A communication risk detection method, system, device and storage medium

By employing multi-timescale feature extraction and multi-engine parallel analysis, combined with hidden Markov models and risk propagation algorithms, this approach addresses the insufficient adaptability of existing technologies to rapidly changing communication patterns. It enables accurate identification and timely intervention of abnormal communications, thereby improving the real-time performance and accuracy of communication network security management.

CN121586003BActive Publication Date: 2026-05-08BEIJING YOUKUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING YOUKUN TECH CO LTD
Filing Date
2026-01-27
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing methods for identifying abnormal communication rely on static rules and single-dimensional features, which are difficult to adapt to rapidly evolving communication behavior patterns. This results in insufficient ability to identify new abnormal patterns and inadequate real-time performance when processing massive amounts of roaming data, failing to fully leverage the synergistic value of communication behavior features and external intelligence.

Method used

A multi-timescale feature extraction mechanism is adopted to extract behavioral features from a dynamic correlation network. A real-time rule matching layer, a behavioral pattern analysis layer, and a correlation network analysis layer are deployed in parallel. Combined with a hidden Markov model and a risk propagation algorithm, a comprehensive risk score is generated through multi-engine fusion decision-making, and graded disposal operations are implemented.

Benefits of technology

It enables accurate identification and timely intervention of abnormal communication behaviors, improves the accuracy and real-time performance of detection, enhances the adaptability to new abnormal communication behaviors, and provides effective technical support for communication network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121586003B_ABST
    Figure CN121586003B_ABST
Patent Text Reader

Abstract

The application discloses a communication risk detection method, system, device and storage medium, relates to the technical field of network security, and solves the problem of difficult data tracing by standardizing communication data and associating the standardized communication data with an abnormal list library to construct a dynamic network; through multi-time scale feature extraction combined with a parallel analysis architecture, fast response is realized by using a real-time rule matching layer, dynamic evolution rules are captured by using a hidden Markov model of a behavior pattern analysis layer, and group risks are identified by using a space-time weighted model of a correlation network analysis layer, so that the defects of poor adaptability and single dimension of traditional methods are overcome; finally, through multi-engine decision and hierarchical disposal mechanism, the recognition accuracy is guaranteed while the disposal efficiency is optimized, so that high-precision and low-delay identification and control of cross-border abnormal communication behaviors are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a communication risk detection method, system, device and storage medium. Background Technology

[0002] In recent years, with the rapid development of international telecommunications services, cross-border communication activities have become increasingly frequent, leading to the emergence of some abnormal communication behaviors using international roaming services. These behaviors typically manifest as using overseas-registered numbers to initiate calls or messages to domestic entities (roaming in), or using domestic numbers while in use overseas (roaming out) to conduct abnormal communication activities. These communication patterns are characterized by high concealment, rapidly changing behavioral patterns, and significant difficulty in tracing their origins, posing new challenges to the management of telecommunications network security.

[0003] Currently, existing methods for identifying abnormal communication have the following limitations: traditional detection methods rely heavily on static rule bases and fixed thresholds, making it difficult to adapt to rapidly evolving communication behavior patterns; furthermore, single-dimensional detection methods often fail to fully capture the multi-scale features of communication behavior, resulting in insufficient ability to identify new abnormal patterns. Summary of the Invention

[0004] To address the aforementioned issues, this application provides a communication risk detection method, system, device, and storage medium.

[0005] The embodiments of this application disclose the following technical solutions:

[0006] The first aspect of this application provides a communication risk detection method, including:

[0007] Acquire communication data, and clean and standardize the communication data;

[0008] The processed communication data is associated with a pre-set list of abnormal communication numbers to construct a dynamic association network;

[0009] Based on multiple preset time windows, behavioral features of the target number at multiple preset time scales are extracted from the dynamic association network;

[0010] The behavioral features are input in parallel to at least two of the real-time rule matching layer, behavior pattern analysis layer, and association network analysis layer for processing, and the analysis results of at least two layers are obtained. The real-time rule matching layer is used to perform matching based on a multi-condition rule base that includes communication frequency thresholds, time window features, and behavioral anomaly degree. The rule weights of each condition are dynamically adjusted according to the hit accuracy, and the first analysis result is output. The behavior pattern analysis layer is used to construct a hidden Markov model containing multiple risk states, and calculate the probability of the number being in each state through a forward-backward algorithm to identify the dynamic evolution of the behavior pattern, and output the second analysis result. The association network analysis layer is used to calculate the node risk value based on a pre-constructed communication relationship graph using a risk propagation algorithm, and identify high-risk association groups using a community detection algorithm, and output the third analysis result.

[0011] A decision is made based on the analysis results of at least two layers to obtain a comprehensive risk score for the target number;

[0012] Based on the comprehensive risk score, corresponding tiered handling operations are performed on the target number.

[0013] In one possible implementation, the step of extracting behavioral features of the target number at multiple preset time scales from the dynamic association network based on multiple preset time windows includes:

[0014] Based on a short time window, a first type of behavioral feature of the target number is extracted from the dynamic association network. The first type of behavioral feature includes at least one of call dispersion, communication success rate and time distribution anomaly.

[0015] Based on a medium-term time window, a second type of behavioral characteristics of the target number is extracted from the dynamic association network. The second type of behavioral characteristics includes at least one of the following: number activity change rate, called number addition rate, and communication pattern mutation index.

[0016] Based on a long-term time window, a third type of behavioral feature of the target number is extracted from the dynamic association network. The third type of behavioral feature includes at least one of the behavioral stability index and the association network evolution feature.

[0017] In one possible implementation, the processing method of the behavior pattern analysis layer includes:

[0018] Construct a hidden Markov model with normal state, suspicious state, low-risk state and high-risk state;

[0019] The observation sequence, which includes communication frequency, called party discreteness, and time distribution, is input into the hidden Markov model.

[0020] The probability of the target number being in each state under the observation sequence is calculated using a forward-backward algorithm;

[0021] Based on the probability that the target number is in the high-risk state and the low-risk state, the second analysis result of the behavior pattern analysis layer is calculated and determined.

[0022] In one possible implementation, the processing method of the correlation network analysis layer includes:

[0023] A risk propagation algorithm is used to propagate risk on the communication relationship graph, calculate the risk value of each node, and calculate the risk propagation weight between each node based on the time decay factor and intensity factor of the communication relationship. The communication relationship graph is constructed with numbers as nodes and communication relationships as edges. The weight of the edge is determined based on at least one of communication frequency, communication duration and communication time distribution.

[0024] The community detection algorithm is used to identify suspicious groups based on the node groups and risk values ​​of each node in the communication relationship graph, and the density of suspicious groups is calculated as the third analysis result of the association network analysis layer.

[0025] In one possible implementation, the step of performing corresponding tiered handling operations on the target number based on the comprehensive risk score includes:

[0026] If the comprehensive risk score is greater than or equal to the first score, then real-time interception and reporting will be performed;

[0027] If the overall risk score is less than the first score but greater than or equal to the second score, then a delayed call will be executed and a notification will be sent.

[0028] If the overall risk score is less than the second score but greater than or equal to the third score, then key monitoring or sampling surveillance will be implemented.

[0029] If the overall risk score is less than the third score, then the vehicle is allowed to proceed normally and its behavior is continuously recorded.

[0030] In one possible implementation, the processing method of the real-time rule matching layer includes:

[0031] Construct a multi-condition combination rule base, wherein the rule base contains combination conditions based on at least two of communication frequency threshold, time window features and behavior anomaly degree;

[0032] The extracted behavioral features are matched with the rules in the multi-condition combination rule base;

[0033] The weights of each rule are dynamically adjusted based on the hit accuracy of the rules, and a real-time rule risk score is obtained based on the weighted calculation as the first analysis result.

[0034] In one possible implementation, the multi-condition combination rule base includes at least one of the following rules:

[0035] The rule is triggered when the number of unique called numbers for the target number is greater than the first threshold, the average call duration is less than the second threshold, and the communication occurs during a preset nighttime period.

[0036] The rule is triggered when the SMS sending rate of the target number is greater than the third threshold, the dispersion of the recipient's number is greater than the fourth threshold, and the similarity of the SMS content is lower than the fifth threshold.

[0037] This rule is triggered when the target number is an international roaming number, the call failure rate is greater than the sixth threshold, and the call frequency is greater than the seventh threshold.

[0038] A second aspect of this application provides a communication risk detection system, including:

[0039] An acquisition unit is used to acquire communication data and perform cleaning and standardization processing on the communication data.

[0040] The construction unit is used to associate the processed communication data with a preset list of abnormal communication numbers to build a dynamic association network;

[0041] The extraction unit is used to extract behavioral features of the target number at multiple preset time scales from the dynamic association network based on multiple preset time windows;

[0042] The processing unit is used to input the behavioral features in parallel to at least two of the real-time rule matching layer, behavior pattern analysis layer, and association network analysis layer for processing, and obtain the analysis results of at least two layers. The real-time rule matching layer is used to perform matching based on a multi-condition rule base that includes communication frequency thresholds, time window features, and behavioral anomaly degree. The rule weights of each condition are dynamically adjusted according to the hit accuracy, and the first analysis result is output. The behavior pattern analysis layer is used to construct a hidden Markov model containing multiple risk states, and calculate the probability of the number being in each state through a forward-backward algorithm to identify the dynamic evolution of the behavior pattern, and output a second analysis result. The association network analysis layer is used to calculate the node risk value based on a pre-constructed communication relationship graph using a risk propagation algorithm, and identify high-risk association groups using a community detection algorithm, and output a third analysis result.

[0043] A decision-making unit is used to make decisions based on the analysis results of the at least two layers to obtain a comprehensive risk score for the target number;

[0044] The execution unit is used to perform corresponding graded handling operations on the target number based on the comprehensive risk score.

[0045] A third aspect of this application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the communication risk detection method as described in the first aspect above.

[0046] A fourth aspect of this application provides a computer program product that, when run on a computer, executes the communication risk detection method as described in the first aspect above.

[0047] A fifth aspect of this application provides a computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to perform the communication risk detection method as described in the first aspect above.

[0048] Compared with the prior art, this application has the following beneficial effects:

[0049] Through data cleaning and standardization, a high-quality data foundation was established, and a dynamic correlation network was constructed by linking it with an abnormal communication number list. This effectively solved the problems of low data quality and insufficient intelligence utilization in traditional methods. Secondly, a multi-timescale feature extraction mechanism was adopted to overcome the limitations of traditional single-time-window analysis. By deploying a real-time rule matching layer, a behavior pattern analysis layer, and a correlation network analysis layer in parallel, a complementary detection system was formed: the real-time rule matching layer, based on a dynamically weighted multi-condition rule base, achieves rapid response, solving the problem of poor adaptability of traditional static rules; the behavior pattern analysis layer uses a hidden Markov model to identify the dynamic evolution of behavioral states, effectively capturing new abnormal behavior patterns; the correlation network analysis layer adopts a spatiotemporally weighted risk propagation model, combined with a community detection algorithm, significantly improving the ability to identify abnormal communication groups in complex networks. This multi-engine parallel analysis architecture ensures both real-time detection and the depth and breadth of analysis. Finally, a comprehensive risk score is generated through a multi-engine fusion decision-making mechanism, and tiered handling operations are implemented based on this score. This achieves precise and differentiated response strategies, which not only improves detection accuracy and real-time performance, but also enhances the ability to adapt to new abnormal communication behaviors, providing effective technical support for communication network security management. Attached Figure Description

[0050] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0051] Figure 1 A flowchart illustrating a communication risk detection method provided in this application embodiment;

[0052] Figure 2 A behavior analysis flowchart provided for an embodiment of this application;

[0053] Figure 3 A flowchart of the association analysis provided for embodiments of this application;

[0054] Figure 4 An evidence fusion decision-making flowchart is provided as an embodiment of this application;

[0055] Figure 5 This is a structural diagram of a communication risk detection system provided in an embodiment of this application. Detailed Implementation

[0056] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.

[0057] To facilitate understanding of the technical solutions provided in the embodiments of this application, the background technology involved in the embodiments of this application will be described below.

[0058] As mentioned earlier, the detection of abnormal behavior in current cross-border communication scenarios mainly faces the following technical challenges: traditional detection methods rely heavily on static rules and single-dimensional features, making it difficult to adapt to rapidly evolving communication behavior patterns; existing technologies suffer from insufficient real-time performance when processing massive amounts of roaming data; and traditional solutions have significant limitations in integrating multi-source heterogeneous data, failing to fully leverage the synergistic value of communication behavior features and external intelligence.

[0059] To address the aforementioned issues, this application first establishes a standardized data processing workflow, ensuring data quality through a multi-level verification mechanism. Secondly, it innovatively employs multi-timescale feature engineering to extract temporally relevant behavioral features from a dynamic correlation network. Furthermore, it forms a complementary detection architecture through parallel deployment of a real-time rule matching layer, a behavioral pattern analysis layer, and a correlation network analysis layer. Specifically, the real-time rule matching layer uses dynamically weighted multi-condition combination rules to ensure rapid response capabilities; the behavioral pattern analysis layer captures the evolutionary patterns of behavioral states based on a Hidden Markov Model; and the correlation network analysis layer identifies group risk characteristics through a spatiotemporally weighted risk propagation model. Finally, a fusion decision-making mechanism based on evidence theory intelligently integrates the results of multi-engine analysis and implements tiered handling based on a comprehensive risk score, thereby achieving accurate identification and timely intervention of abnormal communication behaviors. This technical solution effectively improves the accuracy, real-time performance, and adaptability of the detection system, providing reliable technical support for communication network security management.

[0060] It should be noted that the communication risk detection method, system, device, and medium provided in this application can be applied to the field of computer technology. The above are merely examples and do not limit the application field of the communication risk detection method, system, device, and medium provided in this application. Furthermore, the embodiments of this application may not limit the executing entity of the communication risk detection. For example, the communication risk detection method of this application embodiment can be applied to data processing devices such as terminal devices or servers. The terminal device can be an electronic device such as a computer or a personal digital assistant (PDA). The server can be a standalone server, a cloud server, or a cluster server composed of multiple servers.

[0061] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0062] The following embodiment illustrates a communication risk detection method provided in this application. See also... Figure 1 ,Should Figure 1 A flowchart of a communication risk detection method provided in this application embodiment, the method including:

[0063] S101. Acquire communication data and perform cleaning and standardization processing on the communication data.

[0064] First, the system needs to establish a stable and reliable data access channel to simultaneously acquire two core data sources in real-time or offline mode: roaming communication details provided by international operators and a list of abnormal communication numbers provided by authoritative institutions.

[0065] After acquiring the raw data, the system will initiate an automated, multi-level data cleaning and verification process:

[0066] Data format standardization involves uniformly converting and cleaning key fields in each communication record, such as caller ID, called ID, communication start timestamp, and communication type, to ensure that all data follows the same standard and lay the foundation for subsequent automated processing.

[0067] Data validity verification uses predefined rules to logically validate data. For example, it checks if the number format is valid, the communication time is within a reasonable range, and the call duration is positive. Abnormal records that fail automatic verification are transferred to a manual review queue for specialized processing by operations and maintenance personnel, thus ensuring the quality of input data.

[0068] S102. Associate the processed communication data with the preset abnormal communication number list database to construct a dynamic association network.

[0069] The cleaned and standardized communication data is then deeply correlated with a pre-defined list of abnormal communication numbers. This process is not a simple match, but rather uses a specific algorithm to calculate a dynamic intelligence credibility weight for each number in the list. This weight is a comprehensive quantitative indicator, and its calculation model mainly considers the following factors:

[0070] Time decay factor: Gives higher weight to recently active list numbers to ensure the system's sensitivity to current risks.

[0071] Frequency normalization factor: Weighting of list numbers that appear repeatedly in different scenarios to identify persistent risk sources.

[0072] Evidence credibility factor: Weighted according to the authority of evidence from different sources to enhance the decision-making influence of highly credible intelligence.

[0073] After completing the association and weight calculation, a dynamically updated association network is constructed. This network is constructed according to the following principles: nodes encompass all phone numbers appearing in the communication data; edges are established based on the actual communication relationships between numbers; edge weights quantify the closeness of the relationship based on indicators such as communication frequency and duration; and the initial node attributes assign corresponding intelligence credibility weights to the phone number nodes in the list as initial risk values.

[0074] This step transforms isolated communication records into a dynamic network structure with risk propagation capabilities. This network not only reflects the static relationships between numbers but also achieves real-time risk awareness through dynamic weight adjustments, providing a complete data foundation for subsequent graph analysis algorithms.

[0075] S103. Based on multiple preset time windows, extract behavioral features of the target number at multiple preset time scales from the dynamic association network.

[0076] From the cleaned communication data, multidimensional behavioral features are extracted for each target number across three preset time scales: short-term (1 hour), medium-term (24 hours), and long-term (30 days). This multi-time-scale feature extraction system avoids the limitations of traditional single-time-window methods. The system can simultaneously capture immediate anomalies, medium-term trend changes, and long-term behavioral patterns of the number, providing a data foundation for building a comprehensive risk assessment.

[0077] The standards for the three types of time windows can be fine-tuned according to the actual scenario. The short-term time window can be set to 1 hour to quickly capture sudden anomalies. The core objective is to quickly identify sudden abnormal behavior of numbers, adapting to real-time risk detection scenarios. The medium-term time window can be set to 24 hours to identify short-term fluctuations in behavioral patterns. The core objective is to identify short-term fluctuations and mutations in number behavior, adapting to the state evolution identification of the behavioral pattern analysis layer. The long-term time window can be set to 30 days to focus on stable patterns and to explore long-term behavioral patterns and network evolution. The core objective is to explore long-term behavioral patterns of numbers and changes in related networks, adapting to the group risk identification of the related network analysis layer.

[0078] Using a one-hour analysis window, indicators reflecting immediate behavioral patterns are calculated in real time, including call dispersion (the degree of dispersion in which a target number calls different numbers; high-frequency calls to a small number of targets show significantly different distribution characteristics compared to low-frequency calls to a large number of targets), communication success rate (the percentage of successfully connected calls out of total attempts, reflecting communication effectiveness), and temporal distribution anomaly (analyzing the distribution patterns of communication behavior over 24 hours to identify abnormally active periods that deviate significantly from normal routines). Behavior is captured in layers—immediate, medium-term, and long-term—avoiding both the risk of missing slow evolutions in the short-term window and the risk of misjudging occasional normal fluctuations in the long-term window. Short-term features support the real-time rule matching layer (millisecond-level response); medium-term features support the behavioral pattern analysis layer (hidden Markov model state evolution identification); and long-term features support the association network analysis layer (group risk and network evolution assessment).

[0079] Using a 24-hour analysis period, indicators reflecting behavioral trends are extracted. These include the number activity change rate, which compares daily communication activity with the previous day's to calculate the relative change rate; capturing sudden changes in activity; the rate of new called numbers; the proportion of newly added contact numbers in the total number of contact numbers; identifying abnormal expansion of contact networks; detecting communication pattern mutations; and applying statistical process control algorithms to detect abrupt changes in core behavioral indicators such as communication frequency and duration.

[0080] Using a 30-day analysis span, indicators reflecting behavioral stability and network evolution are extracted. The behavioral stability index, which is based on the ratio of the standard deviation to the mean of the daily behavioral vector, quantifies the degree of long-term behavioral fluctuation. The network evolution trend is revealed by analyzing the changes in network attributes of the target number in the time series of the dynamic network, including the rising and falling trends of network centrality, the changing paths of associated communities, and the evolution of the strength of association with high-risk nodes.

[0081] S104. Input the behavioral features in parallel to at least two of the real-time rule matching layer, behavior pattern analysis layer and association network analysis layer for processing, and obtain the analysis results of at least two layers.

[0082] The real-time rule matching layer, serving as the system's first line of defense, employs a rapid matching mechanism based on multi-condition combinations. This layer maintains a dynamically updated rule knowledge base, containing discrimination conditions based on multiple dimensions such as communication frequency thresholds, time window features, and behavioral anomaly levels. Each rule condition is equipped with an adaptive weight adjustment mechanism; the system dynamically optimizes the weight coefficients of each rule based on historical hit accuracy, ensuring the rule system's continuous evolution capability. The core advantage of this layer lies in its millisecond-level response speed, enabling rapid identification of communication behaviors conforming to preset high-risk patterns and outputting quantitative risk assessment results based on rule matching.

[0083] The behavior pattern analysis layer employs a deep behavior analysis method based on Hidden Markov Models. This layer constructs a state transition model encompassing four states: normal, suspicious, high-risk, and abnormal. A forward-backward algorithm is used to accurately calculate the probability distribution of the target number in each hidden state. During the analysis, key indicators such as communication frequency, called party dispersion, and time distribution are input into the model as observation sequences. The dynamic evolution of behavior patterns is identified by analyzing state transition paths. The key feature of this layer is its ability to capture the temporal characteristics and state transition patterns of communication behavior, providing a dynamic behavioral evolution analysis basis for risk assessment.

[0084] The network analysis layer, from the perspective of complex networks, constructs a topology analysis system based on communication relationships. This layer relies on a pre-constructed communication relationship graph and employs a spatiotemporally weighted risk propagation model. It utilizes an improved risk propagation algorithm to comprehensively consider factors such as communication frequency, time decay effect, and spatial distance to calculate association risks. Simultaneously, a community detection algorithm identifies closely related groups of phone numbers within the network and assesses the risk density characteristics at the group level. This analytical method effectively reveals potential associations between phone numbers, supplementing the shortcomings of individual behavior analysis at the network topology level.

[0085] First, the three analysis layers operate independently, significantly improving system processing efficiency. Second, cross-validation across rule matching, behavioral modeling, and network analysis ensures the comprehensiveness and accuracy of risk assessment. Finally, the system's adaptive optimization mechanism continuously adjusts analysis parameters based on feedback, maintaining its ability to evolve. This multi-engine parallel design provides a solid technical foundation for subsequent fusion decision-making.

[0086] It should be noted that the improved risk propagation algorithm in this application can be considered an improved PageRank algorithm. Traditional PageRank treats links as equal relationships. This algorithm defines the weight of communication relationships (edges) as a function of w_ij = f(communication frequency, communication duration, communication time distribution), making frequent, long-duration communication connections more capable of risk propagation. A time decay function is incorporated into the risk propagation process. (Δt) = exp(-λ·Δt). This means that recent communications contribute more to risk transmission, while the impact of older communications diminishes, which is more consistent with the time-sensitive nature of criminal behavior. A geographical distance attenuation function ψ(d) = 1 / (1 + d / δ) is introduced. The greater the distance between the originating and called numbers (through MCC / MNC, etc.), the weaker the risk transmission effect becomes, which helps to more accurately assess the associated risks in cross-border scenarios. The R_relation(q→p) function in the algorithm integrates edge weights, time attenuation, and communication intensity, making the propagation of risk from known high-risk nodes (q) to associated nodes (p) no longer uniform, but rather directional and weighted calculation based on the spatiotemporal strength and attributes of the relationship. In summary, by integrating the three key dimensions of communication behavior intensity, time freshness, and spatial distance into the traditional link analysis framework, the algorithm transforms the assessment from static importance evaluation to dynamic, spatiotemporally weighted risk transmission probability evaluation, thereby more accurately and reasonably identifying potential risk nodes in complex communication networks.

[0087] S105. Make a decision based on the analysis results of the at least two layers to obtain a comprehensive risk score for the target number.

[0088] First, a basic probability assignment function is constructed for the output of each analysis layer. Specifically, the risk score output by the real-time rule matching layer, the state probability calculated by the behavior pattern analysis layer, and the association risk value obtained by the association network analysis layer are uniformly transformed into a confidence assignment for a preset risk level.

[0089] The Dempster combination rule is used to synthesize the basic probability assignments of multiple analysis layers. This rule effectively handles conflicting evidence between different analysis layers, eliminates inconsistencies between evidence by calculating a normalization constant, and finally obtains the fused comprehensive confidence distribution. This mechanism is particularly suitable for handling boundary cases, where different analysis engines reach contradictory conclusions, and can derive the optimal compromise judgment through mathematical methods.

[0090] Based on the fused risk confidence score, a cost-sensitive hierarchical decision-making model is established. This model fully considers the differentiated costs arising from different types of misjudgments and determines the final risk level classification threshold by minimizing the overall handling cost. The system not only outputs a comprehensive risk score for the target number but also provides a confidence index for the assessment results, providing a basis for subsequent hierarchical handling decisions.

[0091] Thus, it achieves independent judgment by each analysis engine, effectively resolves evidence conflicts through mathematical methods, considers both the accuracy of risk assessment and the cost differences of different treatment strategies, and provides both a deterministic risk score and the credibility of the assessment, thereby realizing precise and intelligent risk decision-making.

[0092] S106. Based on the comprehensive risk score, perform corresponding graded handling operations on the target number.

[0093] Based on the comprehensive risk score generated in step S105, differentiated handling measures are taken for target numbers. This tiered handling mechanism achieves an optimal balance between security protection and communication assurance, effectively controlling high-risk threats while minimizing the impact on normal communications.

[0094] Level 1 response: intercept and report in real time.

[0095] When the overall risk score of a target number is greater than or equal to the first score (extremely high risk threshold), the system immediately activates the highest level of protection. The system sends a real-time interception command to the communication network gateway via a standardized interface, directly blocking the communication connection during the call setup phase. Simultaneously, the system automatically packages the risk assessment results and related evidence chain for the number into an early warning report, which is then reported to the relevant regulatory agency in real time via a secure data channel. This level of response primarily targets security threats with extremely high certainty, achieving proactive defense with a response time of up to seconds.

[0096] Level 2 response: delayed calls and risk alerts.

[0097] When the overall risk score falls between the first and second scores (the high-risk range), the system implements an intelligent delay handling strategy. The communication gateway automatically inserts a specific delay when connecting a call, allowing the system additional time for analysis and judgment. Simultaneously, a security alert is pushed to the called user's terminal, prompting the user to be aware of communication security risks via text or voice. This approach controls risk while preserving the possibility of continued communication, making it suitable for suspicious numbers requiring further observation and confirmation.

[0098] Level 3 Response: Key Monitoring and Sampling Analysis.

[0099] For medium-risk phone numbers whose overall risk score falls between the second and third levels, the system activates a deep monitoring mode. By setting specific sampling rules, the communication behavior of these numbers is monitored and recorded in detail, including communication frequency analysis, call content sampling (within legal limits), and behavioral pattern tracking. New evidence obtained during monitoring is fed back to the analysis system in real time to dynamically adjust the number's risk score.

[0100] Level 4 Response: Normal Release and Continuous Recording.

[0101] When the overall risk score falls below the third-highest score, the system adopts a minimal intervention strategy for the number. Communication requests are allowed normally, but the system continues to record behavioral data and update its feature database. This approach ensures a smooth communication experience for legitimate users while providing data support for the system's continuous learning.

[0102] The entire tiered response system enables flexible adjustments to security strategies through parameterized threshold configuration, creating an organic connection between each response level and constructing a complete response spectrum from complete blocking to full access. All response commands are sent to the communication network gateway in real time via standardized interfaces for execution, ensuring that protective measures are implemented at the network layer.

[0103] One possible implementation involves constructing a feedback data collection channel to collect performance data across three dimensions in real time: first, interception performance data, including the number of interceptions at each risk level, successful interception cases, and false alarm statistics; second, user feedback data, collected through customer service tickets, app feedback, and other channels to gather false alarm appeals and risk reports; and finally, authoritative confirmation data, receiving case confirmation information and new risk notifications from departments such as public security. This multi-source data, after cleaning and labeling, forms a training sample set for system optimization.

[0104] The system employs a policy gradient approach for online parameter tuning. It uses detection thresholds, rule weights, and model parameters as learnable policy parameters and calculates the policy gradient to find the optimal parameter configuration. Specifically, the system constructs a comprehensive reward function that includes key metrics such as true positive rate, false positive rate, and response time. By maximizing the cumulative reward, it achieves a balance between detection accuracy and efficiency.

[0105] Based on a reinforcement learning framework, the system establishes a cost-sensitive hierarchical decision optimization mechanism. By analyzing the differences in misjudgment costs for numbers at different risk levels, the system dynamically adjusts the handling thresholds at each level. The system continuously evaluates the actual effectiveness of each handling strategy, including factors such as interception success rate, user impact, and operational costs, and continuously improves the handling strategies based on the cost function.

[0106] The system periodically updates the state transition probability and observation probability parameters in the behavior pattern recognition model to capture the latest risk behavior characteristics. Simultaneously, the risk propagation weights in the association network analysis layer are dynamically adjusted based on the latest group risk distribution to ensure that network risk calculations reflect the current threat landscape.

[0107] This self-optimization mechanism forms a complete closed loop of identification, handling, feedback, and optimization, enabling the system to continuously adapt to evolving threats. By learning from actual operations, the system can proactively adapt to new risk patterns, maintaining a high detection rate while continuously reducing false alarms, thus steadily improving protection effectiveness. All optimization processes are based on a rigorous A / B testing framework to ensure the security and stability of system updates.

[0108] The following example illustrates the specific implementation process of a communication risk detection method provided in this application.

[0109] S201, International Roaming Data Standardization.

[0110] The system collects roaming communication details from international operators through a dedicated data receiving interface, using either real-time streaming or offline batch processing modes. Each communication record contains the following standardized fields: Caller ID: Uniquely identifies the number initiating the communication. Called Number ID: Uniquely identifies the number receiving the communication. Communication Start Timestamp: The communication start time accurate to the second. Communication Duration: The call duration or message transmission duration in seconds. Communication Type Identifier: Clearly distinguishes between voice calls and SMS services. Roaming Direction Identifier: Identifies the roaming direction of the communication (roaming in / roaming out). Home Network Code of the Other Party Number: Identifies the home network of the other party number using MCC (Mobile Country Code) and MNC (Mobile Network Code).

[0111] An automated data validity verification function can be used to perform real-time quality control on the input communication data. This verification function, based on predefined business rules and technical standards, ensures that the data relied upon for subsequent analysis and processing possesses complete credibility and availability. The verification function f(x) performs parallel verification on each input communication record x across four dimensions. The specific execution logic includes:

[0112] Verify that the calling number identifier conforms to the international standard number specifications defined in the "Valid Number Format Set". This set contains various valid number formats that conform to the standard, ensuring the structural legality of the number. Similarly, verify the called number's format compliance based on the "Valid Number Format Set", eliminating data quality issues such as abnormal number lengths, illegal characters, and non-compliance with numbering rules. Confirm that the communication start timestamp is within a reasonable time interval [current time - Δt, current time]. Here, Δt is the system's preset maximum acceptable delay window, designed to filter future timestamps or excessively delayed historical data to ensure data timeliness. Check that the communication duration falls within a preset reasonable range [0, T_max]. T_max is dynamically configured according to the communication type (e.g., different maximum duration thresholds are used for voice calls and SMS messages) to identify and exclude abnormally long communication records.

[0113] The system automatically marks a record as a "valid record" and transfers it to the subsequent processing flow only if record x simultaneously meets all four of the above conditions. If any condition fails verification, the record will be marked as an "abnormal record" and automatically routed to the manual review queue for specialized verification and processing by data quality specialists. This verification mechanism, through a combination of rigorous automated rules and necessary manual intervention, establishes a robust data quality defense while ensuring processing efficiency, providing a reliable data foundation for upper-level analytical applications.

[0114] S202, Joint analysis with risk data.

[0115] A dynamic correlation network is constructed to correlate the risk number database and communication data provided by the public security department in multiple dimensions. The risk value weight calculation model includes: W_intel=α·R_recency+β·R_frequency+γ·R_verification; where R_recency=e^(-λ·(t_current-t_report)) / / time decay factor; R_frequency=log(1+N_occurrences) / log(1+N_max) / / frequency normalization; R_verification=Σ(Evidence_Level_i×Confidence_i) / / evidence credibility weighting; α+β+γ=1, dynamically adjusted according to actual data performance.

[0116] The timeliness factor (R_recency) is used to assess the time value of intelligence. It is calculated using an exponential decay model, where λ is the decay coefficient, used to control the rate at which the intelligence value decays over time; (t_current - t_report) represents the time span from when the intelligence was reported to the present. This model ensures that recently reported intelligence has a higher weight, consistent with the time-sensitive nature of risk intelligence.

[0117] The frequency factor (R_frequency) measures the frequency of intelligence occurrences in historical data and is normalized using a logarithmic function. Here, N_occurrences represents the number of times the intelligence appears in the risk database, and N_max is the maximum number of occurrences among all intelligence reports. This design reflects the higher importance of recurring intelligence while compressing the numerical range through the logarithmic function, avoiding excessive influence of extreme values ​​on the model.

[0118] The credibility factor (R_verification) comprehensively assesses the reliability and sufficiency of intelligence sources. It achieves credibility fusion of multi-source evidence by weighted summation of the evidence level (Evidence_Level_i) and the corresponding confidence coefficient (Confidence_i) of different sources, ensuring the accuracy and reliability of the assessment results.

[0119] The weight coefficients α, β, and γ in the model satisfy the constraint α + β + γ = 1. These three coefficients represent the importance of the three factors in the overall assessment. The system dynamically adjusts these weight coefficients based on data performance and feedback in actual business scenarios, ensuring that the model can continuously adapt to changing risk situations and business needs. Through scientific mathematical modeling and dynamic optimization mechanisms, this computational model achieves a refined assessment of the value of risk intelligence, providing a reliable quantitative basis for subsequent risk identification and decision analysis.

[0120] S203, Number Behavior Characteristics Engineering System.

[0121] Multi-dimensional feature extraction from data based on a time-sliding window:

[0122] In the short-term behavioral characteristics (1-hour window), the call dispersion index is: D_call=-Σ(p_i·log(p_i)), where p_i=number of calls to the i-th number / total number of calls; the communication success rate characteristic is: S_comm=number of successful connections / total number of attempts; the time distribution anomaly is: T_anomaly=Σ|actual distribution_t-expected distribution_t|, where t∈24-hour period.

[0123] Mid-term behavioral characteristics (24-hour window) change rate of number activity: A_change = (today's activity - yesterday's activity) / yesterday's activity; new called numbers rate: N_new = number of new contact numbers / total number of contact numbers; communication pattern mutation detection: use CUSUM algorithm to detect behavioral pattern changes.

[0124] Long-term behavioral characteristics (30-day window), behavioral stability index: B_stability=1-σ(daily behavioral vector) / μ(daily behavioral vector); Evolutionary characteristics of the association network: by constructing the time series of the number association network, the trend of network structure change of number activity is obtained.

[0125] S204. Perform rule matching using real-time features.

[0126] A weighted risk score is obtained through a combination of multiple conditions. The basic rule function library includes: Rule 1 is... =(N_unique_calls> )&(Avg_duration< )&(Time_window∈Night_hours);

[0127] Two-dimensional rules =(SMS_send_rate> )&(Receiver_dispersion> )&(Content_similarity< );

[0128] Rule 3 is =(Roaming_in_flag=true)&(Call_failure_rate> )&(Short_interval_calls> ).

[0129] Comprehensive risk score: R_rule=Σ(w_i·f_i) / Σw_i, where the weight w_i is dynamically adjusted according to the rule hit accuracy: w_i=Accuracy_i / (1-Accuracy_i+ε).

[0130] Specifically, rule one is high-frequency, short-duration nighttime call detection. This rule targets abnormal behavior such as initiating brief calls to a large number of different targets within a short period of time and being active at night. Among them: N_unique_calls> The number of call objects exceeds the normal threshold, Avg_duration < This indicates that the average call duration is significantly shorter. Time_window∈Night_hours is limited to a specific time period at night. This combination pattern is often used to identify exploratory calling behavior that involves casting a wide net.

[0131] Rule 2 is for detecting bulk SMS sending behavior. This rule focuses on abnormal SMS sending patterns and makes judgments based on three dimensions: SMS_send_rate. An abnormal SMS sending frequency was detected, Receiver_dispersion> Assess the degree of recipient dispersion, Content_similarity< The analysis shows low content similarity, making this model suitable for identifying large-scale mass SMS promotional activities with differentiated content.

[0132] Rule 3 is for detecting roaming-in abnormal call patterns. This rule is specifically designed for abnormal communication in international roaming scenarios: Roaming_in_flag=true limits it to roaming users; Call_failure_rate> High call failure rate is indicated by Short_interval_calls. Detect short-duration, high-volume calls; this combination is used to identify unusual call probing behavior during intrusion.

[0133] A performance-based dynamic weight adjustment strategy is adopted. The rule weight w_i is positively correlated with its historical hit accuracy_i. The higher the accuracy of the rule, the greater its proportion in the decision. A smoothing factor ε is introduced to prevent the denominator from being zero, thus ensuring numerical stability.

[0134] S205. Analyze through behavioral patterns.

[0135] The process of constructing a behavior state recognition system based on a Hidden Markov Model can be found in [link to documentation]. Figure 2 , Figure 2 A behavior analysis flowchart provided for embodiments of this application includes:

[0136] State definition: S = {S_normal, S_suspicious, S_high_risk, S_fraud}, Observation sequence: O = {Communication frequency, called party dispersion, time distribution, call duration, SMS content characteristics}. Wherein, S_normal: represents normal communication behavior patterns, corresponding to typical user communication habits; S_suspicious: identifies slightly deviating behavior patterns, requiring attention but not yet posing a risk; S_high_risk: represents significantly abnormal behavior characteristics, with a clear risk indication; S_fraud: indicates highly abnormal communication patterns, corresponding to clearly defined abnormal behavior characteristics.

[0137] The state transition probability matrix is: A=[a_ij]_{4×4}, where a_ij=P(q_{t+1}=S_j|q_t=S_i), and each element a_ij represents the conditional probability of transitioning from the current state S_i to the next state S_j, which fully describes the evolution trend of the behavior pattern and the characteristics of state persistence.

[0138] The observation probability matrix is: B = [b_j(k)]_{4×M}, where b_j(k) = P(O_t = v_k | q_t = S_j). This matrix quantifies the probability distribution of various observation values ​​v_k under a specific behavioral state S_j, reflecting the statistical correlation between the state and the observation characteristics.

[0139] The forward-backward algorithm is used to calculate the probability of the system being in each state under a specific observation sequence. The final risk score is: R_behavior=P(q_t=S_high_risk|O)+P(q_t=S_fraud|O). This score comprehensively considers the probability of the system being in a high-risk state and an abnormal state, and achieves a quantitative assessment of behavioral risk through probability superposition.

[0140] S206. Analyze the network of connections.

[0141] Number association graph and calculation of network risk propagation risk; see the implementation process. Figure 3 , Figure 3 The flowchart for association analysis provided in this application embodiment, including number association mapping and calculation of network risk propagation risk, includes:

[0142] First, a communication graph is constructed, with nodes defined as V = {set of phone numbers}; edges as E = {set of communication relationships}; and edge weights as w_ij = f(communication frequency, communication duration, communication time distribution). The node set V contains all the communication numbers to be analyzed, with each node representing an independent communication entity. The edge set E records the communication relationships between nodes, establishing connections based on actual communication behavior. The edge weight w_ij is calculated using the function f to comprehensively evaluate the communication frequency, communication duration, and communication time distribution, quantifying the strength of the relationships between nodes.

[0143] An improved PageRank algorithm is used to calculate the node risk value: PR(p) = (1-d) / N + d·Σ(PR(q) / L(q))·R_relation(q→p), where R_relation(q→p) = σ(w_qp)·[α·T_recency + β·T_intensity + γ·T_duration], where the damping factor d controls the attenuation of risk propagation and is set to around 0.85. The total number of nodes N is the number of all nodes in the graph. The out-degree L(q) is the number of edges from node q to other nodes, reflecting the node's activity level. The activation function σ(w_qp) performs a nonlinear transformation on the basic edge weights to enhance the contribution of important relationships. The temporal proximity T_recency is a time decay factor based on the most recent communication time. The communication intensity T_intensity is a comprehensive index quantifying the frequency and duration of communication. The duration T_duration reflects the stability and persistence of communication relationships. α, β, and γ correspond to the importance weights of the three factors, satisfying the normalization condition. The PageRank algorithm can be translated as PageRank algorithm or simply as the page ranking algorithm.

[0144] The Louvain algorithm is used to detect community structure and calculate community risk density: Community_Risk = Σ(R_node_i) / N_community × (1 + δ·N_known_fraud / N_community). R_node_i: the individual risk value of node i within the community; N_community: the total number of nodes in the community; N_known_fraud: the number of known anomalous nodes in the community; and the adjustment factor δ: controls the amplification effect of known anomalous nodes on community risk. This parameter system establishes a complete analytical link from micro-node relationships to macro-community structure, achieving a comprehensive assessment and precise quantification of communication network risk.

[0145] S207. Make a comprehensive decision based on the calculation results of the above multiple engines.

[0146] A scientific multi-engine decision-making fusion mechanism is established to resolve potential evidence conflicts arising from different analytical engines and to arrive at comprehensive and reliable risk assessment conclusions. Based on Dempster-Shafer evidence theory, this mechanism effectively handles uncertain information and enhances the robustness of the overall decision-making system. See also Figure 4 , Figure 4 This is a flowchart of evidence fusion decision-making provided in an embodiment of this application.

[0147] The system receives risk confidence outputs from three independent analysis engines: (R): The reliability assignment of the risk level R by the real-time rule matching layer; (R): Reliability assignment of risk level R to the behavioral pattern analysis layer; (R): The confidence assignment of risk level R by the association network analysis layer. Each confidence assignment function represents the confidence level of the corresponding analysis engine for different risk levels, forming the basis for subsequent evidence fusion.

[0148] set up (R), (R), (R) represents the confidence assignment of the three engines to the risk level R of the number. The Dempster combination rule is used to synthesize the three confidence assignments, and the final confidence score is calculated as: m_fused(R) = [ ⊕ ⊕ ](R)=(1 / K)·Σ_{A∩B∩C=R} (A)· (B)· (C)

[0149] The normalization factor K is specifically used to handle and resolve conflicts between pieces of evidence: K = 1 - Σ_{A∩B∩C= } (A)· (B)· (C). This factor quantifies the degree of consistency among the evidence from the three engines. When the evidence is completely conflicting, the K value approaches 0, and when it is completely consistent, the K value equals 1.

[0150] S208, Interception strategy is dynamically generated.

[0151] Differentiated response strategies are implemented based on the comprehensive risk score of the phone number. By setting multi-level risk thresholds, the system achieves full-spectrum coverage from emergency interception to routine monitoring, ensuring rapid response to high-risk threats while minimizing the impact on normal communications.

[0152] When the final risk score R_final exceeds the extremely high risk threshold θ_high, the system immediately initiates the highest level of protection response. Specific measures include real-time call interception through the communication gateway to block risky communications at the network level; simultaneously, it automatically generates an early warning report and pushes relevant number information, risk assessment results, and evidence chains to the public security department's security system in real time. This level is suitable for security threats with extremely high confidence, achieving a security response within minutes.

[0153] For numbers with risk scores in the range [θ_medium, θ_high), the system implements an intelligent delay handling strategy. A specific delay is inserted during call setup to provide the system with additional time for analysis and judgment; simultaneously, a security alert is pushed to the called user's terminal via voice or text to remind the user to pay attention to communication security; and the number is added to a key monitoring list for continuous behavioral tracking. This approach controls risk while preserving the possibility of communication, and is suitable for suspicious numbers requiring further observation and confirmation.

[0154] When the risk score falls within the range of [θ_low, θ_medium), the system initiates a sampling monitoring mechanism. Communication behavior is recorded and analyzed according to preset sampling rules, including communication frequency statistics and call feature extraction; simultaneously, the system continuously updates the number's behavior profile, providing new data input for the risk assessment model. This level primarily targets numbers with certain risk characteristics but that have not yet met the handling criteria.

[0155] For numbers with a risk score below θ_low, the system maintains normal communication services without imposing any additional restrictions. However, the communication behavior data of these numbers will still be recorded by the system and incorporated into the continuous monitoring system, providing basic data support for the updating and optimization of the behavior model.

[0156] This tiered response system enables flexible adjustments to security strategies through parameterized threshold configuration, creating a seamless connection between response measures at each level. This ensures both effective protection and maintains the communication experience for normal users. All response commands are sent to the communication network gateway in real time via standardized interfaces, forming a complete closed-loop security protection system.

[0157] S209, System self-optimization mechanism.

[0158] Parameter tuning and continuous self-reinforcement: Objective function: J(θ) = E[Σγ^t·R_t]; where γ is used to balance the importance of current and future rewards; R_t represents the immediate reward obtained at each decision step. This objective function guides the system to evolve towards maximizing long-term cumulative rewards. The reward function R_t comprehensively considers three key performance indicators:

[0159] The reward function is: R_t = α·TPR - β·FPR - γ·Response_time; TPR (True Positive Rate): measures the system's ability to correctly identify risky numbers, with its importance reflected by the weight α. FPR (False Positive Rate): assesses the system's false positive rate, with its negative impact on the overall reward controlled by the weight β. Response_time: reflects the system's processing efficiency, with performance and timeliness balanced by the weight γ. These three indicators together constitute a complete evaluation system for system performance, ensuring that the optimization process considers both accuracy and efficiency.

[0160] Update parameters using the policy gradient method: θ←θ+η· _θJ(θ). Where η is the learning rate, which controls the step size for updating the parameters; _θJ(θ) represents the gradient of the objective function with respect to the parameter θ. This update method enables the system to automatically adjust the detection threshold, rule weights, and model parameters in the direction of performance improvement.

[0161] In one possible implementation, a three-tiered time window feature system is established, comprising a short-term time window (1 hour), a medium-term time window (24 hours), and a long-term time window (30 days). A feature importance-weighted fusion strategy is employed: F_fused = Σ_{t∈{S,M,L}}ω_t·Normalize(F_t), where the weights ω_t = f(feature stability_t, discriminative power_t, real-time performance_t). Feature stability assesses the volatility and temporal consistency of feature values; features with high stability are assigned higher confidence in decision-making. Feature discriminative power measures the ability of a feature to distinguish between normal and abnormal behavior; features with strong discriminative power have stronger predictive value. Feature real-time performance measures the speed at which a feature responds to the latest behavioral patterns, ensuring the system's sensitivity to recent changes.

[0162] In one possible implementation, the most probable sequence of states is computed using the Viterbi algorithm by constructing a four-state Hidden Markov Model:

[0163] δ_t(i) = max_{q_1,...,q_{t-1}}P(q_1...q_{t-1},q_t=i,O_1...O_t|λ); ψ_t(i) = argmax_{1≤j≤N}[δ_{t-1}(j)·a_ji]·b_i(O_t); This model can identify the gradual transition of a number from a normal state to a risky state, where δ_t(i) represents the maximum probability among all paths to reach state i at time t, which comprehensively considers the complete observation sequence up to time t and the decay coefficient λ. ψ_t(i) indicates the most likely state j of the previous time step when reaching state i at time t, thus constructing a complete state transition chain. This model can accurately capture the gradual changes in behavioral patterns and identify the complete evolution path from normal, suspicious, high-risk to abnormal states. This fine-grained state division enables the system to detect slowly evolving threats that are difficult to detect by traditional methods. By analyzing state transition sequences, the system can issue an early warning as soon as a number's behavior begins to deviate from the normal pattern, much earlier than when it reaches a clearly abnormal level. This proactive detection provides a time window for risk management.

[0164] In one possible implementation, a spatiotemporally weighted risk propagation model is used: R_propagated(p)=Σ_{q∈N(p)}[w_qp·R(q)· (t_current-t_last)·ψ(geo_distance)], where: (Δt) = exp(-λ·Δt) / / Time decay function, ψ(d) = 1 / (1+d / δ) / / Spatial decay function. This algorithm maintains high recall while avoiding excessively high false positive rates. Here, λ is the decay coefficient, controlling the rate at which risk decays over time; Δt = t_current - t_last represents the time interval between the current time and the most recent communication time. This mechanism ensures that recently occurring communication relationships have a higher weight in risk propagation, consistent with the time-sensitive characteristics of risk association. Here, d represents geographical distance, and δ is an adjustment factor. This function reflects the impact of geographical proximity on risk association; the closer the nodes are, the higher the risk propagation intensity, effectively capturing regional risk clustering characteristics.

[0165] In one possible implementation, an online learning framework based on policy gradients was constructed, enabling automated and intelligent optimization of system parameters: _θJ(θ)≈Σ_t _θlogπ_θ(a_t|s_t)·(R_t-b_t), where, _θJ(θ) represents the gradient of the objective function with respect to the parameter θ, guiding the direction of parameter updates; π_θ(a_t|s_t) represents the policy probability of choosing action a_t in state s_t; (R_t-b_t) is the advantage function, measuring the superiority of the current action relative to the baseline b_t. The system state s_t contains multi-dimensional real-time information: system performance indicators, including key operational indicators such as detection accuracy, response time, and resource utilization; risk manipulation trends, dynamically capturing the emergence and evolution of new risk patterns; and user feedback data, integrating user feedback information such as false alarm appeals and risk reports. Action a_t covers key dimensions of system optimization: threshold adjustment, dynamically optimizing risk judgment thresholds at each level; weight updates, adaptively adjusting the weight configuration of each detection engine; and rule activation / deactivation, intelligently managing the activation status of rules in the rule base.

[0166] In one possible implementation, a hierarchical decision-making model based on cost-sensitive learning is established to minimize the expected cost: minΣ_{i,j}C_{ij}·P(j|i)·P(i), where the cost matrix C_{ij} quantifies the cost of predicting the actual category i as category j; the cost of underreporting high-risk targets (C_high-risk→normal) is much higher than the cost of false positives (C_normal→high-risk); there are significant differences in the cost of misjudgment between different risk levels; the classifier performance P(j|i) is characterized by the confusion matrix; and the prior probability P(i) is the prior distribution of each risk level based on historical data.

[0167] The above are some specific implementations of the communication risk detection method provided in the embodiments of this application. Based on this, this application also provides a corresponding communication risk detection system. The system provided in the embodiments of this application will be described below from the perspective of functional modularity. Figure 5 This is a structural diagram of a communication risk detection system provided in an embodiment of this application.

[0168] The system includes:

[0169] Acquisition unit 110 is used to acquire communication data and perform cleaning and standardization processing on the communication data;

[0170] The construction unit 111 is used to associate the processed communication data with a preset list of abnormal communication numbers to build a dynamic association network;

[0171] Extraction unit 112 is used to extract behavioral features of target numbers at multiple preset time scales from the dynamic association network based on multiple preset time windows;

[0172] Processing unit 113 is used to input the behavioral features in parallel to at least two of the real-time rule matching layer, behavior pattern analysis layer, and association network analysis layer for processing, and obtain the analysis results of at least two layers; the real-time rule matching layer is used to perform matching based on a multi-condition combination rule base including communication frequency threshold, time window features, and behavior anomaly degree, and the rule weight of each condition is dynamically adjusted according to the hit accuracy, and outputs a first analysis result; the behavior pattern analysis layer is used to construct a hidden Markov model containing multiple risk states, and calculate the probability of the number being in each state through a forward and backward algorithm to identify the dynamic evolution of behavior patterns, and outputs a second analysis result; the association network analysis layer is used to calculate the associated risk based on a pre-constructed communication relationship graph and a spatiotemporally weighted risk propagation model, combined with communication frequency, time decay, and spatial distance factors, and simultaneously uses a community detection algorithm to assess the group risk density, and outputs a third analysis result;

[0173] Decision unit 114 is used to make decisions based on the analysis results of the at least two layers to obtain a comprehensive risk score for the target number;

[0174] The execution unit 115 is used to perform corresponding graded disposal operations on the target number based on the comprehensive risk score.

[0175] This application also provides corresponding devices and computer storage media for implementing the communication risk detection scheme provided in this application.

[0176] The device includes a memory and a processor. The memory is used to store instructions or code, and the processor is used to execute the instructions or code to enable the device to perform the communication risk detection method described in any embodiment of this application.

[0177] The computer storage medium stores code, and when the code is executed, the device running the code implements the communication risk detection method described in any embodiment of this application.

[0178] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the systems or apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and relevant parts can be referred to the method section.

[0179] It should be understood that in this application, "at least one" refers to one or more items, and "more" refers to two or more items. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one" or similar expressions refer to any combination of these items, including any combination of singular or plural items. For example, "at least one" of a, b, or c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.

[0180] It should be understood that the terms center, longitudinal, transverse, up, down, front, back, left, right, vertical, horizontal, top, bottom, inside, outside, etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the present invention.

[0181] It should be noted that, unless otherwise explicitly specified and limited, the terms installation, connection, and linking should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0182] It should also be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the statement "comprising a..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0183] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0184] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A communication risk detection method, characterized in that, include: Acquire communication data, and clean and standardize the communication data; The processed communication data is associated with a pre-set list of abnormal communication numbers to construct a dynamic association network; Based on multiple preset time windows, behavioral features of the target number at multiple preset time scales are extracted from the dynamic association network; The behavioral features are input in parallel to at least two of the real-time rule matching layer, behavior pattern analysis layer, and association network analysis layer for processing, and the analysis results of at least two layers are obtained. The real-time rule matching layer is used to perform matching based on a multi-condition rule base that includes communication frequency thresholds, time window features, and behavioral anomaly degree. The rule weights of each condition are dynamically adjusted according to the hit accuracy, and the first analysis result is output. The behavior pattern analysis layer is used to construct a hidden Markov model containing multiple risk states, and calculate the probability of the number being in each state through a forward-backward algorithm to identify the dynamic evolution of the behavior pattern, and output the second analysis result. The association network analysis layer is used to calculate the node risk value based on a pre-constructed communication relationship graph using a risk propagation algorithm, and identify high-risk association groups using a community detection algorithm, and output the third analysis result. A decision is made based on the analysis results of at least two layers to obtain a comprehensive risk score for the target number; Based on the comprehensive risk score, corresponding tiered handling operations will be performed on the target number; The extraction of behavioral features of the target number across multiple preset time scales from the dynamic association network based on multiple preset time windows includes: Based on a short time window, a first type of behavioral feature of the target number is extracted from the dynamic association network. The first type of behavioral feature includes at least one of call dispersion, communication success rate and time distribution anomaly. Based on a medium-term time window, a second type of behavioral characteristics of the target number is extracted from the dynamic association network. The second type of behavioral characteristics includes at least one of the following: number activity change rate, called number addition rate, and communication pattern mutation index. Based on a long-term time window, a third type of behavioral feature of the target number is extracted from the dynamic association network. The third type of behavioral feature includes at least one of the behavioral stability index and the association network evolution feature.

2. The method according to claim 1, characterized in that, The processing methods of the behavior pattern analysis layer include: Construct a hidden Markov model with normal state, suspicious state, low-risk state and high-risk state; The observation sequence, which includes communication frequency, called party discreteness, and time distribution, is input into the hidden Markov model. The probability of the target number being in each state under the observation sequence is calculated using a forward-backward algorithm; Based on the probability that the target number is in the high-risk state and the low-risk state, the second analysis result of the behavior pattern analysis layer is calculated and determined.

3. The method according to claim 1, characterized in that, The processing methods of the correlation network analysis layer include: A risk propagation algorithm is used to propagate risk on the communication relationship graph, calculate the risk value of each node, and calculate the risk propagation weight between each node based on the time decay factor and intensity factor of the communication relationship. The communication relationship graph is constructed with numbers as nodes and communication relationships as edges. The weight of the edge is determined based on at least one of communication frequency, communication duration and communication time distribution. The community detection algorithm is used to identify suspicious groups based on the node groups and risk values ​​of each node in the communication relationship graph, and the density of suspicious groups is calculated as the third analysis result of the association network analysis layer.

4. The method according to claim 1, characterized in that, The step of performing corresponding tiered handling operations on the target number based on the comprehensive risk score includes: If the comprehensive risk score is greater than or equal to the first score, then real-time interception and reporting will be performed; If the overall risk score is less than the first score but greater than or equal to the second score, then a delayed call will be executed and a notification will be sent. If the overall risk score is less than the second score but greater than or equal to the third score, then key monitoring or sampling surveillance will be implemented. If the overall risk score is less than the third score, then the vehicle is allowed to proceed normally and its behavior is continuously recorded.

5. The method according to claim 1, characterized in that, The processing methods of the real-time rule matching layer include: Construct a multi-condition combination rule base, wherein the rule base contains combination conditions based on at least two of communication frequency threshold, time window features and behavior anomaly degree; The extracted behavioral features are matched with the rules in the multi-condition combination rule base; The weights of each rule are dynamically adjusted based on the hit accuracy of the rules, and a real-time rule risk score is obtained based on the weighted calculation as the first analysis result.

6. The method according to claim 5, characterized in that, The multi-condition combination rule base includes at least one of the following rules: The rule is triggered when the number of unique called numbers for the target number is greater than the first threshold, the average call duration is less than the second threshold, and the communication occurs during a preset nighttime period. The rule is triggered when the SMS sending rate of the target number is greater than the third threshold, the dispersion of the recipient's number is greater than the fourth threshold, and the similarity of the SMS content is lower than the fifth threshold. This rule is triggered when the target number is an international roaming number, the call failure rate is greater than the sixth threshold, and the call frequency is greater than the seventh threshold.

7. A communication risk detection system, characterized in that, include: An acquisition unit is used to acquire communication data and perform cleaning and standardization processing on the communication data. The construction unit is used to associate the processed communication data with a preset list of abnormal communication numbers to build a dynamic association network; The extraction unit is used to extract behavioral features of the target number at multiple preset time scales from the dynamic association network based on multiple preset time windows; The method of extracting behavioral features of target numbers at multiple preset time scales from the dynamic association network based on multiple preset time windows includes: extracting a first type of behavioral feature of the target number from the dynamic association network based on a short-term time window, wherein the first type of behavioral feature includes at least one of call dispersion, communication success rate, and time distribution anomaly; extracting a second type of behavioral feature of the target number from the dynamic association network based on a medium-term time window, wherein the second type of behavioral feature includes at least one of number activity change rate, called number addition rate, and communication pattern mutation index; and extracting a third type of behavioral feature of the target number from the dynamic association network based on a long-term time window, wherein the third type of behavioral feature includes at least one of behavioral stability index and association network evolution characteristics. The processing unit is used to input the behavioral features in parallel to at least two of the real-time rule matching layer, behavior pattern analysis layer, and association network analysis layer for processing, and obtain the analysis results of at least two layers. The real-time rule matching layer is used to perform matching based on a multi-condition rule base that includes communication frequency thresholds, time window features, and behavioral anomaly degree. The rule weights of each condition are dynamically adjusted according to the hit accuracy, and the first analysis result is output. The behavior pattern analysis layer is used to construct a hidden Markov model containing multiple risk states, and calculate the probability of the number being in each state through a forward-backward algorithm to identify the dynamic evolution of the behavior pattern, and output a second analysis result. The association network analysis layer is used to calculate the node risk value based on a pre-constructed communication relationship graph using a risk propagation algorithm, and identify high-risk association groups using a community detection algorithm, and output a third analysis result. A decision-making unit is used to make decisions based on the analysis results of the at least two layers to obtain a comprehensive risk score for the target number; The execution unit is used to perform corresponding graded handling operations on the target number based on the comprehensive risk score.

8. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the communication risk detection method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed on a terminal device, cause the terminal device to perform the communication risk detection method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Hybrid intrusion detection method and system based on D-S evidence theory

    CN115225301A

  • Risk identification method and system

    CN121365423A