[0011] e. Obtain the call record information for the number merged in step c on that day and calculate the number of calls, number of calls received / number of calls made, and number of calls / number of calls made within 60 seconds. Then, set a threshold to eliminate numbers that do not meet the fraud criteria.

[0012] f. Obtain grouping information for the remaining numbers after removal, as well as their corresponding product packages, payment methods, channels, network status, number status, and certification information, and mark the remaining numbers to see whether they match the fraud model information used by the operator;

[0013] g. Calculate call behavior indicators based on the group information in step d, such as the number of called / calling numbers, the number of calling numbers, the number of calling peers / number of calling numbers within the entire group, and retain numbers with abnormal call behavior by setting thresholds;

[0014] h. Obtain data on abnormal calls using dangerous apps for the numbers identified in step e, and obtain data on abnormal calls using dangerous apps for the numbers identified in step g. Then, perform a left-association on the numbers identified in step e and step g, and calculate various indicators that indicate the numbers meet fraudulent behavior.

[0015] i. Then, the fraud recognition pattern is processed using undersampling and oversampling, cost-sensitive learning, and probability threshold adjustment until a fraud recognition model with high accuracy and high recall is obtained;

[0016] j. Then, adjust the threshold value in each step according to the fraud identification model obtained in step i until the evaluation result meets the requirements.

[0017] Preferably, in step a, first obtain data on numbers that use more than or equal to two remotely controlled dangerous apps, and then filter out all terminal IMEI data used by the number in the past six months based on the obtained number.

[0018] Preferably, in step b, a number that uses remote control of dangerous APPs and has a traffic volume greater than 1000 bytes is obtained.

[0019] Preferably, in step b, obtain the number that uses remote control dangerous APP and has a traffic volume greater than 1000 bytes, then filter the obtained number to obtain the IMEI data of the terminal used by the number within seven days and find out the numbers used by all the obtained terminals to be merged.

[0020] Preferably, in the step h, the various indicators that meet the fraudulent behavior include whether it is a public area, whether it is a shopping area, and the lac_type type, and the number of IMEIs, the average number of IMEIs, the number of provinces of the opposite number, the number of provinces with the same opposite number, the number of marked numbers, the number of black and gray numbers, the number of tacs, the maximum number of calls, the number of calls less than 60 seconds, the number of calls less than 30 seconds, the number of groups, and other indicators are calculated.

[0021] Compared with the prior art, the advantages and positive effects of the present invention are:

[0022] 1. The present invention provides a method for identifying fraud patterns based on remote control applications and call patterns. According to the characteristics of remote calls, the behavior is summarized and analyzed, and a reasonable fraud identification model is constructed to solve the new type of GOIP form of telecommunications fraud, detect fraudsters in a timely manner, strictly prevent and severely crack down on telecommunications fraud and other illegal and criminal activities, and protect potential victims. DETAILED DESCRIPTION

[0023] In order to more clearly understand the above-mentioned objects, features and advantages of the present invention, the present invention is further described below in conjunction with the embodiments. It should be noted that, in the absence of conflict, the embodiments of the present application and the features therein can be combined with each other.

[0024] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways than those described herein. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0025] Example 1: This example aims to provide a method for identifying remote control (homemade) telecommunications fraud.

[0026] First, obtain data on phone numbers that have used two or more dangerous remote control apps. Then, based on the obtained numbers, filter out the IMEI data of all terminals used by the number in the past six months. Then, find the used numbers of all the obtained terminals and merge them. Among them, dangerous remote control apps are provided by higher-level authorities and telecommunications operators, and are mainly determined based on the remote control apps frequently used in local scams.

[0027] Next, the system obtains phone numbers that use dangerous remote control apps and have traffic greater than 1000 bytes. The obtained numbers are then filtered for the IMEI data of terminals used by the number within seven days, and all numbers used by the obtained terminals are found and merged. The issue of traffic exceeding 1000 bytes is primarily due to the fact that many current smartphone users are elderly, who may accidentally download and then open such remote control apps, only to quickly close them. Thus, limiting traffic can avoid unnecessary number screening. In the case of the local remote control scam, scammers typically install dangerous remote control apps on specific terminals (to prevent the terminal's IMEI number from being marked. Long-term use of a terminal with a marked IMEI number will also mark the phone number, so the scammers will use a different phone). Therefore, if the number has been used on a different phone, it indicates the possibility of fraud.

[0028] Then, the two numbers to be merged are merged, and after removing duplicates, they are arranged in reverse order according to the most recent usage time and the IMEI number of the terminal used. The reverse order of the IMEI number of the terminal used is because a mobile phone number may have used multiple terminals. The IMEI numbers of the terminals used by the number are also arranged in reverse order according to the time of use.

[0029] Then, a recursive algorithm is used to obtain the relationship between the merged numbers, and numbers with the same relationship are grouped together and marked. This relationship may be a relationship that uses the same terminal. For example, number a has used 6 terminals, and these 6 terminals are used by N numbers such as b, c,...n, etc. These numbers can be classified into one category and marked directly with the number of number a. In this way, it is easy to remember that they are all numbers associated with number a.

[0030] Then, the call record information of the merged number on that day is obtained and the number of calls, number of calls / number of calls, and number of calls / number of calls within 60 seconds of the number are calculated. After setting a threshold, numbers that do not meet the fraud situation are eliminated.

[0031] Obtain the grouping information of the remaining numbers after elimination, as well as the corresponding product packages, payment methods, channels, network status, number status, certificates and other family information of the numbers, and mark the remaining numbers to see whether they match the fraud model information used by the operator. The fraud model used by the operator here refers to the fraud model currently constructed by the operator for other types of fraud, and the matching information is to see whether the number has been marked by other fraud models.

[0032] According to the previous group information, call behavior indicators are counted, including the number of called / calling times, number of calling times, number of calling parties / number of calling times, etc. in the entire group. Numbers with abnormal call behavior are retained by setting thresholds.

[0033] After setting a threshold, we remove numbers that do not meet the fraud criteria and obtain data on abnormal calls using dangerous apps. We also retain numbers with abnormal call behavior by setting a threshold and obtain data on abnormal calls using dangerous apps. We then perform a left-association on the two types of numbers and calculate various indicators that indicate the numbers meet fraud criteria. Indicators that indicate fraud include whether the number is in a public area, whether it is a shopping area, and the lac_type type. We calculate indicators such as the number of IMEIs, the average number of IMEIs, the number of provinces with the peer number, the number of provinces with the same peer number, the number of marked numbers (i.e., the number marked by other fraud models), the number of black and gray numbers, the number of TACs, the maximum number of calls, the number of calls less than 60 seconds, the number of calls less than 30 seconds, and the number of groups.

[0034] The fraud recognition pattern is then processed using undersampling and oversampling, cost-sensitive learning, and probability threshold adjustment until a fraud recognition model with high accuracy and high recall is obtained.

[0035] The final fraud identification model adjusts the threshold value in each step until the evaluation result meets the requirements.

[0036] The above description is merely a preferred embodiment of the present invention and does not constitute any other form of limitation to the present invention. Any person skilled in the art may utilize the technical contents disclosed above to change or modify them into equivalent embodiments with equivalent changes for application in other fields. However, any simple modification, equivalent change, and modification of the above embodiments made in accordance with the technical essence of the present invention without departing from the technical solution of the present invention shall still fall within the scope of protection of the technical solution of the present invention.

Claims

1. A method for identifying fraud patterns based on remote control applications and call patterns, characterized in that: The following steps are involved: a. First, obtain the data of phone numbers that use more than two remote control dangerous apps, and filter out the IMEI data of all terminals used by the number based on the obtained number, and find the used numbers of all the obtained terminals to be merged; b. Obtain the phone number used to remotely control dangerous apps, then filter the IMEI data of the terminal used by the obtained number and find the numbers used by all the obtained terminals to be merged; c. Combine the number data obtained in steps a and b, remove duplicates, and sort in reverse order by the most recent use time and the IMEI number of the terminal used; d. Obtain the relationship between the merged numbers through a recursive algorithm, group numbers with the same relationship and mark them; e. Obtain the call record information for the number merged in step c on that day and calculate the number of calls, number of calls received / number of calls made, and number of calls / number of calls made within 60 seconds. Then, set a threshold to eliminate numbers that do not meet the fraud criteria. f. Obtain grouping information for the remaining numbers after removal, as well as their corresponding product packages, payment methods, channels, network availability, number status, and ID information. Mark the remaining numbers to see whether they match the fraud model information used by the operator. g. Count the call behavior indicators based on the group information in step d, calculating the number of called / calling, number of calling, and number of calling peers / number of calling within the entire group. Set thresholds to retain numbers with abnormal call behavior. h. Obtain data on abnormal calls using dangerous apps for the numbers obtained in step e, and obtain data on abnormal calls using dangerous apps for the numbers obtained in step g. Then, perform a left-association on the numbers obtained in step e and step g, and calculate various indicators that the numbers meet the requirements for fraudulent behavior. i. Then, the fraud recognition pattern is processed using undersampling and oversampling, cost-sensitive learning, and probability threshold adjustment until a fraud recognition model with high accuracy and high recall is obtained; j. Then, adjust the threshold value in each step according to the fraud identification model obtained in step i until the evaluation result meets the requirements.

2. The method for fraud pattern recognition based on remote control applications and call patterns according to claim 1, characterized in that: In the step a, firstly, data of phone numbers using more than two remotely controlled dangerous apps are obtained, and then all terminal IMEI data used by the number in the past six months are filtered out based on the obtained number.

3. The method for fraud pattern recognition based on remote control applications and call patterns according to claim 2, characterized in that: In the step b, obtain the number of the user who uses the remote control dangerous APP and whose traffic is greater than 1000 bytes.

4. The method for fraud pattern recognition based on remote control applications and call patterns according to claim 3, characterized in that: In the step b, the obtained number is filtered to obtain the IMEI data of the terminal used by the number within seven days and the numbers used by all the obtained terminals are found out for merging.

5. The method for fraud pattern recognition based on remote control applications and call patterns according to claim 4, characterized in that: In the step h, the various indicators that meet the fraudulent behavior include whether it is a public area, whether it is a shopping area, and the lac_type type, and the number of IMEIs, the average number of IMEIs, the number of provinces of the opposite number, the number of provinces with the same opposite number, the number of marked numbers, the number of black and gray numbers, the number of TACs, the maximum number of calls, the number of calls less than 60 seconds, the number of calls less than 30 seconds, and the number of groups are calculated.

Citation Information

Patent Citations

  • Detection method for parallel-used-card proof based on time and geographic location collisions

    CN102256255A

  • Phone number fraud detection method based on space-time network and graph algorithm

    CN115278687A