GOIP fraud recognition method and recognition system

By monitoring home broadband data and analyzing base station data, screening cross-border call records, and marking suspected fraud dens and victim numbers, the problem of difficulty in identifying simple GOIP fraud in existing technologies has been solved, achieving efficient identification and tracing.

CN121908276APending Publication Date: 2026-04-21XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XINYANG BRANCH HENAN CO LTD OF CHINA MOBILE COMM CORP
Filing Date
2025-12-30
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies are insufficient to effectively identify telecommunications fraud perpetrated using simple GOIP devices, especially when fraudsters employ unprofessional hardware and simplistic methods, making it difficult for conventional models and methods to identify and trace the fraudulent activities.

Method used

By monitoring home broadband data, filtering cross-border call records, obtaining home broadband installation addresses and coverage base station information, and combining this with abnormal outbound call behavior under the base station, it is possible to mark suspected fraud dens and victim numbers.

Benefits of technology

It improves the accuracy of identifying simple GOIP scams, provides clear technical clues and evidence, expands the scope of prevention and control, lowers the identification threshold, and enhances the efficiency of tracing the source.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121908276A_ABST
    Figure CN121908276A_ABST
Patent Text Reader

Abstract

The invention discloses a GOIP fraud identification method and system, and the method comprises the steps: monitoring the Internet data of a household broadband, and screening out a first voice call record from the Internet data of the household broadband; acquiring a first user account and a first user mobile phone number corresponding to the first voice call record; acquiring a first home width address corresponding to the first user account; obtaining a target base station covering the first home width address; and monitoring a voice call record under the target base station, and judging and marking a suspected fraud site, a suspected fraud call and a suspected victim number. Based on the GOIP fraud identification method, the GOIP identification accuracy is improved, and the traceability strike effectiveness is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of GOIP fraud identification technology, and in particular to a GOIP fraud identification method and system. Background Technology

[0002] As the "Cut Off SIM Cards" campaign continues and public awareness of fraud prevention increases, calls from overseas have raised widespread vigilance. However, fraudsters have not stopped there; instead, they have leveraged technological upgrades to use more covert new GOIP devices on top of VoIP to carry out telecommunications fraud.

[0003] GOIP (GSM Over Internet Protocol) is a network communication device that supports SIM card access and converts traditional telephone signals into network signals, enabling virtual dialing globally. Fraudsters set up GOIP devices domestically and remotely control them from abroad to make calls and send / receive text messages, separating the person from the SIM card to conceal their identity and evade detection. This method is gradually becoming a new tactic for fraudsters.

[0004] A simple GOIP pattern is as follows Figure 1 As shown, overseas mobile phone 1 establishes a voice call with domestic mobile phone 2 via voice calling apps such as QQ / WeChat, and sends the victim's number to domestic mobile phone 2 through certain software (such as Batman, Secret Chat, etc.). After domestic mobile phone 2 answers the voice call and receives the victim's number, it calls the victim's number through another domestic SIM card (domestic mobile phone 3). Domestic mobile phone 2 and domestic mobile phone 3 maintain a connection via audio cable / speaker, so that after the call is connected, overseas mobile phone 1 can directly talk to the victim.

[0005] Conventional signaling retrospective analysis typically only analyzes signaling data from a single voice call system or internet data, lacking correlation with the temporal and spatial dimensions of fraud. Furthermore, existing GOIP fraud detection technologies primarily target fraudulent activities using professional GOIP hardware. Once fraudsters employ simpler, non-GOIP devices, conventional models and methods often fail to effectively identify them, leading to decreased detection accuracy and difficulty in tracing and locating specific criminals and their hideouts. Summary of the Invention

[0006] The purpose of this invention is to provide a GOIP fraud identification method and system that can improve identification accuracy by associating fraud with time and space dimensions, and to achieve simple network fraud identification.

[0007] To achieve the above objectives, this invention discloses a GOIP fraud identification method, comprising: Monitor home broadband internet access data, and filter out voice call records from the home broadband internet access data whose service type matches cross-border calls and whose single call duration exceeds a preset first duration threshold, and mark them as the first voice call record; Obtain the home broadband user account and user mobile phone number corresponding to the first voice call record, and mark them as the first user account and first user mobile phone number; Obtain the installation address of the home broadband corresponding to the first user account and mark it as the first home broadband address; Obtain information about the base station covering the first wide address and mark that base station as the target base station; By monitoring voice call records under the target base station, if within the same time period, the call time of a certain voice call record overlaps with the call time of the first voice call record, and under the target base station, the number of outgoing calls by a certain user's mobile phone number exceeds a preset outgoing call frequency threshold within a unit of time, then the user's mobile phone number is marked as the second user's mobile phone number, the first address is marked as a suspected fraud den, the first user's mobile phone number and the second user's mobile phone number are marked as suspected fraudulent calls, and the called mobile phone number dialed with the second user's mobile phone number is marked as a suspected victim's number. Specifically, the steps for obtaining the first voice call record include: Real-time monitoring of data streams at the home broadband network egress point; filtering out several voice data streams whose source IP and destination IP are located domestically and internationally respectively, and whose service type is based on Internet instant messaging protocol. The signaling log data and user plane data of each of the voice data streams are extracted to generate several voice call records, and the voice call records whose call duration exceeds the first duration threshold are marked as the first voice call record.

[0008] Specifically, the steps for obtaining the installation address of the home broadband corresponding to the first user account include: Based on the first user account, by querying the 3A authentication system of the home broadband operator corresponding to the first user account, the user installation information corresponding to the first user account is obtained. The user installation information includes at least the installation address of the home broadband corresponding to the first user account, and the installation address of the home broadband corresponding to the first user account includes the latitude and longitude coordinates of the home broadband.

[0009] Furthermore, the specific steps for obtaining base station information covering the first wide address include: The wireless network optimization system is queried, and the latitude and longitude coordinates of the home broadband corresponding to the first user account are matched with the coverage area information of the base station to obtain information on one or more base stations covering the latitude and longitude coordinates.

[0010] This invention also discloses a GOIP fraud identification system, the GOIP fraud identification system comprising: The home broadband monitoring and filtering unit is used to monitor the internet access data of home broadband and filter out voice call records from the internet access data of home broadband that have a service type that meets the requirements of cross-border calls and a single call duration that exceeds a preset first duration threshold, and mark them as the first voice call record. A home broadband user information acquisition unit is used to acquire the home broadband user account and user mobile phone number corresponding to the first voice call record, and to mark the home broadband user account and user mobile phone number corresponding to the first voice call record as the first user account and the first user mobile phone number. A home broadband address acquisition unit is used to acquire the installation address of the home broadband corresponding to the first user account, and mark the installation address of the home broadband corresponding to the first user account as the first home broadband address. The target base station acquisition unit is used to acquire base station information covering the first wide address and mark the acquired base station as the target base station; The base station monitoring and analysis unit is used to monitor voice call records under the target base station. When, within the same time period, the call time of a certain voice call record overlaps with the call time of the first voice call record, and under the target base station, the number of outgoing calls by a certain user's mobile phone number within a unit of time exceeds a preset outgoing call frequency threshold, the user's mobile phone number is marked as the second user's mobile phone number, the first address is marked as a suspected fraud den, the first user's mobile phone number and the second user's mobile phone number are marked as suspected fraudulent calls, and the called mobile phone number dialed with the second user's mobile phone number is marked as a suspected victim number.

[0011] Specifically, the home broadband monitoring and filtering unit obtains the first voice call record based on the following steps: Real-time monitoring of data streams at the home broadband network egress point; filtering out several voice data streams whose source IP and destination IP are located domestically and internationally respectively, and whose service type is based on Internet instant messaging protocol. The signaling log data and user plane data of each of the voice data streams are extracted to generate several voice call records, and the voice call records whose call duration exceeds the first duration threshold are marked as the first voice call record.

[0012] Specifically, the home broadband address acquisition unit obtains the installation address of the home broadband corresponding to the first user account based on the following steps: Based on the first user account, by querying the 3A authentication system of the home broadband operator corresponding to the first user account, the user installation information corresponding to the first user account is obtained. The user installation information includes at least the installation address of the home broadband corresponding to the first user account, and the installation address of the home broadband corresponding to the first user account includes the latitude and longitude coordinates of the home broadband.

[0013] Furthermore, the target base station acquisition unit acquires base station information covering the first wide address based on the following steps: The wireless network optimization system is queried, and the latitude and longitude coordinates of the home broadband corresponding to the first user account are matched with the coverage area information of the base station to obtain information on one or more base stations covering the latitude and longitude coordinates.

[0014] This invention also discloses a GOIP fraud identification system, which includes: One or more processors; Memory; And one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the programs including instructions for performing the GOIP fraud identification method as described above.

[0015] The present invention also discloses a computer-readable storage medium comprising a computer program that can be executed by a processor to perform the GOIP fraud identification method as described above.

[0016] Compared with existing technologies, the GOIP fraud identification method provided by the above-mentioned technical solution of this invention, based on the characteristics that GOIP fraud methods are mostly home broadband access and domestic mobile phone physical addresses are basically consistent and relatively fixed in location, spatiotemporally correlates home broadband Internet access data with base stations, which can locate virtual Internet access data to specific physical addresses, improve the accuracy of identification, and provide clear technical clues and evidence support for combating fraud. In addition, by locking onto abnormal high-frequency outgoing call behavior that occurs simultaneously with cross-border long-distance calls under specific base stations, it can accurately capture the abnormal activities of criminals using home network environments to set up simple GOIP devices, thereby improving the ability to identify this type of simple fraud. Attached Figure Description

[0017] Figure 1 This is a schematic diagram illustrating the working principle of existing GOIP in the background art of this invention.

[0018] Figure 2 This is a flowchart of the GOIP fraud identification method in an embodiment of the present invention.

[0019] Figure 3This is a flowchart of a GOIP fraud identification method in another embodiment of the present invention.

[0020] Figure 4 This is a schematic diagram of the system architecture of the GOIP fraud identification system in an embodiment of the present invention. Detailed Implementation

[0021] To illustrate the technical content, structural features, objectives, and effects of this invention in detail, the following description, in conjunction with the embodiments and accompanying drawings, provides a comprehensive explanation. The embodiments described herein are merely illustrative of the technical solutions of this application and are therefore intended to be exemplary and should not be construed as limiting the scope of protection of this application.

[0022] This invention discloses a method for identifying GOIP fraud, enabling accurate identification of GOIP fraud based on spatiotemporal correlation and simple network-based fraud. See also... Figure 2 and Figure 4 As shown, this GOIP fraud identification method specifically includes the following steps: S1: Monitor home broadband internet access data and filter out voice call records from the home broadband internet access data that have a service type that matches cross-border calls and a single call duration that exceeds a preset first duration threshold, and mark them as the first voice call record. In this embodiment, the first duration threshold can be adaptively set and adjusted based on the type of internet access data being monitored, the actual characteristics of fraudulent behavior, historical fraud call data, and call service response time, etc., without specific limitations.

[0023] S2: Obtain the home broadband user account and user mobile phone number corresponding to the first voice call record, and mark them as the first user account and first user mobile phone number.

[0024] S3: Obtain the installation address of the home broadband corresponding to the first user account and mark it as the first home broadband address.

[0025] S4: Obtain information about the base station covering the first wide address and mark the base station as the target base station.

[0026] S5: Monitor voice call records under the target base station.

[0027] S6: Determine whether, within the same time period, the call time of a certain voice call record overlaps with the call time of the first voice call record, and whether, under the target base station, the number of calls made by a certain user's mobile phone number within a unit time exceeds a preset call frequency threshold. If yes, proceed to step S7; otherwise, return to step S1. In this embodiment, the preset call frequency threshold can be adaptively set and adjusted based on fraud history call data and call service response timeliness, without specific limitations.

[0028] S7: Mark the user's mobile phone number as the second user's mobile phone number, the first address as a suspected fraud den, the first user's mobile phone number and the second user's mobile phone number as suspected fraudulent calls, and the called mobile phone number to the second user's mobile phone number as a suspected victim's number.

[0029] Compared with existing technologies, the GOIP fraud identification method provided by this invention is advanced and targeted. Its core advantage lies in achieving effective "spatiotemporal correlation" and accurate "simple network fraud identification".

[0030] Regarding "spatiotemporal correlation," conventional signaling retrospective analysis typically only analyzes signaling data from single voice call systems or internet data, lacking correlation with the temporal and spatial dimensions of fraud. This invention, based on the characteristics of GOIP fraud—that it often involves home broadband access and that the broadband access point and the perpetrator's device are usually geographically consistent and fixed—correlates home broadband data with call records from base stations covering that home broadband connection. By pinpointing the home broadband installation address, it successfully anchors virtual, anonymous network behavior to a specific physical address (i.e., the home broadband installation address), achieving spatial location of suspected fraud dens and providing physical investigative clues for case investigation.

[0031] In the area of ​​"simple network fraud identification," existing models struggle to effectively detect fraud perpetrated using non-professional hardware and solely through ordinary mobile phones and home networks. This invention, by establishing a composite judgment rule of "overlapping with cross-border long-duration calls" and "abnormally high-frequency calls under base stations," can accurately capture the typical behavioral characteristics of such simple network setups. This method not only enhances the ability to detect fraud using low-threshold technologies such as audio cables and software calls but also lowers the identification threshold that relies on professional GOIP hardware, thereby expanding the scope of prevention and control and addressing the core shortcomings of traditional technologies.

[0032] In summary, this invention significantly improves identification accuracy and tracing efficiency through spatiotemporal data fusion and behavioral modeling, providing a practical solution for combating the ever-evolving technology-based telecommunications fraud.

[0033] Specifically, see Figure 3 and Figure 4 As shown, in another embodiment, the specific steps (S1) for obtaining the first voice call record include: S11: Real-time monitoring of data streams at the home broadband network exit, filtering out several voice data streams whose source IP and destination IP are located domestically and internationally respectively, and whose service type is based on the Internet instant messaging protocol.

[0034] S12: Extract signaling log data and user plane data from each voice data stream to generate several voice call records, and mark the voice call records whose call duration exceeds the first duration threshold as the first voice call record.

[0035] The signaling log data includes interactive services (voice calls), source IP, destination IP, interaction duration (call duration), and specific start and end times of the interaction (i.e., the start and end times of the voice call, i.e., the call duration). The user plane data includes the user account and mobile phone number of the home broadband.

[0036] Specifically, see Figures 3 to 4 As shown, in another embodiment, the specific step (S3) of obtaining the installation address of the home broadband corresponding to the first user account includes: S31: Based on the first user account, by querying the 3A authentication system of the home broadband operator corresponding to the first user account, obtain the user installation information corresponding to the first user account, thereby obtaining the installation address of the home broadband corresponding to the first user account.

[0037] It should be noted that the user installation information includes at least the installation address of the home broadband corresponding to the first user account, and this installation address includes the latitude and longitude coordinates of the home broadband. Furthermore, by linking the latitude and longitude coordinates of the home broadband, a latitude and longitude database can be established to identify and monitor areas suspected of being high-risk for fraud.

[0038] Furthermore, step S4 specifically includes: S41: Query the wireless network optimization system, match the latitude and longitude coordinates of the home broadband corresponding to the first user account with the coverage area information of the base station, so as to obtain the information of one or more base stations covering the latitude and longitude coordinates, and mark the one or more base stations covering the latitude and longitude coordinates as the target base station.

[0039] It should be noted that, for reference Figure 1 As shown, considering that in a specific GOIP fraud scenario, domestic mobile phone 2 and domestic mobile phone 3 will maintain a connection through an audio cable / speaker, and after the call is connected, the overseas mobile phone 1 can talk directly with the victim. The physical locations of domestic mobile phone 2 and domestic mobile phone 3 must be basically consistent and relatively fixed. Based on this physical location characteristic, domestic mobile phone 2 and domestic mobile phone 3 are often under the same base station or the same WIFI. Therefore, this proposal can obtain the approximate physical location characteristics of domestic mobile phone 3 (under the target base station) based on the location of domestic mobile phone 2 (the installation address of home broadband).

[0040] This invention also discloses a GOIP fraud identification system, see reference. Figure 4 As shown, it includes: The home broadband monitoring and filtering unit is used to monitor home broadband internet access data and filter out voice call records from the home broadband internet access data that have a service type that meets the requirements of cross-border calls and a single call duration that exceeds a preset first duration threshold, and mark them as the first voice call record.

[0041] The home broadband user information acquisition unit is used to acquire the home broadband user account and user mobile phone number corresponding to the first voice call record, and to mark the home broadband user account and user mobile phone number corresponding to the first voice call record as the first user account and the first user mobile phone number.

[0042] The home broadband address acquisition unit is used to acquire the installation address of the home broadband corresponding to the first user account, and mark the installation address of the home broadband corresponding to the first user account as the first home broadband address.

[0043] The target base station acquisition unit is used to acquire base station information covering the first wide address and mark the acquired base station as the target base station.

[0044] The base station monitoring and analysis unit is used to monitor voice call records under the target base station. When the call time of a certain voice call record overlaps with the call time of the first voice call record within the same time period, and the number of outgoing calls made by a certain user's mobile phone number under the target base station exceeds a preset outgoing call frequency threshold within a unit of time, the unit marks the user's mobile phone number as the second user's mobile phone number, the first address as a suspected fraud den, the first user's mobile phone number and the second user's mobile phone number as suspected fraudulent calls, and the called mobile phone number of the second user's mobile phone number as a suspected victim number.

[0045] Specifically, the home broadband monitoring and filtering unit obtains the first voice call record based on the following steps: Real-time monitoring of data streams at the exit of home broadband networks is conducted to identify several voice data streams whose source IP and destination IP are located domestically and internationally, respectively, and whose service type is based on Internet instant messaging protocols.

[0046] Extract signaling log data and user plane data from each voice data stream to generate several voice call records, and mark the voice call record whose call duration exceeds a first duration threshold as the first voice call record.

[0047] Specifically, the home broadband address acquisition unit obtains the installation address of the home broadband corresponding to the first user account based on the following steps: Based on the first user account, the user installation information corresponding to the first user account is obtained by querying the 3A authentication system of the home broadband operator corresponding to the first user account. The user installation information includes at least the installation address of the home broadband corresponding to the first user account, and the installation address of the home broadband corresponding to the first user account includes the latitude and longitude coordinates of the home broadband.

[0048] Furthermore, the target base station acquisition unit obtains base station information covering the first wide address based on the following steps: The wireless network optimization system is queried to match the latitude and longitude coordinates of the home broadband corresponding to the first user account with the coverage area information of the base station to obtain information on one or more base stations covering the latitude and longitude coordinates.

[0049] It should also be noted that the working principle and operation method of the fraud identification system in this embodiment are detailed in the above fraud identification method, and will not be repeated here.

[0050] This invention also discloses another GOIP fraud detection system, which includes one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors. The programs include instructions for performing the GOIP fraud detection method as described above. The processor may be a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, used to execute the relevant programs to implement the functions required by the modules in the GOIP fraud detection system of this application embodiment, or to execute the GOIP fraud detection method of this application method embodiment.

[0051] This invention also discloses a computer-readable storage medium comprising a computer program executable by a processor to perform the GOIP fraud identification method described above. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center integrating one or more available media. The available medium can be read-only memory (ROM), random access memory (RAM), or magnetic media, such as floppy disks, hard disks, magnetic tapes, magnetic disks, or optical media, such as digital versatile discs (DVDs), or semiconductor media, such as solid-state disks (SSDs).

[0052] The above-disclosed embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of the invention. Although the embodiments have been described in the description and drawings of this application, this does not limit the scope of patent protection of this application. Any technical solutions resulting from equivalent structural or procedural substitutions or modifications made based on the essential concept of this application and utilizing the content described in the description and drawings of this application, as well as the direct or indirect application of the technical solutions of the above embodiments to other related technical fields, are all included within the scope of patent protection of this application.

Claims

1. A method for identifying GOIP fraud, characterized in that, include: Monitor home broadband internet access data, and filter out voice call records from the home broadband internet access data whose service type matches cross-border calls and whose single call duration exceeds a preset first duration threshold, and mark them as the first voice call record; Obtain the home broadband user account and user mobile phone number corresponding to the first voice call record, and mark them as the first user account and first user mobile phone number; Obtain the installation address of the home broadband corresponding to the first user account and mark it as the first home broadband address; Obtain information about the base station covering the first wide address and mark that base station as the target base station; If, during the same time period, the call duration of a certain voice call overlaps with that of the first voice call, and under the target base station, the number of outgoing calls made by a certain user's mobile phone number within a unit of time exceeds a preset outgoing call frequency threshold, then the user's mobile phone number is marked as the second user's mobile phone number, the first address is marked as a suspected fraud den, the first user's mobile phone number and the second user's mobile phone number are marked as suspected fraudulent calls, and the called mobile phone number dialed from the second user's mobile phone number is marked as a suspected victim's number.

2. The GOIP fraud identification method according to claim 1, characterized in that, The specific steps for obtaining the first voice call record include: Real-time monitoring of data streams at the home broadband network egress point; filtering out several voice data streams whose source IP and destination IP are located domestically and internationally respectively, and whose service type is based on Internet instant messaging protocol. The signaling log data and user plane data of each of the voice data streams are extracted to generate several voice call records, and the voice call records whose call duration exceeds the first duration threshold are marked as the first voice call record.

3. The GOIP fraud identification method according to claim 1, characterized in that, The specific steps for obtaining the installation address of the home broadband corresponding to the first user account include: Based on the first user account, by querying the 3A authentication system of the home broadband operator corresponding to the first user account, the user installation information corresponding to the first user account is obtained. The user installation information includes at least the installation address of the home broadband corresponding to the first user account, and the installation address of the home broadband corresponding to the first user account includes the latitude and longitude coordinates of the home broadband.

4. The GOIP fraud identification method according to claim 3, characterized in that, The specific steps for obtaining base station information covering the first wide address include: The wireless network optimization system is queried, and the latitude and longitude coordinates of the home broadband corresponding to the first user account are matched with the coverage area information of the base station to obtain information on one or more base stations covering the latitude and longitude coordinates.

5. A GOIP fraud identification system, characterized in that, include: The home broadband monitoring and filtering unit is used to monitor the internet access data of home broadband and filter out voice call records from the internet access data of home broadband that have a service type that meets the requirements of cross-border calls and a single call duration that exceeds a preset first duration threshold, and mark them as the first voice call record. A home broadband user information acquisition unit is used to acquire the home broadband user account and user mobile phone number corresponding to the first voice call record, and to mark the home broadband user account and user mobile phone number corresponding to the first voice call record as the first user account and the first user mobile phone number. A home broadband address acquisition unit is used to acquire the installation address of the home broadband corresponding to the first user account, and mark the installation address of the home broadband corresponding to the first user account as the first home broadband address. The target base station acquisition unit is used to acquire base station information covering the first wide address and mark the acquired base station as the target base station; The base station monitoring and analysis unit is used to monitor voice call records under the target base station. When, within the same time period, the call time of a certain voice call record overlaps with the call time of the first voice call record, and under the target base station, the number of outgoing calls by a certain user's mobile phone number within a unit of time exceeds a preset outgoing call frequency threshold, the user's mobile phone number is marked as the second user's mobile phone number, the first address is marked as a suspected fraud den, the first user's mobile phone number and the second user's mobile phone number are marked as suspected fraudulent calls, and the called mobile phone number dialed with the second user's mobile phone number is marked as a suspected victim number.

6. The GOIP fraud identification system according to claim 5, characterized in that, The home broadband monitoring and filtering unit obtains the first voice call record based on the following steps: Real-time monitoring of data streams at the home broadband network egress point; filtering out several voice data streams whose source IP and destination IP are located domestically and internationally respectively, and whose service type is based on Internet instant messaging protocol. The signaling log data and user plane data of each of the voice data streams are extracted to generate several voice call records, and the voice call records whose call duration exceeds the first duration threshold are marked as the first voice call record.

7. The GOIP fraud identification system according to claim 5, characterized in that, The home broadband address acquisition unit obtains the installation address of the home broadband corresponding to the first user account based on the following steps: Based on the first user account, by querying the 3A authentication system of the home broadband operator corresponding to the first user account, the user installation information corresponding to the first user account is obtained. The user installation information includes at least the installation address of the home broadband corresponding to the first user account, and the installation address of the home broadband corresponding to the first user account includes the latitude and longitude coordinates of the home broadband.

8. The GOIP fraud identification system according to claim 7, characterized in that, The target base station acquisition unit acquires base station information covering the first wide address based on the following steps: The wireless network optimization system is queried, and the latitude and longitude coordinates of the home broadband corresponding to the first user account are matched with the coverage area information of the base station to obtain information on one or more base stations covering the latitude and longitude coordinates.

9. A GOIP fraud identification system, characterized in that, include: One or more processors; Memory; And one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, the programs including instructions for performing the GOIP fraud identification method as claimed in any one of claims 1 to 4.

10. A computer-readable storage medium, characterized in that, Includes a computer program that can be executed by a processor to perform the GOIP fraud identification method as described in any one of claims 1 to 4.