WO2015188500A1 - 一种短信监控方法及装置 - Google Patents

一种短信监控方法及装置 Download PDF

Info

Publication number
WO2015188500A1
WO2015188500A1 PCT/CN2014/086970 CN2014086970W WO2015188500A1 WO 2015188500 A1 WO2015188500 A1 WO 2015188500A1 CN 2014086970 W CN2014086970 W CN 2014086970W WO 2015188500 A1 WO2015188500 A1 WO 2015188500A1
Authority
WO
WIPO (PCT)
Prior art keywords
calling number
short message
user group
preset
threshold
Prior art date
Application number
PCT/CN2014/086970
Other languages
English (en)
French (fr)
Inventor
王飞
储小霞
冯亚军
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Publication of WO2015188500A1 publication Critical patent/WO2015188500A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/12Messaging; Mailboxes; Announcements
    • H04W4/14Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD]

Definitions

  • the present invention relates to the field of communications, and in particular, to a method and device for monitoring short messages.
  • the present invention provides a short message monitoring method and apparatus, which can realize differentiated short message interception processing for different users by setting user groups for different users and assigning different security coefficients to different user groups. , improve the accuracy of SMS interception, reduce the situation of false and missed.
  • the present invention provides a short message monitoring method, including: determining, for a calling number, a caller according to a correspondence between a preset user packet corresponding to a security factor and the calling number. a safety factor of the number; determining an actual violation threshold of the calling number according to a preset basic violation threshold and a safety factor of the calling number; determining, according to the actual violation threshold, the calling number within a preset time Whether the sent short message is in violation, and in case of violation, the short message sent by the calling number within the preset time is processed.
  • the method for monitoring the short message wherein the determining the actual violation threshold of the calling number is specifically: determining that the actual violation threshold of the calling number is a preset basic violation threshold and a safety factor of the calling number product.
  • the user group includes a high-risk user group, a normal user group, and a low-risk user group, wherein the security factor corresponding to the low-risk user group is higher than the security factor corresponding to the normal user group, and is high.
  • the security factor corresponding to the risk user group is lower than the security factor corresponding to the normal user group.
  • the basic violation threshold includes a short message flow threshold sent by the calling number in the preset time and/or a short message sent by the calling number in the preset time
  • the above-mentioned short message monitoring method wherein the to-be-processed short message is encapsulated in a message of an SMPP format; and the obtaining, before sending the calling number of the to-be-processed short message and the attribute information of the to-be-processed short message, includes: The message in the SMPP format is decoded to obtain a short message to be processed.
  • the present invention further provides a short message monitoring apparatus, comprising: a first determining module, configured to determine, according to a calling number, a correspondence between a preset user group corresponding to a security factor and the calling number, Determining a safety factor of the calling number; the second determining module is configured to determine an actual violation threshold of the calling number according to a preset basic violation threshold and a safety factor of the calling number; and the monitoring processing module is set according to The actual violation threshold value is used to determine whether the short message sent by the calling number within a preset time period is violated, and when the violation occurs, the short message sent by the calling number within the preset time is processed.
  • the above-mentioned short message monitoring apparatus wherein the second determining module is configured to determine that the actual violation threshold of the calling number is a product of a preset basic violation threshold and a safety factor of the calling number.
  • the first determining module is configured to determine that the calling number has a security factor of 1.
  • the user group includes a high-risk user group, a general user group, and a low-risk user group, wherein the low-risk user group corresponds to a safety factor higher than a common user group corresponding to a safety factor, and the high risk
  • the security factor corresponding to the user group is lower than the security factor corresponding to the normal user group.
  • the basic violation threshold includes a short message flow threshold sent by the calling number in the preset time and/or a short message sent by the calling number in the preset time
  • the short message monitoring device wherein the to-be-processed short message is encapsulated in a message in an SMPP format, and the device further includes: a decoding module, configured to perform decoding processing on the SMPP format message to obtain a short message to be processed.
  • the monitoring processing module is plural; the device further includes: a modulo module, configured to take the number of the monitoring processing module according to the mantissa of the calling number of the short message to be processed And the third determining module is configured to determine that the monitoring processing module corresponding to the to-be-processed short message is a monitoring processing module numbered as the modulus value.
  • the above-mentioned short message monitoring device further includes: a configuration module, configured to configure a correspondence between the calling number and the user group according to an operation instruction of the user, and set a basic violation threshold and a safety factor corresponding to each user group.
  • the invention provides a short message monitoring method and device, which can set different user groups for different users and assign different security coefficients to different user groups, thereby realizing differentiated short message interception processing for different users and improving short message interception. Accuracy reduces the amount of false and missed.
  • FIG. 1 is a schematic flowchart diagram of a short message monitoring method according to Embodiment 1 of the present invention.
  • FIG. 2 is a schematic flowchart of a short message monitoring method according to Embodiment 2 of the present invention.
  • FIG. 3 is a schematic structural diagram of a short message monitoring apparatus according to Embodiment 1 of the present invention.
  • FIG. 4 is a schematic structural diagram of a short message monitoring apparatus according to Embodiment 2 of the present invention.
  • FIG. 5 is a flow chart of information interaction performed by the short message monitoring apparatus according to Embodiment 3 of the present invention.
  • the embodiment of the present invention provides a method for monitoring a short message and a device for monitoring a spam message in the prior art, and provides a method for monitoring a short message by setting a user group for different users and for different users.
  • the group assigns different security factors to realize differentiated SMS interception processing for different users, which improves the accuracy of short message interception and reduces the situation of false interception and missed interception.
  • FIG. 1 is a schematic flowchart of a short message monitoring method according to Embodiment 1 of the present invention. As shown in the figure, the method includes:
  • Step S100 Determine, for a calling number, a security factor of the calling number according to a correspondence between a preset user group corresponding to a security factor and the calling number;
  • Step S102 Determine, according to a preset basic violation threshold and a security factor of the calling number, an actual violation threshold of the calling number;
  • Step S104 Determine, according to the actual violation threshold, whether the short message sent by the calling number in a preset time is in violation, and if the violation is in violation, perform the short message sent by the calling number within the preset time. deal with.
  • the security factor of the calling number is determined according to the user group corresponding to the calling number, and the actual violation threshold corresponding to the calling number is determined according to the basic violation threshold, and the actual violation threshold is determined according to the actual violation threshold.
  • the short message sent by the calling number within the preset time is illegal.
  • the calling number is sent within the preset time, the short message is sent to the calling number during the time.
  • the processing in particular, can intercept the short message sent by the calling number when the violation occurs, because each calling number has an actual intercepting threshold corresponding thereto, and realizes differentiated short message processing for different users. , improve the accuracy of SMS interception, reduce the situation of false and missed.
  • the method for monitoring the short message wherein the determining the actual violation threshold of the calling number may be specifically: determining that the actual violation threshold of the calling number is a preset basic violation threshold and a safety factor of the calling number The product of.
  • the security factor corresponding to the user group to which the calling number belongs is R
  • the pre-configured basic violation threshold is X
  • the actual violation threshold used when monitoring the short message sent by the calling number is the security factor and the basic violation threshold.
  • the product R*X so the higher the safety factor, the greater the actual violation threshold, which means that the monitoring requirements for the calling number are more relaxed.
  • the security coefficient corresponding to the calling number is first determined. Therefore, the foregoing short message monitoring method, when there is no When the preset user group corresponding to the calling number is determined, the security factor corresponding to the calling number is determined to be 1.
  • the purpose of the above operation is to set the corresponding security factor to 1 for the calling number of the user group, and the actual violation threshold is the default basic violation threshold.
  • the user grouping may include a high-risk user group, a normal user group, and a low-risk user group, wherein the security factor corresponding to the low-risk user group is higher than the security factor corresponding to the ordinary user group, and The safety factor corresponding to the high-risk user group is lower than the safety factor corresponding to the normal user group.
  • the high-risk user group, the normal user group, and the low-risk user group may be set according to the risk degree of the short message sent by the calling number, wherein the short message sent by the calling number in the high-risk user group is garbage.
  • the possibility of short messages is high, and the short message sent by the calling number in the low-risk user group is less likely to be spam.
  • the security factor indicates the security of the user group, and the security factor of a certain user group is high. , indicating that the user group has low possibility of sending spam messages, high security, and low security factor, indicating that the user group has high possibility of sending spam messages, and the security is low, and can be judged according to the situation of the short message sent by the calling number in the past.
  • the calling number belongs to a high-risk user group, a normal user group, or a low-risk user group.
  • the basic violation threshold includes a short message flow threshold sent by the calling number in the preset time and/or a short message sent by the calling number in the preset time
  • the basic violation threshold is a threshold value set according to the content of the short message. Specifically, it may be a threshold of the short message flow sent within the preset time, and may also be a threshold of the number of the short message carrying the preset keyword within a preset time.
  • the rejection keywords have been set to: "Advertisement", “Tax Avoidance”, “Account”, “Fidelity”, “Insurance”, “Villa”, etc., and the preset keyword is carried in the preset time.
  • the number of text messages is limited to three. If the calling number is within the monitoring time range, there are 2 villas with "villa” and 2 messages with "fidelity". In the short message sent by the calling number within the monitoring time range, the number of short messages carrying the rejected keyword reaches 4, and if the threshold is exceeded, the short message is considered to be violated during the time. Process it.
  • the corresponding thresholds may be set according to the attribute information of other short messages.
  • the short message sending interval threshold may be set to determine the time interval attribute of the short message sent by the calling number.
  • the basic violation threshold indicates: if monitoring Within the time range, the calling number A sends two short messages, and the sending time interval of the two short messages is less than 60/T seconds, indicating that the calling number A has a violation during the monitoring time;
  • the whitelist that is, if the calling number of the short message is blacklist for a short message, the violation is considered to be a violation, and if the calling number of the short message is a whitelist, it is considered to be non-violation.
  • the above-mentioned short message monitoring method wherein the to-be-processed short message is encapsulated in a message of the SMPP format; and the obtaining, before the sending of the calling number of the to-be-processed short message and the attribute information of the to-be-processed short message, may further include: The message in the SMPP format is decoded to obtain a short message to be processed.
  • FIG. 2 is a schematic flowchart of a short message monitoring method according to Embodiment 2 of the present invention. As shown in the figure, the method includes:
  • step S200 the correspondence between the calling number and the user group is updated according to the historical monitoring record, wherein the historical monitoring record refers to the previous monitoring data, and the correspondence between the calling number and the user group is updated according to the previous monitoring data.
  • the current calling number A belongs to a high-risk user group.
  • the corresponding relationship can be updated to make the calling number A and the ordinary User group correspondence;
  • Step S202 configuring a basic violation threshold, a monitoring period, and a security factor corresponding to each user group;
  • Step S204 Receive a short message monitoring request in an SMPP format sent by the short message center, where the monitoring request includes a to-be-processed short message, and the calling number of the to-be-processed short message is sent;
  • Step S206 decoding the short message monitoring request in the SMPP format
  • Step S208 querying the corresponding user group and the security factor according to the calling number. If the calling number does not belong to any user group, the security factor is set to 1;
  • Step S210 Determine, according to the corresponding security factor and the basic violation threshold, the actual violation threshold of the calling number, determine whether the pending short message sent by the calling number in the monitoring period exceeds the actual violation threshold, and records the monitoring result;
  • Step S212 the monitoring result is returned to the short message center, and the short message center performs a corresponding operation according to the monitoring result.
  • FIG. 3 is a schematic structural diagram of a short message monitoring apparatus according to Embodiment 1 of the present invention. As shown in the figure, the short message monitoring apparatus 30 includes:
  • the first determining module 31 is configured to determine, according to a calling number, a security factor of the calling number according to a correspondence between a preset user group corresponding to a security factor and the calling number;
  • the second determining module 32 is configured to determine an actual violation threshold of the calling number according to a preset basic violation threshold and a security factor of the calling number;
  • the monitoring processing module 33 is configured to determine, according to the actual violation threshold, whether the short message sent by the calling number in a preset time is in violation, and in the event of a violation, the calling number is within the preset time The sent SMS is processed.
  • the above-mentioned short message monitoring apparatus wherein the second determining module is configured to determine that the actual violation threshold of the calling number is a product of a preset basic violation threshold and a safety factor of the calling number.
  • the first determining module is configured to determine that the calling number has a security factor of 1.
  • the user group includes a high-risk user group, a general user group, and a low-risk user group, wherein the low-risk user group corresponds to a safety factor higher than a common user group corresponding to a safety factor, and the high risk
  • the security factor corresponding to the user group is lower than the security factor corresponding to the normal user group.
  • the basic violation threshold includes a short message flow threshold sent by the calling number in the preset time and/or a short message sent by the calling number in the preset time
  • the short message monitoring device wherein the to-be-processed short message is encapsulated in a message in an SMPP format, and the device further includes: a decoding module, configured to perform decoding processing on the SMPP format message to obtain a short message to be processed.
  • the monitoring processing module is plural; the device further includes: a modulo module, configured to take the number of the monitoring processing module according to the mantissa of the calling number of the short message to be processed And the third determining module is configured to determine that the monitoring processing module corresponding to the to-be-processed short message is a monitoring processing module numbered as the modulus value.
  • the above-mentioned short message monitoring device further includes: a configuration module, configured to configure a correspondence between the calling number and the user group according to an operation instruction of the user, and set a basic violation threshold and a safety factor corresponding to each user group.
  • the short message monitoring apparatus 40 includes:
  • the network security agent module 41 is configured to implement the functions of the decoding module, the modulo module, and the third determining module in the first embodiment, receive the short message monitoring request sent by the short message center, and determine a real-time monitoring service processing module for the monitoring request, During the monitoring time range, if the short message sent by the calling number is monitored and processed, the monitoring result is returned to the short message center;
  • the real-time monitoring service processing module 42 is configured to implement the functions of the first determining module, the second determining module, and the monitoring processing module in Embodiment 1, determine the actual violation threshold corresponding to the calling number, and determine that the calling number is within the monitoring time range. Whether the sent SMS is in violation, the real-time monitoring service processing module can be deployed for load sharing;
  • the user information management module 43 is configured to store a correspondence between the calling number and the user group and a security factor corresponding to the user group, and the real-time monitoring service processing module determines, according to the correspondence stored in the user information management module, the calling number belongs to User grouping, BOSS (Business & Operation Support System) can add, modify or delete user groupings to the user information management module;
  • BOSS Business & Operation Support System
  • the monitoring rule setting module 44 is configured to set a basic violation threshold according to the user operation information, and the basic violation threshold may be multiple, and set a user group to which each basic violation threshold is applicable;
  • the interface module 45 is configured to perform information transmission between the short message monitoring device and the BOSS, wherein the BOSS system receives the suspected spam message detected by the short message monitoring module and exceeds the violation threshold, further reviews the packet, and finally determines the spam message and generates the monitoring. recording.
  • FIG. 5 is a flowchart of information interaction performed by a short message monitoring apparatus according to Embodiment 3 of the present invention, as shown in the figure, including:
  • Step S500 the BOSS system sends the correspondence between the calling number and the user group to the interface module in the short message monitoring device by using ftp;
  • Step S502 the interface module synchronizes the correspondence between the calling number and the user group to the user information management module in the short message monitoring device;
  • Step S504 the short message center sends a short message monitoring request to the calling number A to the network security agent module in the short message monitoring device, wherein the short message monitoring request includes information such as the calling number A, the called number, and the content of the to-be-processed short message;
  • Step S506 the network security proxy module decodes the short message monitoring request in the SMPP format, and sends the decoded short message monitoring request to a real-time monitoring service processing module in the short message monitoring device by modulo the tail number of the calling number A;
  • Step S508 the real-time monitoring service processing module sends a query request to the user information management module, and queries the user group and the security coefficient corresponding to the calling number A;
  • Step S510 the user information management module feeds back the user group to which the calling number A belongs to the real-time monitoring service processing module: high-risk user group ID, safety factor 0.2;
  • Step S514 the real-time monitoring service processing module sends the monitoring result to the network security agent module;
  • Step S520 the interface module sends the violation record to the BOSS system storage in the form of ftp, so that the correspondence between the calling number and the user group can be updated according to the violation record.
  • the SMS interception processing for different users is realized, the accuracy of the short message interception is improved, and the situation of false interception and missed intercept is reduced.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

本发明提供了一种短信监控方法及装置,所述短信监控方法,包括:针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定主叫号码的安全系数;根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;根据实际违规门限,判断所述主叫号码在一预设时间内发送的是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。采用本发明提供的技术方案,通过为不同用户设置用户分组,并为不同的用户分组分配不同的安全系数,实现对不同的用户进行差异化的短信拦截处理,提高了短信拦截的精准度,减少了误拦和漏拦的情况。

Description

一种短信监控方法及装置 技术领域
本发明涉及通信领域,尤其涉及一种短信监控方法及装置。
背景技术
目前,中国手机用户数量已超过10亿,而随着手机使用的普及和短信业务的迅速发展,人们享受着快捷方便的通信手段的同时,伴随而来的却是日趋泛滥的垃圾短信。垃圾短信产生的根源在于短信的发送成本极其低廉,而获得的广告效益却非常之高。垃圾短信不仅对运营商的网络产生冲击,给广大用户的利益也带来了巨大的损害,更造成了严重的不良的社会影响。国外在垃圾短信的治理上,主要通过立法和先进的技术手段来识别并处理欺诈性的信息及手机,还有一整套的打击手机犯罪的先进技术手段。在国内,垃圾短信防控任务主要由运营商主导和负责,通常从技术和管理上采取措施,立法方面还比较欠缺。
近年来,运营商越来越重视垃圾短信的治理,目前运营商已部署了大量的垃圾监控系统,垃圾短信监控技术也愈来愈成熟。从原理上,目前应用最广泛的是基于流量的监控和基于关键字的内容监控。然而,目前的监控系统监控精准度仍然不够理想,存在大量的误拦和漏拦的情况,对于误拦的情况可能还会导致用户投诉,影响用户满意度。
发明内容
为了解决上述技术问题,本发明提供了一种短信监控方法及装置,通过为不同用户设置用户分组,并为不同的用户分组分配不同的安全系数,实现对不同的用户进行差异化的短信拦截处理,提高了短信拦截的精准度,减少了误拦和漏拦的情况。
为了实现上述目的,本发明提供了一种短信监控方法,包括:针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定所述主叫号码的安全系数;根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;根据所述实际违规门限,判断主叫号码在一预设时间内发送的短信是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。
上述的短信监控方法,其中,所述确定所述主叫号码的实际违规门限具体为:确定所述主叫号码的实际违规门限为预设的基础违规门限及所述主叫号码的安全系数的乘积。
上述的短信监控方法,其中,当不存在与所述主叫号码对应的预设的用户分组时,确定所述主叫号码对应的安全系数为1。
上述的短信监控方法,其中,所述用户分组包括高风险用户组、普通用户组及低风险用户组,其中,低风险用户组对应的安全系数要高于普通用户组对应的安全系数,而高风险用户组对应的安全系数要低于普通用户组对应的安全系数。
上述的短信监控方法,其中,所述基础违规门限包括所述主叫号码在所述预设时间内发送的短信流量门限和/或所述主叫号码在所述预设时间内发送的短信中携带有预设关键字的短信的个数门限。
上述的短信监控方法,其中,所述待处理短信封装在SMPP格式的消息中;所述获取发送所述待处理短信的主叫号码及所述待处理短信的属性信息之前,还包括:对所述SMPP格式的消息进行解码处理得到待处理短信。
本发明还提供了一种短信监控装置,包括:第一确定模块,设置为针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定所述主叫号码的安全系数;第二确定模块,设置为根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;监控处理模块,设置为根据所述实际违规门限值,判断所述主叫号码在一预设时间内发送的短信是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。
上述的短信监控装置,其中,所述第二确定模块设置为确定所述主叫号码的实际违规门限为预设的基础违规门限及所述主叫号码的安全系数的乘积。
上述的短信监控装置,其中,当不存在与所述主叫号码对应的预设的用户分组时,所述第一确定模块设置为确定所述主叫号码的安全系数为1。
上述的短信监控装置,其中,所述用户分组包括高风险用户组、普通用户组及低风险用户组,其中低风险用户组对应的安全系数要高于普通用户组对应的安全系数,而高风险用户组对应的安全系数要低于普通用户组对应的安全系数。
上述的短信监控装置,其中,所述基础违规门限包括所述主叫号码在所述预设时间内发送的短信流量门限和/或所述主叫号码在所述预设时间内发送的短信中携带有预设关键字的短信的个数门限。
上述的短信监控装置,其中,所述待处理短信封装在SMPP格式的消息中;所述装置还包括:解码模块,设置为对所述SMPP格式的消息进行解码处理得到待处理短信。
上述的短信监控装置,其中,所述监控处理模块为多个;所述装置还包括:取模模块,设置为根据发送待处理短信的主叫号码的尾数对所述监控处理模块的个数取模,得到模值;第三确定模块,设置为确定所述待处理短信对应的监控处理模块为编号为所述模值的监控处理模块。
上述的短信监控装置,其中,还包括:配置模块,设置为根据用户的操作指令,配置主叫号码与用户分组的对应关系,并设置基础违规门限及每一用户分组对应的安全系数。
本发明的上述技术方案的有益效果如下:
本发明提供了一种短信监控方法及装置,通过为不同用户设置用户分组,并为不同的用户分组分配不同的安全系数,实现对不同的用户进行差异化的短信拦截处理,提高了短信拦截的精准度,减少了误拦和漏拦的情况。
附图说明
图1为本发明实施例1提供的短信监控方法的流程示意图。
图2为本发明实施例2提供的短信监控方法流程示意图。
图3为本发明实施例1提供的短信监控装置的结构示意图。
图4为本发明实施例2提供的短信监控装置的结构示意图。
图5为本发明实施例3提供的短信监控装置进行监控的信息交互流程图。
具体实施方式
为使本发明要解决的技术问题、技术方案和优点更加清楚,下面将结合附图及具体实施例进行详细描述。
本发明实施例针对现有技术中在对垃圾短信进行拦截的时候,存在误拦或漏拦的情况,提供了一种短信监控方法及装置,通过为不同用户设置用户分组,并为不同的用户分组分配不同的安全系数,实现对不同的用户进行差异化的短信拦截处理,提高了短信拦截的精准度,减少了误拦和漏拦的情况。
图1为本发明实施例1提供的短信监控方法的流程示意图,如图所示,所述方法包括:
步骤S100,针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定所述主叫号码的安全系数;
步骤S102,根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;
步骤S104,根据所述实际违规门限,判断所述主叫号码在一预设时间内发送的短信是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。
本发明提供的短信监控方法中,根据主叫号码对应的用户分组,确定主叫号码的安全系数,并根据基础违规门限确定对应于该主叫号码的实际违规门限,根据该实际违规门限判断该主叫号码在预设时间内(监控时间段内)发送的短信是否违规,当主叫号码在预设时间内发送的短信违规时,对该主叫号码在该时间内发送的短信进行相应的处理,具体为,可以在违规时,对该主叫号码发送的短信进行拦截,由于,对于每个主叫号码都有与其对应的实际拦截门限,实现了对不同的用户进行差异化的短信处理,提高了短信拦截的精准度,减少了误拦和漏拦的情况。
上述的短信监控方法,其中,所述确定所述主叫号码的实际违规门限可以具体为:确定所述主叫号码的实际违规门限为预设的基础违规门限及所述主叫号码的安全系数的乘积。
若某主叫号码所属的用户分组对应的安全系数为R,预配置的基础违规门限为X,则在监控该主叫号码发送的短信时,所使用的实际违规门限为安全系数与基础违规门限的乘积R*X,因此安全系数越高实际违规门限值越大,也意味着对该主叫号码的监控要求越宽松。
如果一主叫号码没有与之对应的用户分组,在确定该主叫号码的实际违规门限时首先要确定该主叫号码对应的安全系数,因此,上述的短信监控方法,其中,当不存在与所述主叫号码对应的预设的用户分组时,确定所述主叫号码对应的安全系数为1。
上述操作的目的是,对未设置用户分组的主叫号码,设置其对应的安全系数为1,其实际违规门限即为预设的基础违规门限。
上述的短信监控方法,其中,所述用户分组可以包括高风险用户组、普通用户组及低风险用户组,其中,低风险用户组对应的安全系数要高于普通用户组对应的安全系数,而高风险用户组对应的安全系数要低于普通用户组对应的安全系数。
在设置用户分组时,可以根据主叫号码发送的短信的风险程度,设置高风险用户组、普通用户组及低风险用户组,其中,高风险用户组中的主叫号码所发送的短信为垃圾短信的可能性较高,而低风险用户组中的主叫号码所发送的短信为垃圾短信的可能性较低,安全系数表征了用户组的安全性的高低,某一用户组的安全系数高,表明该用户组发送垃圾短信的可能性低,安全性高,安全系数低,则表明该用户组发送垃圾短信的可能性高,安全性低,可以根据主叫号码以往发送的短信的情况判断主叫号码属于高风险用户组、普通用户组还是低风险用户组。
上述的短信监控方法,其中,所述基础违规门限包括所述主叫号码在所述预设时间内发送的短信流量门限和/或所述主叫号码在所述预设时间内发送的短信中携带有预设关键字的短信的个数门限。
基础违规门限根据短信的内容设置的门限值,具体的,可以为在预设时间内发送的短信流量门限,还可以为在预设时间内携带有预设关键字的短信的个数门限,例如,已经设置了拒绝关键字为:“广告”、“避税”、“办证”、“保真”、“保险”、“别墅”等,而设置了在预设时间内携带有预设关键字的短信的个数门限为3个,则如果主叫号码在监控时间范围内发送的短信信息中,有2条短信中出现了“别墅”,2条短信中出现了“保真”,即该主叫号码在监控时间范围内发送的短信中,携带有拒绝关键字的短信的条数达到了4条,超出了门限值,则认为该主叫号码在该时间内发送的短信违规,需要进行处理。
当然,除了上述的门限,还可以根据其他的短信的属性信息设置对应的门限。例如,可以设置短信发送时间间隔门限用于对主叫号码发送短信的时间间隔属性进行判断,对于一主叫号码A,如果设置短信发送时间间隔门限为T,该基础违规门限表示:如果在监控时间范围内,该主叫号码A发送了两条短信,该两条短信的发送时间间隔低于60/T秒,则表明该主叫号码A在监控时间内出现了违规;还可以设置黑名单及白名单,即如果对于一条短信,发送该短信的主叫号码属于黑名单,则认为出现违规,反之,如果发送该短信的主叫号码属于白名单,则认为未违规。
上述的短信监控方法,其中,所述待处理短信封装在SMPP格式的消息中;所述获取发送所述待处理短信的主叫号码及所述待处理短信的属性信息之前,还可包括:对所述SMPP格式的消息进行解码处理得到待处理短信。
图2为本发明实施例2提供的短信监控方法流程示意图,如图所示,所述方法包括:
步骤S200,根据历史监控记录更新主叫号码与用户分组的对应关系,其中,历史监控记录指的是以往的监控数据,根据该以往的监控数据中对主叫号码与用户分组的对应关系进行更新,例如,当前主叫号码A属于高风险用户分组,但是,从以往监控数据来看,发现该主叫号码A并未频繁发送垃圾短信,则,可以更新对应关系,使主叫号码A与普通用户分组对应;
步骤S202,配置基础违规门限、监控周期及每个用户分组对应的安全系数;
步骤S204,接收短信中心下发的SMPP格式的短信监控请求,该监控请求中包括待处理短信,发送待处理短信的主叫号码;
步骤S206,对SMPP格式的短信监控请求进行解码;
步骤S208,根据主叫号码查询对应的用户分组及安全系数,如果该主叫号码不属于任一用户分组,则安全系数设置为1;
步骤S210,根据对应的安全系数及基础违规门限确定该主叫号码的实际违规门限,判断该主叫号码在监控周期内发送的待处理短信是否超出实际违规门限并记录监控结果;
步骤S212,将监控结果返回给短信中心,短信中心根据该监控结果执行相应操作。
图3为本发明实施例1提供的短信监控装置的结构示意图,如图所示,所述短信监控装置30包括:
第一确定模块31,设置为针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定所述主叫号码的安全系数;
第二确定模块32,设置为根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;
监控处理模块33,设置为根据所述实际违规门限,判断所述主叫号码在一预设时间内发送的短信是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。
上述的短信监控装置,其中,所述第二确定模块设置为确定所述主叫号码的实际违规门限为预设的基础违规门限及所述主叫号码的安全系数的乘积。
上述的短信监控装置,其中,当不存在与所述主叫号码对应的预设的用户分组时,所述第一确定模块设置为确定所述主叫号码的安全系数为1。
上述的短信监控装置,其中,所述用户分组包括高风险用户组、普通用户组及低风险用户组,其中低风险用户组对应的安全系数要高于普通用户组对应的安全系数,而高风险用户组对应的安全系数要低于普通用户组对应的安全系数。
上述的短信监控装置,其中,所述基础违规门限包括所述主叫号码在所述预设时间内发送的短信流量门限和/或所述主叫号码在所述预设时间内发送的短信中携带有预设关键字的短信的个数门限。
上述的短信监控装置,其中,所述待处理短信封装在SMPP格式的消息中;所述装置还包括:解码模块,设置为对所述SMPP格式的消息进行解码处理得到待处理短信。
上述的短信监控装置,其中,所述监控处理模块为多个;所述装置还包括:取模模块,设置为根据发送待处理短信的主叫号码的尾数对所述监控处理模块的个数取模,得到模值;第三确定模块,设置为确定所述待处理短信对应的监控处理模块为编号为所述模值的监控处理模块。
上述的短信监控装置,其中,还包括:配置模块,设置为根据用户的操作指令,配置主叫号码与用户分组的对应关系,并设置基础违规门限及每一用户分组对应的安全系数。
图4为本发明实施例2提供的短信监控装置的结构示意图,如图所示,所述短信监控装置40包括:
网安代理模块41,设置为实现实施例1中的解码模块、取模模块及第三确定模块的功能,接收短信中心下发的短信监控请求,确定对该监控请求进行实时监控业务处理模块,在监控时间范围内,对主叫号码发送的短信进行监控处理的,将监控结果返回给短信中心;
实时监控业务处理模块42,设置为实现实施例1中的第一确定模块、第二确定模块及监控处理模块的功能,确定主叫号码对应的实际违规门限,判断主叫号码在监控时间范围内发送的短信是否违规,实时监控业务处理模块可以部署多个用于负荷分担;
用户信息管理模块43,设置为存储主叫号码与用户分组之间的对应关系及用户分组对应的安全系数,实时监控业务处理模块根据该用户信息管理模块中存储的对应关系确定主叫号码所属的用户分组,BOSS(Business&Operation Support System,业务运营支撑系统)可以向用户信息管理模块中添加、修改或删除用户分组;
监控规则设置模块44,设置为根据用户操作信息设置基础违规门限,基础违规门限可以有多条,并设置每一条基础违规门限所适用的用户分组;
接口机模块45,设置为在短信监控装置与BOSS之间进行信息传递,其中BOSS系统接收到短信监控模块检测的超出违规门限的嫌疑垃圾短信,对其进行进一步审核,最终确定垃圾短信,生成监控记录。
图5为本发明实施例3提供的短信监控装置进行监控的信息交互流程图,如图所示,包括:
步骤S500,BOSS系统将主叫号码与用户分组的对应关系通过ftp发送给短信监控装置中的接口机模块;
步骤S502,接口机模块将主叫号码与用户分组的对应关系同步给短信监控装置中的用户信息管理模块;
步骤S504,短信中心下发对主叫号码A的短信监控请求给短信监控装置中的网安代理模块,其中短信监控请求中包括主叫号码A、被叫号码及待处理短信的内容等信息;
步骤S506,网安代理模块解码SMPP格式的短信监控请求,并通过对主叫号码A的尾数取模将解码后的短信监控请求发送给短信监控装置中的某个实时监控业务处理模块;
步骤S508,实时监控业务处理模块向用户信息管理模块发送查询请求,查询主叫号码A对应的用户分组及安全系数;
步骤S510,用户信息管理模块将主叫号码A所属的用户分组反馈给实时监控业务处理模块:高风险用户分组ID,安全系数0.2;
步骤S512,实时监控业务处理模块根据基础违规门限计算主叫号码A的实际违规门限,对待处理短信进行违规判断,得到监控结果,例如,如果基础违规门限中限制短信流量为20条,则主叫号码A的实际违规门限为20*0.2=4,即在监控周期内主叫号码A发送的前3条短信判定为未违规,对第4条及以后的短信判定为需要拦截;
步骤S514,实时监控业务处理模块将监控结果发送给网安代理模块;
步骤S516,网安代理模块将监控结果反馈给短信中心;
步骤S518,实时监控业务处理模块将主叫号码A在监控周期内的违规记录发送给接口机模块;
步骤S520,接口机模块将违规记录以ftp形式发送给BOSS系统存储,以使得能够根据该违规记录对主叫号码及用户分组的对应关系进行更新。
以上所述是本发明的优选实施方式,应当指出,对于本技术领域的普通技术人员来说,在不脱离本发明所述原理的前提下,还可以作出若干改进和润饰,这些改进和润饰也应视为本发明的保护范围。
工业实用性
如上所述,通过上述实施例及优选实施方式,实现对不同的用户进行差异化的短信拦截处理,提高了短信拦截的精准度,减少了误拦和漏拦的情况。

Claims (14)

  1. 一种短信监控方法,包括:
    针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定所述主叫号码的安全系数;
    根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;
    根据所述实际违规门限,判断所述主叫号码在一预设时间内发送的短信是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。
  2. 如权利要求1所述方法,其中,所述确定所述主叫号码的实际违规门限具体为:
    确定所述主叫号码的实际违规门限为预设的基础违规门限及所述主叫号码的安全系数的乘积。
  3. 如权利要求1所述方法,其中,当不存在与所述主叫号码对应的预设的用户分组时,确定所述主叫号码的安全系数为1。
  4. 如权利要求1所述方法,其中,所述用户分组包括高风险用户组、普通用户组及低风险用户组,其中,低风险用户组对应的安全系数要高于普通用户组对应的安全系数,而高风险用户组对应的安全系数要低于普通用户组对应的安全系数。
  5. 如权利要求1所述方法,其中,所述基础违规门限包括所述主叫号码在所述预设时间内发送的短信流量门限和/或所述主叫号码在所述预设时间内发送的短信中携带有预设关键字的短信的个数门限。
  6. 如权利要求1所述方法,其中,所述待处理短信封装在SMPP格式的消息中;
    所述获取发送所述待处理短信的主叫号码及所述待处理短信的属性信息之前,还包括:
    对所述SMPP格式的消息进行解码处理得到待处理短信。
  7. 一种短信监控装置,包括:
    第一确定模块,设置为针对一主叫号码,根据对应于一安全系数的预设的用户分组与所述主叫号码的对应关系,确定所述主叫号码的安全系数;
    第二确定模块,设置为根据预设的基础违规门限及所述主叫号码的安全系数,确定所述主叫号码的实际违规门限;
    监控处理模块,设置为根据所述实际违规门限,判断所述主叫号码在一预设时间内发送的短信是否违规,并在违规时,对所述主叫号码在所述预设时间内发送的短信进行处理。
  8. 如权利要求7所述装置,其中,所述第二确定模块设置为确定所述主叫号码的实际违规门限为预设的基础违规门限及所述主叫号码的安全系数的乘积。
  9. 如权利要求7所述装置,其中,当不存在与所述主叫号码对应的预设的用户分组时,所述第一确定模块设置为确定所述主叫号码的安全系数为1。
  10. 如权利要求7所述装置,其中,所述用户分组包括高风险用户组、普通用户组及低风险用户组,其中低风险用户组对应的安全系数要高于普通用户组对应的安全系数,而高风险用户组对应的安全系数要低于普通用户组对应的安全系数。
  11. 如权利要求7所述装置,其中,所述基础违规门限包括所述主叫号码在所述预设时间内发送的短信流量门限和/或所述主叫号码在所述预设时间内发送的短信中携带有预设关键字的短信的个数门限。
  12. 如权利要求7所述装置,其中,所述待处理短信封装在SMPP格式的消息中;所述装置还包括:
    解码模块,设置为对所述SMPP格式的消息进行解码处理得到待处理短信。
  13. 如权利要求7所述装置,其中,所述监控处理模块为多个;所述装置还包括:
    取模模块,设置为根据发送待处理短信的主叫号码的尾数对所述监控处理模块的个数取模,得到模值;
    第三确定模块,设置为确定所述待处理短信对应的监控处理模块为编号为所述模值的监控处理模块。
  14. 如权利要求7所述装置,其中,还包括:
    配置模块,设置为根据用户的操作指令,配置主叫号码与用户分组的对应关系,并设置基础违规门限及每一用户分组对应的安全系数。
PCT/CN2014/086970 2014-06-12 2014-09-19 一种短信监控方法及装置 WO2015188500A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410262052.6 2014-06-12
CN201410262052.6A CN105307134B (zh) 2014-06-12 2014-06-12 一种短信监控方法及装置

Publications (1)

Publication Number Publication Date
WO2015188500A1 true WO2015188500A1 (zh) 2015-12-17

Family

ID=54832802

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/086970 WO2015188500A1 (zh) 2014-06-12 2014-09-19 一种短信监控方法及装置

Country Status (2)

Country Link
CN (1) CN105307134B (zh)
WO (1) WO2015188500A1 (zh)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN107231334A (zh) * 2016-03-24 2017-10-03 中国移动通信集团山东有限公司 一种短消息监控方法和装置
CN109684369B (zh) * 2017-10-18 2021-12-10 北京京东尚科信息技术有限公司 信息更新方法和装置
CN110062096A (zh) * 2019-04-23 2019-07-26 贵阳朗玛通信科技有限公司 一种筛选违规用户的方法及装置
CN115942322B (zh) * 2023-02-15 2023-06-06 北京秒信科技有限公司 一种骚扰短信拦截方法及系统

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120028606A1 (en) * 2010-07-27 2012-02-02 At&T Intellectual Property I, L.P. Identifying abusive mobile messages and associated mobile message senders
CN103179530A (zh) * 2011-12-26 2013-06-26 中国移动通信集团设计院有限公司 一种短信拦截方法及装置
CN103796183A (zh) * 2012-10-26 2014-05-14 中国移动通信集团上海有限公司 一种垃圾短信识别方法及装置

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7552186B2 (en) * 2004-06-28 2009-06-23 International Business Machines Corporation Method and system for filtering spam using an adjustable reliability value
CN101257671B (zh) * 2007-07-06 2010-12-08 浙江大学 基于内容的大规模垃圾短信实时过滤方法
US7996897B2 (en) * 2008-01-23 2011-08-09 Yahoo! Inc. Learning framework for online applications
CN101321070B (zh) * 2008-07-16 2011-08-24 中兴通讯股份有限公司 一种可疑用户的监控系统及方法
CN101447984B (zh) * 2008-11-28 2011-11-09 电子科技大学 一种自反馈垃圾信息过滤方法
US20100161734A1 (en) * 2008-12-22 2010-06-24 Yahoo! Inc. Determining spam based on primary and secondary email addresses of a user
CN101707752A (zh) * 2009-11-23 2010-05-12 中兴通讯股份有限公司 通信监控方法、装置及系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20120028606A1 (en) * 2010-07-27 2012-02-02 At&T Intellectual Property I, L.P. Identifying abusive mobile messages and associated mobile message senders
CN103179530A (zh) * 2011-12-26 2013-06-26 中国移动通信集团设计院有限公司 一种短信拦截方法及装置
CN103796183A (zh) * 2012-10-26 2014-05-14 中国移动通信集团上海有限公司 一种垃圾短信识别方法及装置

Also Published As

Publication number Publication date
CN105307134A (zh) 2016-02-03
CN105307134B (zh) 2019-04-23

Similar Documents

Publication Publication Date Title
WO2016197675A1 (zh) 骚扰电话的识别方法及装置
CN110351229A (zh) 一种终端ue管控方法及装置
US9106603B2 (en) Apparatus, method and computer-readable storage mediums for determining application protocol elements as different types of lawful interception content
US9060253B2 (en) Identifying and blocking mobile messaging service spam
US11057436B1 (en) System and method for monitoring computing servers for possible unauthorized access
WO2015188500A1 (zh) 一种短信监控方法及装置
CN112448894A (zh) 阻断信令风暴的方法、装置、设备及存储介质
WO2010031294A1 (zh) 基于区域策略的位置广告业务分众方法及其系统
WO2017193997A1 (zh) 一种短信过滤方法和系统
WO2011153744A1 (zh) 垃圾短信监控方法和系统
US9078134B2 (en) Security recommendations for providing information in a communication system
CN1889773A (zh) 一种基于基站的手机病毒检测和防护方法及系统
US9521510B2 (en) Subscriber location database
US12074911B1 (en) Systems and methods for network security
CN101242658A (zh) 移动信息化多层级网络安全审计系统
CN105681564A (zh) 一种消息提醒方法及装置
KR101306074B1 (ko) 피싱방지방법 및 피싱방지시스템
WO2012089061A1 (zh) 一种识别并阻止设备发送垃圾短信的方法、设备和系统
CN102752406A (zh) 风险号码异常性识别系统和方法
CN102111723B (zh) 一种分析短信消息频次与内容识别垃圾短消息用户的方法
CN104239790B (zh) 病毒处理方法及装置
CN109104429B (zh) 一种针对网络诈骗信息的检测方法
WO2012174823A1 (zh) 一种短信处理方法、装置及系统
WO2017084405A1 (zh) 短消息监管方法及装置
US11595879B2 (en) Fine grained access barring of aggressive cellular devices

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14894637

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14894637

Country of ref document: EP

Kind code of ref document: A1