CN101557441A - Method and device for call filtering - Google Patents

Method and device for call filtering Download PDF

Info

Publication number
CN101557441A
CN101557441A CNA200910140813XA CN200910140813A CN101557441A CN 101557441 A CN101557441 A CN 101557441A CN A200910140813X A CNA200910140813X A CN A200910140813XA CN 200910140813 A CN200910140813 A CN 200910140813A CN 101557441 A CN101557441 A CN 101557441A
Authority
CN
China
Prior art keywords
calling party
credit value
conversation
call
conversation behavior
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CNA200910140813XA
Other languages
Chinese (zh)
Other versions
CN101557441B (en
Inventor
孟健
Original Assignee
Huawei Symantec Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Symantec Technologies Co Ltd filed Critical Huawei Symantec Technologies Co Ltd
Priority to CN200910140813XA priority Critical patent/CN101557441B/en
Publication of CN101557441A publication Critical patent/CN101557441A/en
Application granted granted Critical
Publication of CN101557441B publication Critical patent/CN101557441B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Telephonic Communication Services (AREA)

Abstract

The embodiment of the invention provides a method and a device for call filtering, which realize call filtering by conducting dynamic management to a black list and a white list. The device comprises a call detecting unit used for detecting the call behavior pattern of a calling party, a reputation value calculating unit used for generating the current reputation value of the calling party according to the call behavior pattern, a black list and white list determining unit used for recording the calling party in the white list when the generated reputation value is larger than a threshold value or recording the calling party in the black list when the generated reputation value is smaller than the threshold value, and a call filtering unit used for filtering calls according to the black list or the white list information determined by the black list and white list determining unit. The device and the method can improve the efficiency and accuracy of spam call detection and realize the automatic updating of the black list and the white list.

Description

The call filtering method and apparatus
Technical field
The present invention relates to communication technical field, particularly a kind of call filtering method and apparatus.
Background technology
Along with the develop rapidly of VoIP, the low-cost characteristic of voip phone has been grown spreading unchecked of call spam.Call spam is defined as a large amount of call request that normal users does not wish to receive or that have nothing to do with the user, its objective is that expectation and called party set up multimedia communication, carry out activities such as advertising, distribution or swindle to the user by multimedia messagess such as text, audio or videos, be beneficial to the call spam producer and therefrom obtain considerable commercial profit.
Go up filling the air of call spam and wreak havoc in order to control VoIP, a solution of prior art is: all adopted on mobile communication terminal and communication server end and a kind ofly carried out the filtration of call spam based on static dark white list technology.For example, the call spam filter software is installed on intelligent terminal, but these softwares generally all are to use static dark white list technology, only allow the user manually to add black and white lists and attended operation such as deletion according to self actual conditions, black and white lists maintenance update difficulty and flexibility are not enough.Again for example, operator has taked limited call spam interception measure at server end, at first by bad URL network address or the address that sends spam are in a large number carried out sorting-out in statistics to set up so-called blacklist, then at server end by matching algorithm, these bad URL network address are filtered or to intercepting junk mail; And for some important URL addresses, for example government website, Web bank etc. or be defined as normal mail and send the address, set up a white list by server end, by finding to be in URL or the addresses of items of mail in the white list after mating, unconditionally let pass for the behavior that they are correlated with.The characteristics of this method are that the foundation of black and white lists is added by artificial judgement and deleted to upgrade, and this technology is called static dark white list technology.
Another kind of solution is in the existing skill: statistics is called out the number of times that reciever is reported call initiator, again according to the result and the threshold of adding up, to upgrade black and white lists.
The inventor finds that in realizing process of the present invention there is following problem in prior art: static dark white list technology is simple and easy to usefulness, is not under the very high situation but be only applicable to small and ageing requirement that black and white lists upgrades.And for call spam producer (spammer) black and white lists at server end, static dark white list technology exposes many deficiencies: lack flexibility; Black and white lists is set up and is difficult in maintenance.Report that according to the user also there are many shortcomings in the technical scheme of upgrading black and white lists: for example have the risk of calling out reciever malice report call initiator, also lack normal users by the mechanism of remedying after judging by accident simultaneously.
Summary of the invention
The embodiment of the invention provides a kind of call filtering method and apparatus, realizes dynamically updating black and white lists, improves the flexibility and the accuracy of call filtering.
On the one hand, the embodiment of the invention provides a kind of call filtering device, and described device comprises: the conversation detecting unit is used to detect calling party's conversation behavior pattern; The credit value computing unit is used for generating the current credit value of calling party according to calling party's conversation behavior pattern; The black and white lists determining unit is used for when the credit value that generates during greater than a threshold value described calling party being recorded in white list; When the credit value that generates during, described calling party is recorded in blacklist less than a threshold value; The call filtering unit is used for according to blacklist or white list information that described black and white lists determining unit is determined conversation being filtered.
On the other hand, the embodiment of the invention also provides a kind of call filtering method, and described method comprises: the conversation behavior pattern that detects the calling party; Conversation behavior pattern according to the calling party generates the current credit value of calling party; When the credit value that generates during, described calling party is recorded in white list greater than a threshold value; Maybe, described calling party is recorded in blacklist when the credit value that generates during less than a threshold value; According to described blacklist or white list information conversation is filtered.
The call filtering method and apparatus of the embodiment of the invention owing to introduced the credit value computing unit, quantizes thereby can carry out credit value to calling party's conversation behavior, and being beneficial to us can judge whether it is the call spam producer according to calling party's credit value.The call filtering method and apparatus of the embodiment of the invention is by comparing calling party's credit value and prestige threshold value, the automatic renewal and the Dynamic Maintenance of black and white lists have been realized, increase real-time, high efficiency and flexibility that black and white lists is set up and upgraded simultaneously, overcome inconvenience of static dark white list updating and defective difficult in maintenance in the prior art.The call filtering method and apparatus of the embodiment of the invention by detecting calling party's behavior pattern, has improved the accuracy that call spam detects, and reduces the probability of failing to report and reporting by mistake.
Description of drawings
Fig. 1 is the allomeric function block diagram of the call filtering device of the embodiment of the invention;
Fig. 2 is the holistic approach flow chart of the call filtering method of the embodiment of the invention;
Fig. 3 is the concrete function block diagram of the call filtering device of the embodiment of the invention 1;
Fig. 4 is the specific implementation flow chart one of the call filtering method of the embodiment of the invention 2;
Fig. 5 is the specific implementation flowchart 2 of the call filtering method of the embodiment of the invention 3;
Fig. 6 is the specific implementation flow chart 3 of the call filtering method of the embodiment of the invention 4.
Embodiment
In order to make the clear more and easy to understand of the object of the invention, feature, advantage, the specific embodiment of the present invention is done detailed explanation and elaboration below with reference to accompanying drawing.
Fig. 1 is the allomeric function block diagram of the call filtering device of the embodiment of the invention.The call filtering device can be a for example VoIP security gateway in one embodiment of this invention.As shown in Figure 1, the call filtering device 10 of the embodiment of the invention comprises conversation detecting unit 11, credit value computing unit 12, black and white lists determining unit 13 and call filtering unit 14.The conversation detecting unit 11 of the call filtering device 10 of the embodiment of the invention is used to detect calling party's conversation behavior pattern; Credit value computing unit 12 is used for generating the current credit value of calling party according to calling party's conversation behavior pattern; Black and white lists determining unit 13 is used for when the credit value that generates during greater than a threshold value described calling party being recorded in white list; Maybe, described calling party is recorded in blacklist when the credit value that generates during less than a threshold value; Call filtering unit 14 is used for according to described blacklist or white list information conversation being filtered.
Fig. 2 is the holistic approach flow chart of the call filtering method of the embodiment of the invention.As shown in Figure 2, the call filtering method of the embodiment of the invention comprises the steps:
Step S101, detection calling party's conversation behavior pattern;
Step S102, generate the current credit value of calling party according to calling party's conversation behavior pattern;
Step S103, when the credit value that generates during greater than a threshold value, described calling party is recorded in white list; Perhaps, described calling party is recorded in blacklist when the credit value that generates during less than a threshold value;
Step S104, the blacklist or the white list information that generate according to described step S103 are filtered conversation.
Can only definite blacklist in the practical application or only determine white list, perhaps determine blacklist and white list simultaneously.When only determining a list, then come conversation is filtered according to this list.
Embodiment 1:
The embodiment of the invention 1 provides a kind of call filtering device, quantizes to realize dynamically updating of black and white lists by calling party's unusual conversation behavior pattern is carried out credit value.
Fig. 3 is the concrete function block diagram of the call filtering device of the embodiment of the invention 1, as shown in Figure 3, a kind of call filtering device 10 of the embodiment of the invention 1 comprises: conversation detecting unit 11, credit value computing unit 12, black and white lists determining unit 13, call filtering unit 14, initial credit value setup unit 15.Below will describe the function of each unit and the course of work of passing through filter 10 of the embodiment of the invention in detail.
See also Fig. 3, initial credit value setup unit 15 is used to the calling party to set initial credit value.Alternatively, prescribe a time limit, can set initial credit value and be aforementioned the two mean value when being provided with under a default prestige upper threshold and the default prestige threshold value.Alternatively, in other is used, also can not comprise this unit by filter 10.
Conversation detecting unit 11 is used to detect calling party's conversation behavior pattern.In the present embodiment, conversation detecting unit 11 when detecting calling party's conversation behavior pattern, detects unusual conversation behavior appears in the calling party in default talk times probability.Calling party's contingent unusual conversation behavior pattern in default talk times includes but are not limited to: in short-term call mode, short conversation interval mode, call out non-existent user model, calling and called and concern unbalanced mode, third party call pattern, bell mode etc. in short-term.The explanation of every kind of unusual call mode and computation rule thereof will be described in detail in embodiment 2, wouldn't describe in detail at this.
Credit value computing unit 12, the credit value that reduces according to calling party's unusual conversation behavior probability calculation calling party.In the present embodiment: as calling party during in existing above-mentioned any one the unusual conversation behavior pattern of default talk times, calculate the probability P s of calling party according to its corresponding probability calculation rule for call spam, calculate the credit value that it is lowered: C=Ps*Ps (Hu-Hd)/2 according to following formula again, wherein C sends the credit value that is lowered after the abnormal behaviour pattern for the calling party in default talk times, Ps is the probability of call spam for the calling party, Hu is default prestige upper threshold, and Hd is default prestige threshold value lower limit.For different application, also can adopt other computing formula, for example also can satisfy linear function relation between C and the Ps, only need guarantee that C increases with the increase of Ps to get final product.The credit value C that credit value computing unit 12 deducts the original credit value of calling party reduction again generates the current credit value of calling party.
In the present embodiment, credit value computing unit 12, be further used for when unusual conversation behavior in default talk times, not occurring, calling party's credit value increased a constant, and the original credit value of calling party is added that the credit value of increase generates the current credit value of calling party.Owing to be incorporated in credit value rewards and punishments or increase and decrease mechanism; calling party's credit value can little by little be improved along with the normalization of its behavior of conversing; thereby make the calling party of blacklist might enter in the white list; and along with the calling party converse behavior deterioration and be adjusted in the blacklist; so just realize the automatic renewal of black and white lists, reduced the complexity that black and white lists is safeguarded.
Black and white lists determining unit 13, relatively current credit value of calling party and default prestige upper threshold Hu and default prestige threshold value lower limit Hd are if the current credit value of the calling party who generates during greater than Hu, is recorded in white list with the calling party; When the credit value that generates during, the calling party is recorded in blacklist less than Hd.Alternatively, in other embodiments, also can only preset a prestige threshold value H, black and white lists determining unit 13, compare current credit value of caller and default prestige threshold value H, when calling party's current credit value during, the calling party is recorded in the white list, otherwise then the calling party is recorded in the blacklist greater than H.Alternatively, present embodiment also comprises the memory cell (not shown), is used to store described blacklist or described white list.Alternatively, the current credit value of calling party can be stored in the memory cell.
Call filtering unit 14 is used for according to blacklist or white list information conversation being filtered; In the present embodiment, have blacklist and white list simultaneously, in this case, the calling party's of mating with white list call request is transmitted in the call filtering unit 14 of the embodiment of the invention 1, and the call request of filtration and blacklist coupling.In other is used, also blacklist or white list can only be arranged, in this case, the call filtering device of the embodiment of the invention 1 also can normal operation, and for example: when only white list being arranged, call filtering unit 14 is judged when whether the calling party has been recorded in white list, if, then transmit calling party's call request, if not, then calling party's call request is implemented to filter; When only blacklist being arranged, judge by filter element 14 whether the calling party is recorded in the blacklist, if, then calling party's call request is implemented to filter, if not, then transmit calling party's call request.
Can only definite blacklist in the practical application or only determine white list, perhaps determine blacklist and white list simultaneously.When only determining a list, then come conversation is filtered according to this list.
In another embodiment, its difference is, conversation detecting unit 11, the process that detects calling party's probability of the unusual conversation behavior of appearance in default talk times detects for two kinds of unusual conversation behaviors that the calling party is occurred in default talk times at least, generate the probability of every kind of unusual conversation behavior, and according to the comprehensive many conditional probabilities that generate unusual conversation behavior of the probability of every kind of unusual conversation behavior.Credit value computing unit 12 calculates the credit value that the calling party reduces according to many conditional probabilities, and the original credit value of calling party is deducted the current credit value of credit value generation calling party of reduction.
In another embodiment, its difference is, conversation detecting unit 11, and the report information that is used to receive the user generates unusual conversation behavior appears in the calling party in default talk times probability.
The call filtering device of the embodiment of the invention 1, owing to be based on the abnormal behaviour pattern analysis of call spam, and quantize in conjunction with credit value, therefore improve accuracy and reasonability that call spam detects, reduced the probability of failing to report and reporting by mistake; Owing to adopted more rules credit value algorithm based on multiple call spam conversation behavior pattern, can dynamically adjust black and white lists based on credit value, realize the automatic renewal of black and white lists, solved automatic renewal and two hang-ups difficult in maintenance; Owing to introduced artificial report mechanism based on the credit value computation rule, thereby can increase the enforcement difficulty of artificial malice report effectively, and both made and judge by accident, also can remedy by the method for adjusting credit value, improved the flexibility that black and white lists is safeguarded.
Embodiment 2:
The embodiment of the invention 2 is by detecting the conversation behavior pattern of caller in default talk times; and with its normally or unusually the conversation behavior carry out credit value quantizes and credit value increases and decreases dynamic adjustment (credit value be high more; expression calling party's conversation behavior is normal more; credit value is low more; the expression calling party probably is a call spam); the credit value threshold range of current credit value in matches caller side and black and white lists to be realizing dynamically updating of black and white lists again, thereby realizes call filtering to call spam according to the information of black and white lists.
Fig. 4 is the specific implementation flow chart one of the call filtering method of the embodiment of the invention 2.As shown in Figure 4, the call filtering method of the embodiment of the invention comprises the steps:
Step S201, the conversation behavior of detection calling party in default talk times;
Step S202, judge that the calling party has no abnormal conversation behavior in default talk times, if unusual conversation behavior is arranged, then execution in step S203 is to step S205, if no abnormal conversation behavior then execution in step S206 to step S207;
The probability of step S203, the unusual conversation behavior of calculating calling party in default talk times, promptly the calling party is the probability of call spam;
Step S204, according to the credit value that calling party's unusual conversation behavior probability calculation calling party reduces, its probability is big more, the credit value of reduction is many more;
Step S205, the credit value that the original credit value of calling party is deducted reduction generate the current credit value of calling party;
Step S206, calling party's credit value is increased a credit value constant;
Step S207, the original credit value of calling party is added that the credit value of increase generates the current credit value of calling party;
Equal execution in step S208 after step S205 and the step S207;
Current credit value and preset threshold value scope that step S208, comparison calling party generate compare credit value and the preset threshold value scope that generates,
Prescribe a time limit greater than going up of preset threshold value scope when the credit value of generation, then execution in step S209 is not more than upward prescribing a time limit of preset threshold value scope, then execution in step S211 to step S210 as the credit value that generates;
Step S209, calling party and credit value thereof are stored in the white list;
Step S210, call filtering device are transmitted the calling party's of mating with white list call request;
Step S211, judge current credit value that the calling party generates whether less than the lower limit of threshold range, in this way then execution in step S212 to step S213, as otherwise execution in step S214 to step S215;
Step S212, caller and credit value thereof are stored in the blacklist;
The calling party's of step S213, the filtration of call filtering device or interception and blacklist coupling call request;
Step S214, calling party and credit value thereof are stored in the gray list;
Step S215, call filtering device are transmitted the calling party's of mating with gray list call request.Alternatively, step S215 can also wait other processing for: call filtering device carries out turing test (Turing Test) to the calling party with the gray list coupling earlier, has only by turing test etc. when other are handled, and just transmits calling party's call request.
Alternatively, in other of the embodiment of the invention 2 are used, can judge earlier that also current credit value that the calling party generates is whether less than the lower limit of threshold range; Alternatively, also can make the threshold range upper limit equal the threshold range lower limit, promptly have only a credit value threshold value, be stored in the white list greater than the calling party of this threshold value, otherwise then be stored in the blacklist, this moment, gray list was optional; Can only definite blacklist in the practical application or only determine white list, perhaps determine blacklist and white list simultaneously.When only determining a list, then come conversation is filtered according to this list.Alternatively, step S202 also can be for judging that the unusual conversation behavior of calling party in default talk times is whether in the tolerance or deviation range a permission, the conversation behavior of then representing the calling party in this way is normal, as otherwise the expression calling party the conversation abnormal behavior.
The specific implementation flow process of the call filtering method of the following illustrated in greater detail embodiment of the invention 2.Calling party's contingent unusual conversation behavior pattern in default talk times includes but are not limited to: in short-term call mode (as, the call mode in short-term that the callee is initiatively hung up), short conversation interval mode, call out non-existent user model, calling and called and concern unbalanced mode, third party call pattern, bell mode etc. in short-term.
Mechanism and corresponding call spam probability calculation rule that above-mentioned unusual call mode produces below will be described.
1, call mode in short-term.In call mode in short-term, be user and unwanted information because call spam propagates, therefore after normal users was answered, just can judge it in a rational time range was a call spam, then it is hung up.Exception is also arranged certainly, and the information that call spam is propagated is that it is needed for the certain user, thereby can be before call spam is finished the information transmission, initiatively on-hook.In this case, we just are judged to be this call spam session once conversation normally, because it provides required information to the called subscriber, do not bother the called subscriber.Another situation is that the communication between the normal users for some reason, just is through with in very short time, like this situation that will occur reporting by mistake.But the number of times that this number of times of conversation in short-term of normal users generation occurred in its significant period of time should be limited.And for a real call spam producer, Tong Hua number of times is very high in the ratio of its all talk times in short-term.Therefore a proportion threshold value can be set, when the ratio of conversation in short-term judges then that above this proportion threshold value the calling party is in the unusual call mode.
Tong Hua call spam probability can calculate according to following formula in short-term: the number of times/default talk times of P (S|a)=in short-term conversation.In the call mode in short-term that the callee is initiatively hung up, the calling party for the probability of call spam is: the number of times of conversation in short-term that P (the S|b)=called active is hung up/default conversation time interior number of times of conversation in short-term.
2, short conversation interval mode.In short conversation interval mode, call spam producer Spammer is in order there to be its information of effect spread, need continuously converse, so Spammer can make a call to the another one user in the very short time interval after last once end of conversation.Inventor's research draws in short conversation interval mode, because air time gap size obeys index distribution, so can set a threshold value t0, if twice conversation interval T is less than t0, judge that then conversation this time is short conversation interval mode, in this pattern, the calling party for the computation rule of the probability of call spam is: P (S|c)=P (T<t0) or P (S|c)=short time every talk times/default talk times.
3, call out non-existent user model.In calling out non-existent user model, Spammer just needs constantly to enlarge its contact list in order its information to be propagated to more user, collects user's contact method by various means.Time and fund can be collected abundant customer contact mode but this mode need cost a lot of money.Thereby a Spammer may send call spam to certain customers by the way of structure contact method.As: the user in the tel mode in certain interval, the user in sip in certain territory of structure.In this case, Spammer can often call out those non-existent users.Based on above-mentioned analysis, it is that the probability of spam call is number of times/default talk times that there is not the user in P (S|d)=calling that the inventor draws under this pattern described calling.
4, calling and called concern unbalanced mode.Concern in the unbalanced mode that at calling and called because in the conversation procedure between any two normal users, any one party all might make a call or on-hook immediately at random.We can be in the session, and wherein a side initiatively makes a call and is considered as a chance event.And any twice calling all is independent identically distributed incident, therefore can be subordinate to not Buddhist one Laplce's central-limit theorem to its application, and the probability Mathematical Modeling that draws its call event is a standardized normal distribution model.In like manner, onhook event is also obeyed standardized normal distribution.Therefore set one and the rational deviation range of its probability statistics mean value.If exceed this scope, then look it and exceeded normal relational model.Suppose that its reasonable deviate is D, the deviate that current detection goes out is D0>D, thus the calling party for the probability of call spam be P (S|e)=P (| D0>D).
5, third party call pattern.In the third party call pattern, Spammer sets up a high-performance multimedia server in order to improve its information propagation efficiency, and this server can be finished the multimedia communication to a lot of users simultaneously.Spammer, then transfers to the session of normal users on the multimedia server if normal users is answered by initiating the third party call normal users, diffuses information to normal users.Therefore after such call spam sends the 200K sip message of agreeing to answer the user, will called session be transferred on the multimedia server and then to the called REFERENCE message of sending.
Therefore in this unusual call mode, the calling party for the probability of call spam is: P (S|f)=calling party initiatively sends the number of times/calling party who calls out and send subsequently the REFFERENCE request and initiatively sends in default talk times and call out and number of times that the other side replys.
6, bell mode in short-term.In this pattern, Spammer dials user's phone, hangs up the telephone after hearing bell ring at once.If user's clawback will be transferred to the session of normal users on the multimedia server, perhaps have special sales force and diffuse information to the user, in some cases, the phone of this type of clawback might cause the huge telephone expenses loss of user.Therefore and then such call spam can cancel session to the called Cancel message of sending after receiving that the user sends the 180Ring message of jingle bell.In this call mode, the calling party for the computation rule of call spam promoter's probability is: the number of times/default talk times of P (S|g)=in short-term jingle bell.
When above-mentioned any one unusual conversation behavior pattern has taken place the calling party, all can draw calling party's unusual conversation behavior probability according to above-mentioned call spam probability calculation rule in default talk times.Below will illustrate and how its unusual conversation behavior probability will be converted into the credit value that the calling party loses.
For example: alternatively, can utilize following formula to calculate the credit value that the calling party is lowered: C=Ps*Ps (Hu-Hd)/2, wherein C sends the credit value that is lowered after the abnormal behaviour pattern for the calling party in default talk times, Ps is the probability of call spam for the calling party, Hu is the higher limit of threshold range, and Hd is the lower limit of prestige scope.For different application, also can adopt other computing formula, for example also can satisfy linear function relation between C and the Ps, only need guarantee that C increases with the increase of Ps to get final product.
Afterwards, the original credit value of calling party is deducted the current credit value of credit value generation calling party of reduction; The credit value and the preset threshold value scope that generate are compared, prescribe a time limit greater than going up of described threshold range, described calling party and credit value thereof are stored in white list when the credit value that generates; Prescribe a time limit less than the following of described threshold range when the credit value that generates, described calling party and credit value thereof are stored in blacklist; According to the black and white lists information of storage conversation is filtered at last.
When unusual conversation behavior does not take place in the calling party in default talk times or a small amount of unusual conversation behavior in allowed band has taken place, the conversation behavior that can assert the calling party is normal, therefore the credit value that should increase the calling party is as a means of award, and the credit value of increase can be a constant T.Alternatively, if the calling party has unusual conversation behavior in last one group of default talk times, the credit value of its minimizing is C, and the calling party does not have unusual conversation behavior in default talk times subsequently, the credit value of its increase is T, then can establish T/C=1/5.So just mean that the call spam producer need keep the normal talking pattern just can remedy the credit value of its loss in the default talk times subsequently 5 groups, like this, just improved the cost that the call spam producer carries out spam call, can better suppress or filtering junk telephones.
The call filtering method of the embodiment of the invention 2 quantizes in conjunction with credit value owing to be based on the abnormal behaviour pattern analysis of call spam, has therefore improved accuracy and reasonability that call spam detects, has reduced the probability of failing to report and reporting by mistake; Because the calling party has been introduced credit value review system, can carry out credit value to calling party's unusual conversation behavior pattern and quantize simultaneously, help more catching and location call spam producer; Owing to be incorporated in credit value rewards and punishments or increase and decrease mechanism, calling party's credit value can little by little be improved along with the normalization of its behavior of conversing, thereby make the calling party of blacklist might enter in the white list, and along with the calling party converse behavior deterioration and be adjusted in the blacklist, so just realize the automatic renewal of black and white lists, reduced the complexity that black and white lists is safeguarded; Because credit value plus-minus rule has strengthened the credit value deduction dynamics to unusual conversation behavior, has therefore improved the cost that call spam system person converses unusually greatly; The logical filtering method that lives through of the embodiment of the invention 2 is not only applicable to voip network, can also be applied to other voice communication networks, for example PSTN, GSM, WCDMA, TD-SCDMA etc.
Embodiment 3:
The embodiment of the invention 3 is calculated many conditional probabilities by detecting calling party's simultaneous multiple unusual conversation behavior in default talk times, calculate the credit value that the calling party reduces according to many conditional probabilities again, to generate the current credit value of calling party, mate itself and credit value threshold range again to realize dynamically updating of black and white lists, carry out call filtering according to the information of black and white lists at last.
Fig. 5 is the specific implementation flowchart 2 of the call filtering method of the embodiment of the invention 3.As shown in Figure 5, the call filtering method of the embodiment of the invention comprises the steps:
Step S301, the multiple unusual conversation behavior that the calling party is occurred in default talk times detects, and generates the probability of every kind of unusual conversation behavior, and generates many conditional probabilities of unusual conversation behavior according to the probability of multiple unusual conversation behavior;
Step S302 calculates the credit value that the calling party reduces according to described many conditional probabilities, and the original credit value of calling party is deducted the current credit value of credit value generation calling party of reduction;
Step S303 compares credit value and the preset threshold value scope that generates, and prescribes a time limit greater than going up of described threshold range when the credit value that generates, and described calling party and credit value thereof are stored in white list; Prescribe a time limit less than the following of described threshold range when the credit value that generates, described calling party and credit value thereof are stored in blacklist;
Step S304 filters conversation according to the black and white lists information of storage.
Alternatively, the call filtering method of the embodiment of the invention can also comprise:
Step S300, set initial credit value for the calling party; In the present embodiment, when the calling of setting up a new black and white lists or calling party is filtered by the call filtering device of the embodiment of the invention for the first time, need set an initial credit value to the calling party, alternatively, the intermediate value that this initial credit value can be set is threshold range; Alternatively, initial credit value also can be set to any numerical value between credit value higher limit and the credit value lower limit.Present embodiment helps fast and effeciently setting up the black and white lists database after having introduced the initial credit value step of setting.
The specific implementation flow process of the call filtering method of the following illustrated in greater detail embodiment of the invention 3.For example 3 kinds of unusual conversation behaviors have appearred in the calling party in default talk times: short conversation interval mode, calling and called concern unbalanced mode and third party call pattern.
When above-mentioned three kinds of behavior patterns have appearred in the calling party in default talk times, establish under the situation of any one generation in the abnormal behaviour pattern, this call out for the probability of call spam be P (S|x); Wherein x represents one of above-mentioned feature, and as this time calling out to the probability of call spam is P (S|a) under the situation about taking place at a, the number of times that takes place in default talk times is a1.Under the situation that a plurality of abnormal behaviour patterns all take place, can calculate many conditional probabilities according to certain algorithm.Promptly be provided with n incident x1, x2 ... xn takes place, and the number of times that takes place in default talk times is respectively n1, n2 ... nn, then this calls out to the probability of call spam is Ps, and
Ps = Σ ( P ( S | xi ) * ni ) Σni
It will be appreciated by those skilled in the art that the aforementioned calculation method is not unique, only as an example with the explanation present embodiment.
After utilizing above-mentioned many conditional probabilities computing formula to draw the probability of calling party for call spam, calculate the credit value that the calling party reduces according to the credit value meter formula that is lowered among the embodiment 2: C=Ps*Ps (Hu-Hd)/2 again, and the credit value that the original credit value of calling party deducts reduction generated the current credit value of calling party, treatment step previous embodiment afterwards is identical, does not give unnecessary details at this.
Following as one for example, but be not the scope that is used to limit the embodiment of the invention.For example: default talk times is 10 times, in per 10 sampling tests, if calling party's generation normal talking pattern 2 times, in short-term call mode 4 times, short conversation interval mode 2 times, call out non-existent user model 2 times, then in above-mentioned different unusual call mode, the calling party is respectively for the probability of call spam:
P(s|x1)=4/10=0.4;P(s|x2)=2/10=0.2;P(s|x3)=2/10=0.2;n1=4;n2=2;n3=2;
Can calculate the calling party according to formula again for many conditional probabilities of call spam is:
Ps = 0.4 × 4 + 0.2 × 2 + 0.2 × 2 4 + 2 + 2 = 0.3
Below setting not is to be used to limit the embodiment of the invention, for example can set credit value threshold range upper limit Hu=0.9, set credit value threshold range lower limit Hd=0.1, then can draw the credit value that the calling party should reduce and be according to the above-mentioned credit value computing formula that is lowered:
C=0.3×0.3×(0.9-0.1)/2=0.036
In the present embodiment, owing to adopted more rules credit value algorithm based on multiple call spam conversation behavior pattern, can dynamically adjust black and white lists based on credit value, realize the automatic renewal of black and white lists, automatic renewal and two hang-ups difficult in maintenance have been solved, also improve simultaneously accuracy and reasonability that call spam is detected, reduce the probability of failing to report and reporting by mistake.
Embodiment 4:
The call filtering method of the embodiment of the invention 4 and device can also receive user's report information to generate and the renewal black and white lists.
Fig. 6 is the specific implementation flow chart 3 of the call filtering method of the embodiment of the invention 4.As shown in Figure 6, the call filtering method of the embodiment of the invention can also be for may further comprise the steps:
Step S401, the probability of the unusual conversation behavior that reception user's report information generation calling party occurs in default talk times;
Step S402 is according to calling party's the current credit value of conversation behavior pattern generation calling party;
Step S403 compares credit value and the preset threshold value scope that generates, and prescribes a time limit greater than going up of described threshold range when the credit value that generates, and described calling party and credit value thereof are stored in white list; Prescribe a time limit less than the following of described threshold range when the credit value that generates, described calling party and credit value thereof are stored in blacklist;
Step S404 filters conversation according to the black and white lists information of storage.
The call filtering device of the embodiment of the invention can also receive user's call spam report.When the callee reported the calling party, the calling party was the total number of users that number of users/calling party of P (S|g)=report calling party initiatively gets in touch for the probability of call spam.Execution in step S402, S403, S404 then, calculate the credit value that the calling party reduces according to C=Ps*Ps (Hu-Hd)/2, the credit value that deducts reduction with the original credit value of calling party obtains the current credit value of calling party, the credit value current according to the calling party upgrades black and white lists, according to the information of the black and white lists of storing conversation filtered at last.
In the present embodiment, because introduced artificial report mechanism based on the credit value computation rule, thereby can increase the enforcement difficulty of artificial malice report effectively, and both made and judged by accident, also can remedy by the method for adjusting credit value, improved the flexibility that black and white lists is safeguarded, safeguarded on the basis of black and white lists auxiliaryly in original system automatically, can realize the maintenance of black and white lists and the filtration of call spam more effectively with manual maintenance mechanism.
Though the present invention discloses as above with preferred embodiment; right its is not in order to limiting scope of the present invention, any those skilled in the art, without departing from the spirit and scope of the present invention; when can doing a little change and retouching, so protection scope of the present invention is defined with claims and is as the criterion.

Claims (12)

1, a kind of call filtering device is characterized in that, described device comprises:
The conversation detecting unit is used to detect calling party's conversation behavior pattern;
The credit value computing unit is used for generating the current credit value of calling party according to calling party's conversation behavior pattern;
The black and white lists determining unit is used for when the credit value that generates during greater than a threshold value described calling party being recorded in white list; Maybe, described calling party is recorded in blacklist when the credit value that generates during less than a threshold value;
The call filtering unit is used for according to blacklist or white list information that described black and white lists determining unit is determined conversation being filtered.
2, device according to claim 1 is characterized in that,
Described conversation detecting unit detects unusual conversation behavior appears in the calling party in default talk times probability when detecting calling party's conversation behavior pattern;
Described credit value computing unit, the credit value that reduces according to described calling party's unusual conversation behavior probability calculation calling party, and the credit value that the original credit value of calling party deducts reduction generated the current credit value of calling party.
3, device according to claim 2 is characterized in that,
Described credit value computing unit, be further used for when unusual conversation behavior in default talk times, not occurring, described calling party's credit value is increased a constant, and the original credit value of calling party is added that the credit value of increase generates the current credit value of calling party.
4, device according to claim 2 is characterized in that,
Described conversation detecting unit, the process that detects calling party's probability of the unusual conversation behavior of appearance in default talk times detects for two kinds of unusual conversation behaviors that the calling party is occurred in default talk times at least, generate the probability of every kind of unusual conversation behavior, and according to the comprehensive many conditional probabilities that generate unusual conversation behavior of the probability of every kind of unusual conversation behavior;
Described credit value computing unit is used for calculating the credit value that the calling party reduces according to described many conditional probabilities, and the original credit value of calling party is deducted the current credit value of credit value generation calling party of reduction.
5, device according to claim 2 is characterized in that,
Described conversation detecting unit, the report information that is used to receive the user generates unusual conversation behavior appears in the calling party in default talk times probability.
6, device according to claim 1 is characterized in that, described device also comprises:
Initial credit value setup unit is used to the calling party to set initial credit value;
Memory cell is used to store described blacklist or described white list.
7, a kind of call filtering method is characterized in that, described method comprises:
Detect calling party's conversation behavior pattern;
Conversation behavior pattern according to the calling party generates the current credit value of calling party;
When the credit value that generates during, described calling party and credit value thereof are recorded in white list greater than a threshold value; Maybe, described calling party is recorded in blacklist when the credit value that generates during less than a threshold value;
According to described blacklist or white list information conversation is filtered.
8, method according to claim 7 is characterized in that, described detection calling party's conversation behavior pattern generates the current credit value of calling party according to calling party's conversation behavior pattern and comprises:
Detect unusual conversation behavior appears in the calling party in default talk times probability;
The credit value that reduces according to described calling party's unusual conversation behavior probability calculation calling party, and the credit value that the existing credit value of calling party deducts reduction generated the current credit value of calling party.
9, method according to claim 8 is characterized in that, described detection calling party's conversation behavior pattern generates the current credit value of calling party according to calling party's conversation behavior pattern and also comprises:
When unusual conversation behavior in default talk times, not occurring, described calling party's credit value is increased a constant, and the original credit value of calling party is added that the credit value of increase generates the current credit value of calling party.
10, method according to claim 8 is characterized in that, described detection calling party's conversation behavior pattern generates the current credit value of calling party according to calling party's conversation behavior pattern and also comprises:
At least two kinds of unusual conversation behaviors that the calling party is occurred in default talk times detect, and generate the probability of every kind of unusual conversation behavior, and according to the comprehensive many conditional probabilities that generate unusual conversation behavior of the probability of every kind of unusual conversation behavior;
Calculate the credit value that the calling party reduces according to described many conditional probabilities, and the original credit value of calling party is deducted the current credit value of credit value generation calling party of reduction.
11, method according to claim 8 is characterized in that, described detection calling party's conversation behavior pattern also comprises:
The report information that receives the user generates unusual conversation behavior appears in the calling party in default talk times probability.
12, method according to claim 7 is characterized in that, described method also comprises:
For the calling party sets initial credit value.
CN200910140813XA 2009-05-12 2009-05-12 Method and device for call filtering Expired - Fee Related CN101557441B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN200910140813XA CN101557441B (en) 2009-05-12 2009-05-12 Method and device for call filtering

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN200910140813XA CN101557441B (en) 2009-05-12 2009-05-12 Method and device for call filtering

Publications (2)

Publication Number Publication Date
CN101557441A true CN101557441A (en) 2009-10-14
CN101557441B CN101557441B (en) 2011-11-30

Family

ID=41175381

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200910140813XA Expired - Fee Related CN101557441B (en) 2009-05-12 2009-05-12 Method and device for call filtering

Country Status (1)

Country Link
CN (1) CN101557441B (en)

Cited By (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103179550A (en) * 2013-02-28 2013-06-26 北京国政通科技有限公司 Method and device for inquiring information of calling counter parts
CN103476052A (en) * 2013-08-30 2013-12-25 大唐移动通信设备有限公司 Fault detection method and device
CN103533192A (en) * 2013-10-22 2014-01-22 上海市共进通信技术有限公司 Method of realizing telephone no-disturbing function for VoIP home gateway based on SIP
CN103685675A (en) * 2012-09-24 2014-03-26 联想(北京)有限公司 Information processing method and electronic device
CN104427503A (en) * 2013-09-06 2015-03-18 中国移动通信集团湖南有限公司 Information filter method and device
CN104486515A (en) * 2014-12-18 2015-04-01 上海市共进通信技术有限公司 System and method for realizing home gateway number blacklist management in VoIP network
CN106209724A (en) * 2015-04-29 2016-12-07 福建天晴数码有限公司 A kind of invalid addresses of items of mail filter method and device
CN106304041A (en) * 2015-06-12 2017-01-04 中兴通讯股份有限公司 Harassing call monitoring method and device
CN106534464A (en) * 2016-11-30 2017-03-22 依偎科技(南昌)有限公司 Call processing method and terminal
CN107295146A (en) * 2016-04-01 2017-10-24 中国移动通信集团设计院有限公司 A kind of call processing method and device
CN107734200A (en) * 2017-11-03 2018-02-23 中国人民解放军信息工程大学 A kind of communication network users calling behavior prediction method and device based on maximum likelihood
CN108259680A (en) * 2016-12-28 2018-07-06 广东世纪网通信设备股份有限公司 Fraudulent call recognition methods, device and the server for identifying fraudulent call
CN109451183A (en) * 2018-12-25 2019-03-08 吴吉梅 A method of preventing unwelcome phone
CN109995707A (en) * 2017-12-29 2019-07-09 中国移动通信集团陕西有限公司 A kind of high definition voice is anti-harassment and DDOS attack method and device
CN111405107B (en) * 2020-03-26 2021-08-06 中移雄安信息通信科技有限公司 Call control method, device, equipment and storage medium

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101297533A (en) * 2005-08-10 2008-10-29 诺基亚西门子通信有限责任两合公司 Method and system for the automatic update of a white list
CN1859502A (en) * 2006-03-01 2006-11-08 华为技术有限公司 Main call shielding method, device and its use

Cited By (20)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103685675A (en) * 2012-09-24 2014-03-26 联想(北京)有限公司 Information processing method and electronic device
CN103179550A (en) * 2013-02-28 2013-06-26 北京国政通科技有限公司 Method and device for inquiring information of calling counter parts
CN103476052A (en) * 2013-08-30 2013-12-25 大唐移动通信设备有限公司 Fault detection method and device
CN103476052B (en) * 2013-08-30 2017-02-08 大唐移动通信设备有限公司 Fault detection method and device
CN104427503A (en) * 2013-09-06 2015-03-18 中国移动通信集团湖南有限公司 Information filter method and device
CN103533192A (en) * 2013-10-22 2014-01-22 上海市共进通信技术有限公司 Method of realizing telephone no-disturbing function for VoIP home gateway based on SIP
CN104486515A (en) * 2014-12-18 2015-04-01 上海市共进通信技术有限公司 System and method for realizing home gateway number blacklist management in VoIP network
CN106209724A (en) * 2015-04-29 2016-12-07 福建天晴数码有限公司 A kind of invalid addresses of items of mail filter method and device
CN106304041A (en) * 2015-06-12 2017-01-04 中兴通讯股份有限公司 Harassing call monitoring method and device
CN107295146A (en) * 2016-04-01 2017-10-24 中国移动通信集团设计院有限公司 A kind of call processing method and device
CN107295146B (en) * 2016-04-01 2020-11-24 中国移动通信集团设计院有限公司 Call processing method and device
CN106534464A (en) * 2016-11-30 2017-03-22 依偎科技(南昌)有限公司 Call processing method and terminal
CN108259680A (en) * 2016-12-28 2018-07-06 广东世纪网通信设备股份有限公司 Fraudulent call recognition methods, device and the server for identifying fraudulent call
CN108259680B (en) * 2016-12-28 2020-12-22 广东世纪网通信设备股份有限公司 Fraud call identification method and device and server for identifying fraud calls
CN107734200A (en) * 2017-11-03 2018-02-23 中国人民解放军信息工程大学 A kind of communication network users calling behavior prediction method and device based on maximum likelihood
CN109995707A (en) * 2017-12-29 2019-07-09 中国移动通信集团陕西有限公司 A kind of high definition voice is anti-harassment and DDOS attack method and device
CN109995707B (en) * 2017-12-29 2021-11-02 中国移动通信集团陕西有限公司 Method and device for preventing harassment and DDOS (distributed denial of service) attack of high-definition voice
CN109451183A (en) * 2018-12-25 2019-03-08 吴吉梅 A method of preventing unwelcome phone
WO2020135205A1 (en) * 2018-12-25 2020-07-02 吴吉梅 Method for preventing undesirable call
CN111405107B (en) * 2020-03-26 2021-08-06 中移雄安信息通信科技有限公司 Call control method, device, equipment and storage medium

Also Published As

Publication number Publication date
CN101557441B (en) 2011-11-30

Similar Documents

Publication Publication Date Title
CN101557441B (en) Method and device for call filtering
US9729727B1 (en) Fraud detection on a communication network
CN101321070B (en) Monitoring system and method for suspicious user
CN102892117A (en) Method and system for monitoring crank call
CN101472007A (en) Method and system for determining disturbance telephone
CN101909261A (en) Method and system for monitoring spam
CN102143461A (en) Intelligent call forwarding method and device
CN106937007A (en) System, method and device that a kind of harassing call is reminded
CN101715192B (en) Harassing call filtering method, device and system
CN105657131A (en) Method and device for preventing nuisance calls
CN103002420B (en) A kind ofly prevent the method for call spam, system and intelligent transfer service call center
CN107231494A (en) A kind of acquisition methods of user communication characteristic, storage medium and electronic equipment
US20230216953A1 (en) Machine intelligent isolation of international calling performance degradation
CN111917574A (en) Social network topology model and construction method thereof, user confidence degree and intimacy degree calculation method and telecommunication fraud intelligent interception system
CN104580649A (en) Method and system for checking automatic speech service content
US20060269050A1 (en) Adaptive fraud management systems and methods for telecommunications
CN110113748A (en) Harassing call monitoring method, device
CN105516990B (en) A kind of Telecoms Fraud customer analysis method and device
CN103024206A (en) Method for preventing suspected telephone fraudulence on basis of telecommunication network
CN112351429A (en) Harmful information detection method and system based on deep learning
CN107733900B (en) A kind of communication network users abnormal call behavioral value method for early warning
CN102014346B (en) On-hook namecard service system and implementation method
CN101146250A (en) A mobile call loss prompt notification system and its realization method
CN106203098A (en) Application layer eavesdropping means of defence and device
CN109348053A (en) Telephone number marks processing method, equipment and computer readable storage medium

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
C56 Change in the name or address of the patentee

Owner name: HUAWEI DIGITAL TECHNOLOGY (CHENGDU) CO., LTD.

Free format text: FORMER NAME: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES CO., LTD.

CP01 Change in the name or title of a patent holder

Address after: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River

Patentee after: Huawei Symantec Technologies Co., Ltd.

Address before: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River

Patentee before: Chengdu Huawei Symantec Technologies Co., Ltd.

CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20111130

Termination date: 20190512

CF01 Termination of patent right due to non-payment of annual fee