First node, second node, third node, communications system and methods performed thereby for handling information pertaining to traffic

The method addresses the issue of unsolicited traffic in communications networks by using three nodes to detect and manage such traffic, improving network performance and user experience.

WO2025124746A1PCT designated stage expired Publication Date: 2025-06-19TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/053356
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-02-09
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing methods to handle traffic in communications networks lead to poor performance, including increased latency and low quality of experience, due to malicious or poorly designed applications and servers continuously generating unsolicited traffic.

Method used

A computer-implemented method involving three nodes in a communications system to detect and handle unsolicited traffic by determining if traffic from a server IP address to a client IP address lacks an indication of solicitation, such as an active PDU session or a pre-existing corresponding flow, and sending notifications to enable appropriate actions.

Benefits of technology

The method effectively identifies and manages unsolicited traffic, reducing latency and improving network quality by enabling nodes to take actions such as extending guard times or blocking malicious traffic, thus enhancing network efficiency and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024053356_19062025_PF_FP_ABST
    Figure EP2024053356_19062025_PF_FP_ABST
Patent Text Reader

Abstract

A computer-implemented method, performed by a first node (111). The first node (111) operates in a communications system (100). The first node (111) determines (303), as part of an event to receive notification of unsolicited traffic, the event having been subscribed to by a second node (112) operating in the communications system (100), that traffic detected from a server IP address towards a client IP address is unsolicited, based on the traffic lacking a first indication that the traffic has been solicited by the client IP address, wherein the first indication indicates the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic. The first node (111) then sends (304), directly or indirectly, and responsive to the detected traffic, a second indication to the second node (112). The second indication indicates a result of the determining (303).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] FIRST NODE, SECOND NODE, THIRD NODE, COMMUNICATIONS SYSTEM AND METHODS PERFORMED THEREBY FOR HANDLING INFORMATION PERTAINING TO

[0002] TRAFFIC

[0003] TECHNICAL FIELD

[0004] The present disclosure relates generally to a first node and methods performed thereby for handling information pertaining to traffic. The present disclosure also relates generally to a second node, and methods performed thereby for handling the information pertaining to the traffic. The present disclosure further relates generally to a third node, and methods performed thereby for handling the information pertaining to the traffic. The present disclosure also relates generally to a communications system, and methods performed thereby for handling the information pertaining to the traffic.

[0005] BACKGROUND

[0006] Computer systems in a communications network or communications system may comprise one or more nodes. A node may comprise a processing circuitry which, together with computer program code may perform different functions and actions, a memory, a receiving port, and a sending port. A node may be, for example, a server. Nodes may perform their functions entirely on the cloud.

[0007] The communications system may cover a geographical area which may be divided into cell areas, each cell area being served by a type of node, a network node in the Radio Access Network (RAN), radio network node or Transmission Point (TP), for example, an access node such as a Base Station (BS), e.g., a Radio Base Station (RBS), which sometimes may be referred to as e.g., gNB, evolved Node B (“eNB”), “eNodeB”, “NodeB”, “B node”, or Base Transceiver Station (BTS), depending on the technology and terminology used. The base stations may be of different classes such as e.g., Wide Area Base Stations, Medium Range Base Stations, Local Area Base Stations, and Home Base Stations, based on transmission power and thereby also cell size. A cell may be understood to be the geographical area where radio coverage may be provided by the base station at a base station site. One base station, situated on the base station site, may serve one or several cells. Further, each base station may support one or several communication technologies. The telecommunications network may also comprise network nodes which may serve receiving nodes, such as user equipments, with serving beams.

[0008] The standardization organization Third Generation Partnership Project (3GPP) is currently in the process of specifying a New Radio Interface called Next Generation Radio or New Radio (NR) or 5G-Universal Terrestrial Radio Access (UTRA), as well as a Fifth Generation (5G) Packet Core Network, which may be referred to as 5G Core Network (5GC), abbreviated as 5GC.

[0009] Figure 1 is a schematic diagram depicting a particular example of a 5G reference architecture of a policy and charging control framework, as defined by 3GPP, which may be used as a reference for the present disclosure. An Application Function (AF) 1 may provide a service in the communications system and may interact with the 3GPP Core Network through a Network Exposure Function (NEF) 2. The AF 1 may allow external parties to use the Exposure Application Programming Interfaces (APIs) offered by the network operator. In case the AF 1 is trusted, e.g., internal to the network operator, the AF 1 may interact with the 3GPP Core Network directly, with no NEF 2 involved. The NEF 2 may support different functionality. Specifically, the NEF 2 may support different Exposure APIs. The 5G System architecture may allow a Unified Data Repository (UDR) 3 to store data grouped into distinct collections of subscription-related information: subscription data, policy data, structured data for exposure, and application data. The stored data may comprise subscription policy data to be used by a Policy Control Function (PCF) 4. The PCF 4 may support a unified policy framework to govern the network behavior. Specifically, the PCF 4 may provide Policy and Charging Control (PCC) rules to a Policy and Charging Enforcement Function (PCEF). That is, an Session Management Function (SMF) 5 and / or User Plane function (UPF) 6 that may enforce policy and charging decisions according to provisioned PCC rules.

[0010] The SMF 5 may support different functionalities, such as e.g., Protocol Data Unit (PDU) Session management. The SMF 5 may receive PCC rules from the PCF 4 for a PDU Session and may configure the UPF 6 accordingly with rules for the handling of the user plane traffic. The UPF 6 may support handling of user plane traffic, including packet inspection, packet routing and forwarding, traffic usage reporting, and Quality of Service (QoS) handling for user plane, e.g., Uplink (UL) and / or Downlink (DL) rate enforcement. A Charging Function (CHF) 7 may support charging related functionality, specifically online and offline charging. The PCF 4 may provide policy rules to a User Equipment (UE) through an Access and Mobility Function (AMF) 8. The AMF 8 may manage access of the UE. For example, when the UE may be connected through different access networks, and mobility aspects of the UE. A Network Data Analytics Function (NWDAF) 9 may be understood to represent an operator managed network analytics logical function. The NWDAF 9 may be part of the 5GC architecture and may use the mechanisms and interfaces specified for 5GC and Operations, Administration and Maintenance (QAM). Each of the UDR 3, the NEF 2, the NWDAF 9, the AF 1 , the PCF 4, the CHF 7, the AMF 8, the SMF 5 and the UPF 6 may have an interface through which they may be accessed, which as depicted in the Figure, may be, respectively: Nudr 10, Nnef 11 , Nnwdaf 12, Naf 13, Npcf 14, Nchf 15, Namf 16, Nsmf 17 and N4 18. Existing methods to handle traffic in a communications network may lead to poor performance of the communications network, such as increased latency and low quality of experience.

[0011] SUMMARY

[0012] As part of the development of embodiments herein, one or more challenges with the existing technology will first be identified and discussed.

[0013] One of the problems that may currently affect communication networks is that malicious or poorly designed applications and / or servers may continuously generate traffic towards a certain destination, e.g., the PDU session Internet Protocol (IP) address of a user, even after the user PDU session may have been deactivated.

[0014] Communication networks, in order to ensure the privacy of its users, may assign an IP address to a user for the duration of a PDU session. Such IP address may be obtained from an IP pool of IP addresses. Whenever a PDU session may be deactivated, the IP address used by the user involved in the session may be returned to the pool for reuse.

[0015] Network nodes such as e.g., SMF, UPF, external Authentication, Authorization and Accounting (AAA) servers, handling IP pools may currently use guard timers before allocating a freed IP address to a new UE PDU session. A guard timer may be understood as a timer which may enable a period of time of a certain duration, after a PDU session may have been inactivated, before the IP address used by the user involved in the PDU session may be returned to the pool for reuse. However, the guard timer mechanism does not work in the above scenario, wherein traffic may be bound to a UE which may have been allocated the IP address. Consequently, the latest causing e.g., load and charging issues.

[0016] According to the foregoing, it is an object of embodiments herein to improve the handling of information pertaining to traffic in a communications system.

[0017] According to a first aspect of embodiments herein, the object is achieved by a computer- implemented method, performed by a first node. The method is handling information pertaining to traffic. The first node operates in a communications system. The first node determines, as part of an event to receive notification of unsolicited traffic, the event having been subscribed to by a second node operating in the communications system, that traffic detected from a server Internet Protocol (IP) address towards a client IP address is unsolicited. The determining is based on the traffic lacking a first indication that the traffic has been solicited by the client IP address. The first indication indicates the client IP address has one of: a) an active Protocol Data Unit (PDU) session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic. The first node also sends, directly or indirectly, and responsive to the detected traffic, a second indication to the second node. The second indication indicates a result of the determining. According to a second aspect of embodiments herein, the object is achieved by a computer-implemented method, performed by a second node. The method is for handling the information pertaining to traffic. The second node operates in the communications system. The second node receives, directly or indirectly, the second indication from the first node operating in the communications system. The second indication indicates, as part of the event to receive notification of unsolicited traffic, the event having been subscribed to by the second node, that traffic detected from the server IP address towards the client IP address is unsolicited. The receiving of the second indication is based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication indicates the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for the received packet comprised in the detected traffic.

[0018] According to a third aspect of embodiments herein, the object is achieved by a computer-implemented method, performed by the third node. The method is for handling the information pertaining to traffic. The third node operates in the communications system. The third node receives the first message from the second node operating in the communications system. The first message indicates the subscription to the event to receive notification of unsolicited traffic. The notification of the event is based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication indicates the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for the received packet comprised in the detected traffic. The third node also sends the second message to the first node operating in the communications system indicating the subscription.

[0019] According to a fourth aspect of embodiments herein, the object is achieved by the first node, for handling the information pertaining to traffic. The first node is configured to operate in the communications system. The first node is configured to determine, as part of the event to receive notification of unsolicited traffic, the event being configured to have been subscribed to by the second node configured to operate in the communications system, that traffic configured to be detected from the server IP address towards the client IP address is unsolicited, based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication is configured to indicate the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for the received packet comprised in the detected traffic. The first node is also configured to send, directly or indirectly, and responsive to the detected traffic, the second indication to the second node. The second indication indicates the result of the determining.

[0020] According to a fifth aspect of embodiments herein, the object is achieved by the second node, for handling the information pertaining to traffic. The second node is configured to operate in the communications system. The second node is configured to receive, directly or indirectly, the second indication from the first node configured to operate in the communications system. The second indication is configured to indicate, as part of the event to receive notification of unsolicited traffic, the event being configured to have been subscribed to by the second node, that traffic detected from the server IP address towards the client IP address is unsolicited. The receiving of the second indication is configured to be based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication is configured to indicate the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for the received packet comprised in the detected traffic.

[0021] According to a sixth aspect of embodiments herein, the object is achieved by the third node, for handling the information pertaining to traffic. The third node is configured to operate in the communications system. The third node is configured to receive the first message from the second node configured to operate in the communications system. The first message is configured to indicate the subscription to the event to receive notification of unsolicited traffic. The notification of the event is configured to be based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication is configured to indicate the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic. The third node is further configured to send the second message to the first node configured to operate in the communications system indicating the subscription.

[0022] According to a seventh aspect of embodiments herein, the object is achieved by the communications system, for handling the information pertaining to traffic. The communications system is configured to comprise one or more of: the first node, the second node and the third node.

[0023] By determining that the traffic detected is unsolicited, the first node may be enabled to then notify the second node of the occurrence of the unsolicited traffic. Furthermore, the first node may be enabled to take action itself, such as for example, application of a policy to the unsolicited traffic.

[0024] By sending the second indication, and thereby notifying the second node of the occurrence of the unsolicited traffic, the first node may enable the second node to take any appropriate action. For example, the second node, that is, the event consumer, may be a network function handling allocation of an IP address pool, e.g., an SMF, or a AAA server. Based on the second indication, the second node may be enabled to trigger that, for certain IP addresses, e.g., the one or more detected client IP addresses, the guard-time configured for the IP pool may be extended when a timer may expire, e.g., because some malicious host may still be generating traffic towards that client IP address / es and that may provoke e.g., other issues, such as load increase or unfair charging. In another example, the second node may be, e.g., a security related function such as a firewall, and may be enabled to add that server IP address, that is, the one or more detected server IP addresses, in a non-safe list. Yet in another example, the second node may be, e.g., an NWDAF, that may have subscribed to the event for data collection relative to abnormal behavior analytics, to detect malicious applications and / or servers, and may be enabled to collect such data relative to abnormal behavior analytics by receiving the second indication from the first node.

[0025] By the third node receiving the first message from the second node and sending the second message to the first node, the third node may enable that the first node may receive the subscription to the event from the second node, and thereby enable that the second node may ultimately achieve the advantages described in the previous paragraph.

[0026] BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Examples of embodiments herein are described in more detail with reference to the accompanying drawings, according to the following description.

[0028] Figure 1 is a schematic diagram illustrating an example of a 5G Network Architecture, according to existing methods.

[0029] Figure 2 is a schematic diagram illustrating a non-limiting example of a communications system, according to embodiments herein.

[0030] Figure 3 is a flowchart depicting embodiments of a method in a first node, according to embodiments herein.

[0031] Figure 4 is a flowchart depicting embodiments of a method in a second node, according to embodiments herein.

[0032] Figure 5 is a flowchart depicting embodiments of a method in a third node, according to embodiments herein.

[0033] Figure 6 is a schematic diagram depicting a non-limiting example of signalling between nodes in a communications system, according to embodiments herein.

[0034] Figure 7 is a schematic diagram depicting another non-limiting example of signalling between nodes in a communications system, according to embodiments herein.

[0035] Figure 8 is a schematic block diagram illustrating two non-limiting examples, a) and b), of a first node, according to embodiments herein.

[0036] Figure 9 is a schematic block diagram illustrating two non-limiting examples, a) and b), of a second node, according to embodiments herein.

[0037] Figure 10 is a schematic block diagram illustrating two non-limiting examples, a) and b), of a third node, according to embodiments herein. DETAILED DESCRIPTION

[0038] Certain aspects of the present disclosure and their embodiments address one or more of the challenges identified with the existing methods and provide solutions to the challenges discussed.

[0039] Embodiments herein may be understood to address the problems identified with the existing methods and may relate to exposure of unsolicited network-initiated traffic.

[0040] Embodiments herein may be understood to be based on defining a new event, e.g., a new UPF event, which may be consumed by a Mobile Network Operator (MNO) Network Function (NF), e.g., SMF handling IP pools, or PCF generating PCC rules, or NWDAF for security related analytics, to expose the unsolicited network initiated traffic, even when the Destination IP address may not be allocated to a UE PDU session. That is, when the traffic may be non-session related traffic.

[0041] The embodiments will now be described more fully hereinafter with reference to the accompanying drawings, in which examples are shown. In this section, embodiments herein are illustrated by exemplary embodiments. It should be noted that these embodiments are not mutually exclusive. Components from one embodiment or example may be tacitly assumed to be present in another embodiment or example and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. All possible combinations are not described to simplify the description.

[0042] Figure 2 depicts two non-limiting examples, in panels “a” and “b”, respectively, of a communications system 100, in which embodiments herein may be implemented. In some example implementations, such as that depicted in the non-limiting example of Figure 2a, the communications system 100 may be a computer network. In other example implementations, such as that depicted in the non-limiting example of Figure 2b, the communications system 100 may be implemented in a telecommunications system, sometimes also referred to as a telecommunications network, cellular radio system, cellular network, or wireless communications system. In some examples, the telecommunications system may comprise network nodes which may serve receiving nodes, such as wireless devices. The communications system 100 may for example be a network such as a 5G system, or a newer system supporting similar functionality. The telecommunications system may also support other technologies, such as Long-Term Evolution (LTE), for example, LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), LTE Half-Duplex Frequency Division Duplex (HD-FDD), or LTE operating in an unlicensed band, Wideband Code Division Multiple Access (WCDMA), Universal Mobile Telecommunications System Terrestrial Radio Access (UTRA) TDD, Global System for Mobile communications (GSM) network, GSM / Enhanced Data Rate for GSM Evolution (EDGE) Radio Access Network (GERAN) network, Ultra-Mobile Broadband (UMB), EDGE network, network comprising any combination of Radio Access Technologies (RATs) such as e.g. Multi-Standard Radio (MSR) base stations, multi-RAT base stations etc., any 2rd Generation Partnership Project (3GPP) cellular network, Wireless Local Area Network / s (WLAN) or WiFi network / s, Worldwide Interoperability for Microwave Access (WiMax), IEEE 802.15.4-based low-power short-range networks such as IPv6 over Low-Power Wireless Personal Area Networks (6LowPAN), Zigbee, Z-Wave, Bluetooth Low Energy (BLE), or any cellular network or system. The telecommunications system may for example support a Low Power Wide Area Network (LPWAN). LPWAN technologies may comprise Long Range physical layer protocol (LoRa), Haystack, SigFox, LTE-M, and Narrow-Band loT (NB-loT).

[0043] The communications system 100 may comprise a plurality of nodes, and / or operate in communication with other nodes, whereof a first node 111, a second node 112, and a third node 113 are depicted in Figure 2. It may be understood that other nodes may communicate e.g., with devices comprised in the communications system 100, via the communications system 100,. An optional (as indicated by dashed lines in Figure 2 b) example of such a node may be a fourth node 114. It may be also be understood that the communications system 100 may comprise more nodes than those represented on Figure 2. In other non-limiting examples, which will be depicted in other figures, the communications system 100 may comprise a fifth node 115, a sixth node 116, a seventh node 117, etc... The first node 111, the second node 112 and the third node 113 may be comprised in, or be internal to, the communications system 100. The fourth node 114 may be understood to be external to the communications system 100.

[0044] Any of the first node 111, the second node 112, the third node 113 and the fourth node 114 may be understood, respectively, as a first computer system, a second computer system, a third computer system and fourth computer system. In some examples, any of the first node 111 , the second node 112, the third node 113 and the fourth node 114 may be implemented as a standalone server in e.g., a host computer in the cloud 120, as depicted in the nonlimiting example depicted in panel b) of Figure 2 for the first node 111 , the second node 112, and the third node 113. Any of the first node 111, the second node 112, the third node 113, and the fourth node 114 may in some examples be a distributed node or distributed server, with some of their respective functions being implemented locally, e.g., by a client manager, and some of their functions implemented in the cloud 120, by e.g., a server manager. Yet in other examples, any of the first node 111, the second node 112, the third node 113 and the fourth node 114 may also be implemented as processing resources in a server farm.

[0045] Any of the first node 111, the second node 112 and the third node 113 may be colocalized. However, in typical embodiments, the first node 111 , the second node 112, the third node 113 and the another node 114 may be different nodes.

[0046] The first node 111 be understood to be a node that may have a capability to support handling of user plane traffic, including packet inspection, packet routing and forwarding, traffic usage reporting, and Quality of Service (QoS) handling for user plane, e.g., LIL / DL rate enforcement, e.g., based on rules received from the second node 112. As depicted in Figure 2, in a particular non-limiting example, wherein the communications system 100 may be a 5G network, the first node 111 may be UPF.

[0047] The second node 112 be understood to be a node that may have a capability to consume events that may be offered by the first node 111. As depicted in Figure 2, in a particular non-limiting example, wherein the communications system 100 may be a 5G network, the second node may be, in such examples, a Consumer Network Function (NF), such as, e.g., a security related function such as a firewall, an NWDAF, or a network function handling allocation of an IP pool, such e.g., an SMF or a AAA server.

[0048] The third node 113, in some examples may be a node having a capability to support different functionalities, such as e.g., PDU Session management. The third node 113 may receive PCC rules from another node, e.g., the fifth node 115, which may be a PCF, for a PDU Session, and may configure the first node 111 accordingly with rules for the handling of the user plane traffic. As depicted in Figure 2, in a particular non-limiting example, wherein the communications system 100 may be a 5G network, the third node 113 may be, in such examples, an SMF.

[0049] The fourth node 114 may be a node having a capability to manage service of an application to a device, such as the device 130 described below. The fourth node 114 may interact with the core network of the communications system 100. As depicted in Figure 2, a particular non-limiting example, wherein the communications system 100 may be a 5G network, the fourth node 114 may be an AF / Application Server (AS). In the present disclosure, the fourth node 114 may be understood to be a malicious and / or poorly designed server.

[0050] The communications system 100 may also comprise a device 130. The device 130 may be also known as a e.g., user equipment (UE), wireless device, mobile terminal, wireless terminal and / or mobile station, mobile telephone, cellular telephone, or laptop with wireless capability, an Internet of Things (loT) device, or a Customer Premises Equipment (CPE), just to mention some further examples. The device 130 in the present context may be, for example, portable, pocket-storable, hand-held, computer-comprised, or a vehicle-mounted mobile device, enabled to communicate voice and / or data, via a RAN, with another entity, such as a server, a laptop, a Personal Digital Assistant (PDA), or a tablet, a Machine-to- Machine (M2M) device, an Internet of Things (loT) device, e.g., a sensor or a camera, a device equipped with a wireless interface, such as a printer or a file storage device, modem, Laptop Embedded Equipped (LEE), Laptop Mounted Equipment (LME), USB dongles, CPE or any other radio network unit capable of communicating over a radio link in the communications system 100. The device 130 may be wireless, i.e. , it may be enabled to communicate wirelessly in the communications system 100 and, in some particular examples, may be able support beamforming transmission. The communication may be performed e.g., between two devices, between a device and a radio network node, and / or between a device and a server. The communication may be performed e.g., via a RAN and possibly one or more core networks, comprised, respectively, within the communications system 100.

[0051] The communications system 100 may comprise one or more radio network nodes, whereof a radio network node 140 is depicted in Figure 2b. The radio network node 140 may typically be a base station or Transmission Point (TP), or any other network unit capable to serve a wireless device or a machine type node in the communications system 100. The radio network node 140 may be e.g., a 5G gNB, a 4G eNB, or a radio network node in an alternative 5G radio access technology, e.g., fixed or WiFi. The radio network node 140 may be e.g., a Wide Area Base Station, Medium Range Base Station, Local Area Base Station, and Home Base Station, based on transmission power and thereby also coverage size. The radio network node 140 may be a stationary relay node or a mobile relay node. The radio network node 140 may support one or several communication technologies, and its name may depend on the technology and terminology used. The radio network node 140 may be directly connected to one or more networks and / or one or more core networks.

[0052] The communications system 100 covers a geographical area which may be divided into cell areas, wherein each cell area may be served by a radio network node, although, one radio network node may serve one or several cells.

[0053] The first node 111 may communicate with the second node 112 over a first link 151, e.g., a radio link or a wired link. The first node 111 may communicate with the third node 113 over a second link 152, e.g., a radio link or a wired link. The first node 111 may communicate with the device 130 over a third link 153, e.g., a radio link or a wired link. The second node 112 may communicate with the third node 113 over a fourth link 154, e.g., a radio link or a wired link. The first node 111 may communicate with the radio network node 140 over a fifth link 155, e.g., a radio link or a wired link. The radio network node 140 may communicate with the fourth node 114 over a sixth link 156, e.g., a radio link or a wired link. The device 130 may communicate with the radio network node 140 over a seventh link 157, e.g., a radio link or a wired link. The first node 111 may with the fourth node 114 over an eighth link 158, e.g., a radio link or a wired link.

[0054] Any of the first link 151 , the second link 152, the third link 153, the fourth link 154, the fifth link 155, the sixth link 156, the seventh link 157 and / or the eighth link 158 may be a direct link or it may go via one or more computer systems or one or more core networks in the communications system 100, or it may go via an optional intermediate network. The intermediate network may be one of, or a combination of more than one of, a public, private, or hosted network; the intermediate network, if any, may be a backbone network or the Internet, which is not shown in Figure 2.

[0055] Although terminology from Long Term Evolution (LTE) / 5G has been used in this disclosure to exemplify the embodiments herein, this should not be seen as limiting the scope of the embodiments herein to only the aforementioned system. Other wireless systems supporting similar or equivalent functionality may also benefit from exploiting the ideas covered within this disclosure.

[0056] As depicted in the non-limiting examples of Figure 2, in some embodiments wherein the communications system 100 may be a 5G system, the first node 111 may be a UPF, the second node 112 may be a Consumer node, e.g., an NF, the third node 113 may be an SMF, and the fourth node 114 may be an AS / AF.

[0057] In future telecommunication networks, e.g., in the sixth generation (6G), the terms used herein may need to be reinterpreted in view of possible terminology changes in future technologies. In general, the usage of “first”, “second”, “third”, “fourth”, “fifth”, “sixth”, and / or “seventh” herein may be understood to be an arbitrary way to denote different elements or entities and may be understood to not confer a cumulative or chronological character to the nouns they modify.

[0058] Some of the embodiments contemplated herein will now be described more fully with reference to the accompanying drawings. Other embodiments, however, are contained within the scope of the subject matter disclosed herein, the disclosed subject matter should not be construed as limited to only the embodiments set forth herein; rather, these embodiments are provided by way of example to convey the scope of the subject matter to those skilled in the art.

[0059] Embodiments of a computer-implemented method, performed by the first node 111 , will now be described with reference to the flowchart depicted in Figure 3. The method may be understood to be for handling information pertaining to traffic. The first node 111 operates in the communications system 100.

[0060] In some embodiments, the communications system 100 may be a 5G network and the first node 111 may be a UPF.

[0061] Several embodiments are comprised herein. In some embodiments, all the actions may be performed. In some embodiments, some of the actions may be performed. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. A non-limiting example of the method performed by the first node 111 is depicted in Figure 3.

[0062] In Figure 3, optional actions are represented with dashed lines.

[0063] Action 301

[0064] As stated earlier, embodiments herein may be understood to aim at exposing unsolicited network-initiated traffic. Particularly, embodiments herein may define a new event which may be consumed by the second node 112, e.g., an MNO NF, when the traffic may be unsolicited, such as non-session related traffic.

[0065] In this Action 301, the first node 111 may receive, directly or indirectly, a message from the second node 112. The message may indicate subscription to an event. The event may be to receive notification of unsolicited traffic. This may be understood to be a new event.

[0066] In a first group of examples, unsolicited traffic may be understood to be traffic which may be lacking a relation to an existing session, that is, non-session related traffic. In such examples, the event may be a new event on non-session related traffic. In such examples, the event, e.g., Event-ID= NonSessionRelatedTraffic, may be defined per node, e.g., with the proviso the first node 111 may be a UPF, per UPF instance.

[0067] In a second group of examples, unsolicited traffic may be traffic which may be session related. In such examples, unsolicited traffic may be understood to be traffic which may lack a pre-existing corresponding flow for a first received packet comprised in the detected traffic. That is, where the first IP packet corresponding to a 5-tuple may have not been initiated by a device such as the device 130, in other words, wherein the first packet may be a DL IP packet. In such examples, the event may be, e.g., a new event on session related traffic. In such examples, the event, e.g., Event-ID= UnsolicitedSessionRelatedTraffic, may be defined per subscriber or per session, e.g., per subscriber's PDU session.

[0068] The receiving in this Action 301 of the message may be performed when the second node 112 may subscribe to the new event by triggering the message.

[0069] The receiving may be performed, e.g., via the second link 152.

[0070] In some embodiments, the communications system 100 may be a 5G network, the first node 111 may be a UPF and the second node 112 a Consumer NF. In such embodiments, the event may be understood to be a new UPF event.

[0071] In some embodiments, the third node 113 may operate in the communications system 100, and the message may be received via the third node 113. In some embodiments, the third node 113 may be an SMF.

[0072] The message, that is, the message from the second node 112, or originated at the second node 112, may be one of a first message and a second message. The first message may be an Nsmf_EventExposure_Subscribe request message and the second message may be an Nupf_EventExposure_Subscribe request message. The message may be the first message or the second message in embodiments wherein the message may be received indirectly. For example, this may occur when the second node 112, a consumer, may subscribe to the new UPF non-session related traffic event by triggering, optionally, via the third node 113, an SMF, an Nsmf_EventExposure_Subscribe request message. The third node 113 may then trigger towards the first node 111 a Nupf_EventExposure_Subscribe request message.

[0073] The message may comprise parameters, as follows.

[0074] The message may comprise a first identifier of the event corresponding to the request.

[0075] The first identifier may be a first parameter e.g., an Event-ID. For example, Event- ID=NonSessionRelatedTraffic, or Event-ID=UnsolicitedSessionRelatedTraffic.

[0076] In some embodiments, the message may optionally comprise a filter of the event, e.g., a second parameter “Event-Filter”.

[0077] The filter may comprise at least one of the following. According to a first option, the filter may comprise one or more client IP addresses for which the event may apply. The one or more client IP addresses may be a list of requested client IP addresses. This may indicate a list of DL traffic Destination IP addresses for which the event may apply to.

[0078] According to a second option, the filter may comprise one or more server IP addresses for which the event may apply. The one or more server IP addresses may be a list of requested server IP addresses. This may indicate a list of DL traffic origin server IP addresses for which the event may apply to.

[0079] The one or more server IP addresses may indicate a list of DL traffic origin server IP addresses, which if detected by the first node 111 to generate traffic towards client IP addresses for which there may be no active PDU session may need to be reported as part of the event.

[0080] According to a third option, the filter may comprise a 5 tuple corresponding to the traffic. The 5-Tuple may be understood to correspond to DL traffic towards IP addresses for which there may be no active PDU Session.

[0081] According to a fourth option, the filter may comprise additional information characterizing the detected traffic.

[0082] The additional information may comprise at least one of data rate, volume and number of packets received. The data rate may be, e.g., rate of packets received, e.g., number of packets, or volume, e.g., in bytes, per time unit, e.g., per second. The rate of packets received indicated in the message may be understood to be a first threshold of the rate of packets received from the server IP address above which the event may have to be reported. The message may optionally comprise a URI, where event notifications may have to be sent. The URI may be understood to be another parameter, a Notification-URI. The URI may be set to the consumer URI, so the event notifications generated by the subscription may be sent directly, not via the third node 113, e.g., an SMF, to the second node 112, that is, the service consumer.

[0083] In a particular non-limiting example, the message may be a Nsmf_EventExposure_Subscribe request comprising {Event-ID=NonSessionRelatedTraffic, (optional) Event-Filter(list of requested client IP addresses, list of requested server IP addresses), Notification-URI}.

[0084] In another particular non-limiting example, the message may be a Nupf_EventExposure_Subscribe request comprising {Event-ID=NonSessionRelatedTraffic, (optional) Event-Filter(client IP, server IP), Notification-URI}.

[0085] By receiving the message in this Action 301 , the first node 111 may enable the second node 112 to subscribe to the event, and therefore enable the second node 112 to be notified of unsolicited traffic, with the characteristics that may have been requested by the second node 112 in the message. The second node 112 may therefore be enabled to take any appropriate action, e.g., remedial action after receiving a notification of the detection of unsolicited traffic.

[0086] Action 302

[0087] In this Action 302, the first node 111 may initiate monitoring of the traffic responsive to the received message. For example, the first node 111 may start monitoring non-session related traffic, or session related traffic lacking a pre-existing corresponding flow for a first received packet comprised in the detected traffic.

[0088] By initiating monitoring of the traffic in this Action 302, the first node 111 may be enabled to detect unsolicited traffic, with the characteristics, e.g., first identifier, filter of the event, that may have been requested by the second node 112 in the message.

[0089] The first node 111 may optionally answer the request message in Action 301 with a successful response, thereby accepting the request.

[0090] Action 303

[0091] At some point during the course of operation in the communications system 100, the fourth node 114, which may be understood to be a malicious and / or poorly designed server, may generate traffic towards a certain client IP address. This may be an IP address from which the server may have received traffic in the past, which may facilitate traversing firewalls on the way.

[0092] In this Action 303, the first node 111 determines, as part of the event to receive notification of unsolicited traffic, the event having been subscribed to by the second node 112 operating in the communications system 100, that traffic detected from a server IP address towards a client IP address is unsolicited. The client IP address may correspond to, for example, the device 130 operating in the communications system 100.

[0093] The determining in this Action 303 is based on the traffic lacking a first indication that the traffic has been solicited by the client IP address. The first indication indicates the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic. That is, in some embodiments comprising the first group of examples, the first node 111 may determine in this Action 303 that the traffic is unsolicited if the first node 111 may detect traffic from a server IP address towards a client IP address which may have no active PDU session. In other embodiments comprising the second group of examples, the first node 111 may determine in this Action 303 that the traffic is unsolicited if the first node 111 may detect traffic from a server IP address towards a client IP address wherein the first packet may be a DL IP packet, e.g., a packet originated in the internet.

[0094] In some embodiments, one of the following may apply. According to a first option, the first indication may indicate the client IP address has an active PDU session and the first indication may be the one or more client IP addresses corresponding to the active PDU session. According to a second option, the first indication may indicate the client IP address has a pre-existing corresponding flow for a received packet comprised in the detected traffic, and the first indication may be a flag. If either of the two are missing, that is, if the traffic lacks the first indication, the first node 111 may determine the traffic is unsolicited.

[0095] In some embodiments, the determining in Action 303 may be performed responsive to the initiated monitoring.

[0096] By determining that the traffic detected is unsolicited in this Action 303, the first node 111 may be enabled to then notify the second node 112 of the occurrence of the unsolicited traffic, thereby enabling the second node 112 to take any appropriate action, e.g., remedial action after receiving a notification of the detection of unsolicited traffic. Furthermore, by determining that the traffic detected is unsolicited in this Action 303, the first node 111 may be enabled to take action itself, as will be described in Action 305.

[0097] Action 304

[0098] In this Action 304, the first node 111 sends, directly or indirectly, and responsive to the detected traffic, a second indication to the second node 112. The second indication indicates a result of the determining of Action 303. That is, in this Action 303, the first node 111 may notify the second node 112 of the occurrence of the event.

[0099] The sending in this Action 304 may be performed, e.g., via the first link 151. In some embodiments wherein the message received in Action 301 may have comprised the URI where the event notifications may have to be sent, the second indication may be sent to the URI. In some embodiments, the second indication may be sent periodically.

[0100] In some examples, after the first node 111 may determine the traffic is unsolicited in Action 303, the first node 111 may continue gathering data for the event, e.g., for Event- ID=NonSessionRelatedTraffic and / or Event-ID= UnsolicitedSessionRelatedTraffic, and at some point, e.g., periodic reporting, the first node 111 may report data for the event, that is, for Event-ID= NonSessionRelatedTraffic and / or Event-ID= UnsolicitedSessionRelatedTraffic. To do that, the first node 111 may notify the second node 112 by triggering the second indication. In examples wherein the first node 111 may be a UPF, the second indication may be a Nupf_EventExposure_Notify request message.

[0101] The second indication may comprise, based on the received message, at least one of: the first identifier of the event, e.g., the parameter Event-ID= NonSessionRelatedTraffic and / or Event-ID= UnsolicitedSessionRelatedTraffic, and b) information pertaining to the event, e.g., the parameter Eventinformation.

[0102] In some examples, the contents of the second indication may be the same in both events Event-ID= NonSessionRelatedTraffic and Event-ID= UnsolicitedSessionRelatedTraffic.

[0103] The information pertaining to the event may be understood to indicate, out of the information that the second node 112 may have requested to apply in the filter of the event, that information which may have been detected. This may be the totality of the requested information, e.g., all the requested server IP addresses in the list, or at least a part, e.g., those requested server IP addresses in the list which may have been detected.

[0104] In some embodiments, the information pertaining to the event may comprise at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information and a detected 5 tuple corresponding to the traffic.

[0105] In the first group of examples, as mentioned earlier, the above event, e.g., Event-ID= NonSessionRelatedTraffic, may be per node, e.g., per UPF instance.

[0106] The information pertaining to the event may comprise, according to a first option, e.g., in the first group of examples, one or more detected client IP addresses, e.g., a list of detected client IP addresses. This may indicate a list of DL traffic destination IP addresses detected by the first node 111 for which there may be no active PDU session in the first node 111. In examples of such embodiments, the additional information may also be included, such as data rate, volume and / or number of packets received. According to a second option, the information pertaining to the event may comprise the one or more detected server IP addresses, e.g., a list of detected server IP addresses. This may indicate a list of DL traffic origin server IP addresses detected by the first node 111 which may generate traffic towards client IP addresses for which there may be no active PDU session. In examples of such embodiments, the additional information may also be included, such as data rate, volume and / or number of packets received. Alternatively, according to a third option, the information pertaining to the event may comprise a 5-Tuple corresponding to DL traffic towards IP addresses for which there may be no active PDU Session. In examples of such embodiments, the additional information may also be included, such as data rate, volume and / or number of packets received.

[0107] Alternatively, in the second group of examples, this new event may be defined to be per session instead, e.g., per subscriber's PDU session, as follows. The event per session may be defined by a) the first identifier of the event corresponding to the request e.g., Event- ID= UnsolicitedSessionRelatedTraffic, per subscriber, and b) the information pertaining to the event, e.g., the Eventinformation. The information pertaining to the event may include the rate of packets received and the one or more detected server IP addresses, e.g., the list of detected server IP addresses. As stated earlier, this may indicate the list of server IP addresses detected by the first node 111 which may generate traffic towards the client IP address for which there may be an active PDU session when the 5-tuple may not have been detected in the UL. That is, wherein the first packet may be a DL IP packet. In some examples of embodiments herein, such as in examples wherein the information pertaining to the event may include the one or more detected server IP addresses, the information pertaining to the event may further include the additional information on a per server IP address basis, such as, e.g., a rate of packets received on a per server IP address basis. That is, for example, the respective rate of packets received for each of the server IP addresses from which unsolicited traffic may be received.

[0108] Additionally, the first node 111 may have an internal logic to store and report suspicious server IP addresses, such as those which may keep sending network-initiated traffic and may keep doing it even when the IP destination may no longer belong to an active / valid session. This may be feasible for implementation e.g., if the “rate” of this network-initiated traffic may be above a configurable threshold. However, another node in the communications system 100, such as, e.g., an NWDAF may be the network function implementing the smart logic, as the NWDAF may have access to all input data, by aggregating all NFs information, and may have Machine Learning (ML) capabilities.

[0109] The second node 112 may optionally answer the second indication with a successful response.

[0110] By sending the second indication in this Action 304, and thereby notifying the second node 112 of the occurrence of the unsolicited traffic, the first node 111 may enable the second node 112 to take any appropriate action, e.g., remedial action after receiving a notification of the detection of unsolicited traffic. For example, the second node 112, that is, the event consumer, may be a network function handling allocation of an IP address pool, e.g., an SMF, or a AAA server. Based on the received event information indicated in the second indication, the second node 112 may be enabled to trigger that, for certain IP addresses, that is, the one or more detected client IP addresses, the guard-time configured for the IP pool may be extended when a timer may expire, e.g., because some malicious host may still be generating traffic towards that client IP address / es and that may provoke e.g., other issues such as load increase or unfair charging. In another example, the second node 112, that is, the event consumer, may be, e.g., a security related function such as a firewall, and may be enabled to add that server IP address, that is, the one or more detected server IP addresses, in a nonsafe list. Yet in another example, the second node 112, that is, the event consumer, may be, e.g., an NWDAF, that may have subscribed, in Action 301, to the event for data collection relative to abnormal behavior analytics, to detect malicious applications and / or servers, and may be enabled to collect such data relative to abnormal behavior analytics in this Action 304.

[0111] Action 305

[0112] In this Action 305, the first node 111 may initiate application of a first policy to the unsolicited traffic responsive to the determining performed in Action 303.

[0113] In some embodiments, the first policy may be blockade of the unsolicited traffic. For example, when the fourth node 114, e.g., the malicious and / or badly designed, server may generate traffic towards the IP address assigned to the device 130 for a certain PDU session, and the first node 111 may detect it, the first node 111 may block it. An illustrative example of this is provided later in Figure 7.

[0114] In some embodiments, at least one of the following may apply. According to a first option, the message may be one of the first message and the second message. The first message may be an Nsmf_EventExposure_Subscribe request message and the second message may be an Nupf_EventExposure_Subscribe request message. According to a second option, the message may comprise the first identifier of the event corresponding to the request. According to a third option, the message may comprise the filter of the event, the filter comprising at least one of: i) the one or more client IP addresses for which the event may apply, ii) the one or more server IP addresses for which the event may apply, iii) the 5 tuple corresponding to the traffic, and iv) the additional information characterizing the detected traffic. According to a fourth option, the additional information may comprise at least one of data rate, volume and number of packets received. According to a fifth option, the message may comprise the URI, where event notifications may have to be sent. According to a sixth option, the second indication may be sent to the URI. According to a seventh option, the second indication may be sent periodically. According to an eighth option, the second indication may comprise, based on the received message, at least one of: the first identifier of the event, and detected information pertaining the event. According to a ninth option, the information pertaining to the event may comprise at least one of: i) the one or more detected client IP addresses, ii) the one or more detected server IP addresses, iii) the additional information, and iv) the detected 5 tuple corresponding to the traffic. According to a tenth option, the first policy may be blockade of the unsolicited traffic. According to an eleventh option, the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic. According to a twelfth option, the third node 113 may operate in the communications system 100, and at least one of the following may apply: i) the message may be received via the third node 113, ii) the second indication may be sent via the third node 113, and iii) the third node 113 may be an SMF.

[0115] Embodiments of a computer-implemented method performed by the second node 112, will now be described with reference to the flowchart depicted in Figure 4. The method may be understood to be for handling the information pertaining to traffic. The second node 112 operates in the communications system 100.

[0116] The method may comprise the following actions. Several embodiments are comprised herein. In some embodiments, the method may comprise all the actions. In other embodiments, the method may comprise one or more actions. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. It should be noted that the examples herein are not mutually exclusive. Components from one example may be tacitly assumed to be present in another example and it will be obvious to a person skilled in the art how those components may be used in the other examples. In Figure 4, optional actions are depicted with dashed lines.

[0117] The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here to simplify the description. For example, in some examples, the message may be an Nsmf_EventExposure_Subscribe request.

[0118] Action 401

[0119] In this Action 401, the second node 112 may send, directly or indirectly, the message to the first node 111. The message may indicate subscription to the event.

[0120] The sending in this Action 401 may be performed, e.g., via the first link 151.

[0121] In some embodiments, the communications system 100 may be a 5G network, the first node 111 may be a UPF and the second node 112 may be an NF.

[0122] Action 402

[0123] In this Action 402, the second node 112 receives, directly or indirectly, the second indication from the first node 111 operating in the communications system 100.

[0124] The second indication indicates, as part of the event to receive notification of unsolicited traffic, the event having been subscribed to by the second node 112, that traffic detected from the server IP address towards the client IP address is unsolicited.

[0125] The second indication may comprise, based on the sent message, at least one of: the first identifier of the event, and the detected information pertaining the event.

[0126] In some embodiments, the information pertaining to the event may comprise at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information and the detected 5 tuple corresponding to the traffic.

[0127] The receiving in this Action 402 of the second indication is based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication indicates the client IP address has one of: a) an active PDU session and b) a preexisting corresponding flow for the received packet comprised in the detected traffic.

[0128] In some embodiments, at least one of the following may apply: a) the first indication may indicate the client IP address has an active PDU session and the first indication is one or more client IP addresses corresponding to the active PDU session, and b) the first indication may indicate the client IP address has a pre-existing corresponding flow for the received packet comprised in the detected traffic, and the first indication may be a flag.

[0129] In some embodiments, the second indication may be received at the URI. In some embodiments, the second indication may be received periodically.

[0130] Action 403

[0131] In this Action 403, the second node 112 may initiate performing an action to manage the unsolicited traffic responsive to the receiving, in Action 402, of the second indication.

[0132] In some embodiments, at least one of the following may apply. According to a first option, the message may be one of the first message and the second message. The first message may be an Nsmf_EventExposure_Subscribe request message and the second message may be an Nupf_EventExposure_Subscribe request message. According to a second option, the message may comprise the first identifier of the event corresponding to the request. According to a third option, the message may comprise the filter of the event, the filter comprising at least one of: i) the one or more client IP addresses for which the event may apply, ii) the one or more server IP addresses for which the event may apply, iii) the 5 tuple corresponding to the traffic, and iv) the additional information characterizing the detected traffic. According to a fourth option, the additional information may comprise at least one of data rate, volume and number of packets received. According to a fifth option, the message may comprise the URI, where event notifications may have to be sent. According to a sixth option, the second indication may be received at the URI. According to a seventh option, the second indication may be received periodically. According to an eighth option, the second indication may comprise, based on the sent message, at least one of: the first identifier of the event, and detected information pertaining the event. According to a ninth option, the information pertaining to the event may comprise at least one of: i) the one or more detected client IP addresses, ii) the one or more detected server IP addresses, iii) the additional information, and iv) the detected 5 tuple corresponding to the traffic. According to a tenth option, the action may be at least one of: extending guard times of the server IP address, tracking further traffic from the server IP address, enable a second policy to drop the further traffic from the server IP address, and notify the client IP address to expose the server IP address. According to an eleventh option, the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic. According to a twelfth option, the third node 113 may operate in the communications system 100, and at least one of the following may apply: i) the message may be sent via the third node 113, ii) the second indication may be received via the third node 113, and iii) the third node 113 may be an SMF.

[0133] Embodiments of a computer-implemented method performed by the third node 113, will now be described with reference to the flowchart depicted in Figure 5. The method may be understood to be for handling the information pertaining to traffic. The third node 113 is operating in the communications system 100.

[0134] The method may comprise the following actions. Several embodiments are comprised herein. In some embodiments, the method may comprise all the actions. In other embodiments, the method may comprise some of the actions. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. It should be noted that the examples herein are not mutually exclusive. Components from one example may be tacitly assumed to be present in another example and it will be obvious to a person skilled in the art how those components may be used in the other examples. In Figure 5, optional actions are depicted with dashed lines.

[0135] The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here to simplify the description. For example, in some examples, the first message may be an Nsmf_EventExposure_Subscribe request.

[0136] Action 501

[0137] In this Action 501, the third node 113 receives the first message from the second node 112 operating in the communications system 100. The first message indicates subscription to the event to receive notification of unsolicited traffic. The notification of the event is based on the traffic lacking the first indication that the traffic has been solicited by a client IP address. The first indication indicates the client IP address has one of: a) an active PDU session and b) a pre-existing corresponding flow for the received packet comprised in the detected traffic.

[0138] The receiving in this Action 501 may be performed, e.g., via the fourth link 154.

[0139] In some embodiments, at least one of the following may apply: a) the first indication may indicate the client IP address has an active PDU session and the first indication is one or more client IP addresses corresponding to the active PDU session, and b) the first indication may indicate the client IP address has a pre-existing corresponding flow for the received packet comprised in the detected traffic, and the first indication may be a flag.

[0140] Action 502

[0141] The third node 113, in this Action 502 sends the second message to the first node 111 operating in the communications system 100 indicating the subscription.

[0142] The sending in this Action 502 may be performed, e.g., via the second link 152.

[0143] In some embodiments, the communications system 100 may be a 5G network, the first node 111 may be a UPF, the second node 112 may be an NF and the third node 113 may be an SMF.

[0144] Action 503

[0145] In this Action 503, optionally, the third node 113 may receive the second indication from the first node 111. The second indication may indicate, as part of the event having been subscribed to by the second node 112, that traffic detected from the server IP address towards the client IP address is unsolicited.

[0146] The receiving in this Action 504 may be performed, e.g., via the second link 152.

[0147] The third node 113 may refrain from performing this Action 503 in embodiments wherein the first message may have included the URI of the second node 112, that is, the consumer URI, where to send event notifications, so the second indication, e.g., generated by the subscription may be sent directly, not via the third node 113, to the second node 112.

[0148] The second indication may comprise, based on the received first message, at least one of: the first identifier of the event, and the detected information pertaining the event.

[0149] In some embodiments, the information pertaining to the event may comprise at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information and the detected 5 tuple corresponding to the traffic.

[0150] Action 504

[0151] In this Action 504, optionally, the third node 113 may send the received second indication to the second node 112.

[0152] The sending in this Action 504 may be performed, e.g., via the fourth link 154. In some embodiments, at least one of the following may apply. According to a first option, the first message may be an Nsmf_EventExposure_Subscribe request message and the second message may be an Nupf_EventExposure_Subscribe request message. According to a second option, the first message and the second message may comprise the first identifier of the event corresponding to the request. According to a third option, the first message and the second message may comprise the filter of the event, the filter comprising at least one of: i) the one or more client IP addresses for which the event may apply, ii) the one or more server IP addresses for which the event may apply, iii) the 5 tuple corresponding to the traffic, and iv) the additional information characterizing the detected traffic. According to a fourth option, the additional information may comprise at least one of data rate, volume and number of packets received. According to a fifth option, the message may comprise the URI, where event notifications may have to be sent. According to a sixth option, the second indication may be sent to the URI. According to a seventh option, the second indication may be sent periodically. According to an eighth option, the second indication may comprise, based on the received first message, at least one of: the first identifier of the event, and detected information pertaining the event. According to a ninth option, the information pertaining to the event may comprise at least one of: i) the one or more detected client IP addresses, ii) the one or more detected server IP addresses, iii) the additional information, and iv) the detected 5 tuple corresponding to the traffic. According to a tenth option, the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic.

[0153] Figure 6 is a schematic diagram depicting a non-limiting example of signalling between nodes in the communications system 100, according to embodiments herein. Particularly, Figure 6 depicts an example of embodiments herein wherein the event is a new UPF event on non-session related traffic. In Figure 6, the communications system 100 is a 5G network, the first node 111 is a UPF, the second node 112 is a Consumer, the third node 113 is an SMF and the fourth node is an Application Server. It may be understood that in the following example depicted in Figure 6, any reference to the UPF may be understood to equally refer to the first node 111, any reference to the Consumer may be understood to equally refer to the second node 112, any reference to the NEF may be understood to equally refer to the third node 113 and any reference to the Application Server may be understood to equally refer to the fourth node 114. In Steps 1 and 2), the Consumer, in accordance with Action 401 and Action 501, may subscribe to the new UPF non-session related traffic event by triggering, optionally, via the SMF, an Nsmf_EventExposure_Subscribe request message including the following parameters: a) the first identifier Event-ID=NonSessionRelatedTraffic, b) optionally, the filter of the event, Event-Filter, including: i) a list of requested client IP addresses; this may indicate a list of DL traffic Destination IP addresses for which the event may apply to, and ii) a list of requested server IP addresses; this may indicate a list of DL traffic origin server IP addresses for which the event may apply to, and c) optionally, a notification-URI. This may indicate the URI where to send event notifications. In the sequence diagram in Figure 6, this may be set to the consumer URI, so the event notifications generated by the subscription may be sent directly, not via the SMF, to the service consumer. In Step 3), the SMF, in accordance with Action 502 and Action 301, may trigger towards the UPF a Nupf_EventExposure_Subscribe request message including the same parameters as in Step 2 above, namely: a) the first identifier Event-ID=NonSessionRelatedTraffic, b) optionally, the filter of the event, Event-Filter, including: i) the list of requested client IP addresses; this may indicate the list of DL traffic Destination IP addresses for which the event may apply to, and ii) the list of requested server IP addresses; this may indicate the list of DL traffic origin server IP addresses for which the event may apply to, and c) optionally, a notification-URI. This may indicate the URI where to send event notifications. As stated above, this may be set to the consumer URI, so the event notifications generated by the subscription may be sent directly, not via the SMF, to the service consumer. In Step 4) the UPF, in accordance with Action 302, may start monitoring non-session related traffic. In Step 5) the UPF may answer the request message in Step 3 with a successful response, accepting the request. In Step 6) the SMF may answer the request message in Step 2 with a successful response, accepting the request, if not yet done. In Step 7), the fourth node 114, a malicious and / or badly designed server, may generate traffic toward a certain client IP address. This may be an IP address from which the server may have received traffic in the past, which may facilitate traversing firewalls on the way. In Step 8), based on the above event, steps 3 and 4 above, the UPF, in accordance with Action 303, may detect traffic from a server IP address towards a client IP address which has no active PDU session. In Steps 9 and 10), the UPF may continue gathering data for the Event-ID=NonSessionRelatedTraffic and, at some point, e.g., periodic reporting, the UPF may report data for the Event-ID= NonSessionRelatedTraffic. To do that, the UPF may notify the consumer, in accordance with Action 304 and Action 402, by triggering a Nupf_EventExposure_Notify request message including the following parameters: the first identifier of the event, Event-ID= NonSessionRelatedTraffic, as well as the information pertaining to the event, here, the parameter Eventinformation. The information pertaining to the event, may include the list of detected client IP addresses. This may indicate a list of UPF detected DL traffic destination IP addresses for which there is no active PDU session in the UPF. Additional information may be also included, such as data rate, volume and / or number of packets received. The information pertaining to the event, may include the list of detected server IP addresses. This may indicate a list of UPF detected DL traffic origin server IP addresses which generate traffic towards client IP addresses for which there is no active PDU session. Additional information may be also included, such as data rate, volume / number of packets received. Alternatively, the information pertaining to the event, may include the 5- Tuple corresponding to DL traffic towards IP addresses for which there is no active PDU Session. In this alternative, additional information may be also included, such as data rate, volume / number of packets received.

[0154] The above event, that is, Event-1 D= NonSessionRelatedTraffic, may be understood to be, in accordance with the first group of examples, per node, in this example, per UPF instance. Alternatively, in accordance with the second group of examples, this new event may be defined to be per session instead, that is, per subscriber's PDU session, as follows. The first identifier for the event may be defined as Event-1 D= UnsolicitedSessionRelatedTraffic, per subscriber. The Eventinformation may include: rate of packets received and the list of detected server IP addresses. The latter may be understood to indicate a list of UPF detected server IP addresses which may generate traffic towards the client IP address for which there may be an active PDU session when the 5-tuple has not been detected in UL. As stated earlier, in some examples, such as in examples wherein the information pertaining to the event may include the one or more detected server IP addresses, the information pertaining to the event may further include the rate of packets received on a per server IP address basis.

[0155] As stated earlier, additionally, the UPF may have some internal logic to store and report suspicious server IP addresses, which may keep sending network-initiated traffic and keep doing it even when the IP destination may no longer belong to an active / valid session. This may be feasible for implementation e.g., if the “rate” of this network-initiated traffic may be above a configurable threshold. However, the NWDAF may be the network function implementing the smart logic, as it may be understood to have access to all input data, by aggregating all NFs information and may have ML capabilities. In Step 11 , the Consumer may answer the message in Step 10 with a successful response.

[0156] Figure 7 is a schematic diagram depicting another non-limiting example of signalling between nodes in the communications system 100, according to embodiments herein. Particularly, Figure 7 depicts an example of use Case, wherein the PCF may apply policies based on the received information on the new event on non-session related traffic. In Figure 7, the communications system 100 is a 5G network, the first node 111 is a UPF, the third node 113 is an SMF, the fourth node 114 is an Application Server, the fifth node 115 is a PCF, the sixth node 116 is an AMF, the seventh node 117 is an UDR and the device 130 is a UE. It may be understood that in the following example depicted in Figure 7, any reference to the UPF may be understood to equally refer to the first node 111 , any reference to the SMF may be understood to equally refer to the third node 113, any reference to the Application Server may be understood to equally refer to the fourth node 114, any reference to the PCF may be understood to equally refer to the another node 115, any reference to the AMF may be understood to equally refer to the sixth node 116, any reference to the UDR may be understood to equally refer to the seventh node 117 and any reference to the UE may be understood to equally refer to the device 130. The sequence diagram of the non-limiting example of embodiments herein shown in Figure 7, may be understood to be on how the new UPF NonSessionRelatedTraffic event may be used. Other use cases may be understood to be possible. It may be noted that the sequence diagram in Figure 7 does not include all the signaling messages involved in the PDU Session Establishment procedure. Only selected signaling messages for the embodiments herein are described in subsequent steps. Starting in panel a), in Step), the UE may trigger PDU session establishment, by means of sending an N1 PDU Session Establishment Request to the AMF. In Step 2), the AMF may select an SMF to manage the PDU session and may trigger an Nsmf PDU Session Create Request. In Step 3), the SMF may trigger towards the PCF a Npcf_SMPolicyControl_Create Request message to retrieve SM policies for the user PDU session. In Step 4), the PCF may trigger towards the UDR a Nudr_Query Request message to retrieve the policy data for this user's PDU session. In Step 5), the UDR may answer the PCF with a Nudr_Query Response message including the Subscriber Policy Data. In Steps 6 and 7), the PCF may install PCC rules for the session. In this example use case, the PCF may install a PCC rule to block traffic from a certain server IP address towards the assigned UE's PDU session client IP address. The decision may be based, both on subscriber policy data, received in Step 5 above, and / or may result, according to embodiments herein, from the UPF non-session related event information, either directly consumed by PCF as an example of the second node 112, see Figure 6 Step 10, or by e.g., the NWDAF or some other Security entity that may influence the PCF policy decision. For examples wherein the fifth node 115, that is, the PCF in this Figure, may be the second node 112, the installing of the PCC rules may in Step 6 of this Figure may be understood to be in accordance with Action 403. The PCF may send a Npcf_SMPolicyControl_Create Response to the SMF including PCC rules, including a PCC rule to block traffic from server IP address towards client IP address. Continuing in panel b), in Step 8), the SMF may send to the UPF in the Packet Flow Control Protocol (PFCP) Session Establishment Request message the Packet Detection Rules (PDRs) / Forwarding Action Rule (FAR) / QoS Enforcement Rules (QERs) / Usage Reporting Rules (URRs) for the session, including a PDR to detect traffic from a certain server IP address towards the assigned UE's PDU session client IP address and associated to a FAR with block action. In Step 9), the UPF may answer the message in Step 8 indicating successful operation with a PFCP Session Establishment Response. In Step 10), the SMF may answer the message in Step 2 indicating successful operation with an Nsmf PDU Session Create Response. In Step 11), the AMF may answer the message in Step 1 indicating successful operation with a N1 PDU Session Establishment Response. In Step 12), the malicious / badly designed server may generate traffic towards the IP address assigned to the UE for this PDU session. In Step 13), the UPF, in accordance with Action 305, may detect traffic from the server IP address towards the IP address assigned to the UE for this PDU session and may block it.

[0157] As a summarized overview of the foregoing, embodiments herein may be understood to relate to a new UPF event which may be understood to expose unsolicited network- initiated traffic.

[0158] Certain embodiments disclosed herein may provide one or more of the following technical advantage(s), which may be summarized as follows.

[0159] Embodiments herein may be understood to allow an MNO to detect security vulnerabilities related to non-session related traffic and to act accordingly. This may be done, for example by extending guard times for UE allocated IP addresses until servers may stop sending traffic. It may be noted that this approach may provoke IP pools exhaustion if there is a massive attack. Alternatively, the communications system 100, e.g., a mobile network, may track these behaviors and, for example, notify users targeting these destinations and / or enable PCC rules across the NFs in the network to drop incoming packets from these servers. This may be done not only to protect the specific UEs connected to specific UPF, but all the subscriber base. This method may be understood to allows reusing IP addresses with regular time guard. This method may also be understood to continuously expose malicious unsolicited network-initiated traffic if the behavior persists.

[0160] Embodiments herein may be also understood to allow an MNO to manage efficiently the IP pools in the case of malicious servers.

[0161] Furthermore, embodiments herein may be understood to enable to avoid unfairly charging an UE that may reuses the IP address.

[0162] Figure 8 depicts an example of the arrangement that the first node 111 may comprise to perform the method described in Figure 3, Figure 6 and / or Figure 7. The first node 111 may be understood to be for handling the information pertaining to traffic. The first node 111 is configured to operate in the communications system 100.

[0163] Several embodiments are comprised herein. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here. For example, in some examples, the message may be configured to be an Nsmf_EventExposure_Subscribe request.

[0164] The first node 111 is configured to determine, as part of the event to receive notification of unsolicited traffic, the event being configured to have been subscribed to by the second node 112 configured to operate in the communications system 100, that the traffic configured to be detected from the server IP address towards the client IP address is unsolicited. The determining is configured to be based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication is configured to indicate the client IP address has one of: a) the active PDU session and b) the pre-existing corresponding flow for the received packet comprised in the detected traffic.

[0165] The first node 111 is also configured to send, directly or indirectly, and responsive to the detected traffic, the second indication to the second node 112. The second indication indicates the result of the determining.

[0166] In some embodiments, the first node 111 may be further configured with at least one of the following three configurations.

[0167] In some embodiments, the first node 111 may be further configured to receive, directly or indirectly, the message from the second node 112. The message may be configured to indicate subscription to the event.

[0168] In some embodiments, the first node 111 may be further configured to initiate monitoring of the traffic responsive to the received message. In such embodiments, the determining may be configured to be performed responsive to the monitoring configured to be initiated.

[0169] In some embodiments, the first node 111 may be further configured to initiate application of the first policy to the unsolicited traffic responsive to the determining.

[0170] In some embodiments, the communications system 100 may be configured to be a 5G network and: i) the first node 111 may be configured to be a UPF, and ii) the second node 112 may be configured to be a Consumer NF.

[0171] In some embodiments, at least one of the following may apply: a) the message may be configured to be one of the first message and the second message; the first message may be configured to be the Nsmf_EventExposure_Subscribe request message and the second message may be configured to be the Nupf_EventExposure_Subscribe request message, b) the message may be configured to comprise the first identifier of the event corresponding to the request, c) the message may be configured to comprise the filter of the event, the filter being configured to comprise at least one of: the one or more client IP addresses for which the event may be configured to apply, the one or more server IP addresses for which the event may be configured to apply, the 5 tuple corresponding to the traffic, and the additional information configured to characterize the traffic configured to be detected, d) the additional information may be configured to comprise at least one of data rate, volume and number of packets received, e) the message may be configured to comprise the URI where event notifications may have to be sent, f) the second indication may be configured to be sent to the URI, g) the second indication may be configured to be sent periodically, h) the second indication may be configured to comprise, based on the message configured to be received, at least one of: the first identifier of the event, and the detected information pertaining the event, i) the information pertaining to the event may be configured to comprise at least one of: the one or more detected client IP addresses, the one or more detected server IP addresses, the additional information, and the detected 5 tuple corresponding to the traffic, j) the first policy may be configured to be blockade of the unsolicited traffic, k) the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic, and I) the third node 113 may be configured to operate in the communications system 100, and at least one of: the message may be configured to be received via the third node 113, the second indication may be configured to be sent via the third node 113, and the third node 113 may be configured to be an SMF.

[0172] In some embodiments, one of the following may apply: a) the first indication may be configured to indicate the client IP address has an active PDU session and the first indication may be configured to be the one or more client IP addresses corresponding to the active PDU session, and b) the first indication may be configured to indicate the client IP address has a pre-existing corresponding flow for the received packet comprised in the detected traffic, and the first indication may be configured to be the flag.

[0173] The embodiments herein in the first node 111 may be implemented through one or more processors, such as a processing circuitry 801 in the first node 111 depicted in Figure 8, together with computer program code for performing the functions and actions of the embodiments herein. A processor, as used herein, may be understood to be a hardware component. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the first node 111. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the first node 111.

[0174] The first node 111 may further comprise a memory 802 comprising one or more memory units. The memory 802 is arranged to be used to store obtained information, store data, configurations, schedulings, and applications etc. to perform the methods herein when being executed in the first node 111. In some embodiments, the first node 111 may receive information from, e.g., the second node 112, the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a receiving port 803. In some embodiments, the receiving port 803 may be, for example, connected to one or more antennas in first node 111. In other embodiments, the first node 111 may receive information from another structure in the communications system 100 through the receiving port 803. Since the receiving port 803 may be in communication with the processing circuitry 801 , the receiving port 803 may then send the received information to the processing circuitry 801. The receiving port 803 may also be configured to receive other information.

[0175] The processing circuitry 801 in the first node 111 may be further configured to transmit or send information to e.g., the second node 112, the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a sending port 804, which may be in communication with the processing circuitry 801, and the memory 802.

[0176] Those skilled in the art will also appreciate that the units comprised within the first node 111 described above as being configured to perform different actions, may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g., stored in memory, that, when executed by the one or more processors such as the processing circuitry 801 , perform as described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuit (ASIC), or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).

[0177] The first node 111 may be configured to perform any of the Actions described in relation to Figure 3, Figure 6 and / or Figure 7, e.g., by means of the processing circuitry 801 within the first node 111 , configured to perform any of such actions.

[0178] Also, in some embodiments, different units comprised within the first node 111 may be configured to perform the different actions described above, implemented as one or more applications running on one or more processors such as the processing circuitry 801.

[0179] Thus, the methods according to the embodiments described herein for the first node 111 may be respectively implemented by means of a computer program 805 product, comprising instructions, i.e. , software code portions, which, when executed on at least one processing circuitry 801, cause the at least one processing circuitry 801 to carry out the actions described herein, as performed by the first node 111. The computer program 805 product may be stored on a computer-readable storage medium 806. The computer-readable storage medium 806, having stored thereon the computer program 805, may comprise instructions which, when executed on at least one processing circuitry 801 , cause the at least one processing circuitry 801 to carry out the actions described herein, as performed by the first node 111. In some embodiments, the computer-readable storage medium 806 may be a non-transitory computer- readable storage medium, such as a CD ROM disc, or a memory stick. In other embodiments, the computer program 805 product may be stored on a carrier containing the computer program 805 just described, wherein the carrier is one of an electronic signal, optical signal, radio signal, or the computer-readable storage medium 806, as described above.

[0180] The first node 111 may comprise a communication interface configured to facilitate, or an interface unit to facilitate, communications between the first node 111 and other nodes or devices, e.g., the second node 112, the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. The interface may, for example, include a transceiver configured to transmit and receive radio signals over an air interface in accordance with a suitable standard.

[0181] In other embodiments, the first node 111 may comprise a radio circuitry 807, which may comprise e.g., the receiving port 803 and the sending port 804.

[0182] The radio circuitry 807 may be configured to set up and maintain at least a wireless connection with the second node 112, the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. Circuitry may be understood herein as a hardware component.

[0183] Hence, embodiments herein also relate to the first node 111 operative to operate in the communications system 100. The first node 111 may comprise the processing circuitry 801 and the memory 802, said memory 802 containing instructions executable by said processing circuitry 801 , whereby the first node 111 is further operative to perform the actions described herein in relation to the first node 111 , e.g., in Figure 3, Figure 6 and / or Figure 7.

[0184] Figure 9 depicts an example of the arrangement that the second node 112 may comprise to perform the method described in Figure 4, Figure 6 and / or, in some examples, Figure 7. The second node 112 may be understood to be for handling the information pertaining to traffic. The second node 112 is configured to operate in the communications system 100.

[0185] Several embodiments are comprised herein. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the second node 111 and will thus not be repeated here. For example, in some examples, the message may be configured to be an Nsmf_EventExposure_Subscribe request.

[0186] The second node 112 is configured to receive, directly or indirectly, the second indication from the first node 111 configured to operate in the communications system 100. The second indication is configured to indicate, as part of the event to receive notification of unsolicited traffic, the event being configured to have been subscribed to by the second node 112, that traffic detected from the server IP address towards the client IP address is unsolicited. The receiving of the second indication is configured to be based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication is configured to indicate the client IP address has one of: a) an active PDU session and b) a preexisting corresponding flow for the received packet comprised in the detected traffic.

[0187] In some embodiments, the second node 112 may be further configured with at least one of the following two configurations.

[0188] In some embodiments, the second node 112 may be also configured to send, directly or indirectly, the message to the first node 111. The message may be configured to indicate subscription to the event.

[0189] In some embodiments, the second node 112 may be also configured to initiate performing the action to manage the unsolicited traffic responsive to the receiving of the second indication.

[0190] In some embodiments, the communications system 100 may be configured to be a 5G network and: i) the first node 111 may be configured to be a UPF, and ii) the second node 112 may be configured to be a Consumer NF.

[0191] In some embodiments, at least one of the following may apply: a) the message may be configured to be one of the first message and the second message; the first message may be configured to be the Nsmf_EventExposure_Subscribe request message and the second message may be configured to be the Nupf_EventExposure_Subscribe request message, b) the message may be configured to comprise the first identifier of the event corresponding to the request, c) the message may be configured to comprise the filter of the event, the filter being configured to comprise at least one of: the one or more client IP addresses for which the event may be configured to apply, the one or more server IP addresses for which the event may be configured to apply, the 5 tuple corresponding to the traffic, and the additional information configured to characterize the traffic configured to be detected, d) the additional information may be configured to comprise at least one of data rate, volume and number of packets received, e) the message may be configured to comprise the URI where event notifications may have to be sent, f) the second indication may be configured to be received at the II Rl, g) the second indication may be may be configured to be received periodically, h) the second indication may be configured to comprise, based on the message configured to be sent, at least one of: the first identifier of the event, and the detected information pertaining the event, i) the information pertaining to the event may be configured to comprise at least one of: the one or more detected client IP addresses, the one or more detected server IP addresses, the additional information, and the detected 5 tuple corresponding to the traffic, j) the action may be configured to be at least one of: extending the guard times of the server IP address, tracking further traffic from the server IP address, enable the second policy to drop the further traffic from the server IP address, and notify the client IP address to expose the server IP address, k) the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic, and I) the third node 113 may be configured to operate in the communications system 100, and at least one of: the message may be configured to be sent via the third node 113, the second indication may be configured to be received via the third node 113, and the third node 113 may be configured to be an SMF.

[0192] In some embodiments, one of the following may apply: a) the first indication may be configured to indicate the client IP address has an active PDU session and the first indication may be configured to be the one or more client IP addresses corresponding to the active PDU session, and b) the first indication may be configured to indicate the client IP address has a pre-existing corresponding flow for the received packet comprised in the detected traffic, and the first indication may be configured to be the flag.

[0193] The embodiments herein in the second node 112 may be implemented through one or more processors, such as a processing circuitry 901 in the second node 112 depicted in Figure 9, together with computer program code for performing the functions and actions of the embodiments herein. A processor, as used herein, may be understood to be a hardware component. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the second node 112. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the second node 112.

[0194] The second node 112 may further comprise a memory 902 comprising one or more memory units. The memory 902 is arranged to be used to store obtained information, store data, configurations, schedulings, and applications etc. to perform the methods herein when being executed in the second node 112.

[0195] In some embodiments, the second node 112 may receive information from, e.g., the first node 111 , the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a receiving port 903. In some embodiments, the receiving port 903 may be, for example, connected to one or more antennas in second node 112. In other embodiments, the second node 112 may receive information from another structure in the communications system 100 through the receiving port 903. Since the receiving port 903 may be in communication with the processing circuitry 901 , the receiving port 903 may then send the received information to the processing circuitry 901. The receiving port 903 may also be configured to receive other information.

[0196] The processing circuitry 901 in the second node 112 may be further configured to transmit or send information to e.g., the first node 111, the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a sending port 904, which may be in communication with the processing circuitry 901 , and the memory 902.

[0197] Those skilled in the art will also appreciate that the units comprised within the second node 112 described above as being configured to perform different actions, may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g., stored in memory, that, when executed by the one or more processors such as the processing circuitry 901 , perform as described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuit (ASIC), or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).

[0198] The second node 112 may be configured to perform any of the Actions described in relation to Figure 4, Figure 6 and / or, in some examples, Figure 7, e.g., by means of the processing circuitry 901 within the second node 112, configured to perform any of such actions.

[0199] Also, in some embodiments, different units comprised within the second node 112 may be configured to perform different actions described above, implemented as one or more applications running on one or more processors such as the processing circuitry 901.

[0200] Thus, the methods according to the embodiments described herein for the second node 112 may be respectively implemented by means of a computer program 905 product, comprising instructions, i.e., software code portions, which, when executed on at least one processing circuitry 901 , cause the at least one processing circuitry 901 to carry out the actions described herein, as performed by the second node 112. The computer program 905 product may be stored on a computer-readable storage medium 906. The computer- readable storage medium 906, having stored thereon the computer program 905, may comprise instructions which, when executed on at least one processing circuitry 901 , cause the at least one processing circuitry 901 to carry out the actions described herein, as performed by the second node 112. In some embodiments, the computer-readable storage medium 906 may be a non-transitory computer-readable storage medium, such as a CD ROM disc, or a memory stick. In other embodiments, the computer program 905 product may be stored on a carrier containing the computer program 905 just described, wherein the carrier is one of an electronic signal, optical signal, radio signal, or the computer-readable storage medium 906, as described above.

[0201] The second node 112 may comprise a communication interface configured to facilitate, or an interface unit to facilitate, communications between the second node 112 and other nodes or devices, e.g., the first node 111 , the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. The interface may, for example, include a transceiver configured to transmit and receive radio signals over an air interface in accordance with a suitable standard.

[0202] In other embodiments, the second node 112 may comprise a radio circuitry 907, which may comprise e.g., the receiving port 903 and the sending port 904.

[0203] The radio circuitry 907 may be configured to set up and maintain at least a wireless connection with the first node 111, the third node 113, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. Circuitry may be understood herein as a hardware component.

[0204] Hence, embodiments herein also relate to the second node 112, operative to operate in the communications system 100. The second node 112 may comprise the processing circuitry 901 and the memory 902, said memory 902 containing instructions executable by said processing circuitry 901, whereby the second node 112 is further operative to perform the actions described herein in relation to the second node 112, e.g., in Figure 4, Figure 6 and / or, in some examples, Figure 7.

[0205] Figure 10 depicts an example of the arrangement that the third node 113 may comprise to perform the method described in Figure 5, Figure 6 and / or Figure 7. The third node 113 may be understood to be for handling the information pertaining to traffic. The third node 113 is configured to operate in the communications system 100.

[0206] Several embodiments are comprised herein. It should be noted that the examples herein are not mutually exclusive. One or more embodiments may be combined, where applicable. All possible combinations are not described to simplify the description. Components from one embodiment may be tacitly assumed to be present in another embodiment and it will be obvious to a person skilled in the art how those components may be used in the other exemplary embodiments. The detailed description of some of the following corresponds to the same references provided above, in relation to the actions described for the first node 111 and will thus not be repeated here. For example, in some examples, the first message may be configured to be an Nsmf_EventExposure_Subscribe request.

[0207] The third node 113 is configured to receive the first message from the second node 112 configured to operate in the communications system 100. The first message is configured to indicate the subscription to the event to receive notification of unsolicited traffic. The notification of the event is configured to be based on the traffic lacking the first indication that the traffic has been solicited by the client IP address. The first indication is configured to indicate the client IP address has one of: a) the active PDU session and b) the pre-existing corresponding flow for the received packet comprised in the detected traffic.

[0208] The third node 113 may be further configured to send the second message to the first node 111 configured to operate in the communications system 100 indicating the subscription.

[0209] In some embodiments, the third node 113 may be further configured with the following two configurations.

[0210] In some embodiments, the third node 113 may be further configured to receive the second indication from the first node 111. The second indication may be configured to indicate, as part of the event having been subscribed to by the second node 112, that traffic detected from the server IP address towards the client IP address may be unsolicited.

[0211] In some embodiments, the third node 113 may be further configured to send the second indication configured to be received, to the second node 112.

[0212] In some embodiments, the communications system 100 may be configured to be a 5G network and: i) the first node 111 may be configured to be a UPF, ii) the second node 112 may be configured to be a Consumer and NF, and c) the third node 113 may be configured to be an SMF.

[0213] In some embodiments, at least one of the following may apply: a) the first message may be configured to be the Nsmf_EventExposure_Subscribe request message and the second message may be configured to be the Nupf_EventExposure_Subscribe request message, b) the first message and the second message may be configured to comprise the first identifier of the event corresponding to the request, c) the first message and the second message may be configured to comprise the filter of the event, the filter being configured to comprise at least one of: the one or more client IP addresses for which the event may be configured to apply, the one or more server IP addresses for which the event may be configured to apply, the 5 tuple corresponding to the traffic, and the additional information configured to characterize the traffic configured to be detected, d) the additional information may be configured to comprise at least one of data rate, volume and number of packets received, e) the first message and the second message may be configured to comprise the URI where event notifications may have to be sent, f) the second indication may be configured to be sent at the URI, g) the second indication may be may be configured to be sent periodically, h) the second indication may be configured to comprise, based on the received first message, at least one of: the first identifier of the event, and the detected information pertaining the event, i) the information pertaining to the event may be configured to comprise at least one of: the one or more detected client IP addresses, the one or more detected server IP addresses, the additional information, and the detected 5 tuple corresponding to the traffic, and j) the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic.

[0214] In some embodiments, one of the following may apply: a) the first indication may be configured to indicate the client IP address has an active PDU session and the first indication may be configured to be the one or more client IP addresses corresponding to the active PDU session, and b) the first indication may be configured to indicate the client IP address has a pre-existing corresponding flow for the received packet comprised in the detected traffic, and the first indication may be configured to be the flag.

[0215] The embodiments herein in the third node 113 may be implemented through one or more processors, such as a processing circuitry 1001 in the third node 113 depicted in Figure 10, together with computer program code for performing the functions and actions of the embodiments herein. A processor, as used herein, may be understood to be a hardware component. The program code mentioned above may also be provided as a computer program product, for instance in the form of a data carrier carrying computer program code for performing the embodiments herein when being loaded into the third node 113. One such carrier may be in the form of a CD ROM disc. It is however feasible with other data carriers such as a memory stick. The computer program code may furthermore be provided as pure program code on a server and downloaded to the third node 113.

[0216] The third node 113 may further comprise a memory 1002 comprising one or more memory units. The memory 1002 is arranged to be used to store obtained information, store data, configurations, schedulings, and applications etc. to perform the methods herein when being executed in the third node 113.

[0217] In some embodiments, the third node 113 may receive information from, e.g., first node 111 , the second node 112, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a receiving port 1003. In some embodiments, the receiving port 1003 may be, for example, connected to one or more antennas in the third node 113. In other embodiments, the third node 113 may receive information from another structure in the communications system 100 through the receiving port 1003. Since the receiving port 1003 may be in communication with the processing circuitry 1001, the receiving port 1003 may then send the received information to the processing circuitry 1001. The receiving port 1003 may also be configured to receive other information.

[0218] The processing circuitry 1001 in the third node 113 may be further configured to transmit or send information to e.g., first node 111 , the second node 112, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100, through a sending port 1004, which may be in communication with the processing circuitry 1001, and the memory 1002.

[0219] Those skilled in the art will also appreciate that the units comprised within the third node 113 described above as being configured to perform different actions, may refer to a combination of analog and digital circuits, and / or one or more processors configured with software and / or firmware, e.g., stored in memory, that, when executed by the one or more processors such as the processing circuitry 1001 , perform as described above. One or more of these processors, as well as the other digital hardware, may be included in a single Application-Specific Integrated Circuit (ASIC), or several processors and various digital hardware may be distributed among several separate components, whether individually packaged or assembled into a System-on-a-Chip (SoC).

[0220] The third node 113 may be configured to perform any of the Actions described in relation to Figure 5, Figure 6 and / or Figure 7, e.g., by means of the processing circuitry 1001 within the third node 113, configured to perform any of such actions.

[0221] Also, in some embodiments, different units comprised within the third node 113 may be configured to perform the different actions described above, implemented as one or more applications running on one or more processors such as the processing circuitry 1001.

[0222] Thus, the methods according to the embodiments described herein for the third node 113 may be respectively implemented by means of a computer program 1005 product, comprising instructions, i.e., software code portions, which, when executed on at least one processing circuitry 1001, cause the at least one processing circuitry 1001 to carry out the actions described herein, as performed by the third node 113. The computer program 1005 product may be stored on a computer-readable storage medium 1006. The computer- readable storage medium 1006, having stored thereon the computer program 1005, may comprise instructions which, when executed on at least one processing circuitry 1001, cause the at least one processing circuitry 1001 to carry out the actions described herein, as performed by the third node 113. In some embodiments, the computer-readable storage medium 1006 may be a non-transitory computer-readable storage medium, such as a CD ROM disc, or a memory stick. In other embodiments, the computer program 1005 product may be stored on a carrier containing the computer program 1005 just described, wherein the carrier is one of an electronic signal, optical signal, radio signal, or the computer-readable storage medium 1006, as described above.

[0223] The third node 113 may comprise a communication interface configured to facilitate, or an interface unit to facilitate, communications between the third node 113 and other nodes or devices, e.g., first node 111 , the second node 112, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. The interface may, for example, include a transceiver configured to transmit and receive radio signals over an air interface in accordance with a suitable standard.

[0224] In other embodiments, the third node 113 may comprise a radio circuitry 1007, which may comprise e.g., the receiving port 1003 and the sending port 1004.

[0225] The radio circuitry 1007 may be configured to set up and maintain at least a wireless connection with first node 111 , the second node 112, the fourth node 114, the fifth node 115, the sixth node 116, the seventh node 117, the radio network node 140, the device 130, another node or user equipment, and / or another structure in the communications system 100. Circuitry may be understood herein as a hardware component.

[0226] Hence, embodiments herein also relate to the third node 113, operative to operate in the communications system 100. The third node 113 may comprise the processing circuitry 1001 and the memory 1002, said memory 1002 containing instructions executable by said processing circuitry 1001, whereby the third node 113 is further operative to perform the actions described herein in relation to the third node 113, e.g., in Figure 5, Figure 6 and / or Figure 7.

[0227] Embodiments herein may also comprise the communications system 100 comprising one or more of: the first node 111 configured as described in relation to Figure 8, the second node 112 configured as described in relation to Figure 9, and the third node 113 configured as described in relation to Figure 10.

[0228] When using the word "comprise" or “comprising”, it shall be interpreted as non- limiting, i.e. , meaning "consist at least of".

[0229] The embodiments herein are not limited to the above-described preferred embodiments. Various alternatives, modifications and equivalents may be used. Therefore, the above embodiments should not be taken as limiting the scope of the invention.

[0230] Generally, all terms used herein are to be interpreted according to their ordinary meaning in the relevant technical field, unless a different meaning is clearly given and / or is implied from the context in which it is used. All references to a / an / the element, apparatus, component, means, step, etc. are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, step, etc., unless explicitly stated otherwise. The steps of any methods disclosed herein do not have to be performed in the exact order disclosed, unless a step is explicitly described as following or preceding another step and / or where it is implicit that a step must follow or precede another step. Any feature of any of the embodiments disclosed herein may be applied to any other embodiment, wherever appropriate. Likewise, any advantage of any of the embodiments may apply to any other embodiments, and vice versa. Other objectives, features and advantages of the enclosed embodiments will be apparent from the following description.

[0231] As used herein, the expression “at least one of:” followed by a list of alternatives separated by commas, and wherein the last alternative is preceded by the “and” term, may be understood to mean that only one of the list of alternatives may apply, more than one of the list of alternatives may apply or all of the list of alternatives may apply. This expression may be understood to be equivalent to the expression “at least one of:” followed by a list of alternatives separated by commas, and wherein the last alternative is preceded by the “or” term.

[0232] Any of the terms processor and circuitry may be understood herein as a hardware component.

[0233] As used herein, the expression “in some embodiments” has been used to indicate that the features of the embodiment described may be combined with any other embodiment or example disclosed herein.

[0234] As used herein, the expression “in some examples” has been used to indicate that the features of the example described may be combined with any other embodiment or example disclosed herein.

[0235] REFERENCES

[0236] 1. 3GPP TS 29.564 v18.1.0 (June 2023) “5G System; User Plane Function Services; Stage 3”.

Claims

CLAIMS:1 . A computer-implemented method, performed by a first node (111), for handling information pertaining to traffic, the first node (111) operating in a communications system (100), the method comprising:- determining (303), as part of an event to receive notification of unsolicited traffic, the event having been subscribed to by a second node (112) operating in the communications system (100), that traffic detected from a server Internet Protocol, IP, address towards a client IP address is unsolicited, based on the traffic lacking a first indication that the traffic has been solicited by the client IP address, wherein the first indication indicates the client IP address has one of: a) an active Protocol Data Unit, PDU, session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic, and- sending (304), directly or indirectly, and responsive to the detected traffic, a second indication to the second node (112), the second indication indicating a result of the determining (303).

2. The method according to claim 1 , further comprising at least one of:- receiving (301), directly or indirectly, a message from the second node (112), the message indicating subscription to the event, and- initiating (302) monitoring of the traffic responsive to the received message, and wherein the determining (303) is performed responsive to the initiated monitoring, and- initiating (305) application of a first policy to the unsolicited traffic responsive to the determining (303).

3. The method according to any of claims 1-2, wherein the communications system (100) is a Fifth Generation, 5G, network and: i. the first node (111) is a User Plane Function, UPF, and ii. the second node (112) is a Consumer Network Function, NF.

4. The method according to claims 2 and 3, wherein at least one of: a. the message is one of a first message and a second message, wherein the first message is an Nsmf_EventExposure_Subscribe request message and the second message is an Nupf_EventExposure_Subscribe request message, b. the message comprises a first identifier of the event corresponding to the request,c. the message comprises a filter of the event, the filter comprising at least one of: one or more client IP addresses for which the event applies, one or more server IP addresses for which the event applies, a 5 tuple corresponding to the traffic, and additional information characterizing the detected traffic, d. the additional information comprises at least one of data rate, volume and number of packets received, e. the message comprises a Uniform Resource Indicator, URI, where event notifications are to be sent, f. the second indication is sent to the URI, g. the second indication is sent periodically, h. the second indication comprises, based on the received message, at least one of: the first identifier of the event, and information pertaining to the event, i. the information pertaining to the event comprises at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information, and a detected 5 tuple corresponding to the traffic, j. the first policy is blockade of the unsolicited traffic, k. the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic, and l. a third node (113) operates in the communications system (100), and at least one of: the message is received via the third node (113), the second indication is sent via the third node (113), and the third node (113) is a Session Management Function, SMF.

5. The method according to any of claims 1-4, wherein one of: a. the first indication indicates the client IP address has an active PDU session and the first indication is one or more client IP addresses corresponding to the active PDU session, and b. the first indication indicates the client IP address has a pre-existing corresponding flow for a received packet comprised in the detected traffic, and the first indication is a flag.

6. A computer-implemented method, performed by a second node (112), for handling information pertaining to traffic, the second node (112) operating in a communications system (100), the method comprising:- receiving (402), directly or indirectly, a second indication from a first node (111) operating in the communications system (100), the second indication indicating, as part of an event to receive notification of unsolicited traffic, the event having been subscribed to by the second node (112), that traffic detected from a server Internet Protocol, IP, address towards a client IP address is unsolicited, wherein the receiving (402) of the second indication is based on the traffic lacking a first indication that the traffic has been solicited by the client IP address, wherein the first indication indicates the client IP address has one of: a) an active Protocol Data Unit, PDU, session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic.

7. The method according to claim 6, further comprising at least one of:- sending (401), directly or indirectly, a message to the first node (111), the message indicating subscription to the event, and- initiating (403) performing an action to manage the unsolicited traffic responsive to the receiving (402) of the second indication.

8. The method according to any of claims 6-7, wherein the communications system (100) is a Fifth Generation, 5G, network and: i. the first node (111) is a User Plane Function, UPF, and ii. the second node (112) is a Consumer Network Function, NF.

9. The method according to claims 7 and 8, wherein at least one of: a. the message is one of a first message and a second message, wherein the first message is an Nsmf_EventExposure_Subscribe request message and the second message is an Nupf_EventExposure_Subscribe request message, b. the message comprises a first identifier of the event corresponding to the request, c. the message comprises a filter of the event, the filter comprising at least one of:- one or more client IP addresses for which the event applies,- one or more server IP addresses for which the event applies,- a 5 tuple corresponding to the traffic, and- additional information characterizing the detected traffic,d. the additional information comprises at least one of data rate, volume and number of packets received, e. the message comprises a Uniform Resource Indicator, URI, where event notifications are to be sent, f. the second indication is received at the URI, g. the second indication is received periodically, h. the second indication comprises, based on the sent message, at least one of: the first identifier of the event, and information pertaining to the event, i. the information pertaining to the event comprises at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information, and a detected 5 tuple corresponding to the traffic, j. the action is at least one of: extending guard times of the server IP address, tracking further traffic from the server IP address, enable a second policy to drop the further traffic from the server IP address, and notify the client IP address to expose the server IP address, k. the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic, and l. a third node (113) operates in the communications system (100), and at least one of: the message is sent via the third node (113), the second indication is received via the third node (113), and the third node (113) is a Session Management Function, SMF.

10. The method according to any of claims 6-9, wherein one of: a. the first indication indicates the client IP address has an active PDU session and the first indication is one or more client IP addresses corresponding to the active PDU session, and b. the first indication indicates the client IP address has a pre-existing corresponding flow for a received packet comprised in the detected traffic, and the first indication is a flag.

11. A computer-implemented method, performed by a third node (113), for handling information pertaining to traffic, the third node (113) operating in a communications system (100), the method comprising:- receiving (501) a first message from a second node (112) operating in the communications system (100), the first message indicating subscription to an event to receive notification of unsolicited traffic, wherein the notification of the event is based on the traffic lacking a first indication that the traffic has been solicited by a client Internet Protocol, IP, address, wherein the first indication indicates the client IP address has one of: a) an active Protocol Data Unit, PDU, session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic, and- sending (502) a second message to the first node (111) operating in the communications system (100) indicating the subscription.

12. The method according to claim 11 , further comprising:- receiving (503) a second indication from the first node (111), the second indication indicating, as part of the event having been subscribed to by the second node(112), that traffic detected from a server Internet Protocol, IP, address towards a client IP address is unsolicited, and- sending (504) the received second indication to the second node (112).

13. The method according to any of claims 11-12 wherein the communications system (100) is a Fifth Generation, 5G, network and: i. the first node (111) is a User Plane Function, UPF, ii. the second node (112) is a Consumer Network Function, NF, and iii. the third node (113) is a Session Management Function, SMF.

14. The method according to claims 12 and 13, wherein at least one of: a. the first message is an Nsmf_EventExposure_Subscribe request message and the second message is an Nupf_EventExposure_Subscribe request message, b. the first message and the second message comprise a first identifier of the event corresponding to the request, c. the first message and the second message comprise a filter of the event, the filter comprising at least one of: one or more client IP addresses for which the event applies, one or more server IP addresses for which the event applies,a 5 tuple corresponding to the traffic, and additional information characterizing the detected traffic, d. the additional information comprises at least one of data rate, volume and number of packets received, e. the first message and the second message comprise a Uniform Resource Indicator, URI, where event notifications are to be sent, f. the second indication is received at the URI, g. the second indication is received periodically, h. the second indication comprises, based on the received first message, at least one of: the first identifier of the event, and information pertaining to the event, i. the information pertaining to the event comprises at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information, and a detected 5 tuple corresponding to the traffic, and j. the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic.

15. The method according to any of claims 11-14, wherein one of: a. the first indication indicates the client IP address has an active PDU session and the first indication is one or more client IP addresses corresponding to the active PDU session, and b. the first indication indicates the client IP address has a pre-existing corresponding flow for a received packet comprised in the detected traffic, and the first indication is a flag.

16. A first node (111), for handling information pertaining to traffic, the first node (111) being configured to operate in a communications system (100), the first node (111) being further configured to:- determine, as part of an event to receive notification of unsolicited traffic, the event being configured to have been subscribed to by a second node (112) configured to operate in the communications system (100), that traffic configured to be detected from a server Internet Protocol, IP, address towards a client IP address is unsolicited, based on the traffic lacking a first indication that the traffic has been solicited by the client IP address, wherein the first indication is configured to indicate the client IP address has one of: a) an active Protocol Data Unit, PDU,session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic, and- send, directly or indirectly, and responsive to the detected traffic, a second indication to the second node (112), the second indication indicating a result of the determining.

17. The first node (111) according to claim 16, being further configured to at least one of:- receive, directly or indirectly, a message from the second node (112), the message being configured to indicate subscription to the event, and- initiate monitoring of the traffic responsive to the received message, and wherein the determining is configured to be performed responsive to the monitoring configured to be initiated, and- initiate application of a first policy to the unsolicited traffic responsive to the determining.

18. The first node (111) according to any of claims 16-17, wherein the communications system (100) is configured to be a Fifth Generation, 5G, network and: i. the first node (111) is configured to be a User Plane Function, UPF, and ii. the second node (112) is configured to be a Consumer Network Function, NF.

19. The first node (111) according to claims 17 and 18, wherein at least one of: a. the message is configured to be one of a first message and a second message, wherein the first message is configured to be an Nsmf_EventExposure_Subscribe request message and the second message is configured to be an Nupf_EventExposure_Subscribe request message, b. the message is configured to comprise a first identifier of the event corresponding to the request, c. the message is configured to comprise a filter of the event, the filter being configured to comprise at least one of: one or more client IP addresses for which the event is configured to apply, one or more server IP addresses for which the event is configured to apply, a 5 tuple corresponding to the traffic, andadditional information configured to characterize the traffic configured to be detected, d. the additional information is configured to comprise at least one of data rate, volume and number of packets received, e. the message is configured to comprise a Uniform Resource Indicator, URI, where event notifications are to be sent, f. the second indication is configured to be sent to the URI, g. the second indication is configured to be sent periodically, h. the second indication is configured to comprise, based on the message configured to be received, at least one of: the first identifier of the event, and information pertaining to the event, i. the information pertaining to the event is configured to comprise at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information, and a detected 5 tuple corresponding to the traffic, j. the first policy is configured to be blockade of the unsolicited traffic, k. the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic, and l. a third node (113) is configured to operate in the communications system (100), and at least one of: the message is configured to be received via the third node (113), the second indication is configured to be sent via the third node (113), and the third node (113) is configured to be a Session Management Function, SMF.

20. The first node (111) according to any of claims 16-19, wherein one of: a. the first indication is configured to indicate the client IP address has an active PDU session and the first indication is configured to be one or more client IP addresses corresponding to the active PDU session, and b. the first indication is configured to indicate the client IP address has a preexisting corresponding flow for a received packet comprised in the detected traffic, and the first indication is configured to be a flag.

21. A second node (112), for handling information pertaining to traffic, the second node(112) being configured to operate in a communications system (100), the second node (112) being further configured to:- receive, directly or indirectly, a second indication from a first node (111) configured to operate in the communications system (100), the second indication being configured to indicate, as part of an event to receive notification of unsolicited traffic, the event being configured to have been subscribed to by the second node (112), that traffic detected from a server Internet Protocol, IP, address towards a client IP address is unsolicited, wherein the receiving of the second indication is configured to be based on the traffic lacking a first indication that the traffic has been solicited by the client IP address, wherein the first indication is configured to indicate the client IP address has one of: a) an active Protocol Data Unit, PDU, session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic.

22. The second node (112) according to claim 21 , being further configured to at least one of:- send, directly or indirectly, a message to the first node (111), the message being configured to indicate subscription to the event, and- initiate performing an action to manage the unsolicited traffic responsive to the receiving of the second indication.

23. The second node (112) according to any of claims 21-22, wherein the communications system (100) is configured to be a Fifth Generation, 5G, network and: i. the first node (111) is configured to be a User Plane Function, UPF, and ii. the second node (112) is a configured to be Consumer Network Function, NF.

24. The second node (112) according to claims 22 and 23, wherein at least one of: a. the message is configured to be one of a first message and a second message, wherein the first message is configured to be an Nsmf_EventExposure_Subscribe request message and the second message is configured to be an Nupf_EventExposure_Subscribe request message, b. the message configured to comprise a first identifier of the event corresponding to the request,c. the message is configured to comprise a filter of the event, the filter being configured to comprise at least one of: one or more client IP addresses for which the event is configured to apply, one or more server IP addresses for which the event is configured to apply, a 5 tuple corresponding to the traffic, and additional information configured to characterize the detected traffic, d. the additional information is configured to comprise at least one of data rate, volume and number of packets received, e. the message is configured to comprise a Uniform Resource Indicator, URI, where event notifications are to be sent, f. the second indication is configured to be received at the URI, g. the second indication is configured to be received periodically, h. the second indication is configured to comprise, based on the message configured to be sent, at least one of: the first identifier of the event, and information pertaining to the event, i. the information pertaining to the event is configured to comprise at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information, and a detected 5 tuple corresponding to the traffic, j. the action is configured to be at least one of: extending guard times of the server IP address, tracking further traffic from the server IP address, enable a second policy to drop the further traffic from the server IP address, and k. notify the client IP address to expose the server IP address, l. the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic, and m. a third node (113) configured to operate in the communications system (100), and at least one of: the message is configured to be sent via the third node (113), the second indication is configured to be received via the third node (113), andthe third node (113) is configured to be a Session Management Function, SMF.

25. The second node (112) according to any of claims 21-24, wherein one of: a. the first indication is configured to indicate the client IP address has an active PDU session and the first indication is configured to be one or more client IP addresses corresponding to the active PDU session, and b. the first indication is configured to indicate the client IP address has a preexisting corresponding flow for a received packet comprised in the detected traffic, and the first indication is configured to be a flag.

26. A third node (113), for handling information pertaining to traffic, the third node (113) being configured to operate in a communications system (100), the third node (113) being further configured to:- receive a first message from a second node (112) configured to operate in the communications system (100), the first message being configured to indicate subscription to an event to receive notification of unsolicited traffic, wherein the notification of the event is configured to be based on the traffic lacking a first indication that the traffic has been solicited by a client IP address, wherein the first indication is configured to indicate the client IP address has one of: a) an active Protocol Data Unit, PDU, session and b) a pre-existing corresponding flow for a received packet comprised in the detected traffic, and- send a second message to the first node (111) configured to operate in the communications system (100) indicating the subscription.

27. The third node (113) according to claim 26, being further configured to:- receive a second indication from the first node (111), the second indication being configured to indicate, as part of the event having been subscribed to by the second node (112), that traffic detected from a server Internet Protocol, IP, address towards a client IP address is unsolicited, and- send the second indication configured to be received, to the second node (112).

28. The third node (113) according to any of claims 26-27 wherein the communications system (100) is configured to be a Fifth Generation, 5G, network and: i. the first node (111) is configured to be a User Plane Function, UPF,ii. the second node (112) is configured to be a Consumer Network Function, NF, and iii. the third node (113) is configured to be a Session Management Function, SMF.

29. The third node (113) according to claims 27 and 28, wherein at least one of: a. the first message is configured to be an Nsmf_EventExposure_Subscribe request message and the second message is configured to be an Nupf_EventExposure_Subscribe request message, b. the first message and the second message are configured to comprise a first identifier of the event corresponding to the request, c. the first message and the second message are configured to comprise a filter of the event, the filter being configured to comprise at least one of: one or more client IP addresses for which the event is configured to apply, one or more server IP addresses for which the event is configured to apply, a 5 tuple corresponding to the traffic, and additional information configured to characterize the traffic configured to be detected, d. the additional information is configured to comprise at least one of data rate, volume and number of packets received, e. the first message and the second message are configured to comprise a Uniform Resource Indicator, URI, where event notifications are to be sent, f. the second indication is configured to be sent at the URI, g. the second indication is configured to be sent periodically, h. the second indication is configured to comprise, based on the received first message, at least one of: the first identifier of the event, and information pertaining the event, i. the information pertaining to the event is configured to comprise at least one of: one or more detected client IP addresses, one or more detected server IP addresses, the additional information, and a detected 5 tuple corresponding to the traffic, and j. the received packet comprised in the detected traffic is a first received packet comprised in the detected traffic.

30. The third node (113) according to any of claims 26-29, wherein one of: a. the first indication is configured to indicate the client IP address has an active PDU session and the first indication is one or more client IP addresses corresponding to the active PDU session, and b. the first indication is configured to indicate the client IP address has a preexisting corresponding flow for a received packet comprised in the detected traffic, and the first indication is configured to be a flag.

31. A communications system (100) comprising one or more of: a first node (111) according to any of the claims 16-20, a second node (112) according to any of the claims 21-25, and a third node (113) according to any of the claims 26-30.

Citation Information

Patent Citations

  • First node, second node, communications system and methods performed, thereby for handling security in a communications system

    WO2022167105A1

  • Communications system, first endpoint device and methods performed thereby for handling security

    WO2023134876A1