WO2018018697A1 - 伪基站垃圾短信鉴别方法及系统 - Google Patents

伪基站垃圾短信鉴别方法及系统 Download PDF

Info

Publication number
WO2018018697A1
WO2018018697A1 PCT/CN2016/097145 CN2016097145W WO2018018697A1 WO 2018018697 A1 WO2018018697 A1 WO 2018018697A1 CN 2016097145 W CN2016097145 W CN 2016097145W WO 2018018697 A1 WO2018018697 A1 WO 2018018697A1
Authority
WO
WIPO (PCT)
Prior art keywords
short message
base station
verification information
server
spam
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/097145
Other languages
English (en)
French (fr)
Inventor
司永杰
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Publication of WO2018018697A1 publication Critical patent/WO2018018697A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/121Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
    • H04W12/122Counter-measures against attacks; Protection against rogue devices
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/12Messaging; Mailboxes; Announcements
    • H04W4/14Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/128Anti-malware arrangements, e.g. protection against SMS fraud or mobile malware

Definitions

  • the present invention relates to the field of mobile communications, and in particular, to a method and system for identifying spam messages sent by a pseudo base station.
  • 2G that is, GSM (Global System for Mobile Communication)
  • GSM Global System for Mobile Communication
  • the system only requires the network to authenticate the mobile terminal, and the authentication can pass the connection communication.
  • the 2G network has the defect of one-way authentication, that is, only the network authenticates the terminal, the mobile terminal cannot identify the legitimacy of the network identity, and thus the concept of a pseudo base station appears in real life.
  • the pseudo base station masquerades as a public mobile communication carrier base station, and absorbs surrounding mobile phone terminal users by modifying part of system parameters and increasing its own transmission power.
  • the TAP Tracking Area Code
  • the TAP can also allow the mobile terminal to migrate from the legal network to the pseudo base station, so that the pseudo base station can directly send the short message to the mobile terminal.
  • the mobile terminal is migrated to the illegal base station through the TAC under the 4G network.
  • the identity information of the mobile terminal user is obtained through the registration process, and then the large-capacity illegal information is transmitted, thereby obtaining illegal information. profit.
  • a pseudo base station spam short message authentication method which can authenticate the short message received by the mobile terminal and mark the short message sent by the pseudo base station.
  • a pseudo base station spam message identification method includes:
  • the verification information of the short message is obtained
  • the short message is marked.
  • the verification information is an Internet packet explorer command
  • the Internet packet explorer command includes a preset public network address or an IP address.
  • the verification information of the short message is a preset flag bit added by the mobile network operator when transmitting the short message or a service center number of the short message.
  • the server when the result of the feedback by the server is that the mobile terminal cannot connect to the website or IP address of the public network in the Internet packet explorer command, or forward the preset flag of the short message.
  • the preset flag bit pre-stored in the server cannot be matched, it is determined that the received short message is a spam message sent by the pseudo base station.
  • the server is a server of a mobile network operator.
  • a pseudo base station spam short message authentication system which can authenticate the short message received by the mobile terminal and mark the short message sent by the pseudo base station.
  • a pseudo base station spam short message authentication system comprising:
  • the information obtaining module is configured to acquire verification information of the short message when the mobile terminal receives the short message
  • the short message verification module is configured to send the verification information and the verification information of the short message to the preset server, receive the verification result of the verification information and the verification information by the server, and verify the verification according to the server.
  • the verification result of the information and the verification information determines whether the received short message is Spam messages sent for the pseudo base station;
  • the short message processing module is configured to mark the short message when it is determined that the received short message is a spam message sent by the pseudo base station.
  • the verification information is an Internet packet explorer command
  • the Internet packet explorer command includes a preset public network address or an IP address.
  • the verification information of the short message is a preset flag bit added by the mobile network operator when transmitting the short message or a service center number of the short message.
  • the SMS verification module determines that the received short message is a spam message sent by the pseudo base station when it cannot match the pre-stored preset flag in the server.
  • the server is a server of a network operator.
  • the pseudo base station spam short message authentication method and system can carry the verification request by sending specific information to a specific server while receiving the short message according to the characteristics that the pseudo base station does not support the data service and the attribute value is illegal. (For example, the ping request, the amount of data is extremely small), if the verification fails, the mobile terminal marks the received short message as a spam message, reminding the user to perform the prevention verification.
  • FIG. 1 is a flow chart of a method for a preferred embodiment of a pseudo base station spam short message authentication method according to the present invention.
  • FIG. 2 is a schematic diagram showing the hardware structure of a mobile terminal performing the pseudo base station spam short message authentication system according to the present invention.
  • FIG. 3 is a functional block diagram of a preferred embodiment of the mobile terminal pseudo base station spam short message authentication system of the present invention.
  • Figure 4 shows a schematic diagram of spam messages.
  • the pseudo base station spam short message authentication method provided in this embodiment can be executed in one mobile terminal.
  • the mobile terminal may be, but is not limited to, a mobile electronic device capable of transmitting and receiving short messages, such as a smart phone, a smart watch, or a tablet computer.
  • FIG. 1 it is a flowchart of a method for a preferred embodiment of the pseudo base station spam short message authentication method of the present invention.
  • the order of execution in the flowchart shown in the figure may vary depending on various requirements, and some may be omitted.
  • SMS Short Message Service
  • the S11 is repeatedly executed.
  • the verification information of the short message is a preset flag added by the mobile network operator when transmitting the short message.
  • the verification information of the short message may be a service center number of the short message.
  • the preset server is a server of a mobile network operator.
  • the mobile network operator may be a telecommunication network operator, a Unicom network operator, a mobile network operator, or the like.
  • the preset server may be a telecommunication network operator, and when the transfer terminal receiving the short message uses the Unicom network, the preset server may be Unicom.
  • the network operator, or when the mobile terminal receiving the short message uses a mobile network, the preset server may be a mobile network operator.
  • the verification information may be a ping (Packet Internet Groper) command.
  • the ping command belongs to a communication protocol and is part of the TCP/IP protocol. Use the "ping" command to check if the network is connected to analyze and determine network failures.
  • the ping command includes a preset public network address or an IP address, for example, a Baidu website address, to determine whether the network where the mobile terminal receiving the short message is located can be connected to the public Web address.
  • S13 may further include sending, to the preset server, verification information of the short message, such as a preset flag bit added by the mobile network operator when transmitting the short message or a service center number of the short message.
  • the verification information cannot be passed.
  • the verification of the server performs the following S15.
  • the content of the annotation may be "suspected fraudulent SMS, please pay attention to property security and prevention identification", as shown in Figure 4.
  • the result of the feedback from the server is a URL or an IP address of the public network that can be connected to the ping command, and the verification information is considered to be verified by the server, and then executed. S16 described below.
  • the verification information of the short message is not matched with the verification information pre-stored in the server, it is determined that the verification information of the short message is invalid, and the S15 is performed to determine that the received short message is a pseudo base station. Send spam messages and mark them.
  • the verification information of the short message is matched with the verification information pre-stored in the server, it is determined that the verification information of the short message is legal, and S17 is performed to determine that the short message is a short message sent by the legal base station, and does not do any deal with.
  • the pseudo base station does not support the data service and the attribute value is illegal, and when the short message is received, the specific information is sent to the specific server to send an authentication request (such as a ping request, the amount of data is extremely small), and if the verification fails, the mobile terminal Mark the received SMS as a spam message to remind the user to do a precautionary verification.
  • FIG. 1 details the pseudo base station spam short message authentication method of the present invention.
  • the hardware system architecture for implementing the pseudo base station spam short message authentication method and the software for implementing the pseudo base station spam short message authentication method are respectively combined with the second to third figures.
  • the functional modules of the system are introduced.
  • FIG. 2 it is a hardware structure diagram of a mobile terminal that performs the pseudo base station spam short message authentication system of the present invention.
  • the mobile terminal 1 can be, but is not limited to, a mobile electronic device capable of transmitting and receiving short messages, such as a smart phone, a smart watch, or a tablet computer.
  • the mobile terminal 1 includes a pseudo base station spam authentication system 10, a storage device 11, and a processor 12. It should be understood that the mobile terminal 1 may also include other hardware or software, and is not limited to the components listed above.
  • the storage device 11 is used to store programs and various data, and realizes high-speed, automatic completion of access of programs or data during the operation of the mobile terminal 1.
  • the storage device 11 may be an external storage device and/or an internal storage device of the mobile terminal 1. Further, the storage device 11 may be a circuit having a storage function in a physical form, such as a RAM (Random-Access Memory), a FIFO (First In First Out), or the like. Or, said The storage device 11 may also be a storage device having a physical form, such as a memory stick, a TF card (Trans-flash Card), or the like.
  • the processor 12 also known as a central processing unit (CPU), is a very large-scale integrated circuit, which is a computing core (Core) and a control unit (Mobile Unit) of the mobile terminal 1.
  • the function of processor 12 is primarily to interpret program instructions and to process data in the software.
  • the pseudo base station spam authentication system 10 may include a plurality of functional modules consisting of program segments (see FIG. 3 for details).
  • the program code of each program segment in the pseudo base station spam authentication system 10 may be stored in the storage device 11 and executed by the processor 12 to perform authentication on the spam message sent by the pseudo base station (details See Figure 3).
  • FIG. 3 it is a functional block diagram of a preferred embodiment of the pseudo base station spam short message authentication system 10 of the present invention.
  • the pseudo base station spam short message authentication system 10 can be divided into multiple functional modules according to the functions performed by the pseudo base station.
  • the function module includes: a short message receiving module 100, an information acquiring module 101, a short message checking module 102, and a short message processing module 103.
  • the short message receiving module 100 is configured to determine whether the mobile terminal 1 receives a short message.
  • SMS short message service
  • the information acquiring module 101 is configured to acquire verification information of the short message when the mobile terminal 1 receives the short message.
  • the verification information of the short message is a preset flag added by the mobile network operator when transmitting the short message.
  • the verification information of the short message may be a service center number of the short message.
  • the short message verification module 102 is configured to send verification information and verification information of the short message to a preset server, and receive a verification result of the verification information and the verification information by the server, and according to the server The verification information and the verification result of the verification information determine whether the received short message is a spam message sent by the pseudo base station.
  • the preset server is a server of a mobile network operator.
  • the mobile network operator may be a telecommunication network operator, a Unicom network operator, a mobile network operator, or the like.
  • the preset server may be a telecommunication network operator, and when the transfer terminal receiving the short message uses the Unicom network, the preset server may be Unicom.
  • the network operator, or when the mobile terminal receiving the short message uses a mobile network, the preset server may be a mobile network operator.
  • the verification information may be a ping (Packet Internet Groper) command.
  • the ping command belongs to a communication protocol and is part of the TCP/IP protocol. Use the "ping" command to check if the network is connected to analyze and determine network failures.
  • the ping command includes a preset public network address or an IP address, for example, a Baidu website address, to determine whether the network where the mobile terminal receiving the short message is located can be connected to the public Web address.
  • the result of the feedback by the server is that the mobile terminal cannot connect to the website or IP address of the public network in the ping command, and then the received The SMS is a spam message sent by the pseudo base station.
  • the received short message may also be determined as a spam message sent by the pseudo base station.
  • the result of the feedback from the server is a URL or an IP address of the public network that can be connected to the ping command, and the preset flag bit for forwarding the short message can be pre-stored with the server. If the preset flag matches, it is determined that the received short message is not a spam message.
  • the short message processing module 103 is configured to mark the short message when the received short message is a spam message sent by the pseudo base station.
  • the content of the annotation may be "suspected fraudulent SMS, please pay attention to property security and prevention identification", as shown in Figure 4.
  • each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of hardware plus software function modules.
  • the above-described integrated unit implemented in the form of a software function module can be stored in a computer readable storage medium.
  • the above software function module is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which may be a personal computer, a communication terminal, or a network device, etc.) or a processor to execute the method according to various embodiments of the present invention. part.
  • the processor 12 may execute an operating system of the mobile terminal 1 and various installed applications (such as the pseudo base station spam authentication system 10), program codes, and the like.
  • each of the above modules includes the short message receiving module 100, the information acquiring module 101, and the like.
  • Program code is stored in the storage device 11, and the processor 12 can invoke program code stored in the storage device 11 to perform related functions.
  • each module described in FIG. 3 eg, the short message receiving module 100, the information acquiring module 101, etc.
  • the storage device 11 stores a plurality of instructions that are executed by the processor 12 to implement a pseudo base station spam text authentication method.
  • the executing, by the processor 12, the multiple instructions includes: when the mobile terminal 1 receives the short message, acquiring the verification information of the short message; and sending the verification information and the short message to the preset server. Checking the information; receiving the verification result of the verification information and the verification information by the server; determining, according to the verification result of the verification information and the verification information, whether the received short message is a spam message sent by the pseudo base station When the received short message is determined to be a spam message sent by the pseudo base station, the short message is marked.
  • the verification information is an Internet Packet Explorer command, the Internet Packet Explorer command including a predetermined public network URL or IP address.
  • the verification information of the short message is transmitted by the mobile network operator.
  • the processor 12 determines that the received short message is a spam message sent by the pseudo base station.
  • the server is a server of a mobile network operator.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

一种伪基站垃圾短信鉴别方法,包括:当移动终端收到短信时,获取所述短信的校验信息;向预设的服务器发送验证信息以及所述短信的校验信息;接收所述服务器对所述验证信息以及校验信息的验证结果;根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否为伪基站发送的垃圾短信;当判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。本发明还提供一种伪基站垃圾短信鉴别系统。本发明可以对移动终端收到的短信进行鉴别,并对伪基站发送的短信进行标注。

Description

伪基站垃圾短信鉴别方法及系统
本申请要求于2016年7月29日提交中国专利局,申请号为201610614747.5、发明名称为“伪基站垃圾短信鉴别方法及系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本发明涉及移动通信领域,具体涉及一种鉴别伪基站发送的垃圾短信的方法及系统。
背景技术
2G,即GSM(Global System for Mobile Communication,全球移动通信系统),该系统只要求网络对手机终端进行鉴权,鉴权通过即可进行附着通信。由于2G网络存在单向鉴权的缺陷,即只有网络对终端的鉴权,手机终端无法识别网络身份的合法性,进而在现实生活中出现了伪基站的概念。所述伪基站伪装成公共移动通信运营商基站,通过修改部分系统参数和加大自身发射功率来吸收周围的手机终端用户。
4G虽然有双向鉴权,但是通过TAC(Tracking Area Code,跟踪区域代码),伪基站也可以让手机终端从合法网络迁移到伪基站上面,这样伪基站可以直接对手机终端进行短信发送。4G网络下通过TAC实现手机终端迁移到非法基站,当手机终端用户成功驻留伪基站所在小区后,通过注册过程获取到手机终端用户的身份信息,随后进行大容量非法信息传递,进而从中获取非法盈利。
发明内容
鉴于以上内容,有必要提出一种伪基站垃圾短信鉴别方法,其可以对移动终端收到的短信进行鉴别,并将伪基站发送的短信进行标注。
一种伪基站垃圾短信鉴别方法,包括:
当移动终端收到短信时,获取所述短信的校验信息;
向预设的服务器发送验证信息以及所述短信的校验信息;
接收所述服务器对所述验证信息以及校验信息的验证结果;
根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否为伪基站发送的垃圾短信;
当判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。
本发明较佳实施例中,所述验证信息是一个因特网包探索器命令,所述因特网包探索器命令包括一个预设的公网的网址或者IP地址。
本发明较佳实施例中,所述短信的校验信息为移动网络运营商在传输该短信时添加的一个预置标志位或者所述短信的服务中心号码。
本发明较佳实施例中,当所述服务器反馈的结果为所述移动终端不能连接到所述因特网包探索器命令中的公网的网址或者IP地址,或者转发所述短信的预置标志位不能与所述服务器中预先存储的预置标志位匹配时,判断所接收的短信为伪基站发送的垃圾短信。
本发明较佳实施例中,所述服务器为移动网络运营商的服务器。
鉴于以上内容,还有必要提出一种伪基站垃圾短信鉴别系统,其可以对移动终端收到的短信进行鉴别,并将伪基站发送的短信进行标注。
一种伪基站垃圾短信鉴别系统,包括:
信息获取模块,设置为当移动终端收到短信时,获取所述短信的校验信息;
短信校验模块,设置为向预设的服务器发送验证信息以及所述短信的校验信息,接收所述服务器对所述验证信息以及校验信息的验证结果,并根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否 为伪基站发送的垃圾短信;
短信处理模块,设置为当判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。
本发明较佳实施例中,所述验证信息是一个因特网包探索器命令,所述因特网包探索器命令包括一个预设的公网的网址或者IP地址。
本发明较佳实施例中,所述短信的校验信息为移动网络运营商在传输该短信时添加的一个预置标志位或者所述短信的服务中心号码。
本发明较佳实施例中,当所述服务器反馈的结果为所述移动终端不能连接到所述因特网包探索器命令中的公网的网址或者IP地址,或者转发所述短信的预置标志位不能与所述服务器中预先存储的预置标志位匹配时,所述短信校验模块判断所接收的短信为伪基站发送的垃圾短信。
本发明较佳实施例中,所述服务器为网络运营商的服务器。
相较于现有技术,本发明所述伪基站垃圾短信鉴别方法及系统能够根据伪基站不支持数据业务和属性值非法的特性,在收到短信的同时,携带特定信息向特定服务器发送验证请求(比如ping请求,数据量极小),如果验证不通过,移动终端将收到的短信标注为垃圾短信,提醒用户做好防范验证。
附图说明
图1所示是本发明伪基站垃圾短信鉴别方法较佳实施例的方法流程图。
图2所示是执行本发明所述伪基站垃圾短信鉴别系统的移动终端的硬件结构示意图。
图3所示是本发明移动终端伪基站垃圾短信鉴别系统较佳实施例的功能模块图。
图4所示是对垃圾短信进行标注的示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行 清楚、完整地描述,显然,所描述的实施例仅仅是本发明的一部分实施例,而不是全部的实施例。
基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动的前提下所获得的所有其他实施例,都属于本发明保护的范围。
本实施例所提供的伪基站垃圾短信鉴别方法可以在一个移动终端中执行。所述移动终端可以是,但不限制于,智能手机、智能手表、平板电脑等能够收发短信的移动式电子设备。
参考图1所示,是本发明伪基站垃圾短信鉴别方法较佳实施例的方法流程图。根据不同的需求,该图所示流程图中的执行顺序可以改变,某些可以省略。
S11,判断移动终端是否收到短信。
所述短信(Short Message Service,简称SMS),是用户通过手机或其他移动终端直接发送或接收的文字或数字信息。
当移动终端没有收到短信时,重复执行所述S11。
当S12,当移动终端收到短信时,获取所述短信的校验信息。
本发明较佳实施例中,所述短信的校验信息为移动网络运营商在传输该短信时添加的一个预置标志位。
本发明其他较佳实施例中,所述短信的校验信息可以为所述短信的服务中心号码。
S13,向预设的服务器发送验证信息。
本发明较佳实施例中,所述预设的服务器为移动网络运营商的服务器。所述移动网络运营商可以是电信网络运营商、联通网络运营商或者移动网络运营商等等。
例如,当接收短信的移送终端使用的是电信网络,则所述预设的服务器可以是电信网络运营商,当接收短信的移送终端使用的是联通网络,则所述预设的服务器可以是联通网络运营商,或者当接收短信的移送终端使用的是移动网络,则所述预设的服务器可以是移动网络运营商。
本发明较佳实施例中,所述验证信息可以是一个ping(Packet Internet Groper,因特网包探索器)命令。所述ping命令属于一个通信协议,是TCP/IP协议的一部分。利用“ping”命令可以检查网络是否连通,从而分析和判定网络故障。
本发明较佳实施例中,所述ping命令包括一个预设的公网的网址或者IP地址,例如,百度的网址,以判断所述接收短信的移动终端所在的网络是否可以连接到所述公网地址。
进一步地,S13还可以包括向所述预设的服务器发送所述短信的校验信息,如移动网络运营商在传输该短信时添加的预置标志位或者所述短信的服务中心号码。
S14,接收所述服务器对所述验证信息的验证结果,并判断所述验证信息是否通过了所述服务器的验证。
本发明较佳实施例中,当向所述服务器发送ping命令时,所述服务器反馈的结果为不能连接到所述ping命令中的公网的网址或者IP地址,则认为所述验证信息不能通过所述服务器的验证,则执行下述的S15。
S15,判断所收到的短信为伪基站发送的垃圾短信,并进行标注。
所述标注的内容可以为“疑似诈骗短信,请注意财产安全和防范鉴别”,如图4所示。
当向所述服务器发送ping命令时,所述服务器反馈的结果为可以连接到所述ping命令中的公网的网址或者IP地址,则认为所述验证信息通过了所述服务器的验证,则执行下述的S16。
S16,进一步接收所述服务器对所述校验信息的验证结果,并根据所述服务器对所述校验信息的验证结果判断所述短信的校验信息是否合法,例如,所述短信的校验信息是否能够与所述服务器中预先存储的校验信息相匹配。
当所述短信的校验信息不能够与所述服务器中预先存储的校验信息相匹配,则判断所述短信的校验信息不合法,执行上述的S15,判断所收到的短信为伪基站发送的垃圾短信,并进行标注。
当所述短信的校验信息能够与所述服务器中预先存储的校验信息相匹配,则判断所述短信的校验信息合法,执行S17,判断所述短信为合法基站发送的短信,不作任何处理。
本发明根据伪基站不支持数据业务和属性值非法的特性,在收到短信的同时,携带特定信息向特定服务器发送验证请求(比如ping请求,数据量极小),如果验证不通过,移动终端将收到的短信标注为垃圾短信,提醒用户做好防范验证。
以上所述,仅是本发明的具体实施方式,但本发明的保护范围并不局限于此,对于本领域的普通技术人员来说,在不脱离本发明创造构思的前提下,还可以做出改进,但这些均属于本发明的保护范围。
上述图1详细介绍了本发明的伪基站垃圾短信鉴别方法,下面结合第2~3图,分别对实现上述伪基站垃圾短信鉴别方法的硬件系统架构以及实现所述伪基站垃圾短信鉴别方法的软件系统的功能模块进行介绍。
应该了解,所述实施例仅为说明之用,在专利申请范围上并不受此结构的限制。
如图2所示,是执行本发明所述伪基站垃圾短信鉴别系统的移动终端的硬件结构示意图。
在本发明较佳实施例中,所述移动终端1可以是,但不限制于,智能手机、智能手表、平板电脑等能够收发短信的移动式电子设备。
在本发明较佳实施例中,所述移动终端1包括伪基站垃圾短信鉴别系统10、存储设备11以及处理器12。应该了解,所述移动终端1也可以包括其他硬件或者软件,而并不限制于上述列举的部件。
所述存储设备11用于存储程序和各种数据,并在移动终端1运行过程中实现高速、自动地完成程序或数据的存取。所述存储设备11可以是移动终端1的外部存储设备和/或内部存储设备。进一步地,所述存储设备11可以是集成电路中没有实物形式的具有存储功能的电路,如RAM(Random-Access Memory,随机存取存储设备)、FIFO(First In First Out,)等。或者,所述 存储设备11也可以是具有实物形式的存储设备,如内存条、TF卡(Trans-flash Card)等等。
所述处理器12又称中央处理器(CPU,Central Processing Unit),是一块超大规模的集成电路,是移动终端1的运算核心(Core)和控制核心(Control Unit)。处理器12的功能主要是解释程序指令以及处理软件中的数据。
所述伪基站垃圾短信鉴别系统10可以包括多个由程序段所组成的功能模块(详见图3)。所述伪基站垃圾短信鉴别系统10中的各个程序段的程序代码可以存储于所述存储设备11中,并由所述处理器12所执行,以执行对伪基站发送的垃圾短信进行鉴别(详见图3中描述)。
参阅图3所示,是本发明伪基站垃圾短信鉴别系统10较佳实施例中的功能模块图。
本实施例中,所述伪基站垃圾短信鉴别系统10根据其所执行的功能,可以被划分为多个功能模块。本实施例中,所述功能模块包括:短信接收模块100、信息获取模块101、短信校验模块102以及短信处理模块103。
所述短信接收模块100设置为判断移动终端1是否收到短信。
所述短信(Short Message Service,简称SMS)是用户通过手机或其他移动终端1直接发送或接收的文字或数字信息。
所述信息获取模块101设置为当移动终端1收到短信时,获取所述短信的校验信息。
本发明较佳实施例中,所述短信的校验信息为移动网络运营商在传输该短信时添加的一个预置标志位。
本发明其他较佳实施例中,所述短信的校验信息可以为所述短信的服务中心号码。
所述短信校验模块102设置为向预设的服务器发送验证信息以及所述短信的校验信息,接收所述服务器对所述验证信息以及校验信息的验证结果,并根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否为伪基站发送的垃圾短信。
本发明较佳实施例中,所述预设的服务器为移动网络运营商的服务器。所述移动网络运营商可以是电信网络运营商、联通网络运营商或者移动网络运营商等等。
例如,当接收短信的移送终端使用的是电信网络,则所述预设的服务器可以是电信网络运营商,当接收短信的移送终端使用的是联通网络,则所述预设的服务器可以是联通网络运营商,或者当接收短信的移送终端使用的是移动网络,则所述预设的服务器可以是移动网络运营商。
本发明较佳实施例中,所述验证信息可以是一个ping(Packet Internet Groper,因特网包探索器)命令。所述ping命令属于一个通信协议,是TCP/IP协议的一部分。利用“ping”命令可以检查网络是否连通,从而分析和判定网络故障。
本发明较佳实施例中,所述ping命令包括一个预设的公网的网址或者IP地址,例如,百度的网址,以判断所述接收短信的移动终端所在的网络是否可以连接到所述公网地址。
本发明较佳实施例中,当向所述服务器发送ping命令时,所述服务器反馈的结果为所述移动终端不能连接到所述ping命令中的公网的网址或者IP地址,则判断所接收的短信为伪基站发送的垃圾短信。
进一步地,当所述短信的校验信息不能与所述服务器中预先存储的校验信息匹配时,也可以判断所接收的短信为伪基站发送的垃圾短信。
当向所述服务器发送ping命令时,所服务器反馈的结果为可以连接到所述ping命令中的公网的网址或者IP地址,并且转发所述短信的预置标志位能够与所述服务器预先存储的预置标志位匹配,则判断所接收的短信不是垃圾短信。
所述短信处理模块103设置为判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。所述标注的内容可以为“疑似诈骗短信,请注意财产安全和防范鉴别”,如图4所示。
在本发明各个实施例中的各功能模块可以集成在一个处理单元中,也可 以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用硬件加软件功能模块的形式实现。
上述以软件功能模块的形式实现的集成的单元,可以存储在一个计算机可读取存储介质中。上述软件功能模块存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,通讯终端,或者网络设备等)或处理器(processor)执行本发明各个实施例所述方法的部分。
在进一步的实施例中,结合图2,所述处理器12可执行所述移动终端1的操作系统以及安装的各类应用程序(如所述的伪基站垃圾短信鉴别系统10)、程序代码等,例如,上述的各个模块,包括所述短信接收模块100、所述信息获取模块101等。
所述存储设备11中存储有程序代码,且所述处理器12可调用所述存储设备11中存储的程序代码以执行相关的功能。例如,图3中所述的各个模块(例如,所述短信接收模块100、所述信息获取模块101等)是存储在所述存储设备11中的程序代码,并由所述处理器12所执行,从而实现所述各个模块的功能以实现对伪基站垃圾短信的鉴别。
在本发明的一个实施例中,所述存储设备11存储多个指令,所述多个指令被所述处理器12所执行以实现伪基站垃圾短信鉴别方法。具体而言,所述处理器12对所述多个指令的执行包括:当移动终端1收到短信时,获取所述短信的校验信息;向预设的服务器发送验证信息以及所述短信的校验信息;接收所述服务器对所述验证信息以及校验信息的验证结果;根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否为伪基站发送的垃圾短信;当判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。
在进一步的实施例中,所述验证信息是一个因特网包探索器命令,所述因特网包探索器命令包括一个预设的公网的网址或者IP地址。
在进一步的实施例中,所述短信的校验信息为移动网络运营商在传输该 短信时添加的一个预置标志位或者所述短信的服务中心号码。
在进一步的实施例中,当所述服务器反馈的结果为所述移动终端1不能连接到所述因特网包探索器命令中的公网的网址或者IP地址,或者所述短信的校验信息不能与所述服务器中预先存储的校验信息匹配时,所述处理器12判断所接收的短信为伪基站发送的垃圾短信。
在进一步的实施例中,所述服务器为移动网络运营商的服务器。
具体地,所述处理器12对上述指令的具体实现方法可参考图1对应实施例中相关步骤的描述,在此不赘述。
对于本领域技术人员而言,显然本发明不限于上述示范性实施例的细节,而且在不背离本发明的精神或基本特征的情况下,能够以其他的具体形式实现本发明。因此,无论从哪一点来看,均应将实施例看作是示范性的,而且是非限制性的,本发明的范围由所附权利要求而不是上述说明限定,因此旨在将落在权利要求的等同要件的含义和范围内的所有变化涵括在本发明内。不应将权利要求中的任何附图标记视为限制所涉及的权利要求。此外,显然“包括”一词不排除其他单元或,单数不排除复数。系统权利要求中陈述的多个单元或装置也可以由一个单元或装置通过软件或者硬件来实现。第一,第二等词语用来表示名称,而并不表示任何特定的顺序。
最后应说明的是,以上实施例仅用以说明本发明的技术方案而非限制,尽管参照较佳实施例对本发明进行了详细说明,本领域的普通技术人员应当理解,可以对本发明的技术方案进行修改或等同替换,而不脱离本发明技术方案的精神和范围。

Claims (10)

  1. 一种伪基站垃圾短信鉴别方法,其特征在于,所述伪基站垃圾短信鉴别方法包括:
    当移动终端收到短信时,获取所述短信的校验信息;
    向预设的服务器发送验证信息以及所述短信的校验信息;
    接收所述服务器对所述验证信息以及校验信息的验证结果;
    根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否为伪基站发送的垃圾短信;
    当判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。
  2. 如权利要求1所述的伪基站垃圾短信鉴别方法,其特征在于,所述验证信息是一个因特网包探索器命令,所述因特网包探索器命令包括一个预设的公网的网址或者IP地址。
  3. 如权利要求2所述的伪基站垃圾短信鉴别方法,其特征在于,所述短信的校验信息为移动网络运营商在传输该短信时添加的一个预置标志位或者所述短信的服务中心号码。
  4. 如权利要求3所述的伪基站垃圾短信鉴别方法,其特征在于,当所述服务器反馈的结果为所述移动终端不能连接到所述因特网包探索器命令中的公网的网址或者IP地址,或者所述短信的校验信息不能与所述服务器中预先存储的校验信息匹配时,判断所接收的短信为伪基站发送的垃圾短信。
  5. 如权利要求1至4中的任意一项所述的伪基站垃圾短信鉴别方法,其特征在于,所述服务器为移动网络运营商的服务器。
  6. 一种伪基站垃圾短信鉴别系统,其特征在于,所述伪基站垃圾短信鉴别系统包括:
    信息获取模块,设置为当移动终端收到短信时,获取所述短信的校验信息;
    短信校验模块,设置为向预设的服务器发送验证信息以及所述短信的校 验信息,接收所述服务器对所述验证信息以及校验信息的验证结果,并根据所述服务器对所述验证信息以及校验信息的验证结果判断所接收的短信是否为伪基站发送的垃圾短信;
    短信处理模块,设置为当判断所接收的短信为伪基站发送的垃圾短信时,对所述短信进行标注。
  7. 如权利要求6所述的伪基站垃圾短信鉴别系统,其特征在于,所述验证信息是一个因特网包探索器命令,所述因特网包探索器命令包括一个预设的公网的网址或者IP地址。
  8. 如权利要求7所述的伪基站垃圾短信鉴别系统,其特征在于,所述短信的校验信息为移动网络运营商在传输该短信时添加的一个预置标志位或者所述短信的服务中心号码。
  9. 如权利要求8所述的伪基站垃圾短信鉴别系统,其特征在于,当所述服务器反馈的结果为所述移动终端不能连接到所述因特网包探索器命令中的公网的网址或者IP地址,或者所述短信的校验信息不能与所述服务器中预先存储的校验信息匹配时,判断所接收的短信为伪基站发送的垃圾短信。
  10. 如权利要求6至9中的任意一项所述的伪基站垃圾短信鉴别系统,其特征在于,所述服务器为移动网络运营商的服务器。
PCT/CN2016/097145 2016-07-29 2016-08-29 伪基站垃圾短信鉴别方法及系统 Ceased WO2018018697A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610614747.5 2016-07-29
CN201610614747.5A CN106231572A (zh) 2016-07-29 2016-07-29 伪基站垃圾短信鉴别方法及系统

Publications (1)

Publication Number Publication Date
WO2018018697A1 true WO2018018697A1 (zh) 2018-02-01

Family

ID=57536245

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/097145 Ceased WO2018018697A1 (zh) 2016-07-29 2016-08-29 伪基站垃圾短信鉴别方法及系统

Country Status (2)

Country Link
CN (1) CN106231572A (zh)
WO (1) WO2018018697A1 (zh)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106231572A (zh) * 2016-07-29 2016-12-14 宇龙计算机通信科技(深圳)有限公司 伪基站垃圾短信鉴别方法及系统
CN109076317A (zh) * 2016-12-14 2018-12-21 华为技术有限公司 验证消息合法性的方法和服务器
CN106412916A (zh) * 2016-12-16 2017-02-15 安徽大学 一种伪基站智能监测终端及其监测方法
CN106454848B (zh) * 2016-12-21 2023-07-18 荆楚理工学院 一种伪基站识别方法及设备
CN108271127A (zh) * 2016-12-30 2018-07-10 中国移动通信集团公司 伪基站短信识别的方法及终端
CN108322896A (zh) * 2017-01-18 2018-07-24 大唐移动通信设备有限公司 一种发送短信的方法及装置
CN107155186B (zh) * 2017-04-10 2020-02-14 中国移动通信集团江苏有限公司 一种伪基站定位方法和装置
CN107708115B (zh) * 2017-10-16 2020-11-06 奇酷互联网络科技(深圳)有限公司 重定向管控方法、装置及移动终端
CN109889469B (zh) * 2017-12-06 2021-11-30 中兴通讯股份有限公司 短信验证方法、装置、存储介质、短信验证系统及终端
CN108419241B (zh) * 2018-03-07 2021-06-15 北京元心科技有限公司 确定伪基站的方法、装置及终端设备
CN110062385B (zh) * 2019-04-28 2023-06-02 深圳中网讯通技术有限公司 垃圾短信屏蔽方法、移动终端及可读存储介质

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102480705A (zh) * 2010-11-26 2012-05-30 卓望数码技术(深圳)有限公司 一种根据号码关系图过滤垃圾短信的方法及系统
US8412779B1 (en) * 2004-12-21 2013-04-02 Trend Micro Incorporated Blocking of unsolicited messages in text messaging networks
CN104010285A (zh) * 2014-06-18 2014-08-27 中国联合网络通信集团有限公司 一种短信过滤方法、系统以及短信服务中心和终端
CN104244254A (zh) * 2014-10-16 2014-12-24 北京奇虎科技有限公司 基于短信中心号码检测伪基站的方法和装置
CN104581732A (zh) * 2014-12-25 2015-04-29 中国科学院信息工程研究所 一种基于短信的伪基站实时判别方法及系统
CN105407479A (zh) * 2014-09-10 2016-03-16 中国移动通信集团设计院有限公司 一种信息识别方法、信息网关、sim卡及系统
CN106231572A (zh) * 2016-07-29 2016-12-14 宇龙计算机通信科技(深圳)有限公司 伪基站垃圾短信鉴别方法及系统

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105228143B (zh) * 2014-06-13 2019-05-24 中国移动通信集团公司 一种垃圾短信鉴别方法、装置和终端
CN105578430A (zh) * 2015-12-16 2016-05-11 努比亚技术有限公司 一种移动终端及其识别伪基站短信的方法

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8412779B1 (en) * 2004-12-21 2013-04-02 Trend Micro Incorporated Blocking of unsolicited messages in text messaging networks
CN102480705A (zh) * 2010-11-26 2012-05-30 卓望数码技术(深圳)有限公司 一种根据号码关系图过滤垃圾短信的方法及系统
CN104010285A (zh) * 2014-06-18 2014-08-27 中国联合网络通信集团有限公司 一种短信过滤方法、系统以及短信服务中心和终端
CN105407479A (zh) * 2014-09-10 2016-03-16 中国移动通信集团设计院有限公司 一种信息识别方法、信息网关、sim卡及系统
CN104244254A (zh) * 2014-10-16 2014-12-24 北京奇虎科技有限公司 基于短信中心号码检测伪基站的方法和装置
CN104581732A (zh) * 2014-12-25 2015-04-29 中国科学院信息工程研究所 一种基于短信的伪基站实时判别方法及系统
CN106231572A (zh) * 2016-07-29 2016-12-14 宇龙计算机通信科技(深圳)有限公司 伪基站垃圾短信鉴别方法及系统

Also Published As

Publication number Publication date
CN106231572A (zh) 2016-12-14

Similar Documents

Publication Publication Date Title
WO2018018697A1 (zh) 伪基站垃圾短信鉴别方法及系统
US9882916B2 (en) Method for verifying sensitive operations, terminal device, server, and verification system
EP3044987B1 (en) Method and system for verifying an account operation
US10362026B2 (en) Providing multi-factor authentication credentials via device notifications
US10110538B2 (en) Method and apparatus for message transmission
US9864852B2 (en) Approaches for providing multi-factor authentication credentials
US10395246B2 (en) System and method for verifying identity information using a social networking application
CN112491776B (zh) 安全认证方法及相关设备
CN104113551B (zh) 一种平台授权方法、平台服务端及应用客户端和系统
US20160321745A1 (en) Account binding processing method, apparatus and system
US9589122B2 (en) Operation processing method and device
US11658963B2 (en) Cooperative communication validation
US10841297B2 (en) Providing multi-factor authentication credentials via device notifications
WO2015074443A1 (en) An operation processing method and device
CN104202345A (zh) 验证码生成方法、装置及系统
CN102130909A (zh) 身份验证方法及系统
CN106559386B (zh) 一种认证方法及装置
CN111262865A (zh) 访问控制策略的制定方法、装置及系统
CN108848079A (zh) 实现信息验证的方法、系统、装置和计算机系统
CN103138935B (zh) 一种基于电信运营商的身份认证系统
US20140215582A1 (en) Verification system and verification method
CN105592459A (zh) 基于无线通信的安全认证装置
CN109429191A (zh) 短信保护方法、终端及计算机可读存储介质
EP3329650B1 (en) Providing multi-factor authentication credentials via device notifications
US8620315B1 (en) Multi-tiered anti-abuse registration for a mobile device user

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16910276

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16910276

Country of ref document: EP

Kind code of ref document: A1