Method and apparatus for determining risky-activity user, and electronic device and storage medium
By obtaining base station information and communication behavior data of multiple base stations, identifying risk active users, the problem of low accuracy in border roaming risk assessment in the prior art is solved, and more efficient risk user identification and evaluation is achieved.
Patent Information
- Application Number
- PCT/CN2024/120873
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-22
- Filing Date
- 2024-09-24
- Publication Date
- 2025-05-30
AI Technical Summary
The existing border roaming risk assessment method is based on the voice characteristics of the Internet of People, resulting in low evaluation accuracy and the inability to effectively identify risk users of IoT card border roaming.
By obtaining base station information of multiple base stations associated with the risk activity area, potential risk users are identified and their communication behavior data are obtained, and risk activity users are further identified based on these data to improve the accuracy of boundary roaming risk assessment.
By combining base station information and communication behavior data, the risk assessment of the boundary roaming is significantly improved, and the risk users of boundary roaming of IoT cards can be more effectively identified.
Smart Images

Figure CN2024120873_30052025_PF_FP_ABST
Abstract
Description
Method, device, electronic device and storage medium for determining risky activity users
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This disclosure is based on and claims the priority of Chinese patent application with application number 202311570999.9 and application date November 22, 2023. The entire content of the Chinese patent application is hereby incorporated into this disclosure by reference. Technical Field
[0003] The present application belongs to the field of border roaming risk assessment, and in particular relates to a method, device, electronic device and storage medium for determining users with risky activities. Background Art
[0004] With the development of the Internet of Things (IoT), the scale of IoT card devices has increased, and the business environment has become more complex. This has led to the risk of IoT cards being stolen and abused, impacting normal business operations. Therefore, it is particularly important to assess the risk of users roaming across borders using IoT cards.
[0005] In existing border roaming risk assessment methods, risk assessment is generally performed by a human network based on communication characteristics, such as a single number frequently calling multiple unfamiliar numbers, and the corresponding abnormal numbers are intercepted.
[0006] However, this method only evaluates and analyzes roaming risk based on the voice characteristics of the human network, which easily leads to low accuracy in border roaming risk assessment.
[0007] Summary of the Invention
[0008] The embodiments of the present application provide a method, device, electronic device, and storage medium for determining users with risky activities, which can improve the accuracy of border roaming risk assessment.
[0009] In one aspect of an embodiment of the present application, a method for determining users engaging in risky activities is provided, the method comprising:
[0010] Obtaining base station information of each of a first base station, a second base station, and a third base station associated with the risk activity area, where the first base station is a base station covering at least a portion of the risk activity area, the second base station is a base station that has a risk of covering at least a portion of the risk activity area, and the third base station is an adjacent base station to the first base station or the second base station;
[0011] Determining at least one potential risk user based on base station information of each of the first base station, the second base station, and the third base station, where the potential risk user is a user located within a coverage area of at least one of the first base station, the second base station, and the third base station;
[0012] Obtaining communication behavior data of each potential risk user among at least one potential risk user;
[0013] Based on the communication behavior data of each potential risk user, a risky activity user is determined among at least one potential risk user.
[0014] In one aspect of an embodiment of the present application, a device for determining users engaging in risky activities is provided, the device comprising:
[0015] a base station information acquisition module, configured to acquire base station information of each of a first base station, a second base station, and a third base station associated with the risk activity area, wherein the first base station is a base station covering at least a portion of the risk activity area, the second base station is a base station that is at risk of covering at least a portion of the risk activity area, and the third base station is an adjacent base station to the first base station or the second base station;
[0016] A first user determination module is configured to determine at least one potential risk user based on base station information of each of the first base station, the second base station, and the third base station, where the potential risk user is a user located within a coverage area of at least one of the first base station, the second base station, and the third base station;
[0017] a behavior data acquisition module, configured to acquire communication behavior data of each potential risk user among at least one potential risk user;
[0018] The second user determination module is configured to determine a risky activity user from at least one potential risk user based on the communication behavior data of each potential risk user.
[0019] In one aspect of an embodiment of the present application, an electronic device is provided, which includes: a memory and a program or instruction stored in the memory and executable on a processor, wherein when the program or instruction is executed by the processor, a method for determining users of risky activities as provided in any one aspect of the above-mentioned embodiment of the present application is implemented.
[0020] In one aspect of an embodiment of the present application, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, a method for determining users of risky activities as provided in any aspect of the above-mentioned embodiment of the present application is implemented.
[0021] In one aspect of an embodiment of the present application, a computer program product is provided. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the method for determining users of risky activities provided in any aspect of the above-mentioned embodiment of the present application.
[0022] In the method for determining risky active users provided in the embodiment of the present application, base station information of each of the first base station, the second base station, and the third base station associated with the risky active area is obtained. Then, based on the base station information of each of the first base station, the second base station, and the third base station, at least one potential risk user is determined, and the user's roaming risk is identified by evaluating and analyzing the base station information. Then, communication behavior data of each potential risk user among the at least one potential risk user is obtained, and finally, based on the communication behavior data of each potential risk user, a risky active user is determined among the at least one potential risk user, and the user's roaming risk is further identified by evaluating and analyzing the communication behavior data of the potential risk users. In this way, the embodiment of the present application performs a risk assessment of border roaming for users through base station information and communication behavior data, fully considering the impact of base station information and communication behavior data on roaming risk, and improving the accuracy of border roaming risk assessment. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0024] FIG1 is a flow chart of an embodiment of a method for determining risky activity users provided by the present application;
[0025] FIG2 is a schematic structural diagram of an embodiment of a device for determining users engaging in risky activities provided by the present application;
[0026] FIG3 is a schematic structural diagram of an embodiment of a device for determining users engaging in risky activities provided by the present application. DETAILED DESCRIPTION
[0027] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.
[0028] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.
[0029] The acquisition, storage, use, and processing of data in this application's technical solution comply with relevant national laws and regulations.
[0030] Existing border roaming risk assessment methods typically rely on a network of people to assess risk based on communication characteristics, such as a single number frequently calling multiple unfamiliar numbers, and then intercepting the corresponding abnormal calls. However, this method only assesses and analyzes roaming risk based on voice characteristics of the network of people, which can lead to low accuracy in border roaming risk assessment.
[0031] The purpose of the present application is to provide a method, apparatus, device and storage medium for determining risky activity users. In the method for determining risky activity users provided in the embodiment of the present application, base station information of each of the first base station, the second base station and the third base station associated with the risky activity area is obtained. Then, based on the base station information of each of the first base station, the second base station and the third base station, at least one potential risk user is determined, and the user's roaming risk is identified by evaluating and analyzing the base station information. Then, communication behavior data of each potential risk user among the at least one potential risk user is obtained, and finally, based on the communication behavior data of each potential risk user, a risky activity user is determined among the at least one potential risk user, and the user's roaming risk is further identified by evaluating and analyzing the communication behavior data of the potential risk user. In this way, the embodiment of the present application uses base station information and communication behavior data to perform a risk assessment of border roaming for the user, fully considering the impact of base station information and communication behavior data on roaming risk, and improving the accuracy of border roaming risk assessment.
[0032] The following describes specific embodiments of the method, apparatus, device, and storage medium for determining risky activity users provided by the embodiments of the present application. The following first describes the method for determining risky activity users.
[0033] FIG1 provides a flow chart of a method for determining users of risky activities. The method for determining users of risky activities is applied to a monitoring platform. The method may include the following steps S101 to S104 .
[0034] S101: Acquire base station information of each of a first base station, a second base station, and a third base station associated with a risk activity area.
[0035] In this embodiment, the first base station is a base station covering at least part of the risk activity area, the second base station is a base station that has the risk of covering at least part of the risk activity area, and the third base station is an adjacent base station of the first base station or the second base station.
[0036] Risky activity areas are areas where the risk of IoT card roaming exists. Adjacent base stations are base stations with adjacent coverage areas. For example, base stations A1 and A2 have adjacent coverage areas. A terminal can directly enter the coverage area of A2 by passing through the boundary of A1. In this case, A1 is considered an adjacent base station to A2, and A2 is considered an adjacent base station to A1.
[0037] For example, if the administrator determines that Area A is at risk of IoT card border roaming, Area A is designated as the risk activity area. Furthermore, Base Station A covers part of Area A, Base Station B is an adjacent base station to Base Station A, and Base Station C has an unclear coverage area but poses a risk of covering Area A. Therefore, Base Station A is designated as the first base station, Base Station B is designated as the third base station, and Base Station C is designated as the second base station.
[0038] The monitoring platform obtains base station information of each of base stations A, B, and C in response to the administrator's operation of importing information of base station A, base station B, and base station C.
[0039] S102: Determine at least one potential risk user based on base station information of each of the first base station, the second base station, and the third base station.
[0040] In this embodiment, the potential risk user is used to characterize the user who may have the risk of IoT card border roaming. The potential risk user is a user located in the coverage area of at least one of the first base station, the second base station, and the third base station.
[0041] For example, after obtaining the base station information of each of the first base station, the second base station, and the third base station, the monitoring platform will obtain the base station information corresponding to the target user.
[0042] When the base station information corresponding to the target user matches at least one of the base station information of the first base station, the second base station, and the third base station, the target user is determined to be a potential risk user; when the base station information corresponding to the target user does not match the base station information of the first base station, the second base station, and the third base station, the target user is determined not to be a potential risk user.
[0043] S103: Acquire communication behavior data of each potential risk user among at least one potential risk user.
[0044] In this embodiment, the communication behavior data is data characterizing the communication behavior of a potential risk user. For example, the communication behavior data may be at least one of text message count data and traffic usage data.
[0045] For example, when the monitoring platform determines that the target user is a potential risk user, it further obtains at least one of the target user's text message count data and traffic usage data.
[0046] S104: Determine risky activity users from at least one potential risk user based on the communication behavior data of each potential risk user.
[0047] In this embodiment, the risky activity users are used to characterize users who are determined to have the risk of IoT card border roaming.
[0048] For example, when the monitoring platform obtains the target user's SMS number data and traffic usage data, it compares the target user's SMS number data and traffic usage data with a pre-set maximum usage threshold.
[0049] If at least one of the target user's text message count data and traffic usage data is greater than the maximum usage threshold, the target user is determined to be a risky activity user; if both the target user's text message count data and traffic usage data are less than the maximum usage threshold, the target user is determined not to be a risky activity user.
[0050] Through this embodiment, the base station information of each of the first base station, the second base station, and the third base station associated with the risk activity area is obtained. Then, based on the base station information of each of the first base station, the second base station, and the third base station, at least one potential risk user is determined, and the user's roaming risk is identified by evaluating and analyzing the base station information. Then, the communication behavior data of each potential risk user among the at least one potential risk user is obtained, and finally, based on the communication behavior data of each potential risk user, a risky activity user is determined among the at least one potential risk user, and the user's roaming risk is further identified by evaluating and analyzing the communication behavior data of the potential risk user. In this way, the embodiment of the present application performs a risk assessment of border roaming for the user through base station information and the communication behavior data of the potential risk user, fully considering the impact of the base station information and the communication behavior data of the potential risk user on the roaming risk, and improving the accuracy of the border roaming risk assessment.
[0051] As an optional embodiment, S102 may specifically include:
[0052] Obtaining message information of users within the coverage area of each of the first base station, the second base station, and the third base station within a preset monitoring number of days, where the message information is used to represent base station information in the area where the user is located;
[0053] According to the message information of each user within the preset monitoring days, users located in the coverage area of at least two base stations among the first base station, the second base station and the third base station within the preset monitoring days are determined to be potential risk users.
[0054] In this embodiment, the message information is used to represent the base station information of the user's area. For example, the message information includes the International Mobile Subscriber Identification Number (IMSI), base station location, message time, base station location area code (LAC), and base station cell (CELL).
[0055] For example, the administrator sets the monitoring days to 3 days. In response to the administrator's operation of setting the monitoring days, the server obtains the preset monitoring days as 3 days.
[0056] The target IoT card reports the message information to the monitoring platform through the core network element. The monitoring platform determines whether the base station in the area where the target IoT card is located belongs to any one of the first base station, the second base station, and the third base station based on the received message information. If the base station in the area where the target IoT card is located does not belong to any one of the first base station, the second base station, and the third base station, the message information corresponding to the target IoT card is discarded.
[0057] When the base station in the area where the target IoT card is located belongs to any one of the first base station, the second base station and the third base station, the monitoring platform monitors the target IoT card according to the IMSI in the message information, obtains multiple message information of the target IoT card within the preset monitoring days, and determines the base stations corresponding to the multiple message information respectively.
[0058] When the base stations corresponding to the multiple message information include at least two base stations among the first base station, the second base station and the third base station, the user corresponding to the target IoT card is determined to be a potential risk user; when the base stations corresponding to the multiple message information do not include at least two base stations among the first base station, the second base station and the third base station, the user corresponding to the target IoT card is determined to be a non-potential risk user.
[0059] This embodiment monitors users within the coverage area of each of the first, second, and third base stations over a preset number of days. Message information from users within the coverage area of each of the first, second, and third base stations over the preset number of days is obtained, and users within the coverage area of at least two of the first, second, and third base stations over the preset number of days are identified as potential risk users. This allows for pre-emptive risk prediction based on existing data, reducing risk losses.
[0060] As an optional embodiment, S104 may specifically include:
[0061] Obtain the communication behavior data of each potential risk user within the preset monitoring days;
[0062] Based on communication behavior data, obtain the number of resource overages for each potential risk user;
[0063] Determine a potential risk user whose resource excess times are greater than a first preset threshold as a first potential high-risk user;
[0064] Based on the message information of each first potential high-risk user, risky activity users are determined among the first potential high-risk users.
[0065] In this embodiment, the communication behavior data is used to characterize the use of communication resources by potential risk users. For example, the communication behavior data may be at least one of the number of text messages and traffic usage data.
[0066] The resource excess times are counted as the number of times that the communication behavior data of potential risk users in each time period exceeds the average value.
[0067] For example, the monitoring platform obtains the communication behavior data of each potential risk user in each hour within the preset monitoring days, and at the same time, using hours as the time period, divides the total amount of communication behavior data in each hour by the total number of potential risk users to obtain the average value of the communication behavior data in each hour.
[0068] Compare the communication behavior data of each potential risk user in each hour within the preset monitoring days with the average value of the communication behavior data in the corresponding time period. When the communication behavior data of the potential risk user is greater than the average value, the number of resource excesses is increased by 1, and finally the number of resource excesses of the potential risk user is accumulated.
[0069] The number of resource excess times of each potential risk user is compared with a first preset threshold value preset by an administrator. When the number of resource excess times is greater than the first preset threshold value, the corresponding potential risk user is determined to be a first potential high-risk user.
[0070] Finally, the first potential high-risk users are further screened according to the message information of each first potential high-risk user, and a target number of users with higher risks among the first potential high-risk users are determined as risky activity users.
[0071] This embodiment obtains communication behavior data for each potentially risky user over a preset number of monitoring days, uses this data to further identify the risks of each potentially risky user, and finally filters out risky users based on their message information. This further identification of each potentially risky user through communication behavior data and message information can improve the accuracy of risk assessment.
[0072] As an optional embodiment, after determining that a potential risk user whose resource excess frequency is greater than a first preset threshold is a first potential high-risk user, the method further includes:
[0073] Obtaining a floating value of the communication behavior data of the first potential high-risk user according to the communication behavior data of the first potential high-risk user;
[0074] Obtaining the floating excess times of each first potential high-risk user according to the floating value of the communication behavior data of the first potential high-risk user;
[0075] Determine the potential risk user whose floating excess times are greater than the second preset threshold as a second potential high-risk user;
[0076] Determining risky activity users among the first potential high-risk users based on the message information of each first potential high-risk user specifically includes:
[0077] Based on the message information of each second potential high-risk user, risky activity users are determined among the second potential high-risk users.
[0078] In this embodiment, the communication behavior data floating value is used to represent the ratio of the communication behavior data of the first potential high-risk user in each time period to the communication behavior data in the corresponding time period of the previous day.
[0079] The floating excess times is the counted number of times that the floating value of the communication behavior data of the first potential high-risk user in each time period exceeds the preset floating threshold.
[0080] For example, the monitoring platform obtains the communication behavior data of each first potential risk user at each hour within the preset monitoring days, and then compares the communication behavior data of each time period of the first potential high-risk user with the communication behavior data of the corresponding time period of the previous day, and determines the corresponding ratio as the communication behavior data floating value.
[0081] At the same time, the monitoring platform obtains the startup time and shutdown time of the terminal corresponding to each first potential risk user, determines the time when the terminal corresponding to the first potential risk user is in the shutdown state based on the startup time and shutdown time, eliminates the corresponding time period in which the time in the shutdown state exceeds one hour, and obtains the remaining time period.
[0082] The floating value of the communication behavior data of each first potential risk user in the remaining time period is compared with the preset floating threshold set in advance by the administrator. When the floating value of the communication behavior data of the first potential risk user is greater than the preset floating threshold, the floating excess times are increased by 1, and finally the floating excess times of the potential risk user are accumulated.
[0083] The number of floating excesses of each potential risk user is compared with the total number in the remaining time period. When the number of floating excesses is greater than two-thirds of the total number in the remaining time period, the corresponding potential risk user is determined to be the second potential high-risk user.
[0084] Finally, the second potential high-risk users are further screened according to the message information of each second potential high-risk user, and a target number of users with higher risks among the second potential high-risk users are determined as risky activity users.
[0085] This embodiment obtains the communication behavior data fluctuation value of each first potential high-risk user over a preset number of monitoring days, uses this communication behavior data fluctuation value to further identify the risk of each first potential high-risk user, and finally filters out risky activity users based on message information. Thus, further identifying the risk of each first potential high-risk user based on the communication behavior data fluctuation value can improve the accuracy of risk assessment.
[0086] As an optional embodiment, determining risky activity users among the first potential high-risk users based on the message information of each first potential high-risk user includes:
[0087] Determining activity information of each first potential high-risk user based on message information of each first potential high-risk user within a preset monitoring number of days;
[0088] According to the activity information of each first potential high-risk user, the first potential high-risk user whose activity information is the first risk activity information or the second risk activity information is determined as a risky activity user.
[0089] In this embodiment, the activity information is used to characterize the activity area of the first potential high-risk user within a preset monitoring number of days.
[0090] The first risk activity information is information about activities that are simultaneously within the coverage area of the first base station and the coverage area of the second base station within the preset monitoring days, and the second risk activity information is information about activities that are simultaneously within the coverage area of the first base station and the coverage area of the third base station within the preset monitoring days.
[0091] For example, the monitoring platform determines the activity information of each first potential high-risk user based on the message information of each first potential high-risk user within the preset monitoring days, and finally determines whether the activity information of the first potential high-risk user belongs to the first risk activity information or the second risk activity information. If so, the corresponding first potential high-risk user is determined to be a risk activity user.
[0092] This embodiment determines the corresponding activity information based on the message information of the first potential high-risk user within a preset number of monitoring days. Finally, based on the activity information, it is determined whether the first potential high-risk user is a risky activity user. In this way, based on the activity information corresponding to the first potential high-risk user, further risk identification of the first potential high-risk user can be performed, thereby improving the accuracy of the risk assessment.
[0093] Method for determining users with risky activities. Accordingly, this application also provides a specific embodiment of a device for determining users with risky activities.
[0094] As shown in FIG2 , the apparatus for determining risky activity users provided in an embodiment of the present application includes a base station information acquisition module 210 , a first user determination module 220 , a behavior data acquisition module 230 , and a second user determination module 240 .
[0095] The base station information acquisition module 210 is used to obtain the base station information of each of the first base station, the second base station and the third base station associated with the risk activity area. The first base station is a base station covering at least part of the risk activity area, the second base station is a base station that has the risk of covering at least part of the risk activity area, and the third base station is an adjacent base station of the first base station or the second base station.
[0096] The first user determination module 220 is used to determine at least one potential risk user based on the base station information of each base station among the first base station, the second base station and the third base station. The potential risk user is a user located in the coverage area of at least one base station among the first base station, the second base station and the third base station.
[0097] The behavior data acquisition module 230 is configured to acquire communication behavior data of each potential risk user among at least one potential risk user.
[0098] The second user determination module 240 is configured to determine risky activity users from at least one potential risk user based on the communication behavior data of each potential risk user.
[0099] In this embodiment, the base station information acquisition module 210 acquires base station information for each of the first, second, and third base stations associated with the risk activity area. The first user determination module 220 then identifies at least one potential risk user based on the base station information for each of the first, second, and third base stations. By evaluating and analyzing the base station information, the user's roaming risk is identified. The behavior data acquisition module 230 then acquires communication behavior data for each of the at least one potential risk user. Finally, the second user determination module 240 identifies risky activity users within the at least one potential risk user based on the communication behavior data for each of the potential risk users. By evaluating and analyzing the communication behavior data for the potential risk users, the user's roaming risk is further identified. In this manner, this embodiment of the present application uses base station information and communication behavior data to assess the risk of border roaming for users, fully considering the impact of base station information and communication behavior data on roaming risk and improving the accuracy of border roaming risk assessment.
[0100] As an optional embodiment, the first user determination module 220 includes:
[0101] An information acquisition unit is configured to acquire message information of users within the coverage area of each of the first base station, the second base station, and the third base station within a preset monitoring number of days, where the message information is used to represent base station information in the area where the user is located;
[0102] The first user determination unit is configured to determine, based on message information of each user within the preset monitoring days, users located within the coverage areas of at least two of the first base station, the second base station, and the third base station within the preset monitoring days as potential risk users.
[0103] As an optional embodiment, the second user determination module 240 includes:
[0104] A data acquisition unit is used to acquire the communication behavior data of each potential risk user within a preset monitoring period, where the communication behavior data is used to characterize the use of communication resources by the potential risk user;
[0105] A times acquisition unit is used to obtain the resource excess times of each potential risk user based on the communication behavior data, where the resource excess times are counted as the number of times the communication behavior data of the potential risk user in each time period exceeds the average value;
[0106] A second user determination unit is configured to determine a potential risk user whose number of resource excesses is greater than a first preset threshold as a first potential high-risk user;
[0107] The third user determining unit is configured to determine risky activity users among the first potential high-risk users based on the message information of each first potential high-risk user.
[0108] As an optional embodiment, the second user determination module 240 further includes:
[0109] a floating value acquisition unit, configured to acquire a communication behavior data floating value based on the communication behavior data of the first potential high-risk user, wherein the communication behavior data floating value is used to represent a ratio of the communication behavior data of the first potential high-risk user in each time period to the communication behavior data of the corresponding time period of the previous day;
[0110] The number acquisition unit is further configured to acquire, based on the floating value of the communication behavior data, the floating excess number of each first potential high-risk user, where the floating excess number is the number of times the floating value of the communication behavior data of the first potential high-risk user in each time period exceeds a preset floating threshold;
[0111] a fourth user determination unit, configured to determine a potential risk user whose floating excess times are greater than a second preset threshold as a second potential high-risk user;
[0112] The third user determination unit is further configured to:
[0113] Based on the message information of each second potential high-risk user, risky activity users are determined among the second potential high-risk users.
[0114] As an optional embodiment, the third user determination unit is specifically configured to:
[0115] Determining activity information of each first potential high-risk user based on message information of each first potential high-risk user within a preset monitoring number of days, where the activity information is used to characterize the activity area of the first potential high-risk user within the preset monitoring number of days;
[0116] According to the activity information of each first potential high-risk user, the first potential high-risk user whose activity information is the first risk activity information or the second risk activity information is determined to be a risk activity user, the first risk activity information is the information of the activity being simultaneously within the coverage area of the first base station and the coverage area of the second base station within the preset monitoring days, and the second risk activity information is the information of the activity being simultaneously within the coverage area of the first base station and the coverage area of the third base station within the preset monitoring days.
[0117] FIG3 shows a schematic diagram of the hardware structure of a device for determining borderline risk users provided in an embodiment of the present application.
[0118] The device for determining borderline risk users may include a processor 301 and a memory 302 storing computer program instructions.
[0119] Specifically, the processor 301 may include a central processing unit (CPU), or an application-specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0120] The memory 302 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 302 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 302 may include removable or non-removable (or fixed) media. Where appropriate, the memory 302 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 302 is a non-volatile solid-state memory.
[0121] The memory may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0122] The processor 301 reads and executes computer program instructions stored in the memory 302 to implement any one of the methods for determining borderline risk users in the above embodiments.
[0123] In one example, the device for determining borderline risk users may further include a communication interface 303 and a bus 310. As shown in FIG3, the processor 301, the memory 302, and the communication interface 303 are connected via the bus 310 and communicate with each other.
[0124] The communication interface 303 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0125] Bus 310 includes hardware, software or both, and the parts of the determination equipment of border risk user are coupled to each other.For example, and not limitation, bus can include accelerated graphics port (AGP) or other graphics bus, enhanced industry standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industry standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations.In suitable cases, bus 310 can include one or more buses.Although the present application embodiment describes and shows specific bus, the application considers any suitable bus or interconnection.
[0126] In addition, in conjunction with the methods for determining borderline risk users in the above embodiments, embodiments of the present application may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when executed by a processor, the computer program instructions implement any of the methods for determining borderline risk users in the above embodiments.
[0127] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.
[0128] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memories, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0129] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0130] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor or a field programmable logic circuit. It is also understood that each box in the block diagram and / or flowchart and the combination of the boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0131] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.
Claims
1. A method for determining a user of risky activities, comprising: Acquire base station information of each of a first base station, a second base station, and a third base station associated with a risk activity area, wherein the first base station is a base station covering at least a portion of the risk activity area, the second base station is a base station that has a risk of covering at least a portion of the risk activity area, and the third base station is an adjacent base station of the first base station or the second base station; Determine at least one potential risk user based on base station information of each of the first base station, the second base station, and the third base station, where the potential risk user is a user located in a coverage area of at least one of the first base station, the second base station, and the third base station; Acquiring communication behavior data of each of the at least one potential risk user; Based on the communication behavior data of each of the potential risk users, risky activity users are determined among the at least one potential risk user.
2. The method according to claim 1, wherein: The determining at least one potential risk user based on the base station information of each of the first base station, the second base station, and the third base station includes: Acquire message information of users within the coverage area of each of the first base station, the second base station, and the third base station within a preset monitoring number of days, where the message information is used to represent base station information in the area where the user is located; According to the message information of each user within the preset monitoring days, it is determined that the users located in the coverage areas of at least two base stations among the first base station, the second base station and the third base station within the preset monitoring days are potential risk users.
3. The method according to claim 1, wherein: The determining of risky activity users among the at least one potential risk user based on the communication behavior data of each potential risk user comprises: Acquire communication behavior data of each of the potential risk users within a preset monitoring number of days, wherein the communication behavior data is used to characterize the use of communication resources by the potential risk users; According to the communication behavior data, the resource excess times of each potential risk user are obtained, and the resource excess times are the communication behaviors of the potential risk user in each time period. The count of the number of times the data exceeds the mean; Determine the potential risk user whose resource excess times are greater than a first preset threshold as a first potential high-risk user; Based on the message information of each of the first potential high-risk users, risky activity users are determined among the first potential high-risk users.
4. The method according to claim 3, wherein: After determining that the potential risk user whose resource excess times is greater than the first preset threshold is a first potential high-risk user, the method further includes: According to the communication behavior data of the first potential high-risk user, a communication behavior data floating value is obtained, wherein the communication behavior data floating value is used to represent the ratio of the communication behavior data of each time period of the first potential high-risk user to the communication behavior data of the corresponding time period of the previous day; According to the communication behavior data floating value, obtaining the floating excess times of each of the first potential high-risk users, the floating excess times being the counted times of the situations where the communication behavior data floating value of each time period of the first potential high-risk user exceeds a preset floating threshold; Determine the potential risk user whose floating excess times are greater than a second preset threshold as a second potential high-risk user; The determining risky activity users among the first potential high-risk users based on the message information of each of the first potential high-risk users includes: Based on the message information of each of the second potential high-risk users, risky activity users are determined among the second potential high-risk users.
5. The method according to claim 3, wherein: The determining risky activity users among the first potential high-risk users based on the message information of each of the first potential high-risk users includes: Based on the message information of each of the first potential high-risk users within the preset monitoring days, determining the activity information of each of the first potential high-risk users, wherein the activity information is used to characterize the activity area of the first potential high-risk users within the preset monitoring days; According to the activity information of each of the first potential high-risk users, the first potential high-risk user whose activity information is the first risk activity information or the second risk activity information is determined as a risk activity user, and the first risk activity information is a user who is simultaneously on the first base within a preset monitoring number of days. The second risk activity information is information about activities within the coverage area of the first base station and the coverage area of the second base station within a preset monitoring number of days.
6. A device for determining a borderline risk user, comprising: A base station information acquisition module, used to acquire base station information of each of a first base station, a second base station, and a third base station associated with a risk activity area, wherein the first base station is a base station covering at least a portion of the risk activity area, the second base station is a base station that has a risk of covering at least a portion of the risk activity area, and the third base station is an adjacent base station of the first base station or the second base station; A first user determination module, configured to determine at least one potential risk user based on base station information of each of the first base station, the second base station, and the third base station, wherein the potential risk user is a user located in a coverage area of at least one of the first base station, the second base station, and the third base station; A behavior data acquisition module, used to acquire communication behavior data of each of the at least one potential risk user; The second user determination module is used to determine risky activity users among the at least one potential risk user based on the communication behavior data of each of the potential risk users, wherein the risky activity users are users identified as having risky activities.
7. The device according to claim 6, wherein: The first user determination module includes: an information acquisition unit, configured to acquire message information of users within the coverage area of each of the first base station, the second base station, and the third base station within a preset monitoring number of days, wherein the message information is used to characterize base station information of an area where the user is located; The first user determination unit is used to determine, based on message information of each user within a preset monitoring number of days, that users located in coverage areas of at least two of the first base station, the second base station and the third base station within the preset monitoring number of days are potential risk users.
8. The device according to claim 6, wherein: The second user determination module includes: A data acquisition unit, used to acquire the communication behavior data of each of the potential risk users within a preset monitoring number of days, wherein the communication behavior data is used to characterize the use of communication resources by the potential risk users; A times acquisition unit, used to acquire the resource excess times of each of the potential risk users according to the communication behavior data, wherein the resource excess times are counted times when the communication behavior data of the potential risk users exceeds the average value in each time period; A second user determination unit, configured to determine a potential risk user whose resource excess times are greater than a first preset threshold as a first potential high-risk user; The third user determination unit is configured to determine risky activity users among the first potential high-risk users based on the message information of each of the first potential high-risk users.
9. An electronic device, comprising: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, the method for determining users of risky activities as described in any one of claims 1-5 is implemented.
10. A computer-readable storage medium having computer program instructions stored thereon, wherein the computer program instructions, when executed by a processor, implement the method for determining users of risky activities as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Super-service scene early warning method and system for Internet of Things prevention and control
CN111328021A
User identification method and device, electronic equipment and storage medium
CN117041934A
Risk area determination in communication network
US20190149566A1
Communication device, communication system, connection destination control method, and transmission rate control method
US20200187083A1
Radio communication system, radio communication method, and radio communication device
WO2023067813A1