A method for extracting case-related information from an Internet crime database
Through multi-module processing, the problem of information extraction difficulties caused by database complexity in Internet crime cases has been solved, and rapid and effective information integration and display have been achieved, thereby improving investigative efficiency.
Patent Information
- Application Number
- CN202310231538.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-10
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2043-03-10
AI Technical Summary
The databases involved in Internet crime cases are large and complex, with overlapping and conflicting data content, making it impossible to effectively extract and identify the information involved. This leads to a prominent contradiction between the rapid commission of crimes by criminal gangs and delayed data processing.
It uses a case-related data meaning matching module, a case-related data statistics module, a team type inference module, and a case-related information integration, extraction, and display module to automatically extract and display case-related information through data feature matching, Manhattan distance calculation, data deduplication, and key parameter labeling.
It has improved the speed of investigation and analysis of Internet crime cases, solved the problems of unclear meaning of database tables and data overlap and conflict, and achieved fast and effective information integration and display.
Smart Images

Figure CN116467361B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to a method for extracting case-related information from an Internet crime database. Background Art
[0002] In the investigation of Internet crimes, the databases involved in the case are numerous, with unclear fields, errors, and conflicts. The data content is often as large as hundreds of GB. The backup data overlaps and conflicts with the data in the running system, and there is too much invalid transaction data. For example, in Internet crimes such as online pyramid schemes, online fundraising fraud, and online gambling, the databases involved are huge, making it difficult to extract and identify effective information, and it is impossible to timely integrate the effective data of the crime type and the required information involved. In current Internet crime cases, criminals often commit crimes in just a few months. There is a huge contradiction between the continuous and rapid crimes committed by criminal gangs and the delay in processing the data involved. How to extract effective information involved in the huge database has become an urgent problem to be solved.
[0003] In response to the above problems, we provide a method for extracting case information from an Internet crime database to solve the above problems. Summary of the Invention
[0004] The purpose of the present invention is to provide a method for extracting case-related information from an Internet crime database to solve the problems raised in the above background technology.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A method for extracting case-related information from an Internet crime case database includes a case-related type data meaning matching module, a case-related type data statistics module, a team type inference module, and a case-related information integration, extraction, and display module;
[0007] The case-related data meaning matching module is used to match the data table field values in the case-related database with various types of citizens' personal information based on their data characteristics, including comparing the data field annotation meaning and data feature matching type to confirm whether there are any incorrect annotations;
[0008] The case type data statistics module compares the table names and comments of the corresponding tables in the case data with the table names and comments of the saved case table structures based on the data meanings such as table names and keywords, combined with the statistics and calculation results of completed cases, and calculates the Manhattan distance to identify the case type with the highest similarity;
[0009] The team type inference module includes combining the crime type screening related to the data table fields involved in the case to classify and count the basic information of personnel, funds inflow and outflow, and funds flow in the confirmed type database, and removes duplicate calculations based on the time interval of the confirmed main table and backup table;
[0010] The case-related information integration, extraction and display module includes labeling and displaying the filtered data that conforms to the pattern in the case library according to the relevant information of the criminal gang in the case and the key parameters of the crime model operation, and then sorting and displaying the count values of the number of citizens' personal information items one by one for use by the criminal investigation department. The data of completed cases will be re-uploaded to the case case library for subsequent analysis.
[0011] As a further solution of the present invention: the module for matching the meaning of the data of the case type includes matching the data time interval for the data with timestamps, performing timestamp-based comparison and confirmation on the same type of data generated in the same time interval, and retaining only one keyword that is closer to the actual data characteristics of the field based on whether there are erroneous annotations and semantic analysis.
[0012] As a further solution of the present invention: the module for matching the meaning of the data of the type involved in the case includes comparing the database field types and comments of tables with long identical substrings in the table names or tables with only difference in date strings, judging the main table and the backup table, merging the table contents, comparing and confirming the table names and table field comments, and retaining a table name that is closer to the actual table characteristics of the field based on whether there are erroneous comments and semantic analysis.
[0013] As a further solution of the present invention: the key parameters for the operation of the criminal model include the pyramid scheme profit ratio, the fundraising fraud entry fee and the team management bonus ratio.
[0014] Compared with the prior art, the present invention has the following beneficial effects: the present invention uses multiple modules to classify and count basic personnel information, fund inflow and outflow statistics, and fund transaction statistics by person, date, name, organization, and personnel relationship on the databases, data tables, fields, and data definition annotations involved in the case, infer the actual type of gang involved in the case, and integrate, extract, and display the required information involved in the case based on the needs of investigation, analysis, and prosecution of the corresponding crime. This solves the problems of the investigation of databases involved in Internet crime investigations, such as the large number of tables in the databases involved, unclear field meanings, errors, and conflicts, data content often reaching hundreds of GB, overlapping and conflicting backup data and running system data, and excessive invalid transaction data. The present invention can also comprehensively analyze the type of suspected crime by combining field names and annotations with field content, and automatically extract relevant information based on the analysis results. This can effectively improve the speed of investigation, analysis, and evidence collection in databases involved in Internet crimes such as online pyramid schemes, online fundraising fraud, and online gambling. In the current situation where criminals in Internet crimes often commit crimes in just a few months, this effectively solves the problem of criminal gangs committing crimes in a continuous and rapid manner that cannot be cracked down on. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 It is a flowchart of the method for extracting case-related information of the present invention. DETAILED DESCRIPTION
[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0017] The personal information of citizens obtained has been obtained with their consent and complies with relevant laws and policies.
[0018] The present invention discloses a method for extracting case-related information from an Internet crime database, comprising a case-related type data meaning matching module, a case-related type data statistics module, a team type inference module, and a case-related information integration, extraction, and display module;
[0019] The module for matching and correcting the meaning of case-related data includes:
[0020] The data table field values in the database involved in the case are matched with various types of citizens' personal information such as mobile phone numbers, ID numbers, bank card numbers, and third-party payment interface types based on their data characteristics. The meaning of the data field annotations and the data feature matching types are compared to confirm whether there are any incorrect annotations.
[0021] For data with timestamps, data time intervals are matched, and data of the same type generated in the same time interval are compared and confirmed based on timestamps. Based on whether there are erroneous annotations and semantic analysis, only one keyword that is closer to the actual data characteristics of the field is retained.
[0022] For tables whose names have long identical substrings or whose only difference is the date string, compare their database field types and comments, determine whether the main table is the backup table, merge the table contents, compare and confirm the table names and table field comments, and retain a table name that is closer to the actual table characteristics of the field based on whether there are erroneous comments and semantic analysis.
[0023] The case-related data statistics modules include:
[0024] Based on the meaning of data such as table names and keywords, combined with the statistics and calculation results of completed cases, the table names and comments of the corresponding tables in the case data with the same type of saved case table structure are compared one by one and the Manhattan distance is calculated to identify the case type with the highest similarity.
[0025] The team type inference module includes:
[0026] Combined with the crime type screening, the relevant fields of the data table involved in the case are used to classify and count the basic information of personnel, funds inflow and outflow, and funds transactions in the confirmed type database, and duplicate calculations are removed based on the time intervals of the confirmed main table and backup table.
[0027] The case-related information integration, extraction and display module includes:
[0028] The filtered data that meets the patterns in the case database will be labeled and displayed based on the relevant information of the criminal gangs in the case, key parameters of the criminal model operation such as the pyramid scheme profit ratio, the entry fee for fundraising fraud, the team management bonus ratio, etc., and then the count values of the number of items containing citizens' personal information will be sorted and displayed one by one for use by the criminal investigation department.
[0029] The data of completed cases will be re-uploaded to the case database for subsequent analysis.
[0030] It is obvious to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential features of the present invention. Although this specification describes the embodiments, not every embodiment contains only one technical solution. This description is for clarity only. Those skilled in the art should read the specification as a whole. The technical solutions in the various embodiments can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
Claims
1. A method for extracting case-related information from an internet crime case database, comprising a case-related data meaning matching module, a case-related data statistics module, a team type inference module, and a case-related information integration, extraction, and display module, characterized in that: The case-related data meaning matching module is used to match the data table field values in the case-related database with various types of citizens' personal information based on their data characteristics, including comparing the data field annotation meaning and data feature matching type to confirm whether there are any incorrect annotations; The case type data statistics module compares the table names and comments of the corresponding tables in the case data with the table names and comments of the same tables in the saved case table structure according to the data meaning of the table names and keywords combined with the statistics and calculation results of the completed cases, and calculates the Manhattan distance to identify the case type with the highest similarity; The team type inference module includes combining the crime type screening related to the data table fields involved in the case to classify and count the basic information of personnel, funds inflow and outflow, and funds flow in the confirmed type database, and removes duplicate calculations based on the time interval of the confirmed main table and backup table; The case-related information integration, extraction and display module includes labeling and displaying the filtered data that conforms to the pattern in the case library according to the relevant information of the criminal gang in the case and the key parameters of the crime model operation, and then sorting and displaying the count values of the number of citizens' personal information items one by one for use by the criminal investigation department. The data of completed cases will be re-uploaded to the case case library for subsequent analysis.
2. The method for extracting case-related information from an Internet crime case database according to claim 1, characterized in that: The module for matching the meaning of the data involved in the case includes matching the data time interval for the data with timestamps, comparing and confirming the same type of data generated in the same time interval based on timestamps, and retaining only one keyword that is closer to the actual data characteristics of the field based on whether there are erroneous annotations and semantic analysis.
3. The method for extracting case-related information from an Internet crime case database according to claim 1, characterized in that: The data meaning matching module for the type involved in the case includes comparing the database field types and comments of tables with long identical substrings in the table names or tables with only differences in date strings, determining the main table and the backup table, merging the table contents, comparing and confirming the table names and table field comments, and retaining a table name that is closer to the actual table characteristics of the field based on whether there are erroneous comments and semantic analysis.
4. The method for extracting case-related information from an Internet crime case database according to claim 1, characterized in that: The key parameters for the operation of the criminal model include the pyramid scheme profit ratio, the entry fee for fundraising fraud and the team management bonus ratio.
Citation Information
Patent Citations
Five-fold de-duplicate pyramid selling data analysis method
CN109191334A
Method for counting multiple criminal cases
CN110175790A