CN111314359B - Anti-fraud method based on SIP signaling collection - Google Patents

Anti-fraud method based on SIP signaling collection Download PDF

Info

Publication number
CN111314359B
CN111314359B CN202010110449.9A CN202010110449A CN111314359B CN 111314359 B CN111314359 B CN 111314359B CN 202010110449 A CN202010110449 A CN 202010110449A CN 111314359 B CN111314359 B CN 111314359B
Authority
CN
China
Prior art keywords
call
real
time
sip
analysis
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN202010110449.9A
Other languages
Chinese (zh)
Other versions
CN111314359A (en
Inventor
程钢
周红敏
张阳
刘志永
卢亚洲
邢喜云
贾岩峰
丁正
顾晓东
祝敬安
韦红
刘君晓
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shanghai Xinfang Software Co ltd
Shanghai Cintel Intelligent System Co ltd
Original Assignee
Shanghai Xinfang Software Co ltd
Shanghai Cintel Intelligent System Co ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shanghai Xinfang Software Co ltd, Shanghai Cintel Intelligent System Co ltd filed Critical Shanghai Xinfang Software Co ltd
Priority to CN202010110449.9A priority Critical patent/CN111314359B/en
Publication of CN111314359A publication Critical patent/CN111314359A/en
Application granted granted Critical
Publication of CN111314359B publication Critical patent/CN111314359B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/30Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information
    • H04L63/306Network architectures or network communication protocols for network security for supporting lawful interception, monitoring or retaining of communications or communication related information intercepting packet switched data communications, e.g. Web, Internet or IMS communications
    • GPHYSICS
    • G10MUSICAL INSTRUMENTS; ACOUSTICS
    • G10LSPEECH ANALYSIS OR SYNTHESIS; SPEECH RECOGNITION; SPEECH OR VOICE PROCESSING; SPEECH OR AUDIO CODING OR DECODING
    • G10L17/00Speaker identification or verification
    • G10L17/22Interactive procedures; Man-machine interfaces
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/101Access control lists [ACL]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/1066Session management
    • H04L65/1101Session protocols
    • H04L65/1104Session initiation protocol [SIP]

Abstract

The invention discloses an anti-fraud method based on SIP signaling acquisition, which comprises the following steps: the interception system collects the data through a signaling collection platformSIPSignaling, a,RTPA data stream; interception system analysisSIPSignaling, a,RTPA data stream; according to the analyzed SIP signaling,RTPData flow, judging the telephone type, and searching for fraudulent calls; sendingSIPThe signaling forces the call to be released. By this method, packet acquisition and analysis is achieved by real-time packet captureSIPThe signaling timely discovers fraud and externally tears off the communication, thereby preventing the occurrence of fraud and ensuring the property safety of people; the calling number is analyzed in real time, and the method is easy to operate and has real-time performance; releasing the call at any time after the fraud number is found; the fake special service number can be analyzed; the method can match the voice template and match and intercept the voiceprint in real time.

Description

Anti-fraud method based on SIP signaling collection
Technical Field
The invention relates to the technical field of telecommunication fraud, in particular to an anti-fraud method based on SIP signaling collection.
Background
Telecommunication fraud is a common fraud means for current fraud molecules, and because telecommunication network communication is complex, the fraud molecules can hardly be traced back through call records, so that the fraud molecules are out of the law. People have poor understanding and recognition on the fraud means and the fraud technology of the fraud molecules, and are easy to cheat, so that the fraud molecules are often successful.
At present, the telecommunication fraud mainly comprises the following fraud ways and means:
(1) falsely-acting shopping customer service fraud
The fraud molecule acquires the online shopping transaction record in the modes of purchasing and the like, pretends that the product has a problem and refunds the product to the customer, knows the operation of the customer through voice, asks for a verification code and finishes fraud.
(2) Fraud network loan platform
The fraud persons obtain the loan information of the customers by purchasing and the like, impersonate the network loan platform to provide loan for the customers who cannot loan in the bank under the condition of insufficient qualification, ask for the commission, claim the information filling error later, request the fund to be frozen, ask for the customer's material, guide the customer's operation by voice, ask for the verification code, and finish the fraud.
There is currently no effective anti-fraud method.
Disclosure of Invention
Aiming at the technical problems in the related art, the invention provides an anti-fraud method based on SIP signaling collection, which can overcome the defects in the prior art.
In order to achieve the technical purpose, the technical scheme of the invention is realized as follows:
an anti-fraud method based on SIP signaling collection, the method comprising the steps of:
s1: the interception system acquires an SIP signaling and an RTP data stream through a signaling acquisition platform, wherein the SIP signaling and the RTP data stream are between an end office and a toll office;
the step S1 includes the steps of:
s11: collecting and sending SIP signaling and RTP media streams to an interception service through high-resistance bridging or port mirroring;
s12: adopting SDTP protocol to package the collected signaling, and transmitting the packaged collected signaling to the interception service through a TCP/IP channel;
s2: the interception system analyzes SIP signaling and RTP data flow, wherein the analyzed SIP message is an INVITE message in the SIP signaling, the analysis relates to number, SIP call state and media flow analysis, the number is in the INVITE message, RTP represents a real-time transmission protocol, and INVITE represents a call initial request;
s3: judging the telephone type according to the analyzed SIP signaling and RTP data flow, and searching for fraud telephones;
s4: and sending SIP signaling to forcedly release the call, wherein a CANCEL message is sent to the MSC to release the calling party, a CANCEL message is sent to the TMSC to release the called party, CANCEL indicates the end of the session, the MSC indicates a mobile switching center, and the TMSC indicates a tandem mobile switching center.
Further, the intercepted service analysis content comprises black number library matching analysis, fake service number analysis, real-time voice template matching analysis, real-time voiceprint matching analysis, offline voice matching analysis and offline voiceprint matching analysis.
Further, the content included in the black number library matching analysis is as follows: regularly maintaining a black number library, and regularly adding numbers to be intercepted into the black number library; intercepting service can obtain calling number by analyzing INVITE message in SIP message, match and inquire the calling number and black number in the database, when can match, intercept the conversation.
Further, the false special service number analysis includes the following contents: the interception system obtains the calling number by analyzing the SIP signaling; searching for a policy associated with the calling number; judging the type of the incoming call of the calling number, wherein when the incoming call is an international incoming call, the number is subjected to false special service calling number analysis, and the false special service calling number analysis adopts a right matching rule; and when the matched number is the disguised domestic special service number, releasing the call.
Further, the real-time voice template matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number, wherein when the calling number belongs to a grey list and the strategy configuration is matched with a real-time voice template, the number is subjected to real-time voice template analysis; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT in the RTP stream, establishes the corresponding relation between the SIP session and the RTP data stream, and obtains the voice of the real-time call, wherein the CALLID is the session ID attribute, the SDP is the session description protocol, and the PORT is the PORT number; and matching the voice of the real-time call with the voice template, and when the voice template can be matched, returning a result as true, and intercepting the call.
Further, the real-time voiceprint matching analysis includes the following contents: the interception system firstly obtains a calling number by analyzing the SIP signaling and then searches a strategy related to the calling number; when the calling number belongs to the grey list and the strategy is configured to match the real-time voiceprint, starting the real-time voiceprint for the number; the interception system analyzes the IP address and the PORT PORT in the RTP data stream by analyzing CALLID and SDP in the SIP message, and establishes the corresponding relation between the SIP session and the RTP, thereby obtaining the voice of the real-time call; and matching the real-time call voice with the voice template file, and when the real-time call voice can be matched with the voice template file, returning a result as true and intercepting the call.
Further, the offline voice matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; when the calling number belongs to the grey list and the strategy configuration is matched with the offline voice template, starting real-time voice template analysis on the calling number; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT PORT in the RTP data stream, establishes the corresponding relation between the SIP session and the RTP data stream, associates the voice of the real-time call, records the call, generates a recording file and then stores the data; when the call is finished, the call access content in the database comprises a calling number, a called number, call starting time, call finishing time, a recording file name and recording file path information; starting an offline voice template analysis process independently, and matching the offline voice file with the voice template file; when the matching is available, the number is stored in a blacklist library, and the blackening reason is marked, wherein the blackening reason is the matched voice template; when the number calls in again, the interception is carried out.
Further, the offline voiceprint matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; when the calling number belongs to the grey list and the strategy configuration is matched with the offline voice template, starting real-time voice template analysis on the number; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT PORT in the RTP data stream, establishes the corresponding relation between the SIP session and the RTP data stream, associates the voice of the real-time call, records the call, generates a recording file and then stores the data; when the call is finished, the call access content in the database comprises a calling number, a called number, call starting time, call finishing time, a recording file name and recording file path information; an offline voiceprint analysis process is independently started, and offline voice files are matched with voiceprint file files; when the matching can be carried out, the number is stored in a black name list library, and the blackening reason is marked, wherein the blackening reason is the ID attribute of the matched voiceprint file; when the number calls in again, the interception is carried out.
The invention has the beneficial effects that: through the method, on one hand, an effective anti-fraud method is provided, fraud is timely discovered through real-time packet capturing, SIP signaling analysis and conversation dismantling, fraud is prevented, and the property safety of people is guaranteed; on the other hand, the network packet is acquired on the proxy server based on the SIP protocol, the calling number is analyzed in real time, and the method is easy to operate and has real-time performance; the calling number analysis program is almost zero-coupled with the SIP call flow, the normal call flow is not influenced, and the call is released at any time after the fraud number is found; the fake special service number can be analyzed; the method can match the voice template and match and intercept the voiceprint in real time.
Drawings
In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings needed in the embodiments will be briefly described below, and it is obvious that the drawings in the following description are only some embodiments of the present invention, and it is obvious for those skilled in the art to obtain other drawings without creative efforts.
FIG. 1 is a flow chart of an anti-fraud method based on SIP signaling collection according to an embodiment of the present invention;
fig. 2 is a system structure diagram of an anti-fraud method based on SIP signaling collection according to an embodiment of the present invention.
Detailed Description
The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. All other embodiments that can be derived by one of ordinary skill in the art from the embodiments given herein are intended to be within the scope of the present invention.
As shown in fig. 1 and 2, an anti-fraud method based on SIP signaling collection according to an embodiment of the present invention includes the following steps:
s1: the interception system collects SIP signaling and RTP data flow through a signaling collection platform, wherein the SIP signaling and the RTP data flow are between an end office and a long-distance office;
step S1 includes the following steps:
s11: collecting and sending SIP signaling and RTP media streams to an interception service through high-resistance bridging or port mirroring;
s12: adopting SDTP protocol to package the collected signaling, and transmitting the packaged collected signaling to the interception service through a TCP/IP channel;
s2: the interception system analyzes an SIP signaling and an RTP data stream, wherein the analyzed SIP message is an INVITE message in the SIP signaling, the analysis relates to analysis of numbers, an SIP call state and a media stream, the numbers are in the INVITE message, RTP represents a real-time transmission protocol, and INVITE represents a call initial request;
s3: judging the telephone type according to the analyzed SIP signaling and RTP data flow, and searching for fraud telephones;
s4: and sending SIP signaling to forcibly release the call, wherein a CANCEL message is sent to the MSC to release the calling party, a CANCEL message is sent to the TMSC to release the called party, CANCEL indicates the session end, the MSC indicates a mobile switching center, and the TMSC indicates a tandem mobile switching center.
In an embodiment of the present invention, the intercepted service analysis content includes black number library matching analysis, fake service number analysis, real-time voice template matching analysis, real-time voiceprint matching analysis, offline voice matching analysis, and offline voiceprint matching analysis.
In a specific embodiment of the present invention, the black number library matching analysis includes the following contents: regularly maintaining a black number library, and regularly adding numbers to be intercepted into the black number library; the interception service can acquire the calling number by analyzing the INVITE message in the SIP message, match and inquire the calling number with the black number in the database, and intercept the call when the calling number can be matched with the black number in the database.
In an embodiment of the present invention, the fake special service number analysis includes the following contents: the interception system obtains the calling number by analyzing the SIP signaling; searching for a policy associated with the calling number; judging the type of the incoming call of the calling number, wherein when the incoming call is an international incoming call, the number is subjected to false special service calling number analysis, and the false special service calling number analysis adopts a right matching rule; and when the matched number is the disguised domestic special service number, releasing the call.
In a specific embodiment of the present invention, the real-time voice template matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number, wherein when the calling number belongs to a grey list and the strategy configuration is matched with a real-time voice template, the number is subjected to real-time voice template analysis; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT in the RTP stream, establishes the corresponding relation between the SIP session and the RTP data stream, and obtains the voice of the real-time call, wherein the CALLID is the session ID attribute, the SDP is the session description protocol, and the PORT is the PORT number; and matching the voice of the real-time call with the voice template, and when the voice template can be matched, returning a result as true, and intercepting the call.
In a specific embodiment of the present invention, the real-time voiceprint matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; when the calling number belongs to the grey list and the strategy is configured to match the real-time voiceprint, starting the real-time voiceprint for the number; the interception system analyzes the IP address and the PORT PORT in the RTP data stream by analyzing CALLID and SDP in the SIP message, and establishes the corresponding relation between the SIP session and the RTP, thereby obtaining the voice of the real-time call; and matching the real-time call voice with the voice template file, and when the real-time call voice can be matched with the voice template file, returning a result as true and intercepting the call.
In a specific embodiment of the present invention, the offline voice matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; when the calling number belongs to the grey list and the strategy configuration is matched with the offline voice template, starting real-time voice template analysis on the calling number; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT PORT in the RTP data stream, establishes the corresponding relation between the SIP session and the RTP data stream, associates the voice of the real-time call, records the call, generates a recording file and then stores the data; when the call is finished, the call access content in the database comprises a calling number, a called number, call starting time, call finishing time, a recording file name and recording file path information; starting an offline voice template analysis process independently, and matching the offline voice file with the voice template file; when the matching is available, the number is stored in a blacklist library, and the blackening reason is marked, wherein the blackening reason is the matched voice template; when the number calls in again, the interception is carried out.
In a specific embodiment of the present invention, the offline voiceprint matching analysis includes the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; when the calling number belongs to the grey list and the strategy configuration is matched with the offline voice template, starting real-time voice template analysis on the number; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT PORT in the RTP data stream, establishes the corresponding relation between the SIP session and the RTP data stream, associates the voice of the real-time call, then records the call, generates a recording file and stores the data; when the call is finished, the call access content in the database comprises a calling number, a called number, call starting time, call finishing time, a recording file name and recording file path information; separately starting an off-line voiceprint analysis process, and matching an off-line voice file with a voiceprint file; when the matching can be carried out, the number is stored in a black name list library, and the blackening reason is marked, wherein the blackening reason is the ID attribute of the matched voiceprint file; when the number calls in again, the interception is carried out.
In a specific embodiment of the invention, the SIP signaling is acquired and analyzed in real time, the SIP signaling is collected and processed in real time by a deployment program, and the call of the fraud molecule is removed and refused to be connected, so that a fraud call cannot be established, and the property safety of people is guaranteed.
Noun abbreviation interpretation:
SIP: session Initiation Protocol, Session Initiation Protocol;
INVITE: calling an initial request;
RTP: Real-Time Transport Protocol, Real-Time Transport Protocol;
CANCEL: ending the session;
CALLID: a session ID;
SDP: session description Protocol, Session description Protocol;
MSC: mobile Switching Center, Mobile Switching Center;
TMSC: tandem Mobile Switching Center.
In conclusion, by means of the technical scheme, on one hand, the method provides an effective anti-fraud method, fraud is found in time by capturing packets in real time and analyzing SIP signaling, and the communication is disassembled externally, so that fraud is prevented, and the property safety of people is guaranteed; on the other hand, the network packet is acquired on the proxy server based on the SIP protocol, the calling number is analyzed in real time, and the method is easy to operate and has real-time performance; the calling number analysis program is almost zero-coupled with the SIP call flow, the normal call flow is not influenced, and the call is released at any time after the fraud number is found; false special service numbers can be analyzed; the method can match the voice template and match and intercept the voiceprint in real time.
The above description is only for the purpose of illustrating the preferred embodiments of the present invention and is not to be construed as limiting the invention, and any modifications, equivalents, improvements and the like that fall within the spirit and principle of the present invention are intended to be included therein.

Claims (6)

1. An anti-fraud method based on SIP signaling collection is characterized by comprising the following steps:
s1: the interception system collects SIP signaling and RTP data flow through a signaling collection platform, wherein the SIP signaling and the RTP data flow are between an end office and a long-distance office;
the step S1 includes the steps of:
s11: collecting and sending SIP signaling and RTP media streams to an interception service through high-resistance bridging or port mirroring;
s12: adopting SDTP protocol to package the collected signaling, and transmitting the packaged collected signaling to the interception service through a TCP/IP channel;
s2: the interception system analyzes SIP signaling and RTP data flow, wherein the analyzed SIP message is an INVITE message in the SIP signaling, the analysis relates to number, SIP call state and media flow analysis, the number is in the INVITE message, RTP represents a real-time transmission protocol, and INVITE represents a call initial request;
s3: judging the telephone type according to the analyzed SIP signaling and RTP data flow, and searching for fraud telephones;
s4: sending SIP signaling to forcibly release the call, wherein a CANCEL message is sent to an MSC to release a calling party, a CANCEL message is sent to a TMSC to release a called party, the CANCEL indicates the session is ended, the MSC indicates a mobile switching center, and the TMSC indicates a tandem mobile switching center;
intercepting business analysis contents including black number library matching analysis, false special service number analysis, real-time voice template matching analysis, real-time voiceprint matching analysis, off-line voice matching analysis and off-line voiceprint matching analysis;
the real-time voice template matching analysis comprises the following contents: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number, wherein when the calling number belongs to a grey list and the strategy configuration is matched with a real-time voice template, the number is subjected to real-time voice template analysis; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT in the RTP stream, establishes the corresponding relation between the SIP session and the RTP data stream, and obtains the voice of the real-time call, wherein the CALLID is the session ID attribute, the SDP is the session description protocol, and the PORT is the PORT number; and matching the voice of the real-time call with the voice template, and when the voice template can be matched, returning a result as true, and intercepting the call.
2. The anti-fraud method based on SIP signaling collection according to claim 1, wherein said black number library matching analysis comprises the contents of: regularly maintaining a black number library, and regularly adding numbers to be intercepted into the black number library; the interception service can acquire the calling number by analyzing the INVITE message in the SIP message, match and inquire the calling number with the black number in the database, and intercept the call when the calling number can be matched with the black number in the database.
3. The anti-fraud method of claim 1, wherein said false special service number analysis comprises the following contents: the interception system obtains a calling number by analyzing the SIP signaling; searching for a policy associated with the calling number; judging the type of the incoming call of the calling number, wherein when the incoming call is an international incoming call, the number is subjected to false special service calling number analysis, and the false special service calling number analysis adopts a right matching rule; and when the matched number is the disguised domestic special service number, releasing the call.
4. The anti-fraud method based on SIP signaling collection according to claim 1, wherein said real-time voiceprint matching analysis further comprises the contents of: the interception system firstly obtains a calling number by analyzing the SIP signaling and then searches a strategy related to the calling number; when the calling number belongs to the grey list and the strategy configuration is real-time voiceprint matching, enabling the real-time voiceprint to the number; the interception system analyzes the IP address and the PORT PORT in the RTP data stream by analyzing CALLID and SDP in the SIP message, and establishes the corresponding relation between the SIP session and the RTP, thereby obtaining the voice of the real-time call; and matching the real-time call voice with the voice template file, and when the real-time call voice can be matched with the voice template file, returning a result of true and intercepting the call.
5. The anti-fraud method based on SIP signaling collection according to claim 1, wherein said offline voice matching analysis comprises the contents of: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; the off-line voice matching analysis also comprises the step of starting real-time voice template analysis on the calling number when the calling number belongs to a grey list and the strategy configuration is matched with an off-line voice template; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT PORT in the RTP data stream, establishes the corresponding relation between the SIP session and the RTP data stream, associates the voice of the real-time call, records the call, generates a recording file and then stores the data; when the call is finished, the call access content in the database comprises a calling number, a called number, call starting time, call finishing time, a recording file name and recording file path information; starting an offline voice template analysis process independently, and matching the offline voice file with the voice template file; when the matching can be carried out, the number is stored in a blacklist library, and the blackening reason is marked, wherein the blackening reason is the matched voice template; when the number calls in again, the interception is carried out.
6. The anti-fraud method based on SIP signaling collection according to claim 1, wherein said offline voiceprint matching analysis further comprises the contents of: the method comprises the steps that an interception system firstly obtains a calling number by analyzing SIP signaling, and then searches for a strategy related to the calling number; when the calling number belongs to the grey list and the strategy configuration is matched with the offline voice template, starting real-time voice template analysis on the number; the interception system analyzes the CALLID and the SDP in the SIP message, analyzes the IP address and the PORT PORT in the RTP data stream, establishes the corresponding relation between the SIP session and the RTP data stream, associates the voice of the real-time call, records the call, generates a recording file and then stores the data; when the call is finished, the call access content in the database comprises a calling number, a called number, call starting time, call finishing time, a recording file name and recording file path information; an offline voiceprint analysis process is independently started, and offline voice files are matched with voiceprint files; when the matching can be carried out, the number is stored in a black name list library, and the blackening reason is marked, wherein the blackening reason is the ID attribute of the matched voiceprint file; when the number calls in again, the interception is carried out.
CN202010110449.9A 2020-02-20 2020-02-20 Anti-fraud method based on SIP signaling collection Active CN111314359B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202010110449.9A CN111314359B (en) 2020-02-20 2020-02-20 Anti-fraud method based on SIP signaling collection

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202010110449.9A CN111314359B (en) 2020-02-20 2020-02-20 Anti-fraud method based on SIP signaling collection

Publications (2)

Publication Number Publication Date
CN111314359A CN111314359A (en) 2020-06-19
CN111314359B true CN111314359B (en) 2022-07-19

Family

ID=71147664

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202010110449.9A Active CN111314359B (en) 2020-02-20 2020-02-20 Anti-fraud method based on SIP signaling collection

Country Status (1)

Country Link
CN (1) CN111314359B (en)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111835663B (en) * 2020-07-16 2022-04-26 普强时代(珠海横琴)信息技术有限公司 Real-time call monitoring method based on network packet capturing analysis
CN111741472B (en) * 2020-08-07 2020-11-24 北京微智信业科技有限公司 GoIP fraud telephone identification method, system, medium and equipment
CN113766065A (en) * 2021-09-09 2021-12-07 上海欣方智能系统有限公司 IMS network fraud call interception based realization method and system
CN114679432B (en) * 2022-02-28 2024-01-05 河南信大网御科技有限公司 Harmful telephone prevention equipment and method

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1756179A (en) * 2004-09-27 2006-04-05 华为技术有限公司 Method for preventing unlawful VoIP service in communication network
WO2018038652A1 (en) * 2016-08-23 2018-03-01 Telefonaktiebolaget Lm Ericsson (Publ) Improved lawful interception

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101011221B1 (en) * 2008-12-23 2011-01-26 한국인터넷진흥원 Detection and block system for hacking attack of internet telephone using the SIP-based and method thereof
CN104093153B (en) * 2014-06-25 2017-10-10 东方通信股份有限公司 It is a kind of that the method and its system realized pseudo number call screening and intercepted are analyzed based on signalling route
CN106657689A (en) * 2015-11-04 2017-05-10 中国移动通信集团公司 Method for preventing and controlling international fraud call and apparatus thereof
CN106850552A (en) * 2016-12-21 2017-06-13 恒安嘉新(北京)科技有限公司 A kind of method that harmful Call Intercept is realized based on signaling re-injection
CN108989267A (en) * 2017-05-31 2018-12-11 中兴通讯股份有限公司 Gray scale dissemination method, system, equipment and storage medium based on SIP
CN108234485B (en) * 2017-12-30 2020-09-01 广东世纪网通信设备股份有限公司 VOIP platform-based fraud voiceprint acquisition device and method, device and system for intercepting fraud calls by using same

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1756179A (en) * 2004-09-27 2006-04-05 华为技术有限公司 Method for preventing unlawful VoIP service in communication network
WO2018038652A1 (en) * 2016-08-23 2018-03-01 Telefonaktiebolaget Lm Ericsson (Publ) Improved lawful interception

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
通信信息诈骗防范解决方案探讨;包琅允,阳平,徐爱华;《电信技术》;20170731;全文 *

Also Published As

Publication number Publication date
CN111314359A (en) 2020-06-19

Similar Documents

Publication Publication Date Title
CN111314359B (en) Anti-fraud method based on SIP signaling collection
EP1527552B1 (en) A system and method for the detection and termination of fraudulent services
CN104243727B (en) System and method for performing big data analysis confirmation and interception on phone scams
US11190638B2 (en) Detection and prevention of unwanted calls in a telecommunications system
US11689585B2 (en) Processing sensitive information over VoIP
KR101945782B1 (en) Method and apparatus for providing illegal phishing call blocking services of VoIP call
KR20100058964A (en) Apparatus for blocking voip spam using spam index
CN101305592B (en) Method for accessing call subscriber terminal to pre-payment service system
WO2019226129A2 (en) A system and a method that detect ott bypass fraud using network-data analysis
CN114189866A (en) Multi-card fraud detection method and device
CN104301549B (en) Defaulting downtime missed call prompting system and method
WO2019190438A2 (en) Ott bypass fraud detection by using call detail record and voice quality analytics
US8107459B1 (en) Method and apparatus for executing a call blocking function
CN111132126B (en) Method, system, device and storage medium for full recording of mobile phone number
CN107343278A (en) The implementation method of number verification business is carried out by audio call
CN107493175A (en) Calling-control method, call control apparatus and the system of prepaid user
EP1561321A1 (en) Method for collect call service based on voip technology and system thereof
CN115174728A (en) Harassing call intercepting method of network side
CN115174744A (en) Method, device, storage medium and electronic equipment for identifying virtual dialing equipment

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant