Method for predicting and / or detecting control signaling that has a risk of at least partially overloading a mobile communication network - Patent Application 20070122997

The NWDAF with machine learning models predicts and detects anomalous control signaling in mobile networks, addressing signaling storms to minimize service disruptions and maintain network stability.

JP2026508457AActive Publication Date: 2026-03-11NTT DOCOMO INC
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-01-17
Publication Date
2026-03-11

AI Technical Summary

Technical Problem

Mobile communication networks experience unpredictable spikes in signaling loads, known as signaling storms, which can lead to overloading and service failures due to events like IoT device deployments, causing poor user experience and SLA penalties.

Method used

A method utilizing a Network Data Analytics Function (NWDAF) with machine learning models to predict and detect anomalous control signaling patterns by collecting metrics and notifications from network components, triggering mitigation mechanisms to prevent overload.

Benefits of technology

Early detection and mitigation of signaling storms reduce service outage times, ensuring minimal disruption and maintaining network performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026508457000001_ABST
    Figure 2026508457000001_ABST
Patent Text Reader

Abstract

According to one embodiment, a method for predicting and / or detecting control signaling that has a risk of at least partially overloading a mobile communication network is described, comprising the steps of collecting metrics related to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of the mobile communication network, receiving a notification that the first mobile communication network component has detected an anomalous behavior pattern, and, in response to receiving the notification, using the metrics to predict and / or determine whether control signaling is present that has a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a method for detecting control signaling that has a risk of at least partially overloading a mobile communication network. [Background technology]

[0002] Signaling loads in mobile communication systems can fluctuate dramatically. Spikes in signaling loads, so-called (control plane) signaling storms, can be caused by errors (e.g., errors introduced in policies), attacks, or other exceptional events, such as when a batch of Internet of Things (IoT) devices is deployed and a large number of devices (e.g., IoT devices) are connected simultaneously. Such events can result in overloading of parts of the mobile communication network, which can result in service failures, outages, and therefore, for example, poor user experience and Service Level Agreement (SLA) penalties for network operators. Therefore, in order to minimize or, ideally, avoid service outage times, an effective approach is desired to predict, detect, and possibly mitigate control signaling events that risk at least partially overloading the mobile communication network in advance. Summary of the Invention

[0003] According to one embodiment, there is provided a method for predicting and / or detecting control signaling that has a risk of at least partially overloading a mobile communication network, comprising the steps of collecting metrics relating to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of the mobile communication network, receiving a notification that the first mobile communication network component has detected an anomalous behavior pattern, and in response to receiving the notification, using the metrics to predict and / or determine whether control signaling is present that has a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components. [Brief explanation of the drawings]

[0004] In the drawings, like reference numbers generally refer to the same parts throughout the different views. The drawings are not necessarily to scale, emphasis instead being placed upon illustrating the principles of the invention. In the following description, various aspects are described with reference to the following drawings: [Figure 1] A mobile communication system, in this example a 5G communication system, is shown. [Figure 2] 10 shows a signaling storm on the N1 reference point for registration operations. [Figure 3] 1 illustrates a signaling storm on the N11 reference point for a Protocol Data Unit (PDU) Session Establishment service operation. [Figure 4] 1 shows a signaling storm on the N33 reference point for public service operation. [Figure 5] 10 illustrates a signaling storm on the N4 reference point for a session update service operation. [Figure 6] 1 shows a flow diagram illustrating prediction and / or detection and mitigation of abnormal signaling patterns. [Figure 7]6 shows the flow for detecting a User Equipment (UE) registration signaling storm (corresponding to FIG. 2). [Figure 8] The flow of FIG. 6 for the detection of a PDU establishment signaling storm (corresponding to FIG. 3) is shown. [Figure 9] The flow of FIG. 6 is shown for the detection of an Application Function (AF) request signaling storm (corresponding to FIG. 4). [Figure 10] 10 illustrates two alternative examples of how mitigation mechanisms can be triggered, according to various embodiments. [Figure 11] 1 shows a flow diagram illustrating a method for detecting control signaling that has a risk of at least partially overloading a mobile communication network. DETAILED DESCRIPTION OF THE INVENTION

[0005] The following detailed description refers to the accompanying drawings, which show, by way of example, specific details and aspects of the present disclosure in which the present invention may be practiced. Other aspects may be utilized, and structural, logical, and electrical changes may be made, without departing from the scope of the present invention. Various aspects of the present disclosure are not necessarily mutually exclusive, as some aspects of the present disclosure may be combined with one or more other aspects of the present disclosure to form new aspects.

[0006] Various examples corresponding to aspects of the present disclosure are described below.

[0007] Example 1 is a method for predicting and / or detecting control signaling that has a risk of at least partially overloading a mobile communication network, the method comprising: collecting metrics relating to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of a mobile communication network; receiving a notification that a first mobile communications network component has detected an anomalous behavior pattern; In response to receiving the notification, using the metric to predict and / or determine whether there is control signaling that poses a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components; The method includes:

[0008] Example 2 is the method of example 1, wherein the exceptional operating pattern is an exceptional operating pattern of the first mobile communication network component.

[0009] Example 3 is the method of example 1 or 2, wherein the exceptional pattern of operation includes an exceptional pattern of internal operation of the first mobile communications network component.

[0010] Example 4 is the method of any one of Examples 1-3, wherein the exceptional operating pattern includes an exceptional signaling pattern of signaling between one or more second mobile communication network components and the first mobile communication network component.

[0011] Example 5 is the method of any one of Examples 1 to 4, wherein the first mobile communication network component is a core network function of a core network of the mobile communication network, and / or the one or more second mobile communication network components are core network functions of a core network of the mobile communication network.

[0012] Example 6 is the method of any one of Examples 1 to 4, wherein the first mobile communication network component is a core network function of a core network of the mobile communication network, and / or the one or more second mobile communication network components are one or more components of a radio access network of the mobile communication network.

[0013] Example 7 is the method of any one of Examples 1-6, including predicting and / or determining, with a machine learning model, whether control signaling is present that poses a risk of overloading the first mobile communications network component and / or one or more second mobile communications network components.

[0014] Example 8 is the method of example 7, wherein the machine learning model receives the metric as input.

[0015] Example 9 is the method of example 7 or 8, wherein the notification includes information about the exceptional operating condition, and the machine learning model receives the information about the exceptional operating condition as input.

[0016] Example 10 is the method of any one of Examples 1-9, including triggering a mitigation mechanism configured to reduce load on the first mobile communications network component and / or one or more second mobile communications network components when control signaling is predicted and / or determined to exist that poses a risk of overloading the first mobile communications network component and / or one or more second mobile communications network components.

[0017] Example 11 is the method of any one of Examples 1-10, wherein the metrics include one or more of a number and / or rate of request messages, a number and / or rate of response messages, a number and / or rate of subscribe messages, a number and / or rate of notification messages, and a number and / or rate of request rejections.

[0018] Example 12 is the method of any one of Examples 1 to 11, wherein the exceptional operating condition is: the number and / or rate of messages received by the first mobile communication network component from one or more second mobile communication network components exceeds a predetermined signaling threshold; the load of the first mobile communication network component exceeds a predetermined load threshold; the number of service provision instances of the first mobile communication network component for one or more second mobile communication network components exceeds a predetermined service provision threshold; a message buffer level of the first mobile communication network component exceeds a predetermined buffer level; the rate of memory allocation of the first mobile communication network component exceeds a predetermined memory allocation threshold; a rate of packet drops experienced by the first mobile communication network component exceeds a predetermined packet drop threshold; the rate of thread and / or process creation of the first mobile communication network component exceeds a predetermined thread / process creation threshold; the mass storage input / output latency of the first mobile communication network component exceeds a predetermined input / output latency threshold; The number of Transport Control Protocol and / or User Datagram Protocol sockets exceeds a predetermined socket threshold. At least one of the following is true.

[0019] Example 13 is a mobile communication network overload detection and mitigation system configured to perform the method of any one of Examples 1-12.

[0020] Example 14 is the overload detection and mitigation system of Example 13, including a third communications network component configured to collect metrics, receive notifications, and perform predictions and / or determinations of whether control signaling is present that poses a risk of overloading the first mobile communications network component and / or one or more second mobile communications network components, and configured to notify the first communications network component, the one or more second communications network components, and / or a fourth communications network component of results of the predictions and / or determinations.

[0021] Example 15 is the overload detection and mitigation system of Example 14, wherein the first communications network component, the one or more second communications network components, and / or the fourth communications network component are configured to trigger a mitigation mechanism configured to reduce load on the first mobile communications network component and / or the one or more second mobile communications network components when it is predicted and / or determined that control signaling is present that has a risk of overloading the first mobile communications network component and / or the one or more second mobile communications network components.

[0022] It should be noted that one or more features of any of the above examples may be combined with any one of the other examples. In particular, examples described with respect to apparatus are equally valid for methods.

[0023] According to further embodiments, there is provided a computer program and computer readable medium comprising instructions which, when executed by a computer, cause the computer to perform the method of any one of the above examples.

[0024] Various examples are described in more detail below.

[0025] FIG. 1 shows a mobile communication system 100, in this example a 5G communication system.

[0026] The mobile communication system 100 includes a plurality of UEs 101 (terminal side), and on the network side: Multiple (wireless) access networks 102 Core network 103, including the following (core) network functions (NFs): Access and Mobility Management Function (AMF) 104 ○Session Management Function (SMF) 105 Unified Data Management (UDM) 106 ○Network Slice Selection Function (NSSF) 107 Authentication Server Function (AUSF) 108 ○Policy Control Function (PCF) 109 ○ Application Function (AF) 110 User Plane Function (UPF) 111 Network Exposure Function (NEF) 112 Network Slice Admission Control Function (NSACF) 113 Network slice-specific authentication and authorization functions 114 o Network Data Analytics Function (NWDAF) 115 (shown here for simplicity without connections to other core network functions, but in practice could be connected to most any of the above).

[0027] Data Network 116 Includes.

[0028] The core network functions are connected to each other via reference points (N11, N7, N30, etc.), and furthermore, the RAN 102 is connected to the AMF 104 (or to each AMF 104, respectively) via reference point N2, and the mobile terminal 101 is connected to the AMF 104 (through the RAN 102) via reference point N1.

[0029] In a communication system such as that of FIG. 1, so-called signaling storms can occur, i.e., a large amount of control signaling that can overload components.

[0030] FIG. 2 shows the signaling storm on the N1 reference point for a registration operation.

[0031] There may be a large number of UE registration requests (eg, arising due to Internet of things (IoT) device registrations), causing the AMF 104 to become overloaded.

[0032] Figure 3 shows a signaling storm on the N11 reference point (between the AMF 104 and the SMF 105) for a Protocol Data Unit (PDU) Session Establishment service operation.

[0033] There may be a very large number of PDU establishment requests (e.g., arising from many IoT devices reporting events), which may result in the SMF 105 becoming overloaded.

[0034] FIG. 4 shows a signaling storm on the N33 reference point (between AF 110 and NEF 112) for public service operation.

[0035] There may be a very large number of AF requests, causing the NEF 112 to become overloaded.

[0036] Figure 5 shows the signaling storm on the N4 reference point (between the SMF 105 and the UPF 111) for the Session Update service operation.

[0037] There are a large number of session updates by the SMF 105 (for example, caused by an abnormal PCF 109 making erroneous policy updates signaling to the SMF 105), resulting in the UPF 111 becoming overloaded.

[0038] It is generally desirable for mobile network operators (MNOs) to be able to handle (i.e., predict and avoid) signaling storms, ideally in such a way that there is little or no disruption and interruption of the service (which may be caused by overloads), so that downtime of components affected by a signaling storm is in the range of minutes or seconds rather than hours.

[0039] In view of the above, various embodiments and approaches enable mobile communication network components (or "entities"), particularly on the network side (e.g., in the core network), to be proactively protected against signaling storms, i.e., to predict signaling storms and take measures before a signaling storm actually occurs (or at least mitigate its impact when it does occur). According to various embodiments, this is done using a Network Data Analytics Function (NWDAF) 115 that provides (or aggregates or collects) and / or stores information to enable appropriate predictions (or decisions).

[0040] In particular, according to various embodiments, NWDAF-based signaling storm prediction and detection (and possibly mitigation) is provided, including:

[0041] 1) Use of one or more machine learning (ML) models for anomaly prediction and detection 2) Determining signaling patterns (e.g., request rate, response rate, etc.) of control plane communications (e.g., service operation request / response or subscribe / notify patterns) between mobile network (i.e., network side) components, and interpreting (e.g., by one of the ML models) detected anomalies in the signaling patterns as indicators of a signaling storm (interfering or already occurring), i.e., treating anomalous control plane signaling patterns as indicators of a signaling storm. 3) Mobile network components (e.g., NFs) monitor control plane signaling to report metrics (e.g., measurements) and detect specific behavioral patterns (of themselves) and possibly control plane signaling patterns as well. For example, an ML model may be trained (by the NWDAF 115) to predict and / or detect anomalous control plane signaling patterns at a particular reference point between two mobile network components (e.g., between two NFs of the core network 103 (e.g., 5GC)) based on control plane signaling (i.e., control signaling traffic) metrics and unexpected (i.e., anomalous) signaling pattern notifications provided by one or both (or other) of the mobile network components. The two mobile network components (one acting as a service producer (or “producer”) and the other as a service consumer) and other entities of the mobile communication system (e.g., an Operation, Administration and Maintenance (OAM) or Service Communication Proxy (SCP), both of which are not shown in FIG. 1 but may be part of the communication system) may subscribe to the analysis provided by the NWDAF 115. In the event of prediction and / or detection of an anomalous signaling pattern by the NWDAF 115, the NWDAF 115 notifies subscribed entities, which can then take appropriate mitigation action (e.g., as conventionally present in communication systems).

[0042] Thus, according to various embodiments, the NWDAF 115 performs analysis to predict and / or detect anomalous control plane signaling patterns via ML models trained on signaling traffic metrics in addition to (optionally) unexpected pattern notifications provided by one or more mobile network components (e.g., NFs).

[0043] Thus, the NWDAF 115 can early detect or predict anomalous signaling (or communication) patterns, i.e., anomalies in the control plane signaling (e.g., request / subscribe and response / notify messages) between two mobile network components. For this anomaly prediction and / or detection problem, the NWDAF 115 uses one or more ML models to provide analyses (e.g., assigned newly introduced analysis IDs) for the control plane signaling patterns of service operations at reference points. These analyses can then trigger mitigation actions (e.g., initiated by the NWDAF 115 or by notifying another component of the analysis) by various entities, such as:

[0044] Service producers, e.g., using request throttling, backpressure, connection pooling, etc. as mitigation mechanisms Service consumers, e.g., using request throttling, NF reselection, etc. as mitigation mechanisms OAM, e.g., using horizontal / vertical scaling as a mitigation mechanism SCP, e.g., using request throttling, backpressure, connection pooling, etc. as mitigation mechanisms RAN, e.g., using NF reselection, access barring, etc. as mitigation mechanisms In the following, it is assumed that, for example, one or more mobile network components (e.g., NFs) involved in a possible signaling storm are able to measure and report metrics on control plane traffic (related to their corresponding service operation), such as the number of requests / subscribes sent / received within a time window, the number of responses / notifications sent / received within a time window, timing information for services / responses, and information on the number of errors such as the number of rejected requests, the number of timed-out requests, and that they are able to detect certain (especially unexpected) behavioral patterns (with respect to their service operation, e.g., the number of messages, service provisioning instances, buffer levels, load levels, rate of memory allocation, rate of packet discards, rate of thread / process creation, (disk) I / O operation latency, number of TCP / UDP sockets, etc., exceeding respective predefined thresholds, where the thresholds are determined, for example, to define ranges of values ​​for normal operation, i.e., when a signaling storm is not present).

[0045] The NWDAF 115 trains an ML model for detecting anomalies in signaling patterns between mobile network components, i.e., it collects information of the (main) services and information of the entities for each of several considered reference points between two entities (mobile network components), and optionally asks each of them (or at least some of them) to (optionally) activate an internal behavior pattern detection mechanism, i.e., patterns of information (e.g., values ​​or behavior metrics) about the internal behavior of the mobile network component. The information about the internal behavior of the mobile network component can be, for example, Number of requests / subscribes, number of responses / notifications within a time window, service / response rate, service / response timing information, and information about error counts such as number of rejected requests, number of timed out requests, etc. The number of active (ongoing) requests / subscribes (i.e., generally active (i.e., currently being processed) service provision instances) Operational metrics such as load information, buffer levels, load levels, memory allocation rates, packet drop rates, thread / process creation rates, (disk) I / O operation latencies, number of TCP / UDP sockets, etc. Contains one or more of the following:

[0046] When a mobile network component detects an unexpected behavior pattern, it notifies the NWDAF 115 .

[0047] At least some of the mobile network components (e.g., one or both of the mobile network components involved in the possible signaling storm, i.e., connected by the reference point considered) continuously monitor traffic (for metrics related to control signaling), and the NWDAF collects service control signaling metrics. The control signaling metrics (i.e., metrics related to control plane traffic) and (optionally) possibly unexpected pattern notifications provided by one or more of the mobile network components are provided as input to the ML model to detect anomalous control signaling patterns.

[0048] The NWDAF 115 outputs, for example, at least some of the following (eg, as an analysis "for control plane signaling patterns of service operation at a reference point"):

[0049] Source / Destination NF Reference points and service operations Identification of one of the following anomalies (or exceptions): Too many demands.

[0050] Too many parallel requests (no response) Too few responses Too slow a response Response times are too inconsistent Too many rejected requests Too many request timeouts Unexpected message patterns The NWDAF 115 may also provide as an output information that the exception has been resolved.

[0051] Identifying an anomaly is, for example, what an ML model (e.g., trained on a particular reference point) outputs, e.g., in terms of classification in one of these classes (i.e., exceptions) and a further "no exception" class.

[0052] Service producers and service consumers at the reference points and / or other entities considered may have the ability to monitor control signaling traffic and detect behavioral patterns in their operation (sequence of messages, resource usage, etc.), for example, via:

[0053] their internal logic (i.e., NF internal logic) Configuration set sent by OAM · Use of ML models trained by and shared with NWDAF115, i.e., mobile network components may perform inference.

[0054] As described above, when a mobile network component detects an unexpected behavior pattern, it sends a notification to the NWDAF 115. This triggers ML-based signaling pattern detection in the NWDAF 115 (using an ML model), and the notification (i.e., any information it contains, i.e., information about the unexpected behavior pattern) may also be used as input to the ML model, i.e., the ML model, according to one embodiment, is trained to predict anomalous control signaling using behavior information from one or more of the entities connected by the considered reference point (among other input data). Thus, one or more notifications about unexpected behavior patterns may be (or may include) assisting (input) data for anomalous signaling pattern detection.

[0055] FIG. 6 shows a flow diagram 600 illustrating the detection and mitigation of abnormal signaling patterns (ie, signaling storms).

[0056] A service consumer 601, a service producer 602, an NWDAF 603, an SCP 604 and an OAM 605 are involved in this flow.

[0057] At 606, 607, 608, the NWDAF 603 performs data collection from the service consumer 601, service producer 602, and SCP 604, respectively, and subscribes to be notified of unexpected behavior patterns of the service consumer 601, service producer 602, and SCP 604, respectively. In doing so, the NWDAF 603 indicates the reference point and service behavior under consideration for which it wishes to receive traffic data and be notified of unexpected behavior patterns.

[0058] At 609, the NWDAF 603 performs data collection from the OAM 605 and subscribes to be informed about the load of the network functions (in particular at least one of the service consumers 601 and service producers 602, or possibly both if both are network functions).

[0059] At 610, the NWDAF 603 uses the collected data as training data to train an ML model to detect an anomalous signaling pattern (e.g., one of the above exceptions).

[0060] In 611, 612, 613 and 614, the service consumer 601, the service producer 602, the SCP 604 and the OAM 605 subscribe to analytics on the reference points and service operations (which they indicate in their subscriptions) in the NWDAF 603 and are notified, for example, about the prediction and / or detection of anomalous control signaling patterns. It should be noted that the detection of an anomalous signaling pattern may mean that control (plane) signaling is predicted and / or detected that potentially causes an overload (i.e., that at least partially overloads the communication network, i.e., that has the risk of overloading one or more components (in particular network functions) of the communication network), i.e., that a (control) signaling storm is detected (when it already exists) or predicted (when it is not already exists but is imminent, i.e., when there is a risk of it occurring), i.e., the detection of an anomalous signaling pattern may be considered as a prediction of a control signaling (storm) that will overload one or more components of the network.

[0061] At 615, the service consumer 601, the service producer 602, the NWDAF 603 and the SCP 604 monitor the traffic on the reference point under consideration (for the service operation under consideration) and thus collect input data for the machine learning model.

[0062] When the service consumer 601, service producer 602, or SCP 604 notifies the NWDAF 603 at 616, 617, or 618, respectively, about an unexpected behavior pattern, the NWDAF 603 performs anomalous signaling pattern detection at 619 using the collected input data (e.g., collected within a specific time window prior to the notification) using a (trained) machine learning model.

[0063] At 620, 621, 622, and 623, the NWDAF 603 notifies the SCF 604, the service consumer 601, the service producer 602, and the OAM 605, respectively, of the results of the abnormal signaling pattern detection, i.e., particularly if it is a potential exception. In doing so, it indicates the reference point and service action considered and includes the identity of the mobile network component (e.g., NF) involved. Then, at 624, 625, 626, and 627, respectively, the SCF 604, the service consumer 601, the service producer 602, and the OAM 605 may each trigger a mitigation mechanism. In the case of the OAM 605, this may include configuring the SCF 604, the service consumer 601, and the service producer 602 for mitigation at 628.

[0064] If the exception is resolved, the NWDAF 603 may similarly notify the SCF 604, the service consumer 601, the service producer 602, and the OAM 605. Then, rather than triggering the mitigation mechanism, the mitigation mechanism is undone (i.e., deactivated).

[0065] The monitoring and subsequent actions of 615 in FIG. 6 are performed repeatedly.

[0066] In the following, three examples of the flow of FIG. 6 are given for different pairs of service producer and service consumer, corresponding to the signaling storms shown in FIGS.

[0067] FIG. 7 shows the flow of FIG. 6 for detection of a UE registration signaling storm (corresponding to FIG. 2).

[0068] SCP 604 is not included in this example. The reference point considered is N1 and the service action considered is UE registration. The service consumer is RAN 701 and the service producer is AMF 702. In this example, RAN 701 does not subscribe to the analysis.

[0069] In this case, the mitigation mechanism is, for example:

[0070] AMF scaling with OAM 705 Request throttling by AMF 702 (e.g., via NAS-level congestion control) and N2 overload control (in RAN 701) RRC rejection, RRC connection release, access restriction by RAN701 FIG. 8 shows the flow of FIG. 6 for the detection of a PDU establishment signaling storm (corresponding to FIG. 3).

[0071] The reference point considered is N11, the service operation considered is the PDU session creation context, the service consumer is the AMF 801 (or several AMFs), and the service producer is the SMF 802.

[0072] In this case, the mitigation mechanism is, for example:

[0073] SMF scaling with OAM805 Request throttling via SMF802 (non-access stratum (NAS) level congestion control) Request throttling by AMF801, NF reselection (NAS level congestion control) FIG. 9 shows the flow of FIG. 6 for detection of an AF request signaling storm (corresponding to FIG. 4).

[0074] SCP 604 is not included in this example. The reference point considered is N33 (no service action in this example). The service is AF 901 (or AFs) and the service producer is NEF 902.

[0075] In this case, the mitigation mechanism is, for example:

[0076] NEF scaling with OAM905 Request Throttling by NEF 902 Request throttling by AF 901, NF reselection FIG. 10 shows two alternative examples of how the mitigation mechanism can be triggered.

[0077] In a first option (shown at the top of FIG. 10), the NWDAF 1001 notifies a communication system component, such as the RAN 1002, any core entity (e.g., network function) 1003, the OAM 1004, or others, about the control signaling anomaly. Each component takes this information into account and makes a decision about initiating automatic mitigation (e.g., protection) mechanisms, such as automatic congestion control.

[0078] Alternatively, in a second option (shown at the bottom of FIG. 10), the NWDAF 1001 notifies the OAM 1004 about the control signaling anomaly, and the OAM 1004 takes this information into account, makes a decision about initiating automatic mitigation, and configures one or more of the other entities, e.g., the RAN 1002, any core entities (e.g., network functions) 1003, or others, to perform mitigation (e.g., protection) (see example step 628 of FIG. 6).

[0079] In summary, according to various embodiments, a method is provided as shown in FIG.

[0080] FIG. 11 shows a flow diagram 1100 illustrating a method for predicting and / or detecting control signaling (eg, control plane signaling) that has a risk of at least partially overloading a mobile communication network.

[0081] At 1101, metrics related to (e.g., characterizing the amount or intensity of) control plane traffic between a first mobile communication network component and one or more second mobile communication network components of a mobile communication network are collected (e.g., by monitoring or subscribing to one or more components that provide metrics of that type).

[0082] At 1002, notification is received (e.g., from a first mobile communication network component) that the first mobile communication network component has detected an anomalous (i.e., unexpected) behavior pattern. Each of one or more second mobile communication network components may similarly notify about the behavior pattern.

[0083] In response to (i.e., in reaction to) receiving the notification, at 1003, the metrics are used to predict and / or determine whether there is control signaling that poses a risk of overloading the first mobile communication network component and / or one or more second mobile communication network components (e.g., whether there is an anomalous signaling pattern (e.g., of a particular service operation) that indicates a signaling storm (or an impending signaling storm)). This prediction and / or determination may be made by a suitably trained ML model (to process the metrics and possibly information contained in the notification regarding the exceptional operation state and to predict particular control signaling (e.g., to classify the control signaling into a number of classes, at least one of which has an overload risk)). The ML model may be trained specifically for one pair of communication network components, i.e., for example, for a particular reference point (e.g., N1, N33, or N4 in the above example, etc.).

[0084] In other words, according to various embodiments, (control) signaling storm detection and / or prediction is performed based on control plane traffic metrics and notifications of involved entities that have detected unexpected operating conditions. Receiving such notifications triggers the actual detection / prediction process (e.g., inference by ML models). Thus, resources for the detection / prediction process are used only when there is an actual indication (i.e., notification of an unexpected operating condition) that a signaling storm may occur or may be imminent. The approach of FIG. 11 allows for early detection (or even prediction) of signaling storms, thus reducing service outage time. This may save resources and improve user experience.

[0085] The exceptional operating pattern may include, for example, exceptional patterns of internal operation of the first mobile communication network component, in particular internal information not exposed to the NWDAF such as buffer sizes, time to retrieve information from a database, memory allocation rate, packet discard rate, thread / process creation rate, (disk) I / O operation latency, number of TCP / UDP sockets, etc.

[0086] For example, various embodiments provide a communications system including a first entity (e.g., an NWDAF) that collects metrics of control plane request / response and / or subscribe / notify messages between a second entity and a third entity (e.g., two NFs) directly from the entity or from a fourth entity (e.g., an SCP) and asks the entity to activate an unexpected traffic detection mechanism. The first entity trains an ML model to predict / detect anomalies in control plane signaling between the second entity and the third entity, with inputs being the collected metrics and unexpected behavior pattern notifications from the second, third, and fourth entities. The second, third, and fourth entities and a fifth entity (e.g., an OAM) subscribe to the first entity to be notified when an abnormal traffic pattern is detected. The second, third, and fourth entities monitor control plane traffic to generate unexpected behavior pattern notifications and measure metrics to be sent to the first entity to be used as input for inference by the ML model. If the first entity predicts / detects an abnormal signaling pattern that triggers mitigating action in other entities, it notifies those entities.

[0087] According to various embodiments, there is provided an overload detection and mitigation system for a mobile communication network, configured to perform a method for detecting control (plane) signaling that has a risk of at least partially overloading the mobile communication network according to any one of the examples and embodiments described herein. As mentioned above, the overload detection and mitigation system includes, for example, an NWDAF (performing the actual detection) and one or more other components (including a first communication network component, a second communication network component, or a further communication network component), for example an OAM, an SMF, an AMF, etc., that are notified by the NWDAF and that potentially trigger mitigation.

[0088] The components of the communication network component may be implemented, for example, by one or more circuits. A "circuit" may be understood as any kind of logic implementation entity, which may be a dedicated circuit or a processor executing software stored in a memory, firmware, or any combination thereof. Thus, a "circuit" may be a hard-wired logic circuit or a programmable logic circuit such as a programmable processor, for example, a microprocessor. A "circuit" may also be a processor executing software, for example, any kind of computer program. Any other kind of implementation of each of the above functions may also be understood as a "circuit".

[0089] While particular embodiments have been described, it should be understood by those skilled in the art that various changes in form and details may be made therein without departing from the spirit and scope of the embodiments of the present disclosure as defined by the appended claims. The scope is therefore indicated by the appended claims, and all changes that come within the meaning and range of equivalents of the claims are therefore intended to be embraced.

Claims

1. 1. A method for predicting and / or detecting control signaling that has a risk of at least partially overloading a mobile communication network, the method comprising: collecting, by a particular mobile communication network component, metrics relating to control plane traffic between a first mobile communication network component and one or more second mobile communication network components of said mobile communication network; receiving, by the particular mobile communications network component, a notification that the first mobile communications network component has detected an anomalous behavior pattern; and in response to receiving said notification, by said particular mobile communication network component, using said collected metrics relating to control plane traffic and said detected exceptional behavior pattern of said received notification to predict and / or determine whether there is control signaling present that poses a risk of overloading said first mobile communication network component and / or said one or more second mobile communication network components. Including, the metrics include one or more of a number and / or rate of request messages, a number and / or rate of response messages, a number and / or rate of subscribe messages, a number and / or rate of notification messages, and a number and / or rate of request rejections; The exceptional operation pattern is the number and / or rate of messages received by the first mobile communication network component from the one or more second mobile communication network components exceeds a predetermined signaling threshold; the load of the first mobile communication network component exceeds a predetermined load threshold; a number of serving instances of the first mobile communication network component for the one or more second mobile communication network components exceeds a predetermined serving threshold; a message buffer level of the first mobile communication network component exceeds a predetermined buffer level; a rate of memory allocation of the first mobile communications network component exceeding a predetermined memory allocation threshold; a rate of packet drops experienced by the first mobile communications network component exceeds a predetermined packet drop threshold; the rate of thread and / or process creation of the first mobile communications network component exceeds a predetermined thread / process creation threshold; the mass storage input / output latency of the first mobile communications network component exceeds a predetermined input / output latency threshold; and The number of Transport Control Protocol and / or User Datagram Protocol sockets exceeds a predetermined socket threshold. The method is one or more of:

2. The method of claim 1 , wherein the exceptional behavior pattern is an exceptional behavior pattern of the first mobile communication network component.

3. The method of claim 1 , wherein the exceptional behavior pattern comprises an exceptional pattern of internal behavior of the first mobile communications network component.

4. The method of claim 1 , wherein the exceptional operation pattern comprises an exceptional signaling pattern of signaling between the one or more second mobile communication network components and the first mobile communication network component.

5. 2. The method of claim 1, wherein the first mobile communication network component is a core network function of a core network of the mobile communication network, and / or the one or more second mobile communication network components are core network functions of the core network of the mobile communication network.

6. 2. The method of claim 1, wherein the first mobile communication network component is a core network function of a core network of the mobile communication network, and / or the one or more second mobile communication network components are one or more components of a radio access network of the mobile communication network.

7. 2. The method of claim 1, comprising predicting and / or determining by a machine learning model whether control signaling is present that poses a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components.

8. The method of claim 7 , wherein the machine learning model receives the metric as an input.

9. The method of claim 7 , wherein the notification includes information about the anomalous behavior pattern, and the machine learning model receives the information about the anomalous behavior pattern as input.

10. 2. The method of claim 1, comprising the step of triggering a mitigation mechanism configured to reduce the load on the first mobile communication network component and / or the one or more second mobile communication network components when it is predicted and / or determined that there is control signaling that has a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components.

11. A mobile communication network overload detection and mitigation system configured to perform the method of any one of claims 1 to 10.

12. 12. The overload detection and mitigation system of claim 11, comprising the specific mobile communication network component as a third communication network component configured to collect the metrics, receive the notification, and perform prediction and / or determination of whether there is control signaling that has a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components, and configured to inform the first mobile communication network component, the one or more second mobile communication network components and / or a fourth communication network component of a result of the prediction and / or determination.

13. 13. The overload detection and mitigation system of claim 12, wherein the first mobile communication network component, the one or more second mobile communication network components and / or the fourth communication network component are configured to trigger a mitigation mechanism configured to reduce the load on the first mobile communication network component and / or the one or more second mobile communication network components when it is predicted and / or determined that control signaling is present that has a risk of overloading the first mobile communication network component and / or the one or more second mobile communication network components.

14. A computer program and computer readable medium comprising instructions which, when executed by a computer, cause the computer to carry out the method of any one of claims 1 to 10.

Citation Information

Patent Citations

  • 5G signaling storm prediction method and equipment based on grey prediction model, and medium

    CN117527612A

  • Core network node and method

    JP2022516933A