Method and system for high risk instant identification and second-level response of telecommunication networks

By capturing abnormal behavior such as frequent switching of login IPs, a tiered and time-limited automated response mechanism is established to achieve second-level fund account management, solving the problem of long anti-fraud warning time in existing technologies and realizing rapid response and fund interception against telecommunications network fraud.

CN122264787APending Publication Date: 2026-06-23SHENZHEN HEJIUGUIYI CULTURAL DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN HEJIUGUIYI CULTURAL DEVELOPMENT CO LTD
Filing Date
2026-03-20
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

The existing anti-fraud early warning and handling process is time-consuming and makes it difficult to freeze funds before they are successfully transferred in telecommunications fraud, thus failing to effectively deal with highly organized and technically sophisticated telecommunications fraud.

Method used

By capturing abnormal behavior such as frequent switching of login IPs, a hierarchical, time-limited, and automated collaborative response mechanism is established to achieve second-level fund account management, including real-time data collection, dynamic risk assessment, and second-level linkage and handling.

Benefits of technology

The response time for intercepting funds involved in telecommunications network fraud has been reduced from tens of minutes to seconds, effectively intercepting fraudulent funds and suppressing the tools and methods used by fraud gangs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The application discloses a high-risk instant identification and second-level hierarchical response method and system for a telecommunication network. The method collects user login IP behavior data in real time, calculates the geographical jump characteristics in the time window, and performs millisecond-level risk assessment based on a preset multi-level risk rule library. The core is to establish a hierarchical and time-limited automatic response mechanism for the evaluation results: for the highest risk account, the system completes the freezing of the associated fund account within 5 seconds; for the high-risk account, the freezing is completed within 10 seconds; and for the medium and high-risk account, the main account is frozen within 15 seconds. The corresponding system includes data collection, real-time risk control analysis, linkage disposal and other modules. The application moves the defense pass to the preparation stage of fraud behavior, occupies the excellent disposal time of the fund transfer of telephone fraud through second-level response, and exponentially improves the interception success rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of network security and financial anti-fraud technology, specifically to a method and system for real-time identification and second-level hierarchical response to high-risk telecommunications networks. Background Technology

[0002] Currently, telecommunications and online fraud is highly organized and technologically sophisticated. Automated scripts can be used to disperse and launder funds across multiple layers in a mere 2 to 3 minutes, leaving the police with less than 2 minutes to intercept the funds. Existing anti-fraud warning and response processes typically involve multiple steps, including risk identification, manual assessment, inter-agency coordination, and issuing instructions, which are generally time-consuming and often fail to freeze fraudulent funds before they are successfully transferred. Therefore, there is an urgent need for a technological solution that can quickly and accurately identify risks and respond rapidly during the initial stages of fraudulent activity. Summary of the Invention

[0003] This invention aims to overcome the shortcomings of existing technologies and provide a method and system for instant identification and rapid response within 2 minutes of handling funds involved in telecommunications network fraud, with extremely fast response speed. To achieve the above objectives, the core idea of ​​the technical solution of this invention is to shift the defense checkpoint from "post-event tracing" to "in-event blocking" and even "pre-event warning". By capturing abnormal digital trajectories of frequently switching login IPs to test accounts or prepare for fraudulent activities to receive payments, a hierarchical, time-limited, and automated collaborative response mechanism is established to achieve fund account control within seconds. According to one aspect of the present invention, a method for real-time identification and second-level hierarchical response to high risks in telecommunications networks is provided, comprising the steps of: real-time collection of user login IP behavior data; dynamic calculation of the time density and spatial span of IP switching; real-time risk assessment based on a multi-level risk rule base; and triggering corresponding linkage actions within a strictly defined second-level time frame according to the risk level. According to another aspect of the present invention, a system for implementing the above method is provided, comprising: a data acquisition module, a real-time risk control and analysis module, a coordinated response module, and a response feedback and learning closed-loop module. Beneficial effects

[0004] The beneficial effects of this invention are as follows: By capturing the key early characteristic of IP hopping and constructing a "tiered-time-limited" mandatory response link, the response time for intercepting funds in telecommunications network fraud is compressed from the traditional tens of minutes to seconds. This invention patent not only exponentially increases the amount of funds intercepted, but also effectively suppresses the tools and methods of fraud gangs. Attached Figure Description

[0005] Figure 1 The overall flowchart of system data processing provided for the embodiments of the present invention. Figure 2 A timing diagram provided for a preferred embodiment of the present invention. Figure 3 This is a module structure diagram of the embedded data acquisition probe (SDK) in an embodiment of the present invention. Figure 4 This is a schematic diagram illustrating the training and application principles of the machine learning model built into the streaming computing risk control engine in the embodiments of the present invention. Figure 5 A schematic diagram of the interface layout of the monitoring and command screen is provided for the implementation scheme of the present invention. Figure 6 The system architecture diagram provided for the implementation scheme of the present invention. Implementation

[0006] To make the objectives, technical solutions, and advantages of the present invention clearer, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings. The following embodiments are used to illustrate the present invention, but are not intended to limit the scope of the invention. The system provided in this invention has the following core data processing flow: Figure 1 As shown. When a user (U) logs in, the data acquisition probe (P) captures and reports their IP address, timestamp, and geographic information in real time. The streaming computing risk control engine (E) continuously receives the data stream. If it detects a cross-provincial / municipal IP switch for the same account within a preset very short time of one hour, it immediately triggers a rule, which is then determined by the risk decision center to be of the highest risk. Subsequently, the multi-level disposal instruction distributor (D) receives the instruction within T+1 seconds and simultaneously sends it to the bank's core system (B). The bank system (B) completes the account freezing operation within T+4 seconds and feeds back the result (D→E), thus forming a complete disposal loop within T+5 seconds. The overall logical architecture of the system is as follows Figure 6 As shown, the system mainly comprises five interconnected layers: Data Acquisition Layer (A), Core Analysis Layer (B), Linked Response Layer (C), Data Storage Layer (D), and Application Presentation Layer (E). The Data Acquisition Layer (A) is responsible for acquiring real-time behavioral data from multiple sources, including telecom operators and mobile apps. The Core Analysis Layer (B) is the system's brain, making real-time decisions based on rules and models. The Linked Response Layer (C) is the system's nerve endings, with its streaming computing risk control engine (C1) ensuring that response commands are executed within seconds. The Data Storage Layer (D) provides the data foundation for analysis and decision-making, while the Application Presentation Layer (E) provides the interface for human-computer interaction. Figure 2The system demonstrates a second-level response timeline under the highest-risk scenario. When a fraudster's device (U) makes a cross-provincial login attempt within one hour, the data collection probe (P) reports the behavioral data to the streaming computing risk control engine (E). The engine (E) determines the risk level to be the highest within approximately 0.5 seconds, and the instruction distributor (D) immediately issues a freeze instruction to the bank's core system (B) at T+1 seconds. The bank's core system (B) completes the account lock and provides feedback within T+4 seconds, and the entire closed loop is completed within T+5 seconds. To achieve "second-level freezing," the system employs the following technical safeguards: direct connection to financial institutions via a dedicated financial line; asynchronous message queues, where the risk control engine (E) immediately submits the instruction to the queue after making a decision, allowing the distributor (C1) to process it in parallel at high speed; and pre-set freeze template instructions to enable "on / off" operation. like Figure 3 As shown, this structure includes an SDK interface layer (M1) and a core functionality layer (M2), and can be integrated into various application clients. The SDK architecture designed for this system is intended to obtain high-quality data from the source. Figure 4 As shown, the model is trained offline (F2) using historical behavior sequences as features (F1), the generated model file (F3) provides real-time scoring online (F4), and the treatment results are fed back (F5) for continuous optimization. A self-evolving machine learning model is integrated. Figure 5 The layout of the monitoring and command screen was displayed, including a national real-time early warning map (G1), a response tracking list (G2), and interception statistics (G3), providing a global perspective for command and decision-making. Risk Rule Base: Since the establishment of the risk rule base does not need to be illustrated with diagrams, it is described in text as follows: Based on intelligent early warning of fraudulent behavior using multimodal data and the fusion of multi-dimensional features with high-level rule design, this system's risk rule base can be further expanded to prepare for more covert fraudulent activities, and is not limited to single IP hop detection. For example, the system can integrate financial transaction features: Rule Extension A: Fund Aggregation Detection: The system monitors accounts in real time for any unusual inflow patterns where small amounts of funds are received from multiple unrelated accounts in a short period of time using fundraising methods. Once such "abnormal fund aggregation" is detected, the account can be marked as medium to high risk, even if its IP address has not yet changed, and enhanced monitoring and transaction delays will be triggered. Rule Extension B: Composite Behavior Sequence Warning. When the system identifies an "abnormal accumulation of funds" event, if the account subsequently experiences a "cross-regional IP jump" within a short period of 24 hours, this composite behavior sequence of "fund accumulation → IP jump" constitutes evidence of a very high-risk fraudulent activity. The system will immediately trigger the highest level of response, a second-level freeze. This effectively combats the new fraudulent activity preparation model of "transferring funds first, then switching IPs." Rule Extension C: Abnormal Social Interaction and Communication Pattern Recognition: The system can collaborate with security data from social and content platforms like Douyin and Kuaishou, and can also analyze in-app interactions via client SDK. Through Natural Language Processing (NLP) and behavioral clustering analysis, it identifies the following abnormal patterns: a) Detection of induced collaborative account clusters: Multiple accounts post highly similar messages more than three times at similar times, targeting the same goal or content, and these accounts themselves have bot characteristics with concentrated registration times. b) Identification of persuasive emotional and trust-building rhetoric: Identify classic high-yield promises, emotional inducements, and keywords and semantic patterns used to circumvent platform regulations in communication content. Once such organized "AI-induced cluster" activities are detected, the system can include the leading account in the cluster and the high-risk target accounts that are being induced into the monitoring list, and mark any financial transactions that occur therein as high-risk, shortening the handling time or lowering the handling threshold. This system's risk rule base is highly scalable, capable of integrating data from multiple channels such as communication, social media, and transactions, enabling accurate identification of early warning signs of complex fraudulent activities. For example, in a scenario targeting securities fraud and fake investment schemes, the system can issue an early warning through the following integrated rules: Rule extension D analyzes the combination of funding paths and rhetoric: When the system detects enticing statements promising abnormally high returns of over 35% per month on social media platforms, communication tools, or live streaming content, and simultaneously discovers requests to guide funds to non-bank third-party payment institutions, specific corporate accounts, or private accounts, even if the relevant accounts have not yet experienced IP hopping or fund transfers, the system can immediately mark the account that initiated the rhetoric and the group of accounts actively participating in the inducement as high-risk monitoring targets. Rule extension E provides a profile of cluster behavior: Further, the system can perform cluster behavior analysis on the aforementioned high-risk groups. If it identifies frequent, template-based interactions within the group, such as using standardized rhetoric to flatter, fabricating profit screenshots, or creating a standardized template, the system can determine that it is an organized fraud preparation cluster and freeze its core control accounts in advance, or forcibly delay and manually review transactions of suspected victim accounts, thereby effectively preventing financial losses before they occur. This system, through the aforementioned collaborative design of hardware and software, ensures end-to-end extreme speed and accuracy from risk perception to decision execution, achieving effective technical countermeasures against telecommunications fraud. The above description is merely a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of this specification and drawings, directly or indirectly applied to other related technical fields, should be covered within the patent protection scope of this invention.

Claims

1. A method for real-time identification and second-level hierarchical response to high-risk telecommunications networks, characterized in that, Includes the following steps: Real-time collection of user account login IP addresses and their associated information; Based on the login IP address, dynamically calculate the user's IP switching frequency and geographical span within a preset time window; Based on a pre-set multi-level risk rule base, the IP switching frequency and geographical span are analyzed, and the corresponding risk level is output. Based on the risk level, an automatic handling mechanism corresponding to the risk level is triggered; wherein, the automatic handling mechanism includes at least: issuing an instruction to freeze the associated fund account within a first preset time limit after the risk level is determined to be the highest.

2. The method according to claim 1, characterized in that, The multi-level risk rule base includes at least: If a user switches their IP address across provincial or municipal boundaries within the first time window, it will be marked as the highest risk level. If a user switches their IP address across provincial or municipal levels within the second time window, it will be marked as high-risk. If a user switches their IP address across provincial or municipal levels within the third time window, it will be marked as a medium-to-high risk level. The first time window is shorter than the second time window, and the second time window is shorter than the third time window.

3. The method according to claim 2, characterized in that, The automatic processing mechanism is as follows: When the risk level is the highest, within 5 seconds of the risk assessment, an instruction will be sent to the payment system to freeze all of the user's associated fund accounts. When the risk level is high, within 10 seconds of the risk assessment, an instruction will be sent to the payment system to freeze all of the user's associated fund accounts. When the risk level is medium to high, an instruction will be sent to the payment system within 15 seconds of the risk assessment to freeze the user's main fund account.

4. A system for real-time identification and second-level hierarchical response to high-risk telecommunications networks, used to implement the method of any one of claims 1-3, characterized in that, include: The data acquisition module is used to collect the login IP address of user accounts and their associated information in real time; The real-time risk control analysis module is used to dynamically calculate the user's IP switching frequency and geographical span within a preset time window based on the login IP address, and output the risk level according to the preset multi-level risk rule base. The coordinated response module is used to automatically issue account control instructions to the payment system within the corresponding time limit based on the risk level.

5. The system according to claim 4, characterized in that, It also includes a feedback and learning closed-loop module, which receives the execution results of the account management instructions and feeds back the execution results and corresponding risk assessment data to the real-time risk control analysis module to optimize the multi-level risk rule base.