A method for identifying a GOIP scam call
By using machine learning and mobile internet log data analysis, combined with the characteristics of GOIP fraud scenarios, the system identifies fraudulent numbers associated with new and simplified GOIP devices, solving the identification challenge and achieving efficient identification and crackdown on GOIP fraudulent calls.
Patent Information
- Application Number
- CN202211631153.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-19
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2042-12-19
AI Technical Summary
Existing identification technologies are insufficient to effectively identify fraudulent calls made by new, simplified GOIP devices, especially due to their high degree of concealment and call characteristics similar to those of normal users, which increases the difficulty of identification.
By employing machine learning algorithms combined with mobile internet log DPI data, and by identifying the calling behavior of fraudulent numbers and the usage characteristics of remote control software, combined with GOIP fraud scenario characteristics, the DTW algorithm is used to calculate the similarity of number trajectories, thereby identifying the numbers of fraudulent mobile phone A and mobile phone B.
It has achieved accurate identification of GOIP fraudulent calls, improved the efficiency and accuracy of identification, and can effectively combat GOIP fraud activities.
Smart Images

Figure CN116208961B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication security, in particular to a method for identifying GOIP fraud phone. BACKGROUND
[0002] As a kind of virtual dialing equipment, GOIP equipment has recently become a new type of fraud tool widely used by fraudsters, which supports mobile phone card access, can convert traditional telephone signal into network signal, and can operate hundreds of mobile phone SIM cards simultaneously with a device, can remotely control the SIM card and GOIP equipment in different places to make calls, send and receive messages, realize the separation of SIM card, and achieve the purpose of hiding identity and evading attack. Due to the high-pressure situation of domestic crackdown on communication network fraud, the channel of GOIP equipment is strengthened, and traditional GOIP is not easy to buy, and traditional GOIP has the characteristics of large equipment size and high consistency of mobile phone number track. Based on the behavior analysis of suspicious numbers to determine the criminal facts, the relevant personnel position is determined by positioning equipment such as base station or MR latitude and longitude, equipment identification code (such as IMEI code of mobile phone) or SIM card to implement arrest.
[0003] The relevant organization starts to use a new fraud-related device, which is a simple GOIP composed of two mobile phones and an audio connection line. The relevant organization remotely controls mobile phone A to dial the victim's phone and uses mobile phone B to play voice through the audio line to transmit voice to mobile phone A and the victim to make a call.
[0004] The difference between this device and traditional GOIP is that it has less imei replacement, avoids existing black IMEI / TAC early warning methods, and the call characteristics are similar to normal users. The device is easy to network, has high concealment, and increases the difficulty for mobile communication security maintenance personnel to identify fraud. SUMMARY
[0005] In view of the shortcomings of the prior art, the present application provides a method for identifying GOIP fraud phone. The present application can meet the automatic retrieval and identification of massive call data, combined with remote control software flow monitoring, ensure the accuracy of identification, and effectively crack GOIP equipment fraud.
[0006] The technical scheme of the present application is: a method for identifying GOIP fraud phone, the relevant organization remotely controls mobile phone A to dial the victim's phone, and uses mobile phone B to play voice through the audio line to transmit voice to mobile phone A and the victim to make a call, which specifically includes the following steps:
[0007] S1), modeling based on machine learning algorithm, and training the model according to the characteristics of number fraud, using the historical captured GOIP numbers as samples, to obtain the trained machine learning model;
[0008] S2), by inputting new numbers and signaling behavior data into the trained machine learning model, and then outputting suspected mobile phone A's fraud numbers;
[0009] S3), based on the domain name features in the mobile Internet log DPI data, identify the numbers of mobile phone A using remote control software to further screen multiple suspected mobile phone A's fraud numbers;
[0010] S4), according to the networking characteristics of GOIP, within the time interval of GOIP implementing fraud, the mobile phone A's fraud numbers will have both fraud call behavior characteristics and the characteristics of using remote control software;
[0011] S5), the fraud call behavior characteristics and the characteristics of using remote control software are fused and matched to analyze the numbers that exist in the network at the same time as the two types of characteristics on the same day as the mobile phone A's fraud numbers in GOIP;
[0012] S6), based on the domain name features in the mobile Internet log DPI data, identify the numbers using network voice call software as suspected mobile phone B's numbers;
[0013] S7), according to the characteristics of different GOIP fraud scenarios, identify different types of GOIP fraud mobile phone A and mobile phone B numbers, and determine the number of fraud number B according to the similarity of the trajectory of mobile phone A and mobile phone B numbers.
[0014] As preferred, in step S1), the selected machine learning algorithm is LightGBM.
[0015] As preferred, in step S2), the signaling behavior data includes number, time and latitude and longitude information.
[0016] As preferred, in step S3), the fraud number mobile phone A will install the corresponding remote control software, according to the features of downloading and opening remote control software in the operator mobile Internet log DPI data, obtain the numbers and time information of using remote control software in the network, so as to realize further filtering and screening of multiple suspected mobile phone A's fraud numbers in step S2).
[0017] As preferred, in step S6), according to the GOIP networking characteristics, mobile phone B has VOIP call behavior during fraud, therefore, according to the features of opening VOIP software for voice call in the mobile Internet log DPI data, obtain the numbers and time information of using VOIP software for voice call, which are suspected fraud mobile phone B's numbers.
[0018] As preferred, in step S7), the GOIP fraud scenarios are divided into fixed type fraud and vehicle type fraud;
[0019] The fixed type fraud refers to that the fraud mobile phone A and the fraud mobile phone B perform fraud in a fixed place without movement.
[0020] The vehicle-mounted type fraud refers to that the fraud mobile phone A and the fraud mobile phone B perform fraud in a constantly moving vehicle, which has mobility.
[0021] Preferably, in step S7), for the fixed type fraud, the following characteristics are adopted:
[0022] 1) the mobile phone A has the characteristics of fraud call behavior and remote control software use;
[0023] 2) the mobile phone B has the characteristic of network voice call;
[0024] 3) the start and end time intervals of the above characteristics 1) and 2) are consistent;
[0025] 4) the number of base stations appearing on the same day for the mobile phone A and the mobile phone B is less than or equal to 5;
[0026] 5) the base stations appearing on the same day for the mobile phone A and the mobile phone B are coincident or adjacent;
[0027] According to the above characteristics of the fixed type fraud scene, the numbers of the GOIP-related fraud mobile phone A and the mobile phone B are identified.
[0028] Preferably, in step S7), for the vehicle-mounted type fraud scene, the following characteristics are adopted:
[0029] 1) the mobile phone A has the characteristics of fraud call behavior and remote control software use;
[0030] 2) the mobile phone B has the characteristic of network voice call;
[0031] 3) the start and end time intervals of the above characteristics 1) and 2) are consistent;
[0032] 4) the number of base stations appearing on the same day for the mobile phone A and the mobile phone B is greater than 5;
[0033] 5) the coincidence degree of the base stations appearing on the same day for the mobile phone A and the mobile phone B is high, and the trajectory similarity is high;
[0034] According to the above characteristics of the vehicle-mounted type fraud scene, the numbers of the GOIP-related fraud mobile phone A and the mobile phone B are identified.
[0035] Preferably, in step S7), the DTW algorithm is used to calculate the trajectory similarity of the fraud mobile phone A and the fraud mobile phone B, and the calculation is as follows:
[0036] S71), obtain signaling data of the fraud-related mobile phone A and B according to the operator signaling data, including time, number, base station latitude and longitude position, so as to obtain trajectory information of the fraud-related mobile phone A and B;
[0037] S72), for the fraud-related mobile phone A and B, calculate the distance between the mobile phone A and B at the corresponding time point according to the latitude and longitude information of the mobile phone A and B at the corresponding time point; the smaller the distance between the mobile phone A and B, the higher the similarity of the two.
[0038] The beneficial effects of the present application are:
[0039] 1, the present application identifies the suspected mobile phone A number by the model, then further screens according to whether it uses remote control software; and determines the fraud-related number of mobile phone A according to the two characteristics of having fraud call behavior characteristics and using remote control software at the same time;
[0040] 2, the present application uses the number of network voice call software as the suspected mobile phone B number, then identifies the numbers of different types of GOIP fraud-related mobile phone A and mobile phone B according to the characteristics of fraud scene, and determines the number of fraud-related number B according to the trajectory similarity of the numbers of mobile phone A and mobile phone B. BRIEF DESCRIPTION OF DRAWINGS
[0041] Figure 1 The flow framework diagram of GOIP fraud in the embodiment of the present application;
[0042] Figure 2 The similarity curve of the trajectory of mobile phone A and the collected number B in the embodiment of the present application; DETAILED DESCRIPTION
[0043] The specific embodiments of the present application will be further described below in combination with the drawings:
[0044] As shown in the figure, the present embodiment provides a method for identifying GOIP fraud phone, the related organization calls the victim's phone through remote control mobile phone A, and uses mobile phone B to play voice through audio line voice transmission to mobile phone A and the victim to make a call, which specifically includes the following steps: Figure 1 S1), modeling based on machine learning algorithm, and training the model according to the number fraud characteristics, using the historical captured GOIP number as sample, obtaining the trained machine learning model;
[0045] S2), input new number and signaling behavior data into the trained machine learning model, then output the suspected fraud-related number of mobile phone A;
[0046]
[0047] S3), identify the number of mobile phone A using remote control software based on domain name features in mobile Internet log DPI data, to further filter suspected mobile phone A's fraud numbers;
[0048] S4), according to the networking characteristics of GOIP, within the time interval of GOIP fraud, the fraud number of mobile phone A will have both the characteristics of fraud call behavior and the use of remote control software;
[0049] S5), the two characteristics of fraud call behavior and the use of remote control software are fused and matched to find out the numbers that exist in the network at the same time as the GOIP mobile phone A's fraud numbers;
[0050] S6), identify the number of using network voice call software as suspected mobile phone B's number based on domain name features in mobile Internet log DPI data;
[0051] S7), according to the characteristics of different GOIP fraud scenarios, identify different categories of GOIP fraud mobile phone A and mobile phone B numbers, and determine the fraud numbers A and B according to the similarity of the trajectories of mobile phone A and mobile phone B numbers.
[0052] As preferred in this embodiment, in step S1), the selected machine learning algorithm is LightGBM.
[0053] As preferred in this embodiment, in step S2), the signaling behavior data includes number, time and latitude and longitude information.
[0054] As preferred in this embodiment, in step S3), the fraud number of mobile phone A will install the corresponding remote control software, according to the characteristics of downloading and opening remote control software in the operator mobile Internet log DPI data, to obtain the number and time information of using remote control software in the network, so as to realize further filtering and screening of the multiple suspected mobile phone A's fraud numbers in step S2). For example, table 1 and table 2:
[0055] Table 1 download remote control software
[0056]
[0057] Table 2 open remote control software
[0058]
[0059]
[0060] As preferred in the embodiment, in step S6), according to the GOIP networking feature, the mobile phone B has the behavior of VOIP call during the fraud, therefore, according to the feature of opening VOIP software for voice call in the mobile network log DPI data, the number and time information of using VOIP software for voice call are acquired, and the number is taken as the number of the suspected fraud mobile phone B.
[0061] As shown in Table 3:
[0062]
[0063] As preferred in the embodiment, in step S7), the GOIP fraud scene is divided into fixed type fraud and vehicle type fraud;
[0064] The fixed type fraud refers to that the fraud mobile phone A and the fraud mobile phone B perform fraud in a fixed place without mobility.
[0065] The vehicle type fraud refers to that the fraud mobile phone A and the fraud mobile phone B perform fraud in a constantly moving vehicle with mobility.
[0066] As preferred, in step S7), for the fixed type fraud, it has the following features:
[0067] 1) The mobile phone A has the two features of fraud call behavior feature and using remote control software;
[0068] 2) The mobile phone B has the network voice call feature;
[0069] 3) The start and end time intervals of the above features 1) and 2) are consistent;
[0070] 4) The number of base stations appeared by the mobile phone A and the mobile phone B in the day is less than or equal to 5;
[0071] 5) The base stations appeared by the mobile phone A and the mobile phone B in the day are coincident or adjacent;
[0072] According to the above features of the fixed type fraud scene, the numbers of the GOIP fraud mobile phone A and the mobile phone B are identified.
[0073] As preferred, in step S7), for the vehicle type fraud scene, it has the following features:
[0074] 1) The mobile phone A has the fraud call behavior feature and the remote control software feature;
[0075] 2) The mobile phone B has the network voice call feature;
[0076] 3) The start and end time intervals of the above features 1) and 2) are consistent;
[0077] 4) The number of base stations appearing on the day for mobile phone A and mobile phone B is greater than 5;
[0078] 5) The coincidence degree of base stations appearing on the day for mobile phone A and mobile phone B is high, and the trajectory similarity is high;
[0079] According to the above characteristics of the vehicle-mounted type fraud scene, the numbers of the vehicle-mounted type GOIP fraud-related mobile phone A and mobile phone B are identified.
[0080] As preferred, in step S7), the DTW algorithm is used to calculate the trajectory similarity of the fraud-related mobile phone A and mobile phone B, specifically:
[0081] S71) According to the operator signaling data, the signaling data of the fraud-related mobile phone A and B is obtained, including time, number, base station longitude and latitude position, thereby obtaining the trajectory information of the fraud-related mobile phone A and B;
[0082] S72) For the fraud-related mobile phone A and B, according to the longitude and latitude information of mobile phone A and B at the corresponding time point, the distance between mobile phone A and B at the corresponding time point is calculated; the smaller the distance between mobile phone A and B, the higher the similarity of the two; as shown in the following formula: Figure 2
[0083] The above embodiments and descriptions described in the specification are only to illustrate the principles and best embodiments of the present application, and various changes and improvements can be made without departing from the spirit and scope of the present application, and these changes and improvements all fall within the scope of the claimed present application.
Claims
1. A method of identifying a GOIP scam call, characterized by: The related organization dials the victim's phone through the remote control mobile phone A, and uses the mobile phone B to play the voice through the audio line voice transmission to the mobile phone A and the victim to make a call, which specifically includes the following steps: S1), modeling based on a machine learning algorithm, while according to the characteristics of number fraud, the historical captured GOIP numbers are used as samples to train the model, and a trained machine learning model is obtained; S2), input new numbers and signaling behavior data into the trained machine learning model, and then output suspected mobile phone A involved in fraud numbers; S3), based on the domain name features in the mobile Internet log DPI data, the number of mobile phone A using remote control software is identified to further screen the suspected mobile phone A involved in fraud numbers; the mobile phone A involved in fraud numbers will install the corresponding remote control software, and according to the features of downloading and opening the remote control software in the mobile Internet log DPI data of the operator, the number and time information of the mobile phone using the remote control software in the network are obtained, thereby further filtering and screening the suspected mobile phone A involved in fraud numbers in step S2); S4), according to the networking characteristics of GOIP, the mobile phone A involved in fraud numbers will have both the characteristics of fraud call behavior and the use of remote control software within the time interval of GOIP fraud implementation; S5), the two characteristics of fraud call behavior and the use of remote control software are fused and matched to find the numbers in the network that have both characteristics on the same day as the mobile phone A involved in fraud numbers in GOIP; S6), based on the domain name features in the mobile Internet log DPI data, the number using the network voice call software is identified as the suspected mobile phone B number; according to the GOIP networking characteristics, the mobile phone B has the behavior of VOIP call during the fraud, therefore, according to the feature of opening the VOIP software for voice call in the mobile Internet log DPI data, the number and time information of the number using the VOIP software for voice call are obtained, which is the suspected mobile phone B number; S7), according to the characteristics of different GOIP fraud scenarios, the numbers of different categories of GOIP fraud mobile phone A and mobile phone B are identified, and the fraud numbers A and B are determined according to the trajectory similarity of the numbers of mobile phone A and mobile phone B; The trajectory similarity of the numbers of the fraud mobile phone A and the mobile phone B is calculated by using the DTW algorithm, specifically: S71), according to the signaling data of the operator, the signaling data of the fraud mobile phone A and B is obtained, including time, number, base station latitude and longitude position, thereby obtaining the trajectory information of the fraud mobile phone A and B; S72), for the fraud mobile phone A and B, according to the latitude and longitude information of the mobile phone A and B at the corresponding time point, the distance between the mobile phone A and B at the corresponding time point is calculated; the smaller the distance between the mobile phone A and B, the higher the similarity between them.
2. The method of claim 1, wherein the method further comprises: In step S1), the selected machine learning algorithm is LightGBM.
3. The method of claim 1, wherein the method further comprises: In step S2), the signaling behavior data includes mobile phone number, time and latitude and longitude information.
4. The method of claim 1, wherein the method further comprises: In step S7), the GOIP fraud scenarios are divided into fixed type fraud and vehicle type fraud. The fixed type fraud refers to that the fraud mobile phone A and the fraud mobile phone B perform fraud in a fixed place without movement. The vehicle-mounted type fraud refers to that the fraud mobile phone A and the fraud mobile phone B perform fraud in a constantly moving vehicle, and have mobility.
5. The method of claim 4, wherein the method further comprises: In step S7), for the fixed type fraud, the following characteristics are provided: 1) The mobile phone A has the characteristics of fraud call behavior and remote control software use; 2) The mobile phone B has the characteristic of network voice call; 3) The start and end time intervals of the above characteristics 1) and 2) are consistent; 4) The number of base stations appearing on the mobile phone A and the mobile phone B in the same day is less than or equal to 5; 5) The base stations appearing on the mobile phone A and the mobile phone B in the same day are adjacent or coincide; According to the above characteristics of the fixed type fraud scene, the numbers of the GOIP fraud mobile phone A and the mobile phone B are identified.
6. The method of claim 4, wherein the method further comprises: In step S7), for the vehicle-mounted type fraud scene, the following characteristics are provided: 1) The mobile phone A has the characteristics of fraud call behavior and remote control software use; 2) The mobile phone B has the characteristic of network voice call; 3) The start and end time intervals of the above characteristics 1) and 2) are consistent; 4) The number of base stations appearing on the mobile phone A and the mobile phone B in the same day is greater than 5; 5) The base stations appearing on the mobile phone A and the mobile phone B in the same day have high coincidence degree and high trajectory similarity; According to the above characteristics of the vehicle-mounted type fraud scene, the numbers of the vehicle-mounted type GOIP fraud mobile phone A and the mobile phone B are identified.
Citation Information
Patent Citations
Mobile GoIP equipment monitoring method and device, storage medium and electronic equipment
CN114221993A
GoIP equipment fraud identification and positioning method, system and device and storage medium
CN115208979A