Anti-fraud method based on false login detection and related device

By using the SIM card identifier of the mobile device to obtain the target mobile number and the historical account data and operator data of the mobile number to be logged in, and combining the historical account data and operator data, the fraud risk value is determined. This solves the problem of low fraud detection accuracy caused by a single data source and improves the accuracy of fraud detection results.

CN118449779BActive Publication Date: 2025-12-05CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410826355.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-25
Publication Date
2025-12-05
Estimated Expiration
2044-06-25

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively detect fraudulent activities in users' online accounts because they rely on a single data source, leading to inaccurate detection results.

Method used

The system retrieves the target mobile number and the SIM card identifier of the mobile device from the SIM card identifier retrieval platform. After receiving the target mobile number returned by the retrieval platform, it determines whether the mobile number to be logged in matches the target mobile number. If they match, the system retrieves the historical account data of the mobile number to be logged in, as well as the historical account data of both mobile numbers. Based on the historical account data and operator data, it determines the fraud risk value. If the fraud risk value is high, it determines whether to allow the mobile number to log in.

Benefits of technology

It enables efficient calculation of fraud risk values ​​by combining historical account data of the mobile phone number to be logged in, as well as historical account data and operator data of the mobile phone number to be logged in, thereby improving the accuracy of fraud detection results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118449779B_ABST
    Figure CN118449779B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a kind of anti-fraud method based on pseudonym login detection and related device.The method comprises: in response to the login request of mobile device login APP, obtain the mobile phone number to be logged in and the SIM card identification in mobile device;To number taking platform, send the number taking request carrying SIM card identification;Target mobile phone number is returned by receiving the number taking platform, judge whether the mobile phone number to be logged in is consistent with target mobile phone number, if consistent, the SIM card in mobile device is corresponding with the mobile phone number to be logged in, fraud risk is low, allow this login behavior;If not consistent, calculate fraud risk value, the method of the present embodiment, in the calculation of fraud risk value, combine the historical account data of the mobile phone number to be logged in and the respective operator data of the mobile phone number to be logged in and target mobile phone number make the calculation of fraud risk value get more comprehensive data support, and reduce the influence of the information of user on fraud detection result when data is missing or data is sparse, improve the accuracy of fraud detection result.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of anti-fraud, and in particular to an anti-fraud method based on impersonation login detection and related devices. BACKGROUND

[0002] With the wide application of online payment, electronic banking and social networks, more and more sensitive information of individuals and enterprises is stored in network accounts. Once these network accounts are logged in by criminals, the personal privacy and property safety of users may be threatened. Therefore, how to prevent and detect such fraudulent behavior is particularly important.

[0003] In the existing fraud detection methods, whether there is fraudulent behavior is largely detected by a single data source. For example, fraud detection on network accounts of financial institutions is dependent on the data of a single financial institution for judgment; or fraud detection on network accounts of telecom operators is dependent on the data of a single telecom operator for judgment.

[0004] However, in the case of a single data source, if the data is missing or sparse, it will affect the accuracy of fraud detection, resulting in inaccurate detection results. SUMMARY

[0005] The embodiments of the present application provide an anti-fraud method based on impersonation login detection and related devices to improve the accuracy of fraud detection results.

[0006] In a first aspect, the embodiments of the present application provide an anti-fraud method based on impersonation login detection, comprising:

[0007] In response to a login request of a mobile device logging into an APP, a mobile phone number to be logged in and an identifier of a SIM card in the mobile device are obtained.

[0008] A number taking platform is sent a number taking request carrying the identifier of the SIM card, and a target mobile phone number returned by the number taking platform is received.

[0009] If the mobile phone number to be logged in is inconsistent with the target mobile phone number, historical account data of the mobile phone number to be logged in and operator data of the mobile phone number to be logged in and the target mobile phone number are obtained.

[0010] According to the historical account data and the operator data, a fraud risk value of the mobile phone number to be logged in is determined, and whether to allow the mobile phone number to be logged in to log in is determined according to the fraud risk value.

[0011] In a possible implementation, the determining of the fraud risk value of the to-be-logged-in mobile phone number based on the historical account data and the operator data comprises: obtaining a fraud probability value of a fraud behavior based on the historical account data, and the greater the fraud probability value, the higher the corresponding fraud risk.

[0012] obtaining a familiar relationship probability value based on the operator data of the target mobile phone number and the to-be-logged-in mobile phone number, wherein the greater the familiar relationship probability value, the lower the corresponding fraud risk; and performing weighted summation based on a positive weight of the fraud probability value and a negative weight of the familiar relationship probability value to obtain the fraud risk value, wherein the greater the fraud risk value, the higher the fraud risk.

[0013] In a possible implementation, the obtaining of the fraud probability value of the fraud behavior based on the historical account data comprises: inputting the historical account data into a fraud behavior identification model, wherein the fraud behavior identification model is obtained based on a first data set; and the first data set comprises sample account data and a first label, and the first label is a fraud user or a normal user.

[0014] obtaining the fraud probability value of the fraud behavior output by the fraud behavior identification model.

[0015] In a possible implementation, the obtaining of the familiar relationship probability value based on the operator data of the target mobile phone number and the to-be-logged-in mobile phone number comprises: obtaining interaction data of the target mobile phone number and the to-be-logged-in mobile phone number based on the operator data.

[0016] inputting the interaction data into a familiar relationship model, wherein the familiar relationship model is obtained based on a second data set; and the second data set comprises operator data of a pair of two mobile phone numbers and a second label corresponding to the pair of two mobile phone numbers, and the second label is used to indicate whether the two mobile phone numbers are in a familiar relationship; and obtaining a familiar relationship probability value output by the familiar relationship model.

[0017] In a possible implementation, the determining of whether to allow the to-be-logged-in mobile phone number to log in based on the fraud risk value comprises: determining whether the fraud risk value exceeds a preset threshold.

[0018] If the fraud risk value does not exceed the preset threshold, the login request of the user is allowed.

[0019] If the fraud risk value exceeds the preset threshold, a face recognition verification request is fed back to the user; and in response to the face recognition verification of the user, it is determined whether the face recognition verification is passed, and if so, the login request of the user is allowed.

[0020] In a possible implementation, the obtaining the interaction data of the target mobile phone number and the mobile phone number to be logged in according to the operator data comprises: obtaining communication data of the target mobile phone number and the mobile phone number to be logged in according to the operator data, the communication data comprising at least one of the following: call behavior data, base station data, home package data or short message data.

[0021] The interaction data is determined according to the communication data of the target mobile phone number and the mobile phone number to be logged in, the interaction data comprising at least one of the following: daily call times, call frequency, call duration, call time period distribution, whether there is a master-slave card relationship, base station overlap rate or call and short message quantity proportion.

[0022] In a possible implementation, the APP is a financial APP, and the historical account data comprises at least one of the following: loan data, repayment data, past investment history data, counterparty data, recent account transaction data or transaction time distribution.

[0023] In a second aspect, an anti-fraud device based on impersonation login detection is provided, comprising: a login information obtaining module configured to obtain a mobile phone number to be logged in and an identifier of a SIM card in a mobile device in response to a login request of the mobile device logging in an APP.

[0024] A number taking module is configured to send a number taking request carrying the identifier of the SIM card to a number taking platform and receive a target mobile phone number returned by the number taking platform.

[0025] A data obtaining module is configured to obtain historical account data of the mobile phone number to be logged in and operator data of the mobile phone number to be logged in and the target mobile phone number if the mobile phone number to be logged in is inconsistent with the target mobile phone number.

[0026] A judgment module is configured to determine a fraud risk value of the mobile phone number to be logged in according to the historical account data and the operator data and determine whether to allow the mobile phone number to be logged in to log in according to the fraud risk value.

[0027] In a possible implementation, the judgment module is specifically configured to: obtain a fraud probability value of a fraud behavior according to the historical account data, and the greater the fraud probability value, the higher the corresponding fraud risk.

[0028] obtain a familiar relationship probability value according to the operator data of the target mobile phone number and the mobile phone number to be logged in, and the greater the familiar relationship probability value, the lower the corresponding fraud risk.

[0029] The fraud risk value is obtained by weighted summation according to a positive weight of the fraud probability value and a negative weight of the acquaintance relationship probability value, wherein the greater the fraud risk value is, the higher the fraud risk is.

[0030] In a possible implementation, the determining module is specifically configured to: input the historical account data into a fraud behavior identification model, the fraud behavior identification model being obtained according to a first data set; the first data set includes sample account data and a first label, and the first label is a fraud user or a normal user; and obtain a fraud probability value of fraud behavior output by the fraud behavior identification model.

[0031] In a possible implementation, the determining module is specifically configured to: obtain interaction data of the target mobile phone number and the mobile phone number to be logged in according to the operator data.

[0032] The interaction data is input into an acquaintance relationship model, the acquaintance relationship model being obtained according to a second data set; the second data set includes operator data of two mobile phone numbers in each pair and a second label corresponding to the two mobile phone numbers in each pair, and the second label is used to indicate whether the two mobile phone numbers are in an acquaintance relationship; and an acquaintance relationship probability value output by the acquaintance relationship model is obtained.

[0033] In a possible implementation, the determining module is further configured to: determine whether the fraud risk value exceeds a preset threshold.

[0034] If the fraud risk value does not exceed the preset threshold, the login request of the user is allowed.

[0035] If the fraud risk value exceeds the preset threshold, a face recognition verification request is fed back to the user; and in response to face recognition verification of the user, it is determined whether the face recognition verification is passed, and if so, the login request of the user is allowed.

[0036] In a possible implementation, the determining module is specifically configured to: obtain communication data of the target mobile phone number and the mobile phone number to be logged in according to the operator data, the communication data including at least one of the following: call behavior data, base station data, home package data or short message data.

[0037] According to the communication data of the target mobile phone number and the mobile phone number to be logged in, the interaction data is determined, the interaction data including at least one of the following: daily call times, call frequency, call duration, call time period distribution, whether there is a master-sub card relationship, base station overlap rate or call and short message quantity proportion.

[0038] In a possible implementation, the APP is a financial APP, and the historical account data includes at least one of the following: loan data, repayment data, past investment history data, counterparty data, recent account transaction data, or transaction time distribution.

[0039] In a third aspect, the embodiments of the present application provide an anti-fraud device based on impersonation login detection, comprising a memory and a processor.

[0040] The memory stores computer execution instructions.

[0041] The processor executes the computer execution instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.

[0042] In a fourth aspect, the embodiments of the present application provide a computer readable storage medium, which stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0043] In a fifth aspect, the embodiments of the present application provide a computer program product, which comprises a computer program, and the computer program is executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0044] The anti-fraud method and related device based on impersonation login detection provided by the embodiments of the present application, by responding to the login request of the mobile device logging into the APP, obtaining the to-be-logged-in mobile phone number and the identifier of the SIM card in the mobile device; sending a number taking request carrying the identifier of the SIM card to a number taking platform, after receiving the target mobile phone number corresponding to the identifier of the SIM card returned by the number taking platform, judging whether the to-be-logged-in mobile phone number is consistent with the target mobile phone number, if consistent, the SIM card in the mobile device corresponds to the to-be-logged-in mobile phone number, the fraud risk is low, and the to-be-logged-in mobile phone number is allowed to log in; if not consistent, obtaining the historical account data of the to-be-logged-in mobile phone number and the operator data of the to-be-logged-in mobile phone number and the target mobile phone number respectively; and determining the fraud risk value of the to-be-logged-in mobile phone number according to the historical account data and the operator data, and finally judging whether to allow the to-be-logged-in mobile phone number to log in according to the fraud risk value. The method of the embodiment, in the calculation of the fraud risk value, combines the historical account data of the to-be-logged-in mobile phone number and the operator data of the to-be-logged-in mobile phone number and the target mobile phone number respectively, so that the calculation of the fraud risk value is supported by more comprehensive data. And when the user's information is missing or sparse, the influence of single data source on the fraud detection result is avoided, and the accuracy of the fraud detection result is improved. BRIEF DESCRIPTION OF DRAWINGS

[0045] The accompanying drawings, which are incorporated herein and constitute part of this specification, illustrate embodiments consistent with the application and, together with the description, further serve to explain the principles of the application.

[0046] Figure 1 Scenario diagram of the anti-fraud method based on impersonation login detection provided by the present application;

[0047] Figure 2 Flowchart of the anti-fraud method based on impersonation login detection provided by the present application Figure One ;

[0048] Figure 3 Flowchart of the anti-fraud method based on impersonation login detection provided by the present application Figure Two ;

[0049] Figure 4 Flowchart of the anti-fraud method based on impersonation login detection provided by the present application Figure Three ;

[0050] Figure 5 Structure diagram of the anti-fraud device based on impersonation login detection provided by the present application;

[0051] Figure 6 Structure diagram of the anti-fraud device based on impersonation login detection provided by the present application.

[0052] The specific embodiments of the present application have been shown by the above-described drawings, and will be described in more detail hereinafter. These drawings and the written description are not intended to restrict the scope of the concept of the present application by any means, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0053] The exemplary embodiments will be described in detail herein with reference to the accompanying drawings. The following description is presented with reference to the drawings, wherein the same reference numerals are used to refer to like or similar elements throughout various drawings and illustrative embodiments of the application. The embodiments described in the following exemplary embodiments are not meant to represent all implementations consistent with the present application. Rather, they are simply examples of apparatus and methods consistent with some aspects of the present application as detailed in the appended claims.

[0054] The terms "first", "second", "third", "fourth" and the like in the description and in the claims of the present application, and above-mentioned drawings, if any, are used to distinguish between similar objects and not necessarily for describing a particular sequential or chronological order. It is to be understood that the use of the terms so construed can be interchanged, under appropriate circumstances, and that embodiments of the present application described herein can be capable of accomplishing functionalities by other embodiments with differing configurations except for those specifically described herein. Furthermore, the terms "comprise", "comprising", "including", "comprises", "include" and "includes" as well as any variation thereof are intended to cover a non-exclusive inclusion, for example, a process, method, article, or apparatus that comprises a list of steps or units can not necessarily be limited to those specifically listed but can include other steps or units not expressly listed or inherent to such process, method, article, or apparatus.

[0055] It should be noted that in the embodiments of the present application, the words "exemplary" or "for example" are used to mean example, illustration, or instance, and not "preferred" over other embodiments or designs. The terms "exemplary" or "for example" are therefore to be interpreted in the manner that is most helpful in the particular context. Thus, the use of the terms "exemplary" or "for example" in one or more instances is not to be interpreted as meaning that the particular instance is the only instance or that the particular instance is the best or the preferred instance.

[0056] First, the terms related to the present application are explained:

[0057] Application (APP): refers to a software program installed on a mobile device such as a smartphone, tablet computer, etc., used to perform specific functions or provide services. For example, a financial APP can provide financial transactions, financial management, investment, etc.

[0058] Subscriber Identity Module (SIM card): a small smart card used in mobile devices such as mobile phones, tablet computers, etc. It is mainly used to store user identity information and related data to enable mobile network operators to identify and verify user identity and provide corresponding communication services.

[0059] Number taking platform, i.e. operator number taking platform, the operator can obtain the mobile phone number corresponding to the SIM card inserted in the mobile device through the gateway number taking method.

[0060] As described in the background, detection of fraudulent behavior mostly relies on a single data source, and only according to the data of a certain institution or platform to determine whether there is fraudulent behavior. For example, when detecting network account fraud, financial institutions usually only rely on their own transaction data and user behavior data; when detecting network account fraud, telecom operators also mainly rely on their own user information and communication data.

[0061] However, single data sources often suffer from missing or sparse data, and due to the limitations of the data source, much important information may not be recorded or available. This can lead to insufficient data support for fraud detection models during training, thus affecting their detection accuracy.

[0062] Furthermore, a single data source cannot fully reflect a user's true behavior. A user's online behavior often involves multiple platforms and scenarios, while a single data source can only provide partial information. Relying solely on this data makes it difficult to accurately determine whether a user's behavior is abnormal, potentially causing them to miss some fraudulent activities.

[0063] To address the issue of low accuracy in fraud detection using a single data source, this application provides an anti-fraud method based on impersonation detection. When the mobile phone number to be logged in is inconsistent with the mobile phone number corresponding to the SIM card in the mobile device, the method combines the historical account data of the mobile phone number to be logged in with the operator data of the two mobile phone numbers to determine fraud behavior, thereby improving the accuracy of fraud detection results.

[0064] For example, Figure 1 This is a schematic diagram illustrating the architecture of the anti-fraud method based on impersonation login detection provided in this application. Figure 1 As shown in the diagram, the architecture provided in this embodiment includes a mobile device, a fraud detection server, and a carrier number retrieval platform. After a user enters login information on the mobile device, such as the mobile phone number to be logged in and a password, and clicks the login verification button, a login request is initiated to the fraud detection server. Upon receiving the login request, the fraud detection server obtains the mobile phone number to be logged in and the SIM card identifier; the fraud detection server then sends a number retrieval request to the carrier number retrieval platform, which includes the SIM card identifier. After receiving the number retrieval request, the carrier number retrieval platform obtains the target mobile phone number corresponding to the SIM card identifier according to the gateway number retrieval method and sends the target mobile phone number to the fraud detection server. Furthermore, after judging fraudulent behavior, the fraud detection server sends a permission / denial message to the mobile device to allow / deny the mobile phone number to log in.

[0065] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0066] Figure 2 A flowchart illustrating the anti-fraud method based on impersonation login detection provided in this application embodiment. Figure One The execution entity in this embodiment can be, for example, a Figure 1 The fraud detection server in this embodiment.Figure 2 The method comprises the following steps of:

[0067] S201, in response to a login request of the mobile device logging into the APP, obtaining a to-be-logged-in mobile phone number and an identifier of a SIM card in the mobile device.

[0068] Optionally, the APP can be an APP of a bank or other financial institution, or a payment APP; and the mobile device can be a mobile phone, a tablet computer or other mobile device supporting SIM card insertion.

[0069] Specifically, after the mobile device initiates the login request, in response to the login request of the mobile device logging into the APP, the to-be-logged-in mobile phone number and the identifier of the SIM card in the mobile device are obtained, wherein the to-be-logged-in mobile phone number can be input by a user on a login page.

[0070] S202, sending a number taking request carrying the identifier of the SIM card to a number taking platform, and receiving a target mobile phone number returned by the number taking platform.

[0071] Further, the fraud detection server sends a number taking request carrying the identifier of the SIM card to the number taking platform, and the number taking request is used to instruct the number taking platform to obtain a target mobile phone number corresponding to the identifier of the SIM card. When the number taking platform obtains the target mobile phone number, the target mobile phone number is sent to the fraud detection server.

[0072] S203, determining whether the to-be-logged-in mobile phone number and the target mobile phone number are consistent, if yes, performing S204, and if not, performing S205.

[0073] S204, allowing the to-be-logged-in mobile phone number to log in.

[0074] Correspondingly, after the fraud detection server receives the target mobile phone number, it is determined whether the to-be-logged-in mobile phone number and the target mobile phone number are consistent, if yes, the SIM card in the mobile device corresponds to the to-be-logged-in mobile phone number, the fraud risk is low, and the to-be-logged-in mobile phone number is allowed to log in.

[0075] S205, obtaining historical account data of the to-be-logged-in mobile phone number and operator data of the to-be-logged-in mobile phone number and the target mobile phone number respectively.

[0076] In some embodiments, the historical account data refers to various account-related data generated by the user in the process of using the APP, for example, if the APP is of a financial institution, the historical account data can be account type, account balance, historical transaction record, investment or financial management record, etc. The operator data refers to various data collected and generated by a telecommunications operator in the process of providing communication services for the user, which can indicate the communication behavior, network usage, geographic location and other information of the user.

[0077] In the embodiment, if the to-be-logged mobile phone number and the target mobile phone number are inconsistent, fraud behavior detection needs to be performed, and whether there is a fraud risk between the two mobile phone numbers is determined by combining the historical account data of the to-be-logged mobile phone number and the operator data of the to-be-logged mobile phone number and the target mobile phone number. Therefore, first, the historical account data of the to-be-logged mobile phone number and the operator data of the to-be-logged mobile phone number and the target mobile phone number are obtained.

[0078] In S206, the fraud risk value of the to-be-logged mobile phone number is determined according to the historical account data and the operator data, and whether the to-be-logged mobile phone number is allowed to log in is determined according to the fraud risk value.

[0079] Further, the fraud risk value of the to-be-logged mobile phone number is determined according to the historical account data and the operator data. The fraud risk value indicates the fraud risk between the two mobile phone numbers. Then, whether the to-be-logged mobile phone number is allowed to log in is determined according to the fraud risk value.

[0080] In some embodiments, the fraud probability value of the to-be-logged mobile phone number can be obtained according to the historical account data, where the fraud probability value ranges from 0 to 1. The greater the fraud probability value, the higher the fraud risk of the account.

[0081] Optionally, the fraud probability value can be obtained by a machine learning method. For example, in the scene of detecting fraud behavior in a financial institution, a risk assessment model is constructed, and then the fraud probability value is obtained by the risk assessment model.

[0082] Meanwhile, the acquaintance relationship probability value is obtained according to the operator data corresponding to the target mobile phone number and the to-be-logged mobile phone number, where the acquaintance relationship probability value ranges from 0 to 1. The greater the acquaintance relationship probability value, the lower the fraud risk of this login.

[0083] Optionally, the acquaintance relationship probability value can be obtained by a hard-coded rule, for example, if it is obtained from the operator data that the two mobile phone numbers are relative numbers, it is considered that the acquaintance relationship probability value of the two mobile phone numbers is 1. Alternatively, the acquaintance relationship probability value can be obtained by a machine learning method, which is not limited here in the embodiment.

[0084] Further, the fraud probability value and the acquaintance relationship probability value are weighted and summed to obtain the final fraud risk value, where the fraud risk value ranges from 0 to 1. The greater the fraud risk value, the higher the fraud risk.

[0085] It should be noted that, since the greater the fraud probability value is, the higher the corresponding fraud risk is, and the greater the acquaintance probability value is, the lower the corresponding fraud risk is, the weight corresponding to the fraud probability value is a positive weight, and the weight corresponding to the acquaintance probability value is a negative weight. Therefore, the fraud risk value is obtained by weighted summation according to the fraud probability value and the positive weight corresponding thereto, and the acquaintance probability value and the negative weight corresponding thereto.

[0086] The anti-fraud method based on impersonation login detection provided by the embodiment of the application is applied to a fraud detection server, and the fraud detection server obtains a to-be-logged mobile phone number and an identifier of a SIM card in a mobile device by responding to a login request of a mobile device logging in an APP; sends a number taking request carrying the identifier of the SIM card to a number taking platform, judges whether the to-be-logged mobile phone number is consistent with a target mobile phone number corresponding to the identifier of the SIM card after receiving the target mobile phone number returned by the number taking platform, and if yes, the SIM card in the mobile device corresponds to the to-be-logged mobile phone number, and the fraud risk is low, and then the to-be-logged mobile phone number is allowed to log in; if not, historical account data of the to-be-logged mobile phone number and operator data of the to-be-logged mobile phone number and the target mobile phone number are obtained; and the fraud risk value of the to-be-logged mobile phone number is determined according to the historical account data and the operator data, and finally it is judged whether the to-be-logged mobile phone number is allowed to log in according to the fraud risk value. The method of the embodiment, when calculating the fraud risk value, combines the historical account data of the to-be-logged mobile phone number and the operator data of the to-be-logged mobile phone number and the target mobile phone number to make the calculation of the fraud risk value supported by more comprehensive data. Moreover, when the information of the user is missing or sparse, the influence of a single data source on the fraud detection result is avoided, and the accuracy of the fraud detection result is improved.

[0087] Figure 3 The flowchart of the anti-fraud method based on impersonation login detection provided by the application Figure Two As shown in the figure, Figure 3 The embodiment is based on Figure 2 The calculation process of the fraud risk value is described in detail, and the method comprises the following steps:

[0088] S301, input the historical account data into a fraud behavior recognition model, and the fraud behavior recognition model is obtained according to a first data set; wherein the first data set comprises sample account data and a first label, and the first label is a fraud user or a normal user.

[0089] S302, obtaining a fraud probability value of a fraud behavior output by the fraud behavior recognition model.

[0090] As shown in the figure, Figure 2The historical account data refers to various account-related data generated by the user during the use of the APP, and accordingly, the sample account data included in the first data set is various account data generated by the sample user during the use of the APP, and each sample data in the first data set carries a first label, which indicates that the corresponding sample user is a fraudulent user or a normal user. The fraud behavior recognition model trained by the first data set can obtain the fraud probability value of the mobile phone number to be logged in after inputting the historical account data.

[0091] In some embodiments, if the APP to be logged in by the user is a bank or other financial APP, the historical account data includes at least one of the following: loan data, repayment data, past investment history data, counterparty data, recent account transaction data, or transaction time distribution. Among them, from the loan data, it can be concluded whether the account of the mobile phone number to be logged in has abnormal loan behavior or loan that does not conform to the routine, and the application may be fraudulent; if there is a situation of not repaying on time or abnormal repayment amount in the repayment data, it may indicate that the account has a fraud risk; if there is an abnormal investment behavior or a behavior inconsistent with the user's historical investment pattern in the past investment history data, it may also be a signal of fraud; similarly, if there is frequent transaction with a high-risk counterparty or abnormal counterparty information, there may also be a risk of fraud; in addition, the recent account transaction data includes recent transaction amount, transaction frequency, transaction type, etc., sudden large transaction or significant change in transaction frequency, or a large number of transactions in non-normal time period or abnormal transaction time distribution may also be a manifestation of fraudulent behavior.

[0092] Correspondingly, the sample account data in the first data set also includes at least one of the loan data, the repayment data, the past investment history data, the counterparty data, the recent account transaction data, or the transaction time distribution.

[0093] After obtaining the sample account data, the fraud behavior recognition model is constructed according to the sample account data and the first label carried thereby.

[0094] Optionally, during the construction of the fraud behavior recognition model, more statistical data such as mean, standard deviation, maximum value, median, etc. can be generated according to the sample account data. Further, the sample account data and the corresponding statistical data are divided into a training set and a test set according to the distribution of the first label.

[0095] In some embodiments, an XGBoost model can be used, which is a gradient boosting-based machine learning algorithm. Specifically, the training set data can be input into the XGBoost model for learning, and weights can also be assigned to the samples for cost-sensitive learning to reduce the impact of positive and negative sample imbalance. When evaluating the model, a 5-fold cross-validation method is used to find the best hyperparameters for the model, and then the model is retrained using the set of hyperparameters and the entire training set. Then, the model is used for prediction on the test set and the effect is counted to obtain the final fraud behavior identification model.

[0096] S303, obtaining interaction data of the target mobile phone number and the mobile phone number to be logged in according to the operator data.

[0097] In the specific implementation process, first, the communication data of the target mobile phone number and the mobile phone number to be logged in is obtained according to the operator data, and then the interaction data is determined according to the communication data of the target mobile phone number and the mobile phone number to be logged in. The communication data includes at least one of the following: call behavior data, base station data, family package data or SMS data.

[0098] Specifically, the call behavior data is various data related to call activities of the user. Through the call behavior data between the target mobile phone number and the mobile phone number to be logged in, the interaction data of the daily call times, call frequency, call duration and call time period distribution between the two mobile phone numbers can be determined. The more the daily call times, the higher the call frequency and the longer the call duration, the more likely the two users are acquaintances, and the lower the fraud risk.

[0099] The base station data refers to the information of the base station connected by the mobile phone number. Through the base station data, the base station overlap rate data of the target mobile phone number and the mobile phone number to be logged in can be obtained. The higher the base station overlap rate, the more likely the two mobile phone numbers are to be together, that is, the two users are more likely to be acquaintances, and the lower the fraud risk.

[0100] In addition, if the target mobile phone number and the mobile phone number to be logged in share a family package data, the two mobile phone numbers are more likely to be acquaintances, and the fraud risk is low. Through the call behavior data and the SMS data, the call and SMS quantity ratio between the two mobile phone numbers can be obtained. If the call and SMS quantity ratio of the two mobile phone numbers is high, there are a large number of calls and SMS, which may indicate that the relationship between the two users is close, and the fraud risk is low.

[0101] S304, inputting the interaction data into the acquaintance relationship model, the acquaintance relationship model being trained according to a second data set; wherein the second data set includes the operator data of each of the two mobile phone numbers in pairs, and the second label corresponding to the two mobile phone numbers in pairs, the second label being used to indicate whether the two mobile phone numbers are acquaintances.

[0102] S305. Obtain the probability value of acquaintance relationships output by the acquaintance relationship model.

[0103] Specifically, the second dataset includes sample data of the respective carrier information for each of the two paired phone numbers, as well as a second label indicating whether the two phone numbers are related as acquaintances. The acquaintance relationship model trained using this second dataset can obtain a probability value of a acquaintance relationship between the phone number to be logged in and the target phone number after inputting interaction data. The higher the probability value, the greater the likelihood that the users of the phone number to be logged in and the target phone number are acquaintances, and the lower the risk of fraud in this login attempt.

[0104] In some embodiments, an XGBoost model can also be used to construct a familiar relationship model. Specifically, the second dataset includes carrier data for each of two paired mobile phone numbers, including at least one of the following: call behavior data, base station data, family plan data, or SMS data. Interaction data between the paired mobile phone numbers is then generated based on this carrier data. Further, more statistical data, such as mean, standard deviation, maximum and minimum values, and median, are generated based on this interaction data. The XGBoost model is then trained using the interaction data and statistical data corresponding to this second dataset, along with the second label, to obtain the familiar relationship model.

[0105] S306. Based on the positive weight of the fraud probability value and the negative weight of the probability value of the relationship between acquaintances, perform a weighted sum to obtain the fraud risk value. The larger the fraud risk value, the higher the fraud risk.

[0106] The anti-fraud method based on impersonation login detection provided in this application embodiment obtains the fraud probability value of fraudulent behavior by inputting historical account data into a fraud behavior identification model; it then obtains the interaction data between the target mobile phone number and the mobile phone number to be logged in based on operator data, inputs the interaction data into a familiar relationship model, and obtains the familiar relationship probability value; finally, it combines the fraud probability value and its positive weight, and the familiar relationship probability value and its negative weight, and performs a weighted summation to obtain the fraud risk value. This embodiment's method not only uses historical account data to detect fraudulent behavior but also combines the operator data of the target mobile phone number and the mobile phone number to be logged in for auxiliary judgment, improving the accuracy of the fraud risk value judgment result.

[0107] Figure 4 A flowchart illustrating the anti-fraud method based on impersonation login detection provided in this application. Figure Three ,like Figure 4 As shown, this embodiment, after calculating the fraud risk value, provides a detailed explanation of whether to allow the mobile phone number to log in. The method includes:

[0108] S401, judge whether the fraud risk value exceeds the preset threshold, if not, execute S402, if yes, execute S403.

[0109] S402, allow the login request of the user.

[0110] After obtaining the fraud risk value, judge whether the fraud risk value exceeds the preset threshold, if not, the possibility of fraud risk of this login behavior is low, and the login request of the user is allowed.

[0111] S403, feedback the face recognition verification request to the user.

[0112] Correspondingly, if the fraud risk value exceeds the preset threshold, in order to ensure the property safety of the mobile phone number account to be logged in, the user needs to be fed back a request for further verification, for example, a face recognition verification request.

[0113] S404, in response to the face recognition verification of the user, judge whether the face recognition verification is passed, if yes, execute S402, if not, execute S405.

[0114] S405, reject the login request of the mobile device.

[0115] Specifically, the request for face recognition verification can be initiated on the login page, and in response to the face recognition verification of the user, judge whether the face recognition verification is passed. If the face recognition verification is passed, it means that the current login operation is allowed by the user corresponding to the mobile phone number to be logged in, and the fraud risk is low, so the login request of the user is allowed. Correspondingly, if the face recognition verification is not passed, the login request of the mobile device is rejected.

[0116] The anti-fraud method based on impersonation login detection provided by the embodiment of the application can judge whether the fraud risk value exceeds the preset threshold after obtaining the fraud risk value, if not, allow the login request of the user, if yes, feed back the face recognition verification request to the user, and perform face recognition verification, which can effectively prevent the identity of the user of the mobile phone number to be logged in from being stolen and reduce the fraud risk.

[0117] Figure 5 The structure diagram of the anti-fraud device based on impersonation login detection provided by the application is shown in Figure 5 As shown in the figure, the anti-fraud device 50 provided by the embodiment includes:

[0118] The login information acquisition module 501 is configured to acquire the mobile phone number to be logged in and the identifier of the SIM card in the mobile device in response to the login request of the mobile device to log in the APP.

[0119] The number taking module 502 is configured to send a number taking request carrying the identifier of the SIM card to a number taking platform, and receive the target mobile phone number returned by the number taking platform.

[0120] The data acquisition module 503 is configured to acquire historical account data of the to-be-logged-in mobile phone number and operator data of the to-be-logged-in mobile phone number and the target mobile phone number if the to-be-logged-in mobile phone number is inconsistent with the target mobile phone number.

[0121] The judgment module 504 is configured to determine a fraud risk value of the to-be-logged-in mobile phone number according to the historical account data and the operator data, and determine whether to allow the to-be-logged-in mobile phone number to log in according to the fraud risk value.

[0122] In a possible implementation, the judgment module 504 is specifically configured to acquire a fraud probability value of a fraud behavior according to the historical account data, and the greater the fraud probability value, the higher the corresponding fraud risk.

[0123] According to the operator data of the target mobile phone number and the to-be-logged-in mobile phone number, a familiar relationship probability value is acquired, and the greater the familiar relationship probability value, the lower the corresponding fraud risk.

[0124] According to a positive weight of the fraud probability value and a negative weight of the familiar relationship probability value, a weighted sum is performed to obtain the fraud risk value, and the greater the fraud risk value, the higher the fraud risk.

[0125] In a possible implementation, the judgment module 504 is specifically configured to input the historical account data into a fraud behavior recognition model, the fraud behavior recognition model being trained according to a first data set, and the first data set including sample account data and a first label, the first label being a fraud user or a normal user; and acquire a fraud probability value of a fraud behavior output by the fraud behavior recognition model.

[0126] In a possible implementation, the judgment module 504 is specifically configured to acquire interaction data of the target mobile phone number and the to-be-logged-in mobile phone number according to the operator data; input the interaction data into a familiar relationship model, the familiar relationship model being trained according to a second data set, and the second data set including operator data of two mobile phone numbers in each pair and a second label corresponding to the two mobile phone numbers in each pair, the second label being used to indicate whether the two mobile phone numbers are in a familiar relationship; and acquire a familiar relationship probability value output by the familiar relationship model.

[0127] In a possible implementation, the judgment module 504 is further configured to determine whether the fraud risk value exceeds a preset threshold; if the fraud risk value does not exceed the preset threshold, allow the login request of the user; if the fraud risk value exceeds the preset threshold, feed back a face recognition verification request to the user; and in response to the face recognition verification of the user, determine whether the face recognition verification is passed, and if the face recognition verification is passed, allow the login request of the user.

[0128] In a possible implementation, the judging module 504 is specifically configured to: according to the operator data, obtain communication data of the target mobile phone number and the mobile phone number to be logged in respectively, the communication data including at least one of the following: call behavior data, base station data, home package data or short message data.

[0129] According to the communication data of the target mobile phone number and the mobile phone number to be logged in respectively, the interaction data is determined, the interaction data including at least one of the following: daily call times, call frequency, call duration, call time period distribution, whether there is a master and secondary card relationship, base station overlap rate or call and short message quantity proportion.

[0130] In a possible implementation, the APP is a financial APP, and the historical account data includes at least one of the following: loan data, repayment data, past investment history data, counterparty data, recent account transaction data or transaction time distribution.

[0131] The anti-fraud device based on impersonation login detection provided in this embodiment can execute the method provided in the method embodiment, and has similar implementation principles and technical effects, which will not be described here again.

[0132] Figure 6 A structural diagram of the anti-fraud device based on impersonation login detection provided in this application is shown in FIG. 6. As shown in FIG. 6, the electronic device 60 provided in this embodiment includes at least one processor 601 and a memory 602. Optionally, the device 60 further includes a communication component 603. The processor 601, the memory 602 and the communication component 603 are connected through a bus 604. Figure 6

[0133] In the specific implementation process, the at least one processor 601 executes the computer execution instructions stored in the memory 602, so that the at least one processor 601 executes the method described above.

[0134] The specific implementation process of the processor 601 can refer to the method embodiment described above, and has similar implementation principles and technical effects, which will not be described here again.

[0135] ​In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The steps of the method disclosed in combination with the application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.

[0136] The memory can include a random access memory (RAM), and can also include a non-volatile memory (NVM), such as at least one disk memory.

[0137] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.

[0138] The present application also provides a computer program product, comprising a computer program, which, when executed by a processor, implements the above method.

[0139] The present application also provides a computer readable storage medium, which stores computer execution instructions, and when a processor executes the computer execution instructions, the above method is implemented.

[0140] The above readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0141] An example readable storage medium is coupled to the processor such that the processor can read information from the readable storage medium and can write information to the readable storage medium. Of course, the readable storage medium can also be a part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.

[0142] The division of units is only a logical functional division, and in actual implementation, there can be another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can be electrical, mechanical or other forms.

[0143] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0144] In addition, the functional units in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit.

[0145] If the functions are realized in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the present application that essentially contributes to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the present application. The foregoing storage medium includes a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various program code storage media.

[0146] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The foregoing program can be stored in a computer readable storage medium. The program executes to perform the steps of the above-mentioned method embodiments; and the foregoing storage medium includes various media capable of storing program codes, such as ROM, RAM, magnetic disk, or optical disk.

[0147] Finally, it should be noted that other embodiments of the present application will readily occur to those skilled in the art upon consideration of the specification and practice of the present application disclosed herein. The present application is intended to include all such variations as fall within the general scope of the application, and includes the generic principles disclosed and the best mode known to the inventors to be currently practiced as well as variations thereof, without departing from the scope of the present application as defined by the claims. The specification and examples give the best application of the present application as currently known, and together with the description of the application serve to best illustrate the principles of the application. The scope of the application is expressly set forth by the claims.

Claims

1. A method for anti-fraud based on impersonation detection, characterized in that, The method comprises: in response to a login request of a mobile device logging into an APP, obtaining a to-be-logged-in mobile phone number and an identifier of a SIM card in the mobile device; sending a number-taking request carrying the identifier of the SIM card to a number-taking platform, and receiving a target mobile phone number returned by the number-taking platform; if the to-be-logged-in mobile phone number is inconsistent with the target mobile phone number, obtaining historical account data of the to-be-logged-in mobile phone number and operator data of the to-be-logged-in mobile phone number and the target mobile phone number respectively; determining a fraud risk value of the to-be-logged-in mobile phone number according to the historical account data and the operator data, and judging whether to allow the to-be-logged-in mobile phone number to log in according to the fraud risk value.

2. The method of claim 1, wherein, The method comprises: obtaining a fraud probability value of a fraud behavior according to the historical account data, wherein the greater the fraud probability value is, the higher the corresponding fraud risk is; obtaining a familiar relationship probability value according to the operator data of the target mobile phone number and the to-be-logged-in mobile phone number, wherein the greater the familiar relationship probability value is, the lower the corresponding fraud risk is; performing weighted summation according to a positive weight of the fraud probability value and a negative weight of the familiar relationship probability value to obtain the fraud risk value, wherein the greater the fraud risk value is, the higher the fraud risk is.

3. The method of claim 2, wherein, The method comprises: inputting the historical account data into a fraud behavior identification model, wherein the fraud behavior identification model is obtained by training a first data set, and the first data set comprises sample account data and a first label, and the first label is a fraud user or a normal user; obtaining a fraud probability value of a fraud behavior output by the fraud behavior identification model.

4. The method of claim 3, wherein, The method comprises: obtaining interaction data of the target mobile phone number and the to-be-logged-in mobile phone number according to the operator data; inputting the interaction data into a familiar relationship model, wherein the familiar relationship model is obtained by training a second data set, and the second data set comprises operator data of two mobile phone numbers in pairs and a second label corresponding to the two mobile phone numbers in pairs, and the second label is used to indicate whether the two mobile phone numbers are in a familiar relationship; obtaining a familiar relationship probability value output by the familiar relationship model.

5. The method of claim 1, wherein, The method comprises: judging whether the fraud risk value exceeds a preset threshold; if the fraud risk value does not exceed the preset threshold, allowing the login request of the user; if the fraud risk value exceeds the preset threshold, feeding back a face recognition verification request to the user; in response to the face recognition verification of the user, judging whether the face recognition verification is passed, and if so, allowing the login request of the user.

6. The method of claim 4, wherein, The method comprises: According to the operator data, communication data of the target mobile phone number and the mobile phone number to be logged in is obtained, the communication data including at least one of the following: call behavior data, base station data, home package data or short message data; According to the communication data of the target mobile phone number and the mobile phone number to be logged in, the interaction data is determined, the interaction data including at least one of the following: daily call times, call frequency, call duration, call time period distribution, whether there is a master and secondary card relationship, base station overlap rate or call and short message quantity proportion.

7. The method of claim 1, wherein, The APP is a financial APP, and the historical account data includes at least one of the following: loan data, repayment data, past investment history data, counterparty data, recent account transaction data or transaction time distribution.

8. An anti-fraud device based on detection of false login, characterized in that, Comprising: A login information acquisition module is configured to acquire a mobile phone number to be logged in and an identification of a SIM card in a mobile device in response to a login request of the mobile device logging into an APP; A number taking module is configured to send a number taking request carrying the identification of the SIM card to a number taking platform and receive a target mobile phone number returned by the number taking platform; A data acquisition module is configured to acquire historical account data of the mobile phone number to be logged in and operator data of the mobile phone number to be logged in and the target mobile phone number if the mobile phone number to be logged in is inconsistent with the target mobile phone number; A judgment module is configured to determine a fraud risk value of the mobile phone number to be logged in according to the historical account data and the operator data, and determine whether to allow the mobile phone number to be logged in to log in according to the fraud risk value.

9. An anti-fraud device based on impersonation detection, characterized in that, Comprising: A memory and a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory, so that the processor executes the method of any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method of any one of claims 1-7.

Citation Information

Patent Citations

  • Login method and device

    CN104717224A

  • Method and device for determining suspicion information of fraudulent event

    CN111105064A