Malicious Call Recognition via Behavioral Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing malicious call recognition methods are ineffective in identifying calls modified by lawbreakers to evade blacklist phone numbers, resulting in low accuracy in recognizing malicious calls.

Innovation Solution

A method and apparatus that utilize call detail record information to match with malicious models in a preset library, determining a call as malicious if it matches a defined malicious call event, even if the caller has modified their number.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If phone number blacklist matching is used to identify malicious calls, then the recognition method is simple and fast, but the recognition accuracy deteriorates when lawbreakers modify their phone numbers

Engineering Contradiction:
Improverecognition method simplicityVSAvoidmalicious call recognition accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent segments the malicious call recognition process into multiple independent analysis dimensions: call frequency analysis, call time pattern analysis, call duration analysis, and phone number modification detection. Each dimension is evaluated separately and then综合 to determine if a call is malicious, allowing the system to maintain simplicity while improving accuracy through multi-faceted analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the recognition parameters from solely relying on phone number matching to including call frequency, call time patterns, call duration, and other behavioral parameters. By monitoring changes in these parameters over time, the system can identify malicious calls even when the phone number has been modified, thus resolving the contradiction between simplicity and accuracy.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If phone number modification detection is implemented, then the malicious call recognition accuracy improves, but the device complexity increases

Engineering Contradiction:
Improvemalicious call recognition accuracyVSAvoidrecognition system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing a blacklist of known malicious phone numbers and pre-defining malicious call patterns and thresholds. When a call is detected, the system first checks against the pre-configured blacklist and patterns before conducting detailed analysis, which simplifies the real-time processing complexity while maintaining high recognition accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs self-service mechanisms by automatically learning from new malicious call patterns and updating its detection models without requiring manual intervention. The system autonomously adjusts detection thresholds and adds new malicious number patterns to the blacklist, reducing the operational complexity of maintaining the recognition system while improving its accuracy over time.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9813538B2Malicious call recognition method and apparatus
Publication Date: 2017.11.07 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US9813538B2 patent drawing
  • US9813538B2 patent drawing
  • US9813538B2 patent drawing

AI summary

Embodiments of the present disclosure disclose a malicious call recognition method and apparatus, and belong to the field of mobile communication. The method includes: obtaining call detail record information of the call when a local end makes a call to a peer end, the call detail record information of the call including a call record of the local end within first preset duration that is closest to current time, and/or a call record of the peer end within the first preset duration that is closest to the current time; matching the call detail record information of the call with a malicious model corresponding to a malicious call event included in a preset malicious model library; and determining the call to be a malicious call if the malicious model that matches with the call detail record information of the call is found.