Telecommunication abnormal behavior identification method and device based on network action accompanying call

By constructing a network graph of communication relationships, and identifying abnormal telecommunications behaviors based on network actions and attribute information, the problem of low identification efficiency in low-connectivity scenarios is solved, and efficient and real-time identification of abnormal telecommunications behaviors is achieved.

CN122002290APending Publication Date: 2026-05-08CHINA MOBILE GRP FUJIAN CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE GRP FUJIAN CO LTD
Filing Date
2024-11-01
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively identify abnormal telecommunications behavior in low-connectivity scenarios, and the performance consumption is high when constructing network inference from the entire network data, affecting identification efficiency.

Method used

By acquiring the specified network actions and attribute information of the initial object in multiple target applications, it is determined whether it is a candidate object that triggers abnormal behavior, a communication network graph is constructed, and a preset identification strategy is used to determine the target object that actively triggers abnormal behavior.

Benefits of technology

It enables real-time and accurate identification of abnormal telecommunications behavior in low-connectivity scenarios, improving identification efficiency and reducing computational complexity and resource consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122002290A_ABST
    Figure CN122002290A_ABST
Patent Text Reader

Abstract

The invention provides a telecommunication abnormal behavior identification method and device based on a network action accompanying a call, and relates to the technical field of communication security, wireless and artificial intelligence. Comprising the following steps: acquiring specified network actions of an initial object in a plurality of preset target application programs and attribute information corresponding to the specified network actions; based on the specified network action and the attribute information, judging whether the initial object is a candidate object for triggering the abnormal behavior or not; and in response to the initial object being a candidate object, positioning call data based on a specified network action, expanding the candidate object based on the call data, constructing a communication relation network diagram, performing identification based on the communication relation network diagram according to a preset identification strategy, and determining a target object actively triggering an abnormal behavior from the candidate object. According to the method and the device, a low-communication scene can be effectively dealt with, fine-grained internet surfing information and network actions are applied, telecommunication abnormal behavior identification is carried out in real time, and the efficiency of telecommunication abnormal behavior identification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of communication security, wireless technology, and artificial intelligence technology, and specifically to a method and apparatus for identifying abnormal telecommunications behavior based on network actions accompanying calls. Background Technology

[0002] In related technologies, telecommunications fraud identification based on communication is difficult to distinguish from legitimate business such as sales calls. Simply constructing a threshold model based on call detail records is no longer sufficient to deal with increasingly complex communication-related telecommunications anomalies. When the number of calls is low, it may affect the recognition effect of machine learning mechanisms that rely on voice information. It cannot effectively deal with low communication scenarios. When using the entire network data to construct the network for inference, it consumes a lot of system performance and may affect the efficiency of anomaly behavior identification.

[0003] Therefore, how to effectively deal with low connectivity scenarios, apply fine-grained Internet access information and network actions, and perform real-time identification of abnormal telecommunications behavior to improve the efficiency of such identification has become an important research direction. Summary of the Invention

[0004] This disclosure aims to at least partially address one of the technical problems in the related art. To this end, one objective of this disclosure is to propose a method for identifying abnormal telecommunications behavior based on network actions accompanying phone calls.

[0005] The second objective of this disclosure is to propose a telecommunications abnormal behavior identification device based on network actions accompanying a call.

[0006] The third objective of this disclosure is to propose an electronic device.

[0007] The fourth objective of this disclosure is to provide a non-transitory computer-readable storage medium.

[0008] The fifth objective of this disclosure is to provide a computer program product.

[0009] To achieve the above objectives, the first aspect of this disclosure proposes a method for identifying abnormal telecommunications behavior based on network actions accompanying calls, comprising:

[0010] Obtain the specified network action and corresponding attribute information of the initial object in multiple preset target applications. The attribute information includes at least the time and first traffic data corresponding to the specified network action.

[0011] Based on the specified network actions and attribute information, determine whether the initial object is a candidate object that triggers abnormal behavior;

[0012] In response to the initial object being a candidate object, call data is located based on specified network actions, and candidate objects are expanded based on the call data to construct a communication relationship network graph;

[0013] Based on a pre-defined identification strategy and a network graph of connections, the target object that actively triggers abnormal behavior is identified from the candidate objects.

[0014] In this embodiment, based on specified network actions and attribute information, it is determined whether the initial object is a candidate object for triggering abnormal behavior. In response to the initial object being a candidate object, call data is located based on the specified network actions, and candidate objects are expanded based on the call data to construct a communication relationship network graph. Based on the identification of fine-grained abnormal Internet access behavior of the initial object, the call data accompanying its actions is located, and a high-risk communication relationship network is constructed. This allows for real-time and accurate discovery of target objects. According to a preset identification strategy, identification is performed based on the communication relationship network graph to determine the target object that actively triggers abnormal behavior from the candidate objects. This can effectively address low connectivity scenarios, apply fine-grained Internet access information and network actions, and perform real-time identification of abnormal telecommunications behavior, thereby improving the efficiency of abnormal telecommunications behavior identification.

[0015] To achieve the above objectives, a second aspect of this disclosure provides a telecommunications abnormal behavior identification device based on network actions accompanying calls, comprising:

[0016] The acquisition module is used to acquire the initial object's specified network actions and corresponding attribute information in multiple preset target applications. The attribute information includes at least the time and first traffic data corresponding to the specified network action.

[0017] The judgment module is used to determine whether the initial object is a candidate object that triggers abnormal behavior based on specified network actions and attribute information.

[0018] The building module is used to respond to the initial object as a candidate object, locate call data based on specified network actions, expand the candidate objects based on the call data, and build a communication relationship network graph.

[0019] The determination module is used to identify the target object that actively triggers abnormal behavior from the candidate objects based on the communication relationship network diagram according to the preset identification strategy.

[0020] To achieve the above objectives, a third aspect of this disclosure provides an electronic device comprising:

[0021] At least one processor; and

[0022] A memory that is communicatively connected to at least one processor; wherein,

[0023] The memory stores instructions that can be executed by at least one processor, which enables the at least one processor to perform the telecommunications abnormal behavior identification method based on network actions accompanying calls provided in the first aspect of this disclosure.

[0024] To achieve the above objectives, a fourth aspect of this disclosure provides a computer-readable storage medium having computer instructions stored thereon, wherein the computer instructions are used to cause a computer to execute the telecommunications abnormal behavior identification method based on network actions accompanying calls provided in the first aspect of this disclosure.

[0025] To achieve the above objectives, a fifth aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the telecommunications abnormal behavior identification method based on network actions accompanying calls provided in the first aspect of this disclosure. Attached Figure Description

[0026] Figure 1 This is a flowchart of a method for identifying abnormal telecommunications behavior based on network actions accompanying calls, according to an embodiment of this disclosure;

[0027] Figure 2 This is a flowchart of a method for identifying abnormal telecommunications behavior based on network actions accompanying calls, according to an embodiment of this disclosure;

[0028] Figure 3 This is a schematic diagram of a network diagram showing the connections between different entities according to an embodiment of this disclosure.

[0029] Figure 4 This is a flowchart of a method for identifying abnormal telecommunications behavior based on network actions accompanying calls, according to an embodiment of this disclosure;

[0030] Figure 5 This is a schematic diagram of a maximally connected subgraph according to an embodiment of this disclosure;

[0031] Figure 6 This is a structural block diagram of a telecommunications abnormal behavior identification device based on network actions accompanying a call, according to an embodiment of this disclosure.

[0032] Figure 7 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. Detailed Implementation

[0033] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.

[0034] The following describes, with reference to the accompanying drawings, a method and apparatus for identifying abnormal telecommunications behavior based on network actions accompanying calls, according to embodiments of the present disclosure.

[0035] Figure 1 This is a flowchart of a telecommunications abnormal behavior identification method based on network actions accompanying calls, according to an embodiment of this disclosure. Figure 1 As shown, the method includes the following steps:

[0036] S101, Obtain the specified network action and corresponding attribute information of the initial object in multiple preset target applications.

[0037] In this embodiment of the disclosure, an anti-fraud environment is used as an example for illustration. Abnormal telecommunications behavior can be understood as behavior involving telecommunications fraud. The target application may be an application with one or more of the following functions: screen sharing function, bank transfer function, video chat function, text chat function, voice chat function, electronic payment function, etc. In other embodiments, the target application may also be an application with other functions, and this embodiment of the disclosure does not limit this.

[0038] For example, for a target application with screen sharing functionality, its specified network action can be "initiating screen sharing" or "accepting screen sharing". For a target application with bank transfer functionality, its specified network action can be "bank transfer" or "bank receipt". In other embodiments, the specified network action of the target application can also be other actions / operations, and this disclosure does not limit this.

[0039] The attribute information includes at least the time corresponding to the specified network action and the first traffic data.

[0040] In some implementations, traffic identification systems, such as Deep Packet Inspection (DPI), can be invoked to access the initial object's internet access records and obtain the first traffic data and time generated by each specified network action.

[0041] S102, based on the specified network action and attribute information, determine whether the initial object is a candidate object that triggers abnormal behavior.

[0042] In some implementations, a preset neural network can be invoked, and specified network actions and attribute information can be input into the preset neural network to determine whether the initial object is a candidate object that triggers abnormal behavior.

[0043] In some implementations, to improve data accuracy and monitor fine-grained high-risk internet browsing behaviors of the initial target, such as screen sharing commonly seen in anti-fraud environments, this embodiment of the disclosure calls a preset parsing tool to convert the first traffic data into a target packet length sequence according to a preset fixed length. Since the target application often generates a fixed sequence of packet lengths when performing the same action, such as [134 bytes uplink, 56 bytes downlink, 88 bytes downlink, ...], the traffic data is extracted into a fixed-length packet length sequence vector [x1, x2, ..., x] by a parsing tool (such as Wireshark). N If the number of packets generated by the traffic exceeds N, then truncation will be performed. i The size of the i-th packet that generates traffic for the action, with positive numbers representing uplink and negative numbers representing downlink. For example, the packet length sequence described above can be represented as [134, -56, 88, ...].

[0044] The target packet long sequence is input into a preset target classification model to determine whether the initial object's specified network action in the target application is an abnormal internet access action. In some implementations, taking an anti-fraud environment as an example, a high-risk behavior of a single application (such as screen sharing alone) may not necessarily constitute fraud, but a combination of high-risk behaviors of multiple applications, such as "meeting screen sharing" + "bank transfer", can strengthen the confidence level of fraud identification. Therefore, this application performs combination matching of multiple high-risk internet access behaviors to obtain abnormal internet access action combinations. In response to the initial object having at least two abnormal internet access actions, the abnormal internet access actions are matched with multiple preset abnormal internet access action combinations to determine whether the abnormal internet access action matches any abnormal internet access action combination. In response to the abnormal internet access action matching any abnormal internet access action combination, it is determined that the current internet access mode is high-risk, and the initial object is determined to be a candidate object that triggers abnormal behavior.

[0045] In some implementations, abnormal internet access action combinations belong to two combination types: active and passive. If the abnormal internet access action combination matched by the abnormal internet access action belongs to the active type, the initial object is determined to be the first candidate object actively triggering the abnormal behavior. Alternatively, if the abnormal internet access action combination matched by the abnormal internet access action belongs to the passive type, the initial object is determined to be the second candidate object passively triggering the abnormal behavior. Taking a fraud prevention environment as an example, the first candidate object is a suspected fraudster who may be engaging in fraudulent activities, and the second candidate object is a suspected victim who may be currently experiencing fraudulent activities. For example, if the initial object exhibits the action combination of "accepting screen sharing" + "bank transfer," it corresponds to a suspected victim; if the initial object exhibits the action combination of "accepting meeting screen sharing" + "bank payment," it corresponds to a suspected fraudster. The model in this step only serves as a preliminary screening of victims and suspects, indicating that both exhibit some known fraudulent behavior patterns that can be located through a high-risk behavior identification model, but it cannot confirm whether it is fraud. The output candidate objects will be further analyzed in subsequent steps.

[0046] S103, in response to the initial object being a candidate object, locate the call data based on the specified network action, expand the candidate objects based on the call data, and construct a communication relationship network graph.

[0047] In this embodiment of the disclosure, if the initial object is a candidate object, the call data is located based on the time range corresponding to the specified network action, the peer number in the call data is obtained, and the peer number in the time range is obtained. The candidate objects are expanded based on the communication relationship between the peer numbers, and a communication relationship network graph is constructed.

[0048] S104. Based on the communication network diagram, identify the target object that actively triggers abnormal behavior from the candidate objects according to the preset identification strategy.

[0049] In some implementations, candidate objects include a first candidate object that actively triggers abnormal behavior and a second candidate object that passively triggers abnormal behavior. In the communication relationship network diagram, the peer number connected to the first candidate object is the second candidate object, and the peer number connected to the second candidate object is the first candidate object. The node degree of the node containing the first candidate object in the communication relationship network diagram is obtained, and the first candidate object whose node degree is greater than a preset node degree threshold is identified as the target object. Taking the initial object as the first candidate object as an example, the communication relationship network diagram of the current status is periodically constructed, and all first candidate objects in the communication relationship network diagram are obtained, including the initial object directly determined by a specified network action and other first candidate objects obtained through call accompaniment. The node degree of all first candidate objects is calculated, and a node degree threshold Thres is set. v(Optionally, the node degree threshold is greater than or equal to 2), meaning that within the statistical time period, the first candidate object has at least one node degree threshold with Thres. v If a second candidate has engaged in high-risk online activities accompanied by phone calls, such as sharing their screen after talking to multiple second candidates, the first candidate is more likely to be the target.

[0050] In some implementations, call data, abnormal internet access actions and attribute information of abnormal internet access actions, and communication relationship network diagrams are respectively input into a preset machine learning model or graph neural network model. The preset machine learning model or graph neural network model performs feature extraction and recognition on the above information, and determines the target object that actively triggers abnormal behavior from the candidate objects.

[0051] In this embodiment, based on specified network actions and attribute information, it is determined whether the initial object is a candidate object for triggering abnormal behavior. In response to the initial object being a candidate object, call data is located based on the specified network actions, and candidate objects are expanded based on the call data to construct a communication relationship network graph. Based on the identification of fine-grained abnormal Internet access behavior of the initial object, the call data accompanying its actions is located, and a high-risk communication relationship network is constructed. This allows for real-time and accurate discovery of target objects. According to a preset identification strategy, identification is performed based on the communication relationship network graph to determine the target object that actively triggers abnormal behavior from the candidate objects. This can effectively address low connectivity scenarios, apply fine-grained Internet access information and network actions, and perform real-time identification of abnormal telecommunications behavior, thereby improving the efficiency of abnormal telecommunications behavior identification.

[0052] In some implementations, the training process of the target classification model includes: acquiring abnormal behavior cases and performing keyword recognition on the abnormal behavior cases to obtain candidate applications in the abnormal behavior cases and candidate network actions corresponding to the candidate applications; calling a preset automated testing tool to repeatedly execute the candidate network actions and starting a preset network data acquisition and analysis tool to acquire second traffic data when executing the candidate network actions; marking whether the second traffic data is an abnormal internet access action and obtaining reference labels; calling a parsing tool to convert the second traffic data into a candidate packet length sequence according to a fixed length; inputting the candidate packet length sequence into a preset candidate classification model to determine whether the candidate network action is an abnormal internet access action and obtaining a predicted label; obtaining a loss function based on the reference label and the predicted label to train the candidate classification model and obtain the trained target classification model.

[0053] Taking a fraud prevention scenario as an example, this involves collecting information on apps involved in publicly available fraud cases, as well as the app actions associated with fraudulent activities. An automated testing script is written, and open-source automated testing tools (such as uiautomator2 or airtest) are used to repeatedly execute fraudulent actions by the apps, such as enabling screen sharing in meeting software. During the automated execution of these fraudulent actions, network data collection and analysis tools (such as tcpdump) are used to capture network packets, accurately obtaining traffic generated by high-risk internet browsing actions. Packet capture ends after the actions are completed. The traffic obtained from executing candidate network actions is labeled and saved as training data. The same process of packet capture and labeling is performed on other non-fraudulent actions of the apps, such as normal browsing in meeting software and background traffic. The traffic generated by known high-risk internet browsing actions, along with other normal traffic generated by the involved apps, is labeled and used to train a classification model for subsequent identification. In other words, in this embodiment of the application, candidate network actions include specified network actions and other network actions of the application. When training the classification model, the traffic data of candidate network actions are used for training. After training is completed, in order to improve computational efficiency and reduce computational load, during the use of the classification model, only the relevant information of the specified network actions can be collected and input into the classification model for analysis and identification.

[0054] Figure 2 This is a flowchart of a telecommunications abnormal behavior identification method based on network actions accompanying calls, according to an embodiment of this disclosure. Figure 2 As shown, the method includes the following steps:

[0055] S201, Obtain the specified network action and corresponding attribute information of the initial object in multiple preset target applications. The attribute information includes at least the time and first traffic data corresponding to the specified network action.

[0056] S202, Based on the specified network action and attribute information, determine whether the initial object is a candidate object that triggers abnormal behavior.

[0057] For a description of steps S201 to S202, please refer to the relevant content in the above embodiments, which will not be repeated here.

[0058] S203, in response to the initial object being a candidate object, obtain the detailed call records of the initial object, and obtain the first time range of abnormal internet access actions in the specified network actions.

[0059] For example, in response to the initial object being a candidate object, abnormal internet access behavior detection is triggered, and the call detail records (CDRs) of the number associated with the initial object for that day are obtained.

[0060] In some implementations, the first time range t thres For example, it could be one hour.

[0061] S204, Based on the first time range, filter the detailed call records of the initial object to locate the call data.

[0062] For example, call details can be filtered to retain the first time range t before (or before and after) the time of the abnormal internet activity. thres Call data.

[0063] S205, based on call data, determine the peer number contacted by the initial target as the extended candidate target.

[0064] The peer number contacted by the initial target is identified as a candidate target for high-risk accompanying communications of the initial target.

[0065] In some implementations, in order to prevent candidate objects from using different terminals to make calls and access the Internet separately, it is necessary to consider the spatiotemporal characteristics of Internet access. That is, candidate objects are associated with information such as latitude and longitude in the call records of call and Internet access behavior. For example, if two candidate objects that meet the above conditions have the same number movement trajectory, they can be considered as the same candidate object.

[0066] In some implementations, such as Figure 3 As shown, the candidate objects include a first candidate object that actively triggers abnormal behavior and a second candidate object that passively triggers abnormal behavior. The peer number that the first candidate object communicates with is the second candidate object, and the peer number that the second candidate object communicates with is the first candidate object.

[0067] S206, continue to obtain detailed call records of the expanded candidate objects to locate call data and expand the expanded candidate objects again until the preset expansion conditions are met.

[0068] The first candidate object set is V. fraud The second candidate object set is V victim All call records for both parties are E. Following the same logic as the steps above, continue based on the current V. fraud V victim E obtains the peer number of high-risk communications, V fraud The counterpart of a high-risk communication is the expanded first candidate object set V. victim(+) V victim The counterpart of the high-risk communication is the expanded second candidate object set V. fraud(+) .

[0069] In some implementations, if a preset number of expansions is reached, the preset expansion condition is determined to be met. In some implementations, if the call data of the expanded candidate indicates that there are no other peer numbers, the preset expansion condition is determined to be met.

[0070] S207, Construct a network graph of connections based on the initial object and the expanded candidate objects.

[0071] like Figure 3 As shown, a communication relationship network graph G(V) is constructed with candidate objects as nodes and high-risk call E as an edge. fraud ∪V victim ∪ Vvictim(+) ∪V fraud(+) In the interconnected network graph (E), all points are involved in abnormal internet access behavior (i.e., high-risk internet access behavior), and all edges are associated with high-risk behavior over time.

[0072] S208, based on the communication network diagram, the target object that actively triggers abnormal behavior is identified from the candidate objects according to the preset identification strategy.

[0073] For a description of step S208, please refer to the relevant content in the above embodiments, which will not be repeated here.

[0074] This disclosure uses traffic identification to accurately locate the network of connections related to high-risk online behaviors involving fraud. The network size is significantly reduced, and there is no redundant or invalid information. All points and edges are directly related to fraudulent behaviors. This module periodically outputs a relationship graph for subsequent fraud identification.

[0075] In this embodiment of the disclosure, the accuracy of identifying the first two aspects can be greatly improved after enhancing the accompanying information of the call based on fine-grained abnormal Internet access behavior. Furthermore, because the call is initially screened, the efficiency of identifying abnormal telecommunications behavior is significantly improved. Constructing a communication relationship network graph effectively narrows the scope of subsequent analysis, reduces the computational complexity of the model, avoids resource waste, and can be extended to other network security fields, such as network intrusion detection and malware prevention scenarios.

[0076] Figure 4 This is a flowchart of a telecommunications abnormal behavior identification method based on network actions accompanying calls, according to an embodiment of this disclosure. Figure 4 As shown, the method includes the following steps:

[0077] S401, obtain the specified network action and corresponding attribute information of the initial object in multiple preset target applications. The attribute information includes at least the time and first traffic data corresponding to the specified network action.

[0078] S402, based on the specified network action and attribute information, determine whether the initial object is a candidate object that triggers abnormal behavior.

[0079] S403, in response to the initial object being a candidate object, locate the call data based on the specified network action, expand the candidate objects based on the call data, and construct a communication relationship network graph.

[0080] For a description of steps S401 to S403, please refer to the relevant content in the above embodiments, which will not be repeated here.

[0081] S404 performs connectivity analysis on the network graph of connections to obtain maximally connected subgraphs.

[0082] like Figure 5 As shown, connectivity analysis in graph theory is used to find maximally connected subgraphs in a network graph with interconnected relationships. In some implementations, candidate objects A, B, C, and D are first candidate objects, while in other implementations, they are second candidate objects.

[0083] S405, extract features from the maximally connected subgraph to obtain the first feature representation.

[0084] S406, extract features from call data, abnormal internet access actions, and attribute information of abnormal internet access actions to obtain a second feature representation.

[0085] In this embodiment of the disclosure, call data, abnormal internet access actions, and attribute information of abnormal internet access actions are respectively subjected to feature extraction to obtain a second feature representation. Optionally, the second feature representation includes call-related features (such as the number of calls, total call duration, average call duration, concentrated call time period, etc.), APP usage features (including the usage frequency, usage duration, and usage time distribution of the target APP, etc.), abnormal internet access action features in the APP (such as the number of times and duration of screen sharing in a video conferencing APP, the frequency of abnormal friend additions in a social APP, etc.), abnormal internet access action combination features (capturing the temporal correlation of multiple abnormal internet access action combinations, such as the frequency of screen sharing immediately after adding friends in a social APP), and network traffic data features (specific network traffic patterns identified based on deep packet inspection (DPI), such as data packet sequence features related to specified network actions and abnormal internet access actions).

[0086] S407, invoke a preset machine learning model or graph neural network model to perform recognition analysis based on the first feature representation and the second feature representation, so as to determine the target object from the candidate objects.

[0087] Optionally, in the embodiments of this application, the machine learning model or graph neural network model is a pre-trained model. For example, relevant CDR records of known reference objects within a set time range can be obtained, and a reference connectivity network graph can be constructed in the same way to train the performance of the machine learning model or graph neural network model.

[0088] In this embodiment, the machine learning model or graph neural network model only infers nodes in the connectivity network graph, significantly improving computational efficiency. Regarding feature engineering, common speech recognition features (such as maximum and minimum call duration, connection rate, etc.) can be reused, while a series of innovative features based on abnormal behavior are introduced to improve the model's recognition accuracy.

[0089] In some implementations, taking a machine learning model as an example, the call data of the maximally connected subgraph, the abnormal internet access actions, and the attribute information of the abnormal internet access actions can be directly input into the machine learning model for feature extraction and recognition, and the target object can be determined from the candidate objects.

[0090] In some implementations, taking a graph neural network model as an example, the call data of the maximally connected subgraph, the abnormal internet access actions, and the attribute information of the abnormal internet access actions can be directly input into the graph neural network model for feature extraction and recognition, and the target object can be determined from the candidate objects.

[0091] In this embodiment, the acquisition and application of the first and second feature representations both rely on the mining of upstream fine-grained abnormal internet access actions accompanied by calls. By integrating these new features, the model can more comprehensively characterize various aspects of potential abnormal behavior, thereby significantly improving the accuracy and real-time performance of telecommunications abnormal behavior identification while maintaining high efficiency. This disclosure, based on the enhancement of call-related information accompanying fine-grained abnormal internet access actions, can significantly improve the identification accuracy of the former two features, and because of the initial call screening, it can significantly reduce the computational scale of subsequent machine learning and deep learning.

[0092] The identification process disclosed herein is compatible with most machine learning / deep learning models, but unlike others, it performs precise filtering of calls, retaining only call data containing high-risk calls to construct a network graph of communication relationships, while not processing most normal calls on the existing network. This improves the efficiency of identification and processing and enables more frequent real-time inference.

[0093] Figure 6 This is a structural block diagram of a telecommunications abnormal behavior identification device based on network actions accompanying calls, according to an embodiment of this disclosure. Figure 6 As shown, the telecommunications abnormal behavior identification device 600 based on network actions accompanying calls includes:

[0094] The acquisition module 610 is used to acquire the specified network action of the initial object in multiple preset target applications and the attribute information corresponding to the specified network action. The attribute information includes at least the time and first traffic data corresponding to the specified network action.

[0095] The judgment module 620 is used to determine whether the initial object is a candidate object that triggers abnormal behavior based on specified network actions and attribute information;

[0096] Module 630 is used to respond to an initial object as a candidate object, locate call data based on a specified network action, expand the candidate objects based on the call data, and construct a communication relationship network graph.

[0097] The determination module 640 is used to identify the target object that actively triggers abnormal behavior from the candidate objects by performing identification based on the communication relationship network diagram according to the preset identification strategy.

[0098] In some implementations, the determination module 620 is also used for:

[0099] The preset parsing tool is invoked to convert the first traffic data into a target packet length sequence according to a preset fixed length.

[0100] Input the target packet long sequence into the preset target classification model to determine whether the initial object's specified network action in the target application is an abnormal internet access action;

[0101] In response to the initial object having at least two abnormal internet access actions, the abnormal internet access actions are matched with multiple preset abnormal internet access action combinations to determine whether the abnormal internet access action matches any abnormal internet access action combination.

[0102] In response to any abnormal internet access action matching any combination of abnormal internet access actions, the initial object is determined as a candidate object to trigger abnormal behavior.

[0103] In some implementations, the abnormal internet access action combination belongs to two combination types, including active and passive types. The judgment module 620 is also used for:

[0104] In response to abnormal internet access actions, the matched combination of abnormal internet access actions belongs to the active type, and the initial object is determined to be the first candidate object for actively triggering abnormal behavior; or

[0105] The abnormal internet access action combination matched by the abnormal internet access action belongs to the passive type, and the initial object is determined to be the second candidate object for passively triggering abnormal behavior.

[0106] In some implementations, the construction module 630 is also used for:

[0107] Get the initial object's detailed call records and get the first time range of abnormal internet access actions in the specified network actions;

[0108] Filter the detailed call records of the initial object based on the first time range to locate the call data;

[0109] Based on call data, the peer number contacted by the initial target is determined as the expanded candidate target;

[0110] Continue to acquire detailed call records of the expanded candidate objects to locate call data and expand the expanded candidate objects again until the preset expansion conditions are met.

[0111] Construct a network graph of connections based on the initial object and the expanded candidate objects.

[0112] In some implementations, the candidate objects include a first candidate object that actively triggers abnormal behavior and a second candidate object that passively triggers abnormal behavior. In the communication relationship network diagram, the peer number communicated by the first candidate object is the second candidate object, and the peer number communicated by the second candidate object is the first candidate object.

[0113] In some implementations, the determining module 640 is further configured to:

[0114] Obtain the node degree of the node containing the first candidate object in the connectivity network graph;

[0115] The first candidate object whose node degree is greater than the preset node degree threshold is identified as the target object.

[0116] In some implementations, the determining module 640 is further configured to:

[0117] Perform connectivity analysis on the network graph of connections to obtain maximally connected subgraphs;

[0118] Feature extraction is performed on the maximally connected subgraph to obtain the first feature representation;

[0119] Feature extraction is performed on call data, abnormal internet access actions, and attribute information of abnormal internet access actions to obtain a second feature representation;

[0120] The system invokes a pre-defined machine learning model or graph neural network model to perform identification and analysis based on the first feature representation and the second feature representation in order to determine the target object from the candidate objects.

[0121] In some implementations, the determination module 620 is also used for:

[0122] Obtain abnormal behavior cases, perform keyword recognition on abnormal behavior cases, and obtain candidate applications in abnormal behavior cases, as well as candidate network actions corresponding to candidate applications;

[0123] The preset automated testing tool is invoked to repeatedly execute candidate network actions, and the preset network data acquisition and analysis tool is launched to obtain the second traffic data when the candidate network actions are executed;

[0124] Mark whether the second traffic data represents abnormal internet access behavior and obtain reference tags;

[0125] The parsing tool is invoked to convert the second traffic data into a candidate packet length sequence according to a fixed length.

[0126] The candidate packet long sequence is input into the preset candidate classification model to determine whether the candidate network action is an abnormal Internet access action and obtain the predicted label;

[0127] The loss function is obtained based on the reference label and the predicted label to train the candidate classification model and obtain the trained target classification model.

[0128] This disclosure can effectively address low-connectivity scenarios by applying fine-grained internet access information and network actions to identify abnormal telecommunications behavior in real time, thereby improving the efficiency of such identification.

[0129] The acquisition, transmission, storage, use, and processing of data in this disclosed technical solution all comply with relevant laws and regulations.

[0130] It should be noted that in the embodiments disclosed herein, certain software, components, models, and other existing solutions in the industry may be mentioned. These should be considered as exemplary and are intended only to illustrate the feasibility of implementing the technical solution of this application. However, they do not mean that the applicant has used or necessarily used such solutions.

[0131] Figure 7 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure.

[0132] like Figure 7 As shown, the electronic device 800 includes:

[0133] The system includes a memory 801 and a processor 802, and a bus 803 connecting different components (including the memory 801 and the processor 802). The memory 801 stores a computer program, and when the processor 802 executes the program, it implements the telecommunications abnormal behavior identification method based on network actions accompanying calls according to the present disclosure.

[0134] Bus 803 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0135] Electronic device 800 typically includes a variety of electronic device readable media. These media can be any available media that can be accessed by electronic device 800, including volatile and non-volatile media, removable and non-removable media.

[0136] Memory 801 may also include computer system readable media in the form of volatile memory, such as random access memory (RAM) 804 and / or cache memory 805. Electronic device 800 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 806 may be used to read and write non-removable, non-volatile magnetic media (… Figure 7 Not shown; usually referred to as a "hard drive"). Although Figure 7 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 803 via one or more data media interfaces. Memory 801 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this disclosure.

[0137] A program / utility 808 having a set (at least one) of program modules 807 may be stored, for example, in memory 801. Such program modules 807 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 807 typically perform the functions and / or methods described in the embodiments of this disclosure.

[0138] Electronic device 800 can also communicate with one or more external devices 809 (e.g., keyboard, pointing device, display 811, etc.), and with one or more devices that enable a user to interact with the electronic device 800, and / or with any device that enables the electronic device 800 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed through input / output (I / O) interface 812. Furthermore, electronic device 800 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) through network adapter 813. Figure 7 As shown, network adapter 813 communicates with other modules of electronic device 800 via bus 803. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with electronic device 800, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0139] The processor 802 executes various functional applications and data processing by running programs stored in the memory 801.

[0140] It should be noted that the implementation process and technical principles of the electronic device in this embodiment are explained in the foregoing description of the telecommunications abnormal behavior identification method based on network actions accompanying calls in this disclosure embodiment, and will not be repeated here.

[0141] To implement the above embodiments, this disclosure also proposes a computer-readable storage medium.

[0142] When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is able to perform the aforementioned method for identifying abnormal telecommunications behavior based on network actions accompanying calls. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, or optical data storage device, etc.

[0143] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0144] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A method for identifying abnormal telecommunications behavior based on network actions accompanying phone calls, characterized in that, include: Obtain the specified network action of the initial object in a preset set of multiple target applications and the attribute information corresponding to the specified network action. The attribute information includes at least the time and first traffic data corresponding to the specified network action. Based on the specified network action and the attribute information, determine whether the initial object is a candidate object for triggering abnormal behavior; In response to the initial object being the candidate object, call data is located based on the specified network action, and the candidate object is expanded based on the call data to construct a communication relationship network graph; Based on the communication network diagram, a preset identification strategy is used to identify the target object that actively triggers abnormal behavior from the candidate objects.

2. The method according to claim 1, characterized in that, The step of determining whether the initial object is a candidate object for triggering abnormal behavior based on the specified network action and the attribute information includes: The preset parsing tool is invoked to convert the first traffic data into a target packet length sequence according to a preset fixed length. The target packet long sequence is input into a preset target classification model to determine whether the initial object's specified network action in the target application is an abnormal internet access action; In response to the initial object having at least two of the abnormal internet access actions, the abnormal internet access actions are matched with a plurality of preset abnormal internet access action combinations to determine whether the abnormal internet access action matches any of the abnormal internet access action combinations. In response to the abnormal internet access action matching any of the abnormal internet access action combinations, the initial object is determined to be the candidate object that triggers the abnormal behavior.

3. The method according to claim 2, characterized in that, The abnormal internet access actions described belong to two types: active and passive. The step of determining the initial object as a candidate object triggering the abnormal behavior in response to the abnormal internet access action matching any of the abnormal internet access action combinations further includes: In response to the abnormal internet access action combination matched by the abnormal internet access action belonging to the active type, the initial object is determined to be the first candidate object for actively triggering abnormal behavior; or, In response to the abnormal internet access action matching the abnormal internet access action being of the passive type, the initial object is determined to be the second candidate object for passively triggering abnormal behavior.

4. The method according to any one of claims 1-3, characterized in that, The step of locating call data based on the specified network action, and expanding the candidate objects based on the call data to construct a communication relationship network graph includes: Obtain the detailed call records of the initial object, and obtain the first time range of abnormal internet access actions in the specified network actions; Based on the first time range, the call details of the initial object are filtered to locate the call data; Based on the call data, the peer number contacted by the initial object is determined to be the expanded candidate object; Continue to acquire detailed call records of the expanded candidate objects to locate call data and expand the expanded candidate objects again until the preset expansion conditions are met. A network graph of connections is constructed based on the initial object and the expanded candidate objects.

5. The method according to claim 4, characterized in that, The candidate objects include a first candidate object that actively triggers abnormal behavior and a second candidate object that passively triggers abnormal behavior. In the communication network diagram, The peer number connected to the first candidate is the second candidate, and the peer number connected to the second candidate is the first candidate.

6. The method according to claim 5, characterized in that, The step of identifying the target object that actively triggers abnormal behavior from the candidate objects based on the communication network graph according to the preset identification strategy includes: Obtain the node degree of the node where the first candidate object is located in the connectivity network graph; The first candidate object whose node degree is greater than a preset node degree threshold is determined as the target object.

7. The method according to claim 4, characterized in that, The step of identifying the target object that actively triggers abnormal behavior from the candidate objects based on the communication network graph according to the preset identification strategy includes: Perform connectivity analysis on the network graph to obtain maximally connected subgraphs; Feature extraction is performed on the maximally connected subgraph to obtain a first feature representation; Feature extraction is performed on the call data, abnormal internet access actions, and attribute information of the abnormal internet access actions to obtain a second feature representation; A preset machine learning model or graph neural network model is invoked to perform identification analysis based on the first feature representation and the second feature representation in order to determine the target object from the candidate objects.

8. The method according to claim 2, characterized in that, The training process of the target classification model includes: Obtain abnormal behavior cases, and perform keyword recognition on the abnormal behavior cases to obtain candidate applications in the abnormal behavior cases and candidate network actions corresponding to the candidate applications; The preset automated testing tool is invoked to repeatedly execute the candidate network action, and the preset network data acquisition and analysis tool is launched to obtain the second traffic data when the candidate network action is executed; Mark whether the second traffic data represents an abnormal internet access action and obtain reference tags; The parsing tool is invoked to convert the second traffic data into a candidate packet length sequence according to the fixed length. The candidate packet long sequence is input into a preset candidate classification model to determine whether the candidate network action is an abnormal internet access action, and a predicted label is obtained. Based on the reference label and the predicted label, a loss function is obtained to train the candidate classification model, thereby obtaining the trained target classification model.

9. A telecommunications abnormal behavior identification device based on network actions accompanying phone calls, characterized in that, include: The acquisition module is used to acquire the specified network actions of the initial object in multiple preset target applications and the attribute information corresponding to the specified network actions. The attribute information includes at least the time and first traffic data corresponding to the specified network actions. The judgment module is used to determine whether the initial object is a candidate object for triggering abnormal behavior based on the specified network action and the attribute information; A construction module is used to respond to the initial object being the candidate object, locate call data based on the specified network action, expand the candidate object based on the call data, and construct a communication relationship network graph; The determination module is used to identify, based on the communication network diagram, the target object that actively triggers abnormal behavior from the candidate objects according to the preset identification strategy.

10. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-8.

11. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the steps of the method according to any one of claims 1-8.

12. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1-8.