WO2024027381A1 - Anomaly detection method and communication apparatus - Google Patents

Anomaly detection method and communication apparatus Download PDF

Info

Publication number
WO2024027381A1
WO2024027381A1 PCT/CN2023/103209 CN2023103209W WO2024027381A1 WO 2024027381 A1 WO2024027381 A1 WO 2024027381A1 CN 2023103209 W CN2023103209 W CN 2023103209W WO 2024027381 A1 WO2024027381 A1 WO 2024027381A1
Authority
WO
WIPO (PCT)
Prior art keywords
information
sip
sip message
network element
message
Prior art date
Application number
PCT/CN2023/103209
Other languages
French (fr)
Chinese (zh)
Inventor
李论
吴义壮
崔洋
雷骜
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2024027381A1 publication Critical patent/WO2024027381A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W24/00Supervisory, monitoring or testing arrangements
    • H04W24/08Testing, supervising or monitoring using real traffic

Definitions

  • Embodiments of the present application relate to the field of communications, and more specifically, to an anomaly detection method and a communications device.
  • the network data analytics function can perform network-side functional network element (for example, access and mobility management function network) on the terminal device. Analyze the data generated on the network element, session management function network element, etc.) to identify whether the behavior of the terminal device is abnormal, for example, identify whether the terminal device frequently accesses or registers.
  • NWDAF mainly identifies whether the access and registration information of the terminal device is compliant, thereby identifying whether the terminal device is an abnormal terminal device.
  • the terminal device may also cause interference to other terminal devices, for example, by initiating abnormal calls to other terminal devices. How to identify such abnormal terminal devices has become an urgent problem to be solved.
  • Embodiments of the present application provide an anomaly detection method and a communication device, so that analyzing network elements can effectively detect abnormal terminal equipment.
  • an anomaly detection method includes: receiving first information from a first network element, where the first information includes information about an initialization protocol SIP message related to a terminal device; based on the first information Determine whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the SIP
  • the information in the second field of the message is the time information when the SIP message is detected.
  • the types of the SIP message include the SIP INVITE message, the SIP CANCEL message and the SIP hang-up BYE message.
  • the first field is used to identify the sending of the SIP message.
  • the second field is used to identify the receiving device of the SIP message.
  • abnormal terminal equipment can be effectively identified according to SIP messages related to the terminal equipment to avoid causing interference to other terminal equipment.
  • the method further includes: determining statistical information of the SIP message based on the first information; determining whether the terminal device is abnormal based on the first information includes: based on the first information The statistical information of SIP messages determines whether the terminal device is abnormal.
  • the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
  • the statistical information of the SIP message can be determined based on the SIP messages related to the terminal device, and the abnormal terminal device can be effectively identified based on the statistical information of the SIP message to avoid interference with other terminal devices.
  • the first analysis network element receives the first information from the first network element; the first analysis network element or the second analysis network element is based on the first The information determines whether the terminal device is abnormal, the first analysis network element is a session management network element or a first network data analysis function network element, and the second analysis network element is a second network data analysis function network element.
  • the first analysis network element determines the statistical information of the SIP message based on the first information; the first analysis network element sends the SIP message to the second analysis network element. Statistical information of the message; the second analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
  • the first network element is a user plane network element or an application function network element.
  • a session establishment request from the terminal device is received; indication information is sent to the first network element according to the session establishment request, and the indication information indicates that according to the first data packet
  • the detection rule PDR detects the SIP message.
  • the information of the second field of the third SIP message is sent to the application function network element, and the source address of the third SIP message is the address of the terminal device; receiving The location information of at least one terminal device from the application function network element, the location information of the at least one terminal device is sent according to the second field of the third SIP message; update the first information, the first information includes the Location information of at least one terminal device.
  • the value of the first parameter is determined based on the statistical information of the SIP message; and whether the terminal device is abnormal is determined based on the relationship between the value of the first parameter and the first threshold.
  • the first parameter includes at least one of the following parameters: the ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, the total number of SIP INVITE messages, detection The dispersion degree of the time information to the SIP message, the dispersion degree of the first duration, and the dispersion degree of the location information of the at least one terminal device.
  • the terminal device determines whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold, and a first weight, the first weight including the third The weight corresponding to at least one parameter in a parameter.
  • a second aspect provides an anomaly detection method, which method includes: a first network element determines first information of a terminal device, where the first information includes information on an initialization protocol SIP message related to the terminal device; the first The network element sends the first information to the analysis network element, and the first information is used to determine whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source of the SIP message Address, the target address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP invitation INVITE message, the SIP rejection CANCEL message As well as the SIP hang-up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  • the first network element determines the information of the initialization protocol SIP message related to the terminal device and sends the information of the SIP message to the analysis network element, so that the analysis network element can determine the information based on the SIP message related to the terminal device. Effectively identify abnormal terminal equipment to avoid interference with other terminal equipment.
  • instruction information is received from the analysis network element, and the instruction information instructs to detect the SIP message according to the first packet detection rule PDR.
  • the first network element is a user plane network element or an application function network element.
  • the analysis network element is a session management network element or a network data analysis function network element.
  • a third aspect provides an anomaly detection method, which method includes: receiving first information from a first network element, where the first information includes statistical information of an initialization protocol SIP message, and the statistical information of the SIP message is based on The information of the SIP message related to the terminal device is determined; based on the first information, it is determined whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, The target address of the SIP message, the information in the first field of the SIP message, the information in the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP INVITE message, the SIP CANCEL message and the SIP BYE message, the first field is used to identify the sender device of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  • the statistical information of the SIP message can be determined based on the SIP messages related to the terminal device, and the abnormal terminal device can be effectively identified based on the statistical information of the SIP message to avoid interference with other terminal devices.
  • the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
  • the first analysis network element receives the first information from the first network element; the first analysis network element or the second analysis network element is based on the first The information determines whether the terminal device is abnormal, the first analysis network element is a session management network element or a first network data analysis function network element, and the second analysis network element is a first network data analysis function network element or a second network data Analyze functional network elements.
  • the method further includes the first analysis network element sending statistical information of the SIP messages of the terminal device to the second analysis network element.
  • the first network element includes a user plane network element or an application function network element.
  • a session establishment request from the terminal device before receiving the first information from the first network element, a session establishment request from the terminal device is received; and the session establishment request is sent to the first network element according to the session establishment request.
  • Send instruction information the instruction information indicating detecting the SIP message according to the first packet detection rule PDR.
  • the information of the second field of the third SIP message is sent to the application function network element, and the third The source address of the SIP message is the address of the terminal device; receiving the location information of at least one terminal device from the application function network element, the location information of the at least one terminal device is sent according to the second field of the third SIP message ; Update the first information, which includes the location information of the at least one terminal device.
  • the value of the first parameter is determined based on the statistical information of the SIP message; and whether the terminal device is abnormal is determined based on the relationship between the value of the first parameter and the first threshold.
  • the first parameter includes at least one of the following parameters: the total number of SIP BYE messages accounted for the total number of SIP INVITE messages, the total number of SIP CANCEL messages accounted for the total number of SIP INVITE messages, the total number of SIP INVITE messages, SIP detected The time dispersion of the message, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
  • whether the terminal device is abnormal is determined based on a relationship between the value of the first parameter and the first threshold, and a first weight, the first weight including the third The weight corresponding to at least one parameter in a parameter.
  • a fourth aspect provides an anomaly detection method, which method includes: the first network element determines the information of the SIP message related to the terminal device; the first network element determines the SIP message of the terminal device based on the information of the SIP message. Statistical information, the statistical information of the SIP message is used to determine whether the terminal device is abnormal; the first network element sends the statistical information of the SIP message to the analysis network element; wherein the information of the SIP message includes at least one of the following information: The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the type of the SIP message includes SIP In the INVITE message, the SIP CANCEL message and the SIP BYE message, the first field is used to identify the sender device of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  • the first network element can determine the statistical information of the SIP message based on the SIP message related to the terminal device.
  • the analyzing network element can effectively identify the abnormal terminal device and avoid Cause interference to other terminal equipment.
  • the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the number of SIP messages with the same source address and different first fields, first duration information; wherein the first duration is determined by the time information of the first SIP message and the time information of the second SIP message, and the first SIP message
  • first duration information is determined by the time information of the first SIP message and the time information of the second SIP message, and the first SIP message
  • the source address and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
  • the analysis network element is a session management network element or a network data analysis function network element.
  • the first network element includes a user plane network element or an application function network element.
  • the first network element receives indication information from the analysis network element, and the indication information instructs to detect the SIP message according to the first packet detection rule PDR.
  • a communication device in a fifth aspect, includes a transceiver unit and a processing unit.
  • the transceiver unit is configured to receive first information from the first network element.
  • the first information includes an initialization protocol SIP message related to the terminal device.
  • the processing unit is configured to determine whether the terminal device is abnormal based on the first information; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, the The target address, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the type of the SIP message includes the SIP invitation INVITE message, the SIP rejection CANCEL message and the SIP hang-up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the device of the recipient of the SIP message.
  • the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, the The target address, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the type of the SIP message includes
  • the processing unit is further configured to determine the statistical information of the SIP message based on the first information; the processing unit is specifically configured to determine the terminal based on the statistical information of the SIP message. Whether the equipment is abnormal.
  • the statistical information of the SIP message includes at least one of the following information: Items: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration is represented by the first The time information of the SIP message and the time information of the second SIP message determine that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different. .
  • the first network element is a user plane network element or an application function network element.
  • the transceiver unit is also configured to receive a session establishment request from the terminal device; and send indication information to the first network element according to the session establishment request.
  • the indication information Indicates that the SIP message is detected according to the first packet detection rule PDR.
  • the transceiver unit is also configured to send the information of the second field of the third SIP message to the application function network element, and the source address of the third SIP message is The address of the terminal device; receiving location information of at least one terminal device from the application function network element, the location information of the at least one terminal device being sent according to the second field of the third SIP message; the processing unit is also configured to The first information is updated, and the first information includes location information of the at least one terminal device.
  • the processing unit is specifically configured to determine the value of the first parameter based on the statistical information of the SIP message; based on the relationship between the value of the first parameter and the first threshold. Determine whether the terminal device is abnormal, wherein the first parameter includes at least one of the following parameters: the ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, SIP The total number of INVITE messages, the dispersion of the time information of the detected SIP messages, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
  • the processing unit is specifically configured to determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold, and the first weight.
  • the first weight includes a weight corresponding to at least one parameter in the first parameter.
  • a communication device in a sixth aspect, includes a processing unit and a transceiver unit.
  • the first network element determines the first information of the terminal device, and the first information includes the information of the initialization protocol SIP message related to the terminal device;
  • the first network element sends the first information to the analysis network element, and the first information is used to determine whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: type of SIP message, SIP The source address of the message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP invitation INVITE message, the SIP reject message
  • the first field is used to identify the device used by the sender of the SIP message
  • the second field is used to identify the device of the recipient of the SIP message.
  • the first network element determines the information of the initialization protocol SIP message related to the terminal device and sends the information of the SIP message to the analysis network element, so that the analysis network element can determine the information based on the SIP message related to the terminal device. Effectively identify abnormal terminal equipment to avoid interference with other terminal equipment.
  • instruction information is received from the analysis network element, and the instruction information instructs to detect the SIP message according to the first packet detection rule PDR.
  • the first network element is a user plane network element or an application function network element.
  • the analysis network element is a session management network element or a network data analysis function network element.
  • a communication device in a seventh aspect, includes a transceiver unit and a processing unit.
  • the transceiver unit is used to receive statistical information of the initialization protocol SIP message from the first network element.
  • the statistical information of the SIP message is based on the communication with the terminal.
  • the information of the device-related SIP message is determined; the processing unit is used to determine whether the terminal device is abnormal based on the first information; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the SIP message The source address, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP INVITE message, the SIP CANCEL message and SIP BYE message, the first field is used to identify the sender device of the SIP message, and the second field is used to identify the receiver device of the SIP message.
  • the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
  • the communication device is a session management network element or a network data analysis function network element.
  • the first network element includes a user plane network element or an application function network element.
  • the transceiver unit is also configured to receive a session establishment request from the terminal device; and send indication information to the first network element according to the session establishment request.
  • the indication information Indicates that the SIP message is detected according to the first packet detection rule PDR.
  • the transceiver unit is also configured to send the information of the second field of the third SIP message to the application function network element, and the source address of the third SIP message is the address of the terminal device; receiving the location information of at least one terminal device from the application function network element, the location information of the at least one terminal device being sent according to the second field of the third SIP message; updating the first information, The first information includes location information of the at least one terminal device.
  • the processing unit is further configured to determine the value of the first parameter based on the statistical information of the SIP message; based on the relationship between the value of the first parameter and the first threshold. Determine whether the terminal device is abnormal, wherein the first parameter includes at least one of the following parameters: the total number of SIP BYE messages accounts for the total number of SIP INVITE messages, the total number of SIP CANCEL messages accounts for the total number of SIP INVITE messages, the total number of SIP INVITE messages The total number, the dispersion of the time when the SIP message is detected, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
  • the processing unit is specifically configured to determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold, and the first weight.
  • the first weight includes a weight corresponding to at least one parameter in the first parameter.
  • a communication device in an eighth aspect, includes a transceiver unit and a processing unit.
  • the processing unit is used to determine the information of the SIP message related to the terminal device; the processing unit is also used to determine the terminal according to the information of the SIP message.
  • Statistical information of the SIP message of the device The statistical information of the SIP message is used to determine whether the terminal device is abnormal.
  • the first network element sends the statistical information of the SIP message to the analysis network element.
  • the information of the SIP message includes the following information.
  • At least one of: the type of the SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the SIP Message types include SIP INVITE messages, SIP CANCEL messages, and SIP BYE messages.
  • the first field is used to identify the sender device of the SIP message
  • the second field is used to identify the recipient device of the SIP message.
  • the first network element can determine the statistical information of the SIP message based on the SIP message related to the terminal device.
  • the analyzing network element can effectively identify the abnormal terminal device and avoid Cause interference to other terminal equipment.
  • the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
  • the analysis network element is a session management network element or a network data analysis function network element.
  • the first network element includes a user plane network element or an application function network element.
  • the first network element receives indication information from the analysis network element, and the indication information instructs to detect the SIP message according to the first packet detection rule PDR.
  • a communication device including a processor.
  • the processor is coupled to the memory and can be used to execute instructions in the memory to implement the method in any one of the above first to fourth aspects and possible implementation manners.
  • the communication device further includes a memory.
  • the communication device also includes a communication interface, and the processor is coupled to the communication interface.
  • a processor including: an input circuit, an output circuit and a processing circuit.
  • the processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes to implement any one of the above first to fourth aspects and the first to fourth aspects. possible implementation methods.
  • the above-mentioned processor can be one or more chips
  • the input circuit can be an input pin
  • the output circuit can be an output pin
  • the processing circuit can be a transistor, a gate circuit, a flip-flop and various logic circuits, etc.
  • the input signal received by the input circuit may be received and input by, for example, but not limited to, a receiver
  • the signal output by the output circuit may be, for example, but not limited to, an output To the transmitter and transmitted by the transmitter
  • the input circuit and the output circuit may be the same circuit, which is used as an input circuit and an output circuit respectively at different times.
  • the embodiments of this application do not limit the specific implementation methods of the processor and various circuits.
  • a processing device including a processor and a memory.
  • the processor is used to read instructions stored in the memory, and can receive signals through a receiver and transmit signals through a transmitter to execute any of the above first to fourth aspects and possible implementations of the first to fourth aspects. method within the method.
  • processors there are one or more processors and one or more memories.
  • the memory may be integrated with the processor, or the memory may be provided separately from the processor.
  • the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor, or can be set in different On the chip, the embodiment of the present application does not limit the type of memory and the arrangement of the memory and the processor.
  • ROM read-only memory
  • sending instruction information may be a process of outputting instruction information from the processor
  • receiving capability information may be a process of the processor receiving input capability information.
  • the data output by the processor can be output to the transmitter, and the input data received by the processor can be from the receiver.
  • the transmitter and receiver can be collectively called a transceiver.
  • the processing device in the above eleventh aspect may be one or more chips.
  • the processor in the processing device can be implemented by hardware or software.
  • the processor can be a logic circuit, an integrated circuit, etc.;
  • the processor can be a general processor, which is implemented by reading software codes stored in a memory, and the memory can Integrated in the processor, it can be located outside the processor and exist independently.
  • a computer program product includes: a computer program (which may also be called a code, or an instruction).
  • a computer program which may also be called a code, or an instruction.
  • the computer program When the computer program is run, the computer is caused to execute the first aspect. to the fourth aspect and the method in any possible implementation manner of the first to fourth aspects.
  • a computer-readable storage medium stores a computer program (which may also be called a code, or an instruction) that when run on a computer causes the above-mentioned first aspect and The method in any possible implementation manner of the second aspect is executed.
  • a computer program which may also be called a code, or an instruction
  • a fourteenth aspect provides a communication system, including the aforementioned first network element and an analysis network element communicating with the first network element, wherein the first network element is a user plane network element or an application function network element,
  • the analysis network element is a session management network element or a network data analysis function network element.
  • Figure 1 is a schematic diagram of an application scenario applicable to the method of the embodiment of the present application.
  • FIG. 2 is a schematic flow chart of an anomaly detection method provided by an embodiment of the present application.
  • Figure 3 is a schematic flow chart of an anomaly detection method provided by another embodiment of the present application.
  • Figure 4 is a schematic flow chart of an anomaly detection method provided by another embodiment of the present application.
  • Figure 5 is a schematic flow chart of an anomaly detection method provided by another embodiment of the present application.
  • Figure 6 is a schematic diagram of a communication device provided by an embodiment of the present application.
  • Figure 7 is a schematic block diagram of a communication device provided by an embodiment of the present application.
  • FIG. 8 is a schematic diagram of a chip system provided by an embodiment of the present application.
  • LTE long term evolution
  • FDD frequency division duplex
  • TDD time division duplex
  • WiMAX global interoperability for microwave access
  • 5th generation, 5G fifth generation
  • 6th generation, 6G vehicle-to-x, V2X
  • V2X can include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure ( vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc.
  • LTE-V long term evolution-vehicle
  • MTC Internet of things
  • IoT Internet of things
  • LTE-M long term evolution-machine
  • M2M machine to machine
  • FIG. 1 is a schematic diagram of a network architecture suitable for the method provided by the embodiment of this application.
  • the network architecture may specifically include the following network elements:
  • User equipment can include various handheld devices with wireless communication functions, vehicle-mounted devices, wearable devices, computing devices or other processing devices connected to wireless modems, as well as various forms of terminals, mobile devices Mobile station (MS), terminal or soft terminal, etc. For example, water meters, electricity meters, sensors, etc.
  • MS Mobile station
  • the user equipment in the embodiment of the present application may refer to an access terminal, a user unit, a user station, a mobile station, a mobile station, a relay station, a remote station, a remote terminal, a mobile device, a user terminal (user terminal), and a terminal device.
  • terminal equipment wireless communications equipment, user agent or user device.
  • the user equipment may also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a device with wireless communications Functional handheld devices, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, user equipment in 5G networks or users in future evolved public land mobile communications networks (PLMN) Equipment or user equipment in future Internet of Vehicles, etc.
  • SIP session initiation protocol
  • WLL wireless local loop
  • PDA personal digital assistant
  • PLMN public land mobile communications networks
  • a wearable device may also be called a wearable smart device, which is a general term for applying wearable technology to intelligently design daily wear and develop wearable devices, such as glasses, Gloves, watches, clothing and shoes, etc.
  • a wearable device is a portable device that is worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not just hardware devices, they can also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly defined wearable smart devices include full-featured, large-sized devices that can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, and those that only focus on a certain type of application function and need to cooperate with other devices such as smartphones. Use, such as various smart bracelets, smart jewelry, etc. for physical sign monitoring.
  • the user equipment can also be user equipment in the Internet of Things (IoT) system.
  • IoT Internet of Things
  • Its main technical feature is to transfer items through communication technology. Connect with the network to realize an intelligent network of human-computer interconnection and physical-object interconnection.
  • IOT technology can achieve massive connections, deep coverage, and terminal power saving through, for example, narrowband (NB) technology.
  • user equipment may also include sensors such as smart printers, train detectors, and gas stations.
  • the main functions include collecting data (part of user equipment), receiving control information and downlink data of access network equipment, and Send electromagnetic waves to transmit uplink data to access network equipment.
  • (Wireless) access network equipment radio access network, (R)AN: used to provide network access functions for authorized user equipment in a specific area, and can use different quality transmissions according to the level of user equipment, business needs, etc. tunnel.
  • RAN can manage wireless resources, provide access services for user equipment, and then complete the forwarding of control signals and user equipment data between the user equipment and the core network.
  • RAN can also be understood as a base station in a traditional network.
  • the access network device in the embodiment of the present application may be any communication device with wireless transceiver functions used to communicate with user equipment.
  • the access network equipment includes but is not limited to: evolved Node B (eNB), baseband unit (BBU), access point (access point) in the wireless fidelity (wireless fidelity, WIFI) system, AP), wireless relay node, wireless backhaul node, transmission point (TP) or transmission and reception point (TRP), etc.
  • It can also be 5G, such as NR, gNB in the system, or , transmission point (TRP or TP), one or a group (including multiple antenna panels) of antenna panels of a base station in a 5G system, or it can also be a network node that constitutes a gNB or transmission point, such as a baseband unit (BBU), Or, distributed unit (DU), etc.
  • 5G such as NR, gNB in the system, or , transmission point (TRP or TP), one or a group (including multiple antenna panels) of antenna panels of a base station in a 5G system
  • TRP or TP transmission point
  • BBU baseband unit
  • DU distributed unit
  • gNB may include centralized units (CUs) and DUs.
  • the gNB may also include an active antenna unit (AAU).
  • CU implements some functions of gNB
  • DU implements some functions of gNB.
  • the CU is responsible for processing non-real-time protocols and services, and implementing radio resource control (RRC) and packet data convergence protocol (PDCP) layer functions.
  • RRC radio resource control
  • PDCP packet data convergence protocol
  • DU is responsible for processing physical layer protocols and real-time services, and implementing the functions of the radio link control (RLC) layer, media access control (MAC) layer and physical (physical, PHY) layer.
  • RLC radio link control
  • MAC media access control
  • PHY physical layer
  • the access network device may be a device including one or more of a CU node, a DU node, and an AAU node.
  • the CU can be divided into access network equipment in the access network (radio access network, RAN), or the CU can be divided into access network equipment in the core network (core network, CN). This application does not Make limitations.
  • Access and mobility management function (AMF) network element mainly used for mobility management and access management, etc., and can be used to implement mobility management entity (mobility management entity, MME) functions in addition to Other functions besides session management, such as access authorization/authentication and other functions.
  • MME mobility management entity
  • Session management function (SMF) network element mainly used for session management, Internet protocol (IP) address allocation and management of terminal devices, selection and management of user plane functions, policy control and charging function interfaces Endpoints and downstream data notifications, etc.
  • IP Internet protocol
  • PCF Policy control function
  • User plane function (UPF) network element used for packet routing and forwarding and quality of service (QoS) processing of user plane data.
  • User data can be accessed to the data network (DN) through this network element.
  • DN data network
  • it can be used to implement the functions of user plane network elements.
  • Application function (AF) network element used for data routing affected by applications, access to network open function network elements, and interaction with the policy framework for policy control, etc.
  • Data network used to provide a network for transmitting data.
  • DN Data network
  • the operator's business network Internet network
  • third-party business network etc.
  • NWDAF can have at least one of the following functions:
  • the data collection function can refer to NWDAF collecting data from network elements, third-party servers, terminal devices or network management systems;
  • the model training function can refer to NWDAF analyzing and training based on relevant input data to obtain models (for example, machine learning models);
  • the model feedback function can refer to NWDAF sending the trained machine learning model to the network element that supports the inference function;
  • the analysis result inference function can refer to the NWDAF making inferences based on the trained machine learning model and inference data to determine the data analysis results;
  • the analysis result feedback function It can refer to NWDAF providing data analysis results to network elements, third-party servers, terminal equipment or network management systems.
  • the data analysis results can assist the network in selecting service quality parameters for the business, or assist the network in performing traffic routing, or assist the network in selecting background traffic. Transmission strategy, etc.
  • NWDAF One application scenario of NWDAF is the customization or optimization of terminal parameters. That is, NWDAF collects user information such as connection management, mobility management, session management, and accessed services, and uses reliable analysis and prediction models to evaluate and analyze different types of users, build user portraits, and determine the user's movement trajectory and services. Usage habits, optimize user mobility management parameters and wireless resource management parameters, etc. In addition, NWDAF can also identify whether the terminal has abnormal behavior based on the constructed user portrait.
  • user information such as connection management, mobility management, session management, and accessed services
  • reliable analysis and prediction models to evaluate and analyze different types of users, build user portraits, and determine the user's movement trajectory and services. Usage habits, optimize user mobility management parameters and wireless resource management parameters, etc.
  • NWDAF can also identify whether the terminal has abnormal behavior based on the constructed user portrait.
  • the NWDAF may be a separate network element or may be co-located with other network elements.
  • NWDAF network elements can be co-located with AMF or co-located with SMF.
  • the above network architecture may also include network exposure function (NEF) network elements.
  • NEF network exposure function
  • 3GPP 3rd Generation Partnership Project
  • the N2 interface is the interface between RAN and AMF network elements and is used for sending wireless parameters, non-access stratum (NAS) signaling, etc.
  • the N3 interface is the interface between RAN and UPF network elements. The interface between them is used to transmit user plane data, etc.
  • the N4 interface is the interface between the SMF network element and the UPF network element, and is used to transmit business policies, tunnel identification information of the N3 connection, data cache indication information, and downlink Data notifications and other information.
  • the N6 interface is the interface between the DN and UPF network elements and is used to transmit user plane data.
  • network elements can interact with each other through service-oriented interfaces.
  • NWDAF can collect data generated by terminals on network elements through service-oriented interfaces (such as Namf, Nsmf, etc.) provided by other network elements (such as AMF, SMF, etc.); NWDAF can also use Nnwdaf interfaces to other network elements.
  • Network elements such as AMF, PCF, etc.
  • AMF, PCF, etc. provide data analysis results, models, data, etc.
  • network architecture applicable to the embodiments of the present application is not limited to this, and any network architecture that can realize the functions of each of the above network elements is applicable to the embodiments of the present application.
  • each network element and interface in this application are just examples. This application does not rule out the possibility that each network element will have other names in the future, and the functions between each network element will be merged. With the evolution of technology, any device or network element that can realize the functions of each of the above network elements is within the scope of protection of this application.
  • the above network elements can also be called entities, equipment, devices or modules, etc. This application is not particularly limited.
  • the description of "network element” is omitted in some descriptions.
  • the NWDAF network element is referred to as NWDAF.
  • the NWDAF should be understood as the NWDAF network element. In the following, description of the same or similar situations will be omitted.
  • NWDAF can analyze the data generated by the terminal device on the network-side functional network element (for example, AMF, SMF, etc.) and identify whether the behavior of the terminal device is abnormal, for example, identify whether the terminal device frequently accesses or registers.
  • NWDAF mainly identifies whether the access and registration information of the terminal device is compliant, thereby identifying whether the terminal device is an abnormal terminal device.
  • the terminal device may also cause interference to other terminal devices, for example, by initiating abnormal calls to other terminal devices. How to identify such abnormal terminal devices has become an urgent problem to be solved.
  • this application proposes an anomaly detection method, which can effectively identify such abnormal terminal equipment by analyzing network elements.
  • the first, second and various numerical numbers for example, "#1", “#2", etc.
  • the first, second and various numerical numbers are only for convenience of description and are used to distinguish objects, and are not used to limit this application. Scope of Application Embodiments. For example, distinguish different core network elements, etc. It is not used to describe a specific order or sequence. It is to be understood that objects so described are interchangeable where appropriate to enable description of aspects other than the embodiments of the present application.
  • the "preset”, “preconfiguration”, etc. involved in the embodiments of this application can be realized by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device (for example, network device) , this application does not limit its specific implementation, such as the preset anomaly detection strategy, preset thresholds, etc. in the embodiments of this application.
  • the term "and/or" in this article is only an association relationship describing related objects, indicating that there can be three relationships.
  • a and/or B can mean: A alone exists, and A and B exist simultaneously. , there are three situations of B alone.
  • the character "/" in this article generally indicates that the related objects are an "or" relationship.
  • FIG. 2 is a schematic diagram of an anomaly detection method 200 provided by an embodiment of the present application.
  • Method 200 may include the following steps.
  • the first network element sends first information to the first analysis network element, where the first information includes information about the SIP message related to the terminal device.
  • the first analysis network element receives the first information from the first network element.
  • the first network element may be a user plane network element or an application function network element.
  • the application function network element may be a proxy call control function network element (proxy CSCF, P-CSCF); the first analysis network element may be It is the session management network element.
  • SIP messages related to the terminal device may be understood as SIP messages from the terminal device and/or SIP messages sent to the terminal device.
  • a terminal device initiates a call to another terminal device (called a called terminal device)
  • the terminal device initiates a first session for the call.
  • the data of the first session is transmitted by the first network element.
  • the data of the first session includes a SIP message
  • the SIP message is a SIP message sent by the terminal device.
  • the other terminal device initiates a second session for calling the terminal device.
  • the first network element is used to transmit data of the second session.
  • the data of the second session includes a SIP message.
  • the SIP message may be a SIP message sent to the terminal device.
  • the information of this SIP message includes at least one of the following information:
  • the types of the SIP messages include SIP INVITE messages, SIP CANCEL messages and SIP BYE messages.
  • the type of session corresponding to the SIP message can be determined by the type of the SIP message.
  • the SIP INVITE message can represent a session initiated to initiate a call
  • the SIP BYE message can represent a session initiated to hang up the peer call
  • the SIP CANCEL message Can represent a session initiated to reject a call from the peer.
  • the source address of the SIP message may be the address of the terminal device, for example, an Internet Protocol (IP) address; when the SIP message is sent to the terminal device
  • IP Internet Protocol
  • the source address of the SIP message may be the address of the other terminal device, for example, the IP address.
  • the destination address of the SIP message may be the IP address of the application function network element.
  • This first field is used to identify the device used by the sender of the SIP message.
  • the terminal device is jointly identified by the identity of the terminal device and the identity of the device used by the terminal device.
  • the identity of the terminal device may include the identity of a subscriber identity module (SIM) card of the terminal device.
  • SIM subscriber identity module
  • the identity of the SIM card can be a subscriber permanent identifier (SUPI), an international mobile subscriber identity (IMSI), etc.
  • the identifier of the device used by the terminal device may be, for example, a permanent equipment identifier (Permanent Equipment Identifier, PEI) or an International Mobile Equipment Identity (International Mobile Equipment Identity, IMEI).
  • PEI Permanent Equipment Identifier
  • IMEI International Mobile Equipment Identity
  • the second field is used to identify the recipient device of the SIP message, or in other words, the second field indicates the identity of the recipient device of the SIP message.
  • the second field may be a SIP_Tel_Number field that identifies the telephone number of the recipient device of the SIP message.
  • the time information of detecting the SIP message may be, for example, information of the time when the first network element detects the SIP message.
  • the first network element may send the first information to the first analysis network element according to preset reporting rules.
  • the reporting rule may be periodic reporting, reporting upon detection of SIP messages related to the terminal device, reporting upon detection of a preset number of SIP messages related to the terminal device, etc.
  • the SIP message sent by the first network element to the first analysis network element may include the information of the above-mentioned SIP message of one or more SIP messages; or may include the information of the above-mentioned SIP message of one or more SIP messages. partial information.
  • the first network element may report the type of the first SIP message, the source address and destination address of the first SIP message, information on the time when the first SIP message was detected, and the first field of the first SIP message. Information in the second field; the first network element can report information on the type of the second SIP message, the source address, and the time when the second SIP message was detected.
  • the method may also include S220 and S230:
  • the first network element receives instruction information from the first analysis network element, and the instruction information instructs to detect SIP messages related to the terminal device according to a first packet detection rule (PDR).
  • PDR packet detection rule
  • the first network element receives the first information from the first analysis network element.
  • the first PDR may include at least one of the following rules: detecting SIP messages whose source address is the terminal device; detecting SIP messages whose target address is the terminal device.
  • the SIP message whose source address or destination address is the terminal device can include multiple types of SIP messages.
  • the source address is the SIP INVITE message of the terminal device
  • the destination address is the SIP CANCEL message or SIP BYE message of the terminal device. News etc.
  • the first network element detects the SIP message related to the terminal device according to the first PDR, and determines the information of the SIP message.
  • the first network element may determine that the type of the session data is a SIP message.
  • the first network element can detect the source address and/or destination address of the SIP message based on the first PDR; after detecting the SIP message matching the first PDR, the first network element can also determine the SIP message information in the first field and/or the second field. Further, the first network element may also determine the time information at which the SIP message is detected.
  • the first network element may also determine statistical information of the SIP message based on the information of the SIP message.
  • the statistical information of the SIP message includes at least one of the following: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type, the total number of SIP messages with the same destination address and the same type, the source address The number of SIP messages that are the same but have different first fields, and the information of the first duration; wherein the first duration can be determined by the time information of the third SIP message and the time information of the fourth SIP message, and the source of the third SIP message The address is the same as the target address of the fourth SIP message, and the type of the third SIP message is different from the type of the fourth SIP message.
  • the statistical information of the SIP message is for multiple SIP messages related to the terminal device.
  • the first network element may determine the statistical information of the SIP message within a preset statistical period.
  • the first network element may enable a first counter, which is used to count the total number of SIP messages of the same type.
  • a first counter which is used to count the total number of SIP messages of the same type.
  • the first network element determines The count value of the first counter is increased by 1.
  • the count value of the first counter can represent the total number of SIP messages of the same type.
  • the total number of calls made by the terminal device can be determined by counting the total number of SIP messages of the same type.
  • the total number of calls made by the terminal device includes the sum of the number of calls initiated by the terminal device and the number of calls initiated to the terminal device.
  • the first network element can enable a second counter, which is used to count the total number of SIP messages with the same source address and the same type. Taking the source address as the address of the terminal device and the SIP message as the SIP INVITE message as an example, the first network element detects the SIP INVITE whose source address is the address of the terminal device within a preset statistical period based on the first PDR detection. message, if the SIP INVITE message is detected, the first network element determines that the second counter is increased by 1. The count value of the second counter may represent the total number of calls initiated by the terminal device.
  • At least one of the total number of calls initiated by the terminal device and the number of calls initiated to the terminal device can be determined; by counting SIP BYE messages with the same destination address, it can be determined that the call initiated by the terminal device has been hung up. The number of disconnections; by counting SIP CANCEL messages with the same destination address, at least one of the number of times calls initiated by the terminal device are rejected can be determined.
  • the first network element may also detect a specific field of the SIP message, for example, the first field.
  • the number of SIP messages with the same source address and different first fields can be determined by detecting specific fields of the SIP messages.
  • the first network element can use a counter to count the number of SIP messages with the same source address and different first fields within the preset statistical period.
  • the frequency with which the terminal device switches the identity of the device used can be determined by detecting the total number of SIP messages with the same source address and different first fields.
  • the first network element may also record the time information when the SIP message is detected, for example, record the time when the SIP message is detected.
  • the first network element may also detect the time information of the two SIP messages in association with each other to determine the first duration information.
  • one of the two SIP messages may be a SIPINVITE message with the source address being the address of the terminal device, and the other of the two SIP messages may be a SIP BYE message or SIP message with the destination address being the address of the terminal device. CANCEL message.
  • the time information when the SIP message is detected By determining the time information when the SIP message is detected, the time information when the terminal device initiates a call, and the time information when the call initiated by the terminal device is rejected or hung up can be determined. Further, correlating the time information of the two SIP messages can determine the call duration (ie, the first duration) between the terminal device and at least one called terminal device.
  • the first information includes the statistical information of the SIP message.
  • S240 may be executed before S210.
  • the first analysis network element determines the statistical information of the SIP message based on the information of the SIP message.
  • the first analysis network element determines the statistical information of the SIP message based on the information of the SIP message, which is similar to the first network element determining the statistical information of the SIP message. Please refer to the description of S240, which will not be described again.
  • the first network element can send the information of the SIP message related to the terminal device to the first analysis network element, and the analysis network element determines the SIP message related to the terminal device based on the information. Statistics of SIP messages.
  • the first analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
  • the first analysis network element may determine whether the terminal device is abnormal according to the anomaly detection policy and the statistical information of the SIP message.
  • the first analysis network element may be pre-configured with at least one anomaly detection strategy for detecting whether the terminal device is abnormal.
  • Each anomaly detection strategy in the at least one anomaly detection strategy may include an analysis entry (or may also be called an analysis parameter, an example of the first parameter) and a threshold corresponding to the analysis parameter.
  • the anomaly detection strategy may also include a weight corresponding to each anomaly detection strategy, and the weight is used by the first analysis network element to associate multiple anomaly detection strategies to determine whether there is an abnormality in the terminal device.
  • judging whether the terminal device is abnormal according to the anomaly detection strategy can be understood as judging the size relationship between the statistical value of the analysis entry of the terminal device and its corresponding threshold. If the size relationship meets the expected result, it can be determined that the terminal device may exist abnormal.
  • the statistical value of the analysis entry in the anomaly detection strategy can be determined by the statistical information of the SIP message.
  • the analysis entry may include at least one of the following parameters: the ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, the total number of SIP INVITE messages , detecting the dispersion of the time information of the SIP message, the dispersion of the first duration.
  • the first analysis network element can receive the statistical information of the SIP message from the first network element, or the first analysis network element can The user can determine the statistics of the SIP message by itself.
  • the first analysis network element can determine the total number of SIP BYE messages, SIP CANCEL messages, or SIP INVITE messages, so that the first analysis network element can determine the proportion of the total number of SIP BYE messages to the total number of SIP INVITE messages. The ratio of the total number to the total number of SIP INVITE messages, the total number of SIP INVITE messages.
  • the first analysis network element may determine the dispersion of the time information of the detected SIP message based on the time information of the detected SIP message, and determine the dispersion of the first duration based on the information of the first duration.
  • the first analysis network element determines that the value of the first parameter and its corresponding threshold satisfy the preset size relationship according to the statistical information of the SIP message, the first analysis network element can determine that the terminal device may be abnormal.
  • the first analysis network element may also send a request message to the application function network element, where the request message is used to request the location information of the called terminal device.
  • the first analysis network element receives the location information of the called terminal device from the application function network element.
  • the request message may carry the identity of the called terminal device.
  • the first analysis network element may determine the identity of the peer terminal device by determining the second field of the SIP INVITE message whose source address is the address of the terminal device. It should be understood that the application function network element can determine the location information of the called terminal device according to the identity of the called terminal device.
  • the first analysis network element may determine the dispersion of the call target address of the terminal device based on the location information of the called terminal device.
  • the analysis entry may include the dispersion of the terminal device's call destination address.
  • the first analysis network element can determine whether the terminal device is abnormal by determining the relationship between the dispersion degree of the terminal device's call target address and the threshold value.
  • the first analysis network element sends the statistical information of the SIP message to the second analysis network element.
  • the second analysis network element receives the statistical information of the SIP message from the first analysis network element.
  • the second analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
  • the specific process of the second analysis network element determining whether the terminal device is abnormal may refer to the process of the first analysis network element determining whether the terminal device is abnormal in S260a.
  • the first network element can determine the SIP message related to the terminal device, and the first network element can determine the statistical information of the SIP message based on the information of the SIP message; the first network element sends the SIP message to the analysis network element
  • the statistical information of the message is used to enable the analysis network element to determine whether the terminal device is abnormal based on the statistical information of the SIP message.
  • the analysis network element can be a session management network element or a network data analysis function network element. When the analysis network element is a network data analysis function network element, the first network element can send the statistical information of the SIP message to the network data analysis function network element through the session management network element.
  • the first network element determines the SIP message related to the terminal device, and the first network element sends the information of the SIP message to the analysis network element; the analysis network element can determine the SIP message based on the information of the SIP message. Statistical information; the analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
  • the analysis network element may be a session management network element or a network data analysis function network element.
  • the first network element determines the SIP message related to the terminal device, and the first network element sends the information of the SIP message to the first analysis network element; the first analysis network element can determine the SIP message based on the information of the SIP message. Determine the statistical information of the SIP message; the first analysis network element can send the statistical information of the SIP message to the second analysis network element, so that the second analysis network element determines whether the terminal device is abnormal.
  • the first analysis network element may be a session management network element; the second analysis network element may be a network data analysis function network element.
  • the analysis network element can effectively identify abnormal terminal equipment based on SIP messages related to the terminal equipment to avoid causing interference to other terminal equipment.
  • FIG. 3 is a schematic diagram of an anomaly detection method 300 provided by an embodiment of the present application.
  • Method 300 may include the following steps.
  • S301 SMF starts the abnormality detection process of the UE.
  • SMF enabling the UE's anomaly detection can be understood as SMF enabling the subsequent anomaly detection process.
  • SMF's anomaly detection process can be configured by the operator.
  • the operator may configure an anomaly detection process for one or more SMFs in a specific area of the network, including the SMF.
  • Anomaly detection policies can be configured in this SMF.
  • the multiple anomaly detection strategies are as shown in Table 1, and different anomaly detection strategies can be identified by policy IDs.
  • the call initiated by UE#1 may be that UE#1 initiates a call to the called UE, and the called UE includes at least one UE.
  • the call initiated by UE#1 being rejected may mean that the call initiated by UE#1 is rejected by the called UE.
  • the called UE#1 may be a call initiated by the called UE to UE#1, and the called UE includes at least one UE.
  • the call initiated by UE#1 is hung up may mean that the call initiated by UE#1 is hung up by the called UE.
  • UE#1 When UE#1 initiates a call to the called UE, UE#1 acts as the calling party; otherwise, UE#1 acts as the called party.
  • the ratio of UE#1 acting as the calling party and UE#1 acting as the called party can be understood as the ratio of the number of times UE#1 initiates calls to the number of times UE#1 is called.
  • UE#1 can initiate different times of calls to multiple called UEs. For example, UE#1 initiates 5 calls to called UE#2 and 7 calls to called UE#3. Then UE#1 calls each of the called UEs on average. The number of calls initiated by the called party is 6.
  • the dispersion of MEs switched by UE#1 can be expressed by the dispersion of the identifiers of MEs switched by UE#1.
  • the identifier of the ME is, for example, IMEI.
  • the dispersion of MEs switched by the UE may refer to the span of multiple IMEIs corresponding to the MEs switched by the UE.
  • the dispersion degree of the calling target area of UE#1 may refer to the dispersion degree of the regional locations of the multiple called UEs when UE#1 initiates a call to the multiple called UEs.
  • the dispersion of call duration of UE#1 may refer to the dispersion of call duration between UE#1 and other UEs.
  • the other UEs may be the calling UE or the called UE.
  • UE#1 may initiate calls to different called UEs at multiple times, and the dispersion of the time when UE#1 initiates the call may refer to the dispersion of the multiple times.
  • UE#1 sends a packet data unit (protocol data unit, PDU) session establishment request to the SMF.
  • PDU packet data unit
  • the SMF receives the PDU session establishment request from the UE.
  • the PDU session establishment request is an IP multimedia subsystem (IP multimedia subsystem, IMS) class PDU session establishment request.
  • IP multimedia subsystem IP multimedia subsystem, IMS
  • the PDU session establishment request message carries an identification field used to identify the requested session type.
  • the identification field It can be the "Data Network Name Type (DNN type)" field or any other field.
  • the content of the identification field can be IMS.
  • the PDU session establishment request may also carry indication information, which indicates that UE#1 requests the address of the P-CSCF, for example, the IP address.
  • indication information indicates that UE#1 requests the address of the P-CSCF, for example, the IP address.
  • S303 SMF selects UPF.
  • the UPF selected by the SMF is used to transmit user plane data of UE#1.
  • the UPF may forward the data packet of at least one session received from the UE#1 to the destination UE in the UPF, or send the data packet of the at least one session to the network side device through the N6 interface, or, The data packets of the at least one session may also be sent to other UPFs via the N19 interface.
  • the UPF can also forward data packets from at least one session of the UE in the UPF, or data packets of at least one session from the network side device, or data packets of at least one session from other UPFs to The UE#1.
  • the SMF sends instruction information #1 to the UPF.
  • the instruction information #1 instructs the UPF to count and report statistical information on SIP messages related to UE#1.
  • UPF receives the indication information #1 from the SMF.
  • the SIP messages related to UE#1 may include SIP messages from UE#1 and SIP messages sent to UE#1.
  • UE#1 when UE#1 initiates session #1 for calling UE#2 to UE#2, UE#1 sends SIP message #1 of session #1 to UE#2 through the UPF; in response to the SIP message #1 , UE#2 can send SIP message #2 to UE#1.
  • the SIP message related to UE#1 may include the SIP message #1 and SIP message #2.
  • the indication information #1 may carry the data packet detection rule PDR#1, which is used to match or detect the data packets of the SIP message related to UE#1.
  • the rules of PDR#1 may include: causing UPF to identify data packets whose destination address and/or source address are specific IP addresses, for example, the source address is the IP address of UE#1 (denoted as IPUE#1), A data packet whose destination address is the IP address of P-CSCF (recorded as IPP-CSCF); or a data packet whose source address is the IP address of the opposite end UE and whose destination address is the IP address of P-CSCF.
  • the rules of PDR#1 may also include: causing UPF to identify specific types of data packets. For example, identify data packets of type SIP message. Further, the rules of PDR#1 also include identifying SIP messages whose control fields include "INVITE", "BYE” or “CANCEL". Among them, the SIP message whose control field includes "INVITE” can also be called SIP INVITE message. Similarly, the SIP message whose control field includes "BYE” or “CANCEL” can also be called SIP BYE message or SIP CANCEL message.
  • the PDR#1 may also include reporting rules for UPF to report statistical information of SIP messages related to UE#1, for example, periodic reporting, reporting of statistical information entries exceeding a preset threshold, reporting after each statistical information update, etc.
  • UPF After UPF receives a data packet, it matches each field of the data packet header with the parameter items defined in the PDR, and detects the SIP message related to UE#1.
  • UPF#1 starts counting SIP messages of UE#1 based on the indication information #1.
  • UPF#1 starts to determine the statistical information of the SIP message of UE#1 based on the indication information.
  • S306 The SMF sends the address of the P-CSCF to UE#1.
  • SMF sends the P-CSCF address to UE#1, that is, the PDU session is successfully established.
  • S306 can be executed before or after S305.
  • S306 can be understood as a response to S302.
  • the SMF After receiving the PDU session establishment request of UE#1, the SMF starts an abnormality detection process according to the preconfiguration, and the abnormality detection process includes S304. After S304, UPF starts statistics of SIP messages related to UE#1.
  • the SIP messages of UE#1 that can be counted by UPF can come from calls initiated by UE#1, such as mobile original calls, which can also be called calling calls, MO calls or MO calls, and calls initiated from the network side, such as , mobile terminated call, can also be called called call, MT call or MT call.
  • UPF may only receive SIP messages for MO calls initiated by UE#1 during the statistical time period, but no SIP messages for MT calls; or UPF may only receive SIP messages for MT calls during the statistical time period, but no SIP messages for UE#.
  • UPF detects the first data packet according to PDR#1.
  • the first data packet includes data packet #1, and data packet #1 is a data packet used by the network side to initiate an MT call.
  • the type of data packet #1 is a SIP message; the control field of data packet #1 includes "INVITE"; the source address of data packet #1 is IPP-CSCF, and the destination address of data packet #1 is IPUE#1.
  • UPF detects data packet #1 based on PDR#1, S308, UPF updates information #1, which information #1 includes statistical information of the SIP message of the MT call.
  • UPF if UPF detects a data packet #1, UPF updates the count of counter #1.
  • the counter #1 is used to count the number of calls initiated to UE#1.
  • the statistical information of the SIP messages of the MT call may include the count of counter #1.
  • the count of UPF update counter #1 is UPF update information #1.
  • UPF updates the count of counter #2.
  • the counter #2 is used to count the total number of calls made by UE#1.
  • the total number of calls made by UE#1 includes the sum of the number of times the network side initiates calls to UE#1 and the number of times UE#1 initiates calls.
  • the statistical information of the SIP message of the MT call may also include the count of counter #2.
  • the count of UPF update counter #2 is UPF update information #1.
  • the statistical information of the SIP message of UE#1 may be as shown in Table 2.
  • UPF detects the second data packet based on PDR#1.
  • the second data packet includes data packet #2, and data packet #2 is a data packet for UE#1 to initiate an MO call.
  • the content type of packet #2 is a SIP message; the control field of packet #2 includes "INVITE", the source address is IPUE#1, and the destination address is IPP-CSCF.
  • UPF If UPF detects data packet #2 based on PDR#1, S310, UPF updates information #1, which information #1 includes statistical information of the SIP message of the MO call.
  • UPF if UPF detects a packet #2, UPF updates the count of counter #3.
  • the counter #3 is used to count the number of calls initiated by UE#1.
  • the statistics of the SIP messages of the MO call may include the count of counter #3.
  • the updated statistical information of the SIP message of UE#1 can be as shown in Table 3.
  • UPF updates the count of counter #2. That is, UPF updates the total number of calls made by UE#1.
  • UPF After UPF detects the data packet #2, it can also determine at least one of the information of field #1 and the information of field #2 of data packet #2.
  • Field #1 is used to identify the device used by the sender of data packet #2.
  • field #1 may indicate the device used by UE#1.
  • field #1 carries the IMEI of the UE#1 device.
  • Field #2 is used to identify the receiving device of data packet #2.
  • this data packet #2 is a data packet for UE#1 to initiate a call to UE#2.
  • This field #2 can carry the phone number of UE#2.
  • Field #2 2 can be the SIP_Tel_Number field.
  • UPF can count the information of field #1 and/or field #2 of multiple data packets #2, and the statistical information of the SIP message of UE#1 includes the information of field #1 and/or field of multiple data packets #2. #2 information.
  • the multiple data packets #2 can be understood as multiple calls initiated by UE#1.
  • the multiple data packets #2 may be data packets in which UE#1 initiates multiple calls to one UE, or may be data packets in which UE#1 initiates calls to multiple different UEs.
  • the statistical information of the SIP message of UE#1 includes the information of time #1.
  • the data packet #2 is a SIP message in which UE#1 initiates a call to UE#2.
  • the statistical information of the SIP message of UE#1 can be as shown in Table 4.
  • UPF may also detect data packet #3 (an example of the second data packet), which may be a data packet corresponding to data packet #2.
  • the data packet #3 is a data packet in which the opposite end UE (called UE) of the call initiated by UE#1 responds to the call initiated by UE#1.
  • the destination address of packet #3 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the content is "BYE".
  • the UPF If the UPF detects the data packet #3, the UPF updates the timing of the counter #4.
  • the counter #4 is used to count the number of times the call initiated by UE#1 is connected.
  • the statistical information of the SIP message of UE#1 includes the count value of counter#4.
  • UPF can also record information about time #2 when packet #3 is detected.
  • the UPF may correlate time #1 of packet #2 to determine the length of time between time #1 and time #2. This duration may represent the duration of the conversation between UE#1 and the called UE.
  • data packet #2 is a data packet for UE#1 to initiate a call to UE#2.
  • UPF can record the identity of UE#2 (for example, phone number) and the detected data packet.
  • Moment #1 of #2 when UPF detects data packet #3, UPF can associate the identity of the sender device of data packet #3 to determine whether data packet #3 is sent by UE#2 for this data packet.
  • #2 responds to the data packet, if so, UPF can record the time #2 when the data packet #3 is detected; the time between time #1 and time #2 is the length of the call between UE#1 and UE#2 .
  • the statistical information of the SIP message of UE#1 may be as shown in Table 5.
  • UPF may also detect data packet #4 (an example of the second data packet), which may be a data packet corresponding to data packet #2.
  • the data packet #4 is a data packet in which the opposite end UE (the called UE) of the call initiated by UE#1 responds to the call initiated by UE#1.
  • the destination address of packet #4 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the content is "CANCEL".
  • UPF If UPF detects data packet #4, UPF updates the timing of counter #5. This timer #5 is used to count the number of times calls initiated by UE #1 are rejected.
  • UE#3 sends a SIP CANCEL message to UE#1, and the statistical information of the SIP message of UE#1 can be as shown in Table 6.
  • the SIP messages for UPF statistics on MT calls and the SIP messages for UPF statistics for MO calls can be within the same statistical period, or the period of the SIP messages for UPF statistics on MT calls can be greater than or equal to the SIP messages for UPF statistics on MO calls. cycle.
  • the UPF sends the statistical information of the SIP message of UE#1 to the SMF.
  • the SMF receives the statistical information of the SIP messages of UE#1 from the UPF.
  • the statistical information of the SIP message may include the count of at least one counter among counter #1 to counter #5.
  • the statistical information of the SIP message may also include the time information of detecting the SIP message and the call length information.
  • the SMF sends the statistical information of the SIP message of the UE#1 to the NWDAF.
  • the NWDAF receives the statistical information of the SIP messages of UE#1 from the SMF.
  • the SMF can also send a request message #1 to the P-CSCF.
  • the request message #1 is used to request the location information of the UE#1 calling the opposite end UE. .
  • the P-CSCF receives the request message #1 from the SMF.
  • the request message #1 may carry the identity of the peer UE, for example, a phone number.
  • the P-CSCF sends the location information of the opposite end UE to the SMF.
  • the SMF receives the location information of the opposite end UE from the P-CSCF.
  • the location information may be a location area code (LAC), a tracking area identifier (TAI), a cell ID (cell ID), and a geographic area identifier (LAC) of the peer UE called by UE#1.
  • LAC location area code
  • TAI tracking area identifier
  • cell ID cell ID
  • LAC geographic area identifier
  • GAI area identifier
  • NC network code
  • CC country code
  • CC city code
  • county code county code
  • the statistical information of the SIP message of UE#1 sent by the SMF to the NWDAF may also include the location information of the peer UE called by UE#1.
  • NWDAF determines whether there is an abnormality in UE#1.
  • NWDAF determines whether UE#1 is abnormal based on the abnormality detection policy and the statistical information of the SIP message of UE#1.
  • this anomaly detection strategy please refer to the description in S260a.
  • the value of the analysis entry of the anomaly detection policy may be determined based on the statistical information of the SIP message of UE#1.
  • the number of calls initiated by UE#1 may be determined based on the count value of counter #3. If the NWDAF determines that the count value of counter #3 is greater than the threshold T1, the NWDAF may determine that there may be an abnormality in UE#1.
  • the number of times calls initiated by UE#1 are rejected can be determined by counting counter #5. If NWDAF determines that the count value of counter #5 is greater than T2, NWDAF can determine that UE#1 may be abnormal.
  • the number of times UE#1 is called can be determined by the counting of counter #1; the number of times calls initiated by UE#1 are connected can be determined by the counting of counter #3; the number of times calls initiated by UE#1 are rejected
  • the ratio of the total number of calls to UE#1 can be determined by correlating the count values of counter #5 and counter #2; the ratio of the number of times calls initiated by UE#1 are connected to the total number of calls to UE#1 can be determined by correlating counters #3 and counters
  • the count value of #2 is determined; the ratio of UE acting as the calling party to the UE acting as the called party can be determined by correlating the counting values of counter #1 and technical device #3; the average number of times the UE initiates calls to each called UE can be determined by the counting value of counter #3
  • the count value is determined along with the information in Field #2 of the SIP message.
  • the dispersion of mobile equipment (ME) switched by UE#1 can be determined by the information of field #1 of the SIP message. This field #1 carries the identification of the device used by UE#1, for example, IMEI.
  • the dispersion of the ME switched by UE#1 can be understood as the dispersion of multiple IMEIs switched by UE#1.
  • the dispersion of the multiple IMEIs can be determined by the contents of the IMEI. For example, if the contents of the multiple IMEIs are continuous, then It is considered that the dispersion of IMEI is small; if the content of IMEI is random and irregular, it can be considered that the dispersion of multiple IMEIs is large.
  • the dispersion of the target area called by UE#1 can be determined by the location information of the opposite UE called by UE#1; the dispersion of the call duration of UE#1 can be determined by the call duration information of UE#1; the time when UE#1 initiates the call Dispersion can send SIP messages through UE#1 The time information of the message is determined.
  • NWDAF can determine whether UE#1 is abnormal through one or more analysis parameters in the anomaly detection strategy.
  • NWDAF determines whether UE#1 is abnormal based on one analysis parameter in the anomaly detection strategy
  • NWDAF can determine whether UE#1 is abnormal through The relationship between the statistical information of the SIP message of #1 and the threshold determines whether there is an abnormality in UE#1.
  • NWDAF determines whether UE#1 is abnormal through multiple analysis parameters in the anomaly detection strategy
  • NWDAF can determine UE#1 based on the relationship between the statistical information of UE#1's SIP messages and the threshold, and the weight corresponding to each analysis parameter. Is there any exception?
  • the NWDAF may configure the total weight of the UE to be abnormal as W.
  • the NWDAF determines that the UE is abnormal. For example, NWDAF combines the anomaly detection policy #1 (policy ID is "1") and the anomaly detection policy #2 to determine whether there is an abnormality in UE#1.
  • the NWDAF can receive statistical information of SIP messages of multiple UEs within a preset time period, and determine whether the multiple UEs are abnormal based on the statistical information of SIP messages of the multiple UEs.
  • the NWDAF may also determine the abnormal access address through the location information of the multiple UEs.
  • NWDAF may determine that address #1 is the abnormal access address. By correlating all abnormal UEs, it can be determined whether the abnormal access address has a cluster abnormal call system.
  • NWDAF can obtain the statistical information of SIP messages related to the UE session from the SMF, and determine whether the UE is abnormal based on the statistical information of the SIP message and the anomaly detection policy, thereby effectively preventing the UE's abnormal behavior.
  • FIG. 4 is a schematic diagram of an anomaly detection method 400 provided by an embodiment of the present application.
  • Method 400 may include the following steps.
  • S401 SMF starts the abnormality detection process of the UE.
  • SMF enabling the UE's anomaly detection can be understood as SMF enabling the subsequent anomaly detection process.
  • SMF's anomaly detection process can be configured by the operator.
  • the operator can configure an anomaly detection process for one or more SMFs in a specific area of the network.
  • UE#1 sends a PDU session establishment request to the SMF.
  • the SMF receives the PDU session establishment request from the UE.
  • This step is similar to S302.
  • SMF selects UPF.
  • This step is similar to S303.
  • the SMF sends instruction information #2 to the UPF.
  • the instruction information #2 instructs the UPF to report SIP message information related to UE#1.
  • UPF receives the indication information #2 from the SMF.
  • the indication information #2 may carry the data packet detection rule PDR#2, which is used to match or detect the data packets of the SIP message related to UE#1.
  • the rules of PDR#2 may include: identifying data packets whose destination address and/or source address are specific IP addresses, for example, the source address is the IP address of UE#1 (denoted as IPUE#1), the destination address The data packet is the IP address of P-CSCF (recorded as IPP-CSCF); or the source address is the IP address of the opposite end UE and the destination address is the IP address of P-CSCF.
  • the PDR#2 rules may also include: identifying specific types of data packets. For example, identify data packets of type SIP message. Further, the rules of PDR#1 also include identifying SIP messages whose control fields include "INVITE", "BYE” or "CANCEL".
  • the SIP message whose control field includes "INVITE” can also be called SIP INVITE message.
  • the SIP message whose control field includes "BYE” or “CANCEL” can also be called SIP BYE message or SIP CANCEL message.
  • the PDR#2 may also include a reporting rule for the UPF to report the information of the SIP message related to UE#1.
  • the reporting rule may be to report upon detection, that is, when the UPF detects the information of a SIP message, the UPF reports the information to the SMF. SIP message information.
  • S405 UPF starts detecting the SIP message of UE#1 based on the indication information #2.
  • UPF#1 starts detecting SIP messages related to UE#1 based on the indication information #2.
  • S406 The SMF sends the P-CSCF address to UE#1.
  • SMF sends the P-CSCF address to UE#1, that is, the PDU session is successfully established.
  • S406 can be executed before or after S405.
  • S406 can be understood as a response to S402.
  • the SMF After receiving the PDU session establishment request of UE#1, the SMF starts an abnormality detection process according to the preconfiguration, and the abnormality detection process includes S404. After S404, UPF starts detecting SIP messages related to UE#1.
  • the SIP messages of UE#1 detectable by UPF may come from calls initiated by UE#1, for example, MO calls, and from calls initiated by the network side, for example, MT calls.
  • the UPF may only receive the SIP message for the MO call initiated by UE#1 within the preset time period, but no SIP message for the MT call; or the UPF may only receive the SIP message for the MT call within the preset time period, but no SIP message for the MT call.
  • UPF detects the first data packet according to PDR#2.
  • the first data packet may include data packet #1.
  • This data packet #1 is a data packet for the network side to initiate an MT call.
  • the type of data packet #1 is a SIP message; the control field of data packet #1 includes "INVITE"; the source address of data packet #1 is IPP-CSCF, and the destination address of data packet #1 is IPUE#1.
  • the first data packet may also include data packet #2.
  • This data packet #2 is a data packet for UE#1 to initiate an MO call.
  • the content type of packet #2 is a SIP message
  • the control field of packet #1 includes "INVITE”
  • the source address is IPUE#1
  • the destination address is IPP-CSCF.
  • the first data packet may also include data packet #3.
  • the data packet #3 may be a data packet corresponding to the data packet #2.
  • the data packet #3 is a data packet in which the opposite end UE (called UE) of the call initiated by UE#1 responds to the call initiated by UE#1.
  • the destination address of packet #3 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the control field includes "BYE".
  • the first data packet may also include data packet #4.
  • the data packet #4 may be a data packet corresponding to the data packet #2.
  • the data packet #4 is a data packet in which the opposite end UE (the called UE) of the call initiated by UE#1 responds to the call initiated by UE#1.
  • the destination address of packet #4 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the control field includes "CANCEL".
  • the UPF may also determine the first information of the first data packet.
  • the first information may include time information when the first data packet is detected.
  • the time information may include time information when data packet #2, data packet #3, and data packet #4 are detected.
  • the first information may also include information on specific fields in the first data packet.
  • the specific field may be used to identify the UE that UE#1 calls the opposite end.
  • the specific field identifies the phone number of the opposite end that UE#1 calls. This specific field could be the field in packet #2.
  • UPF can detect the first data packet and report the SIP message information related to UE#1 according to the rules of PDR#2, or UPF can also report the SIP message information related to UE#1 after detecting multiple data packets.
  • the SMF reports the SIP message information related to UE#1, or the UPF can report periodically or regularly.
  • the UPF sends the SIP message information related to UE#1 to the SMF.
  • the information of the SIP message related to UE #1 reported by the UPF to the SMF may be as shown in Table 7.
  • the information of the SIP message related to UE#1 reported by UPF to SMF can be as shown in Table 8.
  • the information of the SIP message related to UE#1 reported by the UPF to the SMF may be as shown in Table 9.
  • the calling UE may refer to the UE that initiates the call; the event ID is used to refer to the session event triggered by the UE, for example, UE#1 initiates a call to UE#2, or in other words, UE#1 initiates a call to UE#2
  • the call initiated by UE#1 to UE#2 can be identified as a session event.
  • the SMF determines the statistical information of the SIP message based on the information of the SIP message of the UE#1.
  • the SMF updates the count of counter #1.
  • the counter #1 is used to count the number of calls initiated to UE#1.
  • the statistical information of the SIP message may include the count of counter #1.
  • SMF After SMF receives the information of the SIP message of event ID #1, SMF updates the count of counter #2.
  • the counter #2 is used to count the total number of calls made by UE#1.
  • the total number of calls made by UE#1 includes the sum of the number of times the network side initiates calls to UE#1 and the number of times UE#1 initiates calls.
  • the statistical information of the SIP message may also include the count of counter #2.
  • the SMF updates the count of counter #3.
  • the counter #3 is used to count the number of calls initiated by UE#1.
  • the statistics of the SIP message may include the count of counter #3.
  • SMF updates the count of counter #2.
  • the SMF If the SMF receives the information of the SIP message of event ID #3, the SMF updates the count of counter #4.
  • the counter #4 is used to count the number of times calls initiated by UE#1 are hung up.
  • the statistics of the SIP message may include the count of counter #4.
  • the SMF can also correlate the information of the SIP message of event ID#2 to determine the duration of the conversation between UE#1 and the called UE. For example, SMF determines based on the statistical information of the SIP message of event ID#3 that the time when UE#2 sends the SIP BYE message to UE#1 is time #2, and SMF determines based on the information of the SIP message of event ID#2 that UE#1 The time when the SIP INVITE message is sent to UE#2 is time #1, then SMF can determine that the duration of the call between UE#1 and the called UE#2 is from time #1 to time #2.
  • the SMF receives the information of the SIP message of event ID #4, the SMF updates the count of counter #5.
  • the counter #5 is used to count the number of times calls initiated by UE#1 are hung up.
  • the statistical information of the SIP message may include the count of counter #5.
  • the SMF sends the statistical information of the SIP message of the UE#1 to the NWDAF.
  • the NWDAF receives the statistical information of the SIP messages of UE#1 from the SMF.
  • This step is similar to S312 and will not be described again.
  • the SMF can also send a request message #1 to the P-CSCF.
  • the request message #1 is used to request the location information of the UE#1 calling the opposite end UE. .
  • the P-CSCF sends the location information of the opposite end UE to the SMF.
  • the statistical information of the SIP message of UE#1 sent by the SMF to the NWDAF may also include the location information of the peer UE called by UE#1.
  • NWDAF determines whether there is an abnormality in UE#1.
  • NWDAF determines whether UE#1 is abnormal based on the abnormality detection policy and the statistical information of the SIP message of UE#1.
  • the value of the analysis parameter of the anomaly detection strategy may be determined based on the statistical information of the SIP message of UE#1.
  • the NWDAF may also determine the abnormal access address through the location information of the multiple UEs.
  • NWDAF can obtain the statistical information of SIP messages related to the UE session from the SMF, and determine whether the UE is abnormal based on the statistical information of the SIP message and the anomaly detection policy, thereby effectively preventing the UE's abnormal behavior.
  • FIG. 5 is a schematic diagram of an anomaly detection method 500 provided by an embodiment of the present application.
  • Method 500 may include the following steps.
  • S501 SMF starts the abnormality detection process of the UE.
  • SMF enabling the UE's anomaly detection can be understood as SMF enabling the subsequent anomaly detection process.
  • SMF's anomaly detection process can be configured by the operator.
  • the operator can configure an anomaly detection process for one or more SMFs in a specific area of the network.
  • multiple anomaly detection strategies for detecting whether the UE is abnormal may be pre-configured in SMF (an example of analyzing network elements).
  • SMF an example of analyzing network elements.
  • S502 UE#1 sends a PDU session establishment request to the SMF.
  • the SMF receives the PDU session establishment request from the UE.
  • This step is similar to S302.
  • S503 SMF selects UPF.
  • This UPF is used to transmit user plane data of UE#1.
  • This step is similar to S303.
  • the SMF sends a request message #2 to the NWDAF.
  • the request message #2 is used to request the selection of an AF with statistics and reporting of UE session signaling.
  • NWDAF receives the request message #2 from SMF.
  • the AF that has statistics and reports UE session signaling is, for example, a P-CSCF that has statistics and reports UE session signaling.
  • the request message #2 may include the identification of UE#1, for example, the SUPI, PEI or GPSI of UE#1.
  • the request message #2 may also include the location information of UE#1, for example, the LAC, cell ID, etc. of UE#1.
  • the NWDAF sends request message #3 to the P-CSCF.
  • the request message #3 is used to request to determine the statistical information of the SIP message related to UE#1.
  • P-CSCF receives the request message #3 from NWDAF.
  • the request message #3 may include the identity of UE#1.
  • the request message #3 also includes the location information of UE#1 and the identification of the anomaly detection strategy.
  • NWDAF sends the address of P-CSCF to SMF.
  • the SMF receives the address of the P-CSCF from the NWDAF.
  • NWDAF After NWDAF receives the response message of P-CSCF to request message #3, NWDAF sends the address of P-CSCF to SMF.
  • S507 The SMF sends the P-CSCF address to UE#1.
  • SMF sends the P-CSCF address to UE#1, that is, the PDU session is successfully established.
  • S508 The P-CSCF starts to detect SIP messages related to UE#1 based on the request message #3.
  • the SIP messages of UE#1 that can be counted by P-CSCF can come from calls initiated by UE#1, for example, the calling call (MO call or MO call), and from calls initiated by the opposite end UE, such as the called call. (MT call or MT call).
  • UE#1 for example, the calling call (MO call or MO call)
  • MT call or MT call calls initiated by the opposite end UE, such as the called call.
  • the opposite end UE is relative to UE#1.
  • UE#1 initiates a call to UE#2, and UE#2 can be called the opposite end UE;
  • UE#2 initiates a call to UE#1, and the UE#2 It can also be called the opposite end UE.
  • the P-CSCF may only receive the SIP message for the MO call initiated by UE#1 within the preset time period, but not the SIP message for the MT call; or the P-CSCF may only receive the SIP message for the MT call within the preset time period. message without the SIP message of the MO call initiated by UE#1; or, the P-CSCF may After receiving one or more SIP messages for UE#1 to initiate a call, one or more SIP messages for MT calls are received; alternatively, the P-CSCF may receive one or more SIP messages for MT calls. One or more SIP messages initiated by UE#1.
  • the P-CSCF detects the first data packet related to UE#1.
  • the first data packet may refer to the description in S407, and the first data packet may include at least one of data packet #1, data packet #2, data packet #3, and data packet #4.
  • data packet #1 to data packet #4 please refer to the description of S407.
  • the P-CSCF may also determine the first information of the first data packet.
  • the first information may include time information when the first data packet is detected.
  • the time information may include time information when data packet #2, data packet #3, and data packet #4 are detected.
  • the first information may also include information on specific fields in the first data packet.
  • the specific field may be used to identify the UE that UE#1 calls the opposite end.
  • the specific field identifies the phone number of the opposite end that UE#1 calls. This specific field could be the field in packet #2.
  • P-CSCF determines the statistical information of the SIP message.
  • the P-CSCF determines the statistical information of the SIP message by referring to the process of the SMF determining the statistical information of the SIP message in S409, which will not be described again.
  • the P-CSCF sends the statistical information of the SIP message of the UE#1 to the NWDAF.
  • the NWDAF receives the statistical information of the SIP messages of UE#1 from the P-CSCF.
  • This step is similar to S312 and will not be described again.
  • the NWDAF After the NWDAF receives the statistical message of the SIP message of the UE#1 from the P-CSCF, optionally, the NWDAF can also request the SMF for the information of the UE#1, for example, the SUPI, LAC, cell of the UE#1 ID etc.
  • NWDAF determines whether there is an abnormality in UE#1.
  • NWDAF determines whether UE#1 is abnormal based on the abnormality detection policy and the statistical information of the SIP message of UE#1.
  • the value of the analysis parameter of the anomaly detection strategy may be determined based on the statistical information of the SIP message of UE#1.
  • the NWDAF may also determine the abnormal access address through the location information of the multiple UEs.
  • NWDAF can obtain the statistical information of SIP messages related to the UE session from the SMF, and determine whether the UE is abnormal based on the statistical information of the SIP message and the anomaly detection policy, thereby effectively preventing the UE's abnormal behavior.
  • the method implemented by the communication device can also be implemented by components (such as chips or circuits) that can be configured inside the communication device.
  • each network element includes a corresponding hardware structure and/or software module to perform each function.
  • each network element includes a corresponding hardware structure and/or software module to perform each function.
  • the present application can be implemented in the form of hardware or a combination of hardware and computer software with the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein. Whether a function is performed by hardware or computer software driving the hardware depends on the specific application and design constraints of the technical solution. Skilled artisans may implement the described functionality using different methods for each specific application, but such implementations should not be considered beyond the scope of this application.
  • the communication device provided by the embodiment of the present application will be described in detail below with reference to FIGS. 6 to 8 . It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for content that is not described in detail, please refer to the above method embodiments. For the sake of brevity, some content will not be described again.
  • FIG. 6 is a schematic block diagram of a communication device 600 provided by an embodiment of the present application. As shown in the figure, the communication device 600 may include: Transceiver unit 610 and processing unit 620.
  • the communication device 600 may be the first network element in the above method embodiment, or may be a chip used to implement the functions of the first network element in the above method embodiment.
  • the communication device 600 may correspond to the first network element in the method 200 according to the embodiment of the present application, or correspond to the UPF in the method 300, 400 or 500, or the P-CSCF in the method 500.
  • the communication device 600 may include a method unit for executing the first network element in the method 200 in FIG. 2, a method unit for executing the UPF in the method 300 in FIG. 3, the method 400 or the method 500 in FIG. 4, FIG.
  • the method unit executed by the P-CSCF in method 500 in 5.
  • each unit in the communication device 600 and the above-mentioned other operations and/or functions are respectively intended to implement the corresponding processes of the method 200 in FIG. 2 to the method 500 in FIG. 5 . It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
  • the communication device 600 may be the analysis network element in the above method embodiment, or may be a chip used to implement the analysis network element function in the above method embodiment.
  • the communication device 600 may correspond to the first analysis network element or the second analysis network element in the method 200 according to the embodiment of the present application, and the communication device 600 may include a device for performing the first analysis network element or the second analysis network element.
  • the unit of the method executed by the network element.
  • each unit in the communication device 600 and the above-mentioned other operations and/or functions are respectively intended to implement the corresponding flow of the method 200 in FIG. 2 . It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
  • the communication device 600 may correspond to SMF or NWDAF in method 300, method 400, or method 500.
  • the communication device 600 may include a method unit for SMF or NWDAF execution in method 400 or method 500 in FIG. 3 .
  • each unit in the communication device 600 and the above-mentioned other operations and/or functions are respectively intended to implement the corresponding processes of the method 300 in FIG. 3 to the method 500 in FIG. 5 . It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
  • transceiver unit 610 in the communication device 600 may correspond to the transceiver 720 in the communication device 700 shown in FIG. 7 .
  • the processing unit 620 in the communication device 600 may correspond to the processor 710 in the communication device 700 shown in FIG. 7 .
  • the chip when the communication device 600 is a chip, the chip includes a transceiver unit.
  • the chip may also include a processing unit.
  • the transceiver unit may be an input-output circuit or a communication interface; the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip.
  • the transceiver unit 610 is used to implement the signal transceiver operation of the communication device 600
  • the processing unit 620 is used to implement the signal processing operation of the communication device 600 .
  • the communication device 600 further includes a storage unit 630, which is used to store instructions.
  • Figure 7 is a schematic block diagram of a communication device 700 provided by an embodiment of the present application.
  • the communication device 700 includes: at least one processor 710 and a communication interface 720 .
  • the processor 710 is coupled to the memory and is used to execute instructions stored in the memory to control the communication interface 720 to send and/or receive signals.
  • the communication device 700 also includes a memory 730 for storing instructions.
  • processor 710 and the memory 730 can be combined into one processing device, and the processor 710 is used to execute the program code stored in the memory 730 to implement the above functions.
  • the memory 730 may also be integrated in the processor 710 or independent of the processor 710 .
  • the communication interface 720 may include a receiver (or receiver) and a transmitter (or transmitter).
  • the communication interface 720 may further include an antenna, and the number of antennas may be one or more.
  • Communication interface 720 may also be an interface circuit.
  • the chip When the communication device 700 is a chip, the chip includes a transceiver unit and a processing unit.
  • the transceiver unit may be an input-output circuit or a communication interface;
  • the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip.
  • FIG 8 is a schematic diagram of a chip system according to an embodiment of the present application.
  • the chip system here may also be a system composed of circuits.
  • the chip system 800 shown in Figure 8 includes: a logic circuit 810 and an input/output interface (input/output interface) 820.
  • the logic circuit is used to couple with the input interface and transmit data (such as a first input interface) through the input/output interface. instruction information) to perform the methods described in Figures 2 to 5.
  • An embodiment of the present application also provides a processing device, including a processor and an interface.
  • the processor may be used to execute the method in the above method embodiment.
  • the above processing device may be a chip.
  • the processing device may be a field programmable gate array (field programmable gate array).
  • programmable gate array FPGA
  • FPGA field programmable gate array
  • ASIC application specific integrated circuit
  • SoC system on chip
  • CPU central processor unit
  • NP network processor
  • DSP digital signal processor
  • MCU microcontroller unit
  • PLD programmable logic controller
  • each step of the above method can be completed by instructions in the form of hardware integrated logic circuits or software in the processor.
  • the steps of the method provided in conjunction with the embodiments of the present application can be directly implemented by a hardware processor, or executed by a combination of hardware and software modules in the processor.
  • the software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field.
  • the storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
  • the processor in the embodiment of the present application may be an integrated circuit chip with signal processing capabilities.
  • each step of the above method embodiment can be completed through an integrated logic circuit of hardware in the processor or instructions in the form of software.
  • the above-mentioned processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
  • DSP digital signal processor
  • ASIC application-specific integrated circuit
  • FPGA field programmable gate array
  • a general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
  • non-volatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable programmable read-only memory (erasable PROM, EPROM), electrically removable memory. Erase electrically programmable read-only memory (EPROM, EEPROM) or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache.
  • RAM random access memory
  • the present application also provides a computer program product.
  • the computer program product includes: computer program code.
  • the computer program code When the computer program code is run on a computer, it causes the computer to execute the steps shown in Figures 2 to 5. The method of any one of the embodiments is shown.
  • the present application also provides a computer-readable medium.
  • the computer-readable medium stores program code.
  • the program code When the program code is run on a computer, it causes the computer to execute the steps shown in Figures 2 to 5. The method of any one of the embodiments is shown.
  • the present application also provides a communication system, which includes the aforementioned first network element, a first analysis network element and a second analysis network element.
  • the first analysis network element can It is a session management network element
  • the second analysis network element can be a network data analysis function network element
  • the communication system can also include a terminal device, and the terminal device is any terminal device that needs to perform abnormality detection.
  • the disclosed systems, devices and methods can be implemented in other ways.
  • the device embodiments described above are only illustrative.
  • the division of the units is only a logical function division. In actual implementation, there may be other division methods.
  • multiple units or components may be combined or can be integrated into another system, or some features can be ignored, or not implemented.
  • the coupling or direct coupling or communication connection between each other shown or discussed may be through some interfaces, and the indirect coupling or communication connection of the devices or units may be in electrical, mechanical or other forms.
  • the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
  • each functional unit in each embodiment of the present application can be integrated into one processing unit, each unit can exist physically alone, or two or more units can be integrated into one unit.
  • the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium.
  • the technical solution of the present application is essentially or the part that contributes to the existing technology or the part of the technical solution can be embodied in the form of a software product.
  • the computer software product is stored in a storage medium, including Several instructions are used to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application.
  • the aforementioned storage media include: U disk, mobile hard disk, read-only memory (ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program code. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Multimedia (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

Provided in the present application are an anomaly detection method and a communication apparatus. The method comprises: receiving first information from a first network element, the first information comprising information of initialization protocol (SIP) messages related to a terminal device; and, on the basis of the first information, determining whether the terminal device is abnormal, wherein the information of the SIP messages comprises at least one of the following: types of the SIP messages; source addresses of the SIP messages; target addresses of the SIP messages; information of first fields of the SIP messages, the first fields being used for identifying devices used by SIP message senders; information of second fields of the SIP messages, the second fields being used for identifying receiver devices of the SIP messages; and time information of detecting the SIP messages. The types of the SIP messages comprise an SIP INVITE message, an SIP CANCEL message and an SIP BYE message. By means of receiving SIP messages related to terminal devices, abnormal terminal devices can be effectively identified, thereby avoiding interference to other terminal devices.

Description

异常检测的方法和通信装置Abnormality detection method and communication device
本申请要求于2022年7月30日提交中国专利局、申请号为202210912476.7、申请名称为“异常检测的方法和通信装置”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims priority to the Chinese patent application filed with the China Patent Office on July 30, 2022, with application number 202210912476.7 and the application title "Method and Communication Device for Anomaly Detection", the entire content of which is incorporated into this application by reference. .
技术领域Technical field
本申请实施例涉及通信领域,并且更具体地,涉及一种异常检测的方法和通信装置。Embodiments of the present application relate to the field of communications, and more specifically, to an anomaly detection method and a communications device.
背景技术Background technique
在第五代(the 5th generation,5G)通信系统中,网络数据分析功能网元(network data analytics function,NWDAF)可以对终端设备在网络侧功能网元(例如,接入与移动管理功能网元、会话管理功能网元等)上产生的数据进行分析,识别终端设备的行为是否异常,例如,识别终端设备是否频繁接入或注册。在现有的方案中,NWDAF主要识别终端设备的接入和注册信息是否合规,从而识别终端设备是否为异常终端设备。而在接入和注册信息都合规的情况下,终端设备还有可能对其他终端设备造成干扰,例如,向其他终端设备发起异常呼叫,如何识别出此类异常终端设备成为亟待解决的问题。In the fifth generation (the 5th generation, 5G) communication system, the network data analytics function (NWDAF) can perform network-side functional network element (for example, access and mobility management function network) on the terminal device. Analyze the data generated on the network element, session management function network element, etc.) to identify whether the behavior of the terminal device is abnormal, for example, identify whether the terminal device frequently accesses or registers. In the existing solution, NWDAF mainly identifies whether the access and registration information of the terminal device is compliant, thereby identifying whether the terminal device is an abnormal terminal device. When the access and registration information are compliant, the terminal device may also cause interference to other terminal devices, for example, by initiating abnormal calls to other terminal devices. How to identify such abnormal terminal devices has become an urgent problem to be solved.
发明内容Contents of the invention
本申请实施例提供一种异常检测的方法及通信装置,使得分析网元可以有效地检测出异常终端设备。Embodiments of the present application provide an anomaly detection method and a communication device, so that analyzing network elements can effectively detect abnormal terminal equipment.
第一方面,提供了一种异常检测的方法,该方法包括:接收来自第一网元的第一信息,该第一信息包括与终端设备相关的初始化协议SIP消息的信息;基于该第一信息确定该终端设备是否异常;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,该第一字段用于标识SIP消息的发送方所使用的设备,该第二字段用于标识SIP消息的接收方设备。In a first aspect, an anomaly detection method is provided. The method includes: receiving first information from a first network element, where the first information includes information about an initialization protocol SIP message related to a terminal device; based on the first information Determine whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the SIP The information in the second field of the message is the time information when the SIP message is detected. The types of the SIP message include the SIP INVITE message, the SIP CANCEL message and the SIP hang-up BYE message. The first field is used to identify the sending of the SIP message. The second field is used to identify the receiving device of the SIP message.
基于上述方案,根据与终端设备的相关的SIP消息可以有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, abnormal terminal equipment can be effectively identified according to SIP messages related to the terminal equipment to avoid causing interference to other terminal equipment.
结合第一方面,在第一方面的某些实现方式中,该方法还包括:根据该第一信息确定SIP消息的统计信息;该基于该第一信息确定该终端设备是否异常,包括:基于该SIP消息的统计信息确定该终端设备是否异常。With reference to the first aspect, in some implementations of the first aspect, the method further includes: determining statistical information of the SIP message based on the first information; determining whether the terminal device is abnormal based on the first information includes: based on the first information The statistical information of SIP messages determines whether the terminal device is abnormal.
结合第一方面,在第一方面的某些实现方式中,该SIP消息的统计信息包括以下信息中的至少一项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;其中,该第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,该第一SIP消息的源地址和该第二SIP消息的目标地址相同,该第一SIP消息的类型和该第二SIP消息的类型不同。In conjunction with the first aspect, in some implementations of the first aspect, the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
基于上述方案,根据与终端设备的相关的SIP消息可以确定SIP消息的统计信息,根据SIP消息的统计信息可以有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the statistical information of the SIP message can be determined based on the SIP messages related to the terminal device, and the abnormal terminal device can be effectively identified based on the statistical information of the SIP message to avoid interference with other terminal devices.
结合第一方面,在第一方面的某些实现方式中,第一分析网元接收来自该第一网元的该第一信息;该第一分析网元或第二分析网元基于该第一信息确定该终端设备是否异常,该第一分析网元为会话管理网元或第一网络数据分析功能网元,该第二分析网元为第二网络数据分析功能网元。In conjunction with the first aspect, in some implementations of the first aspect, the first analysis network element receives the first information from the first network element; the first analysis network element or the second analysis network element is based on the first The information determines whether the terminal device is abnormal, the first analysis network element is a session management network element or a first network data analysis function network element, and the second analysis network element is a second network data analysis function network element.
结合第一方面,在第一方面的某些实现方式中,该第一分析网元根据该第一信息确定SIP消息的统计信息;该第一分析网元向该第二分析网元发送该SIP消息的统计信息;该第二分析网元基于该SIP消息的统计信息确定该终端设备是否异常。With reference to the first aspect, in some implementations of the first aspect, the first analysis network element determines the statistical information of the SIP message based on the first information; the first analysis network element sends the SIP message to the second analysis network element. Statistical information of the message; the second analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
结合第一方面,在第一方面的某些实现方式中,该第一网元为用户面网元或应用功能网元。 With reference to the first aspect, in some implementations of the first aspect, the first network element is a user plane network element or an application function network element.
结合第一方面,在第一方面的某些实现方式中,接收来自该终端设备的会话建立请求;根据该会话建立请求向该第一网元发送指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。With reference to the first aspect, in some implementations of the first aspect, a session establishment request from the terminal device is received; indication information is sent to the first network element according to the session establishment request, and the indication information indicates that according to the first data packet The detection rule PDR detects the SIP message.
结合第一方面,在第一方面的某些实现方式中,向应用功能网元发送第三SIP消息的该第二字段的信息,该第三SIP消息的源地址为该终端设备的地址;接收来自该应用功能网元的至少一个终端设备的位置信息,该至少一个终端设备的位置信息是根据该第三SIP消息的该第二字段发送的;更新该第一信息,该第一信息包括该至少一个终端设备的位置信息。Combined with the first aspect, in some implementations of the first aspect, the information of the second field of the third SIP message is sent to the application function network element, and the source address of the third SIP message is the address of the terminal device; receiving The location information of at least one terminal device from the application function network element, the location information of the at least one terminal device is sent according to the second field of the third SIP message; update the first information, the first information includes the Location information of at least one terminal device.
结合第一方面,在第一方面的某些实现方式中,基于该SIP消息的统计信息确定第一参数的值;基于该第一参数的值与第一阈值的大小关系确定该终端设备是否异常,其中,该第一参数包括以下参数中的至少一个:SIP BYE消息的总数占SIP INVITE消息的总数的比例,SIP CANCEL消息的总数占SIP INVITE消息的总数的比例,SIP INVITE消息的总数,检测到SIP消息的时间信息的离散度,该第一时长的离散度,该至少一个终端设备的位置信息的离散度。In connection with the first aspect, in some implementations of the first aspect, the value of the first parameter is determined based on the statistical information of the SIP message; and whether the terminal device is abnormal is determined based on the relationship between the value of the first parameter and the first threshold. , wherein the first parameter includes at least one of the following parameters: the ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, the total number of SIP INVITE messages, detection The dispersion degree of the time information to the SIP message, the dispersion degree of the first duration, and the dispersion degree of the location information of the at least one terminal device.
结合第一方面,在第一方面的某些实现方式中,基于该第一参数的值与该第一阈值的大小关系,以及第一权重确定该终端设备是否异常,该第一权重包括该第一参数中的至少一个参数对应的权重。With reference to the first aspect, in some implementations of the first aspect, it is determined whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold, and a first weight, the first weight including the third The weight corresponding to at least one parameter in a parameter.
第二方面,提供了一种异常检测的方法,该方法包括:第一网元确定终端设备的第一信息,该第一信息包括与该终端设备相关的初始化协议SIP消息的信息;该第一网元向分析网元发送该第一信息,该第一信息用于确定该终端设备是否异常;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,该第一字段用于标识SIP消息的发送方所使用的设备,该第二字段用于标识SIP消息的接收方设备。A second aspect provides an anomaly detection method, which method includes: a first network element determines first information of a terminal device, where the first information includes information on an initialization protocol SIP message related to the terminal device; the first The network element sends the first information to the analysis network element, and the first information is used to determine whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source of the SIP message Address, the target address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP invitation INVITE message, the SIP rejection CANCEL message As well as the SIP hang-up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
基于上述方案,第一网元通过确定与该终端设备相关的初始化协议SIP消息的信息,并向分析网元发送该SIP消息的信息,可以使得分析网元根据与终端设备的相关的SIP消息可以有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the first network element determines the information of the initialization protocol SIP message related to the terminal device and sends the information of the SIP message to the analysis network element, so that the analysis network element can determine the information based on the SIP message related to the terminal device. Effectively identify abnormal terminal equipment to avoid interference with other terminal equipment.
结合第二方面,在第二方面的某些实现方式中,接收来自该分析网元的指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。Combined with the second aspect, in some implementations of the second aspect, instruction information is received from the analysis network element, and the instruction information instructs to detect the SIP message according to the first packet detection rule PDR.
结合第二方面,在第二方面的某些实现方式中,该第一网元为用户面网元或应用功能网元。Combined with the second aspect, in some implementations of the second aspect, the first network element is a user plane network element or an application function network element.
结合第二方面,在第二方面的某些实现方式中,该分析网元为会话管理网元或网络数据分析功能网元。Combined with the second aspect, in some implementations of the second aspect, the analysis network element is a session management network element or a network data analysis function network element.
第三方面,提供了一种异常检测的方法,该方法包括:接收来自第一网元的第一信息,该第一信息包括初始化协议SIP消息的统计信息,该SIP消息的统计信息是根据与终端设备相关的SIP消息的信息确定的;基于该第一信息确定该终端设备是否异常;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP取消CANCEL消息以及SIP BYE消息,该第一字段用于标识SIP消息的发送方设备,该第二字段用于标识SIP消息的接收方设备。A third aspect provides an anomaly detection method, which method includes: receiving first information from a first network element, where the first information includes statistical information of an initialization protocol SIP message, and the statistical information of the SIP message is based on The information of the SIP message related to the terminal device is determined; based on the first information, it is determined whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, The target address of the SIP message, the information in the first field of the SIP message, the information in the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP INVITE message, the SIP CANCEL message and the SIP BYE message, the first field is used to identify the sender device of the SIP message, and the second field is used to identify the recipient device of the SIP message.
基于上述方案,根据与终端设备的相关的SIP消息可以确定SIP消息的统计信息,根据SIP消息的统计信息可以有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the statistical information of the SIP message can be determined based on the SIP messages related to the terminal device, and the abnormal terminal device can be effectively identified based on the statistical information of the SIP message to avoid interference with other terminal devices.
结合第三方面,在第三方面的某些实现方式中,该SIP消息的统计信息包括以下信息中的至少一项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;其中,该第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,该第一SIP消息的源地址和该第二SIP消息的目标地址相同,该第一SIP消息的类型和该第二SIP消息的类型不同。Combined with the third aspect, in some implementations of the third aspect, the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
结合第三方面,在第三方面的某些实现方式中,第一分析网元接收来自该第一网元的该第一信息;该第一分析网元或第二分析网元基于该第一信息确定该终端设备是否异常,该第一分析网元为会话管理网元或第一网络数据分析功能网元,该第二分析网元为该第一网络数据分析功能网元或第二网络数据分析功能网元。 Combined with the third aspect, in some implementations of the third aspect, the first analysis network element receives the first information from the first network element; the first analysis network element or the second analysis network element is based on the first The information determines whether the terminal device is abnormal, the first analysis network element is a session management network element or a first network data analysis function network element, and the second analysis network element is a first network data analysis function network element or a second network data Analyze functional network elements.
其中,若由该第二分析网元确定该终端设备是否异常,该方法还包括该第一分析网元向该第二分析网元发送该终端设备的SIP消息的统计信息。Wherein, if the second analysis network element determines whether the terminal device is abnormal, the method further includes the first analysis network element sending statistical information of the SIP messages of the terminal device to the second analysis network element.
结合第三方面,在第三方面的某些实现方式中,该第一网元包括用户面网元或应用功能网元。Combined with the third aspect, in some implementations of the third aspect, the first network element includes a user plane network element or an application function network element.
结合第三方面,在第三方面的某些实现方式中,在接收来自第一网元的第一信息之前,接收来自该终端设备的会话建立请求;根据该会话建立请求向该第一网元发送指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。Combined with the third aspect, in some implementations of the third aspect, before receiving the first information from the first network element, a session establishment request from the terminal device is received; and the session establishment request is sent to the first network element according to the session establishment request. Send instruction information, the instruction information indicating detecting the SIP message according to the first packet detection rule PDR.
结合第三方面,在第三方面的某些实现方式中,在接收来自第一网元的第一信息之后,向应用功能网元发送第三SIP消息的该第二字段的信息,该第三SIP消息的源地址为该终端设备的地址;接收来自该应用功能网元的至少一个终端设备的位置信息,该至少一个终端设备的位置信息是根据该第三SIP消息的该第二字段发送的;更新该第一信息,该第一信息包括该至少一个终端设备的位置信息。Combined with the third aspect, in some implementations of the third aspect, after receiving the first information from the first network element, the information of the second field of the third SIP message is sent to the application function network element, and the third The source address of the SIP message is the address of the terminal device; receiving the location information of at least one terminal device from the application function network element, the location information of the at least one terminal device is sent according to the second field of the third SIP message ; Update the first information, which includes the location information of the at least one terminal device.
结合第三方面,在第三方面的某些实现方式中,基于该SIP消息的统计信息确定第一参数的值;基于该第一参数的值与第一阈值的大小关系确定该终端设备是否异常,其中,该第一参数包括以下参数中的至少一个:SIP BYE消息的总数占的SIP INVITE消息的总数,SIP CANCEL消息的总数占的SIP INVITE消息的总数,SIP INVITE消息的总数,检测到SIP消息的时间的离散度,该第一时长的离散度,该至少一个终端设备的位置信息的离散度。Combined with the third aspect, in some implementations of the third aspect, the value of the first parameter is determined based on the statistical information of the SIP message; and whether the terminal device is abnormal is determined based on the relationship between the value of the first parameter and the first threshold. , wherein the first parameter includes at least one of the following parameters: the total number of SIP BYE messages accounted for the total number of SIP INVITE messages, the total number of SIP CANCEL messages accounted for the total number of SIP INVITE messages, the total number of SIP INVITE messages, SIP detected The time dispersion of the message, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
结合第三方面,在第三方面的某些实现方式中,基于该第一参数的值与该第一阈值的大小关系,以及第一权重确定该终端设备是否异常,该第一权重包括该第一参数中的至少一个参数对应的权重。In conjunction with the third aspect, in some implementations of the third aspect, whether the terminal device is abnormal is determined based on a relationship between the value of the first parameter and the first threshold, and a first weight, the first weight including the third The weight corresponding to at least one parameter in a parameter.
第四方面,提供了一种异常检测的方法,该方法包括:第一网元确定与终端设备相关的SIP消息的信息;该第一网元根据该SIP消息的信息确定终端设备的SIP消息的统计信息,该SIP消息的统计信息用于确定终端设备是否异常;该第一网元向分析网元发送该SIP消息的统计信息;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP取消CANCEL消息以及SIP BYE消息,该第一字段用于标识SIP消息的发送方设备,该第二字段用于标识SIP消息的接收方设备。A fourth aspect provides an anomaly detection method, which method includes: the first network element determines the information of the SIP message related to the terminal device; the first network element determines the SIP message of the terminal device based on the information of the SIP message. Statistical information, the statistical information of the SIP message is used to determine whether the terminal device is abnormal; the first network element sends the statistical information of the SIP message to the analysis network element; wherein the information of the SIP message includes at least one of the following information: The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the type of the SIP message includes SIP In the INVITE message, the SIP CANCEL message and the SIP BYE message, the first field is used to identify the sender device of the SIP message, and the second field is used to identify the recipient device of the SIP message.
基于上述方案,第一网元根据与终端设备的相关的SIP消息可以确定SIP消息的统计信息,通过向分析网元发送SIP消息的统计信息可以使得分析网元有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the first network element can determine the statistical information of the SIP message based on the SIP message related to the terminal device. By sending the statistical information of the SIP message to the analyzing network element, the analyzing network element can effectively identify the abnormal terminal device and avoid Cause interference to other terminal equipment.
结合第四方面,在第四方面的某些实现方式中,该SIP消息的统计信息包括以下信息中的至少一项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;其中,该第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,该第一SIP消息的源地址和该第二SIP消息的目标地址相同,该第一SIP消息的类型和该第二SIP消息的类型不同。Combined with the fourth aspect, in some implementations of the fourth aspect, the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the number of SIP messages with the same source address and different first fields, first duration information; wherein the first duration is determined by the time information of the first SIP message and the time information of the second SIP message, and the first SIP message The source address and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
结合第四方面,在第四方面的某些实现方式中,该分析网元为会话管理网元或网络数据分析功能网元。Combined with the fourth aspect, in some implementations of the fourth aspect, the analysis network element is a session management network element or a network data analysis function network element.
结合第四方面,在第四方面的某些实现方式中,该第一网元包括用户面网元或应用功能网元。Combined with the fourth aspect, in some implementations of the fourth aspect, the first network element includes a user plane network element or an application function network element.
结合第四方面,在第四方面的某些实现方式中,该第一网元接收来自分析网元的指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。In connection with the fourth aspect, in some implementations of the fourth aspect, the first network element receives indication information from the analysis network element, and the indication information instructs to detect the SIP message according to the first packet detection rule PDR.
第五方面,提供了一种通信装置,该装置包括收发单元和处理单元,该收发单元用于接收来自第一网元的第一信息,该第一信息包括与终端设备相关的初始化协议SIP消息的信息;该处理单元,用于基于该第一信息确定该终端设备是否异常;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,该第一字段用于标识SIP消息的发送方所使用的设备,该第二字段用于标识SIP消息的接收方设备。In a fifth aspect, a communication device is provided. The device includes a transceiver unit and a processing unit. The transceiver unit is configured to receive first information from the first network element. The first information includes an initialization protocol SIP message related to the terminal device. information; the processing unit is configured to determine whether the terminal device is abnormal based on the first information; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the source address of the SIP message, the The target address, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the type of the SIP message includes the SIP invitation INVITE message, the SIP rejection CANCEL message and the SIP hang-up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the device of the recipient of the SIP message.
结合第五方面,在第五方面的某些实现方式中,该处理单元还用于根据该第一信息确定SIP消息的统计信息;该处理单元具体用于基于该SIP消息的统计信息确定该终端设备是否异常。With reference to the fifth aspect, in some implementations of the fifth aspect, the processing unit is further configured to determine the statistical information of the SIP message based on the first information; the processing unit is specifically configured to determine the terminal based on the statistical information of the SIP message. Whether the equipment is abnormal.
结合第五方面,在第五方面的某些实现方式中,该SIP消息的统计信息包括以下信息中的至少一 项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;其中,该第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,该第一SIP消息的源地址和该第二SIP消息的目标地址相同,该第一SIP消息的类型和该第二SIP消息的类型不同。Combined with the fifth aspect, in some implementations of the fifth aspect, the statistical information of the SIP message includes at least one of the following information: Items: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration is represented by the first The time information of the SIP message and the time information of the second SIP message determine that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different. .
结合第五方面,在第五方面的某些实现方式中,该第一网元为用户面网元或应用功能网元。Combined with the fifth aspect, in some implementations of the fifth aspect, the first network element is a user plane network element or an application function network element.
结合第五方面,在第五方面的某些实现方式中,该收发单元还用于接收来自该终端设备的会话建立请求;根据该会话建立请求向该第一网元发送指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。With reference to the fifth aspect, in some implementations of the fifth aspect, the transceiver unit is also configured to receive a session establishment request from the terminal device; and send indication information to the first network element according to the session establishment request. The indication information Indicates that the SIP message is detected according to the first packet detection rule PDR.
结合第五方面,在第五方面的某些实现方式中,该收发单元还用于向应用功能网元发送第三SIP消息的该第二字段的信息,该第三SIP消息的源地址为该终端设备的地址;接收来自该应用功能网元的至少一个终端设备的位置信息,该至少一个终端设备的位置信息是根据该第三SIP消息的该第二字段发送的;该处理单元还用于更新该第一信息,该第一信息包括该至少一个终端设备的位置信息。In connection with the fifth aspect, in some implementations of the fifth aspect, the transceiver unit is also configured to send the information of the second field of the third SIP message to the application function network element, and the source address of the third SIP message is The address of the terminal device; receiving location information of at least one terminal device from the application function network element, the location information of the at least one terminal device being sent according to the second field of the third SIP message; the processing unit is also configured to The first information is updated, and the first information includes location information of the at least one terminal device.
结合第五方面,在第五方面的某些实现方式中,该处理单元具体用于基于该SIP消息的统计信息确定第一参数的值;基于该第一参数的值与第一阈值的大小关系确定该终端设备是否异常,其中,该第一参数包括以下参数中的至少一个:SIP BYE消息的总数占SIP INVITE消息的总数的比例,SIP CANCEL消息的总数占SIP INVITE消息的总数的比例,SIP INVITE消息的总数,检测到SIP消息的时间信息的离散度,该第一时长的离散度,该至少一个终端设备的位置信息的离散度。With reference to the fifth aspect, in some implementations of the fifth aspect, the processing unit is specifically configured to determine the value of the first parameter based on the statistical information of the SIP message; based on the relationship between the value of the first parameter and the first threshold. Determine whether the terminal device is abnormal, wherein the first parameter includes at least one of the following parameters: the ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, SIP The total number of INVITE messages, the dispersion of the time information of the detected SIP messages, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
结合第五方面,在第五方面的某些实现方式中,该处理单元具体用于基于该第一参数的值与该第一阈值的大小关系,以及第一权重确定该终端设备是否异常,该第一权重包括该第一参数中的至少一个参数对应的权重。With reference to the fifth aspect, in some implementations of the fifth aspect, the processing unit is specifically configured to determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold, and the first weight. The first weight includes a weight corresponding to at least one parameter in the first parameter.
第六方面,提供了一种通信装置,该装置包括处理单元和收发单元,第一网元确定终端设备的第一信息,该第一信息包括与该终端设备相关的初始化协议SIP消息的信息;该第一网元向分析网元发送该第一信息,该第一信息用于确定该终端设备是否异常;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,该第一字段用于标识SIP消息的发送方所使用的设备,该第二字段用于标识SIP消息的接收方设备。In a sixth aspect, a communication device is provided. The device includes a processing unit and a transceiver unit. The first network element determines the first information of the terminal device, and the first information includes the information of the initialization protocol SIP message related to the terminal device; The first network element sends the first information to the analysis network element, and the first information is used to determine whether the terminal device is abnormal; wherein the information of the SIP message includes at least one of the following information: type of SIP message, SIP The source address of the message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP invitation INVITE message, the SIP reject message When receiving a CANCEL message and a SIP hang-up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the device of the recipient of the SIP message.
基于上述方案,第一网元通过确定与该终端设备相关的初始化协议SIP消息的信息,并向分析网元发送该SIP消息的信息,可以使得分析网元根据与终端设备的相关的SIP消息可以有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the first network element determines the information of the initialization protocol SIP message related to the terminal device and sends the information of the SIP message to the analysis network element, so that the analysis network element can determine the information based on the SIP message related to the terminal device. Effectively identify abnormal terminal equipment to avoid interference with other terminal equipment.
结合第六方面,在第六方面的某些实现方式中,接收来自该分析网元的指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。In conjunction with the sixth aspect, in some implementations of the sixth aspect, instruction information is received from the analysis network element, and the instruction information instructs to detect the SIP message according to the first packet detection rule PDR.
结合第六方面,在第六方面的某些实现方式中,该第一网元为用户面网元或应用功能网元。Combined with the sixth aspect, in some implementations of the sixth aspect, the first network element is a user plane network element or an application function network element.
结合第六方面,在第六方面的某些实现方式中,该分析网元为会话管理网元或网络数据分析功能网元。Combined with the sixth aspect, in some implementations of the sixth aspect, the analysis network element is a session management network element or a network data analysis function network element.
第七方面,提供了一种通信装置,该装置包括收发单元和处理单元,该收发单元用于接收来自第一网元的初始化协议SIP消息的统计信息,该SIP消息的统计信息是根据与终端设备相关的SIP消息的信息确定的;该处理单元用于基于该第一信息确定该终端设备是否异常;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP取消CANCEL消息以及SIP BYE消息,该第一字段用于标识SIP消息的发送方设备,该第二字段用于标识SIP消息的接收方设备。In a seventh aspect, a communication device is provided. The device includes a transceiver unit and a processing unit. The transceiver unit is used to receive statistical information of the initialization protocol SIP message from the first network element. The statistical information of the SIP message is based on the communication with the terminal. The information of the device-related SIP message is determined; the processing unit is used to determine whether the terminal device is abnormal based on the first information; wherein the information of the SIP message includes at least one of the following information: the type of the SIP message, the SIP message The source address, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information when the SIP message is detected, the type of the SIP message includes the SIP INVITE message, the SIP CANCEL message and SIP BYE message, the first field is used to identify the sender device of the SIP message, and the second field is used to identify the receiver device of the SIP message.
结合第七方面,在第七方面的某些实现方式中,该SIP消息的统计信息包括以下信息中的至少一项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;其中,该第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,该第一SIP消息的源地址和该第二SIP消息的目标地址相同,该第一SIP消息的类型和该第二SIP消息的类型不同。 Combined with the seventh aspect, in some implementations of the seventh aspect, the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
结合第七方面,在第七方面的某些实现方式中,该通信装置为会话管理网元或网络数据分析功能网元。In conjunction with the seventh aspect, in some implementations of the seventh aspect, the communication device is a session management network element or a network data analysis function network element.
结合第七方面,在第七方面的某些实现方式中,该第一网元包括用户面网元或应用功能网元。Combined with the seventh aspect, in some implementations of the seventh aspect, the first network element includes a user plane network element or an application function network element.
结合第七方面,在第七方面的某些实现方式中,该收发单元还用于接收来自该终端设备的会话建立请求;根据该会话建立请求向该第一网元发送指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。In conjunction with the seventh aspect, in some implementations of the seventh aspect, the transceiver unit is also configured to receive a session establishment request from the terminal device; and send indication information to the first network element according to the session establishment request. The indication information Indicates that the SIP message is detected according to the first packet detection rule PDR.
结合第七方面,在第七方面的某些实现方式中,该收发单元还用于向应用功能网元发送第三SIP消息的该第二字段的信息,该第三SIP消息的源地址为该终端设备的地址;接收来自该应用功能网元的至少一个终端设备的位置信息,该至少一个终端设备的位置信息是根据该第三SIP消息的该第二字段发送的;更新该第一信息,该第一信息包括该至少一个终端设备的位置信息。In conjunction with the seventh aspect, in some implementations of the seventh aspect, the transceiver unit is also configured to send the information of the second field of the third SIP message to the application function network element, and the source address of the third SIP message is the address of the terminal device; receiving the location information of at least one terminal device from the application function network element, the location information of the at least one terminal device being sent according to the second field of the third SIP message; updating the first information, The first information includes location information of the at least one terminal device.
结合第七方面,在第七方面的某些实现方式中,还处理单元具体用于基于该SIP消息的统计信息确定第一参数的值;基于该第一参数的值与第一阈值的大小关系确定该终端设备是否异常,其中,该第一参数包括以下参数中的至少一个:SIP BYE消息的总数占的SIP INVITE消息的总数,SIP CANCEL消息的总数占的SIP INVITE消息的总数,SIP INVITE消息的总数,检测到SIP消息的时间的离散度,该第一时长的离散度,该至少一个终端设备的位置信息的离散度。In connection with the seventh aspect, in some implementations of the seventh aspect, the processing unit is further configured to determine the value of the first parameter based on the statistical information of the SIP message; based on the relationship between the value of the first parameter and the first threshold. Determine whether the terminal device is abnormal, wherein the first parameter includes at least one of the following parameters: the total number of SIP BYE messages accounts for the total number of SIP INVITE messages, the total number of SIP CANCEL messages accounts for the total number of SIP INVITE messages, the total number of SIP INVITE messages The total number, the dispersion of the time when the SIP message is detected, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
结合第七方面,在第七方面的某些实现方式中,该处理单元具体用于基于该第一参数的值与该第一阈值的大小关系,以及第一权重确定该终端设备是否异常,该第一权重包括该第一参数中的至少一个参数对应的权重。In conjunction with the seventh aspect, in some implementations of the seventh aspect, the processing unit is specifically configured to determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold, and the first weight. The first weight includes a weight corresponding to at least one parameter in the first parameter.
第八方面,提供了一种通信装置,该装置包括收发单元和处理单元,该处理单元用于确定与终端设备相关的SIP消息的信息;该处理单元还用于根据该SIP消息的信息确定终端设备的SIP消息的统计信息,该SIP消息的统计信息用于确定终端设备是否异常;该第一网元向分析网元发送该SIP消息的统计信息;其中,该SIP消息的信息包括以下信息中的至少一项:SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,该SIP消息的类型包括SIP邀请INVITE消息,SIP取消CANCEL消息以及SIP BYE消息,该第一字段用于标识SIP消息的发送方设备,该第二字段用于标识SIP消息的接收方设备。In an eighth aspect, a communication device is provided. The device includes a transceiver unit and a processing unit. The processing unit is used to determine the information of the SIP message related to the terminal device; the processing unit is also used to determine the terminal according to the information of the SIP message. Statistical information of the SIP message of the device. The statistical information of the SIP message is used to determine whether the terminal device is abnormal. The first network element sends the statistical information of the SIP message to the analysis network element. The information of the SIP message includes the following information. At least one of: the type of the SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, the SIP Message types include SIP INVITE messages, SIP CANCEL messages, and SIP BYE messages. The first field is used to identify the sender device of the SIP message, and the second field is used to identify the recipient device of the SIP message.
基于上述方案,第一网元根据与终端设备的相关的SIP消息可以确定SIP消息的统计信息,通过向分析网元发送SIP消息的统计信息可以使得分析网元有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the first network element can determine the statistical information of the SIP message based on the SIP message related to the terminal device. By sending the statistical information of the SIP message to the analyzing network element, the analyzing network element can effectively identify the abnormal terminal device and avoid Cause interference to other terminal equipment.
结合第八方面,在第八方面的某些实现方式中,该SIP消息的统计信息包括以下信息中的至少一项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;其中,该第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,该第一SIP消息的源地址和该第二SIP消息的目标地址相同,该第一SIP消息的类型和该第二SIP消息的类型不同。Combined with the eighth aspect, in some implementations of the eighth aspect, the statistical information of the SIP message includes at least one of the following information: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type , the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, first duration information; where the first duration consists of the time information of the first SIP message and the second SIP The time information of the message determines that the source address of the first SIP message and the destination address of the second SIP message are the same, and the type of the first SIP message and the type of the second SIP message are different.
结合第八方面,在第八方面的某些实现方式中,该分析网元为会话管理网元或网络数据分析功能网元。Combined with the eighth aspect, in some implementations of the eighth aspect, the analysis network element is a session management network element or a network data analysis function network element.
结合第八方面,在第八方面的某些实现方式中,该第一网元包括用户面网元或应用功能网元。Combined with the eighth aspect, in some implementations of the eighth aspect, the first network element includes a user plane network element or an application function network element.
结合第八方面,在第八方面的某些实现方式中,该第一网元接收来自分析网元的指示信息,该指示信息指示根据第一数据包检测规则PDR检测该SIP消息。Combined with the eighth aspect, in some implementations of the eighth aspect, the first network element receives indication information from the analysis network element, and the indication information instructs to detect the SIP message according to the first packet detection rule PDR.
第九方面,提供了一种通信装置,包括处理器。该处理器与存储器耦合,可用于执行存储器中的指令,以实现上述第一方面至第四方面及第一方面至第四方面中任一种可能实现方式中的方法。示例性地,该通信装置还包括存储器。该通信装置还包括通信接口,处理器与通信接口耦合。In a ninth aspect, a communication device is provided, including a processor. The processor is coupled to the memory and can be used to execute instructions in the memory to implement the method in any one of the above first to fourth aspects and possible implementation manners. Exemplarily, the communication device further includes a memory. The communication device also includes a communication interface, and the processor is coupled to the communication interface.
第十方面,提供了一种处理器,包括:输入电路、输出电路和处理电路。所述处理电路用于通过所述输入电路接收信号,并通过所述输出电路发射信号,使得所述处理器执行以实现上述第一方面至第四方面及第一方面至第四方面中任一种可能实现方式中的方法。In a tenth aspect, a processor is provided, including: an input circuit, an output circuit and a processing circuit. The processing circuit is configured to receive a signal through the input circuit and transmit a signal through the output circuit, so that the processor executes to implement any one of the above first to fourth aspects and the first to fourth aspects. possible implementation methods.
在具体实现过程中,上述处理器可以为一个或多个芯片,输入电路可以为输入管脚,输出电路可以为输出管脚,处理电路可以为晶体管、门电路、触发器和各种逻辑电路等。输入电路所接收的输入的信号可以是由例如但不限于接收器接收并输入的,输出电路所输出的信号可以是例如但不限于输出 给发射器并由发射器发射的,且输入电路和输出电路可以是同一电路,该电路在不同的时刻分别用作输入电路和输出电路。本申请实施例对处理器及各种电路的具体实现方式不做限定。In the specific implementation process, the above-mentioned processor can be one or more chips, the input circuit can be an input pin, the output circuit can be an output pin, and the processing circuit can be a transistor, a gate circuit, a flip-flop and various logic circuits, etc. . The input signal received by the input circuit may be received and input by, for example, but not limited to, a receiver, and the signal output by the output circuit may be, for example, but not limited to, an output To the transmitter and transmitted by the transmitter, the input circuit and the output circuit may be the same circuit, which is used as an input circuit and an output circuit respectively at different times. The embodiments of this application do not limit the specific implementation methods of the processor and various circuits.
第十一方面,提供了一种处理装置,包括处理器和存储器。该处理器用于读取存储器中存储的指令,并可通过接收器接收信号,通过发射器发射信号,以执行上述第一方面至第四方面及第一方面至第四方面中任一种可能实现方式中的方法。In an eleventh aspect, a processing device is provided, including a processor and a memory. The processor is used to read instructions stored in the memory, and can receive signals through a receiver and transmit signals through a transmitter to execute any of the above first to fourth aspects and possible implementations of the first to fourth aspects. method within the method.
示例性地,所述处理器为一个或多个,所述存储器为一个或多个。For example, there are one or more processors and one or more memories.
示例性地,所述存储器可以与所述处理器集成在一起,或者所述存储器与处理器分离设置。For example, the memory may be integrated with the processor, or the memory may be provided separately from the processor.
在具体实现过程中,存储器可以为非瞬时性(non-transitory)存储器,例如只读存储器(read only memory,ROM),其可以与处理器集成在同一块芯片上,也可以分别设置在不同的芯片上,本申请实施例对存储器的类型以及存储器与处理器的设置方式不做限定。In the specific implementation process, the memory can be a non-transitory memory, such as a read-only memory (ROM), which can be integrated on the same chip as the processor, or can be set in different On the chip, the embodiment of the present application does not limit the type of memory and the arrangement of the memory and the processor.
应理解,相关的数据交互过程例如发送指示信息可以为从处理器输出指示信息的过程,接收能力信息可以为处理器接收输入能力信息的过程。具体地,处理器输出的数据可以输出给发射器,处理器接收的输入数据可以来自接收器。其中,发射器和接收器可以统称为收发器。It should be understood that the relevant data interaction process, for example, sending instruction information may be a process of outputting instruction information from the processor, and receiving capability information may be a process of the processor receiving input capability information. Specifically, the data output by the processor can be output to the transmitter, and the input data received by the processor can be from the receiver. Among them, the transmitter and receiver can be collectively called a transceiver.
上述第十一方面中的处理装置可以是一个或多个芯片。该处理装置中的处理器可以通过硬件来实现也可以通过软件来实现。当通过硬件实现时,该处理器可以是逻辑电路、集成电路等;当通过软件来实现时,该处理器可以是一个通用处理器,通过读取存储器中存储的软件代码来实现,该存储器可以集成在处理器中,可以位于该处理器之外,独立存在。The processing device in the above eleventh aspect may be one or more chips. The processor in the processing device can be implemented by hardware or software. When implemented by hardware, the processor can be a logic circuit, an integrated circuit, etc.; when implemented by software, the processor can be a general processor, which is implemented by reading software codes stored in a memory, and the memory can Integrated in the processor, it can be located outside the processor and exist independently.
第十二方面,提供了一种计算机程序产品,所述计算机程序产品包括:计算机程序(也可以称为代码,或指令),当所述计算机程序被运行时,使得计算机以执行上述第一方面至第四方面及第一方面至第四方面中任一种可能实现方式中的方法。In a twelfth aspect, a computer program product is provided. The computer program product includes: a computer program (which may also be called a code, or an instruction). When the computer program is run, the computer is caused to execute the first aspect. to the fourth aspect and the method in any possible implementation manner of the first to fourth aspects.
第十三方面,提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机程序(也可以称为代码,或指令)当其在计算机上运行时,使得上述第一方面和第二方面中任一种可能实现方式中的方法被执行。In a thirteenth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (which may also be called a code, or an instruction) that when run on a computer causes the above-mentioned first aspect and The method in any possible implementation manner of the second aspect is executed.
第十四方面,提供了一种通信系统,包括前述的第一网元以及与该第一网元通信的分析网元,其中,该第一网元为用户面网元或应用功能网元,该分析网元为会话管理网元或网络数据分析功能网元。A fourteenth aspect provides a communication system, including the aforementioned first network element and an analysis network element communicating with the first network element, wherein the first network element is a user plane network element or an application function network element, The analysis network element is a session management network element or a network data analysis function network element.
附图说明Description of the drawings
图1是本申请实施例方法适用的应用场景的示意图。Figure 1 is a schematic diagram of an application scenario applicable to the method of the embodiment of the present application.
图2是本申请实施例提供的异常检测的方法的示意性流程图。FIG. 2 is a schematic flow chart of an anomaly detection method provided by an embodiment of the present application.
图3是本申请另一实施例提供的异常检测的方法的示意性流程图。Figure 3 is a schematic flow chart of an anomaly detection method provided by another embodiment of the present application.
图4是本申请另一实施例提供的异常检测的方法的示意性流程图。Figure 4 is a schematic flow chart of an anomaly detection method provided by another embodiment of the present application.
图5是本申请另一实施例提供的异常检测的方法的示意性流程图。Figure 5 is a schematic flow chart of an anomaly detection method provided by another embodiment of the present application.
图6是本申请实施例提供的通信装置的示意图。Figure 6 is a schematic diagram of a communication device provided by an embodiment of the present application.
图7是本申请实施例提供的通信装置的示意性框图。Figure 7 is a schematic block diagram of a communication device provided by an embodiment of the present application.
图8是本申请实施例提供的一种芯片系统的示意图。FIG. 8 is a schematic diagram of a chip system provided by an embodiment of the present application.
具体实施方式Detailed ways
下面将结合附图,对本申请实施例中的技术方案进行描述。The technical solutions in the embodiments of the present application will be described below with reference to the accompanying drawings.
本申请实施例的技术方案可以应用于各种通信系统,例如:长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)、全球互联微波接入(worldwide interoperability for microwave access,WiMAX)通信系统、第五代(5th generation,5G)通信系统或未来通信系统,例如,第六代(6th generation,6G)通信系统,车到其它设备(vehicle-to-x,V2X),其中V2X可以包括车到互联网(vehicle-to-network,V2N)、车到车(vehicle-to-vehicle,V2V)、车到基础设施(vehicle-to-infrastructure,V2I)、车到行人(vehicle-to-pedestrian,V2P)等、车间通信长期演进技术(long term evolution-vehicle,LTE-V)、车联网、机器类通信(machine type communication,MTC)、物联网(internet of things,IoT)、机器间通信长期演进技术(long term evolution-machine,LTE-M),机器到机器(machine to machine,M2M) 等。The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: long term evolution (long term evolution, LTE) system, LTE frequency division duplex (FDD) system, LTE time division duplex (time division duplex) , TDD), global interoperability for microwave access (WiMAX) communication system, fifth generation (5th generation, 5G) communication system or future communication system, for example, sixth generation (6th generation, 6G) communication system , vehicle-to-x, V2X), where V2X can include vehicle-to-network (V2N), vehicle-to-vehicle (V2V), vehicle-to-infrastructure ( vehicle-to-infrastructure (V2I), vehicle-to-pedestrian (V2P), etc., long term evolution-vehicle (LTE-V), vehicle networking, machine type communication (machine type communication), etc. , MTC), Internet of things (IoT), long term evolution-machine (LTE-M), machine to machine (M2M) wait.
图1是适用于本申请实施例提供的方法的网络架构示意图。该网络架构具体可以包括下列网元:Figure 1 is a schematic diagram of a network architecture suitable for the method provided by the embodiment of this application. The network architecture may specifically include the following network elements:
1、用户设备(user equipment,UE):可以包括各种具有无线通信功能的手持设备、车载设备、可穿戴设备、计算设备或连接到无线调制解调器的其它处理设备,以及各种形式的终端、移动台(mobile station,MS)、终端(terminal)或软终端等等。例如,水表、电表、传感器等。1. User equipment (UE): can include various handheld devices with wireless communication functions, vehicle-mounted devices, wearable devices, computing devices or other processing devices connected to wireless modems, as well as various forms of terminals, mobile devices Mobile station (MS), terminal or soft terminal, etc. For example, water meters, electricity meters, sensors, etc.
示例性地,本申请实施例中的用户设备可以指接入终端、用户单元、用户站、移动站、移动台、中继站、远方站、远程终端、移动设备、用户终端(user terminal)、终端设备(terminal equipment)、无线通信设备、用户代理或用户装置。用户设备还可以是蜂窝电话、无绳电话、会话启动协议(session initiation protocol,SIP)电话、无线本地环路(wireless local loop,WLL)站、个人数字助理(personal digital assistant,PDA)、具有无线通信功能的手持设备、计算设备或连接到无线调制解调器的其它处理设备、车载设备、可穿戴设备,5G网络中的用户设备或者未来演进的公用陆地移动通信网络(public land mobile network,PLMN)中的用户设备或者未来车联网中的用户设备等,本申请对此并不限定。Illustratively, the user equipment in the embodiment of the present application may refer to an access terminal, a user unit, a user station, a mobile station, a mobile station, a relay station, a remote station, a remote terminal, a mobile device, a user terminal (user terminal), and a terminal device. (terminal equipment), wireless communications equipment, user agent or user device. The user equipment may also be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a device with wireless communications Functional handheld devices, computing devices or other processing devices connected to wireless modems, vehicle-mounted devices, wearable devices, user equipment in 5G networks or users in future evolved public land mobile communications networks (PLMN) Equipment or user equipment in future Internet of Vehicles, etc. This application is not limited to this.
作为示例而非限定,在本申请实施例中,可穿戴设备也可以称为穿戴式智能设备,是应用穿戴式技术对日常穿戴进行智能化设计、开发出可以穿戴的设备的总称,如眼镜、手套、手表、服饰及鞋等。可穿戴设备即直接穿在身上,或是整合到用户的衣服或配件的一种便携式设备。可穿戴设备不仅仅是一种硬件设备,还可以通过软件支持以及数据交互、云端交互来实现强大的功能。广义穿戴式智能设备包括功能全、尺寸大、可不依赖智能手机实现完整或者部分的功能,例如:智能手表或智能眼镜等,以及只专注于某一类应用功能,需要和其它设备如智能手机配合使用,如各类进行体征监测的智能手环、智能首饰等。As an example and not a limitation, in the embodiments of this application, a wearable device may also be called a wearable smart device, which is a general term for applying wearable technology to intelligently design daily wear and develop wearable devices, such as glasses, Gloves, watches, clothing and shoes, etc. A wearable device is a portable device that is worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not just hardware devices, they can also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly defined wearable smart devices include full-featured, large-sized devices that can achieve complete or partial functions without relying on smartphones, such as smart watches or smart glasses, and those that only focus on a certain type of application function and need to cooperate with other devices such as smartphones. Use, such as various smart bracelets, smart jewelry, etc. for physical sign monitoring.
此外,在本申请实施例中,用户设备还可以是物联网(internet of Things,IoT)系统中的用户设备,IoT是未来信息技术发展的重要组成部分,其主要技术特点是将物品通过通信技术与网络连接,从而实现人机互连,物物互连的智能化网络。在本申请实施例中,IOT技术可以通过例如窄带(narrow band,NB)技术,做到海量连接,深度覆盖,终端省电。此外,在本申请实施例中,用户设备还可以包括智能打印机、火车探测器、加油站等传感器,主要功能包括收集数据(部分用户设备)、接收接入网设备的控制信息与下行数据,并发送电磁波,向接入网设备传输上行数据。In addition, in the embodiments of this application, the user equipment can also be user equipment in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to transfer items through communication technology. Connect with the network to realize an intelligent network of human-computer interconnection and physical-object interconnection. In the embodiment of this application, IOT technology can achieve massive connections, deep coverage, and terminal power saving through, for example, narrowband (NB) technology. In addition, in the embodiment of this application, user equipment may also include sensors such as smart printers, train detectors, and gas stations. The main functions include collecting data (part of user equipment), receiving control information and downlink data of access network equipment, and Send electromagnetic waves to transmit uplink data to access network equipment.
2、(无线)接入网设备(radio access network,(R)AN):用于为特定区域的授权用户设备提供入网功能,并能够根据用户设备的级别,业务的需求等使用不同质量的传输隧道。2. (Wireless) access network equipment (radio access network, (R)AN): used to provide network access functions for authorized user equipment in a specific area, and can use different quality transmissions according to the level of user equipment, business needs, etc. tunnel.
RAN能够管理无线资源,为用户设备提供接入服务,进而完成控制信号和用户设备数据在用户设备和核心网之间的转发。RAN也可以理解为传统网络中的基站。RAN can manage wireless resources, provide access services for user equipment, and then complete the forwarding of control signals and user equipment data between the user equipment and the core network. RAN can also be understood as a base station in a traditional network.
示例性地,本申请实施例中的接入网设备可以是用于与用户设备通信的任意一种具有无线收发功能的通信设备。该接入网设备包括但不限于:演进型节点B(evolved Node B,eNB)、基带单元(baseBand unit,BBU),无线保真(wireless fidelity,WIFI)系统中的接入点(access point,AP)、无线中继节点、无线回传节点、传输点(transmission point,TP)或者发送接收点(transmission and reception point,TRP)等,还可以为5G,如,NR,系统中的gNB,或,传输点(TRP或TP),5G系统中的基站的一个或一组(包括多个天线面板)天线面板,或者,还可以为构成gNB或传输点的网络节点,如基带单元(BBU),或,分布式单元(distributed unit,DU)等。Illustratively, the access network device in the embodiment of the present application may be any communication device with wireless transceiver functions used to communicate with user equipment. The access network equipment includes but is not limited to: evolved Node B (eNB), baseband unit (BBU), access point (access point) in the wireless fidelity (wireless fidelity, WIFI) system, AP), wireless relay node, wireless backhaul node, transmission point (TP) or transmission and reception point (TRP), etc. It can also be 5G, such as NR, gNB in the system, or , transmission point (TRP or TP), one or a group (including multiple antenna panels) of antenna panels of a base station in a 5G system, or it can also be a network node that constitutes a gNB or transmission point, such as a baseband unit (BBU), Or, distributed unit (DU), etc.
在一些部署中,gNB可以包括集中式单元(centralized unit,CU)和DU。gNB还可以包括有源天线单元(active antenna unit,AAU)。CU实现gNB的部分功能,DU实现gNB的部分功能。比如,CU负责处理非实时协议和服务,实现无线资源控制(radio resource control,RRC),分组数据汇聚层协议(packet data convergence protocol,PDCP)层的功能。DU负责处理物理层协议和实时服务,实现无线链路控制(radio link control,RLC)层、媒体接入控制(media access control,MAC)层和物理(physical,PHY)层的功能。AAU实现部分物理层处理功能、射频处理及有源天线的相关功能。由于RRC层的信息最终会变成PHY层的信息,或者,由PHY层的信息转变而来,因而,在这种架构下,高层信令,如RRC层信令,也可以认为是由DU发送的,或者,由DU+AAU发送的。可以理解的是,接入网设备可以为包括CU节点、DU节点、AAU节点中一项或多项的设备。此外,可以将CU划分为接入网(radio access network,RAN)中的接入网设备,也可以将CU划分为核心网(core network,CN)中的接入网设备,本申请对此不做限定。 In some deployments, gNB may include centralized units (CUs) and DUs. The gNB may also include an active antenna unit (AAU). CU implements some functions of gNB, and DU implements some functions of gNB. For example, the CU is responsible for processing non-real-time protocols and services, and implementing radio resource control (RRC) and packet data convergence protocol (PDCP) layer functions. DU is responsible for processing physical layer protocols and real-time services, and implementing the functions of the radio link control (RLC) layer, media access control (MAC) layer and physical (physical, PHY) layer. AAU implements some physical layer processing functions, radio frequency processing and active antenna related functions. Since RRC layer information will eventually become PHY layer information, or transformed from PHY layer information, in this architecture, high-level signaling, such as RRC layer signaling, can also be considered to be sent by DU , or sent by DU+AAU. It can be understood that the access network device may be a device including one or more of a CU node, a DU node, and an AAU node. In addition, the CU can be divided into access network equipment in the access network (radio access network, RAN), or the CU can be divided into access network equipment in the core network (core network, CN). This application does not Make limitations.
2、接入和移动管理功能(access and mobility management function,AMF)网元:主要用于移动性管理和接入管理等,可以用于实现移动性管理实体(mobility management entity,MME)功能中除会话管理之外的其它功能,例如,接入授权/鉴权等功能。2. Access and mobility management function (AMF) network element: mainly used for mobility management and access management, etc., and can be used to implement mobility management entity (mobility management entity, MME) functions in addition to Other functions besides session management, such as access authorization/authentication and other functions.
3、会话管理功能(session management function,SMF)网元:主要用于会话管理、终端设备的互联网协议(internet protocol,IP)地址分配和管理、选择和管理用户平面功能、策略控制和收费功能接口的终结点以及下行数据通知等。3. Session management function (SMF) network element: mainly used for session management, Internet protocol (IP) address allocation and management of terminal devices, selection and management of user plane functions, policy control and charging function interfaces Endpoints and downstream data notifications, etc.
4、策略控制功能(policy control function,PCF)网元:用于指导网络行为的统一策略框架,为网络网元(例如AMF,SMF网元等)或终端设备提供策略规则信息等。4. Policy control function (PCF) network element: a unified policy framework used to guide network behavior, providing policy rule information for network network elements (such as AMF, SMF network elements, etc.) or terminal devices.
5、用户面功能(user plane function,UPF)网元:用于分组路由和转发以及用户面数据的服务质量(quality of service,QoS)处理等。用户数据可通过该网元接入到数据网络(data network,DN)。在本申请实施例中,可用于实现用户面网元的功能。5. User plane function (UPF) network element: used for packet routing and forwarding and quality of service (QoS) processing of user plane data. User data can be accessed to the data network (DN) through this network element. In the embodiment of this application, it can be used to implement the functions of user plane network elements.
6、应用功能(application function,AF)网元:用于进行应用影响的数据路由,接入网络开放功能网元,与策略框架交互进行策略控制等。6. Application function (AF) network element: used for data routing affected by applications, access to network open function network elements, and interaction with the policy framework for policy control, etc.
7、数据网络(data network,DN):用于提供传输数据的网络。例如,运营商业务的网络、因特(Internet)网、第三方的业务网络等。7. Data network (DN): used to provide a network for transmitting data. For example, the operator's business network, Internet network, third-party business network, etc.
8、网络数据分析功能(network data analytics function,NWDAF)网元:NWDAF可以具备以下至少一种功能:8. Network data analytics function (NWDAF) network element: NWDAF can have at least one of the following functions:
数据收集、模型训练、模型反馈、分析结果推理、分析结果反馈等。其中,数据收集功能可以指NWDAF收集来自网络网元、第三方服务器、终端设备或网管系统中的数据;模型训练功能可以指NWDAF基于相关输入数据做分析训练得到模型(例如,机器学习模型);模型反馈功能可以指NWDAF将训练好的机器学习模型发送给支持推理功能的网元;分析结果推理功能可以指NWDAF基于训练好的机器学习模型以及推理数据做推理确定数据分析结果;分析结果反馈功能可以指NWDAF向网络网元、第三方服务器、提供终端设备或网管系统提供数据分析结果,该数据分析结果可协助网络选择业务的服务质量参数,或协助网络执行流量路由,或协助网络选择背景流量传输策略等。Data collection, model training, model feedback, analysis result inference, analysis result feedback, etc. Among them, the data collection function can refer to NWDAF collecting data from network elements, third-party servers, terminal devices or network management systems; the model training function can refer to NWDAF analyzing and training based on relevant input data to obtain models (for example, machine learning models); The model feedback function can refer to NWDAF sending the trained machine learning model to the network element that supports the inference function; the analysis result inference function can refer to the NWDAF making inferences based on the trained machine learning model and inference data to determine the data analysis results; the analysis result feedback function It can refer to NWDAF providing data analysis results to network elements, third-party servers, terminal equipment or network management systems. The data analysis results can assist the network in selecting service quality parameters for the business, or assist the network in performing traffic routing, or assist the network in selecting background traffic. Transmission strategy, etc.
NWDAF的一个应用场景是:终端参数的定制或优化。即NWDAF通过收集用户的连接管理、移动性管理、会话管理、接入的业务等信息,利用可靠分析和预测模型,对不同类型用户进行评估和分析,构建用户画像,确定用户的移动轨迹和业务使用习惯,优化用户移动性管理参数和无线资源管理参数等。此外,NWDAF还可以根据构建的用户画像识别终端是否存在异常行为。One application scenario of NWDAF is the customization or optimization of terminal parameters. That is, NWDAF collects user information such as connection management, mobility management, session management, and accessed services, and uses reliable analysis and prediction models to evaluate and analyze different types of users, build user portraits, and determine the user's movement trajectory and services. Usage habits, optimize user mobility management parameters and wireless resource management parameters, etc. In addition, NWDAF can also identify whether the terminal has abnormal behavior based on the constructed user portrait.
在本申请的实施例中,NWDAF可以是一个单独的网元,也可以与其他网元合设。例如,NWDAF网元可以与AMF合设或者与SMF合设。In the embodiment of this application, the NWDAF may be a separate network element or may be co-located with other network elements. For example, NWDAF network elements can be co-located with AMF or co-located with SMF.
另外,上述网络架构还可以包括网络开放功能(network exposure function,NEF)网元。NEF用于安全地向外部开放由第三代合作伙伴计划(3GPP)网络功能提供的业务和能力等。应理解,以上列举的通信系统包括的网元仅仅为示例性说明,本申请并未限定于此。In addition, the above network architecture may also include network exposure function (NEF) network elements. NEF is used to securely open to the outside the services and capabilities provided by the 3rd Generation Partnership Project (3GPP) network functions. It should be understood that the network elements included in the communication system listed above are only exemplary illustrations, and the present application is not limited thereto.
在上述网络架构中,N2接口为RAN和AMF网元之间的接口,用于无线参数、非接入层(non-access stratum,NAS)信令的发送等;N3接口为RAN和UPF网元之间的接口,用于传输用户面的数据等;N4接口为SMF网元和UPF网元之间的接口,用于传输例如业务策略、N3连接的隧道标识信息,数据缓存指示信息,以及下行数据通知等信息。N6接口为DN和UPF网元之间的接口,用于传输用户面的数据。In the above network architecture, the N2 interface is the interface between RAN and AMF network elements and is used for sending wireless parameters, non-access stratum (NAS) signaling, etc.; the N3 interface is the interface between RAN and UPF network elements. The interface between them is used to transmit user plane data, etc.; the N4 interface is the interface between the SMF network element and the UPF network element, and is used to transmit business policies, tunnel identification information of the N3 connection, data cache indication information, and downlink Data notifications and other information. The N6 interface is the interface between the DN and UPF network elements and is used to transmit user plane data.
应理解,在上述网络架构中,网元之间可以通过服务化接口进行信息交互。例如,NWDAF可以通过其他网元(如AMF、SMF等)提供的服务化接口(如Namf、Nsmf等),从这些网元收集终端在网元上产生的数据;NWDAF还可以通过Nnwdaf接口向其他网元(如AMF、PCF等)提供数据分析结果、模型以及数据(data)等。It should be understood that in the above network architecture, network elements can interact with each other through service-oriented interfaces. For example, NWDAF can collect data generated by terminals on network elements through service-oriented interfaces (such as Namf, Nsmf, etc.) provided by other network elements (such as AMF, SMF, etc.); NWDAF can also use Nnwdaf interfaces to other network elements. Network elements (such as AMF, PCF, etc.) provide data analysis results, models, data, etc.
应理解,适用本申请实施例的网络架构并不局限于此,任何能够实现上述各个网元的功能的网络架构都适用于本申请实施例。It should be understood that the network architecture applicable to the embodiments of the present application is not limited to this, and any network architecture that can realize the functions of each of the above network elements is applicable to the embodiments of the present application.
需要说明的是,本申请中各个网元、接口的名称只是示例,本申请不排除以后各个网元为其它名称,以及各个网元之间的功能合并的情况。随着技术的演进,任何能够实现上述各个网元的功能的设备或者网元,都在本申请的保护范围之内。其次,上述网元也可以称为实体、设备、装置或模块等, 本申请并未特别限定。并且,在本申请中,为了便于理解和说明,在部分描述中省略“网元”这一描述,例如,将NWDAF网元简称NWDAF,此情况下,该“NWDAF”应理解为NWDAF网元,以下,省略对相同或相似情况的说明。It should be noted that the names of each network element and interface in this application are just examples. This application does not rule out the possibility that each network element will have other names in the future, and the functions between each network element will be merged. With the evolution of technology, any device or network element that can realize the functions of each of the above network elements is within the scope of protection of this application. Secondly, the above network elements can also be called entities, equipment, devices or modules, etc. This application is not particularly limited. Moreover, in this application, in order to facilitate understanding and explanation, the description of "network element" is omitted in some descriptions. For example, the NWDAF network element is referred to as NWDAF. In this case, the "NWDAF" should be understood as the NWDAF network element. In the following, description of the same or similar situations will be omitted.
NWDAF可以对终端设备在网络侧功能网元(例如,AMF、SMF等)上产生的数据进行分析,识别终端设备的行为是否异常,例如,识别终端设备是否频繁接入或注册。在现有的方案中,NWDAF主要识别终端设备的接入和注册信息是否合规,从而识别终端设备是否为异常终端设备。而在接入和注册信息都合规的情况下,终端设备还有可能对其他终端设备造成干扰,例如,向其他终端设备发起异常呼叫,如何识别出此类异常终端设备成为亟待解决的问题。NWDAF can analyze the data generated by the terminal device on the network-side functional network element (for example, AMF, SMF, etc.) and identify whether the behavior of the terminal device is abnormal, for example, identify whether the terminal device frequently accesses or registers. In the existing solution, NWDAF mainly identifies whether the access and registration information of the terminal device is compliant, thereby identifying whether the terminal device is an abnormal terminal device. When the access and registration information are compliant, the terminal device may also cause interference to other terminal devices, for example, by initiating abnormal calls to other terminal devices. How to identify such abnormal terminal devices has become an urgent problem to be solved.
有鉴于此,本申请提出了一种异常检测的方法,分析网元可以有效地识别出此类异常终端设备。In view of this, this application proposes an anomaly detection method, which can effectively identify such abnormal terminal equipment by analyzing network elements.
为了便于理解本申请实施例,做出以下几点说明。In order to facilitate understanding of the embodiments of the present application, the following points are explained.
第一,在本申请中示出的第一、第二以及各种数字编号(例如,“#1”、“#2”等)仅为描述方便,用于区分的对象,并不用来限制本申请实施例的范围。例如,区分不同的核心网网元等。而不是用于描述特定的顺序或先后次序。应该理解这样描述的对象在适当情况下可以互换,以便能够描述本申请的实施例以外的方案。First, the first, second and various numerical numbers (for example, "#1", "#2", etc.) shown in this application are only for convenience of description and are used to distinguish objects, and are not used to limit this application. Scope of Application Embodiments. For example, distinguish different core network elements, etc. It is not used to describe a specific order or sequence. It is to be understood that objects so described are interchangeable where appropriate to enable description of aspects other than the embodiments of the present application.
第二,本申请实施例中涉及的“预先设定”、“预先配置”等可以通过在设备(例如,网络设备)中预先保存相应的代码、表格或其他可用于指示相关信息的方式来实现,本申请对于其具体的实现方式不做限定,例如本申请实施例中预设的异常检测策略、预设的阈值等。Second, the "preset", "preconfiguration", etc. involved in the embodiments of this application can be realized by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device (for example, network device) , this application does not limit its specific implementation, such as the preset anomaly detection strategy, preset thresholds, etc. in the embodiments of this application.
第三,本文中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本文中字符“/”,一般表示前后关联对象是一种“或”的关系。Third, the term "and/or" in this article is only an association relationship describing related objects, indicating that there can be three relationships. For example, A and/or B can mean: A alone exists, and A and B exist simultaneously. , there are three situations of B alone. In addition, the character "/" in this article generally indicates that the related objects are an "or" relationship.
下文将结合附图详细说明本申请实施例提供的方法。本申请提供的实施例可以应用于上述图1所示的网络架构中,不作限定。The methods provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings. The embodiments provided in this application can be applied to the network architecture shown in Figure 1 above without limitation.
图2是本申请实施例提供的一种异常检测的方法200的示意图。方法200可以包括如下步骤。FIG. 2 is a schematic diagram of an anomaly detection method 200 provided by an embodiment of the present application. Method 200 may include the following steps.
S210,第一网元向第一分析网元发送第一信息,该第一信息包括与终端设备相关的SIP消息的信息。S210. The first network element sends first information to the first analysis network element, where the first information includes information about the SIP message related to the terminal device.
相应地,该第一分析网元接收来自第一网元的该第一信息。Correspondingly, the first analysis network element receives the first information from the first network element.
其中,该第一网元可以是用户面网元或应用功能网元,例如,该应用功能网元可以是代理呼叫控制功能网元(proxy CSCF,P-CSCF);该第一分析网元可以是会话管理网元。与终端设备相关的SIP消息可以理解为来自该终端设备的SIP消息和/或向该终端设备发送的SIP消息。The first network element may be a user plane network element or an application function network element. For example, the application function network element may be a proxy call control function network element (proxy CSCF, P-CSCF); the first analysis network element may be It is the session management network element. SIP messages related to the terminal device may be understood as SIP messages from the terminal device and/or SIP messages sent to the terminal device.
可以理解,在终端设备向其他终端设备(称为被叫终端是设备)发起呼叫的情况下,该终端设备发起用于呼叫的第一会话。该第一会话的数据由该第一网元传输,该第一会话的数据包括SIP消息,该SIP消息即为该终端设备发送的SIP消息。在其他终端设备向该终端设备发起呼叫的情况下,其他终端设备发起用于呼叫该终端设备的第二会话。该第一网元用于传输该第二会话的数据,该第二会话的数据包括SIP消息,该SIP消息可以是向该终端设备发送的SIP消息。It can be understood that when a terminal device initiates a call to another terminal device (called a called terminal device), the terminal device initiates a first session for the call. The data of the first session is transmitted by the first network element. The data of the first session includes a SIP message, and the SIP message is a SIP message sent by the terminal device. In the case where another terminal device initiates a call to the terminal device, the other terminal device initiates a second session for calling the terminal device. The first network element is used to transmit data of the second session. The data of the second session includes a SIP message. The SIP message may be a SIP message sent to the terminal device.
该SIP消息的信息包括以下信息中的至少一项:The information of this SIP message includes at least one of the following information:
(1)SIP消息的类型。(1) Type of SIP message.
示例性地,该SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息。For example, the types of the SIP messages include SIP INVITE messages, SIP CANCEL messages and SIP BYE messages.
通过SIP消息的类型可以确定该SIP消息对应的会话的类型,例如,SIP INVITE消息可以表示为发起呼叫而发起的会话,SIP BYE消息可以表示为挂断对端呼叫而发起的会话,SIP CANCEL消息可以表示为拒接对端呼叫而发起的会话。通过确定会话的类型可以确定终端设备发起呼叫或被呼叫、终端设备发起的呼叫被挂断以及终端设备发起的呼叫的被拒接。The type of session corresponding to the SIP message can be determined by the type of the SIP message. For example, the SIP INVITE message can represent a session initiated to initiate a call, the SIP BYE message can represent a session initiated to hang up the peer call, and the SIP CANCEL message Can represent a session initiated to reject a call from the peer. By determining the type of session, it can be determined whether the terminal device initiates a call or is called, the call initiated by the terminal device is hung up, and the call initiated by the terminal device is rejected.
(2)SIP消息的源地址。(2) The source address of the SIP message.
在该SIP消息为该终端设备发送的SIP消息的情况下,该SIP消息的源地址可以是该终端设备的地址,例如,互联网协议(internet protocol,IP)地址;在该SIP消息为向该终端设备发送的SIP消息的情况下,该SIP消息的源地址可以是该其他终端设备的地址,例如,IP地址。When the SIP message is a SIP message sent by the terminal device, the source address of the SIP message may be the address of the terminal device, for example, an Internet Protocol (IP) address; when the SIP message is sent to the terminal device In the case of a SIP message sent by a device, the source address of the SIP message may be the address of the other terminal device, for example, the IP address.
(3)SIP消息的目标地址。 (3) The destination address of the SIP message.
该SIP消息的目标地址可以是该应用功能网元的IP地址。The destination address of the SIP message may be the IP address of the application function network element.
(4)SIP消息的第一字段的信息。(4) Information in the first field of the SIP message.
该第一字段用于标识SIP消息的发送方所使用的设备。This first field is used to identify the device used by the sender of the SIP message.
一种情况下,终端设备由终端设备的身份标识和终端设备所使用的设备的标识共同标识。其中,该终端设备的身份标识可以包括终端设备的用户识别(subscriber identity module,SIM)卡的身份标识。例如,SIM卡的身份标识可以是用户永久标识符(subscriber permanent identifier,SUPI)、国际移动用户识别码(international mobile subscriber identity,IMSI)等。该终端设备所使用的设备的标识例如可以是永久设备标识(permanent equipment identifier,PEI)或国际移动设备标识(international mobile equipment identity,IMEI)。In one case, the terminal device is jointly identified by the identity of the terminal device and the identity of the device used by the terminal device. The identity of the terminal device may include the identity of a subscriber identity module (SIM) card of the terminal device. For example, the identity of the SIM card can be a subscriber permanent identifier (SUPI), an international mobile subscriber identity (IMSI), etc. The identifier of the device used by the terminal device may be, for example, a permanent equipment identifier (Permanent Equipment Identifier, PEI) or an International Mobile Equipment Identity (International Mobile Equipment Identity, IMEI).
(5)SIP消息的第二字段的信息。(5) Information in the second field of the SIP message.
该第二字段用于标识SIP消息的接收方设备,或者说,该第二字段指示SIP消息的接收方设备的标识。The second field is used to identify the recipient device of the SIP message, or in other words, the second field indicates the identity of the recipient device of the SIP message.
例如,该第二字段可以为SIP_Tel_Number字段,该第二字段标识SIP消息的接收方设备的电话号码。For example, the second field may be a SIP_Tel_Number field that identifies the telephone number of the recipient device of the SIP message.
(6)检测到SIP消息的时间信息。(6) The time information of the SIP message is detected.
该检测到SIP消息的时间信息例如可以是该第一网元检测到该SIP消息的时刻的信息。The time information of detecting the SIP message may be, for example, information of the time when the first network element detects the SIP message.
一种可能的实现方式中,该第一网元可以根据预设的上报规则向该第一分析网元发送该第一信息。例如,该上报规则可以是周期性上报、检测到与该终端设备相关的SIP消息即上报、检测到预设数量的与该终端设备相关的SIP消息上报等。In a possible implementation manner, the first network element may send the first information to the first analysis network element according to preset reporting rules. For example, the reporting rule may be periodic reporting, reporting upon detection of SIP messages related to the terminal device, reporting upon detection of a preset number of SIP messages related to the terminal device, etc.
可以理解,第一网元向第一分析网元发送的SIP消息可以包括一个或多个SIP消息的上述SIP消息的信息;或者,可以包括一个或多个SIP消息的上述SIP消息的信息中的部分信息。例如,该第一网元可以上报第一SIP消息的类型,该第一SIP消息的源地址、目标地址,检测到该第一SIP消息的时间的信息以及该第一SIP消息的第一字段、第二字段的信息;该第一网元可以上报第二SIP消息的类型,源地址以及检测到第二SIP消息的时间的信息。It can be understood that the SIP message sent by the first network element to the first analysis network element may include the information of the above-mentioned SIP message of one or more SIP messages; or may include the information of the above-mentioned SIP message of one or more SIP messages. partial information. For example, the first network element may report the type of the first SIP message, the source address and destination address of the first SIP message, information on the time when the first SIP message was detected, and the first field of the first SIP message. Information in the second field; the first network element can report information on the type of the second SIP message, the source address, and the time when the second SIP message was detected.
可选地,在该第一网元向该第一分析网元发送该第一信息之前,该方法还可以包括S220和S230:Optionally, before the first network element sends the first information to the first analysis network element, the method may also include S220 and S230:
S220,该第一网元接收来自该第一分析网元的指示信息,该指示信息指示根据第一数据包检测规则(packet detection rule,PDR)检测与该终端设备相关的SIP消息。S220: The first network element receives instruction information from the first analysis network element, and the instruction information instructs to detect SIP messages related to the terminal device according to a first packet detection rule (PDR).
相应地,该第一网元接收来自该第一分析网元的该第一信息。Correspondingly, the first network element receives the first information from the first analysis network element.
示例性地,该第一PDR包括可以包括以下至少一种规则:检测源地址为该终端设备的SIP消息;检测目标地址为该终端设备的SIP消息。Exemplarily, the first PDR may include at least one of the following rules: detecting SIP messages whose source address is the terminal device; detecting SIP messages whose target address is the terminal device.
可以理解,源地址或目标地址为该终端设备的SIP消息可以包括多种类型的SIP消息,例如,源地址为该终端设备的SIP INVITE消息,目标地址为该终端设备的SIP CANCEL消息、SIP BYE消息等。It can be understood that the SIP message whose source address or destination address is the terminal device can include multiple types of SIP messages. For example, the source address is the SIP INVITE message of the terminal device, and the destination address is the SIP CANCEL message or SIP BYE message of the terminal device. News etc.
S230,该第一网元根据该第一PDR检测与该终端设备相关的SIP消息,并确定该SIP消息的信息。S230: The first network element detects the SIP message related to the terminal device according to the first PDR, and determines the information of the SIP message.
示例性地,该第一网元接收到会话的数据后,可以确定该会话的数据的类型为SIP消息。该第一网元可以根据该第一PDR检测该SIP消息的源地址和/或目标地址;在检测到和该第一PDR相匹配的SIP消息后,该第一网元还可以确定该SIP消息的第一字段和/或第二字段的信息。进一步地,该第一网元还可以确定检测到该SIP消息的时间信息。For example, after receiving the session data, the first network element may determine that the type of the session data is a SIP message. The first network element can detect the source address and/or destination address of the SIP message based on the first PDR; after detecting the SIP message matching the first PDR, the first network element can also determine the SIP message information in the first field and/or the second field. Further, the first network element may also determine the time information at which the SIP message is detected.
可选地,S240,该第一网元还可以根据该SIP消息的信息确定SIP消息的统计信息。Optionally, S240, the first network element may also determine statistical information of the SIP message based on the information of the SIP message.
示例性地,该SIP消息的统计信息包括以下至少一项:类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长的信息;其中,该第一时长可以由第三SIP消息的时间信息以及第四SIP消息的时间信息确定,该第三SIP消息的源地址和该第四SIP消息的目标地址相同,该第三SIP消息的类型和该第四SIP消息的类型不同。Exemplarily, the statistical information of the SIP message includes at least one of the following: the total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type, the total number of SIP messages with the same destination address and the same type, the source address The number of SIP messages that are the same but have different first fields, and the information of the first duration; wherein the first duration can be determined by the time information of the third SIP message and the time information of the fourth SIP message, and the source of the third SIP message The address is the same as the target address of the fourth SIP message, and the type of the third SIP message is different from the type of the fourth SIP message.
可以理解,该SIP消息的统计信息是针对与该终端设备相关的多个SIP消息来说的。示例性地,该第一网元可以在预设的统计周期内确定该SIP消息的统计信息。It can be understood that the statistical information of the SIP message is for multiple SIP messages related to the terminal device. For example, the first network element may determine the statistical information of the SIP message within a preset statistical period.
例如,该第一网元可以启用第一计数器,该第一计数器用于统计类型相同的SIP消息的总数。当该第一网元根据该第一PDR检测到某一种类型的SIP消息时,例如,SIP INVITE消息,该第一网元确 定该第一计数器的计数加1,在该预设的统计周期内,该第一计数器的计数值可以表示该类型相同的SIP消息的总数。For example, the first network element may enable a first counter, which is used to count the total number of SIP messages of the same type. When the first network element detects a certain type of SIP message based on the first PDR, for example, a SIP INVITE message, the first network element determines The count value of the first counter is increased by 1. Within the preset statistical period, the count value of the first counter can represent the total number of SIP messages of the same type.
通过统计类型相同的SIP消息的总数可以确定终端设备通话的总次数,终端设备的通话的总次数包括终端设备发起呼叫的次数和向该终端设备发起呼叫的次数的总和。The total number of calls made by the terminal device can be determined by counting the total number of SIP messages of the same type. The total number of calls made by the terminal device includes the sum of the number of calls initiated by the terminal device and the number of calls initiated to the terminal device.
再如,该第一网元可以启用第二计数器,该第二计数器用于统计源地址相同且类型相同的SIP消息的总数。以该源地址为该终端设备的地址、SIP消息为SIP INVITE消息为例,该第一网元根据该第一PDR检测在预设的统计周期内检测源地址为该终端设备的地址的SIP INVITE消息,如果检测到该SIP INVITE消息,该第一网元确定该第二计数器的计数加1。该第二计数器的计数值可以表示该终端设备发起呼叫的总数。For another example, the first network element can enable a second counter, which is used to count the total number of SIP messages with the same source address and the same type. Taking the source address as the address of the terminal device and the SIP message as the SIP INVITE message as an example, the first network element detects the SIP INVITE whose source address is the address of the terminal device within a preset statistical period based on the first PDR detection. message, if the SIP INVITE message is detected, the first network element determines that the second counter is increased by 1. The count value of the second counter may represent the total number of calls initiated by the terminal device.
通过统计源地址相同的SIP INVITE消息可以确定终端设备发起呼叫的总次数、向终端设备发起呼叫的次数中的至少一种;通过统计目标地址相同的SIP BYE消息可以确定终端设备发起的呼叫被挂断的次数;通过统计目标地址相同的SIP CANCEL消息可以确定终端设备发起的呼叫被拒接的次数中的至少一种。By counting SIP INVITE messages with the same source address, at least one of the total number of calls initiated by the terminal device and the number of calls initiated to the terminal device can be determined; by counting SIP BYE messages with the same destination address, it can be determined that the call initiated by the terminal device has been hung up. The number of disconnections; by counting SIP CANCEL messages with the same destination address, at least one of the number of times calls initiated by the terminal device are rejected can be determined.
该第一网元还可以检测SIP消息的特定字段,例如,该第一字段。通过检测SIP消息的特定字段可以确定源地址相同且第一字段不同的SIP消息的数量。同样,该第一网元可以通过一个计数器统计预设的统计周期内源地址相同且第一字段不同的SIP消息的数量。The first network element may also detect a specific field of the SIP message, for example, the first field. The number of SIP messages with the same source address and different first fields can be determined by detecting specific fields of the SIP messages. Similarly, the first network element can use a counter to count the number of SIP messages with the same source address and different first fields within the preset statistical period.
通过检测源地址相同且第一字段不同的SIP消息的总数可以确定终端设备切换所使用的设备的标识的频率。The frequency with which the terminal device switches the identity of the device used can be determined by detecting the total number of SIP messages with the same source address and different first fields.
该第一网元还可以记录检测到SIP消息的时间信息,例如,记录检测到SIP消息的时刻。可选地,该第一网元还可以关联检测两个SIP消息的时间信息,确定第一时长的信息。例如,该两个SIP消息中的一个可以为源地址为该终端设备的地址的SIPINVITE消息,该两个SIP消息的中的另一个可以为目标地址为该终端设备的地址的SIP BYE消息或SIP CANCEL消息。The first network element may also record the time information when the SIP message is detected, for example, record the time when the SIP message is detected. Optionally, the first network element may also detect the time information of the two SIP messages in association with each other to determine the first duration information. For example, one of the two SIP messages may be a SIPINVITE message with the source address being the address of the terminal device, and the other of the two SIP messages may be a SIP BYE message or SIP message with the destination address being the address of the terminal device. CANCEL message.
通过确定检测到SIP消息的时间信息可以确定终端设备发起呼叫的时间信息、终端设备发起的呼叫被拒接或被挂断得时间信息。进一步地,关联两个SIP消息的时间信息可以确定该终端设备与至少一个被叫终端设备的通话时长(即该第一时长)。By determining the time information when the SIP message is detected, the time information when the terminal device initiates a call, and the time information when the call initiated by the terminal device is rejected or hung up can be determined. Further, correlating the time information of the two SIP messages can determine the call duration (ie, the first duration) between the terminal device and at least one called terminal device.
在该第一网元确定SIP消息的统计信息的情况下,该第一信息包括该SIP消息的统计信息。在此情况下,S240可以在S210之前执行。In the case where the first network element determines the statistical information of the SIP message, the first information includes the statistical information of the SIP message. In this case, S240 may be executed before S210.
可选地,S250,该第一分析网元根据SIP消息的信息确定SIP消息的统计信息。Optionally, S250, the first analysis network element determines the statistical information of the SIP message based on the information of the SIP message.
该第一分析网元根据SIP消息的信息确定SIP消息的统计信息和第一网元确定SIP消息的统计信息类似,参考S240的描述,不再赘述。The first analysis network element determines the statistical information of the SIP message based on the information of the SIP message, which is similar to the first network element determining the statistical information of the SIP message. Please refer to the description of S240, which will not be described again.
可以理解,若S240不执行,则第一网元可以向该第一分析网元发送与该终端设备相关的SIP消息的信息,该分析网元根据该与终端设备相关的SIP消息的信息确定该SIP消息的统计信息。It can be understood that if S240 is not executed, the first network element can send the information of the SIP message related to the terminal device to the first analysis network element, and the analysis network element determines the SIP message related to the terminal device based on the information. Statistics of SIP messages.
S260a,第一分析网元根据该SIP消息的统计信息确定该终端设备是否异常。S260a: The first analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
具体地,该第一分析网元可以根据异常检测策略和该SIP消息的统计信息确定该终端设备是否异常。Specifically, the first analysis network element may determine whether the terminal device is abnormal according to the anomaly detection policy and the statistical information of the SIP message.
该第一分析网元中可以预先配置用于检测终端设备是否异常的至少一个异常检测策略。该至少一个异常检测策略中的每个异常检测策略可以包括分析条目(或者,也可以称为分析参数,第一参数的一例)、分析参数对应的阈值。The first analysis network element may be pre-configured with at least one anomaly detection strategy for detecting whether the terminal device is abnormal. Each anomaly detection strategy in the at least one anomaly detection strategy may include an analysis entry (or may also be called an analysis parameter, an example of the first parameter) and a threshold corresponding to the analysis parameter.
可选地,该异常检测策略还可以包括每个异常检测策略对应的权重,该权重用于该第一分析网元关联多个异常检测策略判断终端设备是否存在异常。Optionally, the anomaly detection strategy may also include a weight corresponding to each anomaly detection strategy, and the weight is used by the first analysis network element to associate multiple anomaly detection strategies to determine whether there is an abnormality in the terminal device.
示例性地,根据异常检测策略判断终端设备是否异常可以理解为,判断该终端设备的分析条目的统计值与其对应的阈值的大小关系,如果该大小关系满足预期结果,则可以确定终端设备可能存在异常。其中,异常检测策略中分析条目统计值可以由SIP消息的统计信息确定。For example, judging whether the terminal device is abnormal according to the anomaly detection strategy can be understood as judging the size relationship between the statistical value of the analysis entry of the terminal device and its corresponding threshold. If the size relationship meets the expected result, it can be determined that the terminal device may exist abnormal. Among them, the statistical value of the analysis entry in the anomaly detection strategy can be determined by the statistical information of the SIP message.
分析条目(第一参数)可以包括以下参数中的至少一种:SIP BYE消息的总数占SIP INVITE消息的总数的比例,SIP CANCEL消息的总数占SIP INVITE消息的总数的比例,SIP INVITE消息的总数,检测到SIP消息的时间信息的离散度,所述第一时长的离散度。The analysis entry (first parameter) may include at least one of the following parameters: the ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, the total number of SIP INVITE messages , detecting the dispersion of the time information of the SIP message, the dispersion of the first duration.
可以理解,该第一分析网元可以接收来自第一网元的该SIP消息的统计信息,或者该第一分析网 元可以自行确定该SIP消息的统计信息。该第一分析网元可以确定SIP BYE消息、SIP CANCEL消息、或SIP INVITE消息的总数,从而该第一分析网元可以确定SIP BYE消息的总数占SIP INVITE消息的总数的比例,SIP CANCEL消息的总数占SIP INVITE消息的总数的比例,SIP INVITE消息的总数。该第一分析网元可以根据检测到SIP消息的时间信息确定检测到SIP消息的时间信息的离散度,并根据第一时长的信息确定第一时长的离散度。It can be understood that the first analysis network element can receive the statistical information of the SIP message from the first network element, or the first analysis network element can The user can determine the statistics of the SIP message by itself. The first analysis network element can determine the total number of SIP BYE messages, SIP CANCEL messages, or SIP INVITE messages, so that the first analysis network element can determine the proportion of the total number of SIP BYE messages to the total number of SIP INVITE messages. The ratio of the total number to the total number of SIP INVITE messages, the total number of SIP INVITE messages. The first analysis network element may determine the dispersion of the time information of the detected SIP message based on the time information of the detected SIP message, and determine the dispersion of the first duration based on the information of the first duration.
若第一分析网元根据SIP消息的统计信息确定第一参数的值与其对应的阈值满足预设的大小关系,则该第一分析网元可以确定该终端设备可能存在异常。If the first analysis network element determines that the value of the first parameter and its corresponding threshold satisfy the preset size relationship according to the statistical information of the SIP message, the first analysis network element can determine that the terminal device may be abnormal.
可选地,在第一分析网元确定该终端设备是否异常之前,该第一分析网元还可以向应用功能网元发送请求消息,该请求消息用于请求被叫终端设备的位置信息。Optionally, before the first analysis network element determines whether the terminal device is abnormal, the first analysis network element may also send a request message to the application function network element, where the request message is used to request the location information of the called terminal device.
相应地,该第一分析网元接收来自应用功能网元的被叫终端设备的位置信息。Correspondingly, the first analysis network element receives the location information of the called terminal device from the application function network element.
该请求消息可以携带被叫终端设备的标识。示例性地,该第一分析网元可以通过确定源地址为该终端设备的地址的SIP INVITE消息的该第二字段确定该对端终端设备的标识。应理解,该应用功能网元可以根据该被叫终端设备的标识确定该被叫终端设备的位置信息。The request message may carry the identity of the called terminal device. For example, the first analysis network element may determine the identity of the peer terminal device by determining the second field of the SIP INVITE message whose source address is the address of the terminal device. It should be understood that the application function network element can determine the location information of the called terminal device according to the identity of the called terminal device.
该第一分析网元可以根据该被叫终端设备的位置信息确定该终端设备呼叫目标地址的离散度。该分析条目可以包括终端设备呼叫目标地址的离散度。该第一分析网元可以通过确定终端设备呼叫目标地址的离散度与阈值的大小关系确定终端设备是否异常。The first analysis network element may determine the dispersion of the call target address of the terminal device based on the location information of the called terminal device. The analysis entry may include the dispersion of the terminal device's call destination address. The first analysis network element can determine whether the terminal device is abnormal by determining the relationship between the dispersion degree of the terminal device's call target address and the threshold value.
可选地,S270,该第一分析网元向第二分析网元发送该SIP消息的统计信息。Optionally, S270, the first analysis network element sends the statistical information of the SIP message to the second analysis network element.
相应地,该第二分析网元接收来自该第一分析网元的该SIP消息的统计信息。Correspondingly, the second analysis network element receives the statistical information of the SIP message from the first analysis network element.
S260b,该第二分析网元根据SIP消息的统计信息确定该终端设备是否异常。S260b: The second analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message.
该第二分析网元确定该终端设备是否异常的具体过程可以参考S260a中第一分析网元确定该终端设备是否异常的过程。The specific process of the second analysis network element determining whether the terminal device is abnormal may refer to the process of the first analysis network element determining whether the terminal device is abnormal in S260a.
也就是说,可以由第一网元确定与终端设备相关的SIP消息,并由第一网元根据该SIP消息的信息确定SIP消息的统计信息;该第一网元向分析网元发送该SIP消息的统计消息,以使分析网元根据该SIP消息的统计信息确定终端设备是否异常,该分析网元可以是会话管理网元或网络数据分析功能网元。在该分析网元为网络数据分析功能网元的情况下,该第一网元可以通过会话管理网元向该网络数据分析功能网元发送该SIP消息的统计信息。That is to say, the first network element can determine the SIP message related to the terminal device, and the first network element can determine the statistical information of the SIP message based on the information of the SIP message; the first network element sends the SIP message to the analysis network element The statistical information of the message is used to enable the analysis network element to determine whether the terminal device is abnormal based on the statistical information of the SIP message. The analysis network element can be a session management network element or a network data analysis function network element. When the analysis network element is a network data analysis function network element, the first network element can send the statistical information of the SIP message to the network data analysis function network element through the session management network element.
或者,由该第一网元确定与终端设备相关的SIP消息,并由该第一网元向分析网元发送该SIP消息的信息;该分析网元可以根据该SIP消息的信息确定SIP消息的统计信息;该分析网元根据该SIP消息的统计信息确定该终端设备是否异常。该分析网元可以是会话管理网元或网络数据分析功能网元。Alternatively, the first network element determines the SIP message related to the terminal device, and the first network element sends the information of the SIP message to the analysis network element; the analysis network element can determine the SIP message based on the information of the SIP message. Statistical information; the analysis network element determines whether the terminal device is abnormal based on the statistical information of the SIP message. The analysis network element may be a session management network element or a network data analysis function network element.
或者,由该第一网元确定与终端设备相关的SIP消息,并由该第一网元向第一分析网元发送该SIP消息的信息;该第一分析网元可以根据该SIP消息的信息确定SIP消息的统计信息;该第一分析网元可以向第二分析网元发送该SIP消息的统计信息,以使该第二分析网元确定该终端设备是否异常。该第一分析网元可以是会话管理网元;该第二分析网元可以是网络数据分析功能网元。Alternatively, the first network element determines the SIP message related to the terminal device, and the first network element sends the information of the SIP message to the first analysis network element; the first analysis network element can determine the SIP message based on the information of the SIP message. Determine the statistical information of the SIP message; the first analysis network element can send the statistical information of the SIP message to the second analysis network element, so that the second analysis network element determines whether the terminal device is abnormal. The first analysis network element may be a session management network element; the second analysis network element may be a network data analysis function network element.
基于上述方案,分析网元可以根据与终端设备的相关的SIP消息有效地识别出异常终端设备,避免对其他终端设备造成干扰。Based on the above solution, the analysis network element can effectively identify abnormal terminal equipment based on SIP messages related to the terminal equipment to avoid causing interference to other terminal equipment.
图3是本申请实施例提供的一种异常检测的方法300的示意图。方法300可以包括如下步骤。FIG. 3 is a schematic diagram of an anomaly detection method 300 provided by an embodiment of the present application. Method 300 may include the following steps.
S301,SMF开启UE的异常检测流程。S301, SMF starts the abnormality detection process of the UE.
SMF开启UE的异常检测可以理解为SMF开启后续的异常检测流程。SMF enabling the UE's anomaly detection can be understood as SMF enabling the subsequent anomaly detection process.
SMF的异常检测流程可以由运营商配置。示例性地,运营商可以针对网络中特定区域的一个或多个SMF配置异常检测流程,该一个或多个SMF包括该SMF。SMF's anomaly detection process can be configured by the operator. For example, the operator may configure an anomaly detection process for one or more SMFs in a specific area of the network, including the SMF.
该SMF中可以配置异常检测策略。例如,该多个异常检测策略如表1中所示,不同的异常检测策略可以通过策略ID标识。Anomaly detection policies can be configured in this SMF. For example, the multiple anomaly detection strategies are as shown in Table 1, and different anomaly detection strategies can be identified by policy IDs.
表1

Table 1

如表1中所示,以UE#1为例,其中,UE#1发起呼叫可以是UE#1向被叫UE发起呼叫,该被叫UE包括至少一个UE。As shown in Table 1, taking UE#1 as an example, the call initiated by UE#1 may be that UE#1 initiates a call to the called UE, and the called UE includes at least one UE.
UE#1发起的呼叫被拒接可以指UE#1发起的呼叫被该被叫UE拒接。The call initiated by UE#1 being rejected may mean that the call initiated by UE#1 is rejected by the called UE.
UE#1被呼叫可以是被叫UE向UE#1发起呼叫,该被叫UE包括至少一个UE。The called UE#1 may be a call initiated by the called UE to UE#1, and the called UE includes at least one UE.
UE#1发起的呼叫被挂断可以指UE#1发起的呼叫被该被叫UE挂断。The call initiated by UE#1 is hung up may mean that the call initiated by UE#1 is hung up by the called UE.
UE#1向被叫UE发起呼叫,则UE#1充当主叫,反之,UE#1充当被叫。When UE#1 initiates a call to the called UE, UE#1 acts as the calling party; otherwise, UE#1 acts as the called party.
UE#1充当主叫与UE#1充当被叫的比例可以理解为UE#1发起呼叫的次数与UE#1被呼叫的次数的比例。The ratio of UE#1 acting as the calling party and UE#1 acting as the called party can be understood as the ratio of the number of times UE#1 initiates calls to the number of times UE#1 is called.
UE#1可以向多个被叫UE发起不同次数的呼叫,例如,UE#1向被叫UE#2发起5次呼叫,向被叫UE#3发起7次呼叫,则UE#1平均向每被叫发起呼叫的次数为6。UE#1 can initiate different times of calls to multiple called UEs. For example, UE#1 initiates 5 calls to called UE#2 and 7 calls to called UE#3. Then UE#1 calls each of the called UEs on average. The number of calls initiated by the called party is 6.
UE#1切换的ME的离散度可以用UE切换的ME的标识的离散度表示。该ME的标识例如为IMEI。UE切换的ME的离散度可以指UE切换的ME对应的多个IMEI的跨度。The dispersion of MEs switched by UE#1 can be expressed by the dispersion of the identifiers of MEs switched by UE#1. The identifier of the ME is, for example, IMEI. The dispersion of MEs switched by the UE may refer to the span of multiple IMEIs corresponding to the MEs switched by the UE.
UE#1呼叫目标地区的离散度可以指UE#1向多个被叫UE发起呼叫时,该多个被叫UE区域位置的离散度。The dispersion degree of the calling target area of UE#1 may refer to the dispersion degree of the regional locations of the multiple called UEs when UE#1 initiates a call to the multiple called UEs.
UE#1通话时长离散度可以指UE#1与其他UE通话的时长的离散度,该其他UE可以为主叫UE,也可以为被叫UE。The dispersion of call duration of UE#1 may refer to the dispersion of call duration between UE#1 and other UEs. The other UEs may be the calling UE or the called UE.
UE#1可以在多个时刻向不同的被叫UE发起呼叫,UE#1发起呼叫的时间的离散度可以指该多个时刻的离散度。UE#1 may initiate calls to different called UEs at multiple times, and the dispersion of the time when UE#1 initiates the call may refer to the dispersion of the multiple times.
S302,UE#1向该SMF发送分组数据单元(protocol data unit,PDU)会话建立请求。S302, UE#1 sends a packet data unit (protocol data unit, PDU) session establishment request to the SMF.
相应地,该SMF接收来自该UE的PDU会话建立请求。Accordingly, the SMF receives the PDU session establishment request from the UE.
示例性地,该PDU会话建立请求为IP多媒体子系统(IP multimedia subsystem,IMS)类的PDU会话建立请求。Illustratively, the PDU session establishment request is an IP multimedia subsystem (IP multimedia subsystem, IMS) class PDU session establishment request.
该PDU会话建立请求消息携带请求携带用于标识请求的会话类型的标识字段,例如,该标识字段 可以是“数据网络名称类型(DNN type)”字段或者其他任意字段,该标识字段的内容可以是IMS。The PDU session establishment request message carries an identification field used to identify the requested session type. For example, the identification field It can be the "Data Network Name Type (DNN type)" field or any other field. The content of the identification field can be IMS.
该PDU会话建立请求还可以携带指示信息,该指示信息指示UE#1请求P-CSCF的地址,例如,IP地址。UE#1具体请求方式可参考TS 23.502 3.3.2节。The PDU session establishment request may also carry indication information, which indicates that UE#1 requests the address of the P-CSCF, for example, the IP address. For the specific request method of UE#1, please refer to TS 23.502 Section 3.3.2.
S303,SMF选择UPF。S303, SMF selects UPF.
SMF选择的该UPF用于传输UE#1的用户面数据。SMF具体如何选择UPF可以参考现有的相关描述。The UPF selected by the SMF is used to transmit user plane data of UE#1. For details on how to choose UPF for SMF, please refer to the existing relevant descriptions.
例如,该UPF可以将接收到的来自该UE#1的至少一个会话的数据包转发到该UPF内的目的UE,或者经过N6接口将该至少一个会话的数据包发送到网络侧设备,或者,也可以经过N19接口将该至少一个会话的数据包发送到其他UPF。同理,该UPF还可以将来自该UPF内的UE的至少一个会话的数据包,或者,来自网络侧设备的至少一个会话的数据包,或者,来自其他UPF的至少一个会话的数据包转发至该UE#1。For example, the UPF may forward the data packet of at least one session received from the UE#1 to the destination UE in the UPF, or send the data packet of the at least one session to the network side device through the N6 interface, or, The data packets of the at least one session may also be sent to other UPFs via the N19 interface. Similarly, the UPF can also forward data packets from at least one session of the UE in the UPF, or data packets of at least one session from the network side device, or data packets of at least one session from other UPFs to The UE#1.
S304,SMF向该UPF发送指示信息#1,该指示信息#1指示UPF统计并上报与UE#1相关的SIP消息的统计信息。S304: The SMF sends instruction information #1 to the UPF. The instruction information #1 instructs the UPF to count and report statistical information on SIP messages related to UE#1.
相应地,UPF接收来自该SMF的该指示信息#1。Correspondingly, UPF receives the indication information #1 from the SMF.
其中,与UE#1相关的SIP消息可以包括来自UE#1的SIP消息以及向UE#1发送的SIP消息。The SIP messages related to UE#1 may include SIP messages from UE#1 and SIP messages sent to UE#1.
例如,当UE#1向UE#2发起用于呼叫UE#2的会话#1时,UE#1通过该UPF向UE#2发送会话#1的SIP消息#1;响应于该SIP消息#1,UE#2可以向UE#1发送SIP消息#2。与UE#1相关的SIP消息可以包括该SIP消息#1和SIP消息#2。For example, when UE#1 initiates session #1 for calling UE#2 to UE#2, UE#1 sends SIP message #1 of session #1 to UE#2 through the UPF; in response to the SIP message #1 , UE#2 can send SIP message #2 to UE#1. The SIP message related to UE#1 may include the SIP message #1 and SIP message #2.
该指示信息#1可以携带数据包检测规则PDR#1,该PDR#1用于匹配或者说检测与UE#1相关的SIP消息的数据包。The indication information #1 may carry the data packet detection rule PDR#1, which is used to match or detect the data packets of the SIP message related to UE#1.
示例性地,该PDR#1的规则可以包括:令UPF识别目标地址和/或源地址为特定IP地址的数据包,例如,源地址为UE#1的IP地址(记为IPUE#1)、目标地址为P-CSCF的IP地址(记为IPP-CSCF)的数据包;或者,源地址为对端UE的IP地址、目标地址为P-CSCF的IP地址的数据包。For example, the rules of PDR#1 may include: causing UPF to identify data packets whose destination address and/or source address are specific IP addresses, for example, the source address is the IP address of UE#1 (denoted as IPUE#1), A data packet whose destination address is the IP address of P-CSCF (recorded as IPP-CSCF); or a data packet whose source address is the IP address of the opposite end UE and whose destination address is the IP address of P-CSCF.
该PDR#1的规则还可以包括:令UPF识别特定类型的数据包。例如识别类型为SIP消息的数据包。进一步地,该PDR#1的规则还包括识别控制字段包括“INVITE”、“BYE”或“CANCEL”的SIP消息。其中,控制字段包括“INVITE”的SIP消息也可以称为SIP INVITE消息,同理,控制字段包括“BYE”或“CANCEL”的SIP消息也可以称为SIP BYE消息、SIP CANCEL消息。The rules of PDR#1 may also include: causing UPF to identify specific types of data packets. For example, identify data packets of type SIP message. Further, the rules of PDR#1 also include identifying SIP messages whose control fields include "INVITE", "BYE" or "CANCEL". Among them, the SIP message whose control field includes "INVITE" can also be called SIP INVITE message. Similarly, the SIP message whose control field includes "BYE" or "CANCEL" can also be called SIP BYE message or SIP CANCEL message.
该PDR#1还可以包括UPF上报与UE#1相关的SIP消息的统计信息的上报规则,例如,周期上报、统计信息的条目超过预设阈值上报、每次统计信息更新后上报等。The PDR#1 may also include reporting rules for UPF to report statistical information of SIP messages related to UE#1, for example, periodic reporting, reporting of statistical information entries exceeding a preset threshold, reporting after each statistical information update, etc.
UPF收到一个数据包后,将数据包头各字段与PDR内定义的参数项进行匹配,检测与UE#1相关的SIP消息。After UPF receives a data packet, it matches each field of the data packet header with the parameter items defined in the PDR, and detects the SIP message related to UE#1.
S305,UPF#1根据该指示信息#1开始统计UE#1的SIP消息。S305: UPF#1 starts counting SIP messages of UE#1 based on the indication information #1.
或者说,UPF#1根据该指示信息开始确定UE#1的SIP消息的统计信息。In other words, UPF#1 starts to determine the statistical information of the SIP message of UE#1 based on the indication information.
S306,SMF向UE#1发送P-CSCF的地址。S306: The SMF sends the address of the P-CSCF to UE#1.
SMF向UE#1发送P-CSCF的地址,即PDU会话建立成功。SMF sends the P-CSCF address to UE#1, that is, the PDU session is successfully established.
可以理解,S306可以在S305之前或之后执行。S306可以理解为对S302的响应。It can be understood that S306 can be executed before or after S305. S306 can be understood as a response to S302.
即,SMF在收到UE#1的PDU会话建立请求后,根据预配置开启异常检测流程,该异常检测流程包括S304。在S304之后,UPF开启与UE#1相关的SIP消息的统计。That is, after receiving the PDU session establishment request of UE#1, the SMF starts an abnormality detection process according to the preconfiguration, and the abnormality detection process includes S304. After S304, UPF starts statistics of SIP messages related to UE#1.
其中,UPF可统计的UE#1的SIP消息可以来自UE#1发起的通话,例如,mobile original call,也可以称为主叫通话、MO呼叫或MO通话,以及来自网络侧发起的通话,例如,mobile terminatedcall,也可以称为被叫呼叫、MT呼叫或MT通话。Among them, the SIP messages of UE#1 that can be counted by UPF can come from calls initiated by UE#1, such as mobile original calls, which can also be called calling calls, MO calls or MO calls, and calls initiated from the network side, such as , mobile terminated call, can also be called called call, MT call or MT call.
以下分别介绍UPF统计该两种呼叫中与UE#1相关的SIP消息。The UPF statistics of SIP messages related to UE#1 in these two calls are introduced below.
需要说明的是,本申请并不限定以上两种通话发生的次数以及先后顺序。例如,UPF可能在统计时间段内仅接收到UE#1发起MO呼叫的SIP消息,而无MT呼叫的SIP消息;或者UPF在统计时间段内仅收到MT呼叫的SIP消息,而无UE#1发起的MO呼叫的SIP消息;或者,UPF可能在接收到一次或多次UE#1发起呼叫的SIP消息之后,接收到一个或多个MT呼叫的SIP消息;或者,UPF可能在接收到一个或多个MT呼叫的SIP消息之后,接收到一次或多次UE#1发起呼叫的SIP消息。 It should be noted that this application does not limit the number and sequence of the above two calls. For example, UPF may only receive SIP messages for MO calls initiated by UE#1 during the statistical time period, but no SIP messages for MT calls; or UPF may only receive SIP messages for MT calls during the statistical time period, but no SIP messages for UE#. SIP messages for MO calls initiated by UE#1; alternatively, UPF may receive one or more SIP messages for MT calls after receiving one or more SIP messages for calls initiated by UE#1; alternatively, UPF may receive one or more SIP messages for MT calls initiated by UE#1. After one or more SIP messages for the MT call, one or more SIP messages for the call initiated by UE#1 are received.
UPF确定MT呼叫的SIP消息的统计信息可以参考S307和S308。For the statistical information of the SIP messages used by the UPF to determine the MT call, please refer to S307 and S308.
S307,UPF根据PDR#1检测第一数据包。S307, UPF detects the first data packet according to PDR#1.
该第一数据包包括数据包#1,数据包#1为网络侧发起MT呼叫的数据包。数据包#1的类型为SIP消息;数据包#1的控制字段包括“INVITE”;数据包#1的源地址为IPP-CSCF,数据包#1的目标地址为IPUE#1。The first data packet includes data packet #1, and data packet #1 is a data packet used by the network side to initiate an MT call. The type of data packet #1 is a SIP message; the control field of data packet #1 includes "INVITE"; the source address of data packet #1 is IPP-CSCF, and the destination address of data packet #1 is IPUE#1.
若UPF根据PDR#1检测到数据包#1,S308,UPF更新信息#1,该信息#1包括MT呼叫的SIP消息的统计信息。If UPF detects data packet #1 based on PDR#1, S308, UPF updates information #1, which information #1 includes statistical information of the SIP message of the MT call.
具体地,若UPF检测到一个数据包#1,则UPF更新计数器#1的计数。该计数器#1用于统计向UE#1发起呼叫的次数。该MT呼叫的SIP消息的统计信息可以包括计数器#1的计数。换言之,UPF更新计数器#1的计数即UPF更新信息#1。Specifically, if UPF detects a data packet #1, UPF updates the count of counter #1. The counter #1 is used to count the number of calls initiated to UE#1. The statistical information of the SIP messages of the MT call may include the count of counter #1. In other words, the count of UPF update counter #1 is UPF update information #1.
可选地,若UPF检测到该数据包#1,UPF更新计数器#2的计数。该计数器#2用于统计UE#1的通话的总次数。UE#1通话的总次数包括网络侧向UE#1发起呼叫的次数与UE#1发起呼叫的次数的总和。该MT呼叫的SIP消息的统计信息还可以包括计数器#2的计数。换言之,UPF更新计数器#2的计数即UPF更新信息#1。Optionally, if UPF detects the data packet #1, UPF updates the count of counter #2. The counter #2 is used to count the total number of calls made by UE#1. The total number of calls made by UE#1 includes the sum of the number of times the network side initiates calls to UE#1 and the number of times UE#1 initiates calls. The statistical information of the SIP message of the MT call may also include the count of counter #2. In other words, the count of UPF update counter #2 is UPF update information #1.
举例来说,UE#1的SIP消息的统计信息可以如表2中所示。For example, the statistical information of the SIP message of UE#1 may be as shown in Table 2.
表2
Table 2
UPF确定MO呼叫的SIP消息的统计信息可以参考S309和S310。For the statistical information of the SIP messages used by UPF to determine the MO call, please refer to S309 and S310.
S309,UPF根据PDR#1检测第二数据包。S309, UPF detects the second data packet based on PDR#1.
该第二数据包包括数据包#2,数据包#2为UE#1发起MO呼叫的数据包。数据包#2的内容类型为SIP消息;数据包#2的控制字段包括“INVITE”,源地址为IPUE#1,目标地址为IPP-CSCF。The second data packet includes data packet #2, and data packet #2 is a data packet for UE#1 to initiate an MO call. The content type of packet #2 is a SIP message; the control field of packet #2 includes "INVITE", the source address is IPUE#1, and the destination address is IPP-CSCF.
若UPF根据PDR#1检测到数据包#2,S310,UPF更新信息#1,该信息#1包括MO呼叫的SIP消息的统计信息。If UPF detects data packet #2 based on PDR#1, S310, UPF updates information #1, which information #1 includes statistical information of the SIP message of the MO call.
具体地,若UPF检测到一个数据包#2,则UPF更新计数器#3的计数。该计数器#3用于统计UE#1发起呼叫的次数。该MO呼叫的SIP消息的统计信息可以包括计数器#3的计数。Specifically, if UPF detects a packet #2, UPF updates the count of counter #3. The counter #3 is used to count the number of calls initiated by UE#1. The statistics of the SIP messages of the MO call may include the count of counter #3.
举例来说,UPF检测到该数据包#2后,更新后的UE#1的SIP消息的统计信息可以如表3所示。For example, after the UPF detects the data packet #2, the updated statistical information of the SIP message of UE#1 can be as shown in Table 3.
表3
table 3
可选地,若UPF检测到一个该数据包#2,UPF更新该计数器#2的计数。即,UPF更新UE#1通话的总次数。Optionally, if UPF detects a data packet #2, UPF updates the count of counter #2. That is, UPF updates the total number of calls made by UE#1.
UPF检测到该一个数据包#2后,还可以确定数据包#2的字段#1的信息,字段#2的信息中的至少一种。After UPF detects the data packet #2, it can also determine at least one of the information of field #1 and the information of field #2 of data packet #2.
其中,字段#1用于标识数据包#2发送方所使用的设备,在该数据包的源地址为UE#1的地址的情况下,该字段#1可以表示UE#1所使用的设备。例如,字段#1携带UE#1设备的IMEI。字段#2用于标识数据包#2接收方设备,例如,该数据包#2为UE#1向UE#2发起呼叫的数据包,该字段#2可以携带UE#2的电话号码,字段#2可以为SIP_Tel_Number字段。Field #1 is used to identify the device used by the sender of data packet #2. When the source address of the data packet is the address of UE#1, field #1 may indicate the device used by UE#1. For example, field #1 carries the IMEI of the UE#1 device. Field #2 is used to identify the receiving device of data packet #2. For example, this data packet #2 is a data packet for UE#1 to initiate a call to UE#2. This field #2 can carry the phone number of UE#2. Field #2 2 can be the SIP_Tel_Number field.
UPF可以统计多个数据包#2的该字段#1和/或字段#2的信息,该UE#1的SIP消息的统计信息包括该多个数据包#2的该字段#1和/或字段#2的信息。该多个数据包#2可以理解为UE#1发起的多次呼 叫的数据包,该多个数据包#2可以是UE#1向一个UE发起多次呼叫的数据包,也可以是UE#1向多个不同UE发起呼叫的数据包。UPF can count the information of field #1 and/or field #2 of multiple data packets #2, and the statistical information of the SIP message of UE#1 includes the information of field #1 and/or field of multiple data packets #2. #2 information. The multiple data packets #2 can be understood as multiple calls initiated by UE#1. The multiple data packets #2 may be data packets in which UE#1 initiates multiple calls to one UE, or may be data packets in which UE#1 initiates calls to multiple different UEs.
UPF检测到该数据包#2后,还可以记录检测到该数据包#2的时刻#1的信息。该UE#1的SIP消息的统计信息包括该时刻#1的信息。例如,该数据包#2为UE#1向UE#2发起呼叫的SIP消息,该UE#1的SIP消息的统计信息可以如表4中所示。After UPF detects the data packet #2, it can also record the information of time #1 when the data packet #2 is detected. The statistical information of the SIP message of UE#1 includes the information of time #1. For example, the data packet #2 is a SIP message in which UE#1 initiates a call to UE#2. The statistical information of the SIP message of UE#1 can be as shown in Table 4.
表4
Table 4
可选地,UPF还可以检测数据包#3(第二数据包的一例),该数据包#3可以是与该数据包#2相对应的数据包。或者说,该数据包#3为UE#1发起呼叫的对端UE(被叫UE)对UE#1发起的呼叫作出响应的数据包。该数据包#3的目标地址为该IPUE#1,源地址为IPP-CSCF,类型为SIP消息,内容为“BYE”。Optionally, UPF may also detect data packet #3 (an example of the second data packet), which may be a data packet corresponding to data packet #2. In other words, the data packet #3 is a data packet in which the opposite end UE (called UE) of the call initiated by UE#1 responds to the call initiated by UE#1. The destination address of packet #3 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the content is "BYE".
若UPF检测到该数据包#3,则UPF更新计数器#4的计时,该计数器#4用于统计UE#1发起的呼叫被接通的次数。该UE#1的SIP消息的统计信息包括该计数器#4的计数值。If the UPF detects the data packet #3, the UPF updates the timing of the counter #4. The counter #4 is used to count the number of times the call initiated by UE#1 is connected. The statistical information of the SIP message of UE#1 includes the count value of counter#4.
可选地,UPF还可以记录检测到数据包#3的时刻#2的信息。UPF可以关联数据包#2的时刻#1确定时刻#1和时刻#2之间的时长。该时长可以表示UE#1与被叫UE通话的时长。Optionally, UPF can also record information about time #2 when packet #3 is detected. The UPF may correlate time #1 of packet #2 to determine the length of time between time #1 and time #2. This duration may represent the duration of the conversation between UE#1 and the called UE.
例如,数据包#2为UE#1向UE#2发起呼叫的数据包,当UPF检测到数据包#2时,UPF可以记录UE#2的标识(例如,电话号码),以及检测到数据包#2的时刻#1;当UPF检测到数据包#3时,UPF可以关联数据包#3的发送方设备的标识确定该数据包#3是否为该UE#2发送的用于对该数据包#2作出响应的数据包,如果是,UPF可以记录检测到该数据包#3的时刻#2;该时刻#1和时刻#2之间的时长即为UE#1与UE#2通话的时长。For example, data packet #2 is a data packet for UE#1 to initiate a call to UE#2. When UPF detects data packet #2, UPF can record the identity of UE#2 (for example, phone number) and the detected data packet. Moment #1 of #2; when UPF detects data packet #3, UPF can associate the identity of the sender device of data packet #3 to determine whether data packet #3 is sent by UE#2 for this data packet. #2 responds to the data packet, if so, UPF can record the time #2 when the data packet #3 is detected; the time between time #1 and time #2 is the length of the call between UE#1 and UE#2 .
该UE#1的SIP消息的统计信息可以如表5中所示。The statistical information of the SIP message of UE#1 may be as shown in Table 5.
表5
table 5
可选地,UPF还可以检测数据包#4(第二数据包的一例),该数据包#4可以是与该数据包#2相对应的数据包。或者说,该数据包#4为UE#1发起呼叫的对端UE(被叫UE)对UE#1发起的呼叫作出响应的数据包。该数据包#4的目标地址为该IPUE#1,源地址为IPP-CSCF,类型为SIP消息,内容为“CANCEL”。Optionally, UPF may also detect data packet #4 (an example of the second data packet), which may be a data packet corresponding to data packet #2. In other words, the data packet #4 is a data packet in which the opposite end UE (the called UE) of the call initiated by UE#1 responds to the call initiated by UE#1. The destination address of packet #4 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the content is "CANCEL".
若UPF检测到该数据包#4,则UPF更新计数器#5的计时,该计时器#5用于统计UE#1发起的呼叫被拒接的次数。If UPF detects data packet #4, UPF updates the timing of counter #5. This timer #5 is used to count the number of times calls initiated by UE #1 are rejected.
例如,UE#3向UE#1发送SIP CANCEL消息,该UE#1的SIP消息的统计信息可以如表6中所示。For example, UE#3 sends a SIP CANCEL message to UE#1, and the statistical information of the SIP message of UE#1 can be as shown in Table 6.
表6

Table 6

需要说明的是,UPF统计MT呼叫的SIP消息和UPF统计MO呼叫的SIP消息可以是在同一个统计周期内,或者,UPF统计MT呼叫的SIP消息的周期可以大于等于UPF统计MO呼叫的SIP消息的周期。It should be noted that the SIP messages for UPF statistics on MT calls and the SIP messages for UPF statistics for MO calls can be within the same statistical period, or the period of the SIP messages for UPF statistics on MT calls can be greater than or equal to the SIP messages for UPF statistics on MO calls. cycle.
S311,UPF向SMF发送UE#1的SIP消息的统计信息。S311. The UPF sends the statistical information of the SIP message of UE#1 to the SMF.
相应地,SMF接收来自UPF的UE#1的SIP消息的统计信息。Correspondingly, the SMF receives the statistical information of the SIP messages of UE#1 from the UPF.
该SIP消息的统计信息可以包括计数器#1至计数器#5中至少一个计数器的计数。该SIP消息的统计信息还可以包括检测到SIP消息的时间信息、通话时长信息。The statistical information of the SIP message may include the count of at least one counter among counter #1 to counter #5. The statistical information of the SIP message may also include the time information of detecting the SIP message and the call length information.
S312,SMF向NWDAF发送该UE#1的SIP消息的统计信息。S312: The SMF sends the statistical information of the SIP message of the UE#1 to the NWDAF.
相应地,NWDAF接收来自SMF的UE#1的SIP消息的统计信息。Accordingly, the NWDAF receives the statistical information of the SIP messages of UE#1 from the SMF.
可选地,在SMF向NWDAF发送UE#1的SIP消息的统计信息之前,SMF还可以向P-CSCF发送请求消息#1,请求消息#1用于请求UE#1呼叫对端UE的位置信息。Optionally, before the SMF sends the statistical information of UE#1's SIP messages to the NWDAF, the SMF can also send a request message #1 to the P-CSCF. The request message #1 is used to request the location information of the UE#1 calling the opposite end UE. .
相应地,P-CSCF接收来自SMF的该请求消息#1。该请求消息#1可以携带对端UE的标识,例如,电话号码。Correspondingly, the P-CSCF receives the request message #1 from the SMF. The request message #1 may carry the identity of the peer UE, for example, a phone number.
可选地,P-CSCF向SMF发送对端UE的位置信息。Optionally, the P-CSCF sends the location information of the opposite end UE to the SMF.
相应地,SMF接收来自该P-CSCF的对端UE的位置信息。Correspondingly, the SMF receives the location information of the opposite end UE from the P-CSCF.
例如,该位置信息例如可以是UE#1呼叫对端UE的位置区域代码(location area code,LAC)、跟踪区标识(tracing area identifier,TAI)、小区标识(cell ID)、地理区域标识(geographical area identifier,GAI)、网络码(network code,NC)、国家码(country code,CC)、城市码(city code)、县码(county code)等。For example, the location information may be a location area code (LAC), a tracking area identifier (TAI), a cell ID (cell ID), and a geographic area identifier (LAC) of the peer UE called by UE#1. area identifier (GAI), network code (NC), country code (CC), city code (city code), county code (county code), etc.
可以理解,SMF向NWDAF发送UE#1的SIP消息的统计信息中,还可以包括UE#1呼叫对端UE的位置信息。It can be understood that the statistical information of the SIP message of UE#1 sent by the SMF to the NWDAF may also include the location information of the peer UE called by UE#1.
S313,NWDAF确定UE#1是否存在异常。S313, NWDAF determines whether there is an abnormality in UE#1.
具体地,NWDAF根据异常检测策略以及UE#1的SIP消息的统计信息确定UE#1是否异常。该异常检测策略可以参考S260a中的描述。Specifically, NWDAF determines whether UE#1 is abnormal based on the abnormality detection policy and the statistical information of the SIP message of UE#1. For this anomaly detection strategy, please refer to the description in S260a.
其中,异常检测策略的分析条目的值可以根据UE#1的SIP消息的统计信息确定。The value of the analysis entry of the anomaly detection policy may be determined based on the statistical information of the SIP message of UE#1.
示例性地,UE#1发起呼叫的次数可以根据计数器#3的计数值确定,如果NWDAF确定计数器#3的计数值大于阈值T1,则NWDAF可以确定UE#1可能存在异常。For example, the number of calls initiated by UE#1 may be determined based on the count value of counter #3. If the NWDAF determines that the count value of counter #3 is greater than the threshold T1, the NWDAF may determine that there may be an abnormality in UE#1.
UE#1发起的呼叫被拒接的次数可以通过计数器#5的计数确定,如果NWDAF确定计数器#5的计数值大于T2,则NWDAF可以确定UE#1可能存在异常。The number of times calls initiated by UE#1 are rejected can be determined by counting counter #5. If NWDAF determines that the count value of counter #5 is greater than T2, NWDAF can determine that UE#1 may be abnormal.
类似地,UE#1被呼叫的次数可以通过计数器#1的计数确定;UE#1发起的呼叫被接通的次数可以通过计数器#3的计数确定;UE#1发起的呼叫被拒接的次数与UE#1总通话次数的比例可以关联计数器#5和计数器#2的计数值确定;UE#1发起的呼叫被接通的次数与UE#1总通话次数的比例可以关联计数器#3和计数器#2的计数值确定;UE充当主叫与UE充当被叫的比例可以关联计数器#1和技术器#3的计数值确定;UE平均向每个被叫UE发起呼叫的次数可以计数器#3的计数值以及SIP消息的字段#2的信息确定。Similarly, the number of times UE#1 is called can be determined by the counting of counter #1; the number of times calls initiated by UE#1 are connected can be determined by the counting of counter #3; the number of times calls initiated by UE#1 are rejected The ratio of the total number of calls to UE#1 can be determined by correlating the count values of counter #5 and counter #2; the ratio of the number of times calls initiated by UE#1 are connected to the total number of calls to UE#1 can be determined by correlating counters #3 and counters The count value of #2 is determined; the ratio of UE acting as the calling party to the UE acting as the called party can be determined by correlating the counting values of counter #1 and technical device #3; the average number of times the UE initiates calls to each called UE can be determined by the counting value of counter #3 The count value is determined along with the information in Field #2 of the SIP message.
UE#1切换的移动设备(mobile euipment,ME)的离散度可以通过SIP消息的字段#1的信息确定,该字段#1携带UE#1使用的设备的标识,例如,IMEI。UE#1切换的ME的离散度可以理解为UE#1切换的多个IMEI的离散度,该多个IMEI的离散度可以通过IMEI的内容确定,例如,如果多个IMEI的内容连续,则可以认为IMEI的离散度较小;如果IMEI的内容随机且无规律,则可以认为多IMEI的离散度较大。The dispersion of mobile equipment (ME) switched by UE#1 can be determined by the information of field #1 of the SIP message. This field #1 carries the identification of the device used by UE#1, for example, IMEI. The dispersion of the ME switched by UE#1 can be understood as the dispersion of multiple IMEIs switched by UE#1. The dispersion of the multiple IMEIs can be determined by the contents of the IMEI. For example, if the contents of the multiple IMEIs are continuous, then It is considered that the dispersion of IMEI is small; if the content of IMEI is random and irregular, it can be considered that the dispersion of multiple IMEIs is large.
UE#1呼叫目标地区的离散度可以通过UE#1呼叫对端UE的位置信息确定;UE#1通话时长的离散度可以通过UE#1的通话时长信息确定;UE#1发起呼叫的时间的离散度可以通过UE#1发送SIP消 息的时间信息确定。The dispersion of the target area called by UE#1 can be determined by the location information of the opposite UE called by UE#1; the dispersion of the call duration of UE#1 can be determined by the call duration information of UE#1; the time when UE#1 initiates the call Dispersion can send SIP messages through UE#1 The time information of the message is determined.
需要说明的是,NWDAF可以通过异常检测策略中的一个或多个分析参数确定UE#1是否异常,当NWDAF根据异常检测策略中的一个分析参数确定UE#1是否存在异常时,NWDAF可以通过UE#1的SIP消息的统计信息与阈值的大小关系确定UE#1是否存在异常。当NWDAF通过异常检测策略中的多个分析参数确定UE#1是否异常时,NWDAF可以根据UE#1的SIP消息的统计信息与阈值的大小关系,以及每个分析参数对应的权重确定UE#1是否存在异常。It should be noted that NWDAF can determine whether UE#1 is abnormal through one or more analysis parameters in the anomaly detection strategy. When NWDAF determines whether UE#1 is abnormal based on one analysis parameter in the anomaly detection strategy, NWDAF can determine whether UE#1 is abnormal through The relationship between the statistical information of the SIP message of #1 and the threshold determines whether there is an abnormality in UE#1. When NWDAF determines whether UE#1 is abnormal through multiple analysis parameters in the anomaly detection strategy, NWDAF can determine UE#1 based on the relationship between the statistical information of UE#1's SIP messages and the threshold, and the weight corresponding to each analysis parameter. Is there any exception?
示例性地,NWDAF可以配置UE存在异常的总权重为W,当UE当前的总权重Wt大于等于W时,NWDAF确定UE存在异常。例如,NWDAF结合该异常检测策略#1(策略ID为“1”)和异常检测策略#2确定UE#1是否存在异常。若UE#1发起呼叫的次数大于阈值T1,则Wt=W1;在UE#1发起呼叫的次数大于T1的同时,若UE#1发起的呼叫被拒接的次数大于T2,则Wt=W1+W2;若Wt大于等于W,则NWDAF可以确定UE#1存在异常。For example, the NWDAF may configure the total weight of the UE to be abnormal as W. When the current total weight of the UE Wt is greater than or equal to W, the NWDAF determines that the UE is abnormal. For example, NWDAF combines the anomaly detection policy #1 (policy ID is "1") and the anomaly detection policy #2 to determine whether there is an abnormality in UE#1. If the number of times UE#1 initiates calls is greater than the threshold T1, then Wt=W1; while the number of times UE#1 initiates calls is greater than T1, if the number of times UE#1 initiates calls is rejected is greater than T2, then Wt=W1+ W2; If Wt is greater than or equal to W, NWDAF can determine that UE#1 is abnormal.
可以理解,NWDAF可以在预设时长内接收多个UE的SIP消息的统计信息,并根据该多个UE的SIP消息的统计信息确定该多个UE是否异常。It can be understood that the NWDAF can receive statistical information of SIP messages of multiple UEs within a preset time period, and determine whether the multiple UEs are abnormal based on the statistical information of SIP messages of the multiple UEs.
在确定该多个UE异常后,可选地,NWDAF还可以通过该多个UE的位置信息确定异常接入地址。After determining that the multiple UEs are abnormal, optionally, the NWDAF may also determine the abnormal access address through the location information of the multiple UEs.
例如,该多个UE中部分UE的位置信息相同,为地址#1,则NWDAF可以确定地址#1为异常接入地址。通过关联所有异常UE可以判断异常接入地址是否有集群异常呼叫系统。For example, if the location information of some UEs among the multiple UEs is the same, which is address #1, then NWDAF may determine that address #1 is the abnormal access address. By correlating all abnormal UEs, it can be determined whether the abnormal access address has a cluster abnormal call system.
基于上述方案,NWDAF可以从SMF获取与UE会话相关的SIP消息的统计信息,并根据该SIP消息的统计信息以及异常检测策略确定UE是否异常,从而可以有效地阻止UE的异常行为。Based on the above solution, NWDAF can obtain the statistical information of SIP messages related to the UE session from the SMF, and determine whether the UE is abnormal based on the statistical information of the SIP message and the anomaly detection policy, thereby effectively preventing the UE's abnormal behavior.
图4是本申请实施例提供的一种异常检测的方法400的示意图。方法400可以包括如下步骤。FIG. 4 is a schematic diagram of an anomaly detection method 400 provided by an embodiment of the present application. Method 400 may include the following steps.
S401,SMF开启UE的异常检测流程。S401, SMF starts the abnormality detection process of the UE.
SMF开启UE的异常检测可以理解为SMF开启后续的异常检测流程。SMF enabling the UE's anomaly detection can be understood as SMF enabling the subsequent anomaly detection process.
SMF的异常检测流程可以由运营商配置。示例性地,运营商可以针对网络中特定区域的一个或多个SMF配置异常检测流程。SMF's anomaly detection process can be configured by the operator. For example, the operator can configure an anomaly detection process for one or more SMFs in a specific area of the network.
该步骤可以参考S301的描述,不再赘述。For this step, please refer to the description of S301 and will not be described again.
S402,UE#1向该SMF发送PDU会话建立请求。S402, UE#1 sends a PDU session establishment request to the SMF.
相应地,该SMF接收来自该UE的PDU会话建立请求。Accordingly, the SMF receives the PDU session establishment request from the UE.
该步骤和S302类似。This step is similar to S302.
S403,SMF选择UPF。S403, SMF selects UPF.
该步骤和S303类似。This step is similar to S303.
S404,SMF向该UPF发送指示信息#2,该指示信息#2指示UPF上报与UE#1相关的SIP消息的信息。S404: The SMF sends instruction information #2 to the UPF. The instruction information #2 instructs the UPF to report SIP message information related to UE#1.
相应地,UPF接收来自该SMF的该指示信息#2。Correspondingly, UPF receives the indication information #2 from the SMF.
其中,与UE#1相关的SIP消息可以参考S304中的描述。For the SIP message related to UE#1, please refer to the description in S304.
该指示信息#2可以携带数据包检测规则PDR#2,该PDR#2用于匹配或者说检测与UE#1相关的SIP消息的数据包。The indication information #2 may carry the data packet detection rule PDR#2, which is used to match or detect the data packets of the SIP message related to UE#1.
示例性地,该PDR#2的规则可以包括:识别目标地址和/或源地址为特定IP地址的数据包,例如,源地址为UE#1的IP地址(记为IPUE#1)、目标地址为P-CSCF的IP地址(记为IPP-CSCF)的数据包;或者,源地址为对端UE的IP地址、目标地址为P-CSCF的IP地址的数据包。For example, the rules of PDR#2 may include: identifying data packets whose destination address and/or source address are specific IP addresses, for example, the source address is the IP address of UE#1 (denoted as IPUE#1), the destination address The data packet is the IP address of P-CSCF (recorded as IPP-CSCF); or the source address is the IP address of the opposite end UE and the destination address is the IP address of P-CSCF.
该PDR#2的规则还可以包括:识别特定类型的数据包。例如识别类型为SIP消息的数据包。进一步地,该PDR#1的规则还包括识别控制字段包括“INVITE”、“BYE”或“CANCEL”的SIP消息。The PDR#2 rules may also include: identifying specific types of data packets. For example, identify data packets of type SIP message. Further, the rules of PDR#1 also include identifying SIP messages whose control fields include "INVITE", "BYE" or "CANCEL".
其中,控制字段包括“INVITE”的SIP消息也可以称为SIP INVITE消息,同理,控制字段包括“BYE”或“CANCEL”的SIP消息也可以称为SIP BYE消息、SIP CANCEL消息。Among them, the SIP message whose control field includes "INVITE" can also be called SIP INVITE message. Similarly, the SIP message whose control field includes "BYE" or "CANCEL" can also be called SIP BYE message or SIP CANCEL message.
该PDR#2还可以包括UPF上报与UE#1相关的SIP消息的信息的上报规则,例如,该上报规则可以是检测到即上报,即UPF检测到一个SIP消息的信息,UPF向SMF上报该SIP消息的信息。The PDR#2 may also include a reporting rule for the UPF to report the information of the SIP message related to UE#1. For example, the reporting rule may be to report upon detection, that is, when the UPF detects the information of a SIP message, the UPF reports the information to the SMF. SIP message information.
S405,UPF根据该指示信息#2开始检测UE#1的SIP消息。S405: UPF starts detecting the SIP message of UE#1 based on the indication information #2.
或者说,UPF#1根据该指示信息#2开始检测与UE#1相关的SIP消息。In other words, UPF#1 starts detecting SIP messages related to UE#1 based on the indication information #2.
S406,SMF向UE#1发送P-CSCF的地址。 S406: The SMF sends the P-CSCF address to UE#1.
SMF向UE#1发送P-CSCF的地址,即PDU会话建立成功。SMF sends the P-CSCF address to UE#1, that is, the PDU session is successfully established.
可以理解,S406可以在S405之前或之后执行。S406可以理解为对S402的响应。It can be understood that S406 can be executed before or after S405. S406 can be understood as a response to S402.
即,SMF在收到UE#1的PDU会话建立请求后,根据预配置开启异常检测流程,该异常检测流程包括S404。在S404之后,UPF开启检测与UE#1相关的SIP消息。That is, after receiving the PDU session establishment request of UE#1, the SMF starts an abnormality detection process according to the preconfiguration, and the abnormality detection process includes S404. After S404, UPF starts detecting SIP messages related to UE#1.
其中,UPF可检测的UE#1的SIP消息可以来自UE#1发起的通话,例如,MO呼叫,以及来自网络侧发起的通话,例如,MT呼叫。The SIP messages of UE#1 detectable by UPF may come from calls initiated by UE#1, for example, MO calls, and from calls initiated by the network side, for example, MT calls.
需要说明的是,本申请并不限定以上两种通话发生的次数以及先后顺序。例如,UPF可能在预设时间段内仅接收到UE#1发起MO呼叫的SIP消息,而无MT呼叫的SIP消息;或者UPF在预设时间段内仅收到MT呼叫的SIP消息,而无UE#1发起的MO呼叫的SIP消息;或者,UPF可能在接收到一次或多次UE#1发起呼叫的SIP消息之后,接收到一个或多个MT呼叫的SIP消息;或者,UPF可能在接收到一个或多个MT呼叫的SIP消息之后,接收到一次或多次UE#1发起呼叫的SIP消息。It should be noted that this application does not limit the number and sequence of the above two calls. For example, the UPF may only receive the SIP message for the MO call initiated by UE#1 within the preset time period, but no SIP message for the MT call; or the UPF may only receive the SIP message for the MT call within the preset time period, but no SIP message for the MT call. SIP messages for MO calls initiated by UE#1; or, UPF may receive one or more SIP messages for MT calls after receiving one or more SIP messages for calls initiated by UE#1; or, UPF may receive SIP messages for MO calls initiated by UE#1. After receiving SIP messages for one or more MT calls, one or more SIP messages for UE#1 to initiate a call are received.
S407,UPF根据PDR#2检测第一数据包。S407, UPF detects the first data packet according to PDR#2.
该第一数据包可以包括数据包#1。该数据包#1为网络侧发起MT呼叫的数据包。数据包#1的类型为SIP消息;数据包#1的控制字段包括“INVITE”;数据包#1的源地址为IPP-CSCF,数据包#1的目标地址为IPUE#1。The first data packet may include data packet #1. This data packet #1 is a data packet for the network side to initiate an MT call. The type of data packet #1 is a SIP message; the control field of data packet #1 includes "INVITE"; the source address of data packet #1 is IPP-CSCF, and the destination address of data packet #1 is IPUE#1.
该第一数据包还可以包括数据包#2。该数据包#2为UE#1发起MO呼叫的数据包。数据包#2的内容类型为SIP消息,数据包#1的控制字段包括“INVITE”,源地址为IPUE#1,目标地址为IPP-CSCF。The first data packet may also include data packet #2. This data packet #2 is a data packet for UE#1 to initiate an MO call. The content type of packet #2 is a SIP message, the control field of packet #1 includes "INVITE", the source address is IPUE#1, and the destination address is IPP-CSCF.
该第一数据包还可以包括数据包#3。该数据包#3可以是与该数据包#2相对应的数据包。或者说,该数据包#3为UE#1发起呼叫的对端UE(被叫UE)对UE#1发起的呼叫作出响应的数据包。该数据包#3的目标地址为该IPUE#1,源地址为IPP-CSCF,类型为SIP消息,控制字段包括“BYE”。The first data packet may also include data packet #3. The data packet #3 may be a data packet corresponding to the data packet #2. In other words, the data packet #3 is a data packet in which the opposite end UE (called UE) of the call initiated by UE#1 responds to the call initiated by UE#1. The destination address of packet #3 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the control field includes "BYE".
该第一数据包还可以包括数据包#4。该数据包#4可以是与该数据包#2相对应的数据包。或者说,该数据包#4为UE#1发起呼叫的对端UE(被叫UE)对UE#1发起的呼叫作出响应的数据包。该数据包#4的目标地址为该IPUE#1,源地址为IPP-CSCF,类型为SIP消息,控制字段包括“CANCEL”。The first data packet may also include data packet #4. The data packet #4 may be a data packet corresponding to the data packet #2. In other words, the data packet #4 is a data packet in which the opposite end UE (the called UE) of the call initiated by UE#1 responds to the call initiated by UE#1. The destination address of packet #4 is IPUE#1, the source address is IPP-CSCF, the type is SIP message, and the control field includes "CANCEL".
可选地,UPF还可以确定第一数据包的第一信息。Optionally, the UPF may also determine the first information of the first data packet.
该第一信息可以包括检测到第一数据包的时间信息。示例性地,该时间信息可以包括检测到数据包#2、数据包#3以及数据包#4的时间信息。The first information may include time information when the first data packet is detected. For example, the time information may include time information when data packet #2, data packet #3, and data packet #4 are detected.
该第一信息还可以包括第一数据包中特定字段的信息。示例性地,该特定字段可以用于标识UE#1呼叫对端UE,例如,该特定字段标识UE#1呼叫对端的电话号码。该特定字段可以是数据包#2中的字段。The first information may also include information on specific fields in the first data packet. For example, the specific field may be used to identify the UE that UE#1 calls the opposite end. For example, the specific field identifies the phone number of the opposite end that UE#1 calls. This specific field could be the field in packet #2.
需要说明的是,UPF可以按照PDR#2的规则,检测到一个该第一数据包即上报与UE#1相关的SIP消息的信息,或者,UPF也可以在检测到多个数据包后,向SMF上报与UE#1相关的SIP消息的信息,或者,UPF可以周期、定时上报。It should be noted that UPF can detect the first data packet and report the SIP message information related to UE#1 according to the rules of PDR#2, or UPF can also report the SIP message information related to UE#1 after detecting multiple data packets. The SMF reports the SIP message information related to UE#1, or the UPF can report periodically or regularly.
S408,UPF向SMF发送与UE#1相关的SIP消息的信息。S408: The UPF sends the SIP message information related to UE#1 to the SMF.
示例性地,如果UPF检测到数据包#1,UPF向SMF上报的与UE#1相关的SIP消息的信息可以如表7中所示。For example, if the UPF detects data packet #1, the information of the SIP message related to UE #1 reported by the UPF to the SMF may be as shown in Table 7.
表7
Table 7
如果UPF检测到数据包#2,UPF向SMF上报的与UE#1相关的SIP消息的信息可以如表8中所示。If UPF detects packet #2, the information of the SIP message related to UE#1 reported by UPF to SMF can be as shown in Table 8.
表8

Table 8

如果UPF检测到数据包#3和/或数据包#4,UPF向SMF上报的与UE#1相关的SIP消息的信息可以如表9中所示。If the UPF detects data packet #3 and/or data packet #4, the information of the SIP message related to UE#1 reported by the UPF to the SMF may be as shown in Table 9.
表9
Table 9
以上表7至表9中,呼叫UE可以指发起呼叫的UE;事件ID用于指UE触发的会话事件,例如,UE#1向UE#2发起呼叫,或者说,UE#1向UE#2发送用于发起呼叫的SIP消息,则可以将UE#1向UE#2发起的呼叫标识为一个会话事件。In the above Tables 7 to 9, the calling UE may refer to the UE that initiates the call; the event ID is used to refer to the session event triggered by the UE, for example, UE#1 initiates a call to UE#2, or in other words, UE#1 initiates a call to UE#2 By sending a SIP message for initiating a call, the call initiated by UE#1 to UE#2 can be identified as a session event.
S409,SMF根据该UE#1的SIP消息的信息确定SIP消息的统计信息。S409: The SMF determines the statistical information of the SIP message based on the information of the SIP message of the UE#1.
示例性地,若SMF接收到事件ID#1的SIP消息的信息,则SMF更新计数器#1的计数。该计数器#1用于统计向UE#1发起呼叫的次数。该SIP消息的统计信息可以包括计数器#1的计数。For example, if the SMF receives the information of the SIP message of event ID #1, the SMF updates the count of counter #1. The counter #1 is used to count the number of calls initiated to UE#1. The statistical information of the SIP message may include the count of counter #1.
SMF在接收到事件ID#1的SIP消息的信息后,SMF更新计数器#2的计数。该计数器#2用于统计UE#1的通话的总次数。UE#1通话的总次数包括网络侧向UE#1发起呼叫的次数与UE#1发起呼叫的次数的总和。该SIP消息的统计信息还可以包括计数器#2的计数。After SMF receives the information of the SIP message of event ID #1, SMF updates the count of counter #2. The counter #2 is used to count the total number of calls made by UE#1. The total number of calls made by UE#1 includes the sum of the number of times the network side initiates calls to UE#1 and the number of times UE#1 initiates calls. The statistical information of the SIP message may also include the count of counter #2.
若SMF接收到事件ID#2的SIP消息的信息,则SMF更新计数器#3的计数。该计数器#3用于统计UE#1发起呼叫的次数。该SIP消息的统计信息可以包括计数器#3的计数。SMF在接收到事件ID#2的SIP消息的信息后,SMF更新计数器#2的计数。If the SMF receives the information of the SIP message of event ID #2, the SMF updates the count of counter #3. The counter #3 is used to count the number of calls initiated by UE#1. The statistics of the SIP message may include the count of counter #3. After SMF receives the information of the SIP message of event ID #2, SMF updates the count of counter #2.
若SMF接收到事件ID#3的SIP消息的信息,则SMF更新计数器#4的计数。该计数器#4用于统计UE#1发起的呼叫被挂断的次数。该SIP消息的统计信息可以包括计数器#4的计数。If the SMF receives the information of the SIP message of event ID #3, the SMF updates the count of counter #4. The counter #4 is used to count the number of times calls initiated by UE#1 are hung up. The statistics of the SIP message may include the count of counter #4.
可选地,若SMF接收到事件ID#3的SIP消息的信息,SMF还可以关联事件ID#2的SIP消息的信息确定UE#1与被叫UE通话的时长。例如,SMF根据事件ID#3的SIP消息的统计信息确定,UE#2向UE#1发送SIP BYE消息的时刻为时刻#2,SMF通过事件ID#2的SIP消息的信息确定,UE#1向UE#2发送SIP INVITE消息的时刻为时刻#1,则SMF可以确定UE#1与被叫UE#2的通话时长为时刻#1至时刻#2。Optionally, if the SMF receives the information of the SIP message of event ID#3, the SMF can also correlate the information of the SIP message of event ID#2 to determine the duration of the conversation between UE#1 and the called UE. For example, SMF determines based on the statistical information of the SIP message of event ID#3 that the time when UE#2 sends the SIP BYE message to UE#1 is time #2, and SMF determines based on the information of the SIP message of event ID#2 that UE#1 The time when the SIP INVITE message is sent to UE#2 is time #1, then SMF can determine that the duration of the call between UE#1 and the called UE#2 is from time #1 to time #2.
若SMF接收到事件ID#4的SIP消息的信息,则SMF更新计数器#5的计数。该计数器#5用于统计UE#1发起的呼叫被挂断的次数。该SIP消息的统计信息可以包括计数器#5的计数。If the SMF receives the information of the SIP message of event ID #4, the SMF updates the count of counter #5. The counter #5 is used to count the number of times calls initiated by UE#1 are hung up. The statistical information of the SIP message may include the count of counter #5.
S410,SMF向NWDAF发送该UE#1的SIP消息的统计信息。S410: The SMF sends the statistical information of the SIP message of the UE#1 to the NWDAF.
相应地,NWDAF接收来自SMF的UE#1的SIP消息的统计信息。Accordingly, the NWDAF receives the statistical information of the SIP messages of UE#1 from the SMF.
该步骤和S312类似,不再赘述。This step is similar to S312 and will not be described again.
可选地,在SMF向NWDAF发送UE#1的SIP消息的统计信息之前,SMF还可以向P-CSCF发送请求消息#1,请求消息#1用于请求UE#1呼叫对端UE的位置信息。 Optionally, before the SMF sends the statistical information of UE#1's SIP messages to the NWDAF, the SMF can also send a request message #1 to the P-CSCF. The request message #1 is used to request the location information of the UE#1 calling the opposite end UE. .
相应地,P-CSCF向SMF发送对端UE的位置信息。Correspondingly, the P-CSCF sends the location information of the opposite end UE to the SMF.
可以理解,在SMF向NWDAF发送UE#1的SIP消息的统计信息中,还可以包括UE#1呼叫对端UE的位置信息。It can be understood that the statistical information of the SIP message of UE#1 sent by the SMF to the NWDAF may also include the location information of the peer UE called by UE#1.
S411,NWDAF确定UE#1是否存在异常。S411, NWDAF determines whether there is an abnormality in UE#1.
具体地,NWDAF根据异常检测策略以及UE#1的SIP消息的统计信息确定UE#1是否异常。Specifically, NWDAF determines whether UE#1 is abnormal based on the abnormality detection policy and the statistical information of the SIP message of UE#1.
其中,异常检测策略的分析参数的值可以根据UE#1的SIP消息的统计信息确定。The value of the analysis parameter of the anomaly detection strategy may be determined based on the statistical information of the SIP message of UE#1.
该步骤具体可参考S313的描述。For details of this step, please refer to the description of S313.
在确定该多个UE异常后,可选地,NWDAF还可以通过该多个UE的位置信息确定异常接入地址。After determining that the multiple UEs are abnormal, optionally, the NWDAF may also determine the abnormal access address through the location information of the multiple UEs.
基于上述方案,NWDAF可以从SMF获取与UE会话相关的SIP消息的统计信息,并根据该SIP消息的统计信息以及异常检测策略确定UE是否异常,从而可以有效地阻止UE的异常行为。Based on the above solution, NWDAF can obtain the statistical information of SIP messages related to the UE session from the SMF, and determine whether the UE is abnormal based on the statistical information of the SIP message and the anomaly detection policy, thereby effectively preventing the UE's abnormal behavior.
图5是本申请实施例提供的一种异常检测的方法500的示意图。方法500可以包括如下步骤。FIG. 5 is a schematic diagram of an anomaly detection method 500 provided by an embodiment of the present application. Method 500 may include the following steps.
S501,SMF开启UE的异常检测流程。S501, SMF starts the abnormality detection process of the UE.
SMF开启UE的异常检测可以理解为SMF开启后续的异常检测流程。SMF enabling the UE's anomaly detection can be understood as SMF enabling the subsequent anomaly detection process.
SMF的异常检测流程可以由运营商配置。示例性地,运营商可以针对网络中特定区域的一个或多个SMF配置异常检测流程。SMF's anomaly detection process can be configured by the operator. For example, the operator can configure an anomaly detection process for one or more SMFs in a specific area of the network.
例如,在SMF(分析网元的一例)中可以预先配置用于检测UE是否异常的多个异常检测策略。异常检测策略可以参考S301中的描述,不再赘述。For example, multiple anomaly detection strategies for detecting whether the UE is abnormal may be pre-configured in SMF (an example of analyzing network elements). For the anomaly detection strategy, please refer to the description in S301 and will not be described again.
S502,UE#1向该SMF发送PDU会话建立请求。S502: UE#1 sends a PDU session establishment request to the SMF.
相应地,该SMF接收来自该UE的PDU会话建立请求。Accordingly, the SMF receives the PDU session establishment request from the UE.
该步骤和S302类似。This step is similar to S302.
S503,SMF选择UPF。S503, SMF selects UPF.
该UPF用于传输UE#1的用户面数据。SMF具体如何选择UPF可以参考现有的相关描述。该步骤和S303类似。This UPF is used to transmit user plane data of UE#1. For details on how to choose UPF for SMF, please refer to the existing relevant descriptions. This step is similar to S303.
S504,SMF向NWDAF发送请求消息#2,该请求消息#2用于请求选择具有统计和上报UE会话信令的AF。S504. The SMF sends a request message #2 to the NWDAF. The request message #2 is used to request the selection of an AF with statistics and reporting of UE session signaling.
相应地,NWDAF接收来自SMF该请求消息#2。Accordingly, NWDAF receives the request message #2 from SMF.
其中,具有统计和上报UE会话信令的AF例如为具有统计和上报UE会话信令的P-CSCF。The AF that has statistics and reports UE session signaling is, for example, a P-CSCF that has statistics and reports UE session signaling.
该请求消息#2可以包括UE#1的标识,例如,UE#1的SUPI、PEI或者GPSI。该请求消息#2还可以包括UE#1的位置信息,例如,UE#1的LAC、cell ID等。The request message #2 may include the identification of UE#1, for example, the SUPI, PEI or GPSI of UE#1. The request message #2 may also include the location information of UE#1, for example, the LAC, cell ID, etc. of UE#1.
S505,NWDAF向P-CSCF发送请求消息#3,该请求消息#3用于请求确定与UE#1相关的SIP消息的统计信息。S505. The NWDAF sends request message #3 to the P-CSCF. The request message #3 is used to request to determine the statistical information of the SIP message related to UE#1.
相应地,P-CSCF接收来自NWDAF的该请求消息#3。Correspondingly, P-CSCF receives the request message #3 from NWDAF.
该请求消息#3可以包括UE#1的标识。可选地,该请求消息#3还包括UE#1的位置信息以及异常检测策略的标识。The request message #3 may include the identity of UE#1. Optionally, the request message #3 also includes the location information of UE#1 and the identification of the anomaly detection strategy.
S506,NWDAF向SMF发送P-CSCF的地址。S506, NWDAF sends the address of P-CSCF to SMF.
相应地,SMF接收来自NWDAF的P-CSCF的地址。Accordingly, the SMF receives the address of the P-CSCF from the NWDAF.
在NWDAF接收到P-CSCF对请求消息#3的响应消息后,NWDAF向SMF发送P-CSCF的地址。After NWDAF receives the response message of P-CSCF to request message #3, NWDAF sends the address of P-CSCF to SMF.
S507,SMF向UE#1发送P-CSCF的地址。S507: The SMF sends the P-CSCF address to UE#1.
SMF向UE#1发送P-CSCF的地址,即PDU会话建立成功。SMF sends the P-CSCF address to UE#1, that is, the PDU session is successfully established.
S508,P-CSCF根据该请求消息#3开始检测与UE#1相关的SIP消息。S508: The P-CSCF starts to detect SIP messages related to UE#1 based on the request message #3.
其中,P-CSCF可统计的UE#1的SIP消息可以来自UE#1发起的通话,例如,主叫通话(MO呼叫或MO通话),以及来自对端UE发起的通话,例如,被叫呼叫(MT呼叫或MT通话)。Among them, the SIP messages of UE#1 that can be counted by P-CSCF can come from calls initiated by UE#1, for example, the calling call (MO call or MO call), and from calls initiated by the opposite end UE, such as the called call. (MT call or MT call).
可以理解,对端UE是相对于UE#1来说的,UE#1向UE#2发起呼叫,UE#2可以称为对端UE;UE#2向UE#1发起呼叫,该UE#2也可以称为对端UE。It can be understood that the opposite end UE is relative to UE#1. UE#1 initiates a call to UE#2, and UE#2 can be called the opposite end UE; UE#2 initiates a call to UE#1, and the UE#2 It can also be called the opposite end UE.
需要说明的是,本申请并不限定以上两种通话发生的次数以及先后顺序。例如,P-CSCF可能在预设时间段内仅接收到UE#1发起MO呼叫的SIP消息,而无MT呼叫的SIP消息;或者P-CSCF在预设时间段内仅收到MT呼叫的SIP消息,而无UE#1发起的MO呼叫的SIP消息;或者,P-CSCF可能在 接收到一次或多次UE#1发起呼叫的SIP消息之后,接收到一个或多个MT呼叫的SIP消息;或者,P-CSCF可能在接收到一个或多个MT呼叫的SIP消息之后,接收到一次或多次UE#1发起呼叫的SIP消息。It should be noted that this application does not limit the number and sequence of the above two calls. For example, the P-CSCF may only receive the SIP message for the MO call initiated by UE#1 within the preset time period, but not the SIP message for the MT call; or the P-CSCF may only receive the SIP message for the MT call within the preset time period. message without the SIP message of the MO call initiated by UE#1; or, the P-CSCF may After receiving one or more SIP messages for UE#1 to initiate a call, one or more SIP messages for MT calls are received; alternatively, the P-CSCF may receive one or more SIP messages for MT calls. One or more SIP messages initiated by UE#1.
具体地,P-CSCF检测与UE#1相关的第一数据包。Specifically, the P-CSCF detects the first data packet related to UE#1.
示例性地,该第一数据包可以参考S407中的描述,该第一数据包可以包括数据包#1,数据包#2,数据包#3,数据包#4中的至少一个。该数据包#1至数据包#4可以参考S407的描述。For example, the first data packet may refer to the description in S407, and the first data packet may include at least one of data packet #1, data packet #2, data packet #3, and data packet #4. For data packet #1 to data packet #4, please refer to the description of S407.
可选地,P-CSCF还可以确定第一数据包的第一信息。Optionally, the P-CSCF may also determine the first information of the first data packet.
该第一信息可以包括检测到第一数据包的时间信息。示例性地,该时间信息可以包括检测到数据包#2、数据包#3以及数据包#4的时间信息。The first information may include time information when the first data packet is detected. For example, the time information may include time information when data packet #2, data packet #3, and data packet #4 are detected.
该第一信息还可以包括第一数据包中特定字段的信息。示例性地,该特定字段可以用于标识UE#1呼叫对端UE,例如,该特定字段标识UE#1呼叫对端的电话号码。该特定字段可以是数据包#2中的字段。The first information may also include information on specific fields in the first data packet. For example, the specific field may be used to identify the UE that UE#1 calls the opposite end. For example, the specific field identifies the phone number of the opposite end that UE#1 calls. This specific field could be the field in packet #2.
S509,P-CSCF确定SIP消息的统计信息。S509, P-CSCF determines the statistical information of the SIP message.
P-CSCF确定SIP消息的统计信息可以参考S409中SMF确定SIP消息的统计信息的过程,不再赘述。The P-CSCF determines the statistical information of the SIP message by referring to the process of the SMF determining the statistical information of the SIP message in S409, which will not be described again.
S510,P-CSCF向NWDAF发送该UE#1的SIP消息的统计信息。S510: The P-CSCF sends the statistical information of the SIP message of the UE#1 to the NWDAF.
相应地,NWDAF接收来自P-CSCF的UE#1的SIP消息的统计信息。Correspondingly, the NWDAF receives the statistical information of the SIP messages of UE#1 from the P-CSCF.
该步骤和S312类似,不再赘述。This step is similar to S312 and will not be described again.
在NWDAF接收到来自P-CSCF的该UE#1的SIP消息的统计消息之后,可选地,NWDAF还可以向SMF请求该UE#1的信息,例如,该UE#1的SUPI、LAC、cell ID等。After the NWDAF receives the statistical message of the SIP message of the UE#1 from the P-CSCF, optionally, the NWDAF can also request the SMF for the information of the UE#1, for example, the SUPI, LAC, cell of the UE#1 ID etc.
S511,NWDAF确定UE#1是否存在异常。S511, NWDAF determines whether there is an abnormality in UE#1.
具体地,NWDAF根据异常检测策略以及UE#1的SIP消息的统计信息确定UE#1是否异常。Specifically, NWDAF determines whether UE#1 is abnormal based on the abnormality detection policy and the statistical information of the SIP message of UE#1.
其中,异常检测策略的分析参数的值可以根据UE#1的SIP消息的统计信息确定。The value of the analysis parameter of the anomaly detection strategy may be determined based on the statistical information of the SIP message of UE#1.
具体可参考S313的描述。For details, please refer to the description of S313.
在确定该多个UE异常后,可选地,NWDAF还可以通过该多个UE的位置信息确定异常接入地址。After determining that the multiple UEs are abnormal, optionally, the NWDAF may also determine the abnormal access address through the location information of the multiple UEs.
基于上述方案,NWDAF可以从SMF获取与UE会话相关的SIP消息的统计信息,并根据该SIP消息的统计信息以及异常检测策略确定UE是否异常,从而可以有效地阻止UE的异常行为。Based on the above solution, NWDAF can obtain the statistical information of SIP messages related to the UE session from the SMF, and determine whether the UE is abnormal based on the statistical information of the SIP message and the anomaly detection policy, thereby effectively preventing the UE's abnormal behavior.
应理解,本申请实施例中的具体的例子只是为了帮助本领域技术人员更好地理解本申请实施例,而非限制本申请实施例的范围。It should be understood that the specific examples in the embodiments of the present application are only to help those skilled in the art better understand the embodiments of the present application, but are not intended to limit the scope of the embodiments of the present application.
还应理解,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。It should also be understood that the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its functions and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application.
还应理解,在本申请的各个实施例中,如果没有特殊说明以及逻辑冲突,不同的实施例之间的术语和/或描述具有一致性、且可以相互引用,不同的实施例中的技术特征根据其内在的逻辑关系可以组合形成新的实施例。It should also be understood that in the various embodiments of the present application, if there are no special instructions or logical conflicts, the terms and/or descriptions between different embodiments are consistent and can be referenced to each other. The technical features in different embodiments New embodiments can be formed based on their internal logical relationships.
可以理解的是,本申请上述实施例中,由通信设备实现的方法,也可以由可配置于通信设备内部的部件(例如芯片或者电路)实现。It can be understood that in the above embodiments of the present application, the method implemented by the communication device can also be implemented by components (such as chips or circuits) that can be configured inside the communication device.
以上,结合图2至图5详细说明了本申请实施例提供的异常检测的方法。上述方法主要从网元之间交互的角度进行了介绍。可以理解的是,各个网元,为了实现上述功能,其包含了执行各个功能相应的硬件结构和/或软件模块。本领域技术人员应该可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,本申请能够以硬件或硬件和计算机软件的结合形式来实现。某个功能究竟以硬件还是计算机软件驱动硬件的方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。Above, the anomaly detection method provided by the embodiment of the present application is described in detail with reference to FIGS. 2 to 5 . The above methods are mainly introduced from the perspective of interaction between network elements. It can be understood that, in order to implement the above functions, each network element includes a corresponding hardware structure and/or software module to perform each function. Those skilled in the art should realize that the present application can be implemented in the form of hardware or a combination of hardware and computer software with the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein. Whether a function is performed by hardware or computer software driving the hardware depends on the specific application and design constraints of the technical solution. Skilled artisans may implement the described functionality using different methods for each specific application, but such implementations should not be considered beyond the scope of this application.
以下,结合图6至图8对本申请实施例提供的通信装置进行详细说明。应理解,装置实施例的描述与方法实施例的描述相互对应,因此,未详细描述的内容可以参见上文方法实施例,为了简洁,部分内容不再赘述。The communication device provided by the embodiment of the present application will be described in detail below with reference to FIGS. 6 to 8 . It should be understood that the description of the device embodiments corresponds to the description of the method embodiments. Therefore, for content that is not described in detail, please refer to the above method embodiments. For the sake of brevity, some content will not be described again.
图6是本申请实施例提供的通信装置600的示意性框图。如图所示,该通信装置600可以包括: 收发单元610和处理单元620。FIG. 6 is a schematic block diagram of a communication device 600 provided by an embodiment of the present application. As shown in the figure, the communication device 600 may include: Transceiver unit 610 and processing unit 620.
在一种可能的设计中,该通信装置600可以是上文方法实施例中的第一网元,也可以是用于实现上文方法实施例中第一网元的功能的芯片。In a possible design, the communication device 600 may be the first network element in the above method embodiment, or may be a chip used to implement the functions of the first network element in the above method embodiment.
应理解,该通信装置600可对应于根据本申请实施例的方法200中的第一网元,或者对应于方法300、方法400或方法500中的UPF,或者方法500中的P-CSCF。该通信装置600可以包括用于执行图2中的方法200中的第一网元执行的方法单元、图3中的方法300、图4中方法400或方法500中的UPF执行的方法单元、图5中的方法500中的P-CSCF执行的方法单元。并且,该通信装置600中的各单元和上述其他操作和/或功能分别为了实现图2中的方法200至图5中的方法500的相应流程。应理解,各单元执行上述相应步骤的具体过程在上述方法实施例中已经详细说明,为了简洁,在此不再赘述。It should be understood that the communication device 600 may correspond to the first network element in the method 200 according to the embodiment of the present application, or correspond to the UPF in the method 300, 400 or 500, or the P-CSCF in the method 500. The communication device 600 may include a method unit for executing the first network element in the method 200 in FIG. 2, a method unit for executing the UPF in the method 300 in FIG. 3, the method 400 or the method 500 in FIG. 4, FIG. The method unit executed by the P-CSCF in method 500 in 5. Moreover, each unit in the communication device 600 and the above-mentioned other operations and/or functions are respectively intended to implement the corresponding processes of the method 200 in FIG. 2 to the method 500 in FIG. 5 . It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
在另一种可能的设计中,该通信装置600可以是上文方法实施例中的分析网元,也可以是用于实现上文方法实施例中分析网元功能的芯片。In another possible design, the communication device 600 may be the analysis network element in the above method embodiment, or may be a chip used to implement the analysis network element function in the above method embodiment.
应理解,该通信装置600可对应于根据本申请实施例的方法200中的第一分析网元或第二分析网元,该通信装置600可以包括用于执行第一分析网元或第二分析网元执行的方法的单元。并且,该通信装置600中的各单元和上述其他操作和/或功能分别为了实现图2中的方法200的相应流程。应理解,各单元执行上述相应步骤的具体过程在上述方法实施例中已经详细说明,为了简洁,在此不再赘述。It should be understood that the communication device 600 may correspond to the first analysis network element or the second analysis network element in the method 200 according to the embodiment of the present application, and the communication device 600 may include a device for performing the first analysis network element or the second analysis network element. The unit of the method executed by the network element. Moreover, each unit in the communication device 600 and the above-mentioned other operations and/or functions are respectively intended to implement the corresponding flow of the method 200 in FIG. 2 . It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
或者,该通信装置600可对应于方法300、方法400或方法500中的SMF或NWDAF。该通信装置600可以包括用于图3中的方法400或方法500中的SMF或NWDAF执行的方法单元。并且,该通信装置600中的各单元和上述其他操作和/或功能分别为了实现图3中的方法300至图5中的方法500的相应流程。应理解,各单元执行上述相应步骤的具体过程在上述方法实施例中已经详细说明,为了简洁,在此不再赘述。Alternatively, the communication device 600 may correspond to SMF or NWDAF in method 300, method 400, or method 500. The communication device 600 may include a method unit for SMF or NWDAF execution in method 400 or method 500 in FIG. 3 . Moreover, each unit in the communication device 600 and the above-mentioned other operations and/or functions are respectively intended to implement the corresponding processes of the method 300 in FIG. 3 to the method 500 in FIG. 5 . It should be understood that the specific process of each unit performing the above corresponding steps has been described in detail in the above method embodiments, and will not be described again for the sake of brevity.
还应理解,该通信装置600中的收发单元610可对应于图7中示出的通信设备700中的收发器720。该通信装置600中的处理单元620可对应于图7中示出的通信设备700中的处理器710。It should also be understood that the transceiver unit 610 in the communication device 600 may correspond to the transceiver 720 in the communication device 700 shown in FIG. 7 . The processing unit 620 in the communication device 600 may correspond to the processor 710 in the communication device 700 shown in FIG. 7 .
还应理解,当该通信装置600为芯片时,该芯片包括收发单元。示例性地,该芯片还可以包括处理单元。其中,收发单元可以是输入输出电路或通信接口;处理单元可以为该芯片上集成的处理器或者微处理器或者集成电路。It should also be understood that when the communication device 600 is a chip, the chip includes a transceiver unit. Exemplarily, the chip may also include a processing unit. The transceiver unit may be an input-output circuit or a communication interface; the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip.
收发单元610用于实现通信装置600的信号的收发操作,处理单元620用于实现通信装置600的信号的处理操作。The transceiver unit 610 is used to implement the signal transceiver operation of the communication device 600 , and the processing unit 620 is used to implement the signal processing operation of the communication device 600 .
示例性地,该通信装置600还包括存储单元630,该存储单元630用于存储指令。Exemplarily, the communication device 600 further includes a storage unit 630, which is used to store instructions.
图7是本申请实施例提供的通信设备700的示意性框图。如图7所示,该通信设备700包括:至少一个处理器710和通信接口720。该处理器710与存储器耦合,用于执行存储器中存储的指令,以控制通信接口720发送和/或接收信号。示例性地,该通信设备700还包括存储器730,用于存储指令。Figure 7 is a schematic block diagram of a communication device 700 provided by an embodiment of the present application. As shown in FIG. 7 , the communication device 700 includes: at least one processor 710 and a communication interface 720 . The processor 710 is coupled to the memory and is used to execute instructions stored in the memory to control the communication interface 720 to send and/or receive signals. Exemplarily, the communication device 700 also includes a memory 730 for storing instructions.
应理解,上述处理器710和存储器730可以合成一个处理装置,处理器710用于执行存储器730中存储的程序代码来实现上述功能。具体实现时,该存储器730也可以集成在处理器710中,或者独立于处理器710。It should be understood that the above-mentioned processor 710 and the memory 730 can be combined into one processing device, and the processor 710 is used to execute the program code stored in the memory 730 to implement the above functions. During specific implementation, the memory 730 may also be integrated in the processor 710 or independent of the processor 710 .
还应理解,在一种可能的设计中,该通信接口720可以包括接收器(或者称,接收机)和发射器(或者称,发射机)。该通信接口720还可以进一步包括天线,天线的数量可以为一个或多个。通信接口720还可以是接口电路。It should also be understood that in one possible design, the communication interface 720 may include a receiver (or receiver) and a transmitter (or transmitter). The communication interface 720 may further include an antenna, and the number of antennas may be one or more. Communication interface 720 may also be an interface circuit.
当该通信设备700为芯片时,该芯片包括收发单元和处理单元。其中,收发单元可以是输入输出电路或通信接口;处理单元可以为该芯片上集成的处理器或者微处理器或者集成电路。When the communication device 700 is a chip, the chip includes a transceiver unit and a processing unit. The transceiver unit may be an input-output circuit or a communication interface; the processing unit may be a processor, microprocessor, or integrated circuit integrated on the chip.
图8是本申请实施例的一种芯片系统的示意图。这里的芯片系统也可为电路组成的系统。图8所示的芯片系统800包括:逻辑电路810以及输入/输出接口(input/output interface)820,所述逻辑电路用于与输入接口耦合,通过所述输入/输出接口传输数据(例如第一指示信息),以执行图2至图5所述的方法。Figure 8 is a schematic diagram of a chip system according to an embodiment of the present application. The chip system here may also be a system composed of circuits. The chip system 800 shown in Figure 8 includes: a logic circuit 810 and an input/output interface (input/output interface) 820. The logic circuit is used to couple with the input interface and transmit data (such as a first input interface) through the input/output interface. instruction information) to perform the methods described in Figures 2 to 5.
本申请实施例还提供了一种处理装置,包括处理器和接口。所述处理器可用于执行上述方法实施例中的方法。An embodiment of the present application also provides a processing device, including a processor and an interface. The processor may be used to execute the method in the above method embodiment.
应理解,上述处理装置可以是一个芯片。例如,该处理装置可以是现场可编程门阵列(field  programmable gate array,FPGA),可以是专用集成芯片(application specific integrated circuit,ASIC),还可以是系统芯片(system on chip,SoC),还可以是中央处理器(central processor unit,CPU),还可以是网络处理器(network processor,NP),还可以是数字信号处理电路(digital signal processor,DSP),还可以是微控制器(micro controller unit,MCU),还可以是可编程控制器(programmable logic device,PLD)或其他集成芯片。It should be understood that the above processing device may be a chip. For example, the processing device may be a field programmable gate array (field programmable gate array). programmable gate array (FPGA), which can be an application specific integrated circuit (ASIC), a system on chip (SoC), or a central processor unit (CPU), or It can be a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), or a programmable logic controller. device, PLD) or other integrated chip.
在实现过程中,上述方法的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。结合本申请实施例所提供的方法的步骤可以直接体现为硬件处理器执行完成,或者用处理器中的硬件及软件模块组合执行完成。软件模块可以位于随机存储器,闪存、只读存储器,可编程只读存储器或者电可擦写可编程存储器、寄存器等本领域成熟的存储介质中。该存储介质位于存储器,处理器读取存储器中的信息,结合其硬件完成上述方法的步骤。为避免重复,这里不再详细描述。During the implementation process, each step of the above method can be completed by instructions in the form of hardware integrated logic circuits or software in the processor. The steps of the method provided in conjunction with the embodiments of the present application can be directly implemented by a hardware processor, or executed by a combination of hardware and software modules in the processor. The software module can be located in random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers and other mature storage media in this field. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. To avoid repetition, it will not be described in detail here.
应注意,本申请实施例中的处理器可以是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法实施例的各步骤可以通过处理器中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器可以是通用处理器、数字信号处理器(DSP)、专用集成电路(ASIC)、现场可编程门阵列(FPGA)或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件。可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者该处理器也可以是任何常规的处理器等。It should be noted that the processor in the embodiment of the present application may be an integrated circuit chip with signal processing capabilities. During the implementation process, each step of the above method embodiment can be completed through an integrated logic circuit of hardware in the processor or instructions in the form of software. The above-mentioned processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. . Each method, step and logical block diagram disclosed in the embodiment of this application can be implemented or executed. A general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc.
可以理解,本申请实施例中的存储器可以是易失性存储器或非易失性存储器,或可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(read-only memory,ROM)、可编程只读存储器(programmable ROM,PROM)、可擦除可编程只读存储器(erasable PROM,EPROM)、电可擦除可编程只读存储器(electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(random access memory,RAM),其用作外部高速缓存。It can be understood that the memory in the embodiment of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, non-volatile memory can be read-only memory (ROM), programmable ROM (PROM), erasable programmable read-only memory (erasable PROM, EPROM), electrically removable memory. Erase electrically programmable read-only memory (EPROM, EEPROM) or flash memory. Volatile memory can be random access memory (RAM), which is used as an external cache.
根据本申请实施例提供的方法,本申请还提供一种计算机程序产品,该计算机程序产品包括:计算机程序代码,当该计算机程序代码在计算机上运行时,使得该计算机执行图2至图5所示实施例中任意一个实施例的方法。According to the method provided by the embodiment of the present application, the present application also provides a computer program product. The computer program product includes: computer program code. When the computer program code is run on a computer, it causes the computer to execute the steps shown in Figures 2 to 5. The method of any one of the embodiments is shown.
根据本申请实施例提供的方法,本申请还提供一种计算机可读介质,该计算机可读介质存储有程序代码,当该程序代码在计算机上运行时,使得该计算机执行图2至图5所示实施例中任意一个实施例的方法。According to the method provided by the embodiment of the present application, the present application also provides a computer-readable medium. The computer-readable medium stores program code. When the program code is run on a computer, it causes the computer to execute the steps shown in Figures 2 to 5. The method of any one of the embodiments is shown.
根据本申请实施例提供的方法,本申请还提供一种通信系统,其包括前述的第一网元、第一分析网元和第二分析网元,示例性地,该第一分析网元可以是会话管理网元,该第二分析网元可以是网络数据分析功能网元;该通信系统还可以包括终端设备,该终端设备为需要进行异常检测的终端设备中的任一终端设备。According to the method provided by the embodiment of the present application, the present application also provides a communication system, which includes the aforementioned first network element, a first analysis network element and a second analysis network element. For example, the first analysis network element can It is a session management network element, and the second analysis network element can be a network data analysis function network element; the communication system can also include a terminal device, and the terminal device is any terminal device that needs to perform abnormality detection.
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示例的单元及算法步骤,能够以电子硬件、或者计算机软件和电子硬件的结合来实现。这些功能究竟以硬件还是软件方式来执行,取决于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本申请的范围。Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans may implement the described functionality using different methods for each specific application, but such implementations should not be considered beyond the scope of this application.
所属领域的技术人员可以清楚地了解到,为描述的方便和简洁,上述描述的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程,在此不再赘述。Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, devices and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be described again here.
在本申请所提供的几个实施例中,应该理解到,所揭露的系统、装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components may be combined or can be integrated into another system, or some features can be ignored, or not implemented. On the other hand, the coupling or direct coupling or communication connection between each other shown or discussed may be through some interfaces, and the indirect coupling or communication connection of the devices or units may be in electrical, mechanical or other forms.
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or they may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
另外,在本申请各个实施例中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。 In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, each unit can exist physically alone, or two or more units can be integrated into one unit.
所述功能如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁碟或者光盘等各种可以存储程序代码的介质。If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the existing technology or the part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including Several instructions are used to cause a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage media include: U disk, mobile hard disk, read-only memory (ROM), random access memory (Random Access Memory, RAM), magnetic disk or optical disk and other media that can store program code. .
以上所述,仅为本申请的具体实施方式,但本申请的保护范围并不局限于此,任何熟悉本技术领域的技术人员在本申请揭露的技术范围内,可轻易想到变化或替换,都应涵盖在本申请的保护范围之内。因此,本申请的保护范围应以所述权利要求的保护范围为准。 The above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application. should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims (28)

  1. 一种异常检测的方法,其特征在于,包括:A method of anomaly detection, characterized by including:
    接收来自第一网元的第一信息,所述第一信息包括与终端设备相关的初始化协议SIP消息的信息;Receive first information from the first network element, where the first information includes information about the initialization protocol SIP message related to the terminal device;
    基于所述第一信息确定所述终端设备是否异常;Determine whether the terminal device is abnormal based on the first information;
    其中,所述SIP消息的信息包括以下信息中的至少一项:Wherein, the information of the SIP message includes at least one of the following information:
    SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,所述SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,所述第一字段用于标识SIP消息的发送方所使用的设备,所述第二字段用于标识SIP消息的接收方设备。The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, and the type of the SIP message includes SIP invite INVITE message, SIP reject CANCEL message and SIP hang up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  2. 根据权利要求1所述的方法,其特征在于,在基于所述第一信息确定所述终端设备是否异常之前,所述方法还包括:The method according to claim 1, characterized in that before determining whether the terminal device is abnormal based on the first information, the method further includes:
    根据所述第一信息确定SIP消息的统计信息;Determine statistical information of the SIP message according to the first information;
    所述基于所述第一信息确定所述终端设备是否异常,包括:Determining whether the terminal device is abnormal based on the first information includes:
    基于所述SIP消息的统计信息确定所述终端设备是否异常。Determine whether the terminal device is abnormal based on the statistical information of the SIP message.
  3. 根据权利要求2所述的方法,其特征在于,所述SIP消息的统计信息包括以下信息中的至少一项:The method according to claim 2, characterized in that the statistical information of the SIP message includes at least one of the following information:
    类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;The total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type, the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, the first duration information ;
    其中,所述第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,所述第一SIP消息的源地址和所述第二SIP消息的目标地址相同,所述第一SIP消息的类型和所述第二SIP消息的类型不同。Wherein, the first duration is determined by the time information of the first SIP message and the time information of the second SIP message, the source address of the first SIP message and the target address of the second SIP message are the same, and the first The type of the SIP message is different from the type of the second SIP message.
  4. 根据权利要求1至3中任一项所述的方法,其特征在于,The method according to any one of claims 1 to 3, characterized in that,
    所述接收来自第一网元的第一信息包括:第一分析网元接收来自所述第一网元的所述第一信息;The receiving the first information from the first network element includes: the first analysis network element receiving the first information from the first network element;
    所述基于所述第一信息确定所述终端设备是否异常包括:所述第一分析网元或第二分析网元基于所述第一信息确定所述终端设备是否异常,所述第一分析网元为会话管理网元或第一网络数据分析功能网元,所述第二分析网元为第二网络数据分析功能网元。Determining whether the terminal device is abnormal based on the first information includes: the first analysis network element or the second analysis network element determines whether the terminal device is abnormal based on the first information, and the first analysis network element determines whether the terminal device is abnormal based on the first information. The network element is a session management network element or a first network data analysis function network element, and the second analysis network element is a second network data analysis function network element.
  5. 根据权利要求1至4中任一项所述的方法,其特征在于,所述第一网元为用户面网元或应用功能网元。The method according to any one of claims 1 to 4, characterized in that the first network element is a user plane network element or an application function network element.
  6. 根据权利要求1至5中任一项所述的方法,其特征在于,在接收来自第一网元的第一信息之前,所述方法还包括:The method according to any one of claims 1 to 5, characterized in that, before receiving the first information from the first network element, the method further includes:
    接收来自所述终端设备的会话建立请求;Receive a session establishment request from the terminal device;
    根据所述会话建立请求向所述第一网元发送指示信息,所述指示信息指示根据第一数据包检测规则PDR检测所述SIP消息。Instruction information is sent to the first network element according to the session establishment request, and the instruction information instructs to detect the SIP message according to the first packet detection rule PDR.
  7. 根据权利要求1至6中任一项所述的方法,其特征在于,所述方法还包括:The method according to any one of claims 1 to 6, characterized in that the method further includes:
    向应用功能网元发送第三SIP消息的所述第二字段的信息,所述第三SIP消息的源地址为所述终端设备的地址;Send the information of the second field of the third SIP message to the application function network element, where the source address of the third SIP message is the address of the terminal device;
    接收来自所述应用功能网元的至少一个终端设备的位置信息,所述至少一个终端设备的位置信息是根据所述第三SIP消息的所述第二字段发送的;Receive location information from at least one terminal device of the application function network element, where the location information of the at least one terminal device is sent according to the second field of the third SIP message;
    更新所述第一信息,所述第一信息包括所述至少一个终端设备的位置信息。The first information is updated, and the first information includes location information of the at least one terminal device.
  8. 根据权利要求2至7中任一项所述的方法,其特征在于,所述基于所述第一信息确定所述终端设备是否异常,包括:The method according to any one of claims 2 to 7, wherein determining whether the terminal device is abnormal based on the first information includes:
    基于所述SIP消息的统计信息确定第一参数的值;Determine the value of the first parameter based on the statistical information of the SIP message;
    基于所述第一参数的值与第一阈值的大小关系确定所述终端设备是否异常,Determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold,
    其中,所述第一参数包括以下参数中的至少一个:Wherein, the first parameter includes at least one of the following parameters:
    SIP BYE消息的总数占SIP INVITE消息的总数的比例,SIP CANCEL消息的总数占SIP INVITE 消息的总数的比例,SIP INVITE消息的总数,检测到SIP消息的时间信息的离散度,所述第一时长的离散度,所述至少一个终端设备的位置信息的离散度。The ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, and the total number of SIP CANCEL messages to the total number of SIP INVITE The proportion of the total number of messages, the total number of SIP INVITE messages, the dispersion of the time information of the detected SIP messages, the dispersion of the first duration, and the dispersion of the location information of the at least one terminal device.
  9. 根据权利要求8所述的方法,其特征在于,所述基于所述第一信息确定所述终端设备是否异常,还包括:The method of claim 8, wherein determining whether the terminal device is abnormal based on the first information further includes:
    基于所述第一参数的值与所述第一阈值的大小关系,以及第一权重确定所述终端设备是否异常,所述第一权重包括所述第一参数中的至少一个参数对应的权重。Determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold and a first weight, where the first weight includes a weight corresponding to at least one parameter among the first parameters.
  10. 一种异常检测的方法,其特征在于,包括:A method of anomaly detection, characterized by including:
    第一网元确定终端设备的第一信息,所述第一信息包括与所述终端设备相关的初始化协议SIP消息的信息;The first network element determines first information about the terminal device, where the first information includes information about the initialization protocol SIP message related to the terminal device;
    所述第一网元向分析网元发送所述第一信息,所述第一信息用于确定所述终端设备是否异常;The first network element sends the first information to the analysis network element, where the first information is used to determine whether the terminal device is abnormal;
    其中,所述SIP消息的信息包括以下信息中的至少一项:Wherein, the information of the SIP message includes at least one of the following information:
    SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,所述SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,所述第一字段用于标识SIP消息的发送方所使用的设备,所述第二字段用于标识SIP消息的接收方设备。The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, and the type of the SIP message includes SIP invite INVITE message, SIP reject CANCEL message and SIP hang up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  11. 根据权利要求10所述的方法,其特征在于,在所述第一网元确定终端设备的第一信息之前,所述方法还包括:The method according to claim 10, characterized in that, before the first network element determines the first information of the terminal device, the method further includes:
    接收来自所述分析网元的指示信息,所述指示信息指示根据第一数据包检测规则PDR检测所述SIP消息。Receive instruction information from the analysis network element, where the instruction information instructs to detect the SIP message according to the first packet detection rule PDR.
  12. 根据权利要求10或11所述的方法,其特征在于,所述第一网元为用户面网元或应用功能网元。The method according to claim 10 or 11, characterized in that the first network element is a user plane network element or an application function network element.
  13. 根据权利要求10至12中任一项所述的方法,其特征在于,所述分析网元为会话管理网元或网络数据分析功能网元。The method according to any one of claims 10 to 12, characterized in that the analysis network element is a session management network element or a network data analysis function network element.
  14. 一种通信系统,其特征在于,所述通信系统包括第一分析网元和第二分析网元,A communication system, characterized in that the communication system includes a first analysis network element and a second analysis network element,
    所述第一分析网元,用于接收来自第一网元的第一信息,所述第一信息包括与终端设备相关的初始化协议SIP消息的信息;The first analysis network element is configured to receive first information from the first network element, where the first information includes information on the initialization protocol SIP message related to the terminal device;
    所述第二分析网元,用于基于所述第一信息确定所述终端设备是否异常;The second analysis network element is used to determine whether the terminal device is abnormal based on the first information;
    其中,所述SIP消息的信息包括以下信息中的至少一项:Wherein, the information of the SIP message includes at least one of the following information:
    SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,所述SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,所述第一字段用于标识SIP消息的发送方所使用的设备,所述第二字段用于标识SIP消息的接收方设备。The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, and the type of the SIP message includes SIP invite INVITE message, SIP reject CANCEL message and SIP hang up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  15. 根据权利要求14所述的系统,其特征在于,The system according to claim 14, characterized in that:
    所述第一分析网元,还用于根据所述第一信息确定SIP消息的统计信息;The first analysis network element is also used to determine statistical information of SIP messages based on the first information;
    所述第二分析网元,具体用于基于所述SIP消息的统计信息确定所述终端设备是否异常。The second analysis network element is specifically configured to determine whether the terminal device is abnormal based on the statistical information of the SIP message.
  16. 根据权利要求15所述的系统,其特征在于,所述SIP消息的统计信息包括以下信息中的至少一项:The system according to claim 15, characterized in that the statistical information of the SIP message includes at least one of the following information:
    类型相同的SIP消息的总数,源地址相同且类型相同的SIP消息的总数,目标地址相同且类型相同的SIP消息的总数,源地址相同且第一字段不同的SIP消息的数量,第一时长信息;The total number of SIP messages of the same type, the total number of SIP messages with the same source address and the same type, the total number of SIP messages with the same destination address and the same type, the number of SIP messages with the same source address and different first fields, the first duration information ;
    其中,所述第一时长由第一SIP消息的时间信息以及第二SIP消息的时间信息确定,所述第一SIP消息的源地址和所述第二SIP消息的目标地址相同,所述第一SIP消息的类型和所述第二SIP消息的类型不同。Wherein, the first duration is determined by the time information of the first SIP message and the time information of the second SIP message, the source address of the first SIP message and the target address of the second SIP message are the same, and the first The type of the SIP message is different from the type of the second SIP message.
  17. 根据权利要求10至16中任一项所述的系统,其特征在于,所述第一网元为用户面网元或应用功能网元。The system according to any one of claims 10 to 16, characterized in that the first network element is a user plane network element or an application function network element.
  18. 根据权利要求10至17中任一项所述的系统,其特征在于,所述第一分析网元还用于:The system according to any one of claims 10 to 17, characterized in that the first analysis network element is also used for:
    接收来自所述终端设备的会话建立请求;Receive a session establishment request from the terminal device;
    根据所述会话建立请求向所述第一网元发送指示信息,所述指示信息指示根据第一数据包检测规 则PDR检测所述SIP消息。Instruction information is sent to the first network element according to the session establishment request, and the instruction information indicates that according to the first data packet detection rule The PDR then detects the SIP message.
  19. 根据权利要求10至18中任一项所述的系统,其特征在于,所述第一分析网元还用于:The system according to any one of claims 10 to 18, characterized in that the first analysis network element is also used for:
    向应用功能网元发送第三SIP消息的所述第二字段的信息,所述第三SIP消息的源地址为所述终端设备的地址;Send the information of the second field of the third SIP message to the application function network element, where the source address of the third SIP message is the address of the terminal device;
    接收来自所述应用功能网元的至少一个终端设备的位置信息,所述至少一个终端设备的位置信息是根据所述第三SIP消息的所述第二字段发送的;Receive location information from at least one terminal device of the application function network element, where the location information of the at least one terminal device is sent according to the second field of the third SIP message;
    更新所述第一信息,所述第一信息包括所述至少一个终端设备的位置信息。The first information is updated, and the first information includes location information of the at least one terminal device.
  20. 根据权利要求11至19中任一项所述的系统,其特征在于,所述第二分析网元具体用于:The system according to any one of claims 11 to 19, characterized in that the second analysis network element is specifically used for:
    基于所述SIP消息的统计信息确定第一参数的值;Determine the value of the first parameter based on the statistical information of the SIP message;
    基于所述第一参数的值与第一阈值的大小关系确定所述终端设备是否异常,Determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold,
    其中,所述第一参数包括以下参数中的至少一个:Wherein, the first parameter includes at least one of the following parameters:
    SIP BYE消息的总数占SIP INVITE消息的总数的比例,SIP CANCEL消息的总数占SIP INVITE消息的总数的比例,SIP INVITE消息的总数,检测到SIP消息的时间信息的离散度,所述第一时长的离散度,所述至少一个终端设备的位置信息的离散度。The ratio of the total number of SIP BYE messages to the total number of SIP INVITE messages, the ratio of the total number of SIP CANCEL messages to the total number of SIP INVITE messages, the total number of SIP INVITE messages, the discreteness of the time information of the detected SIP messages, the first duration The degree of dispersion is the degree of dispersion of the location information of the at least one terminal device.
  21. 根据权利要求20所述的系统,其特征在于,第二分析网元具体用于:The system according to claim 20, characterized in that the second analysis network element is specifically used for:
    基于所述第一参数的值与所述第一阈值的大小关系,以及第一权重确定所述终端设备是否异常,所述第一权重包括所述第一参数中的至少一个参数对应的权重。Determine whether the terminal device is abnormal based on the relationship between the value of the first parameter and the first threshold and a first weight, where the first weight includes a weight corresponding to at least one parameter among the first parameters.
  22. 一种通信装置,其特征在于,包括:A communication device, characterized by including:
    存储器,用于存储计算机程序;Memory, used to store computer programs;
    处理器,用于执行所述存储器中存储的计算机程序,以使得所述通信装置执行权利要求1至9中任一项所述的方法,或者,执行权利要求10至13中任一项所述的方法。A processor, configured to execute a computer program stored in the memory, so that the communication device performs the method described in any one of claims 1 to 9, or performs the method described in any one of claims 10 to 13 Methods.
  23. 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质上存储有计算机程序,当所述计算机程序被通信装置运行时,使得所述装置执行如权利要求1至9中任意一项所述的方法,或者,执行如权利要求10至13中任意一项所述的方法。A computer-readable storage medium, characterized in that a computer program is stored on the computer-readable storage medium. When the computer program is run by a communication device, it causes the device to execute any one of claims 1 to 9. The method described in claim 10, or performing the method described in any one of claims 10 to 13.
  24. 一种芯片系统,其特征在于,包括:A chip system is characterized by including:
    处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片系统的通信装置执行如权利要求1至9中任意一项所述的方法,或者,执行如权利要求10至13中任意一项所述的方法。A processor, configured to call and run a computer program from the memory, so that the communication device installed with the chip system executes the method as claimed in any one of claims 1 to 9, or executes as claimed in claims 10 to 13 any of the methods described.
  25. 一种包含指令的计算机程序产品,其特征在于,A computer program product containing instructions, characterized by:
    当其在计算机上运行时,使得所述计算机执行如权利要求1至9中任意一项所述的方法;或者,执行如权利要10至13中任意一项所述的方法。When it is run on a computer, the computer is caused to perform the method as described in any one of claims 1 to 9; or, to perform the method as described in any one of claims 10 to 13.
  26. 一种异常检测的方法,其特征在于,包括:A method of anomaly detection, characterized by including:
    第一分析网元接收来自第一网元的第一信息,所述第一信息包括与终端设备相关的初始化协议SIP消息的信息;The first analysis network element receives first information from the first network element, where the first information includes information on the initialization protocol SIP message related to the terminal device;
    第二分析网元基于所述第一信息确定所述终端设备是否异常;The second analysis network element determines whether the terminal device is abnormal based on the first information;
    其中,所述SIP消息的信息包括以下信息中的至少一项:Wherein, the information of the SIP message includes at least one of the following information:
    SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,所述SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,所述第一字段用于标识SIP消息的发送方所使用的设备,所述第二字段用于标识SIP消息的接收方设备。The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, and the type of the SIP message includes SIP invite INVITE message, SIP reject CANCEL message and SIP hang up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  27. 一种异常检测的方法,其特征在于,包括:A method of anomaly detection, characterized by including:
    第一网元确定终端设备的第一信息,所述第一信息包括与所述终端设备相关的初始化协议SIP消息的信息;The first network element determines first information about the terminal device, where the first information includes information about the initialization protocol SIP message related to the terminal device;
    所述第一网元向分析网元发送所述第一信息;The first network element sends the first information to the analysis network element;
    所述分析网元接收来自第一网元的第一信息,并基于所述第一信息确定所述终端设备是否异常;The analysis network element receives the first information from the first network element, and determines whether the terminal device is abnormal based on the first information;
    其中,所述SIP消息的信息包括以下信息中的至少一项:Wherein, the information of the SIP message includes at least one of the following information:
    SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,所述SIP消息的类型包括SIP邀请INVITE消息,SIP 拒接CANCEL消息以及SIP挂断BYE消息,所述第一字段用于标识SIP消息的发送方所使用的设备,所述第二字段用于标识SIP消息的接收方设备。The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, and the type of the SIP message includes SIP invitation INVITE message, SIP To reject the CANCEL message and the SIP hang-up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
  28. 一种通信系统,其特征在于,所述通信系统包括第一网元和分析网元,A communication system, characterized in that the communication system includes a first network element and an analysis network element,
    所述第一网元用于:确定终端设备的第一信息,并向所述分析网元发送所述第一信息,所述第一信息包括与所述终端设备相关的初始化协议SIP消息的信息;The first network element is configured to: determine first information of the terminal device, and send the first information to the analysis network element, where the first information includes information on the initialization protocol SIP message related to the terminal device. ;
    所述分析网元用于:接收来自第一网元的第一信息,并基于所述第一信息确定所述终端设备是否异常;The analyzing network element is configured to: receive first information from the first network element, and determine whether the terminal device is abnormal based on the first information;
    其中,所述SIP消息的信息包括以下信息中的至少一项:Wherein, the information of the SIP message includes at least one of the following information:
    SIP消息的类型,SIP消息的源地址,SIP消息的目标地址,SIP消息的第一字段的信息,SIP消息的第二字段的信息,检测到SIP消息的时间信息,所述SIP消息的类型包括SIP邀请INVITE消息,SIP拒接CANCEL消息以及SIP挂断BYE消息,所述第一字段用于标识SIP消息的发送方所使用的设备,所述第二字段用于标识SIP消息的接收方设备。 The type of SIP message, the source address of the SIP message, the destination address of the SIP message, the information of the first field of the SIP message, the information of the second field of the SIP message, the time information of detecting the SIP message, and the type of the SIP message includes SIP invite INVITE message, SIP reject CANCEL message and SIP hang up BYE message, the first field is used to identify the device used by the sender of the SIP message, and the second field is used to identify the recipient device of the SIP message.
PCT/CN2023/103209 2022-07-30 2023-06-28 Anomaly detection method and communication apparatus WO2024027381A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202210912476.7A CN117528612A (en) 2022-07-30 2022-07-30 Abnormality detection method and communication device
CN202210912476.7 2022-07-30

Publications (1)

Publication Number Publication Date
WO2024027381A1 true WO2024027381A1 (en) 2024-02-08

Family

ID=89757216

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/103209 WO2024027381A1 (en) 2022-07-30 2023-06-28 Anomaly detection method and communication apparatus

Country Status (2)

Country Link
CN (1) CN117528612A (en)
WO (1) WO2024027381A1 (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101388628B1 (en) * 2013-11-07 2014-04-24 한국인터넷진흥원 Method for blocking abnormal traffic in 4g mobile network
CN104519012A (en) * 2013-09-27 2015-04-15 上海信擎信息技术有限公司 SIP-protocol-based method and system for detecting communication network attack
CN105407543A (en) * 2015-12-31 2016-03-16 宇龙计算机通信科技(深圳)有限公司 Call control method and core network device
CN111770490A (en) * 2019-04-02 2020-10-13 电信科学技术研究院有限公司 Method and equipment for determining terminal behavior analysis

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104519012A (en) * 2013-09-27 2015-04-15 上海信擎信息技术有限公司 SIP-protocol-based method and system for detecting communication network attack
KR101388628B1 (en) * 2013-11-07 2014-04-24 한국인터넷진흥원 Method for blocking abnormal traffic in 4g mobile network
CN105407543A (en) * 2015-12-31 2016-03-16 宇龙计算机通信科技(深圳)有限公司 Call control method and core network device
CN111770490A (en) * 2019-04-02 2020-10-13 电信科学技术研究院有限公司 Method and equipment for determining terminal behavior analysis

Also Published As

Publication number Publication date
CN117528612A (en) 2024-02-06

Similar Documents

Publication Publication Date Title
WO2021196214A1 (en) Transmission method and apparatus, and computer storage medium
CN111357239A (en) Communication processing method, device and computer storage medium
CN115065988B (en) Relay transmission method, relay terminal and remote terminal
US20230035694A1 (en) Service guarantee method and apparatus
WO2022141295A1 (en) Communication method and apparatus
WO2021184217A1 (en) Channel state information measurement method and apparatus, and computer storage medium
US20230142002A1 (en) Communication Method and Apparatus
WO2021218563A1 (en) Method and device for transmitting data
WO2023071770A1 (en) Data analysis result obtaining method and communication apparatus
CN115812297A (en) Wireless communication method, terminal equipment and network equipment
WO2024027381A1 (en) Anomaly detection method and communication apparatus
CN111279778A (en) Communication processing method, device and computer storage medium
CN115843125A (en) Communication method and communication device
CN108886766B (en) Control information transmission method and device
WO2022061545A1 (en) Communication method and apparatus
WO2024027427A1 (en) Anomaly detection method and communication apparatus
WO2014019447A1 (en) Frequency selection method, user equipment, and base station
CN115811715A (en) Communication method and communication device
WO2023185452A1 (en) Communication method and communication apparatus
WO2022170588A1 (en) Communication method and communication apparatus
WO2023071771A1 (en) Communication method and communication apparatus
US20230403684A1 (en) Communication method, device, and storage medium
US20230135667A1 (en) Method and apparatus for providing network slice in wireless communication system
WO2023213112A1 (en) Communication method and apparatus
WO2022174780A1 (en) Ddos attack detection method and apparatus

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23849091

Country of ref document: EP

Kind code of ref document: A1