Method and device for processing signaling storm and communication equipment

Through the analysis function, the signaling storm of network-side equipment is obtained and analyzed, and the signaling storm is identified and controlled, which solves the problem of the inability to analyze network-side equipment signaling storm in the prior art, and improves the robustness and efficiency of the network.

CN120456076APending Publication Date: 2025-08-08VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410175029.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-07
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The prior art cannot effectively analyze whether there is a signaling storm in the network side equipment, resulting in excessive network resource consumption and affecting network robustness and efficiency.

Method used

The target data is obtained through the analysis function, the signaling storm of the network-side device is analyzed, the causes and target devices that cause the signaling storm are identified, and the signaling storm analysis results are provided for control.

Benefits of technology

It enhances the robustness of the network, improves the working efficiency of network-side equipment, and reduces the impact of signaling storms on the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120456076A_ABST
    Figure CN120456076A_ABST
Patent Text Reader

Abstract

The invention discloses a signaling storm processing method and device and communication equipment, and belongs to the technical field of communication, and the signaling storm processing method comprises the steps that an analysis function obtains target data; the analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device; wherein the signaling storm analysis result comprises at least one of the following items: a reason causing the signaling storm, and the reason comprises indication information used for indicating that the signaling storm is the signaling storm of the network side equipment; the identifier of the first network side device is determined, and the first network side device is a target device of the signaling storm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of communication technology, and specifically relates to a method, apparatus, and communication equipment for processing a signaling storm. Background Art

[0002] Signaling storms can occur in Third Generation Partnership Projects (3GPP) networks. This can occur when a network function (NF) fails, sending a large amount of abnormal signaling to the target network element (NE). This causes the target NE to consume a large amount of resources to process these messages, resulting in the NE being unable to operate or operating at a low efficiency. Once this occurs, subsequent signaling cannot be processed, causing numerous errors and compromising network robustness.

[0003] In 3GPP networks, the Network Data Analytics Function (NWDAF) has been introduced. It can collect various data generated in the network, perform intelligent data analysis, and ultimately generate corresponding data analysis results to detect or predict various events occurring in the network.

[0004] In related technologies, NWDAF can analyze whether the application function (AF) is congested by analyzing the user plane data related information of the UE, but does not involve the analysis of network-side devices. Therefore, it is impossible to analyze whether other network-side devices (such as gNB, WLAN, AMF and other NFs) have signaling storms. Summary of the Invention

[0005] The embodiments of the present application provide a method, apparatus, and communication device for processing a signaling storm, which can solve the problem that related technologies cannot analyze whether a signaling storm occurs in a network-side device.

[0006] In a first aspect, a method for handling a signaling storm is provided, comprising:

[0007] The analysis function obtains target data;

[0008] The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device;

[0009] The signaling storm analysis result includes at least one of the following:

[0010] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0011] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0012] Secondly, another method for handling signaling storms is provided, including:

[0013] The control function receives the signaling storm analysis result sent by the analysis function;

[0014] The control function performs a signaling storm control operation according to the signaling storm analysis result;

[0015] The signaling storm analysis result includes at least one of the following:

[0016] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0017] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0018] In a third aspect, a signaling storm processing device is provided, which is applied to the analysis function, including:

[0019] Acquisition module, used to obtain target data;

[0020] An analysis module, configured to analyze the target data to obtain a signaling storm analysis result of the first network-side device;

[0021] The signaling storm analysis result includes at least one of the following:

[0022] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0023] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0024] In a fourth aspect, another signaling storm processing device is provided, which is applied to a control function, including:

[0025] An analysis result receiving module is used to receive the signaling storm analysis results sent by the analysis function;

[0026] A signaling storm control module, configured to perform a signaling storm control operation according to the signaling storm analysis result;

[0027] The signaling storm analysis result includes at least one of the following:

[0028] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0029] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0030] In a fifth aspect, a communication device is provided, comprising a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the method for processing a signaling storm as described in the first aspect are implemented, or the steps of the method for processing a signaling storm as described in the second aspect are implemented.

[0031] In a sixth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented, or the steps of the method described in the second aspect are implemented.

[0032] In the seventh aspect, a chip is provided, comprising a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, or to implement the method described in the second aspect.

[0033] In an eighth aspect, a computer program / program product is provided, wherein the computer program / program product is stored in a storage medium and is executed by at least one processor to implement the steps of the method described in the first aspect or the second aspect.

[0034] In an embodiment of the present application, the analysis function analyzes the signaling storm of the network side device according to the target data, and obtains the signaling storm analysis result of the first network side device, so that the network side signaling storm can be controlled according to the signaling storm analysis result, which can enhance the robustness of the network and is conducive to improving the working efficiency of the network side device. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 is a block diagram of a wireless communication system to which embodiments of the present application may be applied;

[0036] Figure 2 This is a flowchart of a method for handling a signaling storm in an embodiment of the present application;

[0037] Figure 3 This is a flowchart of a method for handling a signaling storm in an embodiment of the present application;

[0038] Figure 4 This is a flowchart of a method for handling a signaling storm in an embodiment of the present application;

[0039] Figure 5 This is a flowchart of a method for handling a signaling storm in an embodiment of the present application;

[0040] Figure 6 This is a structural block diagram of a signaling storm processing device in an embodiment of the present application;

[0041] Figure 7 This is a structural block diagram of another signaling storm processing device in an embodiment of the present application;

[0042] Figure 8 This is a structural block diagram of a communication device in an embodiment of the present application;

[0043] Figure 9 This is a structural block diagram of a network-side device in an embodiment of the present application;

[0044] Figure 10 This is a structural block diagram of another network-side device in an embodiment of the present application. DETAILED DESCRIPTION

[0045] The following will be combined with the accompanying drawings in the embodiments of this application to clearly describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0046] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first" and "second" are generally of the same type, and do not limit the number of objects. For example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0047] It is worth noting that the technology described in the embodiments of the present application is not limited to the Long Term Evolution (LTE) / LTE-Advanced (LTE-A) system, but can also be used in other wireless communication systems, such as Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal Frequency Division Multiple Access (OFDMA), Single-carrier Frequency Division Multiple Access (SC-FDMA) and other systems. The terms "system" and "network" in the embodiments of the present application are often used interchangeably, and the technology described can be used for the systems and radio technologies mentioned above, as well as for other systems and radio technologies. The following description describes a New Radio (NR) system for illustrative purposes, and NR terminology is used in most of the following description, but these technologies can also be applied to applications other than NR system applications, such as 6th generation (6G) systems. th Generation, 6G) communication system.

[0048] Figure 1A block diagram of a wireless communication system applicable to the embodiments of the present application is shown. The wireless communication system includes a terminal device 11 and a network side device 12. The terminal device 11 may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer) or a notebook computer, a personal digital assistant (PDA), a handheld computer, a netbook, an ultra-mobile personal computer (UMPC), a mobile internet device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device (Wearable Device), a vehicle-mounted device (VUE), a pedestrian terminal (PUE), a smart home (home appliances with wireless communication functions, such as refrigerators, televisions, washing machines, or furniture, etc.), a game console, a personal computer (PC), an ATM or a self-service machine, and other terminal-side devices. Wearable devices include: smart watches, smart bracelets, smart headphones, smart glasses, smart jewelry (smart bracelets, smart bracelets, smart rings, smart necklaces, smart anklets, smart anklets, etc.), smart wristbands, smart clothing, etc. It should be noted that the specific type of the terminal device 11 is not limited in the embodiments of the present application. The network side device 12 may include an access network device or a core network device, wherein the access network device 12 may also be referred to as a radio access network device, a radio access network (RAN), a radio access network function, or a radio access network unit. The access network device 12 may include a base station, a WLAN access point, or a WiFi node, etc. The base station may be referred to as a node B, an evolved node B (eNB), an access point, a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home node B, a home evolved node B, a transmitting and receiving point (TRP), or other appropriate terms in the field. As long as the same technical effect is achieved, the base station is not limited to a specific technical vocabulary. It should be noted that in the embodiment of the present application, only the base station in the NR system is used as an example for introduction, and the specific type of the base station is not limited.The core network equipment may include but is not limited to at least one of the following: core network node, core network function, mobility management entity (MME), access mobility management function (AMF), session management function (SMF), user plane function (UPF), policy control function (PCF), policy and charging rules function unit (PCRF), edge application service discovery function (EASDF), unified data management (UDM), unified data storage (UDR), home subscriber server (HSS), centralized network configuration (CNC), network storage function (NRF), network exposure function (NEF), local NEF (L-NEF), binding support function (Binding Function, Boundary Separation ... Support Function, BSF), Application Function (AF), Network Data Analysis Function (NWDAF), Operation, Management, Maintenance (OAM) functions, etc. It should be noted that in the embodiment of the present application, only the core network device in the NR system is introduced as an example, and the specific type of the core network device is not limited.

[0049] The following describes in detail the signaling storm processing method provided by the embodiment of the present application through some embodiments and application scenarios in conjunction with the accompanying drawings.

[0050] Reference Figure 2 , shows a flow chart of a method for processing a signaling storm provided by an embodiment of the present application. The method is applied to analysis functions, such as Figure 2 As shown, the method may specifically include:

[0051] Step 101: Analyze the function to obtain target data;

[0052] Step 102: The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device.

[0053] The signaling storm analysis result includes at least one of the following:

[0054] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0055] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0056] It should be noted that the analysis function in the embodiment of the present application may be NWDAF, which can collect various data generated in the network and perform intelligent data analysis, and finally generate corresponding data analysis results to detect or predict various events occurring in the network. Of course, the analysis function may also be other devices or network elements that can collect target data and perform data analysis, such as OAM, or external security functions (such as firewalls, intrusion detection systems, intrusion prevention systems, etc.), and this application does not limit this. For example, the analysis function in the present application may be a communication device configured with an AI model, which is trained to implement a network data analysis function.

[0057] The first network side device is the target device of the signaling storm, which can be understood as the target device that is suffering from the signaling storm, or the target device that is predicted to suffer from the signaling storm through the analysis function. The identifier of the first network side device can identify a single network side device. For example, the identifier of the first network side device can be a cell identifier (cellID), NF instance ID, etc.; the identifier of the first network side device can also identify a group or multiple network side devices, such as through a tracking area (TA), an area of interest (AoI), a single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI) and other identifiers.

[0058] In an optional embodiment of the present application, the first network side device may be an access network device, such as a base station (gNB), a wireless local area network (WLAN) access point, etc.; the first network side device may also be a core network device, such as an AMF or SMF, etc., which is a network function (NF) that performs signaling interaction with other network side devices or terminals.

[0059] A network-side device signaling storm refers to a signaling storm caused by network-side signaling. This is because other network-side devices send a large amount of signaling to the first network-side device, causing the signaling received by the first network-side device to exceed its processing limit. The first network-side device needs to consume a large amount of resources to process these signalings, which in turn causes the first network-side device to be unable to work or to maintain operation at a lower efficiency.

[0060] The target data is input data for signaling storm analysis. Exemplarily, the target data may be at least one of signaling characteristic information and network capacity information of the first network device. The signaling characteristic information indicates at least one of signaling failure characteristics and signaling anomaly characteristics between the first network device and other network devices; the network capacity information indicates the number of current network contexts for the first network device. Alternatively, the target data may also include at least one of signaling characteristic information and network capacity information of other network devices interacting with the first network device.

[0061] The analysis function analyzes the target data, and may perform signaling storm detection on the first network-side device, for example, detecting the number or ratio of failed messages currently on the first network-side device, detecting the number or ratio of unresponsive messages currently on the first network-side device, detecting the level of the signaling storm, or detecting the trend of the signaling storm, etc. In this case, the signaling storm analysis result is a signaling storm detection result, which may include at least one of an identifier of the first network-side device experiencing the signaling storm and a cause of the signaling storm.

[0062] It is understood that a characteristic of a network element experiencing a signaling storm is that the network element is in an abnormal resource usage state (e.g., a central processing unit (CPU) usage rate of 100% and a memory occupancy rate of 100%). Therefore, in the embodiment of the present application, the abnormal resource usage of the first network-side device can be used as a trigger condition for signaling storm detection.

[0063] The analysis function analyzes target data and may also predict a signaling storm for the first network-side device. For example, the function may detect the number or ratio of historical and current failure messages for the first network-side device and predict trends, detect the number or ratio of historical and current unresponsive messages for the first network-side device and predict trends, predict the level of the signaling storm, the changing trend of the signaling storm, and predict the time when the signaling storm may occur. In this case, the signaling storm analysis result is a signaling storm prediction result, which may include at least one of an identifier of the first network-side device that is about to experience a signaling storm and a cause of the signaling storm.

[0064] In an optional embodiment of the present application, signaling storm prediction can be achieved in the following manner: NWDAF analyzes historical data to learn that the proportion of rejected signaling for the first network-side device under normal circumstances is maintained at 2% at a certain capacity. NWDAF learns from historical signaling storm results (the administrator can label the signaling storm after it occurs) that when the proportion of rejected signaling exceeds 10%, it indicates that a signaling storm has occurred. NWDAF finds that the current proportion of rejected signaling has gradually increased from 2% to 4% and has an upward trend. NWDAF predicts that a signaling storm may occur in the first network-side device.

[0065] In an embodiment of the present application, the analysis function analyzes the signaling storm of the network side device according to the target data, and obtains the signaling storm analysis result of the first network side device, so that the network side signaling storm can be controlled according to the signaling storm analysis result, which can enhance the robustness of the network and is conducive to improving the working efficiency of the network side device.

[0066] Optionally, the cause of the signaling storm includes at least one of the following:

[0067] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0068] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0069] The signaling storm on the first network side device caused by the signaling sent by the network device may be caused by the following reasons:

[0070] 1. The first network-side device itself is abnormal. For example, the first network-side device itself experiences an abnormality, sending a large number of abnormal requests (such as duplicate messages, malformed messages, etc.) to other network-side devices and receiving replies from other network-side devices, resulting in a network signaling storm. Optionally, the abnormality of the first network-side device itself can also be expressed as a result of the first network-side device itself, such as abnormal behavior of the first network-side device and signaling looping on the first network-side device.

[0071] 2. Other network-side devices interacting with the first network-side device are abnormal. For example, other network-side devices accessing the first network-side device are in an abnormal state and continuously send abnormal messages (such as duplicate messages, malformed messages, etc.) to the first network-side device, resulting in a surge in message processing by the first network-side device. Optionally, the abnormality of other network-side devices interacting with the first network-side device can also be expressed as other network-side device reasons, other network-side device abnormalities, other network-side device behavior abnormalities, or other network-side device signaling loops.

[0072] Optionally, the signaling storm analysis result further includes at least one of the following:

[0073] The level of signaling storm;

[0074] The development trend of signaling storms;

[0075] Duration of the signaling storm;

[0076] Characteristic information of abnormal signaling;

[0077] an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device that interacts with the first network device;

[0078] Feature information of the abnormal network-side device;

[0079] confidence level;

[0080] Prediction time.

[0081] The level of the signaling storm is used to indicate the severity of the signaling storm, and may be, for example, low, medium, or high.

[0082] The development trend of the signaling storm is used to indicate the possible subsequent trend of the signaling storm, for example, it can be rising, falling, unknown, stable, etc.

[0083] The duration of the signaling storm is used to indicate how long the signaling storm may last.

[0084] In the case where the signaling storm analysis result is a signaling storm prediction result, the signaling storm analysis result may further include a confidence level and a prediction time, wherein the confidence level indicates the accuracy of the signaling storm prediction result and the prediction time indicates the predicted time when a signaling storm may occur.

[0085] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0086] Abnormal signaling message;

[0087] The signaling type of the abnormal signaling;

[0088] The proportion of abnormal signaling in all signaling.

[0089] The abnormal signaling message indicates the signaling or message that caused the signaling storm on the network device. For example, if the first network device is a gNB, the abnormal signaling message may be AMF configure failure; or if the first network device is an AMF or SMF, the abnormal signaling message may be a 503 HTTP response message, etc.

[0090] The signaling type of abnormal signaling indicates the type of signaling that caused the signaling storm on the network device. For example, if the first network device is a gNB, the signaling type of abnormal signaling can be N2; or if the first network device is an AMF or SMF, the signaling type of abnormal signaling can be HTTP.

[0091] The identifier of the abnormal network side device is the network side device that interacts with the first network device and is also the source of the signaling storm. It can be used to identify a single abnormal network side device or multiple abnormal network side devices.

[0092] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0093] abnormal behavior of the abnormal network side device;

[0094] The category of the abnormal network-side device.

[0095] The abnormal behavior of the abnormal network side device may include the abnormal network side device sending repeated signaling, sending malformed signaling, abnormally establishing context, and the like.

[0096] The category of the abnormal network side device is used to indicate the category of the network side device where the abnormality occurs, and can be identified by TA, AoI, S-NSSAAI, etc.

[0097] The level of the signaling storm, its development trend, the type of signaling causing the storm, the characteristics of abnormal signaling, the identification of abnormal network devices, and the characteristics of abnormal network devices can all be determined by analyzing the characteristic signaling and network device data, particularly the characteristics of signaling failures. The duration of the signaling storm can be determined by additional analysis of the time period.

[0098] In an optional embodiment of the present application, the analysis function acquires target data, including:

[0099] The analysis function obtains the first data from the second network side device.

[0100] The second network-side device includes at least one of the following:

[0101] the first network-side device;

[0102] A network-side device for managing the first network-side device.

[0103] In an embodiment of the present application, the analysis function can obtain the first data from the target of the signaling storm (that is, the first network side device in this application), or obtain the first data from the network side device used to manage the first network side device (that is, OAM), and use the obtained first data as the target data for analyzing the signaling storm.

[0104] The network side device used to manage the first network side device may be an Operation Administration Maintenance (OAM) device, or other devices or network elements used to manage the first network side device.

[0105] Optionally, the first data includes at least one of the following:

[0106] Signaling characteristic information of the first network side device; the signaling characteristic information is used to indicate at least one of a signaling failure characteristic and a signaling abnormality characteristic between the first network side device and other network side devices;

[0107] The network capacity information of the first network side device; the network capacity information is used to indicate the number of current network contexts of the first network side device.

[0108] Optionally, before the analysis function obtains the first data from the second network-side device, the method further includes:

[0109] The analysis function sends a first data collection request to the second network side device.

[0110] In an embodiment of the present application, the analysis function may obtain the first data of the first network side device by sending a first data collection request to the first network side device or OAM.

[0111] Exemplarily, the first data collection request may obtain the first data of the first network side device from the first network side device or OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3).

[0112] For example, if the first network-side device is a gNB, the first data collection request can be implemented by calling a subscription notification model (Nnwdaf_AnalyticsSubscription_Subscribe) or a request-response model (Nnwdaf_AnalyticsInfo_Request). The former is based on a subscription-notification model, where the subscriber periodically or sporadically sends messages to the analytics function. The latter is based on a request-response model, where each request is responded to.

[0113] Alternatively, the first network side device is AMF or SMF, and the first data collection request can be achieved by calling the Event_Exposure event reporting service of NF. It can be based on a subscription-notification model, and the subscriber will send messages to NWDAF periodically or irregularly; it can also be based on a request-response model, with one request and one reply.

[0114] Optionally, in addition to collecting the first data of the first network-side device, the NWDAF may also collect data of other network-side devices connected to the first network-side device through this method.

[0115] In another optional embodiment of the present application, the analysis function acquires target data and further includes:

[0116] The analysis function obtains second data from a third network-side device.

[0117] The third network-side device includes at least one of the following:

[0118] a fourth network-side device accessing the first network-side device;

[0119] A network-side device for managing the fourth network-side device.

[0120] In an embodiment of the present application, the analysis function may further obtain the second data from a fourth network-side device, where the fourth network-side device is a network-side device that accesses the first network-side device. Alternatively, the analysis function may obtain the second data from a network-side device used to manage the fourth network-side device, and use the obtained second data as target data for analyzing the signaling storm. Optionally, the network-side device used to manage the fourth network-side device includes an OAM.

[0121] Optionally, when the first network-side device includes an access network device, the fourth network-side device includes another access network device other than the first network-side device, or the fourth network-side device includes a core network device. For example, if the first network-side device is a gNB, the fourth network-side device may be another gNB connected to the first network-side device, or an AMF.

[0122] When the first network-side device includes a core network device, and when the fourth network-side device includes a core network device, the fourth network-side device includes at least one of other core network devices, access network devices, and other network functions other than the first network-side device. For example, if the first network-side device is an AMF or SMF, the fourth network-side device may be a gNB, AUSF, UDM, PCF, SBANF, UPF, etc. connected to the first network-side device.

[0123] The network-side device used to manage the fourth network-side device may be an OAM, or other devices or network elements used to manage the fourth network-side device.

[0124] Optionally, the second data includes at least one of the following:

[0125] Signaling characteristic information of the fourth network side device; the signaling characteristic information is used to indicate at least one of a signaling failure characteristic and a signaling abnormality characteristic between the fourth network side device and the first network side device;

[0126] The network capacity information of the fourth network side device; the network capacity information is used to indicate the number of current network contexts of the fourth network side device.

[0127] Optionally, before the analysis function obtains the first data from the third network-side device, the method further includes:

[0128] The analysis function sends a second data collection request to the third network-side device.

[0129] In an embodiment of the present application, the analysis function may obtain the second data of the fourth network side device by sending a second data collection request to the fourth network side device or OAM.

[0130] Exemplarily, the second data collection request may obtain the second data of the fourth network side device from the fourth network side device or OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3).

[0131] For example, if the first network-side device is a gNB, the fourth network-side device is an AMF, and the third network-side device is an AMF or OAM, then if the second data is collected from the AMF, the second data collection request can be made by invoking the Event_Exposure event reporting service of a different NF. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, with one request and one reply. If the second data is collected from the OAM, the second data collection request can be made by invoking the subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3) to obtain data from the OAM periodically or irregularly.

[0132] Alternatively, the first network-side device is an AMF or SMF, the fourth network-side device is a source NF, and the third network-side device is a source NF or OAM. If the second data is collected from the source NF, the second data collection request can be made by calling the Event_Exposure event reporting service of different NFs. Based on the subscription-notification mode, the subscriber will periodically or irregularly send a message to the NWDAF. It can also be based on a request-response mode, with one request and one reply. If the second data is collected from OAM, the second data collection request can obtain data from OAM periodically or irregularly by calling the subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0133] Optionally, the NWDAF may select the NF to which the first network-side device (target NF) is connected to send the second data collection request.

[0134] Optionally, the signaling characteristic information includes at least one of the following:

[0135] Number of signaling failure messages;

[0136] The number of all signaling;

[0137] The proportion of signaling failure messages in all signaling;

[0138] The number of unresponsive request signals;

[0139] The proportion of unresponsive request signals in all request signals;

[0140] The number of repeated signaling messages;

[0141] The proportion of repeated signaling messages in all signaling;

[0142] The number of malformed signaling messages;

[0143] The proportion of malformed signaling messages in all signaling messages;

[0144] The number of resource allocation messages;

[0145] The proportion of resource allocation messages in all signaling.

[0146] It should be noted that the first data in this application includes at least one of the signaling characteristic information and network capacity information of the first network side device.

[0147] Referring to Table 1, there are shown protocols corresponding to signaling interactions between different types of target network side devices and different types of source network side devices.

[0148] Table 1

[0149] Target network device Source network side device protocol gNB gNB Xn gNB AMF N2 AMF gNB N2 AMF SBA NF HTTP SMF UPF N4 SMF SBA NF HTTP

[0150] The target network-side device is the target of the signaling storm, that is, the first network-side device in the embodiment of the present application, and the source network-side device is the source of the signaling storm, that is, the abnormal network-side device in the embodiment of the present application. The network-side device signaling storm in the embodiment of the present application can be caused by a large amount of network signaling generated during the interaction between the target network-side device and the source network-side device based on the protocol shown in Table 1, and can specifically be caused by at least one abnormality in the target network-side device and the source network-side device.

[0151] It should be noted that the characteristic of a network-side device suffering from a signaling storm is that the network-side device is in a state of abnormal resource usage. The action of the network-side device may be to continuously reject requests from other network-side devices, thereby causing a large number of rejection messages to reject requests from other network-side devices, or not processing / discarding requests from other network-side devices, resulting in an increase in the proportion of unresponsive request messages.

[0152] As an example, the first network side device is the target gNB, and the fourth network side device accessing the first network side device is at least one of the source gNB and the AMF. The signaling characteristic information in the first data may include at least one of the number of signaling failure messages between the target gNB and a source gNB and the AMF, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of malformed signaling messages, the proportion of malformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0153] It is understood that signaling between gNBs is Xn signaling. For example, Xn signaling failure messages may include Handover Preparation Failure, Retrieve UE context Failure, S-node Addition / modification Request Reject, Xn Setup Failure, etc., and Xn request signaling may include Handover Preparation Request, Retrieve UE context Request, S-node Addition / modification Request, Xn Setup Request, etc. Xn resource allocation messages may include Handover Request, S-node Addition Request, Xn Setup Request, etc.

[0154] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the gNB is the target network side device and the AMF is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the AMF is rejected by the gNB. The N2 request message specifically refers to the downlink N2 signaling request sent by the AMF. The N2 resource allocation message specifically refers to the message that the AMF requests the gNB to generate a context. Exemplarily, the N2 signaling failure message may include Initial Context Setup Failure, UE Context Modification Failure, AMF configure Failure, Retrieve UE context Failure, Handover Failure, Broadcast Session Setup / modification Failure, etc., and the N2 request message may include Initial Context Setup Request, UE Context Modification Request, AMF configure Request, Retrieve UE context Request, Handover Request, Broadcast Session Setup / modification Request. The N2 resource allocation message may include Initial Context Setup Request, AMF configure Request, Broadcast Session Setup / modification Request, etc.

[0155] As another example, the first network side device is AMF, and the fourth network side device accessing the first network side device is gNB and at least one of other NFs. The signaling characteristic information in the first data may include at least one of the number of signaling failure messages between the AMF and gNB and other NFs, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of malformed signaling messages, the proportion of malformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0156] It can be understood that the signaling between gNB and AMF is N2 signaling. Especially for the scenario where AMF is the target network side device and gNB is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by gNB is rejected by AMF, the N2 request message specifically refers to the uplink N2 signaling request sent by gNB, and the N2 resource allocation message specifically refers to the message that gNB requests AMF to generate a context. Illustratively, the N2 signaling failure message may include Handover Preparation Failure, Path Switch Failure, NG setup Failure, RAN Configuration Failure, UE Context Suspend / Resume Failure, MT Communication Handling Failure, etc., and the N2 request message may include Handover Request, Path Switch Request, NG setup Request, RAN Configuration Update, UE Context Suspend / Resume Request, MT Communication Handling Request, etc. The N2 resource allocation message may include Handover Request, NG setup Request, RAN Configuration Update, etc.

[0157] The signaling between the AMF and other NFs (e.g., SMF, AUSF, UDM, PCF, etc.) is Service-Based Architecture (SBA) signaling, which is carried on HTTP messages. For example, an SBA signaling failure message can be reflected by the response value of an HTTP Response, such as a response value in the 40x or 50x series. Pay special attention to 429 (Client Sends Too Many Requests) and 503 (Service Unavailable). For example, an SBA signaling request message can be judged using the HTTP GET or POST method. SBA resource allocation messages can include messages such as Nnrf_Register requesting the NF to establish a context.

[0158] As another example, the first network side device is SMF, and the fourth network side device accessing the first network side device is UPF and at least one of other NFs. The signaling characteristic information in the first data may include at least one of the number of signaling failure messages between SMF and UPF and other NFs, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of deformed signaling messages, the proportion of deformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0159] It is understandable that the signaling between the SMF and the UPF is N4 signaling, which is also above the PFCP protocol message. Exemplarily, the PFCP signaling failure message may include a PFCP Heartbeat Response with a rejection cause value, a PFCP PFD Management Response, or a PFCP Association Setup / Update / Release Response message. The PFCP signaling request message may include a PFCP Heartbeat Request, a PFCP PFD Management Request, or a PFCP Association Setup / Update / Release Request message.

[0160] The signaling storm occurring in the first network side device may cause a large number of rejection messages to reject the request of the fourth network side device, or not process / discard its request, resulting in an increase in the proportion of unresponsive request messages. Therefore, the characteristic information of the above signaling failure can reflect the characteristics of the signaling storm.

[0161] The signaling sent by the abnormal network side device may have some signaling characteristics, such as repeated signaling, deformed signaling, and a large number of requested resources. Therefore, the characteristic information of the above signaling anomaly can be used to infer whether it is caused by an abnormality of other network side devices other than the first network side device.

[0162] Optionally, the signaling characteristic information further includes at least one of the following:

[0163] an identifier of the first network-side device;

[0164] Category of the first network-side device;

[0165] Time period information.

[0166] In some optional embodiments of the present application, the first data may only count the signaling of the first network side device, and the signaling characteristic information may include at least one of the identification and category of the first network side device and time period information.

[0167] The time period information is used to indicate the time period for collecting signaling feature data.

[0168] Exemplarily, the identifier of the first network side device can be a cell ID, NF instance ID, TA ID, AoIID, S-NSSAI ID, etc.; the category of the first network side device can be identified by TA, AoI, S-NSSAAI, NF type, TA, AoI, S-NSSAI, etc.

[0169] For example, the signaling characteristic data may be expressed in the form of "cell ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): number of Xn signaling failure messages: 200, number of all Xn signalings: 11000; number of N2 signaling failure messages: 1800, number of all N2 signalings: 12000; ...".

[0170] Optionally, the signaling characteristic information includes at least one of the following:

[0171] The identifier of the fourth network-side device;

[0172] Category of the fourth network-side device;

[0173] Time period information.

[0174] In some optional embodiments of the present application, the second data may only count the signaling of the fourth network side device, and the signaling characteristic information may include at least one of the identification and category of the fourth network side device.

[0175] Exemplarily, the identifier of the fourth network side device can be a cell ID, NF instance ID, TA ID, AoIID, S-NSSAI ID, etc.; the category of the fourth network side device can be identified by TA, AoI, S-NSSAAI, NF type, TA, AoI, S-NSSAI, etc.

[0176] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of N2 signaling failure messages: 1200, number of all N2 signaling messages: 15000..."

[0177] In another optional embodiment of the present application, more fine-grained statistics may be performed on the signaling feature information, for example, statistics may be collected on the signaling received by the first network side device from different fourth network side devices (eg, NF1, NF2, NF3, ...).

[0178] In another optional embodiment of the present application, the signaling characteristic information of the first data may further include at least one of an identifier and a category of each fourth network-side device accessing the first network-side device.

[0179] For example, assuming that the first network side device is SMF1, the fourth network side device is AMF1, and the other network side device is AMF2, the signaling characteristic data of the first data can be expressed in the form of "SMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): AMF ID1 (2.2 0:00-2.3S-NSSAI1): Number of SBA signaling failure messages: 120, number of all SBA signalings: 12340; SMF ID1: AMF ID2 (S-NSSAI2): Number of SBA signaling failure messages: 1500, number of all SBA signalings: 16660;..."

[0180] In another optional embodiment of the present application, the signaling characteristic information of the second data may further include at least one of an identifier and a category of the fourth network side device accessing the first network side device.

[0181] For example, assuming that the first network side device is SMF1 and the fourth network side device is AMF1, the signaling characteristic data of the fourth data can be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): SMF ID1 (S-NSSAI1): Number of SBA signaling failure messages: 145, number of all SBA signaling: 12340".

[0182] It should be noted that, when the signaling characteristic information includes the identifier of the fourth network-side device, the specific abnormal network-side device can be located.

[0183] Optionally, the network capacity information includes at least one of the following:

[0184] The number of terminal contexts;

[0185] The number of connected contexts.

[0186] In the first data, the terminal context refers to the context generated by the terminal served by the first network side device, and the connection context refers to the context of the connection between the first network side device and the fourth network side device.

[0187] As an example, the first network side device is a gNB, and the network capacity information of the gNB is used to indicate the number of current network contexts of the gNB. This can be expressed as the number of all N2 or Xn contexts generated by UEs served by one or a group of gNBs (e.g., one TA or one Area of Interest), or the context of connections between network elements.

[0188] As another example, the first network side device is a target NF (e.g., an AMF or SMF), and the network capacity information of the target NF is used to indicate the number of current network contexts of the NF. This can be expressed as the number of all N2 or SBA or PFCP contexts generated by UEs served under one or a group of NFs (e.g., under one TA or one Area of Interest), or as the context of connections between network elements.

[0189] In the second data, the terminal context refers to the context generated by the terminal served by the fourth network side device, and the connection context refers to the context of the connection between the fourth network side device and the first network side device.

[0190] As an example, the fourth network side device is a gNB, and the network capacity information of the gNB is used to indicate the number of current network contexts of the gNB. This can be expressed as the number of all N2 or Xn contexts generated by UEs served by one or a group of gNBs (e.g., one TA or one Area of Interest), or the context of connections between network elements.

[0191] As another example, the fourth network side device is a target NF (e.g., an AMF or SMF), and the network capacity information of the target NF is used to indicate the number of current network contexts of the NF. The expression can be the number of all N2 or SBA or PFCP contexts generated by the UE served under one / a group of NFs (e.g., under one TA or one Area of Interest), or the context of the connection between network elements.

[0192] The network capacity information of the first network side device can be used to infer the cause of the signaling storm. For example, when the number of terminal contexts of the first network side device is small but the communication is large, the signaling storm may be caused by a network element abnormality.

[0193] The second data in this application includes at least one of signaling feature information and network capacity information of the fourth network side device.

[0194] As an example, the first network side device is the target gNB, and the fourth network side device accessing the first network side device is the AMF. The signaling characteristic information in the second data may include at least one of the number of signaling failure messages between the AMF and the target gNB, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of malformed signaling messages, the proportion of malformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0195] The network capacity information of the AMF is used to indicate the number of network contexts currently in use by the AMF. This information can be expressed as the number of all N2 contexts generated for UEs served by one or a group of AMFs (e.g., one TA or one Area of Interest), or the number of contexts for the connection between the target gNB and the AMF.

[0196] As another example, the first network side device is the target NF, and the fourth network side device accessing the first network side device is the source NF. The signaling characteristic information in the second data may include at least one of the number of signaling failure messages between the source NF and the target NF, the number of all signalings, the number of all request signalings, the proportion of all signaling failure messages in all signalings, the number of unresponsive request signalings, the proportion of unresponsive request signalings in all request signalings, the number of repeated signaling messages, the proportion of repeated signaling messages in all signalings, the number of deformed signaling messages, the proportion of deformed signaling messages in all signalings, the number of resource allocation messages, and the proportion of resource allocation messages in all signalings.

[0197] The network capacity information of the source NF is used to indicate the number of network contexts currently in the source NF. This information can be expressed as the number of all N2, SBA, or PFCP contexts generated for UEs served by a source NF or a group of source NFs (e.g., a TA or an Area of Interest), or as the number of contexts for connections between network elements.

[0198] The signaling characteristic data and capacity information contained in the second data may also refer to the relevant description of the signaling characteristic data and capacity information of the first data, which will not be repeated here.

[0199] Optionally, the analyzing function obtains the second data from the third network-side device, including:

[0200] The analysis function obtains the second data from the third network side device according to the identifier of the fourth network side device in the first data.

[0201] When the signaling characteristic information includes the identifier of the fourth network-side device, the analysis function may trigger, based on the identifier of the fourth network-side device included in the first data, the acquisition of the second data of the fourth network-side device from the third network-side device, so as to analyze the signaling characteristic information and network capacity information of a specific fourth network-side device and locate the specific abnormal network-side device. The third network-side device is the fourth network-side device, or a network-side device for managing the fourth network-side device, such as an OAM.

[0202] In an optional embodiment of the present application, the analysis function sends a first data collection request to the second network side device, including:

[0203] Upon receiving the first analysis request sent by the control function, the analysis function sends a first data collection request to the second network-side device.

[0204] The first analysis request is used to request a signaling storm analysis to be performed on the first network-side device.

[0205] It should be noted that the control function in this application can trigger the analysis function to perform signaling storm analysis on the first network side device by sending a first analysis request. The control function can be a network function consumer (NFconsumer), and the network function consumer can be, for example, a network function such as AMF, PCF, or OAM.

[0206] Optionally, the first analysis request includes at least one of the following:

[0207] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0208] an analysis target, where the analysis target is used to indicate the first network-side device;

[0209] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0210] Among them, the analysis identifier is used to indicate the current analysis, that is, signaling storm analysis. The analysis target is used to indicate the object for which the analysis is directed. The analysis target can be information that identifies one or a group of first network side devices. For example, when the first network side device is a base station, the analysis target can be a cell identifier (Cell ID), a tracking area (TA) ID, an area of interest (Area of Interest), etc.; when the first network side device is an NF, the analysis target can be information that identifies one or a group of NFs, such as NF instance ID, TAID, Area of Interest, etc. The analysis time may include at least one of the start time and the end time of the analysis. The analysis period may also be a periodic time, that is, the analysis is a periodic analysis. The analysis period will affect the setting of the time period in the signaling feature data.

[0211] Optionally, the method further includes:

[0212] Upon receiving the second analysis request sent by the control function, the analysis function sends the network performance analysis result of the first network-side device to the analysis function.

[0213] The network performance analysis result is used to indicate resource usage of the first network side device.

[0214] In an embodiment of the present application, the control function may request the analysis function to analyze the network performance of the first network-side device in advance (see 3GPP TS 23.288 6.6), thereby obtaining the resource usage of the first network-side device. The control function may trigger a signaling storm analysis for the first network-side device or the group of first network-side devices based on the resource usage. For example, if the resource usage of the first network-side device exceeds a certain threshold (CPU usage is greater than 90%), a first analysis request is sent to the analysis function, requesting the analysis function to perform a signaling storm analysis on the first network-side device.

[0215] It should be noted that the second analysis request can be implemented by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former is based on a subscription-notification model, where the subscriber (analysis function) will periodically or sporadically send messages to the control function. The latter is based on a request-response model, with a response per request.

[0216] Optionally, the method further includes:

[0217] The analysis function sends the signaling storm analysis result to the control function.

[0218] After performing signaling storm analysis on the first network side device, the analysis function may send the signaling storm analysis result to the control function so that the control function performs a signaling storm control operation according to the signaling storm analysis result to enhance the robustness of the network.

[0219] Optionally, the target data includes: current target data and historical target data; the analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device, including:

[0220] The analysis function obtains a signaling storm analysis model based on the historical target data;

[0221] The analysis function performs analysis based on the signaling storm analysis model and the current target data to obtain a signaling storm analysis result of the first network side device.

[0222] In an embodiment of the present application, a signaling storm analysis model can be trained based on historical target data. When signaling storm analysis is required, the current target data is input into the trained signaling storm analysis model for inference to obtain a signaling storm analysis result.

[0223] It is understandable that the signaling storm analysis model can be obtained through machine learning, which can be lightweight machine learning, unsupervised learning, or supervised learning. This application does not limit the specific machine learning method.

[0224] It should be noted that the signaling storm analysis model can be updated as needed, for example, periodically updated according to the most recent historical target data.

[0225] Optionally, if the signaling storm analysis is a signaling storm prediction, the signaling storm analysis result may further include at least one of the following: the confidence of the current prediction (Confidence, also called confidence, used to indicate the certainty of the prediction) and the expected time (used to indicate the time when the signaling storm is predicted to occur).

[0226] Since the signaling storm analysis model is trained based on historical target data, it can be understood as the rules generated by a large amount of historical target data. Therefore, when the current target data shows a trend that conforms to this rule, the signaling storm can be predicted, and the confidence and prediction time of the prediction can also be obtained.

[0227] Reference Figure 3 , shows a flow chart of another method for processing a signaling storm provided by an embodiment of the present application. The method is applied to control functions such as Figure 3 As shown, the method may specifically include:

[0228] Step 201: The control function receives the signaling storm analysis result sent by the analysis function;

[0229] Step 202: The control function performs a signaling storm control operation according to the signaling storm analysis result.

[0230] The signaling storm analysis result includes at least one of the following:

[0231] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0232] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0233] It should be noted that in the embodiment of the present application, the control function may be a network function consumer, and the network function consumer may be, for example, a network function such as AMF, PCF, NRF or OAM.

[0234] The analysis function may be NWDAF, which can collect various data generated in the network and perform intelligent data analysis, and finally generate corresponding data analysis results to detect or predict various events occurring in the network. Of course, the analysis function may also be other devices or network elements that can collect target data and perform data analysis, such as OAM, or external security functions (such as firewalls, intrusion detection systems, intrusion prevention systems, etc.), and this application does not limit this. For example, the analysis function in this application may be a communication device configured with an AI model, which is trained to implement a network data analysis function.

[0235] The first network side device is the target device of the signaling storm, which can be understood as the target device that is suffering from the signaling storm, or the target device that is predicted to suffer from the signaling storm through the analysis function. The identifier of the first network side device can identify a single network side device. For example, the identifier of the first network side device can be a cell identifier (cellID), NF instance ID, etc.; the identifier of the first network side device can also identify a group or multiple network side devices, such as through a tracking area (TA), an area of interest (AoI), a single network slice selection assistance information (Single Network Slice Selection Assistance Information, S-NSSAI) and other identifiers.

[0236] In an optional embodiment of the present application, the first network side device may be an access network device, such as a base station (gNB), a wireless local area network (WLAN) access point, etc.; the first network side device may also be a core network device, such as an AMF or SMF, etc., which is a network function (NF) that performs signaling interaction with other network side devices or terminals.

[0237] A network-side device signaling storm refers to a signaling storm caused by network-side signaling. This is because other network-side devices send a large amount of signaling to the first network-side device, causing the signaling received by the first network-side device to exceed its processing limit. The first network-side device needs to consume a large amount of resources to process these signalings, which in turn causes the first network-side device to be unable to work or to maintain operation at a lower efficiency.

[0238] In an embodiment of the present application, the control function may receive a signaling storm analysis result from the analysis function. Optionally, the analysis function may perform a signaling storm analysis based on the target data, obtain a signaling storm analysis result, and send the signaling storm analysis result to the control function. After receiving the signaling storm analysis result, the control function performs a signaling storm analysis control operation based on the signaling storm analysis result to enhance network robustness.

[0239] It should be noted that signaling storm analysis may be signaling storm detection, for example, detecting the number or ratio of failed messages currently sent by the first network-side device, detecting the number or ratio of unresponsive messages currently sent by the first network-side device, detecting the level of the signaling storm, or detecting the trend of the signaling storm, etc. In this case, the signaling storm analysis result is a signaling storm detection result, which may include at least one of an identifier of the first network-side device experiencing the signaling storm and a cause of the signaling storm.

[0240] Alternatively, signaling storm analysis can also be signaling storm prediction, for example, detecting the number or ratio of historical and current failure messages of the first network-side device and predicting the trend, detecting the number or ratio of historical and current unresponsive messages of the first network-side device and predicting the trend, predicting the level of the signaling storm, the changing trend of the signaling storm, predicting the time when the signaling storm is likely to occur, etc. In this case, the signaling storm analysis result is a signaling storm prediction result, which can include at least one of the identification of the first network-side device that is about to experience a signaling storm and the cause of the signaling storm.

[0241] Optionally, the cause of the signaling storm includes at least one of the following:

[0242] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0243] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0244] The signaling storm on the first network side device caused by the signaling sent by the network device may be caused by the following reasons:

[0245] 1. The first network-side device itself is abnormal. For example, the first network-side device itself experiences an abnormality, sending a large number of abnormal requests (such as duplicate messages, malformed messages, etc.) to other network-side devices and receiving replies from other network-side devices, resulting in a network signaling storm. Optionally, the abnormality of the first network-side device itself can also be expressed as a result of the first network-side device itself, such as abnormal behavior of the first network-side device and signaling looping on the first network-side device.

[0246] 2. Other network-side devices interacting with the first network-side device are abnormal. For example, other network-side devices accessing the first network-side device are in an abnormal state and continuously send abnormal messages (such as duplicate messages, malformed messages, etc.) to the first network-side device, resulting in a surge in message processing by the first network-side device. Optionally, the abnormality of other network-side devices interacting with the first network-side device can also be expressed as other network-side device reasons, other network-side device abnormalities, other network-side device behavior abnormalities, or other network-side device signaling loops.

[0247] Optionally, the signaling storm analysis result further includes at least one of the following:

[0248] The level of signaling storm;

[0249] The development trend of signaling storms;

[0250] Duration of the signaling storm;

[0251] Characteristic information of abnormal signaling;

[0252] Identification of abnormal network-side devices;

[0253] Feature information of the abnormal network-side device;

[0254] confidence level;

[0255] Prediction time.

[0256] The level of the signaling storm is used to indicate the severity of the signaling storm, and may be, for example, low, medium, or high.

[0257] The development trend of the signaling storm is used to indicate the possible subsequent trend of the signaling storm, for example, it can be rising, falling, unknown, stable, etc.

[0258] The duration of the signaling storm is used to indicate how long the signaling storm may last.

[0259] The control function can determine what control measures to take based on one or more of the signaling storm's level, development trend, and duration, such as a milder control measure like capacity expansion or a more aggressive control measure like isolation.

[0260] For example, if the level is low and the development trend is stable, the control function may take a mild control measure. If the level is high and the development trend is rising, and the duration indicates that it may last for a long time, the control function may take a more aggressive control measure.

[0261] The level, development trend, and duration of the signaling storm can help the control function determine the overall impact of the current signaling storm on the network, thereby serving as a judgment factor to influence the final control measures.

[0262] The level and trend of the signaling storm, the type of signaling involved, the characteristics of abnormal signaling, and the characteristics of abnormal network devices can all be determined by analyzing the characteristic data of signaling and network devices, especially the characteristics of signaling failures. The duration of the signaling storm can be determined by additional analysis of the time period.

[0263] In the case where the signaling storm analysis result is a signaling storm prediction result, the signaling storm analysis result may further include a confidence level and a prediction time, wherein the confidence level indicates the accuracy of the signaling storm prediction result and the prediction time indicates the predicted time when a signaling storm may occur.

[0264] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0265] Abnormal signaling message;

[0266] The signaling type of the abnormal signaling;

[0267] The proportion of abnormal signaling in all signaling.

[0268] The abnormal signaling message indicates the signaling or message that caused the signaling storm on the network device. For example, if the first network device is a gNB, the abnormal signaling message may be AMF configure failure; or if the first network device is an AMF or SMF, the abnormal signaling message may be a 503 HTTP response message, etc.

[0269] The signaling type of abnormal signaling indicates the type of signaling that caused the signaling storm on the network device. For example, if the first network device is a gNB, the signaling type of abnormal signaling can be N2; or if the first network device is an AMF or SMF, the signaling type of abnormal signaling can be HTTP.

[0270] The control function can record the characteristic information of abnormal signaling to help administrators conduct subsequent tracking and investigation when encountering unknown signaling storms.

[0271] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0272] abnormal behavior of the abnormal network side device;

[0273] The category of the abnormal network-side device.

[0274] The abnormal behavior of the abnormal network side device may include the abnormal network side device sending repeated signaling, sending malformed signaling, abnormally establishing context, and the like.

[0275] The category of the abnormal network side device is used to indicate the category of the network side device where the abnormality occurs, and can be identified by TA, AoI, S-NSSAAI, etc.

[0276] The level of the signaling storm, its development trend, the type of signaling causing the storm, the characteristics of abnormal signaling, the identification of abnormal network devices, and the characteristics of abnormal network devices can all be determined by analyzing the characteristic signaling and network device data, particularly the characteristics of signaling failures. The duration of the signaling storm can be determined by additional analysis of the time period.

[0277] The control function can determine which control method to take based on the characteristic information of abnormal network-side devices, for example, whether to control in a group manner or in a single point manner.

[0278] For example, if the abnormal behavior of the abnormal network side device is abnormal context establishment, the control function can adopt an isolation control method. If the abnormal network side devices are of the same category, the control function can adopt a group control method.

[0279] The characteristic information of the abnormal network-side device can help the control function determine the behavior or common characteristics of the abnormal network-side device, thereby serving as a judgment factor to influence the final control measures.

[0280] In some optional embodiments of the present application, before the control function receives the signaling storm analysis result sent by the analysis function, the method further includes:

[0281] The control function sends a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

[0282] The control function may trigger the analysis function to perform signaling storm analysis on the first network side device by sending a first analysis request.

[0283] Optionally, the first analysis request includes at least one of the following:

[0284] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0285] an analysis target, where the analysis target is used to indicate the first network-side device;

[0286] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0287] Among them, the analysis identifier is used to indicate the current analysis, that is, signaling storm analysis. The analysis target is used to indicate the object for which the analysis is directed. The analysis target can be information that identifies one or a group of first network side devices. For example, when the first network side device is a base station, the analysis target can be a cell identifier (Cell ID), a tracking area (TA) ID, an area of interest (Area of Interest), etc.; when the first network side device is an NF, the analysis target can be information that identifies one or a group of NFs, such as NF instance ID, TA ID, Area of Interest, etc. The analysis period can include at least one of the start time and end time of the analysis. The analysis period can also be a periodic time, that is, the analysis is a periodic analysis.

[0288] Optionally, the control function sends a first analysis request to the analysis function, including:

[0289] The control function obtains a network performance analysis result of the first network side device;

[0290] When the network performance analysis result indicates that resource usage of the first network-side device is in an abnormal state, the control function sends the first analysis request to the analysis function.

[0291] In an embodiment of the present application, the control function may obtain the network performance analysis result of the first network side device in advance, and the network performance analysis result is used to indicate the resource usage of the first network side device. The control function may send a first analysis request to the analysis function when the network performance analysis result indicates that the resource usage of the first network side device is in an abnormal state, triggering the analysis function to perform a signaling storm analysis on this or this group of first network side devices. For example, if the resource usage of the first network side device exceeds a certain threshold (CPU usage is greater than 90%), it can be considered that the resource usage of the first network side device is in an abnormal state, and the control function will be triggered to send a first analysis request to the analysis function, requesting the analysis function to perform a signaling storm analysis on the first network side device.

[0292] Optionally, the control function obtains a network performance analysis result of the first network-side device, including:

[0293] The control function sends a second analysis request to the analysis function, where the second analysis request is used to request analysis of network performance of the first network-side device;

[0294] The control function receives the network performance analysis result of the first network side device sent by the analysis function.

[0295] In an embodiment of the present application, the control function may request the analysis function to analyze the network performance of the first network side device (see 3GPP TS 23.288 6.6) through a second analysis request, thereby obtaining the network performance analysis result of the first network side device.

[0296] It should be noted that the second analysis request can be implemented by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former is based on a subscription-notification model, where the subscriber (analysis function) will periodically or sporadically send messages to the control function. The latter is based on a request-response model, with a response per request.

[0297] In the embodiment of the present application, mitigation measures can be taken for signaling storm detection, and defensive measures can be taken for signaling storm prediction.

[0298] The mitigation and protection of signaling storms are collectively referred to as signaling storm control operations. The following examples illustrate signaling storm control operations.

[0299] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0300] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the local policy of the control function for the first network side device according to the identification of the first network side device, so that the first network side device cannot be discovered.

[0301] The control function in the embodiment of the present application may be a network storage function (NF Repository Function, NRF), which is used to register, manage, and detect the status of NFs to achieve automated management of all NFs. When each NF is started, it must register with the NRF to provide services. The registration information may include the type, address, service list, etc. of the NF. In the embodiment of the present application, when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the NRF may modify the local policy for the first network side device in the NRF according to the identifier of the first network side device, so that the first network side device cannot be discovered by other network side devices. Optionally, the first network side device may temporarily be unable to discover other network side devices, thereby isolating the abnormal first network side device and reducing the interaction between the first network side device and other network side devices. The local policy may be an access control list, and the NRF sets the first network side device to be non-actively discoverable and / or non-discoverable in the access control list.

[0302] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0303] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the local policy of the control function for the abnormal network side device according to the identification of the abnormal network side device, so that the abnormal network side device cannot be discovered.

[0304] The control function in the embodiment of the present application may be an NRF. When the cause of the signaling storm indicates that the signaling storm is caused by network-side devices other than the first network-side device, the NRF may modify the local policy for the abnormal network-side device in the NRF according to the identifier of the abnormal network-side device, so that the abnormal network-side device cannot be discovered by other network-side devices. Optionally, the abnormal network-side device may temporarily not choose to discover other network-side devices, thereby isolating the abnormal network-side device and reducing the interaction between the abnormal network-side device and other network-side devices. The local policy may be an access control list, and the NRF may set the abnormal network-side device to be non-actively discoverable and / or non-discoverable in the access control list.

[0305] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0306] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the first slice information of the first network side device to second slice information according to the identifier of the first network side device, and the first slice information is different from the second slice information.

[0307] In the embodiment of the present application, the control function may be OAM or NRF. For example, when the first network-side device is the target gNB, if the cause of the signaling storm indicates that the signaling storm is caused by an abnormality of the target gNB itself, the control function may be OAM. OAM may modify the slice information to which the target gNB belongs based on the identifier of the target gNB, placing the target gNB in an isolated slice, thereby preventing other network-side devices (such as other gNBs or AMF) from selecting the target gNB for access, thereby reducing signaling interaction between the target gNB and other network-side devices.

[0308] In the case where the first network side device is the target NF, if the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the target NF itself, the control function can be OAM or NRF. The control function can modify the slice information to which the target NF belongs according to the identifier of the target NF, and place the target NF in an isolated slice, so that other network side devices (such as other NFs or gNBs) do not select the target NF for access, thereby reducing the signaling interaction between the target NF and other network side devices.

[0309] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0310] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the third slice information of the abnormal network side device to the fourth slice information according to the identification of the abnormal network side device, and the third slice information is different from the fourth slice information.

[0311] In an embodiment of the present application, the control function may be OAM or NRF. For example, when the first network-side device is the target gNB, if the cause of the signaling storm indicates that the network-side device signaling storm is caused by other network-side devices other than the first network-side device (e.g., other gNBs or AMFs), the control function may be OAM, and OAM may modify the slice information to which the abnormal network-side device belongs based on the identifier of the abnormal network-side device, and place the abnormal network-side device in an isolated slice, so that other network-side devices (e.g., other gNBs or AMFs) do not select the abnormal network-side device for access, thereby reducing signaling interaction between the abnormal network-side device and other network-side devices.

[0312] In the case where the first network side device is the target NF, if the cause of the signaling storm indicates that the network side device signaling storm is caused by other NFs other than the target NF, the control function may be OAM or NRF. The control function may modify the slice information to which the abnormal NF belongs according to the identifier of the abnormal NF, and place the abnormal NF in an isolated slice, so that other network side devices (such as other NFs or gNBs) do not select the abnormal NF for access, thereby reducing the signaling interaction between the abnormal NF and other network side devices.

[0313] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0314] When the cause of the signaling storm indicates that the network-side device signaling storm is caused by an abnormality of the first network-side device itself, the control function notifies the first network-side device to release connections with all other network-side devices.

[0315] In this embodiment of the present application, the control function may be an OAM or an AMF. For example, when the first network-side device is a target gNB, if the cause of the signaling storm indicates that the signaling storm is caused by an abnormality in the target gNB itself, the OAM may notify the target gNB to release connections with other NFs, thereby reducing signaling interactions between the abnormal target gNB and other NFs; alternatively, the AMF may release the N2 interface with the target gNB, thereby reducing signaling interactions between the AMF and the abnormal target gNB.

[0316] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0317] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the first network side device to release the connection with the abnormal network side device.

[0318] In this embodiment of the present application, the control function may be an OAM or an AMF. For example, when the first network-side device is a target gNB, the cause of the signaling storm indicates that the signaling storm is caused by a network-side device other than the target gNB. The control function may be OAM. If the abnormal network-side device includes a gNB, OAM may notify the target gNB to release the Xn connection with the abnormal gNB based on the identifier of the abnormal gNB. If the abnormal network-side device includes an AMF, OAM may notify the target gNB to release the N2 connection with the abnormal AMF.

[0319] In the case where the first network side device is the target NF, the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormal gNB other than the target NF. The control function may be an AMF, and the AMF may notify the target NF to release the N2 interface between the target NF and the abnormal gNB.

[0320] The embodiment of the present application reduces the signaling interaction between the first network side device and the abnormal network side device by releasing the connection between the first network side device and the abnormal network side device.

[0321] Optionally, the control function performs a signaling storm control operation according to the signaling storm analysis result, including:

[0322] When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the abnormal network side device to release the connection with the first network side device.

[0323] In this embodiment of the present application, the control function may be an OAM or an AMF. For example, when the first network-side device is a target gNB, the cause of the signaling storm indicates that the signaling storm is caused by a network-side device other than the target gNB. The control function may be OAM. If the abnormal network-side device includes a gNB, OAM may notify the abnormal gNB to release the Xn connection with the target gNB based on the abnormal gNB identifier. If the abnormal network-side device includes an AMF, OAM may notify the abnormal AMF to release the N2 connection with the target gNB.

[0324] In the case where the first network side device is the target NF, the cause of the signaling storm indicates that the signaling storm is caused by an abnormal gNB other than the target NF. The control function may be an AMF, and the AMF may notify the abnormal gNB to release the N2 interface between the abnormal gNB and the target NF.

[0325] The embodiment of the present application reduces the signaling interaction between the first network side device and the abnormal network side device by releasing the connection between the abnormal network side device and the first network side device.

[0326] Optionally, after releasing the connection between the abnormal network side device and the first network side device, the control function may further prevent subsequent connections between the abnormal network side device and other network side devices.

[0327] The following describes an example of a method for processing a signaling storm provided in an embodiment of the present application in conjunction with a specific application scenario.

[0328] As an example, it is detected whether the gNB (i.e., the first network side device in this application is a gNB) is subjected to a signaling attack. Figure 4 , shows a flow chart of a method for processing a signaling storm provided by an embodiment of the present application. Figure 4 As shown, the signaling storm processing method provided in the embodiment of the present application may include the following steps:

[0329] Step 1: The NF consumer sends a signaling storm analysis request to the NWDAF, requesting a signaling storm analysis. The signaling storm analysis request includes an analysis identifier and, optionally, an analysis target and an analysis period.

[0330] The analysis identifier indicates the current analysis, i.e., the signaling storm. The analysis target indicates the object of the analysis, which can be information identifying one or a group of target gNBs, such as Cell ID, TA ID, Area of Interest, etc. The analysis period indicates the start and end time of the analysis.

[0331] Optionally, the NF consumer may request the NWDAF to analyze the target gNB's network performance (see 3GPP TS 23.288 6.6) in advance to obtain the target gNB's resource usage. The NF consumer can trigger a signaling storm analysis for this target gNB or a group of target gNBs based on the resource usage. For example, if the target gNB's resource usage exceeds a certain threshold (CPU utilization greater than 90%), the signaling storm analysis request is sent to the NWDAF.

[0332] Signaling storm analysis requests can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe service (subscription notification model) or the Nnwdaf_AnalyticsInfo_Request service (request-response model). The former is based on a subscription-notification model, where the subscriber will periodically or sporadically send messages to the NF consumer. The latter is based on a request-response model, with each request receiving a reply.

[0333] Step 2: NWDAF sends a first data collection request to OAM to collect signaling feature information of the target gNB and network capacity information of the target gNB.

[0334] The first data collection request may obtain data from the OAM periodically or irregularly by invoking a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0335] Optionally, the NWDAF may also directly request the first data from the target gNB instead of indirectly through OAM.

[0336] Optionally, in addition to collecting data from the target gNB, the NWDAF can also use this method to collect data from the gNB to which it is connected.

[0337] Step 3: The NWDAF obtains first data from the OAM or the target gNB. The first data includes the gNB's signaling feature information and the gNB's network capacity information.

[0338] The signaling characteristic information of the target gNB is used to indicate the characteristics of signaling failure and / or signaling anomaly between the target gNB and the source gNB and between the target gNB and the AMF.

[0339] Signaling characteristic information may include the number of signaling failure messages between the target gNB and a specific gNB / AMF, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of duplicate signaling messages, the ratio of duplicate signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it may also include the identifier of the target NF (e.g., cell ID) and the NF type (e.g., TA, AoI, S-NSSAI).

[0340] Signaling between gNBs is Xn signaling. Exemplarily, Xn signaling failure messages may include HandoverPreparationFailure, RetrieveUEContextFailure, S-nodeAddition / ModificationRequestReject, or XnSetupFailure. Xn request signaling may include HandoverPreparationRequest, RetrieveUEContextRequest, S-nodeAddition / ModificationRequestRequest, or XnSetupRequest. Xn resource allocation messages may include HandoverRequest, S-nodeAdditionRequest, or XnSetupRequest.

[0341] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the gNB is the target network side device and the AMF is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the AMF is rejected by the gNB. The N2 request message specifically refers to the downlink N2 signaling request sent by the AMF. The N2 resource allocation message specifically refers to the message that the AMF requests the gNB to generate a context. Exemplarily, the N2 signaling failure message may include Initial Context Setup Failure, UE Context Modification Failure, AMF configure Failure, Retrieve UE context Failure, Handover Failure, Broadcast Session Setup / modification Failure, etc., and the N2 request message may include Initial Context Setup Request, UE Context Modification Request, AMF configure Request, Retrieve UE context Request, Handover Request, Broadcast Session Setup / modification Request. The N2 resource allocation message may include Initial Context Setup Request, AMF configure Request, Broadcast Session Setup / modification Request, etc.

[0342] Optionally, the signaling feature information of the target gNB further includes at least one of the following:

[0343] The identifier of the target gNB;

[0344] Category of target gNB;

[0345] Time period information.

[0346] At this time, the first data can only count the signaling of the target gNB, and the signaling characteristic information can include at least one of the identifier and category of the target gNB and time period information.

[0347] The time period information is used to indicate the time period for collecting signaling feature data.

[0348] For example, the signaling characteristic data may be expressed in the form of "cell ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): number of Xn signaling failure messages: 200, number of all Xn signalings: 11000; number of N2 signaling failure messages: 1800, number of all N2 signalings: 12000; ...".

[0349] Optionally, the signaling feature information of the target gNB further includes at least one of the following:

[0350] Identification of other gNBs or AMFs;

[0351] Category of other gNB or AMF;

[0352] Time period information.

[0353] At this point, more fine-grained statistics can be performed on the signaling feature information, such as counting the signaling received by the target gNB from different other gNBs or AMFs.

[0354] For example, the signaling characteristic data may be expressed in the form of "gNB ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): AMF ID1 (2.2 0:00-2.3S-NSSAI1): Number of N2 signaling failure messages: 120, number of all N2 signaling: 12340; gNB ID1: gNB ID2 (2.2 0:00-2.3S-NSSAI2): Number of Xn signaling failure messages: 1500, number of all Xn signaling: 16660; ... ".

[0355] It should be noted that when the signaling characteristic information contains the identifiers of other gNBs or AMFs, the specific abnormal network side device can be located.

[0356] A signaling storm may cause a large number of rejection messages to reject requests from other gNBs or AMFs, or not process or discard their requests, resulting in an increase in the proportion of unresponsive request messages. Therefore, the characteristic information of the above signaling failure can reflect the characteristics of the signaling storm.

[0357] The signaling sent by the abnormal NF may have some signaling characteristics, such as repeated signaling, malformed signaling, and a large number of requested resources. Therefore, the characteristic information of the above signaling anomalies can be used to infer whether it is caused by the NF anomaly.

[0358] The target gNB's network capacity information indicates the number of network contexts currently in the target gNB. This information can be expressed as the number of all N2 or Xn contexts generated for UEs served by a target gNB or a group of target gNBs (e.g., a TA or an Area of Interest), or as the number of contexts for connections between network elements.

[0359] The target gNB's network capacity information can be used to infer the cause of the signaling storm. For example, if the target gNB has a small number of network contexts but a high volume of traffic, it may be caused by a network element anomaly.

[0360] Step 4: Optionally, the NWDAF sends a second data collection request to the AMF or OAM to collect the signaling characteristic information of the AMF and the network capacity information of the AMF and / or the signaling characteristic information of the gNB and the network capacity information of the gNB.

[0361] It should be noted that the AMF and gNB here refer to network devices that interact with the target gNB.

[0362] If collecting data from the AMF, the second data collection request can be made by calling the Event_Exposure event reporting service of different NFs. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.

[0363] If the data is collected from the OAM, the first data collection request may obtain data from the OAM periodically or irregularly by calling a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0364] Optionally, the NWDAF may select the AMF or gNB to which the target gNB is connected to send a second data collection request.

[0365] Step 5: Optionally, the AMF / OAM sends second data to the NWDAF. The second data includes the signaling feature information of the AMF and the network capacity information of the AMF and / or the signaling feature information of the gNB and the network capacity information of the gNB.

[0366] Among them, the signaling characteristic information of the AMF is used to indicate the characteristics of the signaling failure and / or signaling abnormality between the target gNB and the AMF.

[0367] Signaling characteristic information may include the number of signaling failure messages between the AMF and the target gNB, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of duplicate signaling messages, the ratio of duplicate signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it may also include the source NF identifier (e.g., NF instance ID) and NF type (e.g., NF type, TA, AoI, S-NSSAI).

[0368] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the gNB is the target network side device and the AMF is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the AMF is rejected by the gNB. The N2 request message specifically refers to the downlink N2 signaling request sent by the AMF. The N2 resource allocation message specifically refers to the message that the AMF requests the gNB to generate a context. Exemplarily, the N2 signaling failure message may include Initial Context Setup Failure, UE Context Modification Failure, AMF configure Failure, Retrieve UE context Failure, Handover Failure, Broadcast Session Setup / modification Failure, etc., and the N2 request message may include Initial Context Setup Request, UE Context Modification Request, AMF configure Request, Retrieve UE context Request, Handover Request, Broadcast Session Setup / modification Request. The N2 resource allocation message may include Initial Context Setup Request, AMF configure Request, Broadcast Session Setup / modification Request, etc.

[0369] Signaling between gNBs is Xn signaling. Exemplarily, Xn signaling failure messages may include HandoverPreparationFailure, RetrieveUEContextFailure, S-nodeAddition / ModificationRequestReject, or XnSetupFailure. Xn request signaling may include HandoverPreparationRequest, RetrieveUEContextRequest, S-nodeAddition / ModificationRequestRequest, or XnSetupRequest. Xn resource allocation messages may include HandoverRequest, S-nodeAdditionRequest, or XnSetupRequest.

[0370] Optionally, the signaling feature information of the AMF or gNB further includes at least one of the following:

[0371] AMF or gNB identity;

[0372] Type of AMF or gNB;

[0373] Time period information.

[0374] At this time, the first data may only count the signaling of the AMF or gNB, and the signaling characteristic information may include at least one of the identification and category of the AMF or gNB and the time period information.

[0375] The time period information is used to indicate the time period for collecting signaling feature data.

[0376] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of N2 signaling failure messages: 1200, number of all N2 signaling: 15000...; gNB ID2 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of Xn signaling failure messages: 200, number of all Xn signaling: 11000".

[0377] Optionally, the signaling feature information of the target gNB further includes at least one of the following:

[0378] The identifier of the target gNB;

[0379] Category of target gNB;

[0380] Time period information.

[0381] At this point, more fine-grained statistics can be performed on the signaling feature information, such as statistics on the signaling interacting between other gNBs or AMF and the target gNB.

[0382] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): gNB ID1 (2.2 0:00-2.3S-NSSAI1): Number of N2 signaling failure messages: 120, number of all N2 signaling: 12340;" or "gNB ID2: gNB ID1 (2.2 0:00-2.3S-NSSAI2): Number of Xn signaling failure messages: 1500, number of all Xn signaling: 16660;..."

[0383] The network capacity information of the AMF is used to indicate the number of network contexts currently served by the AMF. This information can be expressed as the number of all N2 contexts generated for UEs served by one or a group of AMFs (e.g., one TA or one Area of Interest), or the number of contexts for the connection between the gNB and the AMF.

[0384] The gNB's network capacity information indicates the number of network contexts currently available on the gNB. This information can be expressed as the number of N2 or Xn contexts generated for UEs served by a gNB or a group of gNBs (e.g., a TA or an Area of Interest), or as the number of contexts for connections between network elements.

[0385] Step 6: NWDAF performs analysis based on the first data and the second data (optional) to obtain a signaling storm analysis result. The signaling analysis result may include a detection result and a prediction result.

[0386] The detection result output may include the cause of the signaling storm (e.g., a self-abnormality, an abnormality of another NF), the target (identifying the signaling storm target, which can identify a single gNB, such as the cell ID, or multiple gNBs, such as TA, AoI, S-NSSAAI). Optionally, it also includes the signaling storm level (indicating the severity of the signaling storm, such as low, medium, and high), the trend (subsequent trend of the signaling storm, such as increasing / decreasing / unknown / stable), the signaling type (e.g., N2), abnormal signaling messages (e.g., AMF configure failure), the proportion of abnormal signaling to normal signaling, the duration, the abnormal NF identifier, the abnormal NF behavior (which may include NF sending repeated signaling, NF sending malformed signaling, NF abnormal context establishment, etc.), and the NF abnormality category (which may be identified by TA, AoI, S-NSSAAI, etc.).

[0387] The output of the prediction result can be additionally increased with confidence (used to indicate the confidence of the current prediction result) and expected time (the predicted time when the signaling storm may occur) based on the above information element.

[0388] It is particularly important to note that the prediction can be achieved in the following way: NWDAF analyzes historical data and learns that the proportion of rejected signaling under normal circumstances for gNBs at a certain capacity is maintained at 2%. Based on historical signaling storm results (administrators mark signaling storms after they occur), NWDAF learns that when the proportion of rejected signaling exceeds 10%, it indicates a signaling storm has occurred. NWDAF finds that the current proportion of rejected signaling is gradually increasing from 2% to 4%, and has an upward trend. Therefore, NWDAF predicts that a signaling storm may occur in this gNB.

[0389] Step 7: NWDAF sends the above signaling storm analysis results to the NF consumer.

[0390] Step 8: Optionally, NWDAF obtains updated data from AMF / OAM.

[0391] Step 9: Optionally, the NWDAF performs analysis based on the updated data to generate an updated signaling storm analysis result.

[0392] Step 10: Optionally, the NWDAF sends the updated signaling storm analysis result to NF consume.

[0393] Step 11: The NF consumer performs control based on the signaling storm analysis results. For specific control operations, refer to the example shown in Table 2:

[0394] Table 2

[0395]

[0396]

[0397] As another example, it is detected whether AMF or SMF (ie, the first network side device in this application is AMF or SMF) is subject to a signaling attack. Figure 5 , shows a flow chart of another method for processing a signaling storm provided by an embodiment of the present application. Figure 5 As shown, the signaling storm processing method provided in the embodiment of the present application may include the following steps:

[0398] Step 1: The NF consumer sends a signaling storm analysis request to the NWDAF, requesting a signaling storm analysis. The signaling storm analysis request includes an analysis identifier and, optionally, an analysis target and an analysis period.

[0399] The analysis identifier is used to indicate the current analysis, i.e., the signaling storm; the analysis target is used to indicate the object of the analysis, which can be information identifying one or a group of NFs, such as NF instance ID, TA ID, Area of Interest, etc.; the analysis period is used to indicate the start and end time of the analysis.

[0400] Optionally, the NF consumer may request the NWDAF to analyze the network performance of the AMF / SMF in advance (see 3GPP TS 23.288 6.5), thereby obtaining the resource usage of the AMF / SMF. The NF consumer can trigger a signaling storm analysis for this or this group of AMF / SMFs based on the resource usage. For example, if the resource usage of the AMF / SMF exceeds a certain threshold (CPU usage greater than 90%), the above signaling storm analysis request is triggered to the NWDAF.

[0401] Signaling storm analysis requests can be made by calling the Nnwdaf_AnalyticsSubscription_Subscribe or Nnwdaf_AnalyticsInfo_Request services. The former uses a subscription-notification model, where the subscriber periodically or sporadically sends messages to the NF consumer. The latter uses a request-response model, with a single reply per request.

[0402] Step 2: NWDAF sends a first data collection request to OAM / target NF to collect signaling feature information of the target NF and network capacity information of the target NF (optional).

[0403] The first data collection request for OAM may obtain data from OAM periodically or irregularly by calling a subscription service (refer to the service described in 3GPP TS 28.532 Section 11.6.1.3).

[0404] The first data collection request for the target NF can be generated by calling the NF's Event_Exposure event reporting service. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.

[0405] Step 3: NWDAF obtains first data from OAM / target NF. The first data includes signaling feature information of the target NF and network capacity information of the target NF (optional).

[0406] The signaling characteristic information of the target NF is used to indicate characteristics of signaling failure and / or signaling abnormality when the target NF communicates with other NFs.

[0407] If the target NF is an AMF, the signaling characteristic information may include the number of signaling failure messages between the AMF and gNB, and between the AMF and other NFs, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of duplicate signaling messages, the ratio of duplicate signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it may also include the identifier of the target NF (e.g., NF instance ID) and the NF type (e.g., NF type, TA, AoI, S-NSSAI).

[0408] The signaling between the gNB and the AMF is N2 signaling. Especially for the scenario where the AMF is the target network side device and the gNB is the source network side device, the N2 signaling failure message specifically refers to the message that the N2 signaling request sent by the gNB is rejected by the AMF. The N2 request message specifically refers to the uplink N2 signaling request sent by the gNB. The N2 resource allocation message specifically refers to the message that the gNB requests the AMF to generate a context. Illustratively, the N2 signaling failure message may include Handover Preparation Failure, Path Switch Failure, NG setup Failure, RAN Configuration Failure, UE Context Suspend / Resume Failure, MT Communication Handling Failure, etc., and the N2 request message may include Handover Request, Path Switch Request, NG setup Request, RAN Configuration Update, UE Context Suspend / Resume Request, MT Communication Handling Request, etc. The N2 resource allocation message may include Handover Request, NG setup Request, RAN Configuration Update, etc.

[0409] Signaling between the AMF and other NFs (e.g., SMF, AUSF, UDM, PCF, etc.) is SBA signaling, carried over HTTP messages. For example, an SBA signaling failure message can be reflected by an HTTP response value, such as a 40x or 50x response value. Pay particular attention to 429 (Client Sends Too Many Requests) and 503 (Service Unavailable), which are common responses during signaling storms. For example, SBA signaling request messages can be determined using the HTTP GET or POST method. SBA resource allocation messages can include messages such as Nnrf_Register requesting NF context establishment.

[0410] If the target NF is an SMF, the signaling characteristic information may include the number of signaling failure messages between the SMF and the UPF, and between the SMF and other NFs (also SBA), the number of all signaling, the number of all request signaling, the ratio of all signaling failure messages to all signaling, the number of unresponsive request signaling, and the ratio of unresponsive request signaling to all request signaling. Optionally, it may also include the number of repeated signaling messages, the ratio of repeated signaling messages to all signaling, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling. Optionally, it also includes the identifier of the source NF (e.g., NF instance ID) and the type of NF (e.g., NF type, TA, AoI, S-NSSAI), etc.

[0411] Signaling between the SMF and UPF is N4 signaling, which is also based on PFCP protocol messages. For example, PFCP signaling failure messages can include PFCP Heartbeat Response, PFCP PFD Management Response, and PFCP Association Setup / Update / ReleaseResponse messages with a rejection cause value. PFCP signaling request messages can include PFCP Heartbeat Request, PFCP PFD Management Request, and PFCP Association Setup / Update / Release Request messages.

[0412] If the target NF is another NF, the signaling feature information is the signaling feature message between NFs (SBA).

[0413] Optionally, the signaling feature information of the target NF further includes at least one of the following:

[0414] The identification of the target NF;

[0415] Category of target NF;

[0416] Time period information.

[0417] At this time, the first data may only count the signaling of the target NF, and the signaling characteristic information may include at least one of the identifier and category of the target NF and time period information.

[0418] The time period information is used to indicate the time period for collecting signaling feature data.

[0419] For example, the signaling characteristic data may be expressed in the form of "AMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): Number of N2 signaling failure messages: 200, number of all N2 signalings: 11000; number of SBA signaling failure messages: 1800, number of all SBA signalings: 12000; ... ".

[0420] Optionally, the signaling feature information of the target NF further includes at least one of the following:

[0421] Other NF identification;

[0422] Other categories of NF;

[0423] Time period information.

[0424] At this time, more fine-grained statistics can be performed on the signaling feature information, such as counting the signaling received by the target NF from different other NFs.

[0425] For example, the signaling characteristic data may be expressed in the form of "SMF ID1 (2.2 0:00-2.3 12:00, S-NSSAI1): AMF ID1 (2.2 0:00-2.3S-NSSAI1): Number of SBA signaling failure messages: 120, number of all SBA signalings: 12340; SMF ID1: UPF ID1 (2.2 0:00-2.3S-NSSAI2): Number of PFCP signaling failure messages: 1500, number of all PFCP signalings: 16660;..."

[0426] It should be noted that, when the signaling characteristic information includes the identifier of other NFs, the specific abnormal network-side device can be located.

[0427] A signaling storm may cause a large number of rejection messages to reject requests from other NFs, or not process or discard their requests, resulting in an increase in the proportion of unresponsive request messages. Therefore, the characteristic information of the above signaling failure can reflect the characteristics of the signaling storm.

[0428] The signaling sent by the abnormal NF may have some signaling characteristics, such as repeated signaling, malformed signaling, and a large number of requested resources. Therefore, the characteristic information of the above signaling anomalies can be used to infer whether it is caused by the NF anomaly.

[0429] The target NF's network capacity information indicates the number of network contexts currently in the NF. This information can be expressed as the number of all N2, SBA, or PFCP contexts generated for UEs served by a NF or a group of NFs (e.g., a TA or an Area of Interest), or as the number of contexts for connections between network elements.

[0430] The network capacity information of the NF can be used to infer the cause of the signaling storm. For example, when the number of network contexts of the NF is small but the communication is high, it may be caused by a network element abnormality.

[0431] Step 4: Optionally, the NWDAF sends a second data collection request to the OAM / source NF to collect signaling feature information of the source NF and network capacity information of the source NF (optional).

[0432] If data is collected from the source NF, the second data collection request can be made by calling the Event_Exposure event reporting service of a different NF. This can be based on a subscription-notification model, where the subscriber will periodically or irregularly send messages to the NWDAF. Alternatively, it can be based on a request-response model, where each request is responded to once.

[0433] If the data is collected from the OAM, the first data collection request may obtain data from the OAM periodically or irregularly by calling a subscription service (refer to the service described in Section 11.6.1.3 of 3GPP TS 28.532).

[0434] Optionally, the NWDAF may select the NF to which the target NF is connected to send the data collection request.

[0435] Step 5: Optionally, the OAM / source NF sends second data to the NWDAF. The second data is the signaling feature information of the source NF and the network capacity information of the source NF (optional).

[0436] The signaling characteristic information of the source NF is used to indicate the characteristics of the signaling failure and / or signaling anomaly between the source NF and the target NF.

[0437] The signaling characteristic information may include the number of signaling failure messages between the source NF and the target NF, the number of all signaling messages, the number of all request signaling messages, the ratio of all signaling failure messages to all signaling messages, the number of unresponsive request signaling messages, and the ratio of unresponsive request signaling messages to all request signaling messages. Optionally, it may also include the number of repeated signaling messages, the ratio of repeated signaling messages to all signaling messages, the number of malformed signaling messages, the ratio of malformed signaling messages to all signaling messages, the number of resource allocation messages, and the ratio of resource allocation messages to all signaling messages. Optionally, it also includes the identifier of the target NF (e.g., NF instance ID) and the type of NF (e.g., NF type, TA, AoI, S-NSSAI), etc.

[0438] The NF message is the same as step 3.

[0439] The network capacity information of the source NF is used to indicate the number of network contexts currently in the NF. This information can be expressed as the number of all N2, SBA, or PFCP contexts generated for UEs served by a NF or a group of NFs (e.g., a TA or an Area of Interest), or as the number of contexts for connections between network elements.

[0440] Step 6: NWDAF performs analysis based on the first data and the second data (optional) to obtain a signaling storm analysis result. The signaling analysis result may include a detection result and a prediction result.

[0441] The output of the detection results may include the cause of the signaling storm (e.g., abnormality of the NF itself, abnormality of other NFs), target (identifying the signaling storm target, which may identify a single NF, such as NF instance ID, or multiple NFs, such as NFtype, TA, AoI, S-NSSAAI). Optionally, it also includes the level of the signaling storm (indicating the severity of the signaling storm, such as low, medium, and high), trend (subsequent trend of the signaling storm, such as rising / falling / unknown / stable), signaling type (e.g., HTTP), abnormal signaling message (e.g., HTTP response of 503), the proportion of abnormal signaling to normal signaling, duration, abnormal NF identification, NF abnormal behavior (including NF sending repeated signaling, NF sending malformed signaling, NF abnormal context establishment, etc.), and NF abnormality category (which may be identified by TA, AoI, S-NSSAAI, etc.).

[0442] The output of the prediction result can be additionally increased with confidence (used to indicate the confidence of the current prediction result) and expected time (the predicted time when the signaling storm may occur) based on the above information element.

[0443] It is particularly important to note that the prediction can be achieved in the following way: NWDAF analyzes historical data and learns that under normal circumstances, the proportion of rejected signals for NFs at a certain capacity remains at 2%. Based on historical signaling storm results (administrators mark signaling storms after they occur), NWDAF learns that when the proportion of rejected signals exceeds 10%, it indicates a signaling storm has occurred. NWDAF finds that the current proportion of rejected signals has gradually increased from 2% to 4% and has an upward trend. Therefore, NWDAF predicts that a signaling storm may occur in this NF.

[0444] Step 7: NWDAF sends the above signaling storm analysis results to the NF consumer.

[0445] Step 8: Optionally, NWDAF obtains updated data from NF / OAM.

[0446] Step 9: Optionally, the NWDAF performs analysis based on the updated data to generate an updated signaling storm analysis result.

[0447] Step 10: Optionally, the NWDAF sends the updated signaling storm analysis result to NF consume.

[0448] Step 11: The NF consumer performs control based on the signaling storm analysis results. For specific control operations, refer to the example shown in Table 3:

[0449] Table 3

[0450]

[0451] The signaling storm processing method provided in the embodiment of the present application can be executed by a signaling storm processing device. In the embodiment of the present application, the signaling storm processing device executing the signaling storm processing method is used as an example to illustrate the signaling storm processing device provided in the embodiment of the present application.

[0452] The embodiment of the present application provides a device for processing a signaling storm. Figure 6 , shows a structural block diagram of a signaling storm processing device provided by an embodiment of the present application, which can be applied to analysis functions, such as Figure 6 As shown, the device may specifically include:

[0453] Acquisition module 301, used to acquire target data;

[0454] An analysis module 302 is configured to analyze the target data to obtain a signaling storm analysis result of the first network-side device;

[0455] The signaling storm analysis result includes at least one of the following:

[0456] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0457] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0458] Optionally, the reason includes at least one of the following:

[0459] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0460] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0461] Optionally, the signaling storm analysis result further includes at least one of the following:

[0462] The level of signaling storm;

[0463] The development trend of signaling storms;

[0464] Duration of the signaling storm;

[0465] Characteristic information of abnormal signaling;

[0466] an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device that interacts with the first network device;

[0467] Feature information of the abnormal network-side device;

[0468] confidence level;

[0469] Prediction time.

[0470] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0471] Abnormal signaling message;

[0472] The signaling type of the abnormal signaling;

[0473] The proportion of abnormal signaling in all signaling.

[0474] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0475] abnormal behavior of the abnormal network side device;

[0476] The category of the abnormal network-side device.

[0477] Optionally, the acquisition module includes:

[0478] The first acquisition submodule is configured to acquire the first data from a second network-side device, wherein the second network-side device includes at least one of the following:

[0479] the first network-side device;

[0480] A network-side device for managing the first network-side device.

[0481] Optionally, the first data includes at least one of the following:

[0482] signaling characteristic information of the first network-side device;

[0483] Network capacity information of the first network-side device.

[0484] Optionally, the acquisition module further includes:

[0485] The second acquisition submodule is configured to acquire second data from a third network-side device; the third network-side device includes at least one of the following:

[0486] a fourth network-side device accessing the first network-side device;

[0487] A network-side device for managing the fourth network-side device.

[0488] Optionally, the second data includes at least one of the following:

[0489] signaling characteristic information of the fourth network-side device;

[0490] Network capacity information of the fourth network-side device.

[0491] Optionally, the signaling characteristic information includes at least one of the following:

[0492] Number of signaling failure messages;

[0493] The number of all signaling;

[0494] The proportion of signaling failure messages in all signaling;

[0495] The number of unresponsive request signals;

[0496] The proportion of unresponsive request signals in all request signals;

[0497] The number of repeated signaling messages;

[0498] The proportion of repeated signaling messages in all signaling;

[0499] The number of malformed signaling messages;

[0500] The proportion of malformed signaling messages in all signaling messages;

[0501] The number of resource allocation messages;

[0502] The proportion of resource allocation messages in all signaling.

[0503] Optionally, the signaling characteristic information further includes at least one of the following:

[0504] an identifier of the first network-side device;

[0505] Category of the first network-side device;

[0506] Time period information, where the time period information is used to indicate a time period for collecting the signaling characteristic information.

[0507] Optionally, the signaling characteristic information includes at least one of the following:

[0508] The identifier of the fourth network-side device;

[0509] The category of the fourth network-side device.

[0510] Optionally, the second acquisition submodule includes:

[0511] The second data acquiring unit is configured to acquire the second data from the third network side device according to the identifier of the fourth network side device in the first data.

[0512] Optionally, the network capacity information includes at least one of the following:

[0513] The number of terminal contexts;

[0514] The number of connected contexts.

[0515] Optionally, the acquisition module further includes:

[0516] The first request sending submodule is used to send a first data collection request to the second network side device.

[0517] Optionally, the first request sending submodule includes:

[0518] a first request sending unit, configured to send a first data collection request to the second network-side device upon receiving the first analysis request sent by the control function;

[0519] The first analysis request is used to request a signaling storm analysis to be performed on the first network-side device.

[0520] Optionally, the first analysis request includes at least one of the following:

[0521] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0522] an analysis target, where the analysis target is used to indicate the first network device;

[0523] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0524] Optionally, the device further comprises:

[0525] The network performance analysis result sending module is used to send the network performance analysis result of the first network side device to the analysis function when receiving the second analysis request sent by the control function.

[0526] Optionally, the device further comprises:

[0527] The signaling storm analysis result sending module is used to send the signaling storm analysis result to the control function.

[0528] Optionally, the target data includes: current target data and historical target data;

[0529] The analysis module includes:

[0530] A model training submodule, configured to obtain a signaling storm analysis model based on the historical target data;

[0531] The analysis submodule is configured to perform analysis based on the signaling storm analysis model and the current target data to obtain a signaling storm analysis result of the first network-side device.

[0532] Optionally, the network-side device for managing the first network-side device, or the network-side device for managing the fourth network-side device, includes an operation, administration, and maintenance function OAM.

[0533] Optionally, when the first network side device includes an access network device, the fourth network side device includes other access network devices other than the first network side device, or the fourth network side device includes a core network device; when the first network side device includes a core network device, and the fourth network side device includes a core network device, the fourth network side device includes other core network devices other than the first network side device, access network devices, and at least one of other network functions.

[0534] Optionally, the control function comprises a network function consumer.

[0535] Optionally, the analysis function includes a network data analysis function NWDAF.

[0536] The signaling storm processing device provided in the embodiment of the present application can achieve Figure 2 The various processes implemented by the method embodiment achieve the same technical effect and are not described here again to avoid repetition.

[0537] The embodiment of the present application also provides another signaling storm processing device. Figure 7 , shows a structural block diagram of another signaling storm processing device provided by an embodiment of the present application, which can be applied to control functions such as Figure 7 As shown, the device may specifically include:

[0538] Analysis result receiving module 401, used to receive the signaling storm analysis result sent by the analysis function;

[0539] A signaling storm control module 402 is configured to perform a signaling storm control operation according to the signaling storm analysis result;

[0540] The signaling storm analysis result includes at least one of the following:

[0541] a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device;

[0542] An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

[0543] Optionally, the reason includes at least one of the following:

[0544] The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself;

[0545] The network-side device signaling storm is caused by other network-side devices except the first network-side device.

[0546] Optionally, the signaling storm analysis result further includes at least one of the following:

[0547] The level of signaling storm;

[0548] The development trend of signaling storms;

[0549] Duration of the signaling storm;

[0550] Characteristic information of abnormal signaling;

[0551] an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device that interacts with the first network device;

[0552] Feature information of the abnormal network-side device;

[0553] confidence level;

[0554] Prediction time.

[0555] Optionally, the characteristic information of the abnormal signaling includes at least one of the following:

[0556] Abnormal signaling message;

[0557] The signaling type of the abnormal signaling;

[0558] The proportion of abnormal signaling in all signaling.

[0559] Optionally, the characteristic information of the abnormal network-side device includes at least one of the following:

[0560] abnormal behavior of the abnormal network side device;

[0561] The category of the abnormal network-side device.

[0562] Optionally, the device further comprises:

[0563] The first analysis request sending module is used to send a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

[0564] Optionally, the first analysis request includes at least one of the following:

[0565] An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis;

[0566] an analysis target, where the analysis target is used to indicate the first network-side device;

[0567] Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

[0568] Optionally, the first analysis request sending module includes:

[0569] A network performance analysis result acquisition submodule, configured to acquire a network performance analysis result of the first network-side device;

[0570] The first analysis request sending submodule is used to send the first analysis request to the analysis function when the network performance analysis result indicates that the resource usage of the first network side device is in an abnormal state.

[0571] Optionally, the network performance analysis result acquisition submodule includes:

[0572] A second analysis request sending unit, configured to send a second analysis request to the analysis function, wherein the second analysis request is used to request analysis of network performance of the first network-side device;

[0573] A network performance analysis result receiving unit is used to receive the network performance analysis result of the first network side device sent by the analysis function.

[0574] Optionally, the signaling storm control module includes:

[0575] The first control submodule is used to modify the local policy for the first network side device in the control function according to the identification of the first network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, so that the first network side device cannot be discovered.

[0576] Optionally, the signaling storm control module includes:

[0577] The second control submodule is used to modify the local policy for the abnormal network side device in the control function according to the identification of the abnormal network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identification of the abnormal network side device, so that the abnormal network side device cannot be discovered.

[0578] Optionally, the signaling storm control module includes:

[0579] The third control submodule is used to modify the first slice information of the first network side device to the second slice information according to the identification of the first network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by the abnormality of the first network side device itself, and the first slice information is different from the second slice information.

[0580] Optionally, the signaling storm control module includes:

[0581] The fourth control submodule is used to modify the third slice information of the abnormal network side device to the fourth slice information according to the identifier of the abnormal network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identifier of the abnormal network side device, and the third slice information is different from the fourth slice information.

[0582] Optionally, the signaling storm control module includes:

[0583] The fifth control submodule is configured to notify the first network side device to release connections with all other network side devices when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself.

[0584] Optionally, the signaling storm control module includes:

[0585] The sixth control submodule is used to notify the first network side device to release the connection with the abnormal network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identification of the abnormal network side device.

[0586] Optionally, the signaling storm control module includes:

[0587] The seventh control submodule is used to notify the abnormal network side device to release the connection with the first network side device when the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices and the signaling storm analysis result includes the identification of the abnormal network side device.

[0588] The signaling storm processing device provided in the embodiment of the present application can achieve Figure 3 The various processes implemented by the method embodiment achieve the same technical effect and are not described here again to avoid repetition.

[0589] Optional, such as Figure 8 As shown, an embodiment of the present application further provides a communication device 900, including a processor 901 and a memory 902, wherein the memory 902 stores a program or instruction that can be run on the processor 901. For example, when the communication device 900 is a network-side device, the program or instruction is executed by the processor 901 to implement the various steps of the embodiment of the method for handling a signaling storm described in the first aspect above, and can achieve the same technical effect. When the communication device 900 is a terminal device, the program or instruction is executed by the processor 901 to implement the various steps of the embodiment of the method for handling a signaling storm described in the second aspect above, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0590] The embodiment of the present application further provides a network side device, including a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run a program or instruction to implement the following Figure 2 or Figure 3 The network side device embodiment corresponds to the above network side device method embodiment, and each implementation process and implementation method of the above method embodiment are applicable to the network side device embodiment and can achieve the same technical effect.

[0591] Specifically, the embodiment of the present application also provides a network side device, such as Figure 9As shown, network-side device 1100 includes an antenna 111, a radio frequency device 112, a baseband device 113, a processor 114, and a memory 115. Antenna 111 is connected to radio frequency device 112. In the uplink direction, radio frequency device 112 receives information via antenna 111 and sends the received information to baseband device 113 for processing. In the downlink direction, baseband device 113 processes the information to be transmitted and sends it to radio frequency device 112. Radio frequency device 112 processes the received information and then sends it through antenna 111.

[0592] The method executed by the network-side device in the above embodiment may be implemented in the baseband device 113 , which includes a baseband processor.

[0593] The baseband device 113 may include, for example, at least one baseband board on which a plurality of chips are arranged, such as Figure 9 As shown, one of the chips is, for example, a baseband processor, which is connected to the memory 115 via a bus interface to call the program in the memory 115 to execute the network device operations shown in the above method embodiment.

[0594] The network side device may further include a network interface 116, which is, for example, a common public radio interface (CPRI).

[0595] Specifically, the network side device 1100 of the embodiment of the present invention further includes: instructions or programs stored in the memory 115 and executable on the processor 114, and the processor 114 calls the instructions or programs in the memory 115 to execute. Figure 6 or Figure 7 The methods executed by the modules shown achieve the same technical effects, so they will not be described here to avoid repetition.

[0596] The embodiment of the present application also provides a network side device. Figure 10 As shown, the network side device 1200 includes: a processor 1201, a network interface 1202 and a memory 1203. The network interface 1202 is, for example, a common public radio interface (CPRI).

[0597] Specifically, the network side device 1200 of the embodiment of the present invention further includes: instructions or programs stored in the memory 1203 and executable on the processor 1201, and the processor 1201 calls the instructions or programs in the memory 1203 to execute. Figure 6 or Figure 7 The methods executed by the modules shown achieve the same technical effects, so they will not be described here to avoid repetition.

[0598] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned signaling storm processing method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0599] The processor is the processor in the terminal device described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0600] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned signaling storm processing method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0601] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0602] An embodiment of the present application further provides a computer program / program product, which is stored in a storage medium. The computer program / program product is executed by at least one processor to implement the various processes of the above-mentioned signaling storm processing method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0603] An embodiment of the present application also provides a signaling storm processing system, including: a terminal device and a network side device, wherein the terminal can be used to execute the steps of the signaling storm processing method described in the second aspect above, and the network side device can be used to execute the steps of the signaling storm processing method described in the first aspect above.

[0604] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0605] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0606] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A method for processing a signaling storm, characterized in that: The method comprises: The analysis function obtains target data; The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

2. The method according to claim 1, characterized in that The reasons include at least one of the following: The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself; The network-side device signaling storm is caused by other network-side devices except the first network-side device.

3. The method according to claims 1 to 2, characterized in that The signaling storm analysis result also includes at least one of the following: The level of signaling storm; The development trend of signaling storms; Duration of the signaling storm; Characteristic information of abnormal signaling; an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device that interacts with the first network device; Feature information of the abnormal network-side device; confidence level; Prediction time.

4. The method according to claim 3, characterized in that The characteristic information of the abnormal signaling includes at least one of the following: Abnormal signaling message; The signaling type of the abnormal signaling; The proportion of abnormal signaling in all signaling.

5. The method according to claims 3 to 4, characterized in that The characteristic information of the abnormal network side device includes at least one of the following: abnormal behavior of the abnormal network side device; The category of the abnormal network-side device.

6. The method according to claims 1 to 5, characterized in that The analysis function obtains target data, including: The analysis function obtains the first data from a second network-side device; the second network-side device includes at least one of the following: the first network-side device; A network-side device for managing the first network-side device.

7. The method according to claim 6, characterized in that The first data includes at least one of the following: signaling characteristic information of the first network-side device; Network capacity information of the first network-side device.

8. The method according to claims 6 to 7, characterized in that The analysis function acquires target data and further includes: The analysis function obtains the second data from a third network-side device; the third network-side device includes at least one of the following: a fourth network-side device accessing the first network-side device; A network-side device for managing the fourth network-side device.

9. The method according to claim 8, characterized in that The second data includes at least one of the following: signaling characteristic information of the fourth network-side device; Network capacity information of the fourth network-side device.

10. The method according to claim 7 or 9, characterized in that The signaling characteristic information includes at least one of the following: Number of signaling failure messages; The number of all signaling; The proportion of signaling failure messages in all signaling; The number of unresponsive request signals; The proportion of unresponsive request signals in all request signals; The number of repeated signaling messages; The proportion of repeated signaling messages in all signaling; The number of malformed signaling messages; The proportion of malformed signaling messages in all signaling messages; The number of resource allocation messages; The proportion of resource allocation messages in all signaling.

11. The method according to claim 10, characterized in that The signaling characteristic information also includes at least one of the following: an identifier of the first network-side device; Category of the first network-side device; Time period information, where the time period information is used to indicate a time period for collecting the signaling characteristic information.

12. The method according to claim 10 or 11, characterized in that The signaling characteristic information includes at least one of the following: The identifier of the fourth network-side device; The category of the fourth network-side device.

13. The method according to claim 12, characterized in that The analysis function obtains the second data from the third network side device, including: The analysis function obtains the second data from the third network side device according to the identifier of the fourth network side device in the first data.

14. The method according to claim 7 or 9, characterized in that The network capacity information includes at least one of the following: The number of terminal contexts; The number of connected contexts.

15. The method according to claims 6 to 14, characterized in that Before the analysis function obtains the first data from the second network-side device, the method further includes: The analysis function sends a first data collection request to the second network side device.

16. The method according to claim 15, characterized in that The analysis function sends a first data collection request to the second network side device, including: The analysis function sends a first data collection request to the second network side device when receiving the first analysis request sent by the control function; The first analysis request is used to request a signaling storm analysis to be performed on the first network-side device.

17. The method according to claim 16, characterized in that The first analysis request includes at least one of the following: An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis; an analysis target, where the analysis target is used to indicate the first network device; Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

18. The method according to claims 16 to 17, characterized in that The method further comprises: Upon receiving the second analysis request sent by the control function, the analysis function sends the network performance analysis result of the first network-side device to the analysis function.

19. The method according to claims 16 to 18, characterized in that The method further comprises: The analysis function sends the signaling storm analysis result to the control function.

20. The method according to claims 1 to 19, characterized in that The target data includes: current target data and historical target data; The analysis function analyzes the target data to obtain a signaling storm analysis result of the first network side device, including: The analysis function obtains a signaling storm analysis model based on the historical target data; The analysis function performs analysis based on the signaling storm analysis model and the current target data to obtain a signaling storm analysis result of the first network side device.

21. The method according to claim 8, characterized in that The network-side device for managing the first network-side device, or the network-side device for managing the fourth network-side device, includes an operation, administration, and maintenance function OAM.

22. The method according to claim 8, characterized in that In the case where the first network side device includes an access network device, the fourth network side device includes other access network devices other than the first network side device, or the fourth network side device includes a core network device; in the case where the first network side device includes a core network device, and the fourth network side device includes a core network device, the fourth network side device includes other core network devices other than the first network side device, access network devices and at least one of other network functions.

23. The method according to claims 16 to 19, characterized in that The control function comprises a network function consumer.

24. The method according to claims 1 to 23, characterized in that The analysis function includes a network data analysis function NWDAF.

25. A method for processing a signaling storm, characterized in that: The method comprises: The control function receives the signaling storm analysis result sent by the analysis function; The control function performs a signaling storm control operation according to the signaling storm analysis result; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

26. The method according to claim 25, characterized in that The reasons include at least one of the following: The signaling storm of the network-side device is caused by an abnormality of the first network-side device itself; The network-side device signaling storm is caused by other network-side devices except the first network-side device.

27. The method according to claims 25 to 26, characterized in that The signaling storm analysis result also includes at least one of the following: The level of signaling storm; The development trend of signaling storms; Duration of the signaling storm; Characteristic information of abnormal signaling; an identifier of an abnormal network-side device, where the abnormal network-side device is a network-side device that interacts with the first network device; Feature information of the abnormal network-side device; confidence level; Prediction time.

28. The method according to claim 27, characterized in that The characteristic information of the abnormal signaling includes at least one of the following: Abnormal signaling message; The signaling type of the abnormal signaling; The proportion of abnormal signaling in all signaling.

29. The method according to claims 27 to 28, characterized in that The characteristic information of the abnormal network side device includes at least one of the following: abnormal behavior of the abnormal network side device; The category of the abnormal network-side device.

30. The method according to claims 25 to 29, characterized in that Before the control function receives the signaling storm analysis result sent by the analysis function, the method further includes: The control function sends a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

31. The method according to claim 30, characterized in that The first analysis request includes at least one of the following: An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis; an analysis target, where the analysis target is used to indicate the first network-side device; Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

32. The method according to claims 30 to 31, characterized in that The control function sends a first analysis request to the analysis function, comprising: The control function obtains a network performance analysis result of the first network side device; In a case where the network performance analysis result indicates that resource usage of the first network-side device is in an abnormal state, the control function sends the first analysis request to the analysis function.

33. The method according to claim 32, characterized in that The control function obtains the network performance analysis result of the first network side device, including: The control function sends a second analysis request to the analysis function, where the second analysis request is used to request analysis of network performance of the first network-side device; The control function receives the network performance analysis result of the first network side device sent by the analysis function.

34. The method according to claims 26 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the local policy of the control function for the first network side device according to the identification of the first network side device, so that the first network side device cannot be discovered.

35. The method according to claims 27 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the local policy of the control function for the abnormal network side device according to the identification of the abnormal network side device, so that the abnormal network side device cannot be discovered.

36. The method according to claims 26 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by an abnormality of the first network side device itself, the control function modifies the first slice information of the first network side device to second slice information according to the identifier of the first network side device, and the first slice information is different from the second slice information.

37. The method according to claims 27 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function modifies the third slice information of the abnormal network side device to the fourth slice information according to the identification of the abnormal network side device, and the third slice information is different from the fourth slice information.

38. The method according to claims 26 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the network-side device signaling storm is caused by an abnormality of the first network-side device itself, the control function notifies the first network-side device to release connections with all other network-side devices.

39. The method according to claims 27 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the first network side device to release the connection with the abnormal network side device.

40. The method according to claims 27 to 33, characterized in that The control function performs a signaling storm control operation according to the signaling storm analysis result, including: When the cause of the signaling storm indicates that the signaling storm of the network side device is caused by other network side devices, and the signaling storm analysis result includes the identification of the abnormal network side device, the control function notifies the abnormal network side device to release the connection with the first network side device.

41. A signaling storm processing device, characterized in that: Applied to the analysis function, the device comprises: Acquisition module, used to obtain target data; An analysis module, configured to analyze the target data to obtain a signaling storm analysis result of the first network-side device; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

42. The processing device according to claim 41, characterized in that The acquisition module includes: A first acquisition submodule, configured to acquire first data from a second network-side device; The second network-side device includes at least one of the following: the first network-side device; A network-side device for managing the first network-side device.

43. The processing device according to claim 42, characterized in that The first data includes at least one of the following: signaling characteristic information of the first network-side device; Network capacity information of the first network-side device.

44. The processing device according to claim 42 or 43, characterized in that The acquisition module further includes: A second acquisition submodule, configured to acquire second data from a third network-side device; The third network-side device includes at least one of the following: a fourth network-side device accessing the first network-side device; A network-side device for managing the fourth network-side device.

45. A signaling storm processing device, characterized in that: Applied to the control function, the device comprises: An analysis result receiving module is used to receive the signaling storm analysis results sent by the analysis function; A signaling storm control module, configured to perform a signaling storm control operation according to the signaling storm analysis result; The signaling storm analysis result includes at least one of the following: a cause of the signaling storm, the cause including indication information indicating that the signaling storm is a signaling storm of a network-side device; An identifier of a first network-side device, where the first network-side device is a target device of the signaling storm.

46. The processing device according to claim 45, characterized in that The processing device further includes: The first analysis request sending module is used to send a first analysis request to the analysis function, where the first analysis request is used to request a signaling storm analysis to be performed on the first network side device.

47. The processing device according to claim 46, characterized in that The first analysis request includes at least one of the following: An analysis identifier, where the analysis identifier is used to indicate a signaling storm analysis; an analysis target, where the analysis target is used to indicate the first network-side device; Analysis period, where the analysis period is used to indicate the time for performing signaling storm analysis.

48. The processing device according to claim 46 or 47, characterized in that The first analysis request sending module includes: A network performance analysis result acquisition submodule, configured to acquire a network performance analysis result of the first network-side device; The first analysis request sending submodule is used to send the first analysis request to the analysis function when the network performance analysis result indicates that the resource usage of the first network side device is in an abnormal state.

49. The processing device according to claim 48, characterized in that The network performance analysis result acquisition submodule includes: A second analysis request sending unit, configured to send a second analysis request to the analysis function, wherein the second analysis request is used to request analysis of network performance of the first network-side device; A network performance analysis result receiving unit is used to receive the network performance analysis result of the first network side device sent by the analysis function.

50. A communication device, characterized in that It includes a processor and a memory, the memory storing a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, it implements the steps of the method for processing a signaling storm as described in any one of claims 1 to 24, or implements the steps of the method for processing a signaling storm as described in any one of claims 25 to 40.

51. A readable storage medium, characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, it implements the method for processing a signaling storm as described in any one of claims 1 to 24, or implements the steps of the method for processing a signaling storm as described in any one of claims 25 to 40.

52. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the steps of the method for processing a signaling storm as described in any one of claims 1 to 24, or the method, when executed by a processor, implement the steps of the method for processing a signaling storm as described in any one of claims 25 to 40.