Risk prompting method and electronic equipment

By receiving communication events in electronic devices, judging the sending number and collecting user behavior data, and using AI modules to provide risk warnings, the problem of resource loss when receiving non-intercepting number text messages is solved, timely and accurate risk warnings are achieved, and user security and equipment efficiency are improved.

CN120281849APending Publication Date: 2025-07-08HONOR DEVICE CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202311865346.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

现有技术中,用户在接收到非拦截号码的短信时,仍存在资源损失的风险,无法及时进行风险提示。

Method used

Receive communication events through electronic devices to determine whether the sending number is an unfamiliar number. If the preset triggering conditions are met, the user behavior data will be collected and risk warnings will be used to use the AI module to identify the text message content, including regular expressions and NLP models, and risk detection and prompts will be conducted in combination with user portraits.

Benefits of technology

It realizes timely risk warnings for non-intercepted SMS, reduces the risk of user resource loss, and improves user security and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281849A_ABST
    Figure CN120281849A_ABST
Patent Text Reader

Abstract

The embodiment of the invention is applied to the technical field of communication, and provides a risk prompting method and electronic equipment. When the electronic equipment receives a preset text event, judging whether a sending number corresponding to the preset text event belongs to an unfamiliar number or not, and if the sending number corresponding to the preset text event belongs to the unfamiliar number and the first interaction behavior meets a preset first triggering condition, triggering the sending number corresponding to the preset text event; if it is indicated that a user of the electronic device has a likelihood of being induced to perform a security risk behavior, the electronic device may begin to collect first data. Afterwards, the electronic equipment determines whether the electronic equipment carries out the behavior with the high risk according to the first data, and after it is determined that the electronic equipment carries out the behavior with the high risk, the electronic equipment can carry out risk prompting to remind the user that the current behavior has the risk, so that timely and accurate risk prompting is achieved, and the user experience is improved. Therefore, the property loss of the user is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technologies, and in particular, to a risk prompt method and an electronic device. Background Art

[0002] Currently, there are often situations where a user's resources (such as property) are damaged due to the user's trigger operations based on text messages (such as replying to a text message or clicking on a URL in a text message). In related technologies, in order to reduce the risk of damage to the user's resources, when an electronic device receives a text message, if the sender number corresponding to the text message belongs to a blocked number, the electronic device can directly block the text message to avoid damage to the user's resources.

[0003] However, in the case where the sender number corresponding to the text message does not belong to a blocked number, the sender number may still be a number with security risks, and the user's resources may still be damaged. Therefore, how to promptly give a risk prompt for text messages sent by numbers with security risks to reduce the risk of damage to the user's resources has become an urgent problem to be solved. Summary of the Invention

[0004] Embodiments of this application provide a risk prompt method and an electronic device, which are used to enable the electronic device to promptly give a risk prompt and reduce the risk of damage to the user's resources when the sender number corresponding to the text message does not belong to a blocked number.

[0005] In a first aspect, a risk prompt method is provided. In this method, first, an electronic device receives a communication event; where the communication event includes an incoming call event and / or a preset text event. Then, the electronic device determines whether the sender number corresponding to the preset text event belongs to an unfamiliar number. Then, in the case where the sender number corresponding to the preset text event belongs to an unfamiliar number, it indicates that the sender number may be a number with security risks. In other words, after interacting with the sender number (such as answering the call from the sender number), the user's resources may be damaged. If a first interaction behavior meets a preset first trigger condition, it indicates that there is a possibility that the user of the electronic device has been induced. Therefore, the electronic device can start detecting whether there is a risk of damage to the user's property, that is, the electronic device can start collecting first data, where the first data includes user behavior data and / or operation data of applications in the electronic device. Then, the electronic device can, in the case where the first data has first preset risk behavior data, perform a risk prompt operation based on the first data by using an AI module; or the electronic device can stop collecting the first data in the case where the first data does not have the first preset risk behavior data.

[0006] In this application, after the electronic device collects the first data, it determines whether the first data contains the first preset risk behavior data. If the first data contains the above-mentioned first preset risk behavior data, the AI module can be used to determine whether the electronic device has performed a behavior with a relatively high risk based on the first data. After determining that the electronic device has performed a behavior with a relatively high risk, a risk prompt is given to remind the user that the current behavior has a relatively high risk, ensuring the timeliness and accuracy of the risk prompt, thereby avoiding losses to the user's resources.

[0007] In a possible implementation manner of the first aspect, the above-mentioned preset text event is a text event received that contains text content conforming to the preset text content, and the preset text is text content with a length less than the preset length.

[0008] In a possible implementation manner of the first aspect, the preset first trigger conditions include at least one of: the call duration with the calling number being greater than the first preset duration, the existence of a reply message corresponding to the preset text event, the access duration of the link address in the preset text event being greater than the second preset duration, and copying at least a part of the target text message content corresponding to the target text message type in the preset text event; where the target text message type includes at least one of a link address, a telephone number, a bank card number, and a social account number.

[0009] In a possible implementation manner of the first aspect, the above-mentioned unfamiliar numbers include safe numbers marked with the first preset label and / or suspicious numbers marked with the second preset label; the suspicious numbers refer to the numbers marked with the second preset label, and the second preset label includes labels related to behaviors with security risks; the first preset label is a label other than the second preset label. Among them, behaviors with security risks can include behaviors such as inducing users to consume, transfer money, and borrow, which may pose risks to the life and property safety of users.

[0010] In this application, the electronic device can perform dynamic detection on all unknown numbers except the blacklisted numbers and contact numbers, reducing the occurrence of situations where unfamiliar numbers with risks (or called security risks) induce operations on users, avoiding losses to the property of users, and enhancing the security of users' use of mobile phones.

[0011] In a possible implementation manner of the first aspect, the process of determining the above-mentioned first preset label and the second preset label can specifically include: the electronic device receives a first incoming call sent by a first calling device, and then, in response to a marking operation on the calling number corresponding to the first incoming call, when the electronic device is in a charging state, it records the number label data of the calling number corresponding to the first incoming call.

[0012] In this application, the electronic device can determine a first preset label and a second preset label according to the number label marked by the user, so as to use the number actively marked by the user to remind other users. At the same time, it can perform risk detection on the incoming call numbers marked with the first preset label / second preset label numbers, reducing the risk of the user's property being damaged. In addition, when the electronic device is in a charging state, marking and recording the calling number corresponding to the first incoming call can minimize the power consumption overhead and reduce the situation where too much mobile phone power is consumed due to number marking and recording.

[0013] In a possible implementation manner of the first aspect, when the sender number corresponding to the above preset text event belongs to a black number, the electronic device intercepts the preset text event.

[0014] In this application, if the sender number is a black number included in the black sample library, it indicates that the sender number is clearly a risk number. Therefore, the electronic device can directly intercept the preset text corresponding to the sender number to prevent the user of the electronic device from having direct contact with the calling user corresponding to the sender number, fundamentally avoiding the loss of the user's property, improving the user's usage safety, and thus enhancing the user's usage experience.

[0015] In a possible implementation manner of the first aspect, the above unfamiliar numbers may include suspicious numbers marked with the second preset label. Correspondingly, when the sender number corresponding to the preset text event belongs to a safe number, the electronic device views the above preset text in response to the user's viewing operation, without determining whether the first interaction behavior meets the preset trigger condition, nor triggering the collection of the first data.

[0016] In this application, if the sender number is a safe number, it indicates that the content of the preset text viewed by the user is safe and will not cause damage to the user's property, that is, it indicates that the preset text event is safe. Therefore, after the mobile phone views the preset text, there is no need to determine whether the preset text will induce the user to perform a risk operation, that is, there is no need to perform risk detection, and the mobile phone can normally process the preset text event. In this way, unnecessary power consumption losses can be reduced.

[0017] In a possible implementation manner of the first aspect, when the sender number corresponding to the preset text event belongs to a suspicious number, the electronic device views the preset text in response to the user's viewing operation.

[0018] In this application, when the sender number is a suspicious number, it means that although the sender number may have a security risk, since it has not been added to the black sample library, the electronic device does not need to intercept it to reduce the situation where the user misses a call due to incorrect interception by the electronic device.

[0019] In a possible implementation of the first aspect, after receiving a communication event, the method further includes: obtaining a preset SMS interception rule, and determining whether the above sender number conforms to the preset SMS interception rule. If the sender number conforms to the preset SMS interception rule, intercept the above preset text event. Wherein, the preset SMS interception rule is a rule capable of intercepting a preset text event.

[0020] In this application, if the sender number conforms to the preset SMS interception rule, it indicates that the possibility of this sender number inducing the user to perform a risk behavior is relatively high, that is, the probability that the preset text event is a risk event is relatively high. Therefore, in order to avoid losses to the user's resources, the electronic device can directly intercept the preset text event to avoid direct contact between the user and the sender of the preset text event from the source, and improve the security of user use.

[0021] In a possible implementation of the first aspect, the method further includes: if the above sender number does not conform to the preset SMS interception rule, display the SMS content corresponding to the above preset text event, and in the case where it is determined that the sender number belongs to an unfamiliar number, if the preset text event is not intercepted and the first interaction behavior meets the preset first trigger condition, collect first data.

[0022] In this application, if the sender number does not conform to the preset SMS interception rule, it indicates that the possibility of this sender number inducing the user to perform a risk behavior is relatively low. Therefore, in order to avoid affecting the user's use, the electronic device can display the SMS content corresponding to the preset text event, that is, do not intercept the preset text event. However, if the sender number belongs to an unfamiliar number, it indicates that there is still a possibility that the preset SMS event induces the user to perform a risk behavior. Therefore, it is necessary to further determine whether the first interaction behavior meets the preset first trigger condition to reduce the possibility of losses to the user's resources.

[0023] In a possible implementation of the first aspect, the preset SMS interception rule is determined based on the phone numbers added by the user in the whitelist and blacklist and / or whether the target interception function is enabled. Wherein, the target interception function includes at least one of a harassment interception function, an intercept all numbers function, an intercept unknown / hidden numbers function, an intercept unfamiliar SMS function, and an intelligent interception function. The intelligent interception function is a function that determines whether to intercept a preset text event by identifying the content corresponding to the preset text event.

[0024] In a possible implementation of the first aspect, the process of collecting the first data may specifically include: identifying the content of the short message corresponding to the preset text event according to a regular expression and / or a language recognition model to obtain a short message recognition result, where the short message recognition result is used to indicate whether there is preset short message content in the content of the short message corresponding to the preset text event, and the preset short message content is the content of the short message corresponding to the target short message type. Then, in the case where the short message recognition result indicates that there is preset short message content in the content of the short message corresponding to the preset text event, extracting the preset short message content existing in the preset text event to obtain at least one short message data; where the short message data includes the target short message type and / or the target short message content corresponding to the target short message type. Then, in the case where a first interaction behavior of the user with respect to the target short message content in the preset text event is detected and the first interaction behavior meets a preset first trigger condition, the first data is collected.

[0025] In this application, only when it is detected that there is preset short message content in the content of the short message corresponding to the preset text event, the preset short message content existing in the preset text event is extracted, and when the first interaction behavior meets the preset first trigger condition, the first data is collected. That is to say, if there is no preset short message content in the content of the short message corresponding to the preset text event, it means that there is no security risk for the target short message, that is, there is no possibility that the user is induced to perform a risk behavior. Therefore, the electronic device does not need to detect the first interaction behavior, and thus does not need to collect the first data. In this way, the impact on the user's use is avoided, and while ensuring the user's use safety, the user's use experience can also be improved.

[0026] In a possible implementation of the first aspect, the process of the above short message recognition may specifically include: inputting the above target short message into a regular expression to obtain a first detection result, where the first detection result is used to indicate whether the target short message includes content of a first short message type, and the first short message type may include at least one of a telephone number, a URL address, and a bank card number. Then, inputting the target short message into an NLP model to obtain a second detection result, where the second detection result is used to indicate whether the target short message includes content of a second short message type, and the second short message type may include a social account. Then, according to the first detection result and the second detection result, a short message recognition result is obtained.

[0027] In this application, the content of the short message corresponding to the preset text event is identified through a regular expression and a language recognition model to determine whether there is preset short message content in the content of the short message corresponding to the preset text event. In this way, not only can computing resources be saved to the greatest extent and unnecessary resource waste be reduced, but also the accuracy of the detection result can be ensured, thereby improving the interception accuracy of the target short message.

[0028] In a possible implementation of the first aspect, when the communication event is an incoming call event, after receiving the communication event, the method further includes: when the calling number corresponding to the incoming call event belongs to an unfamiliar number, it indicates that the communication number may be a number with security risks. In other words, after interacting with the communication number (such as answering the communication number), the user's resources may be damaged. If the second interaction behavior meets the preset second trigger condition, it indicates that there is a possibility that the user of the electronic device is induced. Therefore, the electronic device can start to detect whether there is a risk of the user's property being damaged, that is, the electronic device can start to collect the first data. After that, when there is the first preset risk behavior data in the first data, the electronic device can use the AI module to perform a risk prompt operation based on the first data; or, when there is no first preset risk behavior data in the first data, the electronic device can stop collecting the first data.

[0029] In this application, after the electronic device collects the first data, it determines whether there is the first preset risk behavior data in the first data. If there is the first preset risk behavior data in the first data, the electronic device can use the AI module to determine whether the electronic device has performed a behavior with a relatively high risk based on the first data. After determining that the electronic device has performed a behavior with a relatively high risk, a risk prompt is performed to remind the user that the current behavior has a relatively high risk, ensuring the timeliness and accuracy of the risk prompt, thereby avoiding the loss of the user's resources.

[0030] In a possible implementation of the first aspect, the above user behavior data includes at least one of application startup data, screen sharing behavior data, SMS behavior data, call behavior data, call forwarding setting data, flight mode setting data, harassment interception setting data, and do not disturb setting data. The above operation data of the application includes application jump behavior data;

[0031] The above first preset risk behavior data includes at least one of preset payment application startup data, preset screen sharing data, preset application jump behavior data, preset SMS behavior data, preset call behavior data, preset call forwarding setting data, preset flight mode setting data, preset harassment interception setting data, and preset do not disturb setting data.

[0032] In this application, the electronic device can collect behavior data from multiple aspects, so as to subsequently determine from multiple aspects whether the user is induced to perform a risk operation and avoid the loss of the user's property.

[0033] In a possible implementation of the first aspect, the process of the electronic device collecting the first data may specifically include: the electronic device collects the first data within the first collection duration.

[0034] In this application, the electronic device collects the first data only within the first collection duration. In this way, it is possible to avoid unnecessary power consumption losses caused by long-term data collection and reduce the power consumption overhead of the mobile phone.

[0035] In a possible implementation manner of the first aspect, the process of the electronic device performing a risk prompt operation based on the first data may specifically include: The electronic device performs a risk prompt operation based on the first data in combination with the user profile, where the user profile is generated based on user behavior habit data, and the user behavior habit data includes at least one of user gender, user age group, user's permanent city, communication preference city, risk level, overseas contact habit, and the usage habit of the first preset application.

[0036] In this application, if the first data matches the user behavior habit data corresponding to the user profile, it means that the user often performs the behavior operation corresponding to the first data. Therefore, in order to avoid disturbing the user, the electronic device does not need to perform a risk prompt operation; if the first data does not match the user behavior habit data corresponding to the user profile, it means that the user has not performed the behavior operation corresponding to the first data. Therefore, in order to reduce the probability of the user's property being damaged, the mobile phone can perform a risk prompt operation to timely remind the user of the risk.

[0037] In a possible implementation manner of the first aspect, when the electronic device is in a charging state, the electronic device collects user behavior habit data. After that, when the electronic device is in a charging state, the electronic device generates a user profile according to the user behavior habit data.

[0038] In this application, the electronic device collects user behavior habit data and generates a user profile when it is in a charging state, which can save the power consumption of the mobile phone to the greatest extent and reduce the situation of excessive power consumption of the mobile phone due to data collection.

[0039] In a possible implementation manner of the first aspect, the above method further includes: When the first data does not have the first preset risk behavior data, the electronic device determines whether the first collection duration has ended. When the first collection duration ends, the electronic device stops collecting the first data.

[0040] In this application, if the first data does not have the first preset risk behavior data, it indicates that the electronic device has not performed a risk operation, that is, it indicates that there is no security risk such as inducing the user to consume, transfer money, borrow money, etc. Therefore, the electronic device can further determine whether the first collection duration has ended. If the first collection duration ends, it means that no risk behavior has occurred during the entire first collection duration. Therefore, the electronic device can stop collecting the first data to reduce unnecessary power consumption losses.

[0041] In a possible implementation of the first aspect, the above method further includes: when the first acquisition duration has not ended, the electronic device continues to acquire the first data.

[0042] In this application, if the first acquisition duration has not ended, it indicates that the electronic device may still perform risk operations. Therefore, in order to reduce the probability of the user's property being damaged, the electronic device also needs to continue to acquire the first data to improve the accuracy of risk detection.

[0043] In a possible implementation of the first aspect, the electronic device determines whether the second data has the first preset risk behavior data. If the second data has the first preset risk behavior data, the electronic device performs a risk prompt operation; wherein, the second data includes the above first data and the permission information of the first target application, and the first preset risk behavior data may further include preset application permission data, and the preset application permission data may include target permission data.

[0044] In this application, if the permission information of the first target application includes the target permission data, it can be determined that the permission information of the first target application belongs to the first preset risk behavior data. In this way, it can be judged whether the application has the risk of obtaining the user's private information (such as application, bank card, etc. account numbers, passwords) through the application's permission information. That is to say, if the user sets the opening of the target permission, it indicates that the risk of the user's private information being leaked is relatively high. Therefore, the mobile phone can perform a risk prompt operation after determining that the permission information of the first target application belongs to the first preset risk behavior data to prevent the loss of the user's resources (such as privacy information) and improve the security of the user using the mobile phone.

[0045] In a possible implementation of the first aspect, the process of the electronic device performing a risk prompt operation based on the first data may specifically include: the electronic device determines whether the first data has the first preset risk behavior data. When the first data has the first preset risk behavior data, the electronic device performs a risk prompt operation based on the first data in combination with the user portrait.

[0046] In this application, the electronic device performs a risk prompt operation only when the first data has the first preset risk behavior data and the first data does not match the user behavior habit data corresponding to the user portrait. In this way, the situation of disturbing the user due to incorrect reminders can be reduced, and the accuracy of risk detection can be improved.

[0047] In a possible implementation of the first aspect, the electronic device performs a risk prompt operation based on the first data in combination with the user profile. Specifically, it may include: The electronic device obtains a risk detection result based on the first data in combination with the user profile, where the risk detection result indicates whether there is any abnormal behavior data in the behavior corresponding to the first data. After that, when the risk detection result indicates that the first data has abnormal behavior data, the electronic device performs a risk prompt operation.

[0048] In this application, after the electronic device determines that the first data has the first preset risk behavior data, it can determine whether there is any abnormal behavior data in the first data according to the first data and the user profile. If the first data has abnormal behavior data, it can be explained that the behavior corresponding to the first data does not belong to the user's regular behavior, that is, the behavior corresponding to the first data has a relatively high risk of existence. Therefore, in order to reduce the probability of the user's property being damaged, the mobile phone can perform a risk prompt operation to timely remind the user of the risk.

[0049] In a possible implementation of the first aspect, the behavior corresponding to the above first data may include at least one of an operation of clicking on a screen sharing control, an operation of setting a communication blocking function, and an operation of entering a payment application or a payment interface. Among them, the operation of clicking on a screen sharing control means that the user enables the screen sharing function to perform screen sharing. The operation of entering a payment application or a payment interface means that the user clicks on the target control of a certain application, causing the mobile phone to jump from the current interface to another payment application or another payment interface. The operation of setting a communication blocking function means that the user sets a communication blocking mode to block all communications with the outside world. The communication blocking mode may include a do not disturb mode, a flight mode, a call forwarding mode, an intercepted call mode, and an intercepted text message mode.

[0050] In this application, the electronic device can judge whether the user's behavior has abnormal behavior from multiple angles. In this way, risk detection can be more accurate and the probability of missed behavior detection can be reduced.

[0051] In a possible implementation of the first aspect, the above risk prompt operation may include the electronic device displaying a first risk prompt message and / or sending a second risk prompt message to a target contact.

[0052] In this application, the electronic device can use multiple methods to perform risk prompts, realizing dual risk prompts. In this way, the user can be timely reminded of the risk, and the probability of the user's property being damaged can be reduced. In addition, sending a second risk prompt message to the target contact can timely dissuade the mobile phone user from performing a payment operation through the target contact, thereby avoiding damage to the user's property.

[0053] In a possible implementation of the first aspect, when the risk detection result indicates that the first data has abnormal behavior data, the electronic device performs a risk prompt operation, which may specifically include: when the risk detection result indicates that the behavior corresponding to the first data is risky, a first risk prompt is performed. After that, the electronic device can collect application startup data and determine whether the application startup data is second preset risk behavior data. If the application startup data is second preset risk behavior data, the electronic device performs a second risk prompt. Among them, the first risk prompt may be that the electronic device displays a first risk prompt message, and the second risk prompt may be sending a second risk prompt message to a target contact.

[0054] In this application, when the electronic device detects that a payment application has been started on the electronic device, it is considered that the mobile phone may be about to perform a payment behavior. Therefore, the electronic device can perform a second risk prompt when the collected application startup data is second preset risk behavior data. In this way, timely and accurate risk prompts can be achieved, and the probability of the user's property being damaged can be reduced.

[0055] In a possible implementation of the first aspect, when the risk detection result indicates that the first data has abnormal behavior data, the electronic device performs a risk prompt operation, which may specifically include: when the risk detection result indicates that the behavior corresponding to the first data is risky, the electronic device determines target data from the first data belonging to the first preset risk behavior data, and collects application startup data within the second collection duration corresponding to the target data. After that, the electronic device determines whether the application startup data is second preset risk behavior data. If the application startup data is second preset risk behavior data, the electronic device performs a second risk prompt.

[0056] In this application, if the behavior corresponding to the first data is risky, the collection duration will be updated accordingly to continue collecting application startup data, and a second risk prompt will be performed after determining that the application startup data is second preset risk behavior data. In this way, application startup data can be collected in a targeted manner, not only reducing unnecessary power consumption losses caused by too long a collection duration, but also reducing the occurrence of missed data collection due to too short a collection duration.

[0057] In a possible implementation of the first aspect, for the electronic device to determine target data from the first data belonging to the first preset risk behavior data, it may specifically include: the electronic device determines the data quantity of the first data belonging to the first preset risk behavior data in the first data. After that, when there is one piece of data in the first data belonging to the first preset risk behavior data, the electronic device can directly determine the first data belonging to the first preset risk behavior data as the target data.

[0058] In this application, if the number of the first data belonging to the first preset risk behavior data is one, the electronic device can directly determine the first data belonging to the first preset risk behavior data as the target data. In this way, the accuracy of determining the target data can be improved, providing a basis for determining the second acquisition duration subsequently.

[0059] In a possible implementation manner of the first aspect, the above method further includes: when there are multiple data belonging to the first preset risk behavior data among the first data, the electronic device can determine the last acquired data among the multiple data as the target data.

[0060] In this application, if the number of the first data belonging to the first preset risk behavior data is multiple, the electronic device can determine the last acquired data among the multiple data as the target data. In this way, the accuracy of determining the target data can be improved, providing a basis for determining the second acquired data subsequently.

[0061] In a possible implementation manner of the first aspect, the above method further includes: when there are multiple data belonging to the first preset risk behavior data among the first data, the electronic device can determine the first data with the longest second acquisition duration as the target data.

[0062] In this application, if the number of the first data belonging to the first preset risk behavior data is multiple, the electronic device can determine the first data with the longest second acquisition duration among the multiple data as the target data. In this way, the accuracy of determining the target data can be improved, providing a basis for determining the second acquired data subsequently.

[0063] In a possible implementation manner of the first aspect, the above method further includes: when the above application start data does not belong to the second preset risk behavior data, the electronic device may not perform the second risk prompt.

[0064] In this application, if the application start data does not belong to the second preset risk behavior data, it means that the behavior corresponding to the application start data does not have a risk, that is, it indicates that there is no risk of inducing user transactions currently. Therefore, in order to avoid causing trouble to others, the electronic device does not need to perform the second risk prompt.

[0065] In a possible implementation manner of the first aspect, the above method further includes: when the above application start data does not belong to the second preset risk behavior data, the electronic device determines whether the second acquisition duration has ended. If the second acquisition duration has ended, the electronic device can stop acquiring the application start data.

[0066] In this application, if the application startup data does not belong to the second preset risk behavior data, it indicates that the behavior corresponding to the application startup data does not pose a risk, that is, there is no risk of inducing user transactions currently. Therefore, the electronic device can further determine whether the second collection duration has ended. If the second collection duration has ended, it means that no risk behavior has occurred during the entire second collection duration. Therefore, the electronic device can stop collecting the second data to reduce unnecessary power consumption losses.

[0067] In a possible implementation manner of the first aspect, the above method further includes: when the second collection duration has not ended, the electronic device continues to collect application startup data.

[0068] In this application, if the second collection duration has not ended, it means that the electronic device may still perform risk operations. Therefore, in order to reduce the probability of the user's property being damaged, the electronic device also needs to continue to collect application startup data to improve the accuracy of risk detection.

[0069] In a possible implementation manner of the first aspect, the above method further includes: when the risk detection result indicates that the first data does not contain unconventional behavior data, the electronic device does not perform a risk prompt operation.

[0070] In this application, if the risk detection result indicates that the first data does not contain unconventional behavior data, it means that the risky operation performed by the mobile phone belongs to the user's normal operation, and this operation does not belong to a risk operation. Therefore, the mobile phone does not need to give a risk prompt to the user to avoid affecting the user's use.

[0071] In a second aspect, this application provides an electronic device, which includes a display screen, a memory, and one or more processors; the display screen, the memory, and the processor are coupled; the display screen is used to display the images generated by the processor, the memory is used to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the electronic device is caused to execute the method as described above.

[0072] In a third aspect, this application provides a computer-readable storage medium, including computer instructions, which when running on an electronic device, cause the electronic device to execute the method as described above.

[0073] In a fourth aspect, this application provides a computer program product, which when running on an electronic device, causes the electronic device to execute the method as described above.

[0074] In a fifth aspect, a chip is provided, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is configured to execute the code in the memory. When the code is executed, the processor is configured to execute the method as described above.

[0075] Among them, for the beneficial effects that can be achieved by the electronic device described in the second aspect, the computer-readable storage medium described in the third aspect, the computer program product described in the fourth aspect, and the chip described in the fifth aspect provided above, reference can be made to the beneficial effects in the first aspect and any possible design manner thereof, which will not be elaborated herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0076] Figure 1 FIG. [X] is a schematic diagram of an interface for displaying spam messages provided by an embodiment of the present application;

[0077] Figure 2 FIG. [X] is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present application;

[0078] Figure 3 FIG. [X] is a schematic diagram of the software structure of an electronic device provided by an embodiment of the present application;

[0079] Figure 4 FIG. [X] is a schematic diagram of the software structure of another electronic device provided by an embodiment of the present application;

[0080] Figure 5 FIG. [X] is a schematic diagram of the flow of a risk prompt method provided by an embodiment of the present application;

[0081] Figure 6 FIG. [X] is a schematic diagram of an interface for a call from a risk number provided by an embodiment of the present application;

[0082] Figure 7 FIG. [X] is a schematic diagram of an interface for setting a text message interception rule provided by an embodiment of the present application;

[0083] Figure 8 FIG. [X] is a flowchart of intercepting a target text message according to a set text message interception rule provided by an embodiment of the present application;

[0084] Figure 9 FIG. [X] is a schematic diagram of an interface for triggering a text message list provided by an embodiment of the present application;

[0085] Figure 10 FIG. [X] is a schematic diagram of an operation detection process provided by an embodiment of the present application;

[0086] Figure 11 FIG. [X] is a schematic diagram of an interface for triggering a call operation in a target text message provided by an embodiment of the present application;

[0087] Figure 12 A flowchart of a method for collecting first data provided by an embodiment of the present application;

[0088] Figure 13 A schematic diagram of an interface for displaying a risk reminder on a do not disturb settings interface provided by an embodiment of the present application;

[0089] Figure 14 A schematic diagram of the relationship between a user behavior process and a risk level provided by an embodiment of the present application;

[0090] Figure 15 A schematic diagram of an application installation interface provided by an embodiment of the present application. Detailed implementation manners

[0091] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. Among them, in the description of the present application, unless otherwise specified, "and / or" in the present application is only an association relationship describing associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. These three situations, where A and B may be singular or plural. Also, in the description of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or a similar expression thereof refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, c may be single or multiple. In addition, in order to clearly describe the technical solutions in the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that the terms "first", "second", etc. do not limit the quantity and execution order, and the terms "first", "second", etc. do not necessarily limit to be different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present related concepts in a specific way for easy understanding.

[0092] In some embodiments, when receiving a text message sent from a number other than the contacts in the address book (or called an unfamiliar number), the user may perform a trigger operation on the text message sent from the unfamiliar number. In response to the user's trigger operation on the text message, the electronic device performs the action corresponding to the trigger operation. Since the text message sent from an unfamiliar number may pose a security risk and be illegal, the trigger operation initiated for such a text message may lead to the leakage of the user's private information (such as the user's account number and payment password), resulting in the loss of the user's resources (such as property), thereby affecting the user experience.

[0093] Exemplarily, the above trigger operation may include at least one of a reply operation for the above text message, a dialing operation for the sender of the above text message, an access operation for the website in the above text message, and a copying operation for the target information in the above text message. Among them, the target information may be a website, a mobile phone number, a social account, a bank card account, etc. It should be understood that any information that may cause losses to the user's resources in this application can be used as the target information, and there is no specific limitation. The social account is the account information in a social application (APP).

[0094] For example, taking the above trigger operation as a dialing operation for the sender of the above text message as an example, the process in which the user's resources are lost due to the user dialing the recipient's number is generally as follows: The user views the text message with a risky sender number through an electronic device (such as a mobile phone). After viewing the text message, if the mobile phone receives the user's dialing operation for the sender number to which the text message belongs, the mobile phone dials the sender number. During the call, the user may be induced to install a specific application (such as a meeting APP, a payment APP, a bank APP, a wealth management APP, etc.) on the mobile phone, start the specific application, and perform corresponding processing through the specific application, such as sharing the screen through the meeting APP, accessing a malicious website through the browser on the mobile phone, and performing a loan operation through the specific application, resulting in the leakage of the user's private information and / or the loss of the user's property.

[0095] Another example is taking the above trigger operation as a copying operation for the social account in the above text message. The process in which the user's resources are lost due to the user copying the social account is generally as follows: The user views the text message with a risky sender number through an electronic device (such as a mobile phone). After viewing the text message, if the mobile phone receives the user's copying operation for the social account in the text message, the mobile phone copies the social account and adds the social account in the social APP corresponding to the social account in response to the user's addition operation. After the addition is successful, the sender may induce the user to perform a risky behavior through chatting, such as inducing the user to install a specific application required by the sender. The specific application may be an application with a security risk, thereby causing losses to the user's property through the specific application.

[0096] In some embodiments, to reduce the risk of property loss caused by a user performing a triggering operation on a text message sent from an unfamiliar number, the relevant center and / or the system steward in the electronic device identify such unfamiliar numbers as numbers with security risks, mark the numbers with security risks as blacklisted numbers, and store the marked blacklisted numbers in a blacklist database. Subsequently, the electronic device activates the telecommunications risk protection function to intercept the blacklisted numbers (or called intercepted numbers) in the blacklist database, so as to prevent the user from receiving text messages sent from the blacklisted numbers, thereby directly preventing the user from contacting the calling user corresponding to the blacklisted number.

[0097] For example, please refer to Figure 1 , mobile phone A intercepted spam messages with the calling number "131****2233" on April 2 and intercepted spam messages with the calling number "131****5522" on May 4. It can be understood that the calling numbers "131****5522" and "131****2233" are blacklisted numbers in the blacklist database. After the mobile phone receives text messages from these two numbers, it can directly intercept them to prevent the user's property from being lost.

[0098] However, the blacklisted numbers in the blacklist database have timeliness and limitations. Although some numbers belong to suspicious numbers (or have security risks), the suspicious numbers have not been added to the blacklist database for the time being. Then, when the electronic device receives text messages from these suspicious numbers, the electronic device cannot intercept the text messages, and the user can still receive the text messages, which may still induce the user to perform some risk operations (such as screen sharing, accessing malicious websites, taking loans, etc.) on the electronic device, thereby causing the user's property to be lost.

[0099] To address the above problems, considering that behaviors such as inducing the user to consume, transfer money, take loans, etc., which pose risks to the user's life and property safety, generally require communication events such as sending text messages, and text messages that have been marked as blacklisted numbers will be directly intercepted. Therefore, this application only performs risk detection on numbers other than blacklisted numbers and safe numbers. And considering that the process of inducing the user to perform security risk behaviors includes the process of the user operating on a specific application, the embodiments of this application provide a risk prompt method. First, the electronic device receives a communication event; wherein, the communication event includes an incoming call event (hereinafter simply referred to as an incoming call) and / or a preset text event (hereinafter simply referred to as a text message). The electronic device determines whether the sender number corresponding to the preset text event belongs to an unfamiliar number.

[0100] Among them, the communication number represents the sending number corresponding to the communication event. When the communication event is a preset text event, the sender number corresponding to the preset text event can also be referred to as the sender number. When the communication event is an incoming call event, the communication number corresponding to the incoming call event can be referred to as the incoming call number or the calling number.

[0101] After that, when the sender number corresponding to the preset text event belongs to an unfamiliar number and the first interaction behavior meets the preset first trigger condition, the electronic device can start to detect whether there is a risk of the user's property being damaged, such as starting to collect the user's behavior data and / or the running data of the applications in the electronic device; after that, the electronic device can perform a risk prompt based on the collected user's behavior data and / or the running data of the applications in the electronic device to achieve timely risk prompting.

[0102] Among them, the first interaction behavior may include at least one of calling the sender number, replying to the information corresponding to the preset text event, accessing the link address in the preset text event, and copying the text content in the preset text event. The above preset text event is a text event received that contains text content conforming to the preset text content, and the preset text is text content with a text length less than the preset length.

[0103] It can be understood that the above preset text event can be a preset text sent by the sender number, that is, a text message event, or a preset text sent by an unfamiliar account in a social application, or a preset text pushed by an unfamiliar application, etc., and no specific limitation is made.

[0104] Exemplarily, the above electronic device can be any device with a call function, such as a mobile phone, a tablet computer, a wearable device (such as a smart watch, a bracelet), etc., and the specific type of the electronic device is not limited in any way in the embodiments of the present application.

[0105] Figure 2 It is a schematic diagram of the hardware structure of the electronic device 100 provided by the embodiments of the present application, such as Figure 2As shown, the electronic device 100 may include a processor 110, antenna 1, antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a sensor module 180, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, a button 190, an indicator 192, a display screen 194, and a subscriber identification module (SIM) card interface 1-N 195, etc. Among them, the sensor module 180 may include a pressure sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, etc.

[0106] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or combine certain components, or split certain components, or have different component arrangements. The components shown may be implemented in hardware, software, or a combination of software and hardware.

[0107] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0108] Among them, the controller may be the nerve center and command center of the electronic device 100. The controller may generate operation control signals according to the instruction operation code and timing signal to complete the control of fetching and executing instructions.

[0109] A memory can also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can hold the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can directly call it from the said memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.

[0110] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, etc.

[0111] The I2S interface can be used for audio communication. In some embodiments, the processor 110 may include multiple groups of I2S buses. The processor 110 can be coupled to the audio module 170 through the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit an audio signal to the wireless communication module 160 through the I2S interface to implement the function of answering a call through a Bluetooth headset.

[0112] The PCM interface can also be used for audio communication to sample, quantize, and encode analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled through the PCM bus interface. In some embodiments, the audio module 170 can also transmit an audio signal to the wireless communication module 160 through the PCM interface to implement the function of answering a call through a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.

[0113] The wireless communication function of the electronic device 100 can be implemented through antenna 1, antenna 2, the mobile communication module 150, the wireless communication module 160, the modulation and demodulation processor, and the baseband processor, etc.

[0114] Antenna 1 and Antenna 2 are used for transmitting and receiving electromagnetic wave signals. Each antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, Antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0115] The mobile communication module 150 can provide solutions for wireless communications such as 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 can include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves through Antenna 1, filter, amplify, and process the received electromagnetic waves, and then transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor and convert it into electromagnetic waves through Antenna 1 for radiation. In some embodiments, at least some functional modules of the mobile communication module 150 can be disposed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 can be disposed in the same device.

[0116] The modulation and demodulation processor can include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. Subsequently, the demodulator transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, receiver 170B, etc.), or displays an image or video through the display screen 194. In some embodiments, the modulation and demodulation processor can be an independent device. In some other embodiments, the modulation and demodulation processor can be independent of the processor 110 and be disposed in the same device as the mobile communication module 150 or other functional modules.

[0117] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling electronic device 100 to communicate with a network and other devices via wireless communication technologies. The wireless communication technologies may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time-Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include Global Positioning System (GPS), Global Navigation Satellite System (GLONASS), BeiDou Navigation Satellite System (BDS), Quasi-Zenith Satellite System (QZSS), and / or Satellite Based Augmentation Systems (SBAS).

[0118] It can be understood that the interface connection relationships between the modules illustrated in the embodiments of the present invention are only illustrative and do not constitute a structural limitation on electronic device 100. In other embodiments of the present application, electronic device 100 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.

[0119] Charging management module 140 is configured to receive a charging input from a charger. While charging management module 140 charges battery 142, it can also supply power to electronic device 100 through power management module 141.

[0120] The electronic device 100 implements the display function through the GPU, the display screen 194, the application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to execute mathematical and geometric calculations for graphics rendering. The processor 110 may include one or more GPUs, which execute program instructions to generate or change display information.

[0121] The display screen 194 is used to display images, videos, etc. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than 1.

[0122] The electronic device 100 can implement the shooting function through the video codec, the GPU, the display screen 194, the application processor, etc.

[0123] The electronic device 100 can implement the audio function through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack, and the application processor, etc. Such as music playback, recording, etc.

[0124] The audio module 170 is used to convert digital audio information into an analog audio signal for output, and is also used to convert analog audio input into a digital audio signal. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 can be set in the processor 110, or some functional modules of the audio module 170 can be set in the processor 110.

[0125] The speaker 170A, also known as the "loudspeaker", is used to convert an audio electrical signal into a sound signal. The electronic device 100 can listen to music or hands-free calls through the speaker. The receiver 170B, also known as the "earpiece", is used to convert an audio electrical signal into a sound signal. When the electronic device 100 answers a call or a voice message, it can listen to the voice by bringing the receiver 170B close to the ear. The microphone 170C, also known as the "microphone", "transmitter", is used to convert a sound signal into an electrical signal. When making a call or sending a voice message, the user can speak by bringing the mouth close to the microphone 170C to input the sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C.

[0126] The headphone jack is used to connect a wired headphone. The headphone jack can be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0127] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to implement the storage capacity expansion of the electronic device 100.

[0128] The internal memory 121 can be used to store computer-executable program codes, and the executable program codes include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 can include a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.). The data storage area can store data created during the use of the electronic device 100 (such as audio data, a phone book, etc.). In addition, the internal memory 121 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.

[0129] The keys 190 include a power-on key, volume keys, etc. The keys 190 can be mechanical keys or touch keys. The electronic device 100 can receive key inputs and generate key signal inputs related to the user settings and function controls of the electronic device 100. The indicator 192 can be an indicator light.

[0130] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation from the electronic device 100. The electronic device 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. It can be understood that the electronic device can receive incoming calls and / or text messages only when the SIM card is connected to the electronic device 100.

[0131] Figure 3 It is a software structure block diagram of the electronic device 100 according to an embodiment of the present application. The layered architecture divides the software into several layers, and each layer has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom, namely the application layer (referred to as the application layer for short), the application framework layer (referred to as the framework layer for short), the Android runtime, and the system library, and the kernel layer (or called the driver layer). The application layer can include a series of application program packages.

[0132] Such as Figure 3As shown, the application package may include a phone, a short message, a social application, a payment application, a browser, a clipboard, a communication module, a system manager, and an artificial intelligence (AI) module, etc. Among them, the clipboard is an area in the memory of the electronic device, which is used to temporarily store data and provide a module for sharing functions. That is to say, through the clipboard, the copied content can be stored in the memory of the electronic device, which provides convenience for subsequent use of this content.

[0133] The above-mentioned communication module is used to mark unfamiliar numbers. Specifically, in response to the user's marking operation on an unfamiliar number, the communication module in the electronic device marks the unfamiliar number to obtain the marked number. Among them, the marked number carries the user's marking information, and the marking information is used to indicate the number type of the current number, and the number may include a contact number, an advertising and promotion number, a harassing call, etc.

[0134] The above-mentioned system manager is used to schedule and manage the system. In some embodiments, the system manager can be connected to the AI module. The system manager can collect suspicious text messages and suspicious behaviors, and interact with the AI module about the collected suspicious text messages and suspicious behaviors, so that the subsequent AI module can identify based on the suspicious text messages and suspicious behaviors. In other embodiments, the system manager can also determine whether the calling number and / or the sending number is a number in the blacklist, so as to further determine whether it is necessary to intercept the call corresponding to the calling number and / or the text message corresponding to the sending number, thereby avoiding losses to the user's resources. In still other embodiments, the system manager can also control suspicious behaviors, and when the suspicious behavior is a preset risk behavior, output a risk prompt message to timely remind the user, thereby reducing the probability of the user's property being damaged.

[0135] It should be understood that the suspicious text messages in this application may refer to text messages that may have security risks, and the suspicious behaviors may refer to behaviors that may have security risks.

[0136] The above AI module can be used to identify suspicious behaviors and suspicious text messages. For example, the AI module can include an AI model, which can be used to identify whether the current behavior of the user is a preset risk behavior. The input parameter of the AI model is the current behavior of the user, and the output parameter of the AI model is the risk level. That is to say, through this AI module, it can be determined whether the current behavior is a behavior with security risks. In some embodiments, the AI module can store the behavior data of the user to facilitate subsequent parameter adjustment of the AI model in the AI module based on the behavior data, thereby improving the accuracy of risk prediction. In other embodiments, the AI module can identify the above-mentioned suspicious text messages and suspicious behaviors to determine the possibility of current suspicious risks, so as to timely remind the user and avoid losses to the user's property.

[0137] It should be understood that the risk level in this application is used to indicate the probability that the current behavior of the user is a risk behavior. That is to say, the higher the risk level, the higher the possibility that the current behavior of the user is a risk behavior, that is, the higher the possibility that the user is induced. The above AI model is used to detect the risk of the current behavior of the user to determine whether the current behavior of the user is a preset risk behavior.

[0138] The application framework layer provides application programming interfaces (APIs) and programming frameworks for the applications in the application layer. The application framework layer includes some predefined functions. Such as Figure 3 shown, the application framework layer can include a window manager service (WMS), a content provider, a notification manager, a view system, a resource manager, and a behavior sequence collector, etc.

[0139] Among them, the window manager is used to manage window programs. The window manager can obtain the size of the display screen, determine whether there is a status bar, lock the screen, capture the screen, etc. The content provider is used to store and obtain data, and make these data accessible to applications. The data can include videos, images, audio, dialed and answered calls, browsing history and bookmarks, phone books, etc.

[0140] The notification manager enables applications to display notification information in the status bar. It can be used to convey message types of notifications, and can automatically disappear after a short stay without user interaction. In some embodiments, in the case of receiving an incoming call, the notification manager is used to notify the incoming call reminder. Or, in the case of receiving a text message, the notification manager is used to notify the text message reminder.

[0141] The view system includes visual controls, such as controls for displaying text, controls for displaying pictures, etc. The view system can be used to build applications. The display interface can be composed of one or more views. The resource manager provides various resources for the application, such as localized strings, icons, pictures, layout files, video files, and so on.

[0142] The behavior sequence collector is used to collect the behavior sequences of logical function modules such as WMS and notification, and report the behavior sequences that need to be reported to the system steward at the application layer. In some embodiments, when receiving an interaction operation (or referred to as the first interaction behavior) of the user on the electronic device, the behavior sequence collector can collect the interaction operation and send the collected interaction operation to the system steward to determine whether the interaction operation is a risk behavior.

[0143] Android runtime includes a core library and a virtual machine. Android runtime is responsible for the scheduling and management of the Android system. The core library consists of two parts: one part is the functional functions that need to be called by the Java language, and the other part is the core library of Android.

[0144] The application layer and the application framework layer run in the virtual machine. The virtual machine executes the Java files of the application layer and the application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.

[0145] The system library can include multiple functional modules. For example: surface manager, 3D graphics processing library (such as: OpenGL ES), 2D graphics engine (such as: SGL), media libraries, etc.

[0146] The surface manager is used to manage the display subsystem and provides the fusion of 2D and 3D layers for multiple applications. The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, synthesis, and layer processing, etc. The 2D graphics engine is the drawing engine for 2D drawing.

[0147] The kernel layer is the layer between the hardware and the software. The kernel layer at least includes a display driver, a camera driver, an audio driver, a sensor driver, etc.

[0148] It can be understood that Figure 3 The layers in the shown structure and the components included in each layer do not constitute a specific limitation on the electronic device 100, that is, the mobile phone. In other embodiments of the present application, the structure may include more or fewer layers than shown, and each layer may include more or fewer components, which are not limited in the present application.

[0149] It should be noted that Figure 3 when the system steward judges whether the calling number and / or the sending number is a number in the blacklist, the blacklist involved can be obtained from the cloud side. And the AI model included in the artificial intelligence module can also be obtained from the cloud side. Specifically, as Figure 4 shown, this technical solution can be deployed on the cloud side and the terminal side, and the combination of the cloud and the terminal is used to realize risk identification. Among them, the cloud side is the cloud side server, and the terminal side is the electronic device.

[0150] Among them, the cloud side server can set up a security cloud platform and a smart cloud platform.

[0151] The above-mentioned security cloud platform can include the above-mentioned blacklist. In some embodiments, the blacklist can include black numbers. In other embodiments, the blacklist can also include black URL addresses and / or black applications. Specifically, the above-mentioned security cloud platform is used to store the above-mentioned blacklist and send the stored blacklist to the system steward on the terminal side for the system steward to judge whether the calling number and / or the sending number is a number in the blacklist.

[0152] The above-mentioned smart cloud platform includes a parameter configuration unit and a machine learning platform. Among them, the machine learning platform is used to summarize various illegal behavior sequences reported from the terminal side, obtain training samples after calibration, and then perform feature calculations on these training samples for model training to obtain a trained AI model, and use the trained AI model for inference and prediction to verify the accuracy of the AI model in the artificial intelligence module on the terminal side for risk detection. The parameter configuration unit is used to configure the parameters of the AI model in the artificial intelligence module on the terminal side and send the configured parameters to the artificial intelligence module on the terminal side to realize the update function of the AI model.

[0153] It should be noted that the above-mentioned smart cloud platform and security cloud platform can be set on different cloud side servers respectively, or can be set on the same cloud side server. The embodiments of this application do not make any limitations on this.

[0154] The terminal side can include multiple electronic devices, and these multiple electronic devices can share various rules, lists, and recognition results on the cloud side. Taking one of the electronic devices as an example, the application layer of this electronic device can install a system steward and set up a communication module and an artificial intelligence module. Among them, the system steward and the AI module can provide a set of security services. The system steward is used to schedule and manage the system. The AI module is used to identify suspicious behaviors and suspicious text messages. Exemplarily, the above-mentioned AI model is included in the AI module.

[0155] Specifically, the above communication module may include a number marking unit. The number marking unit is used to mark unfamiliar numbers. The above system steward includes a text message collection unit, a behavior collection unit, a number query unit, and a risk reminder unit. The text message collection unit is used to collect suspicious text messages. The behavior collection unit is used to collect suspicious behaviors. The number query unit is used to query whether the calling number and / or the sending number is a number in the blacklist. The risk reminder unit is used to control suspicious behaviors, and when the suspicious behavior is a preset risk behavior, output a risk reminder message to timely remind the user, thereby reducing the probability of the user's property being damaged. The above artificial intelligence module may include a data storage unit, a behavior recognition unit, and a text message recognition unit. The data storage unit is used to store the user's behavior data, so as to adjust the parameters of the AI model in the AI module according to the behavior data subsequently, thereby improving the accuracy of risk prediction. The behavior recognition unit is used to perform risk recognition on the user's current behavior to determine whether the user's current behavior is a behavior with security risks. The text message recognition unit is used to perform risk recognition on the received text message to determine whether the text message is a text message with security risks.

[0156] The risk reminder method provided by the embodiments of the present application can be applied to scenarios of communication events (such as incoming calls, text messages) received from unfamiliar numbers. Below, taking the electronic device as a mobile phone and the specific Figure 3 system architecture shown, and the communication event as a text message as an example, the method of the embodiments of the present application will be described. Figure 5 It is a flowchart of the risk reminder method provided by the present application. As Figure 5 shown, the method may include S501 - S513:

[0157] S501, the system steward in the mobile phone receives the target text message.

[0158] Exemplarily, the sending number of the target text message may include any number such as a safe number, a black number, a suspicious number, an unfamiliar number, etc.

[0159] Among them, the black number refers to the number in the black number library, and the black number library includes the numbers directly intercepted provided by the relevant center and / or the system steward in the electronic device.

[0160] The safe number means a number that will not cause damage to the user's resources (such as property), that is, it is not a risk number. For example, the safe number may include the contact number and the number marked with the first preset label. The first preset label includes labels such as express delivery, takeout, customer service, etc. that have nothing to do with behaviors with security risks.

[0161] A strange number refers to all unknown numbers other than blacklisted numbers and contact numbers. In other words, the strange number includes the above-mentioned suspicious numbers and numbers marked with a first preset label. That is, some numbers marked with a first preset label that may pose risks and may induce users to perform risky operations are regarded as strange numbers.

[0162] A suspicious number refers to a number other than blacklisted numbers and safe numbers, which may include numbers marked with a second preset label. Among them, the second preset label may include labels related to behaviors with security risks. Behaviors with security risks may include behaviors that induce users to consume, transfer money, borrow money, etc., which may pose risks to the life and property safety of users. Simply put, the second preset label is a label other than the above-mentioned first preset label.

[0163] In some embodiments, the above-mentioned suspicious numbers may also include numbers corresponding to risk levels, and the risk levels may include at least one of high, medium, and low levels. Of course, the risk levels may also be characterized by other values, such as the first level, the second level, etc., and the present application does not limit them.

[0164] The numbers corresponding to the above-mentioned risk levels may be provided by a relevant center. The numbers marked with the second preset label may be provided by the system manager in the mobile phone. Specifically, the numbers marked with the second preset label may be recorded by the system manager in the mobile phone based on the number labels marked by the user. It can be understood that in the case of receiving a call or text message from a strange number, in response to the user's marking operation for the strange number, the system manager may generate a number label, that is, generate the number label marked by the user.

[0165] It can be understood that a suspicious number is a number that has certain risks but has not been added to the blacklist, that is, it does not belong to the blacklist yet. For example, see Figure 6 As shown, mobile phone F receives a call from the caller number "189****4444", and the caller number "189****4444" has been marked as a risk number by 200 people. Although the caller number "189****4444" has been marked as a risk number by 200 people, the caller number "189****4444" has not been added to the blacklist yet. The risk label corresponding to the caller number "189****4444" belongs to the second preset label. That is to say, the caller number "189****4444" belongs to the suspicious numbers.

[0166] S502, when it is determined that the sender number of the above-mentioned target text message does not belong to a safe number, the system manager determines whether to intercept the above-mentioned target text message according to the preset text message interception rule.

[0167] Specifically, after the system manager in the mobile phone receives the above-mentioned target text message, it can obtain the text message data of the target text message. Among them, the text message data of the target text message may include the sender number corresponding to the target text message.

[0168] In some embodiments, the text message data of the above-mentioned target text message may further include other data, such as call location, operator and other information.

[0169] In one implementation, after the system manager obtains the text message data of the above-mentioned target text message, it can determine the number type of the sender number corresponding to the target text message. If the sender number is a safe number, it means that the target text message will not induce the user to perform some risky operations, that is, it means that the content of this text message is safe, and it also means that the target text message is a text message without security risks. Therefore, when the mobile phone receives the target text message, there is no need to determine whether the target text message will induce the user to perform risky operations, that is, there is no need to perform risk detection. The mobile phone can normally display the target text message. In this way, unnecessary power consumption losses can be reduced. If the sender number is not a safe number, it means that the target text message may induce the user to perform some risky operations, that is, it means that the content of this text message may have security risks. Therefore, the system manager can determine whether to intercept the target text message according to the preset text message interception rules to avoid losses to user resources.

[0170] In another implementation, after the system manager obtains the text message data of the above-mentioned target text message, it can send the text message data of the target text message to the cloud service for subsequent determination of the number type of the sender number corresponding to the target text message. After that, when the cloud service determines that the sender number corresponding to the above-mentioned target text message is a safe number, it can send a browsing instruction to the system manager, where the browsing instruction indicates that the sender number is a safe number. The system manager triggers the display operation of the target text message and does not need to monitor the user's subsequent trigger behavior. After the system manager receives the above-mentioned browsing instruction, it can directly display the above-mentioned target text message according to the user's viewing operation. That is to say, the process of determining whether the sender number is a safe number can be directly determined by the system manager, or it can be a process in which the cloud service makes a judgment and then sends the judgment result to the system manager, and the specific is not limited.

[0171] In some embodiments, after the system manager determines that the sender number corresponding to the above-mentioned target text message does not belong to a safe number, it can determine whether to intercept the target text message according to the above-mentioned preset text message interception rules. Among them, the preset text message interception rules can be set by the system by default, or can be set by the user according to their own needs, and the specific is not limited.

[0172] In one implementation, the SMS interception rules can be preset in the electronic device. Before receiving the target SMS, if it is detected that the user performs a setting operation on the SMS interception rules, the system manager in the mobile phone can respond to the setting operation and determine whether the target SMS needs to be intercepted according to the set SMS interception rules. Among them, the SMS interception rules can include at least one of the harassment interception function, the function of intercepting all numbers, the white list, the black list, the function of intercepting unknown / hidden numbers, the function of intercepting strange SMS, and the intelligent interception function. The function of intercepting all numbers refers to the function of intercepting all numbers except those in the white list and the security numbers. An unknown number refers to a number with an unknown place of origin, that is, the mobile phone cannot obtain the place of origin of the sender's number. The intelligent interception function is the function of judging whether to intercept the target SMS by identifying the content contained in the target SMS.

[0173] Exemplarily, as Figure 7 shown, Figure 7 the interface (a) in is the interception rule interface. Among them, the interception rule interface can include controls such as "Call Interception Rules", "SMS Interception Rules" control 701, "Black List" control, "White List" control, and "Interception Notification" control. For example, if the "Black List" control is clicked by the user, it means that the user wants to add a number to the black list. Therefore, the mobile phone can perform the setting operation of the black list according to the number added by the user.

[0174] Again, for example, if the "SMS Interception Rules" control 701 is clicked by the user, it means that the user wants to set the interception rules for receiving SMS. The mobile phone can display the detailed interface for setting the SMS interception rules, that is, display the Figure 7 interface (b) in. Among them, the setting interface includes settings such as separate settings for dual SIM cards, harassment interception, intercepting all numbers, intercepting unknown / hidden numbers, intercepting strange SMS, and intelligent interception. After any interception setting item in the setting interface is clicked by the user, the mobile phone can control the corresponding interception function of the clicked interception setting item to be turned on or off. For example, if the "Harassment Interception" setting item is clicked, it means that the user wants to turn on the harassment interception function. Therefore, the mobile phone can turn on the harassment interception function according to the user's click operation. Again, for example, if the "Intercept Strange SMS" setting item is clicked, it means that the user wants to turn off the function of intercepting strange SMS. Therefore, the mobile phone can turn off the function of intercepting strange SMS according to the user's click operation.

[0175] It should be noted that the above Figure 7The shown setting interface for interception rules is only an example, and users can also control the enabling or disabling of the interception function in other ways. For example, the mobile phone can directly display the "SMS Interception Rules" setting item, so that users can directly agree to control the enabling or disabling of all interception functions in the SMS interception rules. That is to say, if the "SMS Interception Rules" setting item is clicked by the user, all interception functions included in the SMS interception rules will be enabled or disabled.

[0176] It can be understood that if the sender number corresponding to the above target SMS is a number that can be intercepted in the SMS interception rules, the system manager can intercept the target SMS. If the sender number corresponding to the above target SMS is not a number that can be intercepted in the SMS interception rules, or the sender number is a number in the white list of the SMS interception rules, the system manager can not intercept the target SMS.

[0177] In one implementation, when the sender number corresponding to the above target SMS meets the preset SMS interception rules, it means that the sender number is intercepted by the interception function enabled by the user. Therefore, the system manager can intercept the target SMS. When the sender number corresponding to the above target SMS does not meet the preset SMS interception rules, it means that the sender number is not intercepted by the interception function enabled by the user. Therefore, the system manager can not intercept the target SMS, that is, the mobile phone can display the target SMS for the user to view the target content.

[0178] Among them, the above preset SMS interception rules are determined based on the phone numbers added by the user in the white list and the black list and / or whether the target interception function is enabled. The target interception function includes at least one of the harassment interception function, the function of intercepting all numbers, the function of intercepting unknown / hidden numbers, the function of intercepting strange SMS, and the intelligent interception function.

[0179] It should be noted that the above-mentioned target interception function may include a combination of one or more of the above. If the target interception function includes multiple items and these multiple target interception functions are enabled simultaneously, the system manager can make judgments simultaneously, which can be made in a preset order, and the specific order is not limited. In one example, the preset order may be to first synchronously execute the interception operations corresponding to the harassment interception function, the function of intercepting all numbers, the whitelist, the blacklist, the function of intercepting unknown / hidden numbers, and the function of intercepting strange text messages, and then execute the interception operation corresponding to the intelligent interception function. Specifically, after receiving the target text message, the system manager can first sequentially determine whether it is necessary to intercept the above-mentioned target text message based on whether the harassment interception function, the function of intercepting all numbers, the whitelist, the blacklist, the function of intercepting unknown / hidden numbers, and the function of intercepting strange text messages are enabled. If the target text message is intercepted, it means that the user will not view the target text message, that is, the situation of resource loss will not occur. Therefore, the system manager can not execute the interception operation of the intelligent interception. If the target text message is not intercepted and the intelligent interception function is enabled, the system manager can continue to execute the interception operation corresponding to the intelligent interception function to avoid resource loss of the user. In this way, the interception efficiency of the target text message can be improved and the interception time can be reduced.

[0180] In another example, the above-mentioned preset order may be to sequentially execute the interception operations corresponding to the harassment interception function, the function of intercepting all numbers, the whitelist, the blacklist, the function of intercepting unknown / hidden numbers, the function of intercepting strange text messages, and the intelligent interception function. Specifically, as Figure 8 shown, after receiving the target text message, the system manager can first determine whether the harassment interception function is enabled. If the harassment interception function is enabled, the system manager can intercept the text messages sent by all harassment numbers. If the harassment interception function is not enabled, that is, the harassment interception function is in the closed state, the system manager can not intercept the text messages sent by harassment numbers and determine whether the function of intercepting all numbers is enabled. If the function of intercepting all numbers is enabled, the system manager can intercept the text messages sent by all numbers except those in the whitelist and the security numbers. If the function of intercepting all numbers is closed, that is, the function of intercepting all numbers is in the closed state, the system manager can not intercept the text messages sent by all numbers except those in the whitelist and the security numbers and determine whether the sender number corresponding to the target text message is a number in the whitelist. If the sender number corresponding to the target text message is a number in the whitelist, the system manager can not intercept the target text message. If the sender number corresponding to the target text message is not a number in the whitelist, the system manager can determine whether the sender number corresponding to the target text message is a number in the blacklist. If the sender number corresponding to the target text message is a number in the blacklist, the system manager can intercept the target text message.

[0181] If the sender number corresponding to the above target text message is not a number in the blacklist, the system manager can determine whether the function of intercepting unknown / hidden numbers is enabled. If the function of intercepting unknown / hidden numbers is enabled, the system manager can intercept the text messages sent by unknown / hidden numbers. If the function of intercepting unknown / hidden numbers is not enabled, that is, the function of intercepting unknown / hidden numbers is in the closed state, the system manager can not intercept the text messages sent by the unknown / hidden number, and determine whether the function of intercepting strange text messages is enabled. If the function of intercepting strange text messages is enabled, the system manager can intercept the strange text messages, that is, intercept the text messages sent by strange numbers. If the function of intercepting strange text messages is not enabled, that is, the function of intercepting strange text messages is in the closed state, the system manager can not intercept the strange text messages, and determine whether the intelligent interception function is enabled. If the intelligent interception function is enabled, the system manager can perform intelligent interception on the target text message. If the intelligent interception function is not enabled, that is, the intelligent interception function is in the closed state, the system manager can output the interception result of the target text message, and the interception result is used to indicate whether the target text message is intercepted.

[0182] It can be understood that the above intelligent interception can be used to determine whether the sender number corresponding to the target text message is a black number, a safe number, or a suspicious number. Specifically, if the sender number is a black number included in the black number library, it means that the sender number is clearly a risk number that will induce users to perform some security risk behaviors, resulting in losses of users' resources. Therefore, the system manager can intercept the target text message. In this way, it is possible to avoid direct contact between the mobile phone user and the sender number, fundamentally avoid losses of users' property, improve the security of users' use, and thus improve the user experience.

[0183] If the above sender number is a safe number, it means that after the user views the text message corresponding to the sender number, the sender will not induce the user to perform some risk operations, resulting in losses of users' property, that is, it means that the content of this text message is safe. Therefore, when the mobile phone receives the target text message, there is no need to determine whether the target text message will induce the user to perform risk operations, that is, there is no need to perform risk detection, and the mobile phone can normally process the target text message. In this way, unnecessary power consumption losses can be reduced.

[0184] If the above sender number is a suspicious number and the suspicious number has not been added to the black number library, therefore, the mobile phone can not intercept the target text message, that is, the user can view the target text message, but the system manager can perform corresponding detection on the user's interaction behavior to avoid losses of users' property.

[0185] Exemplarily, such as Figure 9As shown, the text content of the target SMS can be normally displayed in the SMS list in the mobile phone, enabling the user to choose whether to view the text content of the target SMS according to their own needs. For example, if any position in the SMS area 601 is clicked by the user, it means that the user wants to view the detailed content of the target SMS. Therefore, the mobile phone can display the detailed content of the target SMS (e.g., Because you often watch short videos, now you can get a full-automatic intelligent rice cooker for free by mail. Please search in Alipay: 12**56 , contact the staff to claim it!). Another example is that if it is detected that the user performs an exit operation on this SMS interface, it means that the user does not want to view the text content of the target SMS. Therefore, the mobile phone can exit this SMS interface, that is to say, the mobile phone can display the display interface before this SMS interface (such as the main interface of the mobile phone).

[0186] In some embodiments, in the case where the sender number corresponding to the above-mentioned target SMS is a suspicious number, if the target SMS exits the SMS interface without being viewed by the user (such as the user believes that the target SMS has risks and actively refuses to view the target SMS), it indicates that the user of this mobile phone (or the owner user) will not communicate with the sender of the target SMS, that is, the user will not be induced by the sender of the target SMS to perform some risk operations. Therefore, the mobile phone does not need to perform risk detection. In this way, unnecessary risk detection can be avoided, thereby reducing unnecessary power consumption losses.

[0187] S503, in the case where the above-mentioned target SMS is not intercepted, the system manager sends a content recognition instruction to the AI module.

[0188] Specifically, after determining not to intercept the above-mentioned target SMS, the system manager can send a content recognition instruction to the AI module to instruct the AI module to perform content recognition on the target SMS.

[0189] S504, the AI module receives the above-mentioned content recognition instruction, performs content recognition on the above-mentioned target SMS, and obtains a SMS recognition result.

[0190] Among them, the above-mentioned SMS recognition result is used to indicate whether there is preset SMS content in the target SMS. The preset SMS content is the SMS content corresponding to the target SMS type. The target SMS type may include at least one of a social account, a telephone number, a uniform resource locator (URL) address, and a bank card number. That is to say, the preset SMS content may be the content corresponding to the telephone number, the content corresponding to the URL address, the content corresponding to the bank card number, or the content corresponding to the social account.

[0191] Specifically, after receiving the content recognition instruction, the AI module can perform content recognition on the above-mentioned target SMS according to regular expression parsing (or called regular expression) and / or language recognition model to obtain the SMS recognition result. Among them, the regular expression is a logical formula for string operations, and usually the regular expression is used to match and filter strings. The language recognition model is a natural language processing (NLP) model, and this NLP model is used to recognize the SMS content of the target SMS.

[0192] In some embodiments, the system steward can input the above-mentioned target SMS into the regular expression to obtain the first detection result, where the first detection result is used to indicate whether the target SMS includes the content of the first SMS type, and the first SMS type may include at least one of a telephone number, a URL address, and a bank card number. The system steward can input the above-mentioned target SMS into the NLP model to obtain the second detection result, where the second detection result is used to indicate whether the target SMS includes the content of the second SMS type, and the second SMS type may include a social account.

[0193] After that, the system steward can obtain the SMS recognition result according to the above-mentioned first detection result and the above-mentioned second detection result. In this way, not only can the computing resources be saved to the greatest extent, unnecessary resource waste be reduced, but also the accuracy of the detection result can be ensured, thereby improving the interception accuracy of the target SMS.

[0194] In some other embodiments, in order to save computing resources, the system steward can perform content recognition on the target SMS through the regular expression to obtain the SMS recognition result to reduce unnecessary resource waste. In still some other embodiments, in order to improve the accuracy of the detection result, the system steward can perform content recognition on the target SMS through the NLP model to obtain the SMS recognition result. In this way, it can provide a basis for subsequent accurate interception of risk SMS.

[0195] S505, in the case that the above-mentioned SMS recognition result indicates that there is preset SMS content in the target SMS, the AI module sends a content extraction instruction to the system steward.

[0196] Specifically, if the above-mentioned SMS recognition result indicates that there is preset SMS content in the target SMS, it means that the target SMS may have a security risk, that is, there is a possibility that the user is induced to perform a risk behavior. Therefore, the AI module needs to send a content extraction instruction to the system steward to instruct the system steward to extract the preset SMS content included in the target SMS.

[0197] In some embodiments, if the above-mentioned SMS recognition result indicates that the preset SMS content does not exist in the target SMS, it means that there is no security risk in the target SMS, that is, there is no possibility that the user is induced to perform a risk behavior. Therefore, the AI module does not need to send a content extraction instruction to the system steward. The AI module can send a browsing instruction to the system steward to display the SMS content corresponding to the target SMS according to the user's viewing operation.

[0198] S506, the system steward receives the above-mentioned content extraction instruction, extracts the content of the target SMS, and obtains at least one piece of SMS data.

[0199] Specifically, after receiving the above-mentioned content extraction instruction, the system steward can extract the preset SMS content included in the above-mentioned target SMS to obtain at least one piece of SMS data. It can be understood that the SMS data includes the preset SMS content.

[0200] In one implementation, the above-mentioned SMS data may further include the target SMS type and the reception time of the target SMS. Among them, the reception time is the time corresponding to when the mobile phone receives the target SMS.

[0201] It can be understood that one piece of SMS data corresponds to the content of one SMS type. That is to say, if the target SMS includes the content of multiple SMS types, then the target SMS includes multiple pieces of SMS data. For example, if the target SMS A includes a phone number and a URL address, then the target SMS A may include two pieces of SMS data. Among them, SMS data 1 includes the content corresponding to the phone number (such as 189****4444), and SMS data 2 includes the content corresponding to the URL address (such as http: / / ***123.com). Another example, if the target SMS B only includes a social account, then the target SMS B includes one piece of SMS data 3, where the SMS data 3 includes the social account (such as 879****01).

[0202] Optionally, after obtaining at least one piece of SMS data, the system steward can store the at least one piece of SMS data in a temporary file. Among them, multiple pieces of SMS data are stored in the temporary file.

[0203] In this embodiment, in order to prevent the temporary file from occupying too much storage resources of the mobile phone, the mobile phone can pre-set the data quantity of the SMS data in the temporary file. That is to say, only a preset quantity of SMS data can be stored in the temporary file. In this way, it can be ensured that the SMS data is kept within a controllable range, and the situation where the temporary file occupies too much storage resources due to the disorderly growth of the SMS data can be reduced. Among them, the preset quantity is the quantity defaulted by the system. The preset quantity can be 10, 20, etc., and is not specifically limited.

[0204] Specifically, the system manager can process the SMS data in the temporary file according to a preset storage rule. Among them, the preset storage rule can include at least one of the storage time of the SMS data being less than or equal to a preset time and the storage quantity of the SMS data being less than or equal to a preset quantity. The preset time is the default time of the system, and the preset time can be 24 hours, 12 hours, etc., without specific limitation.

[0205] In some embodiments, if the storage time of the above SMS data is less than or equal to the preset time and the storage quantity of the SMS data is less than or equal to the preset quantity, the system manager does not process the SMS data in the temporary file. If the storage time of the SMS data is greater than the preset time, it means that the storage time of the SMS data in the temporary file is too long. Therefore, the system manager can delete the SMS data that exceeds the preset time, so as to ensure that the storage time corresponding to the SMS data stored in the temporary file is not greater than the preset time. If the storage quantity of the SMS data is greater than the preset quantity, it means that there is too much SMS data stored in the temporary file, that is, the temporary file occupies too much storage resource. Therefore, the system manager can delete the SMS data with the longest storage time in the temporary file to ensure that the storage quantity is not greater than the preset quantity, thereby reducing unnecessary resource waste.

[0206] S507, in response to the triggering operation of the user for any SMS data in the above target SMS being a preset triggering operation, the system manager collects first data within the first collection duration.

[0207] Specifically, after obtaining at least one piece of SMS data, the system manager can determine whether the triggering operation of the user for the target SMS is a triggering operation for any SMS data, that is, determine whether the triggering operation of the user for the target SMS is a triggering operation for any target SMS content. If the triggering operation of the user for the target SMS is not a triggering operation for any target SMS content, it means that although the user has performed a triggering operation on the target SMS, it does not involve a risk operation. Therefore, the system manager does not need to collect the first data.

[0208] If the triggering operation of the user for the target SMS is a triggering operation for any target SMS content, the system manager can further determine whether the triggering operation is a preset triggering operation. If the triggering operation is not a preset triggering operation, it means that although the user has performed a triggering operation on the above SMS data, there is no possibility of being induced by the sender, that is, the sender will not induce the machine owner to perform a risk operation. Therefore, the system manager does not need to collect the first data. If the triggering operation is a preset triggering operation, it means that there is a possibility that the user is induced by the sender. Therefore, the system manager can collect the first data within the first collection duration. Among them, the preset triggering operation can be a click operation on the SMS data and a copy operation on the SMS data, etc.

[0209] Among them, the above-mentioned target SMS content may include at least one of the SMS content corresponding to the telephone number, the SMS content corresponding to the social account, the SMS content corresponding to the bank card number, and the SMS content corresponding to the URL address.

[0210] Next, in combination with the above Figure 2 shown structure and Figure 10 the shown operation detection process, the above S504 will be described in detail. Specifically, the operation detection process may include S1001 to S1012:

[0211] S1001. The system manager in the mobile phone receives the click operation of the user on the first SMS content in the target SMS.

[0212] Specifically, after the mobile phone receives the target SMS, if the SMS content in the target SMS is clicked by the user, the system manager in the mobile phone can determine whether the SMS content is the first SMS content. If the SMS content is the first SMS content, it means that the user may be induced by the sender to perform a risk operation. Therefore, the system manager can further determine whether the first SMS content is the SMS data in the temporary file. If the SMS content is not the first SMS content, it means that the user is not induced by the sender to perform a risk operation, that is, there is no possibility of loss of user resources. Therefore, the system manager does not need to judge the first SMS content to reduce unnecessary resource waste.

[0213] Among them, the above-mentioned first SMS content may include at least one of the SMS content corresponding to the telephone number and the SMS content corresponding to the URL address.

[0214] S1002. When it is determined that the above-mentioned first SMS content is the SMS content corresponding to the telephone number, if a call operation is received for the SMS content, the system manager sends a call instruction to the phone application.

[0215] Specifically, after it is determined that the above-mentioned first SMS content is the SMS content corresponding to the telephone number, in response to the user's call operation on the telephone number in the target SMS, the system manager can send a call instruction to the phone application. Among them, the call instruction indicates that the phone application can call the telephone number, but it is necessary to determine whether the telephone number is the cached number in the temporary file to determine whether the telephone number is a suspicious number.

[0216] S1003. The phone application receives the above call instruction and determines whether the telephone number in the above target SMS is the cached number in the temporary file.

[0217] Specifically, after receiving the above call indication, the phone application can determine whether the phone number in the above target text message is a cached number in the temporary file. If the phone number in the target text message is a cached number in the temporary file, it indicates that the phone number the user wants to call is a suspicious number. Therefore, the phone application can execute S1004 to avoid loss of user resources at the root. If the phone number in the target text message is not a cached number in the temporary file, it means that the phone number the user wants to call is not a suspicious number, that is, it will not cause loss of user resources. Therefore, the system manager does not need to perform risk detection operations. The cached number is all the text message data about phone numbers cached in the temporary file.

[0218] In this embodiment, to protect the user's privacy, the number matching is only performed inside the phone application, that is, the above phone number does not leave the phone application. In this way, it is possible to fundamentally avoid the leakage of the phone number, ensure that the user's privacy is not leaked, and thus improve the user's experience.

[0219] In some embodiments, after the phone application receives the above call indication, the mobile phone can display a dialing interface. Exemplarily, as Figure 11 shown, interface (a) is a detailed interface containing the text message content. Among them, the text message content includes the phone number (134****8797). If the phone number "134****8797" in the text message content is clicked by the user, the mobile phone can display a settings interface, that is, Figure 11 interface (b) in it. The settings interface includes a "Call" control, a "Edit before Call" control, a "Send Text Message" control, a "Copy to Clipboard" control, and a "New Contact" control. After that, if the "Call" control is clicked by the user, it means that the user wants to call this phone number. Therefore, the mobile phone can display a dialing interface, that is, Figure 11 interface (c) in it.

[0220] It can be understood that the process of the above mobile phone displaying the dialing interface and the process of the above phone application determining whether the phone number in the target text message is a cached number can be executed simultaneously. That is, during the process of the mobile phone displaying the dialing interface, the phone application judges the phone number. In this way, the waiting time of the user can be reduced and the calling efficiency of the mobile phone can be improved. In some embodiments, the process of the above mobile phone displaying the dialing interface and the process of the above phone application determining whether the phone number in the target text message is a cached number can also be executed in a sequential order, which is not specifically limited. For example, the mobile phone can first execute the step of displaying the dialing interface and then execute the step of determining whether the phone number in the target text message is a cached number. Or, for another example, the mobile phone can first execute the step of determining whether the phone number in the target text message is a cached number and then execute the step of displaying the dialing interface.

[0221] S1004. When the phone number in the above target text message is a cached number, the phone application sends a risk detection instruction to the system manager.

[0222] Specifically, after determining that the phone number in the above target text message is a cached number, the phone application can directly send a risk detection instruction to the system manager to trigger the system manager to collect subsequent behavior data. Among them, this risk detection instruction indicates that the system manager can collect and detect the user's subsequent behavior operations, so as to avoid losses to user resources.

[0223] S1005. When it is determined that the content of the first text message is the content corresponding to the URL address, if an access operation for the text message data is received, the system manager sends an access instruction to the browser application.

[0224] Specifically, after determining that the content of the first text message is the content corresponding to the URL address, in response to the user's access operation for the URL address in the target text message, the system manager can send an access instruction to the browser application. Among them, this access instruction indicates that the browser application can access the URL address, but it is necessary to determine whether the URL address is a cached address in the temporary file to determine whether the URL address is a suspicious address.

[0225] S1006. The browser application receives the above access instruction and determines whether the URL address in the above target text message is a cached address in the temporary file.

[0226] Specifically, after receiving the above access instruction, the browser application can determine whether the URL address in the target text message is a cached address in the temporary file. If the URL address in the target text message is a cached address in the temporary file, it means that the URL address that the user wants to access is a suspicious address. Therefore, the browser application can execute S1007 to avoid losses to user resources from the source. If the URL address in the target text message is not a cached address in the temporary file, it means that the URL address that the user wants to access is not a suspicious address, that is, it will not cause losses to user resources. Therefore, the system manager does not need to perform risk detection operations. Among them, the cached address is all the text message data about the URL address cached in the temporary file.

[0227] In some embodiments, after the browser application receives the above access instruction, the mobile phone can display the access interface of the browser. Specifically, during the process of the mobile phone jumping from the text message application to the browser application, it can listen to the URL address included in the intent when jumping to the browser through the Activity Task Manager Service (ATMS), that is to say, the mobile phone can obtain the URL address through the ATMS.

[0228] It can be understood that the process of the above mobile phone displaying the access interface and the process of the above browser application determining whether the URL address in the target SMS is a cached address can be executed simultaneously. That is, during the process of the mobile phone displaying the access interface, the browser application determines the URL address, so that the waiting time of the user can be reduced and the access efficiency of the mobile phone can be improved. In some embodiments, the process of the above mobile phone displaying the access interface and the process of the above browser application determining whether the URL address in the target SMS is a cached address can be executed in a sequential order, and the specific order is not limited. For example, the mobile phone can first execute the step of displaying the access interface, and then execute the step of determining whether the URL address in the target SMS is a cached address. For another example, the mobile phone can first execute the step of determining whether the URL address in the target SMS is a cached address, and then execute the step of displaying the access interface.

[0229] S1007. When the URL address in the above target SMS is a cached address, the browser application sends a risk detection instruction to the system manager.

[0230] Specifically, after determining that the URL address in the above target SMS is a cached address, the browser application can directly send a risk detection instruction to the system manager to trigger the system manager to collect subsequent behavior data.

[0231] It can be understood that the above S1002-S1004 and S1005-S1007 are parallel solutions. That is to say, if the first SMS content is the SMS content corresponding to the phone number, the mobile phone can only execute the steps of S1002-S1004, and there is no need to execute the steps of S1005-S1007; if the first SMS content is the SMS content corresponding to the URL address, the mobile phone can only execute the steps of S1005-S1007, and there is no need to execute the steps of S1002-S1004.

[0232] S1008. The system manager receives the user's copy operation on the second SMS content in the target SMS.

[0233] Specifically, after receiving the target SMS, if the SMS content in the target SMS is copied by the user, the system manager in the mobile phone can determine whether the SMS content is the second SMS content. If the SMS content is the second SMS content, it means that the user may be induced by the sender to perform a risk operation. Therefore, the system manager can further determine whether a risk detection operation needs to be performed. If the SMS content is not the second SMS content, it means that the user is not induced by the sender to perform a risk operation, that is, there is no possibility of loss of user resources. Therefore, the system manager does not need to perform a risk detection operation.

[0234] Among them, the above second text message content can be any text message content included in the target text message. For example, it can be the full text of the target text message, or the text message content corresponding to the phone number in the target text message, etc.

[0235] Exemplarily, the above copy operation can be a long-press operation on the second text message content, or a double-click operation on the second text message content, etc. Among them, the long-press operation refers to an operation in which the user's finger presses on the second text message content for a preset time. The double-click operation refers to an operation in which the user's finger makes two consecutive clicks on the second text message content.

[0236] S1009. The system manager sends a copy instruction to the clipboard.

[0237] Specifically, after receiving the user's copy operation on the second text message content, the system manager can send a copy instruction to the clipboard. Among them, this copy instruction indicates that the clipboard can copy the second text message content, but it is necessary to determine whether the second text message content to be copied is the text message data in the temporary file to determine whether the second text message content to be copied is suspicious text message content.

[0238] In some embodiments, after the system manager receives the user's copy operation on the second text message content, it may also not send a copy instruction to the clipboard. The clipboard can detect changes in the copied content in the clipboard. If the clipboard detects changes in the copied content, it means that the user has performed a copy operation. Therefore, the clipboard can execute S1010. If the clipboard does not detect changes in the copied content, it means that the user has not performed a copy operation, that is, the user has no possibility of being induced by the sender. Therefore, the clipboard does not need to judge the second text message content. Specifically, the clipboard can detect whether the copied content in the clipboard has changed through ClipboardManager.addPrimaryClipChangedListener.

[0239] After that, in the case of detecting changes in the copied content in the clipboard, the clipboard can judge the text message type corresponding to the content currently copied by the clipboard through regular parsing. If the text message type is a social account, the clipboard can send a first jump detection instruction to the system manager to trigger the system manager to monitor the jump behavior of the social application. If the text message type is a bank card number, the clipboard can send a second jump detection instruction to the system manager to trigger the system manager to monitor the jump behavior of the payment application. If the text message type is a URL address, the clipboard can send a third jump detection instruction to the system manager to trigger the system manager to monitor the jump behavior of the browser application.

[0240] S1010. The clipboard receives the above copy instruction and determines whether the second SMS content to be copied is the SMS data in the temporary file.

[0241] Specifically, after receiving the above copy instruction, the clipboard can determine whether the second SMS content to be copied is the SMS data in the temporary file. If the second SMS content to be copied is the SMS data in the temporary file, it indicates that the second SMS content the user wants to copy is suspicious content. Therefore, the clipboard can execute S1011 to avoid loss of user resources at the source. If the second SMS content to be copied is not the SMS data in the temporary file, it means that the second SMS content the user wants to copy is not suspicious content, that is, it will not cause loss of user resources. Therefore, the system manager does not need to perform a risk detection operation.

[0242] In some embodiments, the clipboard can identify the second SMS content to be copied according to a regular expression parsing and / or a language recognition model to obtain a third detection result. Wherein, the third detection result is used to indicate whether the second SMS content to be copied is the SMS content corresponding to the target SMS type. Then, when the third detection result indicates that the second SMS content to be copied is the SMS content corresponding to the target SMS type, the clipboard determines whether the second SMS content to be copied is the SMS data in the temporary file. If the second SMS content to be copied is the SMS data in the temporary file, the clipboard can execute S1011.

[0243] S1011. When the second SMS content to be copied is the SMS data in the temporary file, the clipboard sends a risk detection instruction to the system manager.

[0244] Specifically, after determining that the second SMS content to be copied is the SMS data in the temporary file, the clipboard can directly send a risk detection instruction to the system manager to trigger the system manager to collect subsequent behavior data.

[0245] In some embodiments, if the second SMS content to be copied is the SMS data corresponding to the social account in the temporary file, the clipboard can monitor the process of the mobile phone jumping from the SMS application to the social application through ATMS. If the second SMS content to be copied is the SMS data corresponding to the bank card number in the temporary file, the clipboard can monitor the process of the mobile phone jumping from the SMS application to the payment application through ATMS. If the second SMS content to be copied is the SMS data corresponding to the URL address in the temporary file, the clipboard can monitor the process of the mobile phone jumping from the SMS application to the browser through ATMS. If the second SMS content to be copied is the SMS data corresponding to the phone number in the temporary file, the clipboard can monitor the process of the mobile phone jumping from the SMS application to the phone application through ATMS.

[0246] It can be understood that the above S1001 - S1007 and S1008 - S1011 are parallel solutions. That is to say, if the system steward receives a click operation from the user on the first text content in the target text message, the mobile phone can only execute the steps of S1001 - S1007 and does not need to execute the steps of S1008 - S1011; if the system steward receives a copy operation from the user on the second text content in the target text message, the mobile phone can only execute the steps of S1008 - S1011 and does not need to execute the steps of S1001 - S1007.

[0247] S1012. The system steward receives the above risk detection instruction and collects first data within the first collection duration.

[0248] Specifically, after receiving the above risk detection instruction, the system steward can trigger the collection of first data within the first collection duration. Among them, the first data includes user behavior data and / or the running data of applications in the mobile phone.

[0249] Among them, the above user behavior data represents the data generated by the mobile phone in response to the user's operation, that is, the data triggered by the user's operation. For example, the behavior data generated by the mobile phone in response to the user's trigger operation on the controls in the mobile phone interface. Exemplarily, the user behavior data can include at least one type of data among application startup data, screen sharing behavior data, text message behavior data, call behavior data, call forwarding setting data, flight mode setting data, harassment interception setting data, and do not disturb setting data.

[0250] The above application startup data represents the data generated when entering an application. Since the ways to enter an application can include the user actively starting the application, correspondingly, the application startup data can include response startup behavior data. Among them, the response startup behavior data represents the data generated by the mobile phone when starting the application in response to the user's startup operation on the application in the mobile phone. Exemplarily, the response startup behavior data can include the identifier for entering the application (such as the application package name).

[0251] In some embodiments, the mobile phone can maintain a list of the package names of applications on the mobile phone (such as the package names of banks, other applications, etc.) and activities, and insert stakes in the ActivityTaskManagerService in the system framework to obtain application information (such as the application type corresponding to the application). The staking in this application means inserting a piece of code into the target code through a certain strategy, or replacing the target code with a preset code to obtain a new target code, so that when the new target code is run, the required information can be recorded.

[0252] The above screen sharing behavior data refers to the data generated when an application performs screen sharing. Exemplarily, the screen sharing data may include the identification of the application performing screen sharing. Exemplarily, in response to a user's click operation on a screen sharing control in a certain application, the mobile phone can obtain the package name of the application and determine whether the display object has created a virtual screen. Then, the mobile phone can determine whether the application performs screen sharing based on whether the display object has created a virtual screen. It can be understood that after the screen sharing control is triggered, the mobile phone will automatically generate a corresponding virtual interface (or virtual screen) according to the interface currently displayed on the mobile phone and send the virtual interface to the peer end to achieve screen sharing. Specifically, by registering the callback listener of the DisplayManager to listen for the creation and deletion of the display, and after obtaining the exclusive number (identification, ID) used by the display object, the reflection call method is used to obtain the package name of the application that enables screen sharing, providing a basis for subsequently determining whether the package name of the application is a meeting APP.

[0253] The above SMS behavior data refers to the data obtained by analyzing the SMS content received by the mobile phone. Among them, the SMS behavior data may include the type of the number, the network location to which the SMS belongs, and / or the verification code identifier, and the verification code identifier indicates whether there is a verification code in the SMS received by the mobile phone. For example, the verification identifier includes identifier 1 or identifier 2, where identifier 1 indicates that there is a verification code in the SMS, and identifier 2 indicates that there is no verification code in the SMS.

[0254] In some embodiments, the network location to which the above SMS belongs can be determined by using the network address in the SMS. The network address can be a Uniform Resource Locator (URL) address. The mobile phone can determine whether there is a URL address in the SMS through regular parsing (or regular expression) and upload the URL address to the cloud. The cloud performs Domain Name System (DNS) parsing on the URL address to obtain the IP address corresponding to the URL address. Then, the cloud can determine the network location (such as country, city, etc.) corresponding to the IP address corresponding to the URL address to obtain the network location to which the SMS belongs. Then, the cloud can send the network location to which the SMS belongs to the mobile phone. Of course, the mobile phone itself can also determine the network location based on regular parsing. Among them, DNS is a service on the Internet. As a distributed database that maps domain names and IP addresses to each other, it can access the Internet more conveniently.

[0255] In some embodiments, the above-mentioned SMS behavior data may further include the type of the sending number corresponding to the SMS received by the mobile phone, such as a suspicious number. Alternatively, the above-mentioned SMS behavior data represents the data obtained by analyzing the content of the SMS sent by a suspicious number or an unfamiliar number received by the mobile phone. After the mobile phone receives an SMS, when determining that the sending number corresponding to the SMS belongs to the target number type, the mobile phone may collect the corresponding SMS behavior data, and the target number type includes suspicious numbers and / or unfamiliar numbers.

[0256] The above-mentioned call behavior data refers to the new incoming call data received by the mobile phone. Exemplarily, the new incoming call data may include at least one piece of information among the calling number corresponding to the new incoming call, the call duration, and the location of origin of the calling number (or referred to as the call location of origin). Specifically, the mobile phone may report the call behavior data to the system manager through the mobile communication module, and the call location of origin refers to the location where the calling number is registered.

[0257] The above-mentioned call forwarding setting data represents the setting situation of the call forwarding mode, that is, it can represent the behavior data corresponding to when the user sets the call forwarding mode. Exemplarily, the call forwarding setting data may include at least one of the setting status of the call forwarding mode, the setting path information, the number to which the call is forwarded, and the setting mode. Among them, the setting status of the call forwarding mode includes the on state and the off state. The setting path information represents the entry method of the call forwarding mode setting interface. The call forwarding mode setting interface is used to set the on state and / or the setting mode of the call forwarding mode. Among them, the setting path information includes the setting interface identifier and the dial pad password identifier. The setting interface identifier indicates entering the call forwarding mode setting interface through the setting interface; the dial pad password identifier indicates entering the call forwarding mode setting interface by inputting a preset field on the dial pad.

[0258] Among them, the above-mentioned number to which the call is forwarded represents the number to which the incoming call is transferred, such as the above-mentioned specified telephone number. The above-mentioned setting mode includes at least one of the unconditional mode, the busy time mode, and the unreachable mode. The unconditional mode means that all incoming calls are transferred to the specified telephone number. The busy time mode means that during the process of the mobile phone being in the answering state, if an incoming call is received, the incoming call is transferred to the specified telephone number. The unreachable mode means that when the mobile phone is in the shutdown state, the mobile phone does not have a SIM card, the wireless line is congested or out of the coverage area, the incoming call is transferred to the specified telephone number. Of course, it may also include other types of modes, such as the no answer mode, that is, the no answer call forwarding mode.

[0259] Exemplarily, the mobile phone may obtain the number to which the call is forwarded and the setting mode through the reflection call method.

[0260] The above flight mode setting data represents the data recorded when the user sets the flight mode on the mobile phone. Among them, the flight mode setting data may include the status of the flight mode, and the status includes the on state and the off state. Specifically, the mobile phone can listen for broadcast messages (ACTION_AIRPLANE_MODE_CHANGED) regarding the flight mode to determine the status change of the flight mode. When the flight mode status changes, the corresponding setting data is collected to determine the status of the flight mode in the mobile phone.

[0261] The above harassment interception setting data refers to the data recorded when the user sets the harassment interception mode. Exemplarily, the harassment interception setting data may include the status of the harassment interception mode. Among them, the status may include the on state and the off state. For example, in response to the user's click operation on the harassment interception mode, the mobile phone enables the harassment interception mode to intercept calls from all suspicious numbers and blacklisted numbers and / or text messages sent by suspicious numbers and blacklisted numbers. The status of the harassment interception mode changes from the off state to the on state, or the status of the harassment interception mode changes from the on state to the off state. Exemplarily, the harassment interception mode may include a call interception mode and / or a text message interception mode. The call interception mode refers to the mode of intercepting calls from unfamiliar numbers and blacklisted numbers. The text message interception mode refers to the mode of intercepting text messages sent by suspicious numbers and blacklisted numbers. Specifically, the mobile phone can listen for whether the field value of relevant fields (such as fields related to the harassment interception mode) in the setting database changes. When the field changes, the corresponding data item is collected to determine the status of the harassment interception mode.

[0262] The above do not disturb setting data refers to the data recorded when the user sets the do not disturb mode on the mobile phone. Exemplarily, the do not disturb mode setting data may include the status of the do not disturb mode, and the status may include the on state and the off state. For example, in response to the user's operation to enable the do not disturb mode, the mobile phone enables the do not disturb mode to intercept all calls and text messages. The status of the do not disturb mode changes from the off state to the on state, or the status of the do not disturb mode changes from the on state to the off state. Specifically, the mobile phone can listen for whether the field value of relevant fields (such as fields related to the do not disturb mode) in the setting database changes. When the field changes, the corresponding data item is collected to determine the on / off state of the do not disturb mode. Among them, optionally, the do not disturb mode setting data may further include the mode data corresponding to the do not disturb mode, such as scheduled do not disturb and immediate do not disturb.

[0263] The running data of the applications used in the mobile phones included in the above first data represents the data of the applications running by themselves. Exemplarily, the running data of the applications may include application jump behavior data. Among them, the application jump behavior data represents that the foreground application of the mobile phone is switched from the first application (such as Application 1) to the second application (such as Application 2) to enter Application 2, that is, the data generated when the interface displayed on the mobile phone is switched from the interface in Application 1 to the interface in Application 2. Among them, Application 1 and Application 2 are different applications in the mobile phone. The application jump behavior data may include the identifier of the application before the jump (such as the identifier of the above Application 1) and / or the identifier of the application after the jump (such as the identifier of the above Application 2). The mobile phone can record this jump event when the application has a jump behavior to obtain the corresponding application jump behavior data. Specifically, instrumentation is performed on the activity task manager service in the system framework to obtain the jump information between applications, and the jump information is sent to the system steward through a callback interface. Then, the system steward filters the relevant behaviors of unknown applications according to the filtering rules. Among them, the jump information refers to the application package name of the application jumped to by other applications.

[0264] In some embodiments, the mobile phone can also collect the relevant startup data of applications belonging to the target type. For example, the above application jump behavior data can represent the data generated when the foreground application of the mobile phone jumps from an unknown application to other applications (such as a browser, an app market, a social application, a shopping application, etc.). Among them, the unknown application (or called a gray application) refers to an application for which the virus detection engine cannot detect the corresponding result, that is, the virus detection engine cannot detect whether this application is a malicious application or a safe application. Among them, the target type may include types such as payment and unknown.

[0265] In some embodiments, the running data of the above application may represent the running data of the first target application (or described as an unknown application). That is, when the mobile phone is running the first target application, the running situation of the target application can be recorded. Among them, optionally, the running data of the application can also be recorded when the mobile phone is running the application, without starting to collect only when certain conditions are met (such as the call status corresponding to an incoming call is the hung-up state and the call duration exceeds the preset duration).

[0266] In this application, if the sender number corresponding to the above target text message is a suspicious number, it indicates that the sender number may be a risk number, that is, a number with a security risk. In other words, it means that there may be a risk of property loss after the user receives the target text message sent by the sender number. Therefore, after the target text message is viewed, the mobile phone can determine whether to perform behavior detection according to the user's interaction operation on the target text message, that is, determine whether the mobile phone performs a risk operation, and then give a risk prompt in time to ensure the user's property safety.

[0267] It should be noted that if the mobile phone directly collects the first data when receiving the target short message for using the first data to determine whether to give a risk prompt, it may result in a waste of resources due to unnecessary data collection, causing unnecessary power consumption losses. To reduce power consumption, the present application can start collecting the first data only when the target short message is not intercepted. In this way, security numbers such as express delivery and takeaway can be filtered, which not only avoids the situation of unnecessary power consumption losses caused by the user browsing target short messages such as express delivery and takeaway triggering data collection, but also can reduce the probability of collecting user behavior data, effectively avoiding privacy issues caused by detecting the user's specific behavior, protecting the user's usage privacy, and enhancing the user's usage experience.

[0268] In some embodiments, since some numbers marked with the first preset label may also pose risks, in order to ensure the accuracy and timeliness of the risk prompt, when the mobile phone receives a target short message, if the sender number corresponding to the target short message belongs to a blacklist number, the mobile phone can directly intercept the target short message. When the sender number corresponding to the target short message is a contact number, the mobile phone views the target short message in response to the user's browsing operation. When the sender number corresponding to the target short message is an unknown number, the mobile phone views the target short message in response to the user's browsing operation, and then the mobile phone can continue to execute step S503 and subsequent steps as described above.

[0269] In some embodiments, the mobile phone can collect user behavior data and / or application running data in real time for detecting risk operations by using the user behavior data and the application running data, so as to achieve timely and accurate risk prompts. Of course, to reduce power consumption, the mobile phone can also collect user behavior data and application running data periodically.

[0270] It should be understood that the data collected by the mobile phone is all carried out under the user's authorization.

[0271] It should be noted that to reduce the power consumption of the mobile phone, the first collection duration corresponding to the mobile phone collecting the first data is determined by the parameters involved in the configuration file sent by the cloud. And this first collection duration can be continuously optimized by the system manager and / or the AI module according to big data analysis, so as to reduce the power consumption overhead. Among them, the first collection duration is the duration of the first data collected by the mobile phone after determining that the call duration of an incoming call exceeds the preset duration, that is, the duration of risk detection. For example, the first collection duration is 5 hours. After determining that the call duration exceeds the preset duration, the mobile phone can collect the first data within 5 hours after the current time. Simply put, the mobile phone can perform risk detection within 5 hours after an incoming call to determine whether the mobile phone has performed a risk operation.

[0272] The following specifically introduces how to collect the first data in combination with the accompanying drawings. Specifically, as Figure 12 shown, the system manager in the mobile phone can obtain the target configuration file. Among them, the target configuration file includes a risk identification rule library file, a risk data collection strategy, and a reminder strategy file.

[0273] The above-mentioned risk identification rule library file can include data identification strategies, such as strategies for identifying whether there is a risk in the first data (this strategy can indicate which user behavior data and / or which application's running data is at risk), etc.

[0274] The above-mentioned risk data collection strategy represents the collection strategy of the first data, that is, the above-mentioned system manager can collect the first data based on the risk data collection strategy. For example, when the behavior collection manager collects user behavior and / or application behavior, it will send the collected user behavior and / or application behavior to the system manager. Then, the system manager will perform feature extraction on the collected user behavior and / or application behavior to obtain the first data, so as to achieve the collection of the first data.

[0275] The above-mentioned reminder strategy configuration file can include risk reminder strategies. For example, in the case of determining that there is a risk of inducing user transactions, the mobile phone can perform corresponding risk reminder operations according to the reminder strategy configuration file. For example, display risk reminder information, send risk reminder information to the target person, etc.

[0276] After that, the above-mentioned system manager can set the first collection duration based on the above-mentioned target configuration file. Specifically, after the system manager in the mobile phone obtains the target configuration file, it will call the target interface associated with the AlarmManager, so that the AlarmManager can set a timing task to update the collection configuration and set the first collection duration. Among them, the first collection duration is set in advance according to actual needs. In this embodiment, the first collection duration is 6 hours. In other embodiments, the first collection duration can be 8 hours, 12 hours, etc., and specific values are not limited.

[0277] After that, the above-mentioned system manager can register a listener for the first preset risk behavior data. Among them, the first preset risk behavior data can include at least one type of data among preset payment application startup data, preset screen sharing data, preset application jump behavior data, preset SMS behavior data, preset call behavior data, preset call forwarding setting data, preset flight mode setting data, preset harassment interception setting data, and preset do not disturb setting data.

[0278] The above-mentioned preset payment application startup data refers to the data generated when entering a payment application. Exemplarily, the preset payment application startup data may include preset payment application jump behavior data and / or preset response startup behavior data. Among them, the preset payment application jump behavior data represents the data generated by jumping from an unknown application to a payment application, that is, it represents that the foreground application of the mobile phone jumps from an unknown application to a payment application. The preset response startup behavior data represents the data generated when the mobile phone starts a payment application in response to the user's startup operation on the payment application of the mobile phone.

[0279] Correspondingly, the preset payment application jump behavior data may include the identifier of the unknown application and / or the identifier of the payment application (such as the application package name). The unknown application represents the identifier of the application before the jump, and the payment application represents the identifier of the application after the jump. If the identifier of the application before the jump in the collected application jump behavior data is the identifier of the unknown application and the identifier of the application after the jump is the identifier of the payment application, the mobile phone can determine that the application jump behavior data is the preset payment application jump behavior data, and thus can determine that the application startup data belongs to the preset payment application startup data.

[0280] The above-mentioned preset response startup behavior data may include the identifier of the payment application. During the above first collection duration, if the user starts a certain application (such as by clicking the icon of the application), the mobile phone can start the application and record the identifier of the application to obtain the corresponding startup behavior data. If the identifier of the application is the identifier of the payment application, indicating that the user has started the payment application, the mobile phone can determine that the startup behavior data is the preset response startup behavior data, and thus can determine that the application startup data belongs to the first preset risk behavior data.

[0281] The above-mentioned preset screen sharing data refers to the data generated when the second target application performs screen sharing. Exemplarily, the preset screen sharing data may include the identifier of the second target application. For example, the second target application may include a meeting APP. During the first collection duration, in response to the user's click operation on the screen sharing control in the meeting application, the mobile phone turns on screen sharing to share the mobile phone interface and records the identifier of the meeting application to obtain the screen sharing behavior data. If the identifier of the meeting application belongs to the identifier of the second target application, the mobile phone can determine that the screen sharing data is the preset screen sharing data, that is, the screen sharing data belongs to the first preset risk behavior data.

[0282] It can be understood that after the screen sharing control is triggered, the system will automatically generate a corresponding virtual interface (or virtual screen) according to the current interface displayed on the mobile phone, and send the virtual interface to the corresponding calling device to achieve screen sharing. Specifically, by registering the callback of the display manager to listen for the creation and deletion of the display object, and after obtaining the exclusive number used by the display object, the reflection call method is used to obtain the application package name for enabling screen sharing to determine whether the application package name is the conference APP. If the application package name is the conference APP and it is monitored that the display object creates a virtual screen, it can be indicated that the user enables screen sharing through the conference APP.

[0283] The above-mentioned preset application jump behavior data refers to the data generated by the application jump behavior of an unknown application. Among them, the application jump of an unknown application means that the interface displayed on the mobile phone automatically jumps from the interface in the unknown application to the interface in other applications. For example, other applications can include applications such as browsers, application markets, and other unknown applications. The preset application jump behavior data can include the identifier of the unknown application. The unknown application refers to the application before the jump. For example, when the mobile phone collects application jump behavior data at the first collection time, and the identifier of the application before the jump in the application jump behavior data is the identifier of the unknown application, the mobile phone can determine that the application jump behavior data is the preset application jump behavior, that is, the running data of the application belongs to the first preset risk behavior data.

[0284] It can be understood that the data included in the above-mentioned first preset risk behavior data is only an example, and it can also include other types of data. For example, the above-mentioned preset application jump behavior data can also include the identifier of the third target application, and the third target application represents the identifier of the application after the jump. That is to say, when the identifier of the application before the jump in the application jump behavior data is the identifier of the unknown application and the identifier of the application after the jump is the identifier of the third target application, the mobile phone can determine that the application jump behavior data is the preset application jump behavior data.

[0285] The above-mentioned preset SMS behavior data includes the preset network location and / or the preset verification code identifier. For example, the above-mentioned SMS behavior data includes the network location corresponding to the SMS. When the network location corresponding to the SMS belongs to the preset network location, the mobile phone can determine that the SMS behavior data is the preset SMS behavior data, that is, the SMS behavior data belongs to the first preset risk behavior data. Another example is that the above-mentioned SMS behavior data includes identifier 1. The preset verification code identifier is identifier 1, and the mobile phone can determine that the SMS behavior data is the preset SMS behavior data, that is, the SMS behavior data belongs to the first preset risk behavior data.

[0286] In some embodiments, the above-mentioned preset SMS behavior data may further include a target number type, which includes suspicious numbers and / or unfamiliar numbers.

[0287] The above-mentioned preset call behavior data may include at least one of a target number type, a first preset duration threshold, and a preset call location. Among them, the target number type may include types such as unfamiliar numbers or incoming call numbers. For example, the preset call behavior data includes a suspicious number type, a first preset duration threshold, and a preset call location. Correspondingly, when the calling number corresponding to a new incoming call in the call behavior data collected by the mobile phone is a suspicious number, the call duration exceeds the first preset duration threshold, and the location of the calling number is the preset call location, it indicates that the mobile phone has received suspicious incoming call data, and the property of the user of the mobile phone may be damaged. Therefore, it is determined that this call behavior data is the preset call behavior data, that is, this call behavior data belongs to the first preset risk behavior data.

[0288] The above-mentioned preset call forwarding setting data includes at least one of the enabled state of the call forwarding mode, the target number type, the target setting method information, and the target setting mode. Among them, the target setting method information may include a dial pad secret code identifier or a setting interface identifier. The target setting mode may include at least one of an unconditional mode, a busy time mode, and an unreachable mode. For example, the preset call forwarding setting includes the enabled state of the call forwarding mode, the target setting method information, and the target setting mode. Correspondingly, when the mobile phone collects call forwarding setting data within the first collection duration, and the state of the call forwarding mode in the call forwarding setting data is the enabled state, the call forwarding number is the target number type, the setting method information is the target setting method information, and the setting mode is the target setting mode, it indicates that the call forwarding data collected by the mobile phone is the preset call forwarding setting data, that is, the call forwarding setting data collected by the mobile phone belongs to the first preset risk behavior data.

[0289] The above-mentioned preset flight mode setting data may include the enabled state of the flight mode. When the mobile phone collects flight mode setting data within the first collection duration, and the state of the flight mode in the flight mode setting data is the enabled state, it indicates that the flight mode setting data collected by the mobile phone is the preset flight mode setting data, that is, the flight mode setting data collected by the mobile phone belongs to the first preset risk behavior data.

[0290] The above-mentioned preset harassment interception setting data may include the enabled state of harassment interception. Optionally, the enabled state of harassment interception may represent the enabled state of a target harassment interception mode (such as a call interception mode and / or an SMS interception mode).

[0291] The above-mentioned preset Do Not Disturb setting data may include the Do Not Disturb mode on state and / or target mode data. For example, the target mode data indicates immediate Do Not Disturb.

[0292] Exemplarily, registering the first preset risk behavior data monitoring includes registering application behavior monitoring, registering screen sharing monitoring, registering a Do Not Disturb content observer, and registering a flight mode broadcast, etc.

[0293] After that, the above-mentioned system steward can, within the above-mentioned first collection duration, based on the above-mentioned target profile, collect first data to determine whether there is first preset risk behavior data in the first data.

[0294] In some embodiments, after the end of the first collection duration, the above-mentioned system steward can determine whether there is first preset risk behavior data in the first data collected within the first collection duration; or, the above-mentioned system steward can, within the first collection duration, after collecting a type of first data, determine whether the collected first data belongs to one of the first preset risk behavior data, that is, determine whether there is first data that matches the first preset risk behavior data in all the first data that has been collected (that is, whether there is first preset risk behavior data in all the first data that has been collected); or, the above-mentioned system steward can, within the first collection duration, periodically determine whether there is first data that matches the first preset risk behavior data in all the first data that has been collected.

[0295] In some embodiments, the above-mentioned system steward can use the permission information of the first target application to determine whether the first target application belongs to the first preset risk behavior data. Among them, the permission information may include at least one of the permission to read text messages (READ_SMS), the permission to read contacts (READ_CONTACTS), the permission to read external storage (READ_EXTERNAL_STORAGE), the permission to read call records (READ_CALL_LOG), the floating window permission (SYSTEM_ALERT_WINDOW), and the notification reading permission (BIND_NOTIFICATION_LISTENER_SERVIC). Of course, the permissions listed here are only one example, and the permission information may also include other types of permission information.

[0296] Exemplarily, the above system manager can determine whether the second data has the first preset risk behavior data. Among them, the second data may include the above first data and the permission information of the first target application, that is, the APP application permission authorization status (i.e., permission information). The authorization status refers to the permission authorization situation of the application. Correspondingly, the first preset risk behavior data may further include preset application permission data, and the preset application permission data may include target permission data, where the target permission data is permission data preset according to actual requirements. For example, the target permission data may include enabling the permission to read text messages and enabling the permission to read notifications, etc. When the permission information of the first target application includes the target permission data, it indicates that there is a risk that the first target application reads the user's private information, and the mobile phone can determine that the permission information of the first target application is the preset application permission data, that is, the permission information of the first target application belongs to the first preset risk behavior data.

[0297] Among them, optionally, the mobile phone can collect (such as periodically collect) the permission information of the first target application only after meeting certain conditions (such as the above target text message is not intercepted and the sender number corresponding to the target text message is a suspicious number), or because the real-time requirement for the data of the permission information of the first target application is not high, the permission information of the first target application can belong to the data collected regularly, that is, the mobile phone can periodically collect the permission information of the first target application. Or, in order to reduce power consumption, the mobile phone can periodically collect the permission information of the first target application when the mobile phone is in the charging state. Specifically, the mobile phone obtains the permissions called by the application through the PackageManager.GET_PERMISSIONS field and determines whether the application permission has been authorized through the REQUESTED_PERMISSION_GRANTED field.

[0298] It can be understood that if the above target text message is intercepted, or the sender number corresponding to the target text message is a safe number, then in order to protect the user's privacy, the system manager does not need to trigger the collection of the first data.

[0299] Specifically, if the above target text message is not intercepted, it means that the user can view the target text message. If the target text message is sent from a suspicious number, there may be a situation where the sender induces the user to perform a risk behavior. Therefore, the system manager in the mobile phone can collect the first data when the user performs a preset trigger operation on any text message data in the target text message. It can be understood that the collected first data reflects to a certain extent that it is generated by the target text message, that is, the first data is associated with the target text message, so that the first data can be used to determine whether the user has been induced by the caller of the target text message to perform a risk behavior, realizing accurate detection of risks.

[0300] S508. The AI module receives the first data sent by the system steward.

[0301] In this application, after the system steward collects the first data, it sends the first data to the AI module. Then, the AI module can determine whether the user has performed a risk behavior based on the received first data, realizing accurate detection of risks.

[0302] S509. The AI module determines whether there is first preset risk behavior data in the above first data.

[0303] In this application, the first data having first preset risk behavior data means that the first data contains one or more kinds of data in the first preset risk behavior data. In one example, the first data having first preset risk behavior data means that the first data contains one kind of data in the first preset risk behavior data. That is, as long as there is one kind of data belonging to the first preset risk behavior data in the first data, it can be indicated that the first data has first preset risk behavior data. For example, the first preset risk behavior data is preset do-not-disturb setting data. If the first data includes do-not-disturb setting data and the do-not-disturb setting data is preset do-not-disturb setting data, the mobile phone can determine that the first data has first preset risk behavior data.

[0304] In another example, the first data having first preset risk behavior data means that the first data contains multiple kinds of data in the first preset risk behavior data. That is, in the case where there are at least two kinds of data belonging to the first preset risk behavior data in the first data, it can be indicated that the first data has first preset risk behavior data. For example, the first preset risk behavior data includes preset payment application startup data and preset screen sharing data. If the first data includes application startup data and screen sharing data, and the application startup data is payment application behavior data and the screen sharing data is preset payment application startup data, it can be determined that the first data has first preset risk behavior data.

[0305] After S509, in the case where the above first data does not have first preset risk behavior data, it indicates that the mobile phone has not performed a risk operation, that is, it indicates that the risk of the user being induced to perform a security risk behavior is relatively low. Therefore, the AI module in the mobile phone can execute S510. In the case where the above first data has first preset risk behavior data, it indicates that the mobile phone has performed the behavior corresponding to the first preset risk behavior data, that is, it indicates that the user may have performed a risk operation. Therefore, the AI module in the mobile phone can execute S511.

[0306] S510. In the case where the above first data does not have first preset risk behavior data, the AI module sends a first risk indication to the system steward.

[0307] Among them, the first risk indication indicates that there is no risk operation on the mobile phone.

[0308] S511, the system steward receives the above first risk indication and determines whether the first collection duration has ended.

[0309] In this application, after receiving the above first risk indication, the system steward can determine whether the first collection duration has ended. If the first collection duration has ended, it means that no risk behavior has occurred during the entire first collection duration. Therefore, the collection of the first data can be stopped. If the first collection duration has not ended, the first data needs to be continuously collected to reduce the probability of the user's property being damaged.

[0310] S512, in the case where the above first collection duration has ended, the system steward stops collecting the first data.

[0311] In some embodiments, if the first data collected by the system steward does not contain the first preset risk behavior data and the first collection duration has also ended, the system steward can cancel the monitoring of the first preset risk behavior data, that is, stop collecting the first data. Among them, canceling the monitoring of the first preset risk behavior data can include canceling the application behavior monitoring, canceling the screen sharing monitoring, canceling the do not disturb, and registering the flight mode broadcast, etc.

[0312] Specifically, after the first collection duration has ended and all the above first data collected during the first collection duration do not contain the first preset risk behavior data, it means that no risk behavior has occurred during the entire first collection duration. Therefore, the collection of the first data can be stopped. In this embodiment, only the data types corresponding to the first preset risk behavior data are identified, rather than the data types corresponding to any trigger behavior data. In this way, unnecessary resource waste caused by excessive identification times can be reduced, the working efficiency of trigger behavior identification can be improved, and the user can be reminded in a timely manner.

[0313] S513, in the case where the above first collection duration has not ended, the system steward continues to collect the first data.

[0314] In this application, in the case where the first collection duration has not ended, the mobile phone continues to collect the first data for continuing to use the first data to determine whether there is a risk operation on the mobile phone, that is, the mobile phone can return to the above S512.

[0315] It can be understood that the above S512 and S513 are parallel solutions. That is to say, if the above first collection duration has ended, the system steward can execute the above S512; if the above first collection duration has not ended, the system steward can execute S513.

[0316] S514. When there is first preset risk behavior data in the above first data, the AI module obtains a risk detection result based on the above first data and in combination with the user profile.

[0317] Among them, the risk detection result indicates whether there is a risk in the behavior corresponding to the first data.

[0318] Specifically, after determining that there is first preset risk behavior data in the above first data, the AI module can determine whether there is non-conventional behavior data in the first data according to the first data and the user profile, that is, determine whether the behavior corresponding to the first data conforms to the user's regular operations, so as to obtain the corresponding risk detection result. Among them, non-conventional behavior data refers to behavior data that does not conform to the user's usage habits.

[0319] If there is non-conventional behavior data in the first data, it can be explained that the behavior corresponding to the first data does not belong to the user's regular behavior, that is, the possibility that the behavior corresponding to the first data has a risk is relatively high. Among them, the regular behavior is a behavior that conforms to the user's usage habits, that is to say, the non-conventional behavior is a behavior that does not conform to the user's usage habits. If there is no non-conventional behavior data in the first data, it can be explained that the behaviors corresponding to the first data all belong to the user's regular behaviors, and the possibility that the behavior corresponding to the first data has a risk is relatively low. That is to say, the risk detection result can also be expressed as whether there is non-conventional behavior data in the first data.

[0320] Exemplarily, if there is first preset risk behavior data in the first data, and the first preset risk behavior data is non-conventional behavior data, it can be determined that the possibility that the behavior corresponding to the first data has a risk is very high. Therefore, the mobile phone can give a risk prompt to prevent the user's property from being damaged; if there is first preset risk behavior data in the first data, but there is no non-conventional behavior data in the first data corresponding to the first preset risk behavior data, indicating that the operations performed by the user are all regular operations, it can be determined that the possibility that the behavior corresponding to the first data has a risk is relatively low. Therefore, there is no need to give a risk prompt to avoid affecting the user's use.

[0321] Among them, the behavior corresponding to the first data can include at least one of a click operation on a screen sharing control, a setting operation on a communication blocking function, and an entry operation on a payment application or a payment interface. It can be understood that the click operation on the screen sharing control means that the user enables the screen sharing function to perform screen sharing. The entry operation on a payment application or a payment interface means that the user clicks on the target control of an application, so that the mobile phone jumps from the current interface to another payment application or another payment interface.

[0322] Correspondingly, the setting operation for the communication blocking function refers to the user setting a communication blocking mode to block all communications with the outside world. The communication blocking mode may include a do not disturb mode, a flight mode, a call forwarding mode, an incoming call blocking mode, and an incoming message blocking mode.

[0323] In some embodiments, if the first preset risk behavior data exists in the above first data, it indicates that the system manager has monitored the first preset risk behavior data, and the mobile phone may have performed a risk operation. Therefore, it is necessary to send the first data to the AI module through the onRiskyFraudBehavior field, so that the AI module can identify the behavior corresponding to the first data using the user portrait corresponding to the mobile phone.

[0324] Among them, the user portrait is a tagged user model abstracted from data such as the user's usage habits (or called user behavior habits). That is to say, the user portrait may include multiple user portrait tags. Specifically, the user portrait tags in the user portrait can obtain call records through call logs, and obtain the usage duration of applications through usage stats. After that, the mobile phone can determine whether there are risk behaviors, the number of incoming calls blocked daily, risky APPs, and risky messages on the mobile phone based on the above call records and application usage duration.

[0325] In this embodiment, the above user behavior habit data may include at least one of user gender, user age group, user's permanent city, communication preference city, risk level, overseas contact habit, and usage habit of the first preset application. Exemplarily, the first preset application may be a meeting application, a financial application, etc. The usage habit of the first preset application indicates whether the user has the habit of using the first preset application.

[0326] Among them, the communication preference city, risk level, and overseas contact habit are determined based on the call records stored in the mobile phone. For example, if the user holding the mobile phone often makes and receives calls in city A, then the user's communication preference city is city A; if the user holding the mobile phone often answers risky calls (such as the number of risky calls received within a certain period exceeds a certain value), then the user's risk level is high risk, and the possibility that the user is induced to perform a risk operation is relatively high, that is, the risk of the user's property being damaged is relatively high; if the user holding the mobile phone often answers overseas calls (such as the number of overseas calls received within a certain period exceeds a certain value), it indicates that the user has overseas contacts. In other embodiments, the user behavior habit may also include APP preference (or called APP usage rate), APP usage type, etc., which are not specifically limited. Among them, in some embodiments, the risky calls here may refer to calls from suspicious numbers or unfamiliar numbers.

[0327] It should be noted that the generation of the user profile does not require high real-time performance, that is, it is not necessary to generate the user profile in real time according to the user's usage habits. The user profile can be generated in the form of a scheduled task. For example, the mobile phone can generate a corresponding user profile every preset time based on the user behavior habit data collected within the preset time. Of course, the mobile phone can also generate a corresponding user profile based on the user behavior habit data collected within the preset time and in combination with the historical user behavior habit data, where the historical user behavior habit data represents the user behavior habit data collected within a previous period of time. Among them, the preset time can be set according to requirements. For example, the preset time can be 1 day, 1 week, etc.

[0328] In some embodiments, in order to save the power consumption of the mobile phone to the greatest extent, the mobile phone can collect the user usage habit data when it is in the charging state for generating the user profile according to the user behavior data.

[0329] S515. In the case that the above risk detection result indicates a risk, the AI module sends a risk reminder instruction to the above system steward.

[0330] Among them, the above risk reminder instruction is used to instruct the mobile phone to perform a risk prompt operation. The risk prompt operation may include the mobile phone displaying a first risk prompt message (such as displaying the first risk prompt message in the form of a pop-up window) and / or sending a second risk prompt message to a target contact (such as sending the second risk prompt message to the target contact by means of a text message to prompt the user of the mobile phone through the target contact).

[0331] Specifically, if the above risk detection result indicates that the behavior corresponding to the first data has an unconventional behavior, that is, it indicates that the first data has unconventional behavior data, it means that the user is more likely to perform a risk operation, that is, it means that the mobile phone is more likely to perform a risk operation. Therefore, the AI module can send a risk reminder instruction to the above system steward to timely remind the user of the risk and reduce the probability of the user's property being damaged.

[0332] S516. The system steward receives the risk reminder instruction and performs a risk prompt operation.

[0333] In this application, after receiving the risk reminder instruction, the system steward can prompt the user of the risk. For example, in response to the opening operation of the do not disturb mode (such as the user opens such as Figure 13The immediate activation switch 6) under the Do Not Disturb function shown. The mobile phone collects Do Not Disturb data, which includes the activation status information of the Do Not Disturb mode. After that, when the mobile phone determines that the first data (which includes the Do Not Disturb data) has the first preset risk behavior data, the mobile phone can continue to use the user profile to determine whether the first data has unconventional behavior data, such as whether the Do Not Disturb data is unconventional behavior data, to obtain a risk detection result. When the behavior corresponding to the first data has unconventional behavior, that is, when the risk detection result indicates that the behavior corresponding to the first data has a risk, it means that the risky operation performed by the mobile phone does not belong to the user's regular operation, and the risk of the user's property being damaged is relatively high. Therefore, in order to protect the user's property safety, the mobile phone can display a pop-up window saying "Your current operation is suspected of having a risk. For your property safety, do not follow the instructions of strangers to transfer money and perform related payment operations" on the settings interface of the Do Not Disturb mode to timely remind the user of the risk and reduce the probability of the user's property being damaged.

[0334] Exemplarily, if the user of the mobile phone sets the Do Not Disturb mode from 9:00 to 11:00 in the morning, and according to the user profile, it can be determined that the user usually only sets the Do Not Disturb mode between 23:00 at night and 6:00 in the morning of the next day, it means that the user does not have the habit of setting the Do Not Disturb mode from 9:00 to 11:00 in the morning. Therefore, the mobile phone can determine that the behavior corresponding to the first data has a risk and needs to timely give a risk prompt to the user.

[0335] In some embodiments, considering that the payment behavior is generally carried out after the user is induced to perform a security risk behavior, in order to avoid the user's property being damaged, the above first preset risk behavior data may not include payment application startup data, that is, the first preset risk behavior data may include at least one type of data among preset screen sharing data, preset application jump behavior data, preset SMS behavior data, preset call behavior data, preset call forwarding setting data, preset flight mode setting data, preset harassment interception setting data, and preset Do Not Disturb setting data. The second preset risk behavior data may include preset payment application startup data.

[0336] Specifically, when the above risk detection result indicates that the behavior corresponding to the first data has a risk, the mobile phone can give a first risk prompt to remind the mobile phone user that a risk operation has been performed. And the mobile phone can continue to detect whether the mobile phone may perform a payment behavior, that is, detect whether the mobile phone has performed the second preset risk behavior data. In order to avoid the user's property being damaged, when the mobile phone detects that a payment application is launched, it can be considered that the mobile phone may perform a payment behavior. Correspondingly, when the mobile phone collects the application startup data as the preset payment application startup data (that is, the second preset risk behavior data), it can give a second risk prompt.

[0337] Among them, on the one hand, when the above risk detection result indicates that the behavior corresponding to the first data is risky, the mobile phone can continue to collect application startup data within the first collection duration. When the collected application startup data is the preset payment application startup data, the mobile phone can give a second risk prompt to achieve timely and accurate risk prompting. Among them, the second risk prompt can be to send a second risk prompt message to the target contact to timely dissuade the mobile phone user from performing a payment operation through the target contact, thereby avoiding losses to the user's property.

[0338] On the other hand, considering that there is a certain correlation between the user's payment behavior and the behavior corresponding to the first data performed previously, therefore, when the above risk detection result indicates that the behavior corresponding to the first data is risky, the mobile phone can determine the target data from the first data belonging to the first preset risk behavior data, and within the second collection duration corresponding to the target data, collect application startup data. Among them, the target data represents the first data belonging to the first preset risk behavior data, or the target data is the first data belonging to the first preset risk behavior data finally collected by the electronic device.

[0339] In some embodiments, when the above risk detection result indicates that the behavior corresponding to the first data is risky, the mobile phone can determine the number of data in the first data that belong to the first preset risk behavior data. If the number of data is one, that is, there is only one data in the first data that belongs to the first preset risk behavior data, then the first data that belongs to the first preset risk behavior data can directly be the target data, and the mobile phone can continue to collect application startup data within the second collection duration corresponding to the target data. If the number of data is multiple, that is, there are multiple data in the first data that belong to the first preset risk behavior data, then the mobile phone can determine the target data based on the multiple data. After that, the mobile phone can continue to collect application startup data within the second collection duration corresponding to the target data.

[0340] Among them, in one implementation manner, the mobile phone can use the data collected last among the above multiple data as the target data. The mobile phone can select the first data collected last as the target data according to the collection order of the above multiple data, that is, select the first data corresponding to the last operation performed by the mobile phone as the target data. For example, the mobile phone successively collects screen sharing data and do not disturb setting data. The screen sharing data and the do not disturb setting data are both first data and both belong to the first preset risk behavior data. When the risk detection result determined based on the first data indicates risk, the mobile phone can use the first data collected last, that is, the do not disturb setting data as the target data for collecting application startup data within the second collection duration corresponding to the do not disturb setting data.

[0341] In another implementation, the mobile phone can use each of the above-mentioned multiple data as the target data, or use the first data with the longest second collection duration as the target data. For example, taking the first data including do-not-disturb setting data and screen sharing data as an example, the preset second collection duration corresponding to the do-not-disturb setting data is 0.5 hours, and the second collection duration corresponding to the screen sharing data is 3 hours. The do-not-disturb setting data and the screen sharing data both belong to the preset risk behavior data. The mobile phone can select the data with the longest second collection duration in the first data as the target data, that is, the screen sharing data as the target data.

[0342] After that, after collecting the application startup data, the mobile phone can determine whether the application startup data is the preset payment application startup data. If the application startup data is the preset payment application startup data, the mobile phone can continue to give a risk prompt. If the application startup data does not belong to the preset payment application startup data, and the second collection duration corresponding to the target data has not ended, the mobile phone continues to detect whether a payment application has been started on the mobile phone, that is, continues to collect the preset payment application startup data. If the second collection duration corresponding to the target data has ended, it indicates that no payment application has been started on the mobile phone during this second collection duration, that is, the mobile phone has not performed a high-risk behavior. Therefore, the mobile phone can stop detecting whether a payment application has been started on the mobile phone. It should be understood that when there are multiple target data, the mobile phone can stop detecting whether a payment application has been started on the mobile phone when the second collection durations corresponding to all target data have ended.

[0343] Among them, each type of first preset risk behavior data can correspond to a second collection duration. In other words, each first data corresponds to a second collection duration. The second collection durations corresponding to different first preset risk behavior data are different. For example, for the preset screen sharing data, the time for the mobile phone to perform screen sharing may be relatively long (such as 2 hours). That is to say, the mobile phone can perform the payment application startup behavior after 2 hours of screen sharing. Therefore, the second collection duration corresponding to the preset screen sharing data can be set relatively long. For example, the second collection duration corresponding to the preset screen sharing data can be 3 hours, that is, the second collection duration corresponding to the screen sharing data is set to 3 hours. Another example is that for the preset do-not-disturb setting data, generally, the time for the mobile phone to set the do-not-disturb mode is relatively short (such as 2 minutes). For example, in response to the user's click operation on the do-not-disturb control, the do-not-disturb mode of the mobile phone can be turned on. The mobile phone can perform the payment application startup behavior after turning on the do-not-disturb mode. Therefore, the second collection duration corresponding to the preset do-not-disturb setting data is set relatively short. For example, the second collection duration corresponding to the preset do-not-disturb setting data can be 0.5 hours.

[0344] It can be understood that, referring to Figure 12 As shown, after the alarm manager sets the first collection duration, it can collect the first data in real time and perform real-time detection. In this way, when there is a risk in the current behavior, the user can be reminded in time to prevent the user's property from being damaged. After that, if the first data collected currently has the first preset risk behavior data, the system manager in the mobile phone can obtain the second collection duration corresponding to the first preset risk behavior data matching various first data from the above target configuration file, and update the above first collection duration to continue collecting application startup data within the second collection duration; if the currently collected application startup data is not the second preset risk behavior data and the current collection duration has not reached the second collection duration, the above system manager can continue to collect application startup data until the current collection duration reaches the second collection duration, and then stop collecting application startup data. That is to say, if the current collection duration reaches the second collection duration and all the application startup data collected within the second collection duration are not the second preset risk behavior data, it can be explained that the user behavior and / or application behavior do not have risks. Therefore, the above system manager can stop collecting application startup data.

[0345] In some embodiments, considering that the user may perform multiple payment behaviors, the above first data may also include application startup data. When the above risk detection result indicates that the behavior corresponding to the first data is risky, the mobile phone can give a first risk prompt. And the mobile phone can continue to detect whether the mobile phone may perform a payment behavior, that is, detect whether the mobile phone has performed the second preset risk behavior data. To avoid the user's property from being damaged, when the mobile phone detects that a payment application is launched, it can be considered that the mobile phone may perform a payment behavior. Correspondingly, when the mobile phone collects the application startup data as the preset payment application startup data (i.e., the second preset risk behavior data), it can give a second risk prompt.

[0346] It can be understood that if the above risk detection result indicates that the behavior corresponding to the first data is not risky, the AI module does not send the first indication information to the above system manager.

[0347] Specifically, if the above risk detection result indicates that the behavior corresponding to the first data does not have an unconventional behavior, that is, the risk detection result indicates that the first data does not have unconventional behavior data, it means that the risky operation performed by the mobile phone belongs to the user's regular operation, and this operation does not belong to a risk operation. Therefore, the mobile phone does not need to give a risk prompt to the user to avoid affecting the user's use.

[0348] In some embodiments, when the above risk detection result indicates that the behavior corresponding to the first data has no risk, if the above first collection duration has not ended, the system manager in the mobile phone can continue to collect the first data for further determining whether the mobile phone performs a risk operation by using the first data.

[0349] In other embodiments, when the above risk detection result indicates that the behavior corresponding to the first data has no risk, if the mobile phone is still within the second collection duration corresponding to a certain first preset risk behavior data, the system manager in the mobile phone can continue to collect the first data corresponding to the first preset risk behavior data. For example, if the mobile phone is still within the first collection duration corresponding to the preset screen sharing data, it indicates that the mobile phone can continue to detect whether the mobile phone has performed screen sharing, that is, it can continue to collect screen sharing data.

[0350] Exemplarily, if the mobile phone user sets the do not disturb mode from 9:00 to 11:00 in the morning, and it can be determined according to the user portrait that the user usually also sets the do not disturb mode between 9:00 and 11:00 in the morning, it indicates that the user does not have the habit of setting the do not disturb mode from 9:00 to 11:00 in the morning. Therefore, the mobile phone can determine that the behavior corresponding to the first data has no risk, that is, the mobile phone does not need to give a risk prompt to the user.

[0351] The process of giving a risk prompt based on the target text message is introduced above. Next, a possible implementation process of giving a risk prompt based on received calls, text messages, and installed APPs will be continued. As Figure 14 shown, the process is as follows:

[0352] First, when the mobile phone receives a call or text message from a gray number (or a suspicious number), or installs a gray APP (or an unknown application), it indicates that the user may be at risk of property loss. Then, the mobile phone can determine whether the gray sample data meets the first trigger condition. The first trigger condition may include at least one of the following: the call duration corresponding to the gray number exceeds the first preset duration (or is described as the first preset threshold), there is a reply message corresponding to the text message event, the access duration of the link address in the text message event exceeds the second preset duration, copying the information of the target text message type in the text message event, and the usage duration of the gray app exceeds the third preset duration. Exemplarily, the link address may include the web address in the text message.

[0353] After that, if the user installs or opens a meeting or unknown APP within the preset time, and the phone enables screen sharing, or the phone blocks communication behavior, it indicates that the risk level of the phone is medium risk, and further monitoring of the trigger behavior based on the phone is required. Among them, communication behavior includes call forwarding, aperiodic do not disturb, and intercepting all calls and / or text messages. This aperiodic do not disturb refers to the do not disturb mode set under abnormal circumstances. For example, if the user sets the do not disturb mode from 8:00 to 9:00 every day, but the user sets the do not disturb mode at 12:00 today, it means that the user has set an aperiodic do not disturb mode. In this embodiment, the preset time is 24 hours.

[0354] Finally, if the phone has a payment behavior, it indicates that the risk level of the phone is high risk. Among them, the payment behavior can be that the phone automatically jumps to the payment interface, or the phone responds to the user's trigger operation to open the payment application or payment interface, etc.

[0355] In some embodiments, when the application installed on the phone belongs to a black APP, as shown in Figure 15 the phone can display information such as the application name (AAAAAA), application version (13.5.0), application storage (30.6MB), and risk reminder (this application is a risk APP, there are bad contents such as inducing consumption, using this application will bring greater risks) on the installation interface.

[0356] Exemplarily, taking the example that the user portrait corresponding to the phone does not include the user portrait label of having overseas contacts, the phone receives a call from an overseas number. After that, the phone answers the call. If the call duration of this call exceeds the preset duration, it indicates that the risk level of the phone is low risk. If user A also enables screen sharing and / or blocks communication behavior within the preset time, it indicates that the risk level of the phone is medium risk. If user A also performs a payment behavior, it indicates that the risk level of the phone is high risk, that is to say, the possibility that the resources of user A will be lost is very high. Therefore, it is necessary to remind user A in time to prevent the property of user A from being lost.

[0357] In some embodiments, the present application provides a computer-readable storage medium, including computer instructions, which when running on an electronic device, cause the electronic device to execute the method described above.

[0358] In some embodiments, the present application provides a computer program product, which when running on an electronic device, causes the electronic device to execute the method described above.

[0359] From the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above functional modules is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0360] In several embodiments provided in the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in electrical, mechanical or other forms.

[0361] The units described as separate components may or may not be physically separated. The components displayed as units can be one physical unit or multiple physical units, that is, they can be located in one place or distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0362] In addition, each functional unit in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0363] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read only memory (ROM), random access memory (RAM), magnetic disks or optical discs and other various media that can store program codes.

[0364] The above content is only a specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be covered by the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.

Claims

1. A risk warning method, characterized in that, Applied to an electronic device, the method includes: Receiving a communication event; wherein, the communication event includes a preset text event and / or an incoming call event; When the sender number corresponding to the preset text event belongs to an unfamiliar number and the first interaction behavior meets a preset first trigger condition, collecting first data; wherein, the preset first trigger condition includes at least one of calling the sender number corresponding to the preset text event, having a reply message corresponding to the preset text event, accessing the link address in the preset text event, and copying the text message content in the preset text event; the first data includes user behavior data and / or the running data of an application in the electronic device; When there is first preset risk behavior data in the first data, using an AI module to perform a risk prompt operation based on the first data; When there is no such first preset risk behavior data in the first data, stopping collecting the first data.

2. The method according to claim 1, wherein When the communication event is a preset text event, after receiving the communication event, the method further includes: When the sender number does not meet a preset text message interception rule, displaying the text message content corresponding to the preset text event; wherein, the preset text message interception rule is a rule capable of intercepting the preset text event; The step of collecting first data when the sender number corresponding to the preset text event belongs to an unfamiliar number and the first interaction behavior meets a preset first trigger condition includes: When the preset text event is not intercepted and the sender number corresponding to the preset text event belongs to an unfamiliar number, if the first interaction behavior meets the preset first trigger condition, collecting the first data.

3. The method according to claim 2, characterized in that, The preset text message interception rule is determined based on the phone numbers added by the user in the white list and the black list and / or whether a target interception function is enabled, wherein the target interception function includes at least one of a harassment interception function, an all-number interception function, an unknown / hidden number interception function, a strange text message interception function, and an intelligent interception function, and the intelligent interception function is a function of judging whether to intercept the preset text event by identifying the content corresponding to the preset text event.

4. The method according to any one of claims 1 to 3, characterized in that The preset first trigger condition includes at least one of a call duration with the sender number being greater than a first preset duration, having a reply message corresponding to the preset text event, an access duration of accessing the link address in the preset text event being greater than a second preset duration, and copying the target text message content corresponding to a target text message type in the preset text event; wherein, the target text message type includes at least one of the link address, phone number, bank card number, and social account.

5. The method according to claim 2, wherein The step of collecting the first data if the first interaction behavior meets the preset first trigger condition includes: Identify the SMS content corresponding to the preset text event according to a regular expression and / or a language recognition model to obtain an SMS recognition result, where the SMS recognition result is used to indicate whether preset SMS content exists in the SMS content corresponding to the preset text event, and the preset SMS content is the SMS content corresponding to the target SMS type; In the case where the SMS recognition result indicates that the preset SMS content exists in the SMS content corresponding to the preset text event, extract the preset SMS content existing in the preset text event to obtain at least one piece of SMS data; where the SMS data includes the target SMS type and / or the target SMS content corresponding to the target SMS type; When a first interaction behavior of the user with respect to the target SMS content in the preset text event is detected and the first interaction behavior meets a preset first trigger condition, collect the first data.

6. The method according to claim 5, characterized in that The SMS recognition result includes a first detection result and a second detection result. Identifying the SMS content corresponding to the SMS event according to a regular expression and / or a language recognition model to obtain an SMS recognition result includes: Input the SMS content corresponding to the SMS event into the regular expression to obtain a first detection result, where the first detection result is used to indicate whether the SMS content corresponding to the SMS event includes content of a first SMS type, and the first SMS type includes at least one of a link address, a telephone number, and a bank card number; Input the SMS content corresponding to the SMS event into the language recognition model to obtain a second detection result, where the second detection result is used to indicate whether the SMS content corresponding to the SMS event includes content of a second SMS type, and the second SMS type includes a social account.

7. The method according to any one of claims 1 to 6, characterized in that The preset text event is a text event received that contains text content that conforms to preset text content, and the preset text is text content with a length less than a preset length.

8. The method according to claim 1, wherein In the case where the communication event is an incoming call event, after receiving the communication event, the method further includes: In the case where the calling number corresponding to the incoming call event belongs to an unfamiliar number and a second interaction behavior meets a preset second trigger condition, collect the first data; where the preset second trigger condition includes answering the calling number corresponding to the incoming call event; In the case where the first data has the first preset risk behavior data, use the AI module to perform a risk prompt operation based on the first data; In the case where the first data does not have the first preset risk behavior data, stop collecting the first data.

9. An electronic device, characterized in that, The electronic device includes a display screen, a memory, and one or more processors; the display screen, the memory, and the processor are coupled; the display screen is used to display unblocked communication events, the memory is used to store computer program code, and the computer program code includes computer instructions; when the processor executes the computer instructions, the electronic device executes the risk prompt method according to any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, Comprising computer instructions, when the computer instructions are run on an electronic device, enabling the electronic device to execute the risk prompting method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method for mobile phone to prevent from spam

    CN101262675A

  • Telephone processing method and device

    CN104010065A

  • Communication event processing method and apparatus

    CN106302938A

  • Telecommunication fraud recognition method and data processing equipment

    CN107169629A

  • Method for preventing harassment of strange incoming call, terminal equipment and storage medium

    CN110191222A