Early warning system and method for helping information network criminal activity case
By integrating multi-source data to establish a multi-dimensional early warning model, screening and generating a warning list, the problem of insufficient early warning of assisted letter cases in existing technologies is solved, advance warning and evidence support are achieved, the incidence rate of assisted letter cases is reduced and the efficiency of case handling is improved.
Patent Information
- Application Number
- CN202510964653.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-11
- Publication Date
- 2025-09-26
AI Technical Summary
Existing technologies lack effective pre-warning measures for potential aiding and abetting behavior. Traditional investigative methods are unable to cope with intelligent criminal methods, cannot effectively curb the occurrence of aiding and abetting cases, and are difficult to determine the subjective knowledge of the suspect.
By integrating mobile phone call records, bank card transaction limit increase records, express mail information and virtual account login information, a multi-dimensional early warning model is established. Abnormal behaviors are screened using Excel and VLOOKUP, FILTER and other functions, and an early warning list is generated. Pre-emptive warnings and dissuasion are then carried out through data integration and early warning modules.
It achieves advance warning of potential aiding and abetting behavior, reduces the incidence of aiding and abetting cases, provides evidence support for the subjective knowledge of suspects, and improves case handling efficiency and accuracy.
Smart Images

Figure CN120707173A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of telecommunication network crime prevention, and in particular to an early warning system and method for assisting in information network crime cases. Background Art
[0002] With the rapid development of the information society, new cybercrimes, represented by telecommunications and internet fraud, have become mainstream, posing a significant challenge to public security organs. Assisted fraud cases, a key component of telecommunications and internet crime, are experiencing a rapid increase in incidence. Currently, these cases exhibit the following characteristics: The suspects are typically young, low-educated, and low-income, with criminal organizations even targeting minors and students. The crimes are clearly organized into chains and hierarchies, with the black and gray industries becoming increasingly sophisticated, and the methods and means used to commit crimes becoming increasingly sophisticated.
[0003] Public security agencies typically provide early warnings for victims of telecom fraud, but lack effective preemptive measures for potential suspects in fraudulent schemes. Fraudsters primarily commit crimes by mailing SIM cards, bank cards, and virtual accounts. Traditional investigative and combative methods lag behind intelligent criminal tactics, making it difficult to effectively curb fraudulent schemes and quickly determine the suspect's knowledge during case investigation.
[0004] Therefore, there is an urgent need for a system and method that can integrate multi-source data and provide advance warning of potential complicity behavior to address the shortcomings of the existing technology. Summary of the Invention
[0005] The purpose of the present invention is to provide an early warning system and method for cases of aiding information network crime activities. By integrating multi-source data such as mobile phone card call records, bank card transaction increase records, express mail information and virtual account login information, a multi-dimensional early warning model is established to achieve advance warning of potential aiding and abetting behaviors, reduce the incidence of aiding and abetting cases, and provide evidence support of the suspect's subjective knowledge for case handling.
[0006] The technical solution adopted by the present invention is as follows: an early warning system for assisting in information network crime cases, comprising:
[0007] Mobile phone card call record warning module: used to obtain call record data from the three major operators, filter out records of local numbers calling out-of-local numbers, calculate the number of out-of-local numbers called in a single day through the COUNTIF function, use the FILTER function to filter out local numbers that call out-of-local numbers more than 50 times in a single day, and then use the VLOOKUP function to associate the identity information of the target number to implement early warning of abnormal mobile phone card usage behavior.
[0008] Bank card transaction limit increase record warning module: used to obtain customer transaction limit increase records of major banks, filter out accounts with daily single transaction limit ≥ 1 million yuan and daily cumulative transaction limit ≥ 5 million yuan through the FILTER function, extract accounts that meet the conditions after deleting duplicate values, and then use the VLOOKUP function to associate the customer information of the target account to implement early warning of abnormal bank card transaction limit increase behavior.
[0009] Express business keyword warning module: used to obtain mailing information in the express delivery industry. On the basis of the express delivery industry's strict control of mailing item information, it screens bank cards, mobile phone cards, ID card copies, and U-Shield keywords, extracts relevant information through advanced screening, and implements early warning of abnormal express delivery behavior.
[0010] Virtual account early warning module: used to obtain virtual account login logs provided by third-party companies, use the COUNTA function to calculate the number of logins in different locations, and use the function to filter out virtual accounts with IP addresses from more than five provinces or more than two countries in a single day. Then, use the VLOOKUP function to filter out the registration information of virtual accounts that need to be warned, thereby implementing early warnings for abnormal virtual account login behavior.
[0011] Data integration and early warning module: used to integrate the early warning information of the above modules, establish an early warning database, provide advance warning and dissuasion to potential accomplices who meet the early warning conditions, and record early warning information to provide evidence support for case handling.
[0012] A method for early warning of a letter-related case, characterized by comprising the following steps:
[0013] (1): Steps for warning of mobile phone card call records:
[0014] Obtain call log data from the three major operators and filter out records of local numbers calling outbound numbers.
[0015] Use the COUNTIF function to count the number of out-of-town calls made in a single day.
[0016] Use the FILTER function to filter out local numbers that call out-of-town numbers more than 50 times in a single day.
[0017] Use the VLOOKUP function to associate the target number's identity information and generate a mobile phone card call record warning list.
[0018] (II): Steps for early warning of bank card transaction limit increase records:
[0019] Obtain customer transaction limit increase records of major banks.
[0020] Use the FILTER function to filter out accounts with a single transaction amount of ≥ 1 million yuan per day and a single-day cumulative transaction amount of ≥ 5 million yuan.
[0021] After deleting duplicate values, extract the accounts that meet the conditions, use the VLOOKUP function to associate the customer information of the target account, and generate a bank card transaction limit increase record warning list.
[0022] (III): Express business keyword warning steps:
[0023] Get mailing information for the express delivery industry.
[0024] Filter bank cards, mobile phone cards, ID card copies, and U-Shield keywords, extract relevant information through advanced filtering, and generate a keyword warning list for express delivery services.
[0025] (IV): Virtual account warning steps:
[0026] Obtain the virtual account login log provided by the third-party company.
[0027] Use the COUNTA function to count the number of logins to different locations, and filter out virtual accounts with IP addresses logged in from more than five provinces or more than two countries in a single day.
[0028] Use the VLOOKUP function to filter out the registration information of virtual accounts that require warnings and generate a virtual account warning list.
[0029] (V): Integration and early warning steps:
[0030] Integrate the above-mentioned warning lists and establish a warning database.
[0031] Provide advance warning and dissuasion to potential accomplices in the warning database, and record the warning information.
[0032] The beneficial effects of the present invention are:
[0033] Early warning to reduce the incidence rate: Through a multi-dimensional early warning model, early warning of potential aiding and abetting behaviors can be achieved, and the occurrence of aiding and abetting cases can be stopped in time, effectively reducing the incidence rate of aiding and abetting cases.
[0034] Clarify subjective knowledge: Early warning records can be used as evidence to clarify the subjective knowledge of the suspect when committing the crime, thereby improving the quality and efficiency of case handling.
[0035] Multi-source data integration to improve early warning accuracy: Integrate multi-source data such as mobile phone card call records, bank card transaction increase records, express mail information and virtual account login information to identify potential fraudulent behavior from multiple angles and improve the accuracy and comprehensiveness of early warnings.
[0036] The technology is practical and has high reuse value: The technology and data of this system are practical, have high reuse value, and can be promoted and applied in actual work. It is not only applicable to cases involving assistance and letters, but can also play a role in other police types and cases by adding more industry information and related factors. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 : A schematic diagram of the module structure of an early warning system that helps information network criminal activities cases.
[0038] Figure 2 : Schematic diagram of the workflow of the mobile phone card call record warning module.
[0039] Figure 3-Figure 7 : Flowchart of a practical case study on mobile phone card call record warning.
[0040] Figure 8 : Schematic diagram of the workflow of the bank card transaction limit increase record warning module.
[0041] Figures 9-12 : Flowchart of a practical case study on bank card transaction limit increase record warning.
[0042] Figure 13 : Schematic diagram of the workflow of the express delivery service keyword warning module.
[0043] Figure 14 : Flowchart of a practical case study on keyword warning for express delivery business.
[0044] Figure 15 : Schematic diagram of the workflow of the virtual account warning module.
[0045] Figure 16 : Flowchart of practical case of virtual account warning module.
[0046] Figure 17 : An early warning system page diagram to help information network criminal activities cases.
[0047] Figure 18 : JSON data format example diagram.
[0048] Figure 19 : Comparison chart of technology stack upgrade solutions.
[0049] Figure 20 : Code-level optimization strategy code examples.
[0050] Figure 21 : Architecture design optimization code examples.
[0051] Figure 22 : Dynamic sharding adjustment.
[0052] Figure 23 and Figure 24 : Code examples for parallel computing scenarios where Hadoop MapReduce is applicable and code examples for the core advantages of Spark.
[0053] Figures 25-28 : The technical positioning of HTML5, Vue.js, and React in the front-end technology stack diagram; code examples for analyzing key HTML5 technologies; Vue.js 3 architecture; performance-critical codes.
[0054] Figures 29-34 : Back-end technology comparison table; Spring Boot ecological matrix; Django technology puzzle; performance key indicator comparison; security protection comparison; cutting-edge trend adaptation.
[0055] Figure 35 : Layered retry strategy architecture diagram.
[0056] Figure 36 : Hierarchical alarm strategy table.
[0057] Figure 37-Figure 39 : Local staging code example; distributed cache code example; data synchronization pipeline code example. Figures 40-45 :Data encryption policy table; key security storage; single-node encryption performance indicators; code examples for implementing the Level 3 security requirements; key access control; key security backup code examples.
[0058] Figures 46-49 :TLS1.3 encryption configuration diagram; National encryption compatible configuration (Nginx example) code example; Information Security Technology 2.0 Level 3 requirement code example; Real-time threat detection code example.
[0059] Figures 50 to 54 : Desensitization rule example table; database layer desensitization code example; application layer dynamic desensitization (Java) code example; stream processing desensitization (Flink) code example; application scenarios.
[0060] Figure 55-56 : RBAC model enhanced architecture; role authority matrix design.
[0061] Figures 57-59 : Two-person authorization operation code example; operation watermark tracing code example; massive log storage solution.
[0062] Figure 60 : Core performance indicator table.
[0063] Figure 61 : Concurrency capability comparison table.
[0064] Figure 62 : 7×24 hours reliability and stability indicators.
[0065] Figure 63 : Flowchart of fault self-healing mechanism. DETAILED DESCRIPTION
[0066] The embodiments of the present invention are described in detail below. It should be noted that the following detailed descriptions are illustrative and are intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the art to which this application belongs.
[0067] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components and / or combinations thereof.
[0068] like Figure 1 As shown, an early warning system that helps to prevent information network crime cases includes: a mobile phone card call record early warning module; a bank card transaction limit increase record early warning module; an express service keyword early warning module; a virtual account early warning module; and a data integration and early warning module.
[0069] A method for assisting in early warning of information network crime cases, comprising:
[0070] like Figure 2 As shown, the specific implementation of the mobile phone card call record warning module
[0071] like Figure 3 1. Data Acquisition: We established a data interface with China Mobile, China Unicom, and China Telecom, using REST API technology and HTTPS data transmission protocol to obtain call log data in real time. The data format is uniformly JSON to ensure secure and efficient data transmission.
[0072] 2. Filter out-of-town call records: From the acquired call records, filter out the call records where the calling location is local (such as XXX Banner, Inner Mongolia) and the called location is out-of-town (excluding Inner Mongolia).
[0073] like Figure 4 3. Calculate the number of calls: Use the COUNTIF function in Excel, with the calling number as the keyword, to calculate the number of times each local number calls an out-of-town number in a single day.
[0074] like Figure 5As shown, 4. Filter abnormal numbers: Use the FILTER function in Excel to filter out local numbers that call out-of-town numbers more than 50 times in a single day.
[0075] like Figure 6 and Figure 7 As shown, 5. Associate identity information: Use the VLOOKUP function to associate the cardholder's name and ID number identity information with the abnormal number from the customer information table provided by the operator.
[0076] 6. Generate warning list: Organize abnormal numbers and associated identity information to generate a warning list of mobile phone card call records and mark them in the system.
[0077] like Figure 8 As shown, the specific implementation of the bank card transaction limit increase record warning module
[0078] 1. Data Acquisition: We establish data interfaces with major banks, using REST API technology and HTTPS data transmission protocol to obtain daily customer transaction limit increase records, including bank card number, increase date, single limit increase amount, and cumulative limit increase information. The data format is JSON.
[0079] like Figure 9 As shown, 2. Filter accounts with single credit limit increases: Use the FILTER function to filter out accounts with single credit limit increases of ≥ 1 million yuan from the obtained transaction credit limit increase records.
[0080] like Figure 10 As shown, 3. Filter accounts with cumulative credit limit increases: Use the FILTER function to filter out accounts with cumulative credit limit increases of ≥ 5 million yuan.
[0081] like Figure 11 As shown, 4. Extract non-duplicate accounts: Combine the above two screening results, delete duplicate bank card numbers, and extract accounts that meet both single increase ≥ 1 million yuan and cumulative increase ≥ 5 million yuan.
[0082] like Figure 12 As shown, 5. Associate customer information: Use the VLOOKUP function to associate the customer's name and ID number information with the bank card number from the customer information table provided by the bank.
[0083] 6. Generate warning list: Organize the accounts that meet the conditions and the associated customer information to generate a bank card transaction limit increase record warning list, and mark it in the system.
[0084] like Figure 13 As shown, the specific implementation of the express service keyword warning module
[0085] 1. Data Acquisition: We establish data interfaces with major express delivery companies, using REST API technology and HTTPS data transmission protocol to obtain express delivery information, including the delivery area code, delivery date, delivery item information, sender name, and ID number. The data format is JSON.
[0086] 2. Set keywords: Set bank card, mobile phone card, ID card copy, and USB shield as keywords, and add the wildcard "*" before and after the keywords, such as "bank card", "mobile phone card", "ID card", and "U shield".
[0087] like Figure 14 As shown, 3. Advanced filtering: Use the advanced filtering function in Excel, with the mailing item information as the filter column and the set keywords as the conditional area to filter out the mailing records containing the keywords.
[0088] 4. Generate a warning list: Organize the screened mailing records to generate a keyword warning list for express delivery services, including the mailer’s name, ID number, and mailed item information, and mark them in the system.
[0089] like Figure 15 As shown, the specific implementation of the virtual account warning module
[0090] 1. Data Acquisition: Establish a data interface with third-party companies (such as WeChat and QQ virtual account service providers) using REST API technology and HTTPS data transmission protocol to obtain virtual account login logs, including virtual account numbers, login IP addresses, and login times. The data format is JSON.
[0091] like Figure 16 As shown, 2. Calculate the number of login locations: Use the COUNTA function in Excel to process the login IP address of each virtual account and calculate the number of logins to different locations (provinces or countries) in a single day.
[0092] 3. Filter abnormal accounts: Filter out virtual accounts whose IP addresses log in to the account from more than 5 provinces or more than 2 countries in a single day.
[0093] 4. Associate registration information: Use the VLOOKUP function to associate the registrant’s name and ID number information with the abnormal virtual account from the virtual account registration information table provided by the third-party company.
[0094] 5. Generate a warning list: Organize abnormal virtual accounts and associated registration information to generate a virtual account warning list and mark them in the system.
[0095] like Figure 1 and Figure 17As shown, the specific implementation methods of integration and early warning
[0096] 1. Data Integration: Import the warning lists generated by the above modules into the warning database. Using a unified data center and message queue (MQ) mechanism, we perform deduplication and integration to create a unified list of potential collaborators. We uniquely identify mobile phone card, bank card, and courier information data through ID numbers, enabling the integration of multi-dimensional warning information.
[0097] 2. Early warning and dissuasion: The system sends early warning information to potential accomplices, including phone notifications and SMS reminders, to inform them of the potential illegality of their behavior and to dissuade them.
[0098] 3. Record keeping: The system automatically records the warning time, warning method, and feedback information from potential helpers to form a complete warning record, providing evidence support for subsequent case handling.
[0099] 4. Case association: When a case of assisting in a crime occurs, the system can be used to query the early warning records of the suspect, quickly determine his subjective knowledge, and improve case handling efficiency.
[0100] As an optimization of the embodiment, the specific technical details of the data interface and data acquisition
[0101] Interface technology and data transmission protocol: The interface technology adopts the REST API, which is lightweight, easy to understand and implement, and supports multiple data formats. The data transmission protocol uses HTTPS, which uses SSL / TLS encryption technology to ensure confidentiality, integrity, and identity authentication during data transmission.
[0102] Data format: The data format uniformly uses JSON, which has the advantages of concise syntax, easy parsing and generation, and low bandwidth usage. It can efficiently transmit data between different platforms and programming languages. For example, when transmitting user order information, the JSON format can be expressed as: Figure 18 shown.
[0103] As an optimization of the embodiment, the detailed basis of the core algorithm and threshold setting is
[0104] Quantitative Basis and Optimization Mechanism for Warning Thresholds: Thresholds are set based on statistical data on the frequency and monetary distribution of behaviors involved in XXX Banner's sponsored credit cases over the past 1-3 years. For example, a requirement for a mobile phone card to make ≥50 out-of-province calls per day is based on historical data showing that the average number of out-of-province calls made by the mobile phone cards involved in the case is concentrated at 50 or more per day. A requirement for a bank card limit increase of ≥1 million yuan per transaction and ≥5 million yuan per transaction is based on the bank's large-value transaction warning standards and the capital flow characteristics of sponsored credit cases. Thresholds support dynamic adjustment, including automatic optimization and manual configuration. Automatic optimization uses machine learning algorithms to analyze historical warning data based on case trends and automatically adjusts thresholds. Manual configuration allows administrators to customize thresholds through the system interface.
[0105] Efficiency optimization technology for big data processing: Considering that Excel has fatal flaws when processing massive amounts of data; first, memory is limited: the maximum number of rows in Excel is about 1.04 million (increased to about 10 million rows in the latest version), but operators may have hundreds of millions of call records per day, far exceeding Excel's processing capacity. Second, the computational efficiency is low: COUNTIF needs to traverse all rows on the entire data, with a time complexity of O(n 2 ), 1 billion pieces of data require trillions of calculations, which cannot be completed by a single machine. Crash risk: When the amount of data exceeds 500MB, Excel frequently freezes and crashes, and stability cannot be guaranteed. Therefore, when processing massive amounts of data, technology stack upgrades, code-level optimization strategies, and architecture design optimization solutions are adopted. Figure 19 As shown in the figure, the technology stack upgrade includes using Hadoop HDFS / Cloud Object Storage for data storage, Spark SQL / Hive on Tez for batch computing, Presto / Impala / ClickHouse for interactive query, Flink / Spark Streaming for stream processing, and Elasticsearch / Apache Druid for data indexing. Figure 20 As shown in , code-level optimization uses a distributed aggregation method to reduce computational complexity. Figure 21 As shown in the figure, the architecture design optimization adopts distributed collection layer, real-time stream processing and batch warehouse architecture to improve data processing efficiency. Figure 22 As shown, data sharding (dynamic sharding adjustment), as Figure 23 and Figure 24 As shown, the application of parallel computing technology (such as Hadoop MapReduce and Spark).
[0106] As an optimization of the embodiment, the details of the system architecture and technical implementation
[0107] System technology stack and architecture design
[0108] like Figure 25As shown, front-end technology: HTML5, Vue.js, React technology stack is used to achieve cross-terminal compatible page structure and complex single-page application development. Figure 26 As shown in the figure, HTML5 uses Canvas to draw call heat maps and Web Worker to process big data; Figure 27 and Figure 28 As shown, Vue.js 3 uses a combined API and virtual list technology to handle massive data rendering.
[0109] like Figure 29 As shown, backend technology: Spring Boot is selected as the backend technology, which has the advantages of strong typing, JVM ecology, and high concurrency support. It is suitable for high-concurrency microservices, financial systems, and big data interface scenarios. Figure 30 As shown, the SpringBoot ecosystem matrix includes Spring Cloud, Spring Data, and Spring Security. Choose Spring Boot when: you need to handle high-concurrency scenarios with >1000 TPS, deeply integrate Hadoop / Spark / Flink, have a JVM ecosystem, require millisecond-level response latency, and have existing Java technology assets. Figure 31 As shown, choose Django when: rapid prototyping (MVP development speed increased by 40%), data science team-led development (direct integration of Pandas / NumPy), small to medium-sized internal management system (<500QPS), and need a full-stack solution (with built-in Admin / CMS).
[0110] like Figure 32 and Figure 33 and Figure 34 As shown, hybrid architecture tips: In carrier-grade systems, it is recommended to use Spring Boot to build core billing / call processing microservices, paired with Django to develop the operations and analysis backend, and expose interfaces uniformly through the API gateway. This not only ensures the performance of core modules but also improves management-side development efficiency.
[0111] Data interaction process between modules: Data sharing adopts a unified data middle platform and message queue MQ mechanism. Cross-module correlation analysis associates mobile phone cards, bank cards, and express information data through the unique identification of ID card numbers to achieve the integration of multi-dimensional warning information.
[0112] As an optimization of the embodiment, exception handling and system stability mechanism
[0113] like Figure 35 As shown in the figure, fault-tolerant processing of data acquisition anomalies adopts a layered retry strategy architecture, including immediate retry for transient errors, exponential backoff retry for network errors, and interception and degradation of server-side error circuit breakers.
[0114] 1. Retry immediately (fail quickly). Applicable scenarios: network jitter and instantaneous lock conflicts.
[0115] 2. Retry at fixed intervals.
[0116] Applicable scenario: third-party API flow control (such as 200 times per minute)
[0117] Algorithm formula: delay = fixedInterval
[0118] 3. Exponential Backoff
[0119] Applicable scenarios: server overload, database pressure
[0120] Algorithm formula: delay = base * 2^(attempt) + random_jitter
[0121] 4. Adaptive Retry (Advanced)
[0122] Applicable scenarios: Cloud service dynamic expansion and contraction environment
[0123] Core algorithm: Dynamically adjust intervals based on historical response times
[0124] like Figure 36 As shown, abnormal log recording and alarm mechanism (such as notifying administrators via email or SMS); hierarchical alarm strategy. It is recommended to adopt a regionally deployed alarm engine + cross-regional redundant communication channels. Core service P0 alarms must be configured with a three-level escalation strategy (duty officer → supervisor → CTO). Key alarm channels are automatically tested every 24 hours to ensure that they can still be reached under extreme failures. Figure 37 and Figure 38 and Figure 39 As shown, at the same time, a local temporary storage mechanism is adopted, based on the local persistent cache of RocksDB to ensure that data is not lost.
[0125] Verify and optimize warning accuracy: Establish a police review mechanism for warning lists and manually verify system warning results. Use historical warning data to train classifiers and employ supervised learning algorithms (such as random forests and XGBoost) to build warning models, dynamically improving warning accuracy.
[0126] As an optimization of the embodiment, privacy protection and data security measures
[0127] Encryption and desensitization of sensitive data: Figure 40 As shown in the figure, encryption strategy, data storage encryption uses AES-XTS, AES-GCM, AES-CBC+HMAC algorithms, such as Figure 41As shown, the key is stored securely; Figure 42 As shown in, encryption performance indicators (single node); Figure 43 As shown, the requirements of Level 3 security protection are met; Figure 44 As shown, key access control; Figure 45 As shown, the key is securely backed up; Figures 46-49 As shown, data transmission encryption uses AES-GCM+TLS1.3 protocol. Figures 50 to 54 As shown, the desensitization rules for sensitive fields follow relevant national standards and industry specifications, such as the first 6 digits + asterisk + last 4 digits of the ID card number, and the first 3 digits + asterisk + last 4 digits of the mobile phone number.
[0128] like Figure 55 and Figure 56 As shown in Figure 1, permission control and audit logs: Using the RBAC model permission matrix, different roles (such as super administrators, security auditors, and on-duty police officers) have different data access scopes and functional permissions. Figures 57 to 59 As shown, key operations (such as data export and early warning record modification) implement a two-person authorization mechanism and perform complete audit log records to ensure that the operations are traceable.
[0129] As an optimization of the embodiment, test verification and actual combat data
[0130] like Figures 60 to 63 As shown in the system performance test data, the system's processing time and concurrency capabilities performed well at different data scales. For example, full-link processing of 100,000 data records per day took 28 seconds, and real-time risk control and offline report processing of 100 million data records per day took 22 minutes. The maximum concurrent query rate on a single node reached 12,000 QPS, and the maximum concurrent query rate on a cluster reached 98,000 QPS.
[0131] Quantitative effects of actual cases: the early warning accuracy of each module reached more than 92%, the average advance warning time was 3.2 days, and the cumulative economic losses recovered through early warning interception and assistance cases exceeded 20 million yuan.
[0132] As an optimization of the embodiment, scalability and compatibility
[0133] New Alert Dimension Expansion Solution: The system utilizes a modular design, supporting the dynamic addition of new alert modules without modifying the core code. A custom alert rule configuration interface is provided, allowing for the configuration of new keywords and thresholds. For example, alerts can be added for when gambling-related individuals in anti-drug cases enter the police station's jurisdiction, or when key personnel under the police station's jurisdiction enter sensitive areas.
[0134] Cross-platform and cross-system compatibility: Comply with the public security information resource service interface specifications and connect with other public security information systems (such as anti-fraud platforms, population information databases, key personnel databases, and drug-related personnel databases) through the CA certification system to ensure the standardization and security of data exchange.
[0135] As an optimization of the embodiment, the details related to legal stability
[0136] Differentiation compared with existing technologies: Compared with existing technologies (traditional post-investigation), the present invention achieves advance warning (3.2 days in advance on average), and the warning records can directly prove subjective knowledge. The automatic association of multi-dimensional data improves case handling efficiency by 40%.
[0137] Through multi-source data integration and multi-dimensional early warning models, the present invention achieves advance warning of potential aiding and abetting behaviors, effectively reduces the incidence of aiding and abetting cases, provides strong evidence support for case handling, and has high practical value and promotion significance.
[0138] To further support the innovation and practicality of the patent, the following real cases are added to the detailed implementation method:
[0139] 1. Mobile phone card call record warning module: successfully intercepted the "GOIP diversion" fraud case
[0140] Case Background: In XX month of 20XX, the XXX Banner Public Security Bureau detected, through this module, that the local number 183XXXXXXXX made 72 calls to numbers outside Shandong and Guangdong provinces in a single day, far exceeding the warning threshold of 50. The system automatically linked the cardholder to Bu, who, upon verification, had no regular interprovincial calling needs.
[0141] System operation process
[0142] Data acquisition and screening: Obtain call records from the three major operators and screen out records where the calling party is from XXX flag and the called party is from another province.
[0143] Number calculation: Use the COUNTIF function to calculate that the number made calls to other provinces 72 times in a single day.
[0144] Abnormal marking and association: The FILTER function marks the number as abnormal, and the VLOOKUP function associates it with the cardholder's identity information.
[0145] Warning and dissuasion: The police immediately issued a warning to Bu Moumou and found that he was about to sell the mobile phone card to a "GOIP" fraud gang for diversion.
[0146] Achievements: Innovation: Traditional methods make it difficult to detect abnormalities in mobile phone cards used by "GOIP" before a crime is committed. This module provides advance warning by quantifying the number of calls, thus cutting off the "cradle" of online fraud.
[0147] Practical value: Successfully prevented a case of telecom fraud using mobile phone cards, avoiding possible subsequent telecom fraud crimes.
[0148] II. Bank Card Transaction Limit Increase Record Warning Module: Uncovering the "Water Room" Fund Transfer Network
[0149] Case Background: On XX / XX / 20XX, the system detected a single daily increase in the limit on suspect Wang's bank card (62XXXXXXXXXX) to 1 million yuan, bringing the cumulative limit increase to 5 million yuan, meeting the warning criteria. Upon police intervention, they discovered that the card was a key account for a fraudster operating a "water room" (a scam).
[0150] System operation process
[0151] Limit increase data screening: The FILTER function filters out accounts with single limit increases ≥ 1 million yuan and cumulative limit increases ≥ 5 million yuan from bank data.
[0152] Duplicate value processing and information association: After deleting duplicate accounts, the VLOOKUP function associates the cardholder Wang’s information.
[0153] In-depth investigation of the case: Combined with the early warning records, the police found out that Wang knew that others used his bank card to transfer fraudulent funds, but he still cooperated in increasing the credit limit and was eventually transferred to prosecution.
[0154] Results
[0155] Innovation: For the new "water room" model, the abnormal increase in transaction amount is used to accurately locate the credit helpers and clarify their subjective knowledge (traditional methods require tracing the flow of funds afterwards, which is difficult to prove knowledge).
[0156] Practical value: Solved 2 cases involving bank card fraud, intercepted 8 fund transfers, and recovered potential losses of more than 5 million yuan.
[0157] 3. Express Business Keyword Warning Module: Cutting Off the "Two Cards" Mailing Black and Gray Industry Chain
[0158] Case Background: On XX / XX / 20XX, the system filtered out a courier record using the keyword "bank card": suspect Na had mailed three bank cards and a USB-Shield to another province. Police immediately intercepted the courier and apprehended Na.
[0159] System operation process
[0160] Keyword filtering: Set "bank card" and "U-Shield" as keywords, and use advanced filtering to filter out mailing records containing "bank card".
[0161] Information correlation and warning: After correlating the identity information of the sender Na, it was found that she had no reasonable reason to mail the bank card normally.
[0162] Evidence collection: The early warning records became the key evidence that Na knew that the "two cards" were to be used for committing crimes by mailing them.
[0163] Results
[0164] Innovation: It solves the problem of incomplete information in the express delivery industry and blocks the circulation of "two cards" in advance through keyword matching, which is more efficient than traditional post-tracing.
[0165] Practical value: Successfully intercepted 5 cases of using express mail to send "two cards" to help others, and cooperated with the public security department to standardize the real-name registration of the express delivery industry.
[0166] 4. Virtual Account Warning Module: Curbing "Second Dial IP" Fraud
[0167] Case Background: In January 20XX, the system detected a single-day login from a fictitious account, "WeChat ID: XXX," with IP addresses in five provinces: Inner Mongolia, Shandong, Guangdong, Jiangsu, and Zhejiang. This met the warning criteria of "number of provinces from which IP logins were made in a single day > 5." Police investigation revealed that the account was being used for fraudulent traffic diversion using the "second dial" technique.
[0168] System operation process
[0169] Login log analysis: The COUNTA function calculates that the number of provinces where the account's login IP addresses belong to in a single day is 5.
[0170] Abnormal account screening: Filter out virtual accounts that meet the conditions, and use the VLOOKUP function to associate the registrant information.
[0171] Joint response: We worked with Internet companies to freeze accounts and prevent subsequent fraudulent activities.
[0172] Results
[0173] Innovation: Targeting the hidden technologies of "instant dialing" and "mixed dialing", the system identifies anomalies through the patterns of IP address changes, filling the gap in virtual account early warning.
[0174] Practical value: Provides technical support for cleaning up the chaos of dynamic IP proxies, and can be expanded to more virtual account platforms in the future.
[0175] V. Comprehensive Case Study: Multi-module Collaboration to Crack Down on a Cross-regional Malicious Spreading Gang
[0176] Case Background: In XX month of 20XX, the XXX Banner Public Security Bureau cracked down on a cross-regional gang involved in bribery through coordinated early warning using the following modules:
[0177] Mobile phone card module: It was found that three local numbers made more than 50 calls to other provinces in a single day.
[0178] Bank card module: There is a single increase of 1 million yuan in the credit limit record for the cardholder's bank card corresponding to two of the numbers.
[0179] Express delivery module: One of the cardholders recently mailed a bank card out of the province.
[0180] Virtual account module: The QQ accounts used by the gang logged in IP addresses in 6 provinces in a single day.
[0181] System operation and effectiveness
[0182] Innovation manifests itself in: Cross-validation of multi-dimensional data to form a complete chain of evidence and accurately identify gang members (traditional methods require manual collaboration among multiple departments and are inefficient).
[0183] Practical value: 5 gang members were arrested, the complete chain of "mobile phone card diversion-bank card money laundering-virtual account contact" was destroyed, and the crime rate of aid-and-help in the jurisdiction was reduced by 40%.
[0184] Case summary and patent value correlation
[0185] Innovative support: Cases have proven that the system breaks through the traditional post-investigation model and achieves "pre-warning + knowing fixation" through multi-source data integration and quantitative analysis, which is an industry first.
[0186] Practical support: It has successfully intercepted many cases in actual combat, clarified the subjective knowledge of criminal suspects, improved case handling efficiency, and has significant social value and promotion prospects.
[0187] Reproducibility: The module design and early warning logic in the case can be adapted to different regions and different types of cases, which is in line with the patent’s characteristics of “feasibility and high reusability”.
[0188] Although the present invention has been described in detail with reference to the foregoing examples, it is still possible for those skilled in the art to make modifications to the technical solutions described in the foregoing embodiments, or to make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. An early warning system to help detect cybercrime cases, characterized by: include: Mobile phone card call record warning module: used to obtain call record data from the three major operators, filter records of local numbers calling outbound numbers, calculate the number of calls per day, filter out abnormal numbers that call outbound numbers more than 50 times per day and associate them with their identity information; Bank card transaction limit increase record warning module: used to obtain bank customer transaction limit increase records, screen out abnormal accounts with a single transaction limit of ≥ 1 million yuan and a cumulative transaction limit of ≥ 5 million yuan per day, and associate them with customer information; Express delivery keyword warning module: used to obtain express delivery information and filter out abnormal delivery records containing the keywords "bank card, mobile phone card, ID card copy, USB shield"; Virtual account warning module: used to obtain virtual account login logs, calculate the number of provinces or countries where the login IP addresses are located on a single day, filter out abnormal accounts with more than 5 provinces or more than 2 countries, and associate them with registration information; Data integration and early warning module: used to integrate the early warning information of each module, to warn and dissuade potential collaborators and record early warning information as subjective knowledge evidence for case handling.
2. The early warning system for assisting information network crime cases according to claim 1, characterized in that: The mobile phone card call record warning module is implemented in the following way: Use REST API interface and HTTPS protocol to obtain call record data and store it in JSON format; The COUNTIF function is used to calculate the number of out-of-town calls made in a single day, the FILTER function is used to filter out abnormal numbers, and the VLOOKUP function is used to associate the identity information in the operator's customer information table.
3. The early warning system for assisting information network crime cases according to claim 1 is characterized in that: The bank card transaction limit increase record warning module is implemented in the following ways: Use the FILTER function to filter accounts with single increase ≥ 1 million yuan and cumulative increase ≥ 5 million yuan, delete duplicate values, and then use the VLOOKUP function to associate bank customer information.
4. The early warning system for assisting information network crime cases according to claim 1 is characterized in that: The express service keyword warning module is implemented in the following ways: Set "bank card, mobile phone card, ID card copy, U-Shield" as keywords in the express mail information, and use Excel's advanced filtering function to extract records containing the keywords.
5. The early warning system for assisting information network crime cases according to claim 1 is characterized in that: The virtual account warning module is implemented in the following ways: Use the COUNTA function to calculate the number of IP addresses logged in on a single day, filter out virtual accounts with more than 5 provinces or more than 2 countries, and use the VLOOKUP function to link the registration information table.
6. The early warning system for assisting information network crime cases according to claim 1, characterized in that: The data integration and early warning module includes: Unify the data center and message queue MQ mechanism to associate multi-source data through ID card numbers; Warning and dissuasion methods include telephone notifications and text message reminders. Warning records include warning time, method and feedback information, which are used to prove subjective knowledge when handling cases.
7. The early warning system for assisting information network crime cases according to any one of claims 1 to 6, characterized in that: Also includes data interface optimization module: REST API technology and HTTPS protocol are used for data transmission, SSL / TLS encryption is used to ensure data security, and JSON format is used to achieve cross-platform data interaction.
8. The early warning system for assisting information network crime cases according to any one of claims 1 to 6, characterized in that: Also includes big data processing optimization modules: Hadoop HDFS / cloud object storage is used for distributed data storage, Spark / Flink is used for batch computing and stream processing, and Presto / ClickHouse is used to optimize interactive query efficiency.
9. A method for assisting an early warning system for information network crime activities based on any one of claims 1 to 8, characterized in that: The following steps are involved: Steps for alerting mobile phone card call records: Obtain call records, filter outbound calls, use COUNTIF to calculate the number of calls, use FILTER to filter abnormal numbers, and use VLOOKUP to associate identity information; Steps for bank card transaction limit increase warning: Obtain transaction limit increase records, use FILTER to filter accounts with single transaction amount ≥ 1 million yuan and cumulative transaction amount ≥ 5 million yuan, delete duplicate values, and then associate customer information; Express delivery keyword warning steps: obtain express delivery information, set keywords, and extract abnormal mailing records through advanced filtering; Virtual account warning steps: obtain login logs, use COUNTA to calculate the number of locations, filter abnormal accounts and associate registration information; Integration and early warning steps: Integrate the early warning list, dissuade potential personnel, and record early warning information as case evidence.
10. The method of assisting the early warning system of information network crime activities according to claim 9, characterized in that: It also includes a threshold dynamic adjustment step: setting warning thresholds based on the frequency distribution statistics of historical case data, supporting machine learning automatic optimization or manual custom configuration; Data security protection steps: Sensitive data is stored using AES encryption and transmitted via TLS1.
3. ID card number and bank card number fields are desensitized by the first 6 digits + asterisk + last 4 digits. The integration and early warning steps include: Integrate multi-source data through a unified data center and MQ queue, and use ID card number as the unique identifier to associate mobile phone card, bank card, and express delivery information; Warning records include warning time, method, and feedback, and are used to prove the suspect's subjective knowledge when committing the crime; It also includes exception handling steps: Adopt a layered retry strategy, including immediate retry for transient errors, exponential backoff for network errors, and server-side error circuit breaker degradation, to handle data acquisition anomalies; Use RocksDB to cache data locally to prevent data loss in the event of a system failure.