Overseas social software supervision method and supervision system based on dynamic electronic fence
By building dynamic electronic fences on overseas social software, simulating GPS signals to obtain group data, combining crawling technology and big data analysis, identifying core nodes and monitoring sensitive content in real time, it solves the problem that traditional regulatory methods are difficult to track sensitive activities, and achieves efficient monitoring and early warning of encrypted social software.
Patent Information
- Application Number
- CN202510180205.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-16
AI Technical Summary
Traditional regulatory methods are difficult to effectively track sensitive activities in overseas social software, especially on platforms with strong anonymity and geographic location dynamics. It is impossible to bypass geographical location restrictions to obtain group data outside the designated area. It relies on manual joining groups or active authorization of users. The data collection efficiency is low and easy to be detected. It lacks real-time analysis capabilities for massive data, and it is difficult to warn of abnormal gatherings or the spread of sensitive content.
The supervision method based on dynamic electronic fences is adopted, and the coordinate points of the target area are forged by simulating GPS signals, and the interface of social software is called to obtain groups and user data in the fence, and the deployment mount is automatically searched and crawled group and user data. Combined with big data analysis and identity collision matching, core nodes are identified and sensitive content is monitored in real time, triggering early warnings and countermeasures.
It realizes efficient monitoring and early warning of encrypted social software, improves the accuracy of illegal aggregation and dissemination of sensitive content, and can shift from passive defense to active control, and is suitable for public security and network counter-terrorism.
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security and monitoring technology, and in particular to a method and system for supervising overseas social software based on a dynamic electronic fence. Background Art
[0002] With the popularity of overseas social software, especially instant messaging tools such as Telegram that are highly anonymous and encrypted. Due to the anonymity and dynamic location of such encrypted social software, traditional regulatory means are difficult to effectively track sensitive activities. Traditional regulatory means have the following shortcomings:
[0003] 1. It is impossible to bypass the geographical location restrictions of social software to obtain user and group data outside the specified area;
[0004] 2. Relying on manual group joining or user active authorization, data collection efficiency is low and easy to be detected;
[0005] 3. Lack of real-time analysis capabilities for massive amounts of data, making it difficult to warn of abnormal aggregation or the spread of sensitive content.
[0006] Therefore, there is an urgent need for a solution that can effectively supervise and warn overseas social software to solve the above problems. Summary of the invention
[0007] The present invention aims to solve the technical problems existing in the prior art. To this end, the present invention provides a method and system for supervising overseas social software based on dynamic electronic fences, which can effectively supervise and warn overseas social software.
[0008] The technical solution adopted by the present invention to solve its technical problem is:
[0009] In a first aspect, a method for supervising overseas social software based on a dynamic electronic fence is provided, comprising the following steps:
[0010] Step S1, constructing a dynamic electronic fence: by simulating GPS signals, forging the coordinate points of the target area, calling the "nearby groups" or / and "nearby people" interfaces opened by social software, and obtaining the group and user data within the set fence;
[0011] Step S2, deploy checkpoints: calculate the required number and positions of checkpoints based on the fence radius and the target area, and the checkpoints are automatically deployed by the crawler account;
[0012] Step S3, crawling data: the card port account automatically searches for nearby groups and users according to the set period, captures group members, chat records and user dynamics, and stores them in the distributed database;
[0013] Step S4, identity collision matching: extract data including user ID and group administrator's mobile phone number from social software, compare them with the mobile phone number database provided by local communication operators, match the real identity, and build a user relationship network diagram based on user group joining and leaving records and interaction frequency to identify core nodes;
[0014] Step S5, sensitive content monitoring and early warning: establish a sensitive keyword library, scan chat content in real time, extract high-mentioned words, set threshold rules, and trigger real-time early warning for abnormal behavior.
[0015] In some optional implementations, step S6 is also included, active countermeasures and public opinion guidance: creating a honeypot group to attract target users to join, monitoring their chat content and member relationships in real time, publishing guiding information through controllable accounts, and interfering with the planning of illegal activities.
[0016] In some optional implementations, step S7 is also included, multi-platform data fusion and intelligence output: integrating social software monitoring data with other social platform information, performing correlation analysis through a unified data interface, and outputting a standardized intelligence report.
[0017] In some optional implementations, in step S4, the user login IP, GPS positioning data and the electronic fence monitoring results are also associated to generate a time-space trajectory heat map and mark abnormal aggregation points.
[0018] In some optional implementations, in step S6, a batch of mobile phone numbers are also used to register social accounts to simulate normal user behavior and improve account credibility. At the same time, an account pool management system is established to allocate accounts according to task requirements to perform monitoring, phishing or counter-operations.
[0019] In a second aspect, a supervision system for implementing the overseas social software supervision method based on dynamic electronic fence is provided, including a virtual positioning module, a checkpoint deployment module, a crawler module, a big data analysis module, an identity collision module, a real-time monitoring module, an early warning module and a countermeasure module, wherein:
[0020] The virtual positioning module is used to forge the GPS coordinate points of the target area;
[0021] The checkpoint deployment module is used to automatically calculate the number and location of checkpoints based on the fence radius and the target area area;
[0022] The crawler module uses the crawler account to automatically search and crawl group and member information within the fence;
[0023] The big data analysis module performs correlation analysis on the data collected from the crawler module and the virtual positioning module, generates feature intelligence data, and realizes monitoring and investigation of target personnel and groups;
[0024] The identity collision module is used to match the real identity by associating the mobile phone number with the ID of the social software;
[0025] The real-time monitoring module is used to define the monitoring range on the map and monitor the flow of people, groups and member data in the area in real time;
[0026] The warning module triggers a real-time warning for abnormal behaviors that exceed the set threshold rules;
[0027] The countermeasure module is used to deploy honeypot groups and / or number pool management.
[0028] In some optional implementations, the early warning module includes an illegal gathering event early warning module, which is used to push real-time early warnings for abnormal personnel flow situations that reach restrictions.
[0029] Compared with the prior art, the present invention has the following beneficial effects:
[0030] The present invention breaks through geographical restrictions by simulating GPS locations, combines crawler technology to capture user and group data in the target area in real time, and uses big data analysis to generate behavior trajectories and sensitive content propagation paths, thereby realizing functions such as illegal gathering warning and key personnel tracking, improving the monitoring efficiency and accuracy of encrypted social software, and realizing a technical upgrade from passive defense to active control. It can be widely used in public security, cyber counter-terrorism and other fields. DETAILED DESCRIPTION
[0031] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0032] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0033] In addition, the technical solutions between the various embodiments can be combined with each other, but it must be based on the fact that ordinary technicians in the field can implement it. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by the present invention.
[0034] Embodiment: This embodiment provides a method for supervising overseas social software based on a dynamic electronic fence, comprising the following steps:
[0035] Step S1, building a dynamic electronic fence: by simulating GPS signals, forging the coordinate points of the target area (such as the center of a sensitive area), calling the "nearby groups" or / and "nearby people" interfaces opened by social software (such as Telegram), and obtaining group and user data within a 10-kilometer range.
[0036] Step S2, deploy checkpoints: Calculate the required number and location of checkpoints based on the fence radius (default 10 kilometers) and the target area. Checkpoints are automatically deployed by the crawler account. Each checkpoint covers a circular area. Checkpoint deployment uses a hexagonal paving algorithm to dynamically adjust the location and number of checkpoints.
[0037] Step S3, crawling data: the card port account automatically searches for nearby groups and users at a set period (such as every 5 minutes), captures group members, chat records and user dynamics, and stores them in a distributed database.
[0038] Step S4, identity collision matching: extract data including user ID and group administrator’s mobile phone number from social software, compare them with the mobile phone number database provided by local communication operators, match the real identity, and build a user relationship network diagram based on user group joining and leaving records and interaction frequency to identify core nodes (such as group owners and high-frequency interactors); also associate user login IP and GPS positioning data with electronic fence monitoring results to generate a time-space trajectory heat map and mark abnormal aggregation points.
[0039] Step S5: Sensitive content monitoring and early warning:
[0040] Establish a database of sensitive keywords such as politics, violence and terrorism, and black and gray industries, scan chat content in real time, extract high-mentioned words, set threshold rules, and trigger real-time warnings for abnormal behaviors;
[0041] Analyze the propagation path of sensitive content (initial sender, forwarder, responder) through message timestamp and user ID, and generate a propagation network map;
[0042] Set threshold rules (e.g. 50 new people in the same area within 10 minutes) to trigger real-time warnings for abnormal behaviors such as gathering of people and surge in group size;
[0043] Early warning information is pushed through multiple terminals and intelligence briefings can be automatically generated.
[0044] Step S6: Active countermeasures and public opinion guidance:
[0045] Create honeypot groups disguised as "supply groups" or "activity planning groups" to attract target users to join and monitor their chat content and member relationships in real time; during sensitive periods, controllable accounts can also be used to release guiding information to interfere with illegal activity planning;
[0046] Using batches of mobile phone numbers to register social media accounts, simulating normal user behavior (such as randomly joining groups and sending harmless messages) to enhance the credibility of the accounts;
[0047] Establish an account pool management system and allocate accounts to perform monitoring, phishing or counter-operations according to task requirements.
[0048] Step S7, multi-platform data fusion and intelligence output: Integrate social software monitoring data with other social platform information, perform correlation analysis through a unified data interface, and output standardized intelligence reports, including event timelines, risk registration assessments, and support PDF / Excel format export.
[0049] In the specific implementation, take the sudden illegal gathering incident in a sensitive area as an example:
[0050] 1. Dynamic fence deployment: Forge 10 GPS checkpoints around the target area and crawl data of 50 groups and 300 users.
[0051] 2. Identity matching: The real identities of the three organizers were locked through mobile phone number collision and their historical activity tracks were linked.
[0052] 3. Warning trigger: The system detects that the number of group members increases by 200% within 2 hours, triggering an "illegal gathering" warning and pushing it to the law enforcement terminal.
[0053] 4. Countermeasure implementation: Release false information about the meeting location through honeypot groups to disperse participants, and at the same time retrieve controllable accounts to collect on-site intelligence.
[0054] The above-mentioned overseas social software supervision method based on dynamic electronic fence is implemented by a corresponding supervision system, which includes a virtual positioning module, a checkpoint deployment module, a crawler module, a big data analysis module, an identity collision module, a real-time monitoring module, an early warning module and a countermeasure module, wherein:
[0055] The virtual positioning module is used to forge the GPS coordinate points of the target area; the checkpoint deployment module is used to automatically calculate the number and location of checkpoints according to the fence radius and the target area area; the crawler module uses the crawler account to automatically search and crawl group and member information within the fence; the big data analysis module performs correlation analysis on the data collected from the crawler module and the virtual positioning module, generates feature intelligence data, and realizes the monitoring and investigation of target personnel and groups; the identity collision module is used to match the real identity by associating the mobile phone number with the ID of the social software; the real-time monitoring module is used to circle the monitoring range on the map, and monitor the flow of people, groups and member data in the area in real time; the early warning module triggers a real-time warning for abnormal behavior that exceeds the set threshold rules; preferably, the early warning module includes an illegal gathering event early warning module, which is used to push real-time early warnings for abnormal personnel flow that touches the restrictions; the countermeasure module is used to deploy honeypot groups and / or number pool management.
[0056] The above descriptions are merely embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention specification, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A method for supervising overseas social software based on dynamic electronic fence, characterized in that: The following steps are involved: Step S1, constructing a dynamic electronic fence: by simulating GPS signals, forging the coordinate points of the target area, calling the "nearby groups" or / and "nearby people" interface opened by the social software, and obtaining the group and user data within the set fence; Step S2, deploy checkpoints: calculate the required number and positions of checkpoints based on the fence radius and the target area, and the checkpoints are automatically deployed by the crawler account; Step S3, crawling data: the card port account automatically searches for nearby groups and users according to the set period, captures group members, chat records and user dynamics, and stores them in the distributed database; Step S4, identity collision matching: extract data including user ID and group administrator's mobile phone number from social software, compare them with the mobile phone number database provided by local communication operators, match the real identity, and build a user relationship network diagram based on user group joining and leaving records and interaction frequency to identify core nodes; Step S5, sensitive content monitoring and early warning: establish a sensitive keyword library, scan chat content in real time, extract high-mentioned words, set threshold rules, and trigger real-time early warning for abnormal behavior.
2. The overseas social software supervision method based on dynamic electronic fence according to claim 1 is characterized in that: It also includes step S6, active countermeasures and public opinion guidance: creating a honeypot group to attract target users to join, monitoring their chat content and member relationships in real time, and publishing guiding information through controllable accounts to interfere with the planning of illegal activities.
3. The overseas social software supervision method based on dynamic electronic fence according to claim 2 is characterized in that: It also includes step S7, multi-platform data fusion and intelligence output: integrating social software monitoring data with other social platform information, performing correlation analysis through a unified data interface, and outputting standardized intelligence reports.
4. The overseas social software supervision method based on dynamic electronic fence according to claim 1 is characterized in that: In step S4, the user login IP, GPS positioning data and electronic fence monitoring results are also associated to generate a time-space trajectory heat map and mark abnormal gathering points.
5. The overseas social software supervision method based on dynamic electronic fence according to claim 2 is characterized in that: In step S6, a batch of mobile phone numbers are used to register social accounts to simulate normal user behavior and improve the credibility of the accounts. At the same time, an account pool management system is established to allocate accounts according to task requirements to perform monitoring, phishing or countermeasure operations.
6. A foreign social software supervision system based on dynamic electronic fence, characterized in that: The method for supervising overseas social software based on dynamic electronic fences according to any one of claims 1 to 5 is used to implement the supervision system, which includes a virtual positioning module, a checkpoint deployment module, a crawler module, a big data analysis module, an identity collision module, a real-time monitoring module, an early warning module and a countermeasure module, wherein: The virtual positioning module is used to forge the GPS coordinate points of the target area; The checkpoint deployment module is used to automatically calculate the number and location of checkpoints based on the fence radius and the target area area; The crawler module uses the crawler account to automatically search and crawl group and member information within the fence; The big data analysis module performs correlation analysis on the data collected from the crawler module and the virtual positioning module, generates feature intelligence data, and realizes monitoring and investigation of target personnel and groups; The identity collision module is used to match the real identity by associating the mobile phone number with the ID of the social software; The real-time monitoring module is used to define the monitoring range on the map and monitor the flow of people, groups and member data in the area in real time; The warning module triggers a real-time warning for abnormal behaviors that exceed the set threshold rules; The countermeasure module is used to deploy honeypot groups and / or number pool management.
7. The overseas social software supervision system based on dynamic electronic fence according to claim 6 is characterized in that: The early warning module includes an illegal gathering event early warning module, which is used to push real-time early warnings for abnormal personnel flow situations that reach restrictions.