A number recognition method, device, equipment, medium and computer program product
By analyzing voice signaling and internet signaling data, and combining multi-dimensional features and causal relationships, fraudulent numbers can be identified, solving the problems of single detection dimensions and high false alarm rates in existing technologies, and achieving more efficient fraudulent call identification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE GROUP JILIN BRANCH
- Filing Date
- 2026-03-03
- Publication Date
- 2026-05-19
AI Technical Summary
Existing methods for identifying fraudulent calls have limited detection dimensions and incomplete evidence chains, resulting in a high false alarm rate.
By analyzing voice signaling data to obtain call scores for caller ID numbers, and combining this with internet signaling data to analyze abnormal behavior characteristics of called users, a multi-dimensional fraud identification mechanism is established. This mechanism uses causal relationships to identify fraudulent numbers, including obtaining call scores, causal strength values, and abnormal behavior similarity, and determining the probability and confidence level of risk assessment.
It significantly improves the integrity of the evidence chain for identifying fraudulent calls, reduces the false alarm rate, and achieves more accurate identification of fraudulent calls.
Smart Images

Figure CN121771325B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of fraudulent call identification technology, and in particular to a number identification method, device, equipment, medium, and computer program product. Background Technology
[0002] This invention relates to the fields of communication network and information security technology, particularly focusing on the detection and prevention of telecommunications network fraud. Modern communication networks, as a key infrastructure for the development of the digital economy, carry massive amounts of user communication behavior and business interaction data. Telecommunications network fraud, as one of the main methods of fraud today, poses a serious threat to users' property and communication security by disguising itself as normal communication behavior or providing false information. Therefore, accurately and efficiently identifying fraudulent calls is of paramount importance for building a secure communication environment and protecting users' rights.
[0003] In existing technologies, telecommunications network fraud detection mainly employs three technical solutions: static matching based on rule bases and blacklists, single-dimensional analysis based on shallow machine learning, and feature extraction based on single-modal deep learning. However, these methods have significant limitations. For example, the static matching scheme based on rule bases and blacklists heavily relies on a pre-set blacklist database, failing to promptly cover new types of fraudulent numbers. The single-dimensional analysis scheme based on shallow machine learning can only learn single-dimensional call behavior features, exhibiting limited generalization ability and difficulty in capturing complex fraudulent behavior patterns. Furthermore, while the feature extraction scheme based on single-modal deep learning utilizes deep learning technology, its recognition capability is limited. Summary of the Invention
[0004] The purpose of this invention is to provide a number identification method, apparatus, device, medium, and computer program product to solve the problems of existing fraud call identification methods having a single detection dimension, incomplete evidence chain, and high false alarm rate.
[0005] To achieve the above objectives, embodiments of the present invention provide a number identification method, comprising:
[0006] Based on voice signaling data, at least one target number with a call score exceeding a first threshold is obtained from multiple calling numbers; wherein, the call score is obtained based on the call characteristics of the calling number;
[0007] Based on the Internet access signaling data, the Internet access behavior of multiple called users corresponding to each target number is analyzed within a first preset time period to obtain the abnormal behavior characteristics of the called users.
[0008] Based on the abnormal behavior characteristics corresponding to each target number, obtain the causal strength value of the target number;
[0009] A first type of number is identified from the at least one target number based on the call score and the causal strength value; wherein, the first type of number is the target number whose risk assessment probability is greater than a second threshold and whose risk assessment confidence is greater than a third threshold; the risk assessment probability is obtained based on the call score and the causal strength value; the risk assessment confidence is obtained based on the call score and the causal strength value.
[0010] Optionally, the method, wherein obtaining the causal strength value of the target number based on the abnormal behavior characteristics corresponding to each target number includes:
[0011] Based on the abnormal behavior characteristics of the multiple called users corresponding to the target number, obtain the behavior similarity.
[0012] A behavior similarity matrix is obtained based on the behavior similarity corresponding to the target number; wherein each element in the similarity matrix represents the behavior similarity between any two of the multiple called users;
[0013] Based on the behavioral similarity matrix and the number of called users corresponding to the target number, a group consistency score is obtained;
[0014] The causal strength value is obtained based on the group consistency score.
[0015] Optionally, the method further includes, before obtaining the causal strength value based on the group consistency score:
[0016] A temporal correlation strength value is obtained based on the time interval between the abnormal behavior of the called user corresponding to the target number and the target call; wherein, the abnormal behavior is the behavior corresponding to the abnormal behavior feature; and the target call is the call between the called user and the target number.
[0017] The abnormal behavior score and the pre-acquired normal behavior score are used to obtain the abnormal behavior improvement degree.
[0018] Wherein, obtaining the causal strength value based on the group consistency score includes:
[0019] The causal strength value is obtained based on the group consistency score, the temporal correlation strength value, and the behavioral anomaly boosting degree.
[0020] Optionally, the method, wherein identifying a first type of number among the at least one target number based on the call score and the causal strength value, includes:
[0021] The risk assessment probability is obtained based on the call score and the causal strength value;
[0022] The risk assessment confidence level is obtained based on the difference between the call score and the causal strength value.
[0023] The target number is determined to be of the first type if the risk assessment probability is greater than the second threshold and the risk assessment confidence level is greater than the third threshold.
[0024] Optionally, the method, wherein obtaining the risk assessment probability based on the call score and the causal strength value includes:
[0025] Based on the call score and the preset call score weight, obtain the first value;
[0026] The second value is obtained based on the causal strength value and the preset causal strength value weight;
[0027] The risk assessment probability is obtained based on the first value and the second value.
[0028] Optionally, the method, wherein obtaining at least one target number among multiple calling numbers whose call score exceeds a first threshold based on voice signaling data, includes:
[0029] Based on the voice signaling data, obtain the call characteristics of the multiple calling numbers;
[0030] The call score of each calling number is obtained based on the difference between the call characteristics of each calling number and the fourth threshold corresponding to the call characteristics.
[0031] The calling number whose call score exceeds the first threshold is identified as the target number.
[0032] Optionally, the method wherein the call features include at least one of the following:
[0033] Call frequency characteristics, wherein the call frequency characteristics are obtained based on the number of calls made by the calling number within a second preset time period and the corresponding called party dispersion; the called party dispersion is the degree of dispersion of the called party numbers;
[0034] The call duration distribution characteristics are obtained based on the proportion of short calls and the degree of fluctuation in call duration; the proportion of short calls is the ratio of the number of short calls to the total number of calls; short calls are those with a duration less than a fifth threshold; and the degree of fluctuation in call duration is obtained based on the standard deviation and mean of the call duration.
[0035] Spatiotemporal anomaly features, wherein the spatiotemporal anomaly features are obtained based on the standard deviation and mean of the number of calls made by the calling number to the corresponding base station;
[0036] The called number discrete feature is obtained based on the calling probability of the called number corresponding to the calling number;
[0037] Call time distribution characteristics, wherein the call time distribution characteristics are obtained based on the number of calls made by the calling number within a unit time period and the preset expected number of calls;
[0038] The call failure rate feature is based on the number of failed calls and the number of short-term failed calls of the calling number; the short-term failed calls are calls with a duration less than a sixth threshold; the sixth threshold is less than the fifth threshold.
[0039] Optionally, in the method, the abnormal behavior characteristics include at least one of the following:
[0040] High-risk application access behavior, wherein the high-risk application access behavior is obtained based on the number of times the called user accesses a preset high-risk application within the first preset time period;
[0041] Sensitive operational behaviors, wherein the sensitive operational behaviors are obtained based on the called user's download behavior of abnormal software and acceptance of verification code SMS messages within the first preset time period;
[0042] Financial operations, wherein the financial operations are obtained based on the number of times the called user accesses financial applications within the first preset time period;
[0043] Information leakage behavior, wherein the information leakage behavior is obtained based on the website risk level corresponding to the preset risk website visited by the called user within the first preset time period;
[0044] Abnormal network behavior, wherein the abnormal network behavior is obtained based on the number of times the called user connects to a preset suspicious network within the first preset time period.
[0045] To achieve the above objectives, embodiments of the present invention provide a number recognition device, comprising:
[0046] The first acquisition module is used to acquire at least one target number whose call score exceeds a first threshold from multiple calling numbers based on voice signaling data; wherein the call score is acquired based on the call characteristics of the calling number;
[0047] The second acquisition module is used to analyze the internet access behavior of multiple called users corresponding to each target number within a first preset time period based on internet access signaling data, and to acquire the abnormal behavior characteristics of the called users.
[0048] The third acquisition module is used to acquire the causal strength value of the target number based on the abnormal behavior characteristics corresponding to each target number;
[0049] A first processing module is configured to identify a first type of number among the at least one target number based on the call score and the causal strength value; wherein the first type of number is a target number whose risk assessment probability is greater than a second threshold and whose risk assessment confidence is greater than a third threshold; the risk assessment probability is obtained based on the call score and the causal strength value; the risk assessment confidence is obtained based on the call score and the causal strength value.
[0050] To achieve the above objectives, embodiments of the present invention provide a number recognition device, comprising: a processor, a memory, a transceiver, and a program or instructions stored in the memory and executable on the processor; wherein, when the processor executes the program or instructions, it implements the number recognition method as described above.
[0051] To achieve the above objectives, embodiments of the present invention provide a readable storage medium having a program or instructions stored thereon, wherein the program or instructions, when executed by a processor, implement the steps in the number identification method described above.
[0052] To achieve the above objectives, embodiments of the present invention provide a computer program product, which includes computer instructions that, when executed by a processor, implement the steps of the number recognition method described above.
[0053] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0054] In this embodiment of the invention, call scores of multiple calling numbers are obtained based on voice signaling data to filter out target numbers suspected of being fraudulent. Then, the online behavior of multiple called users of the target numbers within a first preset time period is analyzed to obtain the causal strength value of the target numbers. Based on the call scores and causal strength values of the target numbers, fraudulent numbers among the target numbers are confirmed. By fully utilizing voice signaling data and internet signaling data, and by analyzing the causal relationship between abnormal communication characteristics of calling numbers and abnormal network behavior of called users after the call, a multi-dimensional and comprehensive fraud identification mechanism is established. This solves the problem of one-sidedness caused by a single detection dimension, significantly improves the completeness of the evidence chain, and reduces the false alarm rate. Attached Figure Description
[0055] Figure 1This is a schematic diagram of the number recognition method described in an embodiment of the present invention;
[0056] Figure 2 This is a schematic diagram of the number recognition device according to an embodiment of the present invention;
[0057] Figure 3 This is a schematic diagram of the number recognition device according to an embodiment of the present invention. Detailed Implementation
[0058] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0059] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0060] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0061] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0062] In the embodiments provided by this invention, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean that B is determined solely based on A; B can also be determined based on A and / or other information.
[0063] For ease of understanding, some aspects of the embodiments of the present invention will be described below.
[0064] like Figure 1 As shown, an embodiment of the present invention provides a number recognition method, which includes:
[0065] Step S10: Based on voice signaling data, at least one target number with a call score exceeding a first threshold is obtained from multiple calling numbers; wherein the call score is obtained based on the call characteristics of the calling number.
[0066] It should be noted that, based on multi-dimensional feature engineering, abnormal communication characteristics (i.e., call characteristics) of calling numbers are quantitatively analyzed, extracting call frequency characteristics, call duration distribution characteristics, spatiotemporal anomaly characteristics, called number dispersion characteristics, call time distribution anomaly characteristics, and call failure rate characteristics to generate a calling anomaly score, i.e., the call score. Based on voice signaling data, a multi-dimensional feature analysis method is used to identify abnormal calling numbers. The feature extraction method is as follows: Let the set of calling numbers be... For each calling number Extract the following feature vectors: The formula for calculating the call score is as follows:
[0067] .
[0068] The meanings of the relevant parameters in the formula are as follows:
[0069] w k The weight coefficient of the k-th feature (i.e., the call feature) satisfies Σw k =1;
[0070] α k : The scaling factor of the k-th feature, used to control the steepness of the Sigmoid function;
[0071] β k The threshold parameter for the k-th feature determines the critical point of feature anomaly.
[0072] f k : The actual calculated value of the k-th feature.
[0073] The weight configuration of the call features:
[0074] w1=0.25 (call frequency characteristics), w2=0.20 (call duration distribution characteristics), w3=0.15 (spatiotemporal anomaly characteristics), w4=0.18 (called number dispersion characteristics), w5=0.12 (call time distribution anomaly characteristics), w6=0.10 (call failure rate characteristics).
[0075] The threshold parameter for the call characteristics:
[0076] β1=0.8 (threshold for call frequency characteristics), β2=0.6 (threshold for call duration distribution characteristics), β3=1.5 (threshold for spatiotemporal anomaly characteristics), β4=0.7 (threshold for called number dispersion characteristics), β5=2.0 (threshold for call time distribution anomaly characteristics), β6=0.4 (threshold for call failure rate characteristics).
[0077] The scaling factor for the call characteristics:
[0078] αk It is recommended that the value be between 2 and 5, which can be adjusted according to the sensitivity of the feature.
[0079] Rules for identifying suspected fraudulent caller ID numbers (i.e., the target number):
[0080] Score_caller < 0.3: Normal number, meaning a call score less than 0.3 indicates a normal number;
[0081] 0.3 ≤ Score_caller < 0.6: Low risk, meaning the call score is between 0.3 and 0.6, indicating a low-risk number;
[0082] 0.6 ≤ Score_caller < 0.8: Medium risk, to be observed, meaning the call score is between 0.6 and 0.8, which is a medium risk number to be observed;
[0083] Score_caller ≥ 0.8: High risk, considered a suspicious caller number and included in the further called party association analysis sequence; that is, the call score is greater than 0.8, and it is used as the target number for subsequent analysis. The first threshold can be set to 0.8, or it can be set to other values according to actual needs.
[0084] Step S20: Based on the Internet access signaling data, analyze the Internet access behavior of multiple called users corresponding to each target number within a first preset time period to obtain the abnormal behavior characteristics of the called users.
[0085] It should be noted that for the identified suspicious caller ID (i.e., the target ID), the set of called users contacted by it is extracted, and the abnormal internet behavior of the called users within a certain period after the call is analyzed. A time-series behavior window is defined: the behavior observation time window is [t_call_end, t_call_end + Δt_observation], where Δt_observation is recommended to be 3 hours (i.e., the first preset time period). The setting of the first preset time period can be adjusted according to actual needs. Abnormal internet behavior feature extraction: For each called user uj, a behavior feature vector (i.e., the abnormal behavior features) is extracted:
[0086] F_web(uj) = [g1, g2, g3, g4, g5].
[0087] The abnormal threshold setting for the abnormal behavior characteristics:
[0088] g1 > 1.5: High-frequency access to financial applications;
[0089] g2 > 0.7: Sensitive downloads or CAPTCHA bombing may exist;
[0090] g3 > 2.0: Frequent switching between multiple bank applications;
[0091] g4 > 1.0: Accessing websites with known risks;
[0092] g5 > 1.8: Abnormal network connection behavior exists.
[0093] Step S30: Obtain the causal strength value of the target number based on the abnormal behavior characteristics corresponding to each target number.
[0094] It should be noted that for the set of called users U = {u1, u2, ..., um} contacted by the suspicious calling number ci (i.e., the target number), the behavioral similarity matrix SimMatrix is calculated, thereby obtaining the group consistency score corresponding to the target number. The causal strength value Strength_causal(ci) is calculated based on the group consistency score.
[0095] Step S40: Identify a first type of number among the at least one target number based on the call score and the causal strength value; wherein, the first type of number is the target number whose risk assessment probability is greater than a second threshold and whose risk assessment confidence is greater than a third threshold; the risk assessment probability is obtained based on the call score and the causal strength value; the risk assessment confidence is obtained based on the call score and the causal strength value.
[0096] It should be noted that the call score and causal strength value of each target number are calculated to obtain the corresponding risk assessment probability and risk assessment confidence level. If the risk assessment probability is greater than the second threshold and the risk assessment confidence level is greater than the third threshold, the corresponding target number is identified as the first type of number, i.e., a high-risk fraud-related number, and appropriate action is required.
[0097] In this embodiment, call scores of multiple calling numbers are obtained based on voice signaling data to filter out target numbers suspected of being fraudulent. Then, the online behavior of multiple called users of the target numbers within a first preset time period is analyzed to obtain the causal strength value of the target numbers. Based on the call scores and causal strength values of the target numbers, fraudulent numbers among the target numbers are confirmed. By fully utilizing voice signaling data and internet signaling data, and analyzing the causal relationship between abnormal communication characteristics of calling numbers and abnormal network behavior of called users after the call, a multi-dimensional and comprehensive fraud identification mechanism is established. This solves the problem of one-sidedness caused by a single detection dimension, significantly improves the integrity of the evidence chain, and reduces the false alarm rate.
[0098] Optionally, the method, wherein step S30 includes:
[0099] Based on the abnormal behavior characteristics of the multiple called users corresponding to the target number, obtain the behavior similarity.
[0100] A behavior similarity matrix is obtained based on the behavior similarity corresponding to the target number; wherein each element in the similarity matrix represents the behavior similarity between any two of the multiple called users;
[0101] Based on the behavioral similarity matrix and the number of called users corresponding to the target number, a group consistency score is obtained;
[0102] The causal strength value is obtained based on the group consistency score.
[0103] In this embodiment, the similarity S ij The calculation is as follows:
[0104] ;
[0105] Parameter meaning:
[0106] F_web(u i User u i The abnormal behavior feature vector [g1, g2, g3, g4, g5];
[0107] t i , t j User u i and u j The call ended timestamp;
[0108] τ: Time decay coefficient, recommended value is 3600 seconds (1 hour);
[0109] |t i - t j |: The absolute value of the time difference between two users' calls.
[0110] Further construct a similarity matrix (i.e., the behavior similarity matrix). For m called users, construct an m*m symmetric matrix:
[0111] ;
[0112] Where S ij = S ji And S ii = 1.
[0113] Calculate the group consistency score:
[0114] ;
[0115] (where i ranges from 1 to m-1, and j ranges from i+1 to m).
[0116] The meaning of the parameters in the formula for the group consistency score:
[0117] m: Total number of called users, i.e., the number of called users;
[0118] : Indicator function, returns 1 if the condition is true, otherwise returns 0;
[0119] Score_web(u j User u j Individual abnormality scores. ,in, The feature weights satisfy the condition that the weighting is equal to 1. For u j The kth abnormal feature value (i.e. the abnormal behavior feature).
[0120] θ abnormal Individual abnormality threshold, recommended value is 0.6.
[0121] The causal strength value is obtained based on the group consistency score.
[0122] Optionally, the method further includes, before obtaining the causal strength value based on the group consistency score:
[0123] A temporal correlation strength value is obtained based on the time interval between the abnormal behavior of the called user corresponding to the target number and the target call; wherein, the abnormal behavior is the behavior corresponding to the abnormal behavior feature; and the target call is the call between the called user and the target number.
[0124] The abnormal behavior score and the pre-acquired normal behavior score are used to obtain the abnormal behavior improvement degree.
[0125] Wherein, obtaining the causal strength value based on the group consistency score includes:
[0126] The causal strength value is obtained based on the group consistency score, the temporal correlation strength value, and the behavioral anomaly boosting degree.
[0127] In this embodiment, the formula for calculating the temporal correlation strength value is as follows:
[0128] ;
[0129] In the formula, min_delay(uj () represents the minimum time delay for the called user u j The minimum value is calculated by finding the timestamps of all abnormal behaviors using the following formula: t_action is the time point at which the internet access behavior occurs, and t_call is the time point at which the target call ends.
[0130] The meaning of the parameters in the formula for the temporal correlation strength value:
[0131] min_delay(u j User u j The minimum time interval between the abnormal behavior and the call, i.e., the time interval;
[0132] τ_temporal: Temporal decay coefficient, a value of 1800 seconds (30 minutes) is recommended, but it can be adjusted according to needs;
[0133] t_action: The timestamp of the abnormal behavior, i.e., the time when the internet activity occurred;
[0134] t_call: Call end timestamp, i.e. the time when the target call ended.
[0135] The formula for calculating the elevation degree of the behavioral anomaly is as follows:
[0136] Strength_anomaly = max(0, (avg_abnormal_score - Baseline_web) / Baseline_web);
[0137] The meanings of the parameters in the formula for calculating the elevation of abnormal behavior are as follows:
[0138] avg_abnormal_score: Average abnormality score, calculated as: avg_abnormal_score = (1 / m) × Σ Score_web(u j ), Score_web(u j ) is the called user u j The aforementioned abnormal behavior score;
[0139] Baseline_web: Baseline score, calculated as: Baseline_web = μ_normal + 2 × σ_normal. It is based on the statistical distribution of the normal user group and is recommended to be set to 0.3. This value can be adjusted based on actual data. μ_normal is the mean of abnormal scores from normal users, and σ_normal is the standard deviation of abnormal scores from normal users. The data for normal users consists of pre-collected positive sample data.
[0140] The formula for calculating the causal strength value is as follows:
[0141] Strength_causal(c i ) = w t × Strength_temporal + w a × Strength_anomaly+ w c × Score_consistency(c i );
[0142] Among them, Strength_causal(c i ) represents the causal strength value of the target number, Strength_temporal represents the temporal correlation strength value of the target number, Strength_anomaly represents the behavioral anomaly elevation degree of the target number, and Score_consistency(c) represents the causal strength value of the target number. i The target number is given a group consistency score.
[0143] weight w t + w a + w c = 1, w can be set t = 0.35 (the weight corresponding to the temporal correlation strength value), w a = 0.40 (the weight corresponding to the elevation degree of the aforementioned behavioral anomalies), w c = 0.25 (the weight corresponding to the group consistency score).
[0144] Optionally, the method, wherein step S40 includes:
[0145] The risk assessment probability is obtained based on the call score and the causal strength value;
[0146] The risk assessment confidence level is obtained based on the difference between the call score and the causal strength value.
[0147] The target number is determined to be of the first type if the risk assessment probability is greater than the second threshold and the risk assessment confidence level is greater than the third threshold.
[0148] In this embodiment, the final risk assessment is constructed based on two core dimensions: caller anomaly score and causal correlation strength. The risk assessment probability, RiskScore, is obtained based on the call score and the causal correlation strength value. The formula for calculating the risk assessment confidence level is as follows:
[0149] Confidence = 1 - |Score_caller - Strength_causal|;
[0150] Wherein, Score_caller is the call score, and Strength_causal is the causal strength value.
[0151] Confidence > 0.8: High confidence level, evidence from both dimensions is consistent, the third threshold is 0.8, which can be adjusted according to actual needs;
[0152] 0.5 ≤ Confidence ≤ 0.8: Moderate confidence level;
[0153] Confidence < 0.5: Low confidence level, the evidence is contradictory.
[0154] When the final assessment result of the target number is that the risk assessment probability is high (RiskScore ≥ 0.7) and the risk assessment confidence level is greater than 0.8, the target number is a high-risk fraud-related number (i.e., the first type of number) and needs to be dealt with accordingly.
[0155] Optionally, the method, wherein obtaining the risk assessment probability based on the call score and the causal strength value includes:
[0156] Based on the call score and the preset call score weight, obtain the first value;
[0157] The second value is obtained based on the causal strength value and the preset causal strength value weight;
[0158] The risk assessment probability is obtained based on the first value and the second value.
[0159] In this embodiment, the formula for calculating the risk assessment probability is as follows:
[0160] RiskScore(c i ) = sigmoid(α × Score_caller(c i ) + β × Strength_causal(c i ) + γ);
[0161] Among them, Score_caller(c i Strength_causal(c) represents the call score, and α represents the call score weight, with a recommended value of 2.5-3.5. iα is the causal strength value, β is the weight of the causal strength value, and a value of 3.0-4.0 is recommended. γ is the bias term used to adjust the risk baseline, and a value of -2.5 is recommended. The values of α, β and γ can be adjusted according to actual needs.
[0162] Risk levels are classified based on the aforementioned risk assessment probabilities:
[0163] Low risk: RiskScore < 0.3;
[0164] Medium risk: 0.3 ≤ RiskScore < 0.7;
[0165] High risk: RiskScore ≥ 0.7.
[0166] In low-risk situations: Score_caller < 0.5 and Strength_causal < 0.4, the caller (i.e., the target number) exhibits slightly abnormal behavior, but lacks clear evidence of causal relationship;
[0167] In the case of medium risk: (Score_caller ≥ 0.5 and Strength_causal ≥ 0.4) or (Score_caller ≥ 0.7 and Strength_causal ≥ 0.3), the target number has some anomalies, but the evidence is not sufficient;
[0168] In high-risk situations: Score_caller ≥ 0.7 and Strength_causal ≥ 0.6, the caller (i.e. the target number) behaves highly abnormally and there is strong evidence of causal relationship.
[0169] Optionally, the method, wherein step S10 includes:
[0170] Based on the voice signaling data, obtain the call characteristics of the multiple calling numbers;
[0171] The call score of each calling number is obtained based on the difference between the call characteristics of each calling number and the fourth threshold corresponding to the call characteristics.
[0172] The calling number whose call score exceeds the first threshold is identified as the target number.
[0173] In this embodiment, based on voice signaling data, a multi-dimensional feature analysis method is used to identify abnormal caller ID numbers. The feature extraction method is as follows: Let the set of caller ID numbers be... For each calling number Extract the following feature vectors: The call score for each calling number is obtained based on the difference between the call characteristics of that calling number and the fourth threshold corresponding to those call characteristics. The calculation formula is as follows:
[0174] ;
[0175] A caller score of Score_caller ≥ 0.8 indicates high risk and is considered a suspicious caller number, thus being included in further called party association analysis. The first threshold is 0.8, which can be adjusted according to actual needs. Caller numbers with a call score exceeding the first threshold are considered suspicious numbers, i.e., the target numbers.
[0176] Optionally, the method wherein the call features include at least one of the following:
[0177] Call frequency characteristics, wherein the call frequency characteristics are obtained based on the number of calls made by the calling number within a second preset time period and the corresponding called party dispersion; the called party dispersion is the degree of dispersion of the called party numbers;
[0178] The call duration distribution characteristics are obtained based on the proportion of short calls and the degree of fluctuation in call duration; the proportion of short calls is the ratio of the number of short calls to the total number of calls; short calls are those with a duration less than a fifth threshold; and the degree of fluctuation in call duration is obtained based on the standard deviation and mean of the call duration.
[0179] Spatiotemporal anomaly features, wherein the spatiotemporal anomaly features are obtained based on the standard deviation and mean of the number of calls made by the calling number to the corresponding base station;
[0180] The called number discrete feature is obtained based on the calling probability of the called number corresponding to the calling number;
[0181] Call time distribution characteristics, wherein the call time distribution characteristics are obtained based on the number of calls within the time period of the calling number and the preset expected number of calls;
[0182] The call failure rate feature is based on the number of failed calls and the number of short-term failed calls of the calling number; the short-term failed calls are calls with a duration less than a sixth threshold; the sixth threshold is less than the fifth threshold.
[0183] In this embodiment, the call frequency characteristics The calculation formula is as follows:
[0184] ;
[0185] The parameters in the formula have the following meanings:
[0186] N_calls(c i Caller ID c i The total number of calls within the observation time window, i.e., the number of calls made by the calling number within the second preset time period;
[0187] T_observation: Observation time window length (unit: hours), preset to 24 hours, which is the second preset time period;
[0188] N_unique_calls(c i Caller ID c i The number of unique called numbers; duplicate numbers are counted only once.
[0189] The log operation is used to prevent division by zero errors and to smooth out data.
[0190] The call frequency characteristics can comprehensively reflect the calling activity of the calling number and the dispersion of the called number. Fraudulent numbers usually have the characteristics of high-frequency calling and highly dispersed called numbers.
[0191] The call duration distribution characteristics The calculation formula is as follows:
[0192] ;
[0193] The parameters in the formula have the following meanings:
[0194] N_short_calls(c i ): The number of calls whose call duration is less than the threshold T_short, where T_short is preset to 30 seconds;
[0195] N_total_calls(c i Total number of calls;
[0196] σ_duration: Standard deviation of call duration;
[0197] μ_duration: The average call duration;
[0198] The call duration distribution feature is used to characterize the abnormal distribution pattern of call duration. The first part is used to calculate the proportion of short calls, and the second part reflects the degree of fluctuation in call duration. Fraudulent numbers usually have a high proportion of short calls and large fluctuations in call duration (for example, the call is longer when the fraud is successful and shorter when it fails).
[0199] The spatiotemporal anomaly features The calculation formula is as follows:
[0200] ;
[0201] The parameters in the formula have the following meanings:
[0202] N_calls(cell_j): The number of calls made at base station cell_j;
[0203] μ_cell: The average number of calls made to all base stations, μ_cell = ΣN_calls(cell_j) / N_cells;
[0204] σ_cell: Standard deviation of the number of calls to all base stations;
[0205] N_cells: The total number of base stations involved in the calling number.
[0206] The spatiotemporal anomaly features quantify the degree of anomaly in the spatial distribution of calling numbers. By calculating the absolute deviation of the number of calls from each base station from the mean, dividing by the standard deviation for standardization, and finally averaging, a comprehensive spatial anomaly score is obtained. Fraudulent devices (such as GOIP) typically switch frequently between different base stations, leading to spatial distribution anomalies.
[0207] The discrete characteristics of the called number The calculation formula is as follows:
[0208] ;
[0209] The parameters in the formula have the following meanings:
[0210] N_unique_calls(c i ): The number of unique called numbers;
[0211] N_calls(c i Total number of calls;
[0212] p k The probability of calling the kth called number can be calculated by dividing the number of times the kth called number is called by the total number of calls, which is the calling probability.
[0213] The called number discrete characteristics measure the degree of dispersion and uniformity of distribution of called numbers. The first part, N_unique / N_calls, directly reflects the called number dispersion, while the second part, entropy, reflects the amount of information in the called number distribution. Fraudulent numbers typically contact a large number of different called numbers, and their distribution is relatively uniform.
[0214] The call time distribution characteristics The calculation formula is as follows:
[0215] ;
[0216] The parameters in the formula have the following meanings:
[0217] N_calls(h): The actual number of calls made in hour h, where h = 0, 1, ..., 23;
[0218] E_calls(h): The expected number of calls per hour h (based on normal user behavior patterns), calculated as follows: , where P_normal(h) is the calling probability distribution of normal users in hour h (which can be constructed using known data samples of normal users);
[0219] I_non_peak(h): The off-peak period indicator function, which is 1 during off-peak periods and 0 otherwise.
[0220] The call time distribution features are used to detect abnormal patterns in call time distribution by comparing the difference between the actual call distribution and the expected distribution, and focusing on abnormal activities during off-peak hours.
[0221] The call failure rate characteristics The calculation formula is as follows:
[0222] ;
[0223] The parameters in the formula have the following meanings:
[0224] N_failed_calls(c i ): Number of failed calls (including rejected calls, calls that did not connect, etc.);
[0225] N_total_calls(c i Total number of calls;
[0226] N_short_failed_calls: The number of short-term failed calls (calls that are immediately disconnected after being connected), and calls with a duration less than the sixth threshold. Unlike the short calls mentioned above, the call duration is shorter than that of the short calls.
[0227] The call failure rate feature comprehensively reflects abnormal call success rates. The first part calculates the overall failure rate, and the second part is the weighted short-term failure rate. Fraudulent numbers typically have a high failure rate, and include a large number of cases where the call is immediately disconnected after being identified by the user.
[0228] Optionally, in the method, the abnormal behavior characteristics include at least one of the following:
[0229] High-risk application access behavior, wherein the high-risk application access behavior is obtained based on the number of times the called user accesses a preset high-risk application within the first preset time period;
[0230] Sensitive operational behaviors, wherein the sensitive operational behaviors are obtained based on the called user's download behavior of abnormal software and acceptance of verification code SMS messages within the first preset time period;
[0231] Financial operations, wherein the financial operations are obtained based on the number of times the called user accesses financial applications within the first preset time period;
[0232] Information leakage behavior, wherein the information leakage behavior is obtained based on the website risk level corresponding to the preset risk website visited by the called user within the first preset time period;
[0233] Abnormal network behavior, wherein the abnormal network behavior is obtained based on the number of times the called user connects to a preset suspicious network within the first preset time period.
[0234] In this embodiment, the calculation formula for the high-risk application access behavior g1 is as follows:
[0235] ;
[0236] The parameters in the formula have the following meanings:
[0237] N_access(app): The number of times an application (app) in a predefined set of high-risk application domains is accessed within the observation time window (based on DNS queries or traffic feature identification).
[0238] T_observation: Length of the observation time window, i.e., the duration of the first preset time period;
[0239] RiskWeight (app): Applies risk weights, which can be set as follows: Banking: 0.9, Payment: 0.8, Loan: 0.7. These weights can be adjusted according to actual needs.
[0240] A_high_risk: A predefined set of high-risk application domain names.
[0241] The formula for calculating the sensitive operation behavior g2 is as follows:
[0242] ;
[0243] The parameters in the formula have the following meanings:
[0244] I_download: Whether abnormal software is downloaded (0 / 1), based on download traffic outside the app store;
[0245] N_verify_sms: Number of verification code SMS messages received (based on SMS signaling analysis);
[0246] w_download: Download behavior weight (recommended 0.6), which can be adjusted according to actual needs;
[0247] w_sms: CAPTCHA receiving weight (recommended 0.4), which can be adjusted according to actual needs;
[0248] T_observation: Length of the observation time window, the duration of the first preset time period.
[0249] The formula for calculating the financial operation intensity g3 is as follows:
[0250] ;
[0251] The parameters in the formula have the following meanings:
[0252] N_financial_app_access: Number of times financial applications have been accessed;
[0253] T_observation: Observation time window;
[0254] App_diversity_risk: Application diversity risk coefficient N_different_bank_apps represents the number of different bank-related apps accessed.
[0255] The formula for calculating the information leakage behavior g4 is as follows:
[0256] ;
[0257] The parameters in the formula have the following meanings:
[0258] I_access(leak_risk_site): Whether to access websites with information leakage risks;
[0259] RiskLevel (site): Website risk level. You can set it to phishing website: 1.0, fake customer service: 0.9, information gathering site: 0.8. You can adjust it according to your actual needs.
[0260] The risky website collection includes phishing websites, fake customer service websites, and websites that collect personal information, which can be fuzzy matched based on URL features.
[0261] The formula for calculating the abnormal network behavior g5 is as follows:
[0262] ;
[0263] The parameters in the formula have the following meanings:
[0264] N_suspicious_connections: Number of suspicious network connections;
[0265] Connection_risk_score: Connection risk score;
[0266] T_observation: Observation time window.
[0267] Connections can be identified based on IP and port characteristics:
[0268] A malicious IP address is known to be connecting;
[0269] Remote connection using uncommon ports;
[0270] Connections to suspicious overseas servers;
[0271] Connections are frequently established / disconnected within a short period of time.
[0272] It should be noted that the main innovations of the number recognition method described in this embodiment of the invention are as follows:
[0273] 1. Cross-domain causal association analysis mechanism based on voice signaling and Internet signaling:
[0274] 1.1 This is the first technology to establish a temporal causal relationship between the caller's abnormal call characteristics and the callee's subsequent internet access behavior;
[0275] 1.2 Construct a causal chain verification model of "call event - abnormal behavior" to overcome the limitations of single data source analysis.
[0276] 2. Fraud pattern identification mechanism based on the consistency of group behavior:
[0277] 2.1 Enhance the confidence level of fraud identification by using a matrix of similar abnormal behaviors of multiple called users;
[0278] 2.2 Establish a group behavior coordination analysis algorithm to solve the problem of misjudgment of individual behavior.
[0279] 3. System architecture for real-time cross-domain detection and handling:
[0280] 3.1 Establish real-time association between voice signaling and Internet signaling. 3.2 Achieve technological breakthroughs from post-event identification to in-event detection and real-time intervention.
[0281] The core advantage of this invention lies in its cross-domain behavioral causal association analysis mechanism, achieving technological breakthroughs in three aspects: detection dimensions, identification timing, and evidence reliability. Its advantages include:
[0282] I. Multi-dimensional cross-domain correlation analysis, breaking through the limitations of a single data source:
[0283] Compared to analysis methods that rely solely on voice signaling or a single dimension, this invention pioneers a dynamic correlation between abnormal call characteristics of the caller and the subsequent internet behavior of the called party. By performing causal verification through abnormal call characteristics in voice signaling (such as short-term high-frequency calls and abnormal call duration) and operational behavior characteristics in internet signaling (such as bank transfers and downloads of sensitive applications), it solves the problem of the one-sidedness of analysis based on a single data source and significantly improves the detection coverage.
[0284] II. Consistency verification of group behavior significantly reduces false alarm rate:
[0285] Compared to traditional methods based on individual behavior analysis, this invention constructs a group behavior consistency verification mechanism by analyzing similar abnormal behavior patterns of multiple called users after a call. When multiple called parties contacted by the same caller exhibit similar abnormal operation sequences, the confidence level of fraud identification is greatly enhanced, reducing the false alarm rate from 15-20% in traditional methods to below 3%.
[0286] III. Real-time detection capability, enabling a breakthrough from post-event identification to in-event intervention:
[0287] Traditional methods often only identify fraud after it has been committed. This invention, however, establishes a real-time cross-domain data analysis pipeline that can identify risks and intervene during the fraud process. This technological shift from post-incident tracing to in-process prevention effectively avoids financial losses for users and moves the anti-fraud defense line forward.
[0288] This invention is based entirely on existing signaling data from operators, requiring no additional hardware. It protects user privacy and is practical for rapid deployment, providing core technical support for building a new generation of proactive anti-fraud systems.
[0289] like Figure 2 As shown, to achieve the above objectives, embodiments of the present invention provide a number recognition device, comprising:
[0290] The first acquisition module 201 is used to acquire at least one target number with a call score exceeding a first threshold from multiple calling numbers based on voice signaling data; wherein the call score is acquired based on the call characteristics of the calling number;
[0291] The second acquisition module 202 is used to analyze the internet access behavior of multiple called users corresponding to each target number within a first preset time period based on internet access signaling data, and to acquire the abnormal behavior characteristics of the called users.
[0292] The third acquisition module 203 is used to acquire the causal strength value of the target number based on the abnormal behavior characteristics corresponding to each target number;
[0293] The first processing module 204 is configured to identify a first type of number among the at least one target number based on the call score and the causal strength value; wherein the first type of number is the target number whose risk assessment probability is greater than a second threshold and whose risk assessment confidence is greater than a third threshold; the risk assessment probability is obtained based on the call score and the causal strength value; the risk assessment confidence is obtained based on the call score and the causal strength value.
[0294] Optionally, in the aforementioned apparatus, the third acquisition module 203 includes:
[0295] The first acquisition unit is used to acquire behavior similarity based on the abnormal behavior characteristics of the multiple called users corresponding to the target number;
[0296] The second acquisition unit is used to acquire a behavior similarity matrix based on the behavior similarity corresponding to the target number; wherein each element in the similarity matrix represents the behavior similarity between any two of the multiple called users;
[0297] The third acquisition unit is used to acquire a group consistency score based on the behavior similarity matrix and the number of called users corresponding to the target number;
[0298] The fourth acquisition unit is used to acquire the causal strength value based on the group consistency score.
[0299] Optionally, the device further includes:
[0300] The fourth acquisition module is used to acquire a temporal correlation strength value based on the time interval between the abnormal behavior of the called user corresponding to the target number and the target call; wherein, the abnormal behavior is the behavior corresponding to the abnormal behavior feature; and the target call is the call between the called user and the target number;
[0301] The fifth acquisition module is used to acquire the abnormal behavior improvement degree based on the abnormal behavior score of the abnormal behavior and the pre-acquired normal behavior score;
[0302] The fourth acquisition unit includes:
[0303] The first acquisition component is used to acquire the causal strength value based on the group consistency score, the temporal correlation strength value, and the behavioral anomaly boosting degree.
[0304] Optionally, in the aforementioned apparatus, the first processing module 204 includes:
[0305] The fifth acquisition unit is used to acquire the risk assessment probability based on the call score and the causal strength value;
[0306] The sixth acquisition unit is used to acquire the risk assessment confidence level based on the difference between the call score and the causal strength value;
[0307] The first determining unit is used to determine that the target number whose risk assessment probability is greater than the second threshold and whose risk assessment confidence level is greater than the third threshold is the first type of number.
[0308] Optionally, in the aforementioned apparatus, the fifth acquiring unit comprises:
[0309] The second acquisition component is used to acquire a first value based on the call score and a preset call score weight;
[0310] The third acquisition component is used to acquire a second value based on the causal strength value and a preset causal strength value weight;
[0311] The fourth acquisition component is used to acquire the risk assessment probability based on the first value and the second value.
[0312] Optionally, in the apparatus, the first acquisition module 201 includes:
[0313] The seventh acquisition unit is used to acquire the call characteristics of the plurality of calling numbers based on the voice signaling data;
[0314] The eighth acquisition unit is used to acquire the call score of the calling number based on the difference between the call characteristics of each calling number and the fourth threshold corresponding to the call characteristics;
[0315] The second determining unit is used to determine the calling number whose call score exceeds the first threshold as the target number.
[0316] Optionally, in the device, the call features include at least one of the following:
[0317] Call frequency characteristics, wherein the call frequency characteristics are obtained based on the number of calls made by the calling number within a second preset time period and the corresponding called party dispersion; the called party dispersion is the degree of dispersion of the called party numbers;
[0318] The call duration distribution characteristics are obtained based on the proportion of short calls and the degree of fluctuation in call duration; the proportion of short calls is the ratio of the number of short calls to the total number of calls; short calls are those with a duration less than a fifth threshold; and the degree of fluctuation in call duration is obtained based on the standard deviation and mean of the call duration.
[0319] Spatiotemporal anomaly features, wherein the spatiotemporal anomaly features are obtained based on the standard deviation and mean of the number of calls made by the calling number to the corresponding base station;
[0320] The called number discrete feature is obtained based on the calling probability of the called number corresponding to the calling number;
[0321] Call time distribution characteristics, wherein the call time distribution characteristics are obtained based on the number of calls made by the calling number within a unit time period and the preset expected number of calls;
[0322] The call failure rate feature is based on the number of failed calls and the number of short-term failed calls of the calling number; the short-term failed calls are calls with a duration less than a sixth threshold; the sixth threshold is less than the fifth threshold.
[0323] Optionally, in the device, the abnormal behavior characteristic includes at least one of the following:
[0324] High-risk application access behavior, wherein the high-risk application access behavior is obtained based on the number of times the called user accesses a preset high-risk application within the first preset time period;
[0325] Sensitive operational behaviors, wherein the sensitive operational behaviors are obtained based on the called user's download behavior of abnormal software and acceptance of verification code SMS messages within the first preset time period;
[0326] Financial operations, wherein the financial operations are obtained based on the number of times the called user accesses financial applications within the first preset time period;
[0327] Information leakage behavior, wherein the information leakage behavior is obtained based on the website risk level corresponding to the preset risk website visited by the called user within the first preset time period;
[0328] Abnormal network behavior, wherein the abnormal network behavior is obtained based on the number of times the called user connects to a preset suspicious network within the first preset time period.
[0329] It should be noted that the apparatus provided in this embodiment of the invention can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0330] This application also provides a number recognition device, such as... Figure 3 As shown, it includes:
[0331] The processor 301, memory 302, transceiver 303, and a program or instructions stored in the memory 302 and executable on the processor 301; when the processor 301 executes the program or instructions, it implements the various processes of the above-described number recognition method embodiments and achieves the same technical effect. To avoid repetition, these will not be described again here.
[0332] The transceiver 303 is used to receive and send data under the control of the processor 301.
[0333] Among them, Figure 3 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 301 and memory represented by memory 302 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 303 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, the user interface 304 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0334] The processor 301 is responsible for managing the bus architecture and general processing, while the memory 302 can store the data used by the processor 301 when performing operations.
[0335] To achieve the above objectives, embodiments of the present invention provide a readable storage medium having a program or instructions stored thereon, wherein the program or instructions, when executed by a processor, implement the steps in the number identification method described above.
[0336] To achieve the above objectives, embodiments of the present invention provide a computer program product, which includes computer instructions that, when executed by a processor, implement the steps of the number recognition method described above.
[0337] It should be further noted that the terminals described in this specification include, but are not limited to, smartphones, tablets, etc., and many of the functional components described are referred to as modules in order to emphasize the independence of their implementation.
[0338] In this embodiment of the invention, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0339] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0340] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0341] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of the invention. Therefore, the invention should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make the invention complete and convey the scope of the invention to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0342] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A number recognition method, characterized in that, include: Based on voice signaling data, at least one target number with a call score exceeding a first threshold is obtained from multiple calling numbers; wherein, the call score is obtained based on the call characteristics of the calling number; Based on the Internet access signaling data, the Internet access behavior of multiple called users corresponding to each target number is analyzed within a first preset time period to obtain the abnormal behavior characteristics of the called users. Based on the abnormal behavior characteristics corresponding to each target number, obtain the causal strength value of the target number; A first type of number is identified from the at least one target number based on the call score and the causal strength value; wherein, the first type of number is the target number whose risk assessment probability is greater than a second threshold and whose risk assessment confidence is greater than a third threshold; the risk assessment probability is obtained based on the call score and the causal strength value; the risk assessment confidence is obtained based on the call score and the causal strength value; The step of obtaining the causal strength value of each target number based on the abnormal behavior characteristics corresponding to each target number includes: Based on the abnormal behavior characteristics of the multiple called users corresponding to the target number, obtain the behavior similarity. A behavior similarity matrix is obtained based on the behavior similarity corresponding to the target number; wherein each element in the similarity matrix represents the behavior similarity between any two of the multiple called users; Based on the behavioral similarity matrix and the number of called users corresponding to the target number, a group consistency score is obtained; The causal strength value is obtained based on the group consistency score; Before obtaining the causal strength value based on the group consistency score, the method further includes: A temporal correlation strength value is obtained based on the time interval between the abnormal behavior of the called user corresponding to the target number and the target call; wherein, the abnormal behavior is the behavior corresponding to the abnormal behavior feature; and the target call is the call between the called user and the target number. The abnormal behavior score and the pre-acquired normal behavior score are used to obtain the abnormal behavior improvement degree. Wherein, obtaining the causal strength value based on the group consistency score includes: The causal strength value is obtained based on the group consistency score, the temporal correlation strength value, and the behavioral anomaly boosting degree.
2. The method according to claim 1, characterized in that, Identifying a first type of number among the at least one target number based on the call score and the causality strength value includes: The risk assessment probability is obtained based on the call score and the causal strength value; The risk assessment confidence level is obtained based on the difference between the call score and the causal strength value. The target number is determined to be of the first type if the risk assessment probability is greater than the second threshold and the risk assessment confidence level is greater than the third threshold.
3. The method according to claim 1, characterized in that, The risk assessment probability is obtained based on the call score and the causal strength value, including: Based on the call score and the preset call score weight, obtain the first value; The second value is obtained based on the causal strength value and the preset causal strength value weight; The risk assessment probability is obtained based on the first value and the second value.
4. The method according to claim 1, characterized in that, Based on voice signaling data, at least one target number among multiple calling numbers whose call score exceeds a first threshold is identified, including: Based on the voice signaling data, obtain the call characteristics of the multiple calling numbers; The call score of each calling number is obtained based on the difference between the call characteristics of each calling number and the fourth threshold corresponding to the call characteristics. The calling number whose call score exceeds the first threshold is identified as the target number.
5. The method according to claim 1, characterized in that, The call features include at least one of the following: Call frequency characteristics, wherein the call frequency characteristics are obtained based on the number of calls made by the calling number within a second preset time period and the corresponding called party dispersion; the called party dispersion is the degree of dispersion of the called party numbers; The call duration distribution characteristics are obtained based on the proportion of short calls and the degree of fluctuation in call duration; the proportion of short calls is the ratio of the number of short calls to the total number of calls; short calls are those with a duration less than a fifth threshold; and the degree of fluctuation in call duration is obtained based on the standard deviation and mean of the call duration. Spatiotemporal anomaly features, wherein the spatiotemporal anomaly features are obtained based on the standard deviation and mean of the number of calls made by the calling number to the corresponding base station; The called number discrete feature is obtained based on the calling probability of the called number corresponding to the calling number; Call time distribution characteristics, wherein the call time distribution characteristics are obtained based on the number of calls made by the calling number within a unit time period and the preset expected number of calls; The call failure rate feature is based on the number of failed calls and the number of short-term failed calls of the calling number; the short-term failed calls are calls with a duration less than a sixth threshold; the sixth threshold is less than the fifth threshold.
6. The method according to claim 1, characterized in that, The abnormal behavior characteristics include at least one of the following: High-risk application access behavior, wherein the high-risk application access behavior is obtained based on the number of times the called user accesses a preset high-risk application within the first preset time period; Sensitive operational behaviors, wherein the sensitive operational behaviors are obtained based on the called user's download behavior of abnormal software and acceptance of verification code SMS messages within the first preset time period; Financial operations, wherein the financial operations are obtained based on the number of times the called user accesses financial applications within the first preset time period; Information leakage behavior, wherein the information leakage behavior is obtained based on the website risk level corresponding to the preset risk website visited by the called user within the first preset time period; Abnormal network behavior, wherein the abnormal network behavior is obtained based on the number of times the called user connects to a preset suspicious network within the first preset time period.
7. A number recognition device, characterized in that, include: The first acquisition module is used to acquire at least one target number whose call score exceeds a first threshold from multiple calling numbers based on voice signaling data; wherein the call score is acquired based on the call characteristics of the calling number; The second acquisition module is used to analyze the internet access behavior of multiple called users corresponding to each target number within a first preset time period based on internet access signaling data, and to acquire the abnormal behavior characteristics of the called users. The third acquisition module is used to acquire the causal strength value of the target number based on the abnormal behavior characteristics corresponding to each target number; A first processing module is configured to identify a first type of number among the at least one target number based on the call score and the causal strength value; wherein the first type of number is a target number whose risk assessment probability is greater than a second threshold and whose risk assessment confidence is greater than a third threshold; the risk assessment probability is obtained based on the call score and the causal strength value; the risk assessment confidence is obtained based on the call score and the causal strength value. The third acquisition module includes: The first acquisition unit is used to acquire behavior similarity based on the abnormal behavior characteristics of the multiple called users corresponding to the target number; The second acquisition unit is used to acquire a behavior similarity matrix based on the behavior similarity corresponding to the target number; wherein each element in the similarity matrix represents the behavior similarity between any two of the multiple called users; The third acquisition unit is used to acquire a group consistency score based on the behavior similarity matrix and the number of called users corresponding to the target number; The fourth acquisition unit is used to acquire the causal strength value based on the group consistency score.
8. A number recognition device, comprising: A processor, a memory, a transceiver, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the number identification method as described in any one of claims 1-6.
9. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps in the number identification method as described in any one of claims 1-6.
10. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the number identification method as described in any one of claims 1-6.