WO2005018152A1 - A system and method of intelligently monitoring the message centers - Google Patents
A system and method of intelligently monitoring the message centers Download PDFInfo
- Publication number
- WO2005018152A1 WO2005018152A1 PCT/CN2004/000486 CN2004000486W WO2005018152A1 WO 2005018152 A1 WO2005018152 A1 WO 2005018152A1 CN 2004000486 W CN2004000486 W CN 2004000486W WO 2005018152 A1 WO2005018152 A1 WO 2005018152A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- monitoring
- message
- user
- blacklist
- server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/21—Monitoring or handling of messages
- H04L51/212—Monitoring or handling of messages using filtering or selective blocking
Definitions
- the present invention relates to the technical field of monitoring message centers in communication systems, and in particular, to a system and method for intelligently monitoring short message centers, multimedia message centers, mail centers, etc. of CDMA communication systems, GSM communication systems, and wireless local telephone systems.
- the function of the message center in the communication system is becoming increasingly powerful, and it has developed from a short message center to a multimedia message center and a mail center.
- the number of users who use the message center is increasing, and the use of the message center to promote advertising is endless, and communication networks have gradually realized interconnection.
- the amount of messages flowing between communication networks has grown geometrically.
- Spam attacks in a short period of time can cause the transmission volume of communication networks to increase rapidly and easily cause network paralysis. Frequent spam and malicious messages, etc. It will also annoy users who use the message center; and reactionary and rumorous messages will have extremely bad social impact.
- the monitoring methods of the message center are mainly as follows: The manager of the message center manually sets a blacklist number on the service processor of the message center for specified filtering, but this method is inconvenient and inaccurate, and cannot be real-time according to the network conditions. Modifying the blacklist number is very time-consuming and cannot cope with the large message traffic of the current message center. Therefore, there is an urgent need for a system and method that can automatically monitor the message center. However, no publicly similar technical solution has been found.
- the technical problem to be solved by the present invention is to provide a system and method for intelligently monitoring a message center.
- This method can automatically monitor various types of message centers, and modify the monitoring configuration parameters according to the actual situation of the communication network to avoid the spread of spam and malicious messages and ensure the stability of the message center.
- the system of the intelligent monitoring message center of the present invention includes a service processor, a monitoring server, and at least one monitoring management station, wherein the service processor is configured to process a received information service and send a message to be monitored to the monitoring server, And controlling the processing of information services according to the user blacklist returned by the monitoring server; the monitoring server is configured to process the messages to be monitored according to the monitoring configuration parameters output by the monitoring management station, and generate a user blacklist to output to the service processing The monitoring management station is configured to generate monitoring configuration parameters and send the monitoring configuration parameters to the monitoring server.
- a message database is provided for storing records generated during the message monitoring process, including the banned messages themselves and the monitoring results.
- the service processor is further provided with a user blacklist table for storing the user blacklist, and performing blacklist monitoring on the user according to the user blacklist.
- the monitoring server is also provided with a message flow monitoring table for storing information of monitoring users.
- the method for intelligently monitoring a message center according to the present invention includes the following steps: a service processor sends a message to be monitored to a monitoring server; the monitoring server monitors the monitoring message in real time according to the monitoring configuration parameters sent by the monitoring management station; the monitoring server The forbidden user generates a user blacklist and sends it to the service processor; the service processor controls the processing of information services according to the user blacklist.
- the monitoring server monitors the monitored messages in real time, including monitoring the message content and monitoring the message traffic.
- the system and method according to the present invention can automatically intercept suspicious objects according to the monitoring configuration parameters, and set them as blacklisted users, and the service processor immediately closes the message source corresponding to the user; meanwhile, it can also automatically The user is deleted from the blacklist, so that the corresponding message source is unblocked immediately.
- the invention can modify the monitoring configuration parameters in real time, and the monitoring operation takes effect immediately.
- the present invention can be Control configuration for multi-channel alarms; each remote terminal with authority can monitor the monitoring status in real time, and can query and analyze its historical records at any time.
- the invention can be applied to the monitoring of various short message centers, multimedia message centers, and mail centers.
- FIG. 1 is a schematic diagram of a network structure of a system of an intelligent monitoring message center according to the present invention
- FIG. 3 is a schematic flowchart of monitoring user message traffic in the method of the present invention.
- FIG. 5 is a schematic flowchart of a service processor controlling information service processing according to a user blacklist in the method of the present invention.
- the message centers of various communication systems generally include a service processor 110, a service access server 160, a switching center 140, and a WW server 150.
- the service access server 160 is mainly used to access information services from the switching center 140 and the stomach server 150.
- the service processor 110 is used to process various types of information services, such as short messages, multimedia short messages, and multimedia mails, and to perform various types of messages and mail interactions with the switching center 140 and WW server 150 through the service access server 16 Send and receive.
- the system for intelligently monitoring a message center includes: a service processor 110 located in the message center, a monitoring server 120 and a monitoring management station 130.
- the business processor 110 communicates with the monitoring server 120.
- the business processor 110 also sends messages to be monitored to the monitoring server 120.
- the monitoring server 120 is separately connected to the business processor 110 and the monitoring management station. 130 is connected and communicates in real time, and is used for real-time monitoring of the monitored messages according to the monitoring configuration parameters, and generates a user blacklist and a blacklist unban list, and sends it to the service processor 110; the monitoring management station 130 is used to set monitoring configuration parameters and send them to the monitoring server 120.
- the monitoring server 120 may also send the monitoring result to the monitoring management station 130.
- the monitoring server 120 is also provided with at least one remote interface 180 to provide an interface for remote users.
- the monitoring server 120 may be connected to a remote terminal 181 or a browser 182 through the remote interface 180 to provide a remote user with a configuration interface or a monitoring interface for monitoring configuration parameters.
- the monitoring server 120 may also be connected to a log printing device 191 or an acousto-optic alarm device 192 to output and display a monitoring result.
- a message database is set in the business processor 110 and the monitoring server 120, and is used to store records generated during the monitoring process of the message, including the banned messages themselves and the monitoring results.
- the above message database may be located in the memory of the business processor 110 and the monitoring server 120, and is a data table organized in a HASH manner.
- the specific implementation is: apply for a structure array area in the memory, each member structure of the array corresponds to a India record; a certain member in the member structure is used as an index, such as a number.
- Hash algorithm is used to locate the corresponding record according to the index, which can locate the data at high speed.
- the monitoring configuration parameters are information used to guide the monitoring server 120 to perform monitoring, including configuration parameters of the monitoring mode, parameters of monitoring result processing, blacklist user lifting conditions, super users, monitoring keywords, etc., where the monitoring mode refers to the monitoring server 120 Information of the messages to be monitored, such as message traffic monitoring, message content monitoring, etc.
- Super users are users who do not perform message monitoring.
- Configuration parameters for message traffic monitoring include monitoring time, monitoring count, threshold, etc .
- configuration parameters for message content monitoring include monitoring keywords
- parameters for processing monitoring results include "generate user blacklist", “monitoring results feedback”, “sound and light”"Alarm”,"Logprint”,”Notifyadministrator", etc.
- the monitoring management station 130 generates monitoring configuration parameters and sends the monitoring configuration parameters to the monitoring server 120.
- the monitoring configuration parameters are global structural variables stored in the memory of the monitoring server 120.
- the monitoring server 120 monitors the messages to be monitored in real time according to the specific monitoring configuration parameters. After receiving the monitoring configuration parameters of the monitoring management station 130, the monitoring server 120 immediately modifies the monitoring configuration parameter items in the memory, and the monitoring server 120 performs monitoring according to the new monitoring configuration parameters. At the same time, the monitoring server 120 writes the new configuration parameters into the monitoring configuration file to prevent the configuration parameters from being lost, and is also available for the monitoring management station 130 to verify.
- the monitoring server 120 monitors the monitored messages according to the monitoring configuration parameters, which may be the traffic of the monitored messages and / or the content of the messages.
- the monitoring server 120 is provided with a message flow monitoring table for storing information of monitoring users.
- the message flow monitoring table is a memory table that uses a structured array area in memory, such as HASH.
- the LRU algorithm can be further used to ensure the security of the table and the effectiveness of the records in the table.
- the monitoring server 120 generates a user blacklist for users who meet the prohibition conditions according to the monitoring result, and sends the user blacklist to the service processor 110.
- the service processor 110 controls the processing of information services according to the blacklist, and filters the blacklist users.
- a user blacklist table is set in the service processor 110 for storing the user blacklist.
- the blacklist table can also be a memory table that uses a structured array area in memory, and further uses the LRU algorithm to ensure the security of the table and the effectiveness of the records in the table.
- the method for intelligently monitoring a message center includes: the service processor 110 sends a message to be monitored to the monitoring server 120; the monitoring server 120 monitors the monitoring message in real time according to the monitoring configuration parameters sent by the monitoring management station 130; the monitoring server 120 According to the monitoring results, automatically select the users who meet the prohibition conditions and generate a user blacklist, and send it to the business processor 110; business processing The machine 110 controls the processing of information services according to the user blacklist, and closes the message sources of the blacklisted users.
- the monitoring configuration parameters are configured by the administrator on the monitoring management station 130 through a graphical configuration interface.
- the monitoring server 120 may also send the monitoring results to the monitoring management station 130 or other authorized remote terminals or users, and may also perform all-round alarms, including sound and light alarms.
- the monitoring server 120 may also automatically generate a blacklist unbanning list and send it to the service processor 110, and the service processor 110 deletes the unbanned blacklist user from the user blacklist table, thereby unbanning the user.
- the message to be monitored may be the information received by the service processor 110 itself, or it may be a simplification of the above information, such as a bill, etc .;
- the data flow D is The user blacklist or blacklist unban list sent by the monitoring server 120 to the business processor 110; data streams 1, 2, and 3 are monitoring configuration parameters sent by the monitoring management station 130 or other remote users to the monitoring server 120; data stream 4 , 5, 6, 7, 8, and 9 are messages sent by the monitoring server 120 to the monitoring management station 130 and other various terminals for alarm, browsing, and tracking analysis.
- the method of the present invention is specifically as follows: after receiving the information to be processed or mail, that is, data flow A, the service processor 110 sends the data to the subsequent processing server for normal processing (data flow B), and also monitors
- the server 120 sends a message to be monitored, that is, the data stream C for monitoring, and the data stream C sent to the monitoring server 120 may carry only basic information required for monitoring.
- the monitoring server 120 monitors the monitoring messages in real time according to the monitoring configuration parameters sent by each monitoring management station 130, that is, data streams 1, 2, and 3, and sends monitoring results that are data streams 4, 5, 6, 7, 8, and 9 To each monitoring management station 130, analysis terminal, alarm device, or printing device.
- the monitoring server 120 monitors the obtained user blacklist data, namely The data stream D is immediately sent to the service processor 110 and stored in the user blacklist table, so that the information service of the user is closed.
- the monitoring server 120 also periodically checks the user blacklist table according to the unbanning conditions configured by the monitoring management station 1 30, filters out the blacklisted users who meet the unbanning conditions, generates a blacklist unbanning list, and sends the blacklist to the service processor 110.
- the blacklisted users in the unbanned list are deleted, and the information services of these users are lifted.
- the monitoring of message traffic refers to monitoring whether the amount of information sent by the information user within a set unit time exceeds a set threshold, and if it exceeds, a user blacklist is generated; then the monitoring server 120 sends the user blacklist to the service processor 110 Or output to the alarm device or perform other monitoring results processing.
- a message traffic monitoring table is set in the monitoring server 120, which is used to store information of the monitoring users, including at least the user's number, the current monitoring time, and the current monitoring count value.
- the message flow monitoring table uses the form of an in-memory database.
- the monitoring server 120 records the information of the user in the message flow monitoring table, where the count value of the recording monitoring is 1, and the recording current time is the monitoring start time (step 303). The monitoring server 120 then checks whether the count value of the user exceeds the set monitoring count threshold (step 306). If the count value does not exceed the monitoring count threshold, it indicates that the message traffic of the user does not exceed the preset threshold, and ends the monitoring.
- the monitoring server 120 processes the monitoring result (step 307), which may be: generating a blacklist of the user and sending it to the business process machine 110, either feedback the monitoring result to the monitoring management station 130, or perform an acousto-optic alarm or the like, or all of the above three processes. Then the monitoring server 120 resets the record of the user, the count value returns to 0 (step 308), and the monitoring ends.
- the monitoring server 120 checks whether the current monitoring time of the user reaches the set monitoring time interval (step 304). If the monitoring time interval is exceeded, the monitoring server 120 resets the user Record, the count value returns to 0 (step 308), and the monitoring ends. If the monitoring time interval has not been exceeded, the monitoring server 120 checks whether the user's record has just been reset (step 305), and if so, sets the user's count value to 1 and sets the current time as the monitoring start time, Then step 306 is performed; if it has not just been reset, then the count value of the user is incremented by 1, and then step 306 is performed.
- the monitoring of the content of the message refers to monitoring the content of the short message, the content of the multimedia short message, and the subject of the multimedia mail according to the monitoring keywords configured by the monitoring management station 130.
- the monitoring server 120 receives the message to be monitored sent by the service processor 110 (step 401), and then checks whether the content of the received message to be monitored contains the set monitoring key. Word (step 402). If it does, the monitoring server 120 processes the monitoring result (step 403), which may be: generating a user blacklist and sending it to the service processor 110, or performing an audible and visual alarm, or feeding back the monitoring result to the monitoring management station 130, Or all three processes described above are performed. If there is no monitoring keyword, the monitoring is ended (step 404).
- a super user is set in the monitoring management station 130, check whether the user of the message to be monitored is a super user before monitoring the monitored messages, and if so, do not perform monitoring processing on the monitored messages; if not, perform subsequent monitoring deal with.
- the method further includes: judging whether the monitored suspicious user meets the blacklist generating widget set by the monitoring management station 130 (such as being detected in a unit time). In order to determine whether the frequency of suspicious users reaches the specified threshold, suspicious users who meet the blacklist generation conditions are determined as blacklisted users.
- the service processor 110 After receiving the user blacklist from the monitoring server 120, the service processor 110 stores the user blacklist in the user blacklist table.
- This table may use a memory table in the form of an in-memory database.
- the service processor 110 performs filtering processing on the blacklisted users according to the user blacklist table, intercepts messages of the users in the user blacklist table, and processes only messages of legitimate users.
- the monitoring server 120 periodically checks the user blacklist table according to the banning conditions configured by the monitoring management station 130, selects the blacklist users who meet the banning conditions, generates a blacklist banning list, and sends it to the service processor 110.
- the service processor 110 After receiving the blacklist lifted list, the service processor 110 deletes the users in the lifted list from the user blacklist and unblocks its information services.
- Figure 5 shows the process of the service processor controlling the information service processing according to the user blacklist.
- the service processor 110 receives the information to be processed (step 501), and then checks whether the user of the information is recorded in the user blacklist (step 502). If it has been recorded in the user blacklist, the service processor 110 terminates the processing of the information service, and can determine whether to save the truncated information according to the configuration of the system (step 503). If the information user is not a blacklisted user, the service processor 110 performs normal processing on the information service (step 504).
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Information Transfer Between Computers (AREA)
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CNB03140202XA CN1314293C (zh) | 2003-08-15 | 2003-08-15 | 一种用于消息中心智能监控的系统和方法 |
| CN03140202.X | 2003-08-15 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2005018152A1 true WO2005018152A1 (en) | 2005-02-24 |
Family
ID=34155246
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2004/000486 Ceased WO2005018152A1 (en) | 2003-08-15 | 2004-05-14 | A system and method of intelligently monitoring the message centers |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN1314293C (zh) |
| WO (1) | WO2005018152A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103491518A (zh) * | 2013-09-09 | 2014-01-01 | 北京思特奇信息技术股份有限公司 | 一种安全高效的预防移动用户恶意欠费的方法 |
Families Citing this family (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2006098668A1 (en) * | 2005-03-18 | 2006-09-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Lawful interception of unauthorized subscribers and equipments |
| CN1997058B (zh) * | 2005-12-29 | 2010-09-29 | 山东移动通信有限责任公司 | 一种高流量短信监控的方法 |
| CN101453528B (zh) * | 2007-11-30 | 2010-12-15 | 上海粱江通信系统股份有限公司 | 一种实现呼叫鉴权网关的系统及方法 |
| CN101600170A (zh) * | 2009-06-01 | 2009-12-09 | 中兴通讯股份有限公司 | 一种消息监控装置、监控系统及监控方法 |
| CN101609319B (zh) * | 2009-07-17 | 2012-09-05 | 中国印钞造币总公司 | 一种实时监测程序运行状态的电路装置 |
| CN101997730B (zh) * | 2009-08-20 | 2012-11-21 | 中国移动通信集团辽宁有限公司 | 业务触发告警的方法及系统 |
| CN104734895B (zh) * | 2013-12-18 | 2018-05-22 | 青岛海尔空调器有限总公司 | 业务监控系统及业务监控方法 |
| CN108452525B (zh) * | 2017-12-25 | 2021-06-29 | 福建省天奕网络科技有限公司 | 一种游戏中聊天信息的监控方法及系统 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1350246A (zh) * | 2001-12-03 | 2002-05-22 | 上海交通大学 | 智能化的电子邮件内容过滤方法 |
| CN1422050A (zh) * | 2001-11-26 | 2003-06-04 | 深圳市中兴通讯股份有限公司上海第二研究所 | 短消息过滤监管网关与方法 |
| CN1426214A (zh) * | 2001-12-19 | 2003-06-25 | 深圳市中兴通讯股份有限公司上海第二研究所 | 一种短消息监管的方法及设备 |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FI106509B (fi) * | 1997-09-26 | 2001-02-15 | Nokia Networks Oy | Laillinen salakuuntelu tietoliikenneverkossa |
-
2003
- 2003-08-15 CN CNB03140202XA patent/CN1314293C/zh not_active Expired - Fee Related
-
2004
- 2004-05-14 WO PCT/CN2004/000486 patent/WO2005018152A1/zh not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1422050A (zh) * | 2001-11-26 | 2003-06-04 | 深圳市中兴通讯股份有限公司上海第二研究所 | 短消息过滤监管网关与方法 |
| CN1350246A (zh) * | 2001-12-03 | 2002-05-22 | 上海交通大学 | 智能化的电子邮件内容过滤方法 |
| CN1426214A (zh) * | 2001-12-19 | 2003-06-25 | 深圳市中兴通讯股份有限公司上海第二研究所 | 一种短消息监管的方法及设备 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103491518A (zh) * | 2013-09-09 | 2014-01-01 | 北京思特奇信息技术股份有限公司 | 一种安全高效的预防移动用户恶意欠费的方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN1582038A (zh) | 2005-02-16 |
| CN1314293C (zh) | 2007-05-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP6385896B2 (ja) | 無線装置でコンテンツ変換を管理する装置および方法 | |
| CN101459718B (zh) | 一种基于移动通信网的垃圾语音过滤方法及其系统 | |
| CN103152352B (zh) | 一种基于云计算环境的全信息安全取证监听方法和系统 | |
| CN101548506B (zh) | 用于确定安全性攻击的装置和安全性节点 | |
| CN102915374B (zh) | 一种控制数据库资源访问的方法、装置及系统 | |
| JP4512361B2 (ja) | データ伝送ネットワーク中のトラフィック管理制御のためのシステムおよび方法 | |
| CN101431434B (zh) | 基于wap的内容监控及封堵系统和方法 | |
| CN113032710A (zh) | 一种综合审计监管系统 | |
| CN107733863B (zh) | 一种分布式hadoop环境下的日志调试方法和装置 | |
| CN106850690B (zh) | 一种蜜罐构造方法及系统 | |
| WO2016197675A1 (zh) | 骚扰电话的识别方法及装置 | |
| CN102906756A (zh) | 与安全事件和参与者分类模型相关联的安全威胁检测 | |
| CN102158830B (zh) | 一种移动网络垃圾信息实时监控系统 | |
| WO2005018152A1 (en) | A system and method of intelligently monitoring the message centers | |
| GB2391419A (en) | Restricting the propagation of a virus within a network | |
| CN101702801A (zh) | 短消息监控方法和系统 | |
| CN103888919A (zh) | 短消息监控方法及装置 | |
| CN114254378A (zh) | 一种基于Windows的文件上传下载管控系统及方法 | |
| CN102595357B (zh) | 一种短消息监控方法和系统 | |
| US20100175103A1 (en) | Reactive throttling of inbound messages and ranges | |
| CN111259383B (zh) | 一种安全管理中心系统 | |
| CN101494598A (zh) | 流量控制方法、装置及系统 | |
| WO2025138625A1 (zh) | 保护个人隐私的垃圾信息处理装置、系统和介质 | |
| CN119449433A (zh) | Poe驱动的物联网设备多维安全监控与防护系统 | |
| CN108040031A (zh) | 一种基于portal协议实现AC黑白名单控制方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BW BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE EG ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NA NI NO NZ OM PG PH PL PT RO RU SC SD SE SG SK SL SY TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW |
|
| AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): BW GH GM KE LS MW MZ NA SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
| 122 | Ep: pct application non-entry in european phase |