Method and device for multi-channel comprehensive anti-fraud intervention, electronic equipment and storage medium

By using a multi-channel integrated anti-fraud intervention device, deep packet inspection and machine learning technologies are employed to classify and categorize fraud warning information and make automatic decisions. Various anti-fraud intervention methods are implemented, which solves the problem of frequent and diverse telecommunications network fraud and achieves efficient anti-fraud warning coverage and low-cost anti-fraud effect.

CN116320160BActive Publication Date: 2026-02-10SHANDONG BRANCH OF BEST TONE INFORMATION
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211664491.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2026-02-10
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

In the current technology, telecommunications network fraud crimes are frequent and diverse, and a single anti-fraud method is difficult to effectively deal with them. It is necessary to classify and categorize fraud warning information and implement the most suitable comprehensive anti-fraud intervention method.

Method used

A multi-channel integrated anti-fraud intervention method is adopted. Through a multi-channel integrated anti-fraud intervention device, including a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision-making module, and a multi-channel intervention execution module, deep packet inspection, machine learning, and big data analysis are used to automatically decide and implement various anti-fraud intervention methods, such as sending messages, intelligent outbound calls, manual outbound calls, call blocking, and dispatching police to the scene.

Benefits of technology

It enables efficient classification and automated processing of fraud warning information, improves the coverage and processing efficiency of anti-fraud warnings, reduces the investment of anti-fraud police resources, and has clear application scenarios and broad social value.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116320160B_ABST
    Figure CN116320160B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of multi-channel comprehensive anti-fraud intervention method, device, electronic equipment and storage medium.The multi-channel comprehensive anti-fraud intervention method includes steps:S1, multi-source early warning information research and judge module collects communication original data and carries out extraction, analysis, obtains fraud early warning information;S2, external early warning data receiving module receives the early warning data of system external cooperation party;S3, intervention method decision module receives the early warning data output by multi-source early warning information research and judge module, external early warning data receiving module, and the early warning intervention execution result feedback of the same piece of early warning data in the feedback of multi-channel intervention execution module, decision needs to be used Intervention mode;S4, multi-channel intervention execution module receives the early warning data and intervention mode decision result of intervention method decision module, and according to decision result, execute early warning intervention.The multi-channel comprehensive anti-fraud intervention method according to the present application can automatically decide to implement the most suitable one or use multiple anti-fraud intervention methods.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communications, and more specifically, to a method, apparatus, electronic device, and storage medium for comprehensive anti-fraud intervention using a multi-channel combination. Background Technology

[0002] With the continuous development of the internet and mobile internet, and the continuous improvement of communication technology, telecommunications and online fraud crimes are on the rise. Criminals meticulously design scams through the internet, text messages, and telephones, using methods such as fabricating false information, impersonating others, impersonating government websites, and defrauding the public through gambling / investment / friendship scams. Telecommunications and online fraud is characterized by remote execution, covert behavior, and wide coverage. The amount of fraud warning information obtained from various data channels is enormous, and objectively, there is a certain probability of accuracy, making it difficult to fully dedicate anti-fraud police resources to manually analyze and process each case around the clock. Therefore, using different intervention methods for different types of fraud information can effectively improve the coverage of anti-fraud warnings, enhance the efficiency of anti-fraud warning data processing, and significantly save anti-fraud police resources.

[0003] Chinese patent CN113067947A, "An Anti-Fraud Solution and System Based on Intelligent Outbound Calls," mainly revolves around using AI voice machines to make outbound calls with different phrases to dissuade people from fraud. It is a single-channel anti-fraud system that reaches the public.

[0004] However, in practical applications, fraud situations are complex and diverse, and a single anti-fraud method cannot cope with them. Therefore, it is urgent to classify and categorize fraud warning information, and then have the system automatically decide on the most suitable anti-fraud intervention method or to use a combination of multiple anti-fraud intervention methods. Summary of the Invention

[0005] The technical problem this invention aims to solve is how to classify and categorize complex and diverse fraud warning information, thereby enabling the system to automatically decide on and implement the most suitable anti-fraud intervention method or to comprehensively utilize multiple anti-fraud intervention methods.

[0006] To address the aforementioned technical problems, according to one aspect of the present invention, a multi-channel integrated anti-fraud intervention method is provided. This method is implemented based on a multi-channel integrated anti-fraud intervention device, which includes: a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision module, and a multi-channel intervention execution module, wherein each module is connected via an API interface. The multi-channel integrated anti-fraud intervention method includes the following steps: S1, the multi-source early warning information analysis module collects raw network communication data from mobile phones, landlines, and broadband internet access in the communication network and extracts application-layer data packets from the network communication using deep packet inspection technology; it analyzes the extracted application-layer data packets using big data and machine learning technologies, performing big data analysis and judgment on behaviors including but not limited to APP downloads, internet access behavior, call behavior, and money transfer behavior, obtaining near real-time fraud early warning information including downloading fraudulent APPs, visiting fraudulent websites, answering fraudulent calls, and transferring money to fraudulent accounts, and marking the fraud type and fraud risk level; S2, the external early warning data receiving module receives data from external partners of the system. The system analyzes and judges early warning data using its own big data analysis model; S3, the intervention method decision module has an intervention decision model with a supervised learning algorithm based on machine learning. The intervention method decision module receives early warning data output from the multi-source early warning information judgment module and the external early warning data receiving module through the API interface, as well as the early warning intervention execution results feedback from the same early warning data in the multi-channel intervention execution module, and decides on the intervention method to be used next; S4, the multi-channel intervention execution module has sub-modules with corresponding intervention methods. The multi-channel intervention execution module receives early warning data and intervention method decision results from the intervention method decision module through the API interface, and executes early warning intervention in each intervention sub-module according to the decision results.

[0007] According to an embodiment of the present invention, the multi-channel intervention execution module can feed back the early warning intervention execution result to the intervention method decision module through the API interface. If the previous intervention method has no effect or the effect is not good, the intervention method decision module determines whether it is necessary to intervene again and the intervention method for the second intervention. If so, the intervention method decision module will select a more suitable intervention again and send it to the multi-channel intervention execution module for intervention execution again.

[0008] According to an embodiment of the present invention, the multi-channel intervention execution module may also have a frequency control function for intervention execution, which is used to prevent the system from repeatedly notifying or making outbound calls to the same phone number, thereby causing harassment to the public.

[0009] According to an embodiment of the present invention, in step S3, the intervention decision model may include one or more of the following: logistic regression, support vector machine, k-nearest neighbor, Adaboost, XGBoost, and CatBoost.

[0010] According to an embodiment of the present invention, in step S3, the intervention methods may include: sending information intervention, intelligent outbound call intervention, manual outbound call intervention, call blocking intervention, and dispatching police to the door intervention.

[0011] Furthermore, the message sending intervention includes, but is not limited to, various message notification methods such as iMessage, WeChat messages, SMS, Flash Message, and 5G Message.

[0012] According to an embodiment of the present invention, the API interface may be one or more of HTTP, WebSocket, or other custom protocols based on TCP or UDP.

[0013] According to a second aspect of the present invention, a multi-channel integrated anti-fraud intervention device is provided, comprising: a multi-source early warning information analysis module, which is used to collect raw network communication data from mobile phones, landlines, and broadband internet access in a communication network and extract application layer data packets from the network communication using deep packet inspection technology; analyze the extracted application layer data packets using big data and machine learning technologies, and perform big data analysis and judgment on behaviors including but not limited to APP downloads, internet access behavior, call behavior, and money transfer behavior to obtain near real-time fraud early warning information including downloading fraudulent APPs, visiting fraudulent websites, answering fraudulent calls, and transferring money to fraudulent accounts, and mark the fraud type and fraud risk level; and an external early warning data receiving module, which receives external early warning data. The system has several modules: a warning data receiving module, an intervention method decision module, and a multi-channel intervention execution module. The first module receives warning data from external partners using their proprietary big data analytics models. The second module receives warning data from multiple sources (the warning information analysis module, the external warning data receiving module, and the intervention execution results from the same warning data in the multi-channel intervention execution module via an API interface, and determines the next intervention method to be used. The third module receives warning data and intervention method decision results from the intervention method decision module via an API interface, and executes warning interventions in each intervention sub-module according to the decision results. The system comprises a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision-making module, and a multi-channel intervention execution module. These modules are connected via an API interface. The multi-channel intervention execution module feeds back the early warning intervention execution results to the intervention method decision-making module via the API interface. If the previous intervention method is ineffective or has poor results, the intervention method decision-making module determines whether further intervention is needed and what intervention method to use. If so, the intervention method decision-making module will select a more suitable intervention and send it back to the multi-channel intervention execution module for further intervention execution.

[0014] According to a third aspect of the present invention, an electronic device is provided, comprising: a memory, a processor, and a multi-channel integrated anti-fraud intervention program stored in the memory and executable on the processor, wherein the multi-channel integrated anti-fraud intervention program, when executed by the processor, implements the steps of the multi-channel integrated anti-fraud intervention method described above.

[0015] According to a fourth aspect of the present invention, a computer storage medium is provided, wherein a multi-channel integrated anti-fraud intervention program is stored on the computer storage medium, and when the multi-channel integrated anti-fraud intervention program is executed by a processor, it implements the steps of the multi-channel integrated anti-fraud intervention method described above.

[0016] Compared with the prior art, the technical solution provided by the embodiments of the present invention can achieve at least the following beneficial effects:

[0017] This invention utilizes a multi-channel intervention module that can automatically determine the optimal intervention method for early warning data through machine learning classification models or rule engines. Multiple early warning intervention methods can be used simultaneously or in combination, achieving a better anti-fraud early warning effect compared to using a single intervention method.

[0018] This invention integrates various intervention methods, each with its own characteristics, and fully utilizes the features of these methods to expand the scope and enhance the effectiveness of early warning interventions. For example, information intervention can be sent via various message types such as flash messages, SMS, and 5G messages. Flash messages have a forced pop-up function, ensuring that the user sees the message while using their mobile phone; SMS is low-cost and suitable for sending intervention reminders in bulk; 5G messages have rich multimedia attributes, enhancing the intervention effect through images and videos. Intelligent outbound calling intervention allows for multi-round dialogues with the victim, automatically records the details of fraud, and operates 24 / 7; manual outbound calling offers the greatest flexibility, allowing for adaptable responses to various emergencies; and dispatching police officers to the victim's home is the most direct intervention method, providing direct contact with the victim.

[0019] This technical solution can organically integrate the characteristics of various intervention methods, intelligently select the better intervention method, and use different intervention methods multiple times to improve the anti-fraud intervention effect.

[0020] This invention can automatically decide and implement the most suitable anti-fraud intervention method or combine multiple anti-fraud intervention methods. When a previous intervention method is ineffective, it automatically adjusts and upgrades to a new one. For example, for warnings of low fraud risk levels, anti-fraud intervention can be carried out through message notifications; for warnings of medium to high fraud risk levels, it can be carried out through telephone communication; and for warnings of high fraud risk levels where multiple attempts to contact the perpetrator have failed, it can be carried out by directly dispatching police to the site. Most fraud warnings can be processed automatically, effectively increasing the coverage of anti-fraud warnings, improving the efficiency of anti-fraud warning data processing, achieving high-quality warning intervention results with minimal investment, and ultimately achieving the goal of efficient anti-fraud. It has clear application scenarios and broad social value. Attached Figure Description

[0021] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings of the embodiments will be briefly described below. Obviously, the drawings described below only relate to some embodiments of the present invention and are not intended to limit the present invention.

[0022] Figure 1This is a flowchart illustrating a multi-channel integrated anti-fraud intervention method according to an embodiment of the present invention. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the described embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0024] Unless otherwise defined, the technical or scientific terms used herein shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains. The terms “first,” “second,” and similar terms used in the specification and claims of this patent application do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, the terms “an” or “a” and similar terms do not indicate a limitation of quantity, but rather indicate the presence of at least one.

[0025] Figure 1 This is a flowchart illustrating a multi-channel integrated anti-fraud intervention method according to an embodiment of the present invention.

[0026] like Figure 1 As shown, the multi-channel integrated anti-fraud intervention method is implemented based on a multi-channel integrated anti-fraud intervention device, which includes: a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision-making module, and a multi-channel intervention execution module. These modules are connected via an API interface.

[0027] The multi-channel comprehensive anti-fraud intervention method includes the following steps:

[0028] S1, the multi-source early warning information analysis module collects raw network communication data from mobile phones, landlines, and broadband internet access in the communication network and uses deep packet inspection technology to extract application layer data packets in the network communication. It uses big data and machine learning technology to analyze the extracted application layer data packets, and performs big data analysis and judgment on behaviors including but not limited to APP downloads, internet access behavior, call behavior, and money transfer behavior to obtain near real-time fraud early warning information, including downloading fraudulent APPs, visiting fraudulent websites, answering fraudulent calls, and transferring money to fraudulent accounts, and marks the fraud type and fraud risk level.

[0029] S2, External Early Warning Data Receiving Module: Receives early warning data obtained by external partners of the system through their own big data analysis models.

[0030] S3, the intervention method decision module has an intervention decision model with a supervised learning algorithm for machine learning. The intervention method decision module receives early warning data output by the multi-source early warning information analysis module and the external early warning data receiving module through the API interface, as well as the early warning intervention execution result feedback of the same early warning data from the multi-channel intervention execution module, and decides on the intervention method to be used next.

[0031] S4. The multi-channel intervention execution module has sub-modules corresponding to the intervention methods. The multi-channel intervention execution module receives the early warning data and intervention method decision results from the intervention method decision module through the API interface, and executes the early warning intervention in each intervention sub-module according to the decision results.

[0032] This invention utilizes a multi-channel intervention module that can automatically determine the optimal intervention method for early warning data through machine learning classification models or rule engines. Multiple early warning intervention methods can be used simultaneously or in combination, achieving a better anti-fraud early warning effect compared to using a single intervention method.

[0033] According to one or more embodiments of the present invention, the multi-channel intervention execution module feeds back the early warning intervention execution result to the intervention method decision module through the API interface. If the previous intervention method has no effect or the effect is not good, the intervention method decision module determines whether it is necessary to intervene again and the intervention method for the second intervention. If so, the intervention method decision module will select a more suitable intervention again and send it to the multi-channel intervention execution module for intervention execution again.

[0034] This technical solution can organically integrate the characteristics of various intervention methods, intelligently select the better intervention method, and use different intervention methods multiple times to improve the anti-fraud intervention effect.

[0035] According to one or more embodiments of the present invention, the multi-channel intervention execution module also has a frequency control function for intervention execution, which is used to prevent the system from repeatedly notifying or making outbound calls to the same phone number, thereby causing harassment to the public.

[0036] According to one or more embodiments of the present invention, in step S3, the intervention decision model includes one or more of the following: logistic regression, support vector machine, k-nearest neighbor, Adaboost, XGBoost, and CatBoost.

[0037] According to one or more embodiments of the present invention, in step S3, the intervention methods include: sending information intervention, intelligent outbound call intervention, manual outbound call intervention, call blocking intervention, and dispatching police to the door.

[0038] Furthermore, the message sending intervention includes, but is not limited to, various message notification methods such as iMessage, WeChat messages, SMS, Flash Message, and 5G Message.

[0039] This invention integrates various intervention methods, each with its own characteristics, and fully utilizes the features of these methods to expand the scope and enhance the effectiveness of early warning interventions. For example, information intervention can be sent via various message types such as flash messages, SMS, and 5G messages. Flash messages have a forced pop-up function, ensuring that the user sees the message while using their mobile phone; SMS is low-cost and suitable for sending intervention reminders in bulk; 5G messages have rich multimedia attributes, enhancing the intervention effect through images and videos. Intelligent outbound calling intervention allows for multi-round dialogues with the victim, automatically records the details of fraud, and operates 24 / 7; manual outbound calling offers the greatest flexibility, allowing for adaptable responses to various emergencies; and dispatching police officers to the victim's home is the most direct intervention method, providing direct contact with the victim.

[0040] According to one or more embodiments of the present invention, the API interface is one or more of HTTP, WebSocket, or other custom protocols based on TCP or UDP.

[0041] According to a second aspect of the present invention, a multi-channel integrated anti-fraud intervention device is provided, comprising: a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision-making module, and a multi-channel intervention execution module. The modules are connected to each other via an API interface.

[0042] The multi-source early warning information analysis module is used to collect raw network communication data from mobile phones, landlines, and broadband internet access in the communication network and use deep packet inspection technology to extract application layer data packets in the network communication. It uses big data and machine learning technology to analyze the extracted application layer data packets, and performs big data analysis and judgment on behaviors including but not limited to APP downloads, internet access behavior, call behavior, and money transfer behavior to obtain near real-time fraud early warning information, including downloading fraudulent APPs, visiting fraudulent websites, answering fraudulent calls, and transferring money to fraudulent accounts, and marks the fraud type and fraud risk level.

[0043] The external early warning data receiving module is used to receive early warning data obtained by external partners of the system through their own big data analysis models.

[0044] The intervention method decision module has an intervention decision model based on a supervised learning algorithm for machine learning. The intervention method decision module is used to receive early warning data output by the multi-source early warning information analysis module and the external early warning data receiving module through the API interface, as well as the early warning intervention execution results feedback of the same early warning data from the multi-channel intervention execution module, and to decide on the intervention method to be used next time.

[0045] The multi-channel intervention execution module is used to receive early warning data and intervention method decision results from the intervention method decision module through the API interface, and execute early warning interventions in each intervention sub-module according to the decision results.

[0046] The multi-channel intervention execution module feeds back the early warning intervention execution results to the intervention method decision module through the API interface. If the previous intervention method has no effect or the effect is not good, the intervention method decision module determines whether further intervention is needed and what kind of intervention to use. If so, the intervention method decision module will select a more suitable intervention and send it back to the multi-channel intervention execution module for intervention execution.

[0047] In embodiments of the present invention, the multi-source early warning information analysis module collects raw network communication data from mobile phones, landlines, and broadband internet access in the communication network and uses deep packet inspection technology to extract application layer data packets in the network communication. Through big data and artificial intelligence algorithms, it is determined that a mobile phone is receiving a call suspected of being of medium threat level. The multi-source early warning information analysis module immediately generates early warning data (including fields such as alarm time, location, phone number, fraud type, fraud risk level, and early warning data source) and notifies the intervention method decision module through an API interface.

[0048] In this embodiment of the invention, the intervention method decision module is implemented through a machine learning model. The intervention method decision module establishes feature engineering based on early warning data and feedback data from multi-channel intervention execution modules. It constructs dozens of features as X for model training, including early warning data occurrence time features (year, month, day, hour, weekday, holiday, weekend), geographical features (province, city, district), fraud type features, fraud risk level features, fraud information source features, information sending intervention features (information type and sending result), intelligent outbound call intervention features (whether intelligent anti-fraud outbound calls are used, number of outbound calls, whether the public reports being defrauded, and the amount defrauded), manual outbound call intervention features (whether manual outbound calls are used, number of outbound calls, whether the public reports being defrauded, and the amount defrauded), call blocking intervention features (whether call blocking is used, call blocking result), and police dispatch intervention features (whether police are dispatched to intervene, whether the public reports being defrauded, and the amount defrauded). Various intervention methods are used as Y for the model, and the intervention decision model is trained using a supervised learning algorithm. After the model training is completed, the intervention method decision module automatically analyzes the warning data received from the API interface to determine the next intervention method to be taken and notifies the multi-channel intervention execution module to execute the warning intervention through the interface.

[0049] When the intelligent intervention decision-making module uses the intervention decision model to predict the first intervention method based on the received early warning data, since the system has not yet sent intervention information or made outbound intervention calls for this early warning data, this module only uses the early warning information as the feature to generate the model; all other features are empty. The intervention decision model calculates the features and predicts which intervention method is needed or not. After the early warning data has undergone its first intervention, the system calculates the features composed of the early warning data and the intervention result and predicts which subsequent intervention method is needed or not. Both the early warning data and the intervention method calculated by this module are sent to the multi-channel intervention execution module via API calls.

[0050] After receiving the early warning data and the determined intervention method, the multi-channel intervention execution module executes the specified intervention. Different intervention methods generate their own feedback results. Both the early warning data and feedback results are sent back to the intelligent intervention method decision module via API calls for further judgment on the next necessary intervention method, until the model determines that the data no longer requires further intervention. The frequency control function allows for frequency control of early warning intervention actions for a specific victim, preventing the system from repeatedly notifying or calling the same phone number at high frequencies, thus avoiding harassment.

[0051] This invention can automatically decide and implement the most suitable anti-fraud intervention method or combine multiple anti-fraud intervention methods. When a previous intervention method is ineffective, it automatically adjusts and upgrades to a new one. For example, for warnings of low fraud risk levels, anti-fraud intervention can be carried out through message notifications; for warnings of medium to high fraud risk levels, it can be carried out through telephone communication; and for warnings of high fraud risk levels where multiple attempts to contact the perpetrator have failed, it can be carried out by directly dispatching police to the site. Most fraud warnings can be processed automatically, effectively increasing the coverage of anti-fraud warnings, improving the efficiency of anti-fraud warning data processing, achieving high-quality warning intervention results with minimal investment, and ultimately achieving the goal of efficient anti-fraud. It has clear application scenarios and broad social value.

[0052] According to another aspect of the present invention, a device for multi-channel integrated anti-fraud intervention is provided, comprising: a memory, a processor, and a multi-channel integrated anti-fraud intervention program stored in the memory and executable on the processor, wherein the multi-channel integrated anti-fraud intervention program, when executed by the processor, implements the steps of the above-described multi-channel integrated anti-fraud intervention method.

[0053] The present invention also provides a computer storage medium.

[0054] The computer storage medium stores a multi-channel integrated anti-fraud intervention program, which, when executed by the processor, implements the steps of the aforementioned multi-channel integrated anti-fraud intervention method.

[0055] The method implemented when the multi-channel integrated anti-fraud intervention program running on the processor is executed can be referred to in various embodiments of the multi-channel integrated anti-fraud intervention method of the present invention, and will not be repeated here.

[0056] The present invention also provides a computer program product.

[0057] The computer program product of the present invention includes a multi-channel integrated anti-fraud intervention program, which, when executed by a processor, implements the steps of the multi-channel integrated anti-fraud intervention method as described above.

[0058] The method implemented when the multi-channel integrated anti-fraud intervention program running on the processor is executed can be referred to in various embodiments of the multi-channel integrated anti-fraud intervention method of the present invention, and will not be repeated here.

[0059] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0060] The above description is merely an exemplary embodiment of the present invention and is not intended to limit the scope of protection of the present invention, which is determined by the appended claims.

Claims

1. A method for multi-channel integrated anti-fraud intervention, the method being implemented based on a device for multi-channel integrated anti-fraud intervention, the device comprising: The system comprises a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision-making module, and a multi-channel intervention execution module. These modules are interconnected via API interfaces. The multi-channel integrated anti-fraud intervention method includes the following steps: S1. The multi-source early warning information analysis module collects raw network communication data from mobile phones, landlines, and broadband internet access in the communication network and uses deep packet inspection technology to extract application layer data packets in the network communication; it uses big data and machine learning technology to analyze the extracted application layer data packets, and performs big data analysis and judgment on behaviors including APP downloads, internet access behavior, call behavior, and money transfer behavior to obtain near real-time fraud early warning information including downloading fraudulent APPs, visiting fraudulent websites, answering fraudulent calls, and transferring money to fraudulent accounts, and marks the fraud type and fraud risk level; S2. The external early warning data receiving module receives early warning data obtained by external partners of the system through their own big data analysis models. S3. The intervention method decision module has an intervention decision model based on a supervised learning algorithm of machine learning. The intervention method decision module receives the early warning data output by the multi-source early warning information analysis module and the external early warning data receiving module through the API interface, as well as the early warning intervention execution result feedback of the same early warning data fed back by the multi-channel intervention execution module, and decides on the intervention method to be used next time. S4. The multi-channel intervention execution module has sub-modules corresponding to the intervention methods. The multi-channel intervention execution module receives the early warning data and intervention method decision results from the intervention method decision module through an API interface, and executes the early warning intervention in each intervention sub-module according to the decision results. The multi-channel intervention execution module feeds back the early warning intervention execution results to the intervention method decision module via an API interface. If the previous intervention method is ineffective or inefficient, the intervention method decision module determines whether further intervention is needed and, if so, the intervention method decision module will select a more suitable intervention and send it back to the multi-channel intervention execution module for execution. The multi-channel intervention execution module also has a frequency control function for intervention execution, which is used to prevent the system from repeatedly notifying or calling the same phone number, causing harassment to the public.

2. The method as described in claim 1, wherein in step S3, the intervention decision model includes: One or more of the following: logistic regression, support vector machine, k-nearest neighbor, Adaboost, XGBoost, and CatBoost.

3. The method as described in claim 1, wherein in step S3, the intervention method includes: Intervention methods include sending messages, intelligent outbound calling, manual outbound calling, call blocking, and dispatching police to the scene.

4. The method as described in claim 3, wherein the information transmission intervention includes: Multiple message notification methods including iMessage, WeChat messages, SMS, Flash Message, and 5G Message.

5. The method as described in claim 1, wherein the API interface is one or more of HTTP, WebSocket, or other custom protocols based on TCP or UDP.

6. A device for multi-channel integrated anti-fraud intervention, comprising: The multi-source early warning information analysis module is used to collect raw network communication data from mobile phones, landlines, and broadband internet access in the communication network and use deep packet inspection technology to extract application layer data packets in the network communication; it uses big data and machine learning technology to analyze the extracted application layer data packets, and performs big data analysis and judgment on behaviors including APP downloads, internet access behavior, call behavior, and money transfer behavior to obtain near real-time fraud early warning information including downloading fraudulent APPs, visiting fraudulent websites, answering fraudulent calls, and transferring money to fraudulent accounts, and marks the fraud type and fraud risk level; An external early warning data receiving module is used to receive early warning data obtained by external partners of the system through their own big data analysis models. The intervention method decision module has an intervention decision model based on a supervised learning algorithm for machine learning. The intervention method decision module is used to receive the early warning data output by the multi-source early warning information analysis module and the external early warning data receiving module through the API interface, as well as the early warning intervention execution result feedback of the same early warning data from the multi-channel intervention execution module, and to decide on the intervention method to be used next time. A multi-channel intervention execution module is used to receive early warning data and intervention method decision results from the intervention method decision module via an API interface, and execute early warning interventions in each intervention sub-module according to the decision results. The system includes a multi-source early warning information analysis module, an external early warning data receiving module, an intervention method decision-making module, and a multi-channel intervention execution module. These modules are connected via API interfaces. The multi-channel intervention execution module feeds back the early warning intervention execution results to the intervention method decision module via an API interface. If the previous intervention method is ineffective or inefficient, the intervention method decision module determines whether further intervention is needed and, if so, the intervention method decision module will select a more suitable intervention and send it back to the multi-channel intervention execution module for execution. The multi-channel intervention execution module also has a frequency control function for intervention execution, which is used to prevent the system from repeatedly notifying or calling the same phone number, causing harassment to the public.

7. An electronic device, comprising: A memory, a processor, and a multi-channel integrated anti-fraud intervention program stored in the memory and executable on the processor, wherein the multi-channel integrated anti-fraud intervention program, when executed by the processor, implements the steps of the multi-channel integrated anti-fraud intervention method as described in any one of claims 1 to 5.

8. A computer storage medium, wherein, The computer storage medium stores a multi-channel integrated anti-fraud intervention program, which, when executed by a processor, implements the steps of the multi-channel integrated anti-fraud intervention method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Anti-fraud solution method and system based on intelligent outbound

    CN113067947A

  • Communication fraud prevention system

    CN110381219A

  • Intelligent anti-fraud method, system and device based on decision engine and medium

    CN114519588A