Fraudulent call detection method, device, apparatus, storage medium and computer program product

By comprehensively utilizing caller ID, server address, and SIM card status to generate multi-dimensional fusion features, and using a neural network model to analyze fraud probability, the problem of insufficient detection accuracy in existing technologies is solved, achieving higher accuracy in detecting fraudulent calls.

CN120980169BActive Publication Date: 2026-01-06SHENZHEN DINSTAR TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511493274.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-20
Publication Date
2026-01-06
Estimated Expiration
2045-10-20

AI Technical Summary

Technical Problem

Existing technologies rely on caller ID analysis to detect fraudulent calls, ignoring RTP voice stream characteristics and SIM card physical status, resulting in low detection accuracy.

Method used

By obtaining the caller ID, server address, and current SIM card status, multi-dimensional fusion features are generated. A preset neural network model is used to analyze the probability of fraud, and fraudulent behavior is determined when a preset threshold is reached.

Benefits of technology

It improves the accuracy of fraudulent call detection, effectively identifies and prevents fraudulent activities, and protects users from harm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120980169B_ABST
    Figure CN120980169B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of telephone outbound call, and discloses a fraud telephone detection method, device, equipment, storage medium and computer program product, the method comprising the following steps: in the case that a session request signaling is detected, obtaining a corresponding calling number and a session server address based on the session request signaling; determining a corresponding current SIM card state based on the calling number; and performing fraud telephone detection on the calling number according to the calling number, the server address and the current SIM card state. The application obtains the calling number, the server address and the current SIM card state, and comprehensively performs fraud telephone detection on the calling number, the server address and the current SIM card state, so that the accuracy of the fraud telephone detection is improved, and the problem of insufficient accuracy caused by the single parameter detection in the prior art is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of telephone detection technology, and in particular to a method, apparatus, equipment, storage medium, and computer program product for detecting fraudulent telephone calls. Background Technology

[0002] Fraudulent call detection is an important technological tool used to identify and prevent fraudulent activities, protecting users from scam calls.

[0003] Existing technologies for detecting fraudulent calls using GOIP devices primarily rely on analyzing the caller ID in SIP signaling to determine whether the caller ID belongs to a fraudulent call list or an overseas call list. This ignores other important information, such as RTP voice stream characteristics and the physical status of the SIM card. Relying solely on a single caller ID for fraudulent call detection results in low accuracy. Summary of the Invention

[0004] The main purpose of this application is to provide a method for detecting fraudulent calls, aiming to solve the technical problem of how to improve the accuracy of fraudulent call detection.

[0005] To achieve the above objectives, this application proposes a method for detecting fraudulent phone calls, the method comprising:

[0006] Upon detecting a session request signaling, the corresponding calling number and session server address are obtained based on the session request signaling;

[0007] The current SIM card status is determined based on the calling number;

[0008] Fraudulent calls are detected by analyzing the caller ID, the server address, and the current SIM card status.

[0009] In one embodiment, the step of detecting fraudulent calls based on the caller ID, the server address, and the current SIM card status includes:

[0010] A multi-dimensional fusion feature is generated based on the caller ID, the server address, and the current SIM card status.

[0011] The multi-dimensional fused features are input into a preset neural network model to obtain the current fraud probability.

[0012] When the current fraud probability reaches a preset fraud probability threshold, the caller ID is determined to be involved in fraudulent activity.

[0013] In one embodiment, the step of generating multi-dimensional fusion features based on the calling number, the server address, and the current SIM card status includes:

[0014] Obtain the current network status and the user behavior information corresponding to the calling number;

[0015] Data anomaly analysis is performed based on the current network status, user behavior information, caller ID, server address, and current SIM card status, and fusion weights are generated based on the anomaly analysis results.

[0016] A multidimensional fused feature is generated by fusing the current network state, user behavior information, caller ID, server address, and current SIM card state using a pre-defined convolutional neural network according to the fusion weights.

[0017] In one embodiment, before the step of obtaining the corresponding calling number and session server address based on the session request signaling upon detection of session request signaling, the method further includes:

[0018] Obtain the sample SIM card status, sample number, and sample server address;

[0019] Generate multidimensional fusion features of the samples based on the sample SIM card status, sample number, and sample server address;

[0020] Obtain the sample fraud probability, and train the initial neural network model based on the sample multidimensional fusion features and the sample fraud probability to obtain the preset neural network model.

[0021] In one embodiment, the step of basing the current SIM card status corresponding to the calling number includes:

[0022] Identify the calling SIM card corresponding to the calling number;

[0023] Obtain the event log corresponding to the calling SIM card, and extract the on-premises status, registration status, signal strength, hot-swap frequency, and port unregistration rate of the calling SIM card from the event log;

[0024] A time series analysis is performed based on the in-situ status, the registration status, the signal strength, the hot-plug frequency, and the port non-registration rate, and the target weight is determined based on the time series analysis results.

[0025] The current SIM card status corresponding to the calling number is obtained by weighting and fusing the in-situ status, the registration status, the signal strength, the hot-swap frequency, and the port unregistration rate according to the target weight.

[0026] In one embodiment, after the step of determining that the calling number is involved in fraudulent activity, the method further includes:

[0027] A fraud evidence file is generated based on the current SIM card status, the caller ID, and the server address.

[0028] The fraud evidence file is encrypted using a preset quantum encryption algorithm, and a hash value is generated based on a preset hash algorithm and the encrypted fraud evidence file.

[0029] The target block is generated based on the hash value and the encrypted fraud evidence file, and stored according to a preset smart contract.

[0030] Furthermore, to achieve the above objectives, this application also proposes a fraudulent call detection device, the device comprising:

[0031] The information acquisition module is used to obtain the corresponding calling number and session server address based on the session request signaling when a session request signaling is detected.

[0032] The status acquisition module is used to determine the current SIM card status based on the calling number;

[0033] The fraud detection module is used to detect fraudulent calls to the caller ID based on the caller ID, the server address, and the current SIM card status.

[0034] In addition, to achieve the above objectives, this application also proposes a fraudulent call detection device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the fraudulent call detection method described above.

[0035] In addition, to achieve the above objectives, this application also proposes a storage medium that is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the fraudulent call detection method described above.

[0036] In addition, to achieve the above objectives, this application also proposes a computer program product comprising a computer program that, when executed by a processor, implements the steps of the fraudulent call detection method described above.

[0037] This application proposes a method, apparatus, device, storage medium, and computer program product for detecting fraudulent calls. The method includes: upon detecting a session request signaling, obtaining the corresponding caller ID and session server address based on the session request signaling; determining the corresponding current SIM card status based on the caller ID; and performing fraudulent call detection on the caller ID based on the caller ID, the server address, and the current SIM card status. Because this application, upon detecting a session request signaling, obtains the corresponding caller ID and session server address based on the session request signaling, determines the corresponding current SIM card status based on the caller ID, and performs fraudulent call detection on the caller ID based on the caller ID, the server address, and the current SIM card status, this application avoids the inaccuracy caused by existing methods using a single parameter for detection, thereby improving the accuracy of fraudulent call detection. Attached Figure Description

[0038] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0039] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 This is a flowchart of the first embodiment of the fraudulent call detection method proposed in this application;

[0041] Figure 2 This is a flowchart of the second embodiment of the fraudulent call detection method proposed in this application;

[0042] Figure 3 This is a flowchart of the third embodiment of the fraudulent call detection method proposed in this application;

[0043] Figure 4 A diagram of a fraudulent call detection device provided in an embodiment of this application;

[0044] Figure 5 A schematic diagram of the structure of a fraudulent call detection device suitable for implementing embodiments of this application.

[0045] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0046] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not intended to limit this application.

[0047] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0048] It should be noted that all directional indications (such as up, down, left, right, front, back, etc.) in the embodiments of this application are only used to explain the relative positional relationship and movement of each component in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indication will also change accordingly.

[0049] Understandably, fraud call detection is an important technological means used to identify and prevent fraudulent activities and protect users from fraudulent calls.

[0050] Existing technologies for detecting fraudulent calls using GOIP devices primarily rely on analyzing the caller ID in SIP signaling to determine whether the caller ID belongs to a fraudulent call list or an overseas call list. This ignores other important information, such as RTP voice stream characteristics and the physical status of the SIM card. Relying solely on a single caller ID for fraudulent call detection results in low accuracy.

[0051] Therefore, to address the technical problem of improving the accuracy of fraudulent call detection, this embodiment proposes a fraudulent call detection method. The method includes: upon detecting a session request signaling, obtaining the corresponding caller ID and session server address based on the session request signaling; determining the corresponding current SIM card status based on the caller ID; and performing fraudulent call detection on the caller ID based on the caller ID, server address, and current SIM card status. Because this embodiment, when detecting fraudulent calls, upon detecting a session request signaling, obtains the corresponding caller ID and session server address based on the session request signaling, determines the corresponding current SIM card status based on the caller ID, and performs fraudulent call detection on the caller ID based on the caller ID, server address, and current SIM card status, this embodiment avoids the inaccuracy caused by existing methods using a single parameter, thereby improving the accuracy of fraudulent call detection.

[0052] For ease of understanding, the following is combined with Figures 1 to 5 The fraud call detection method provided in the embodiments of this application, as well as the fraud call detection method, apparatus, equipment, storage medium, and computer program product provided in the following embodiments, will be described in detail.

[0053] This application provides a method for detecting fraudulent phone calls, referring to... Figure 1 , Figure 1 This is a flowchart of the first embodiment of the fraudulent call detection method proposed in this application.

[0054] like Figure 1 As shown, the method includes:

[0055] Step S10: If a session request signaling is detected, obtain the corresponding calling number and session server address based on the session request signaling.

[0056] It should be noted that the executing entity in this embodiment can be a multi-functional machine or device with fraudulent call detection capabilities, such as a fraudulent call detection device, or any device capable of performing the aforementioned functions. This embodiment uses a fraudulent call detection device (hereinafter referred to as the device) for illustration. The device can detect whether fraudulent calls exist in devices with SIM cards, such as mobile phones and Gateway Open Interface Platform (GSM over IP, GOIP) devices. This embodiment uses a GOIP device for illustration, but this does not impose specific limitations on this embodiment. The device can be located inside the GOIP device or connected to the GOIP device.

[0057] It should also be noted that the aforementioned session request signaling can be a signal sent by the initiator to the receiver during communication to establish a communication session, and typically includes key information such as the calling number, the called number, and the session type.

[0058] In its implementation, upon detecting a session request signaling, the aforementioned device can obtain the corresponding caller ID and session server address based on the signaling. Based on this information, the device can further analyze and determine whether the session carries a risk of fraud. For example, the device can check whether the caller ID belongs to a known list of fraudulent numbers, or whether the session server address is located in a high-risk area. Combining this information, the device can more accurately identify potential fraudulent activities and take appropriate measures, such as issuing an alarm or blocking communication.

[0059] For ease of understanding, the following example illustrates the concept, but does not limit the scope of this embodiment. Assume the device detects a session request signaling message containing the caller ID "+1234567890" and the session server address "192.168.1.100". The device first verifies whether the caller ID is in a known database of fraudulent numbers. Simultaneously, the device checks whether the session server address belongs to a known high-risk server. If the caller ID is in the fraudulent number list and the session server address is located in a high-risk area, the device marks the session as high-risk and takes further detection measures, such as analyzing call content or monitoring call behavior. If the detection results indicate that the session poses a fraud risk, the device automatically disconnects the communication and records relevant evidence for subsequent investigation. In this way, the device can effectively identify and block fraudulent calls, protecting users from fraudulent activities.

[0060] Step S20: Determine the current SIM card status based on the calling number.

[0061] It should be noted that the aforementioned current SIM card status can be the real-time status of the SIM card in the device, including information such as its presence status, registration status, signal strength, hot-swapping frequency, and port unregistration rate. In specific implementations, the device obtains information such as the presence status, registration status, signal strength, hot-swapping frequency, and port unregistration rate by querying the SIM card associated with the calling number.

[0062] Step S30: Detect fraudulent calls by the calling number based on the calling number, the server address, and the current SIM card status.

[0063] In its implementation, the device first obtains relevant information about the caller ID, including its location and historical records. Next, it analyzes the session server address to determine if it belongs to a known high-risk server. Simultaneously, the device queries the current SIM card status, including its in-place status, registration status, signal strength, hot-swapping frequency, and port unregistration rate. By combining this information, the device uses pre-set detection algorithms or machine learning models to assess whether the communication session carries a fraud risk and takes appropriate measures, such as issuing an alarm or blocking the communication.

[0064] For ease of understanding, the following example illustrates the concept, but does not limit the scope of this embodiment. Assume the device detects a caller ID "+1234567890" with a session server address of "192.168.1.100". The device queries and finds that the caller ID originates from a high-risk area and has a history of fraudulent activity. Simultaneously, the device detects that the session server address belongs to a known high-risk server. Further checks of the current SIM card status reveal an abnormally high frequency of hot-swapping and a high rate of unregistered ports. Based on this information, the device uses a pre-set detection algorithm to determine that the communication session is high-risk, issues an alarm, and disconnects the communication, effectively preventing potential fraudulent activity.

[0065] Further, the step of detecting fraudulent calls based on the caller ID, the server address, and the current SIM card status includes:

[0066] Step S31: Generate a multi-dimensional fusion feature based on the calling number, the server address, and the current SIM card status.

[0067] It should be noted that the aforementioned multi-dimensional fusion features can be formed by combining information from multiple dimensions (such as caller ID features, server address features, and SIM card status features) into a comprehensive feature vector for subsequent analysis and judgment.

[0068] In its implementation, the device first extracts relevant information about the caller ID, such as location, number type, and historical data. Next, it analyzes the session server address, including the server's IP address, geographical location, and reputation score. Simultaneously, the device queries the current SIM card status, including its in-place status, registration status, signal strength, hot-swapping frequency, and port unregistration rate. This information is integrated into a multi-dimensional feature vector for subsequent fraudulent call detection. In this way, the device can more comprehensively assess the risk of communication sessions, improving the accuracy and reliability of detection.

[0069] For ease of understanding, the following example illustrates the concept, but does not impose specific limitations on this embodiment. Assume the device detects a caller ID "+1234567890" with a session server address of "192.168.1.100". The device queries and finds that the caller ID originates from a high-risk area and has a history of fraudulent activity. Simultaneously, the device detects that the session server address belongs to a known high-risk server with a low reputation score. Further querying the current SIM card status reveals an abnormally high frequency of hot-swapping and a high port unregistration rate. The device integrates this information into a multi-dimensional feature vector.

[0070] Step S32: Input the multidimensional fusion features into a preset neural network model to obtain the current fraud probability.

[0071] It should be noted that the aforementioned preset neural network model can be a pre-trained neural network model used to analyze and predict the input feature vector and output the fraud probability. The aforementioned current fraud probability can be calculated by the neural network model based on the multi-dimensional fused features of the input, representing the possibility of fraudulent behavior in the current communication session.

[0072] In its implementation, the device inputs the multi-dimensional fused features into a preset neural network model to obtain the current fraud probability. The device first generates a multi-dimensional fused feature vector containing caller ID features, server address features, and SIM card status features. Then, this feature vector is input into a pre-trained neural network model. The model analyzes the information in each dimension of the feature vector to calculate the probability that the current communication session involves fraud. Based on this probability value, the device can determine whether the communication session carries a fraud risk and take corresponding measures, such as issuing an alarm or blocking communication.

[0073] Step S33: When the current fraud probability reaches a preset fraud probability threshold, it is determined that the calling number is involved in fraudulent activity.

[0074] It should be noted that the aforementioned preset fraud probability threshold can be a probability value pre-set by the system, used as a standard to determine whether a communication session involves fraudulent activity. In specific implementation, after obtaining the current fraud probability, the device compares this probability with the preset fraud probability threshold. If the current fraud probability reaches or exceeds the preset fraud probability threshold, the device will determine that the caller ID indicates fraudulent activity. This determination process is a crucial step in fraudulent call detection. By setting a reasonable threshold, the device can effectively reduce false positives while ensuring detection accuracy. Once fraudulent activity is determined, the device will take corresponding measures, such as issuing an alarm, recording evidence, or blocking communication, to protect users from fraudulent calls.

[0075] For ease of understanding, the following example illustrates the concept, but does not impose specific limitations on this embodiment. Assume the device calculates a current fraud probability of 95% using a neural network model, while the preset fraud probability threshold is 90%. Since the current fraud probability exceeds the preset threshold, the device determines that the caller ID indicates fraudulent activity. Subsequently, the device issues an alarm to the administrator, automatically disconnects the communication connection with the caller ID, and records relevant evidence for subsequent investigation.

[0076] In this embodiment, when detecting fraudulent calls, upon detecting a session request signaling, the corresponding caller ID and session server address are obtained based on the session request signaling. The current SIM card status is then determined based on the caller ID. Fraudulent call detection is performed on the caller ID based on the caller ID, server address, and current SIM card status. This embodiment improves the accuracy of fraudulent call detection by comprehensively acquiring and using these three factors, avoiding the inaccuracies caused by using a single parameter in existing methods.

[0077] Based on the first embodiment, in the second embodiment, the content that is the same as or similar to that in Embodiment 1 above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2 , Figure 2 This is a flowchart of the second embodiment of the fraud call detection method proposed in this application. Further, to achieve more accurate fraud call detection, the step of generating multi-dimensional fusion features based on the caller ID, the server address, and the current SIM card status includes:

[0078] Step S311: Obtain the current network status and the user behavior information corresponding to the calling number.

[0079] It should be noted that the aforementioned current network status can refer to the specific network environment in which the device is communicating, including parameters such as network latency, packet loss rate, and bandwidth. The aforementioned user behavior information can refer to the behavioral patterns of users associated with the calling number during the communication process, such as call duration, call frequency, and SMS sending frequency, used to analyze whether user behavior is abnormal.

[0080] In its implementation, when detecting fraudulent calls, the aforementioned device analyzes not only the caller ID, server address, and SIM card status, but also the current network status and user behavior information corresponding to the caller ID. By combining this information, the device can more comprehensively assess the risk of the communication session. Network status parameters such as network latency, packet loss rate, and bandwidth help the device determine whether the communication environment is normal. User behavior information, such as call duration, call frequency, and SMS sending frequency, can reveal whether the user's behavior patterns conform to normal communication habits.

[0081] Step S312: Perform data anomaly analysis based on the current network status, user behavior information, caller ID, server address, and current SIM card status, and generate fusion weights based on the anomaly analysis results.

[0082] It should be noted that the aforementioned anomaly analysis can be a process of analyzing various data sources to identify behaviors or states that do not conform to normal communication patterns, thereby determining the potential for fraud. The aforementioned fusion weights can be weights assigned to different data dimensions based on the anomaly analysis results, used to comprehensively assess fraud risk. The weight allocation is based on the strength of each dimension's indicative power for fraudulent behavior.

[0083] In its implementation, the device performs data anomaly analysis based on the current network status, user behavior information, caller ID, server address, and current SIM card status, and generates fusion weights based on the anomaly analysis results. The device comprehensively considers multiple dimensions of data, including network environment stability, user behavior patterns, caller ID source, session server reputation, and SIM card usage status. Through anomaly analysis of this data, the device can identify behaviors or states that do not conform to normal communication patterns. Based on the anomaly analysis results, the device assigns corresponding weights to each data dimension.

[0084] Step S313: Using a preset convolutional neural network, feature fusion is performed on the current network state, the user behavior information, the calling number, the server address, and the current SIM card state according to the fusion weights to generate multi-dimensional fused features.

[0085] It should be noted that the aforementioned preset convolutional neural network can be a pre-trained deep learning model specifically designed for processing and analyzing multi-dimensional input data, extracting features through convolutional layers. In specific implementation, the device uses the preset convolutional neural network to perform feature fusion on the current network state, user behavior information, caller ID, server address, and current SIM card state according to the fusion weights, generating multi-dimensional fused features. The device first inputs this multi-dimensional data into the preset convolutional neural network, where the network weights the data for each dimension according to the fusion weights. Through the operations of convolutional and pooling layers, the network can extract key features from each dimension of the data and fuse these features to generate a multi-dimensional fused feature vector.

[0086] For ease of understanding, the following example illustrates the concept, but does not impose specific limitations on this embodiment. Assume that when the device performs feature fusion, it takes the current network status, user behavior information, caller ID, server address, and SIM card status as input data. Based on the anomaly analysis results, the device assigns different fusion weights to these data; for example, the network status weight is 0.1, user behavior information weight is 0.3, caller ID weight is 0.2, server address weight is 0.2, and SIM card status weight is 0.2. These weights reflect the importance of different data in indicating fraudulent behavior. The device inputs this weighted data into a pre-defined convolutional neural network. The network extracts key features from each dimension of the data through convolutional layers, then performs feature dimensionality reduction and fusion through pooling layers, ultimately generating a multi-dimensional fused feature vector. This feature vector contains important information from all the input data, providing a more comprehensive and accurate input for subsequent fraudulent call detection.

[0087] Furthermore, before the step of obtaining the corresponding calling number and session server address based on the session request signaling upon detection of session request signaling, the method further includes:

[0088] Obtain the sample SIM card status, sample number, and sample server address;

[0089] Generate multidimensional fusion features of the samples based on the sample SIM card status, sample number, and sample server address;

[0090] Obtain the sample fraud probability, and train the initial neural network model based on the sample multidimensional fusion features and the sample fraud probability to obtain the preset neural network model.

[0091] It should be noted that the aforementioned sample SIM card status can be information such as the SIM card's presence status, registration status, signal strength, hot-swapping frequency, and port unregistration rate in the sample data used for model training. The aforementioned sample phone numbers can be calling phone numbers in the sample data used for model training; these numbers may be known to be involved in fraudulent activities. The aforementioned sample server address can be the network address of the server handling session requests in the sample data used for model training, typically an IP address. The aforementioned multi-dimensional fusion feature can be a feature vector formed by combining multi-dimensional information such as sample SIM card status, sample phone numbers, and sample server addresses to train the model.

[0092] Furthermore, the aforementioned sample fraud probabilities can be known fraud probabilities associated with the sample data, which can be derived based on historical data or expert annotations. The aforementioned initial neural network model can be an untrained neural network model that needs to be trained using sample data to learn patterns for recognizing fraudulent behavior. Alternatively, the aforementioned preset neural network model can be a trained neural network model capable of accurately predicting fraud probabilities based on the multidimensional fusion features of the input.

[0093] In its implementation, the device first acquires the sample SIM card status, sample number, and sample server address. This sample data forms the foundation for training the neural network model, encompassing the physical status of the SIM card, the caller ID's location and history, and the session server's IP address and reputation score. Next, the device generates multi-dimensional fusion features based on this data, integrating information from different dimensions into a single feature vector for model training. Then, the device obtains the sample fraud probabilities, derived from historical data or expert annotations, reflecting the likelihood of fraudulent activity in the communication sessions within the sample data. Finally, the device trains the initial neural network model based on the multi-dimensional fusion features and the sample fraud probabilities. By learning patterns and relationships within the sample data, the model gradually improves its ability to identify fraudulent activities, ultimately obtaining a pre-defined neural network model capable of accurately predicting fraud probabilities in practical applications.

[0094] For ease of understanding, the following example illustrates the concept, but does not limit the scope of this embodiment. Assume that when training the neural network model, the device collects a series of sample data, including sample SIM card status (e.g., high hot-swapping frequency, normal signal strength), sample phone numbers (e.g., from high-risk areas, with a history of fraudulent activity), and sample server addresses (e.g., belonging to a known high-risk server, low server reputation score). The device generates multi-dimensional fusion features based on this sample data. For example, the feature vector might include dimensions such as SIM card hot-swapping frequency, caller ID location risk level, and server reputation score. Simultaneously, the device obtains the fraud probability for each sample, based on historical data or expert annotations. Then, the device uses these multi-dimensional fusion features and fraud probabilities to train the initial neural network model. During training, the model learns patterns and relationships in the sample data, gradually adjusting its parameters to improve its ability to identify fraudulent activities. After multiple rounds of training, the device finally obtains a preset neural network model that can accurately predict fraud probabilities based on the input multi-dimensional fusion features in practical applications, thereby effectively identifying and preventing fraudulent calls.

[0095] Based on the first and second embodiments, in the third embodiment, the content that is the same as or similar to that in Embodiments 1 and 2 above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 3 , Figure 3 This is a flowchart of the third embodiment of the fraudulent call detection method proposed in this application. Further, the step based on the current SIM card status corresponding to the caller ID includes:

[0096] Step S21: Determine the calling SIM card corresponding to the calling number.

[0097] It should be noted that the aforementioned calling SIM card can be a physical SIM card associated with the calling number. This SIM card is inserted into the GOIP device to initiate a communication request.

[0098] Step S22: Obtain the event log corresponding to the calling SIM card, and extract the on-premises status, registration status, signal strength, hot-swap frequency, and port unregistration rate of the calling SIM card from the event log.

[0099] It should be noted that the aforementioned event logs can be log information recorded by the device related to SIM card operations and status. These logs record the usage and status changes of the SIM card. The aforementioned "in-place status" can refer to whether the SIM card is correctly inserted into the device, and is usually a Boolean value indicating whether the SIM card is in place.

[0100] The above registration status indicates whether the SIM card has successfully registered with the mobile network; it is usually a Boolean value indicating whether the SIM card is registered. The above signal strength indicates the SIM card's signal strength; it is usually a numerical value indicating the SIM card's signal quality. The above hot-swapping frequency indicates the frequency at which the SIM card is frequently inserted and removed; it is usually a numerical value indicating the frequency of hot-swapping within a certain time period. The above port unregistration rate indicates the SIM card's port unregistration rate; it is usually a numerical value indicating the frequency at which the SIM card's ports are not registered.

[0101] In its implementation, the device obtains the event logs corresponding to the calling SIM card and extracts the calling SIM card's presence status, registration status, signal strength, hot-swapping frequency, and port unregistration rate from these logs. The device retrieves event logs related to the calling SIM card by querying its internal SIM card management module. These logs record the SIM card's usage and status changes, including information such as its presence status, registration status, signal strength, hot-swapping frequency, and port unregistration rate.

[0102] For ease of understanding, the following example illustrates the concept, but does not impose specific limitations on this embodiment. Assume that when the device processes a communication request, it detects the caller ID as "+1234567890". The device queries its internal SIM card management module to find the SIM card associated with this caller ID and retrieves the corresponding event log. The device extracts the following information from the event log: Presence Status: SIM card is present (true). Registration Status: SIM card has been successfully registered to the network (true). Signal Strength: Signal strength is "strong". Hot-Swap Frequency: SIM card hot-swap frequency is "high". Port Unregistered Rate: SIM card port unregistered rate is "high".

[0103] Step S23: Perform time-series analysis based on the in-situ status, the registration status, the signal strength, the hot-plug frequency, and the port non-registration rate, and determine the target weight based on the time-series analysis results.

[0104] It should be noted that the aforementioned time-series analysis can be an analysis of SIM card status information changing over time, used to identify trends and patterns in status changes, helping to determine whether abnormal behavior exists. In this embodiment, the target weight can be determined based on the time-series changes in in-situ status, registration status, signal strength, hot-swapping frequency, and port unregistration rate, dynamically generating the target weight according to the rule that the greater the change trend, the higher the weight allocation.

[0105] In its implementation, the device first collects historical data on these status information, forming a time series. Through time series analysis, the device can identify trends and patterns in status changes, such as whether the hot-swapping frequency increases significantly in a short period of time, or whether the signal strength fluctuates frequently within a specific time period. Based on these analysis results, the device dynamically adjusts the target weights to reflect the indicative strength of different status information for fraudulent activities at the current point in time.

[0106] Step S24: Based on the target weight, perform weighted fusion of the in-place status, the registration status, the signal strength, the hot-swap frequency, and the port unregistered rate to obtain the current SIM card status corresponding to the calling number.

[0107] In its implementation, the device first acquires the numerical value of each status information and then weights these status information according to a preset target weight. Through weighted fusion, the device integrates these multi-dimensional status information to generate a comprehensive score or status vector, representing the current status of the SIM card.

[0108] For ease of understanding, the following example is used for illustration, but it does not impose specific limitations on this embodiment. Suppose that when the above device is processing a communication request, it detects that the calling number is "+1234567890". The device extracts the following status information from the event log: In-situ status: SIM card in-situ (1). Registration status: SIM card has been successfully registered to the network (1). Signal strength: Signal strength is "strong" (0.9). Hot-swap frequency: SIM card hot-swap frequency is "high" (0.8). Port unregistered rate: SIM card port unregistered rate is "high" (0.7). The device performs weighted fusion of these status information according to preset target weights. Assume that the target weights are as follows: In-situ status weight: 0.1; Registration status weight: 0.1; Signal strength weight: 0.2; Hot-swap frequency weight: 0.3; Port unregistered rate weight: 0.3; The device calculates the current SIM card status after weighted fusion based on the above parameters.

[0109] Furthermore, after the step of determining that the caller ID number is involved in fraudulent activity, the method further includes:

[0110] A fraud evidence file is generated based on the current SIM card status, the caller ID, and the server address.

[0111] The fraud evidence file is encrypted using a preset quantum encryption algorithm, and a hash value is generated based on a preset hash algorithm and the encrypted fraud evidence file.

[0112] The target block is generated based on the hash value and the encrypted fraud evidence file, and stored according to a preset smart contract.

[0113] It should be noted that the aforementioned preset quantum encryption algorithm can be a pre-defined algorithm that uses the principles of quantum mechanics to encrypt data, ensuring the confidentiality and integrity of the data. The aforementioned hash value can be a fixed-length digital digest generated from the encrypted fraud evidence file using a preset hash algorithm, used to verify the integrity and authenticity of the file. The aforementioned target block can be a blockchain block containing the encrypted fraud evidence file and its hash value, used to store the evidence file on the blockchain. The aforementioned preset smart contract can be pre-defined, automatically executed contract code deployed on the blockchain, used to manage the storage and verification of blocks.

[0114] In its implementation, the aforementioned device generates a fraud evidence file based on the current SIM card status, the caller ID, and the server address. This information includes the physical status of the SIM card, the caller ID's location and history, and the session server's IP address and reputation score. Next, the device encrypts the fraud evidence file using a preset quantum encryption algorithm to ensure the confidentiality and integrity of the file content. Then, a hash value is generated based on a preset hash algorithm and the encrypted fraud evidence file to verify the file's integrity and authenticity. Finally, a target block is generated based on the hash value and the encrypted fraud evidence file, and stored according to a preset smart contract. In this way, the device ensures the secure storage and immutability of the fraud evidence file, providing reliable evidentiary support for subsequent legal proceedings.

[0115] For ease of understanding, the following example illustrates the concept, but does not limit the scope of this embodiment. Assume that when the device processes a communication request, it detects the caller ID as "+1234567890". The device extracts the following information from the event log: Current SIM card status: SIM card in place, registered, strong signal strength, high hot-swapping frequency, high port unregistration rate. Caller ID: Caller ID "+1234567890". Server address: Session server address "192.168.1.100".

[0116] The aforementioned device generates fraud evidence files based on this information and encrypts the files using a preset quantum encryption algorithm. The encrypted file content cannot be read by unauthorized users, ensuring data confidentiality. Next, the device generates a hash value for the encrypted fraud evidence file using a preset hash algorithm (such as SHA-256). This hash value is a fixed-length digital digest used to verify the integrity and authenticity of the file. Then, the device generates a target block based on the hash value and the encrypted fraud evidence file. This block contains the encrypted file and the hash value, ensuring the file's immutability. Finally, the device stores the target block according to a preset smart contract. The smart contract automatically verifies the block's integrity and authenticity and stores it on the blockchain.

[0117] In addition, after the step of determining that the caller ID number is involved in fraudulent activity, the method further includes:

[0118] Determine the current SIM card slot corresponding to the calling number;

[0119] Power is cut off to the current SIM card slot.

[0120] It should be noted that the aforementioned calling number can be the phone number that initiates the communication request, used to identify the initiator. In GOIP devices, the calling number may originate from the SIM card inserted into the device. The aforementioned current SIM card slot can be the physical card slot where the SIM card associated with the calling number resides, used to insert the SIM card and provide power and a communication interface. The aforementioned power cut-off can be achieved through hardware control, cutting off the power supply to the SIM card slot, thereby stopping the SIM card's communication function.

[0121] In its implementation, the device determines the current SIM card slot corresponding to the calling number and cuts off power to that slot. The device first queries its internal SIM card management module to locate the physical card slot associated with the calling number. Once the current SIM card slot is identified, the device, through its hardware control module, cuts off the power supply to that slot, thereby stopping the SIM card's communication function.

[0122] This embodiment also provides a first embodiment of a fraudulent call detection device, please refer to... Figure 4 , Figure 4 This is a diagram of a fraudulent call detection device provided in an embodiment of this application. The fraudulent call detection device includes:

[0123] The information acquisition module is used to obtain the corresponding calling number and session server address based on the session request signaling when a session request signaling is detected.

[0124] The status acquisition module is used to determine the current SIM card status based on the calling number;

[0125] The fraud detection module is used to detect fraudulent calls to the caller ID based on the caller ID, the server address, and the current SIM card status.

[0126] The fraud detection module is further configured to generate multi-dimensional fusion features based on the caller ID, the server address, and the current SIM card status; input the multi-dimensional fusion features into a preset neural network model to obtain the current fraud probability; and determine that the caller ID is involved in fraudulent activity when the current fraud probability reaches a preset fraud probability threshold.

[0127] Referring to the first embodiment of the fraudulent call detection device, this embodiment also proposes a second embodiment of the fraudulent call detection device. The contents that are the same as or similar to those in the first embodiment of the fraudulent call detection device can be referred to the above description, and will not be repeated hereafter.

[0128] The fraud detection module is further configured to acquire the current network status and user behavior information corresponding to the calling number; perform data anomaly analysis based on the current network status, user behavior information, calling number, server address, and current SIM card status, and generate fusion weights based on the anomaly analysis results; and perform feature fusion on the current network status, user behavior information, calling number, server address, and current SIM card status using a preset convolutional neural network according to the fusion weights to generate multi-dimensional fusion features.

[0129] The status acquisition module is also used to acquire the sample SIM card status, sample number, and sample server address; generate sample multidimensional fusion features based on the sample SIM card status, sample number, and sample server address; acquire the sample fraud probability; and train the initial neural network model based on the sample multidimensional fusion features and the sample fraud probability to obtain a preset neural network model.

[0130] Referring to the first and second embodiments of the fraudulent call detection device, this embodiment also proposes a third embodiment of the fraudulent call detection device. The contents that are the same as or similar to the first and second embodiments of the fraudulent call detection device can be referred to the above description, and will not be repeated hereafter.

[0131] The status acquisition module is further configured to: determine the calling SIM card corresponding to the calling number; acquire the event log corresponding to the calling SIM card, and extract the on-premises status, registration status, signal strength, hot-swapping frequency, and port non-registration rate of the calling SIM card from the event log; perform time-series analysis based on the on-premises status, registration status, signal strength, hot-swapping frequency, and port non-registration rate, and determine the target weight based on the time-series analysis results; and perform weighted fusion of the on-premises status, registration status, signal strength, hot-swapping frequency, and port non-registration rate according to the target weight to obtain the current SIM card status corresponding to the calling number.

[0132] The fraud detection module is further configured to generate a fraud evidence file based on the current SIM card status, caller ID, and server address; encrypt the fraud evidence file using a preset quantum encryption algorithm; generate a hash value based on a preset hash algorithm and the encrypted fraud evidence file; generate a target block based on the hash value and the encrypted fraud evidence file; and store the target block according to a preset smart contract.

[0133] The fraud call detection device provided in this embodiment employs the fraud call detection method described in the above embodiments, and can solve the technical problem of how to improve the accuracy of fraud call detection. Compared with the prior art, the beneficial effects of the fraud call detection device provided in this embodiment are the same as those of the fraud call detection method provided in the above embodiments, and other technical features in the fraud call detection device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0134] This embodiment provides a fraudulent call detection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the fraudulent call detection method in the first embodiment described above.

[0135] The following is for reference. Figure 5 , Figure 5This is a schematic diagram of the structure of a fraudulent call detection device suitable for implementing the embodiments of this application. The fraudulent call detection device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), vehicle terminals (such as vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The fraudulent call detection device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0136] like Figure 5 As shown, the fraud call detection device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the fraud call detection device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the fraud call detection device to communicate wirelessly or wiredly with other devices to exchange data. Although the figure shows fraud call detection devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0137] Specifically, according to this embodiment, the process described above with reference to the flowchart can be implemented as a computer software program. For example, this embodiment includes a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the disclosed embodiments of this embodiment.

[0138] The fraud call detection device provided in this embodiment employs the fraud call detection method described in the above embodiments, and can solve the technical problem of how to improve the accuracy of fraud call detection. Compared with the prior art, the beneficial effects of the fraud call detection device provided in this embodiment are the same as those of the fraud call detection method provided in the above embodiments, and other technical features in this fraud call detection device are the same as those disclosed in the method of the previous embodiment, and will not be repeated here.

[0139] It should be understood that the various parts disclosed in this embodiment can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0140] The above description is merely a specific implementation of this embodiment, but the protection scope of this embodiment is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this embodiment should be included within the protection scope of this embodiment. Therefore, the protection scope of this embodiment should be determined by the protection scope of the claims.

[0141] This embodiment provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the fraudulent call detection method in the above embodiment.

[0142] The computer-readable storage medium provided in this embodiment may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0143] The aforementioned computer-readable storage medium may be included in the fraud call detection device; or it may exist independently and not be assembled into the fraud call detection device.

[0144] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the fraud call detection device, cause the fraud call detection device to perform fraud call detection.

[0145] Computer program code for performing the operations of this embodiment can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include object-oriented programming languages—such as Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0146] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this embodiment. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0147] The modules described in this embodiment can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0148] The readable storage medium provided in this embodiment is a computer-readable storage medium, which stores computer-readable program instructions (i.e., a computer program) for executing the above-described fraudulent call detection method, thereby solving the technical problem of how to improve the accuracy of fraudulent call detection. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this embodiment are the same as those of the fraudulent call detection method provided in the above embodiments, and will not be repeated here.

[0149] The above descriptions are only some embodiments and do not limit the patent scope of this embodiment. All equivalent structural transformations made based on the technical concept of this application and the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included within the patent protection scope of this application.

Claims

1. A fraud phone detection method, characterized by, The method comprises: In the case of detecting session request signaling, obtaining the corresponding calling number and session server address based on the session request signaling; Determine the corresponding current SIM card state based on the calling number; Fraud phone detection is performed on the calling number according to the calling number, the server address and the current SIM card state; The step of determining the corresponding current SIM card state based on the calling number comprises: Determine the calling SIM card corresponding to the calling number; Obtain the event log corresponding to the calling SIM card, and extract the in-place state, registration state, signal strength, hot plug frequency and port unregistered rate corresponding to the calling SIM card from the event log; Time sequence analysis is performed based on the in-place state, the registration state, the signal strength, the hot plug frequency and the port unregistered rate, and the target weight is determined based on the time sequence analysis result; The in-place state, the registration state, the signal strength, the hot plug frequency and the port unregistered rate are weighted and fused according to the target weight to obtain the current SIM card state corresponding to the calling number.

2. The method of claim 1, wherein, The step of performing fraud phone detection on the calling number according to the calling number, the server address and the current SIM card state comprises: Generate multi-dimensional fusion features according to the calling number, the server address and the current SIM card state; Input the multi-dimensional fusion features into a preset neural network model to obtain a current fraud probability; When the current fraud probability reaches a preset fraud probability threshold, it is determined that the calling number has fraud behavior.

3. The method of claim 2, wherein, The step of generating multi-dimensional fusion features according to the calling number, the server address and the current SIM card state comprises: Obtain the current network state and the user behavior information corresponding to the calling number; Perform data anomaly analysis based on the current network state, the user behavior information, the calling number, the server address and the current SIM card state, and generate a fusion weight based on the anomaly analysis result; Feature fusion is performed on the current network state, the user behavior information, the calling number, the server address and the current SIM card state according to the fusion weight through a preset convolutional neural network to generate multi-dimensional fusion features.

4. The method of claim 2, wherein, Before the step of obtaining the corresponding calling number and session server address based on the session request signaling in the case of detecting session request signaling, it further comprises: Obtain sample SIM card state, sample number and sample server address; Generate sample multi-dimensional fusion features according to the sample SIM card state, sample number and sample server address; Obtain a sample fraud probability, and train an initial neural network model based on the sample multi-dimensional fusion features and the sample fraud probability to obtain a preset neural network model.

5. The method of claim 2, wherein, After the step of determining that the calling number has fraud behavior, it further comprises: Generate a fraud evidence file based on the current SIM card state, the calling number and the server address; The fraud evidence file is encrypted based on a preset quantum encryption algorithm, and a hash value is generated based on a preset hash algorithm and the encrypted fraud evidence file; A target block is generated based on the hash value and the encrypted fraud evidence file, and the target block is stored according to a preset smart contract.

6. A fraud phone detection device characterized by comprising: The apparatus comprises: The information obtaining module is configured to, when detecting session request signaling, obtain a corresponding calling number and session server address based on the session request signaling; The state obtaining module is configured to determine a corresponding current SIM card state based on the calling number; The fraud detection module is configured to perform fraud phone detection on the calling number according to the calling number, the server address, and the current SIM card state. The state obtaining module is further configured to determine a calling SIM card corresponding to the calling number, obtain an event log corresponding to the calling SIM card, and extract an in-place state, a registration state, a signal strength, a hot plug frequency, and a port unregistered rate corresponding to the calling SIM card from the event log; perform timing analysis based on the in-place state, the registration state, the signal strength, the hot plug frequency, and the port unregistered rate, and determine a target weight based on a timing analysis result; and perform weighted fusion on the in-place state, the registration state, the signal strength, the hot plug frequency, and the port unregistered rate according to the target weight to obtain the current SIM card state corresponding to the calling number.

7. A conversational device, characterized by The device comprises a plurality of SIM card slots, a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the fraud phone detection method according to any one of claims 1 to 5.

8. A storage medium, characterized by The storage medium is a computer-readable storage medium, and the storage medium stores a computer program, which is executed by a processor to implement the steps of the fraud phone detection method according to any one of claims 1 to 5.

9. A computer program product, characterised in that, The computer program product comprises a computer program, which is executed by a processor to implement the steps of the fraud phone detection method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network telephone security management system and method

    CN117240961A

  • Control system for enabling use of wireless telephones

    US7706774B1