Policy updating method and apparatus

By introducing network data analysis elements into the communication network for security detection and coordinated response of policy control elements, the problem of lack of security detection and response in the existing policy architecture is solved, enabling real-time detection and rapid response to security events and improving network security.

WO2025241782A1PCT designated stage Publication Date: 2025-11-27HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/089331
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-20
Filing Date
2025-04-16
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

Existing communication network policy architectures lack security detection and response mechanisms, failing to meet the security requirements of communication networks.

Method used

By introducing network data analysis network elements for security detection, security events are detected in real time through the deployment of security detection models and algorithms, and security policies are issued by policy control network elements to achieve coordinated response to security events.

Benefits of technology

It improves the security of communication networks, enables rapid response to emergency security incidents, reduces false detections and frequent policy updates, and enhances detection accuracy and network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025089331_27112025_PF_FP_ABST
    Figure CN2025089331_27112025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of communications, and particularly relates to a policy updating method and apparatus, which aim to introduce detection and response mechanisms for security into a communication network, thereby improving the security of the communication network. The method comprises: a network data analytics network element acquiring detection data corresponding to a first analysis type; on the basis of the detection data, determining whether there is a security event corresponding to the first analysis type; and when there is a security event corresponding to the first analysis type, sending first information to a policy control network element, wherein the first information indicates the security event and a detection target that corresponds to the detection data.
Need to check novelty before this filing date? Find Prior Art

Description

A policy updating method and device

[0001] Cross-reference to Related Applications

[0002] The present application claims priority to the Chinese patent application No. 202410627581.5, filed on May 20, 2024, and entitled "A policy updating method and device", the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] The present application relates to the field of communication technology, and in particular to a policy updating method and device. BACKGROUND

[0004] In existing communication networks, a policy and charging control (PCC) architecture is adopted to provide differentiated and intelligent service and experience for users, and to realize dynamic policy management and charging mode. A policy and charging rule function (PCRF) is the core of the PCC architecture of a 4th generation (4G) or long term evolution (LTE) network, and the PCRF is used to assist in service data flow detection, policy implementation and flow-based charging, to ensure reliable monitoring of services or use cases and fees related to each use case. A policy control function (PCF) is the core of the PCC architecture of a 5th generation (5G) network, and the PCF can be considered as an evolution of the PCRF. The PCF increases the ability to request and monitor the quality of service per session, and in addition to retaining these session-based functions, the PCF also increases other functions, including control of network slices and new control mechanisms for terminal activity, such as roaming and mobility management.

[0005] Then, the existing policy architecture mainly focuses on service identification and classification, and lacks detection and response mechanisms for security, which cannot meet the needs of communication networks for security. SUMMARY

[0006] Embodiments of the present application provide a policy updating method and device, in order to introduce detection and response mechanisms for security in communication networks, and to improve the security of communication networks.

[0007] In a first aspect, an embodiment of the present application provides a policy updating method, which can be executed by a network data analysis network element. The method comprises: obtaining detection data corresponding to a first analysis type; determining whether a security event corresponding to the first analysis type exists according to the detection data; and in the case where the security event corresponding to the first analysis type exists, sending first information to a policy control network element, the first information indicating the security event and a detection target corresponding to the detection data. The first analysis type can be an analysis type of network security, such as security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

[0008] Through the above method, a model / algorithm related to security detection can be deployed in the network data analysis network element. The network data analysis network element can detect the traffic of a flow control node (such as a user plane function (UPF) or a sensing data processing function (SDPF)), and the policy control network element can issue a control policy corresponding to a security event in the case where the security event exists. The network data analysis network element security detection and the policy configuration of the policy control network element can be linked, real-time detection and response to security problems in the communication network can be supported, and the security of the communication network can be improved.

[0009] In a possible design, obtaining the detection data corresponding to the first analysis type comprises: sending a data collection requirement to the flow control node, the data collection requirement indicating the first analysis type and the detection target; and receiving the detection data from the flow control node.

[0010] Through the above design, different sampling requirements can be configured for different analysis types, such as different sampling rates, different matching conditions (such as different terminal groups, service types, slice types, or device types), which is beneficial to improve the accuracy of detection.

[0011] In a possible design, before obtaining the detection data corresponding to the first analysis type, the method further comprises: receiving second information from the policy control network element, the second information indicating the first analysis type.

[0012] Through the above design, the policy control network element can trigger the network data analysis network element to perform security detection, which is beneficial to link the security detection of the network data analysis network element and the policy configuration of the policy control network element.

[0013] In a possible design, the second information further indicates a detection threshold, where the detection threshold can include a frequency threshold, a frequency domain threshold, an abnormal traffic detection threshold, and the like. For example, the network data analysis network element can send the first information to the policy control network element in a case where a frequency of the security event corresponding to the first analysis type is not less than the frequency threshold; or in a case where a frequency of the security event corresponding to the first analysis type is not less than the frequency threshold.

[0014] Through the above design, the network data analysis network element can indicate the detection target corresponding to the security event and the detection data to the policy control network element in a case where the detection result meets the detection threshold, which can avoid false detection of the policy control network element and frequent policy update of the flow control node.

[0015] In a possible design, the detection target includes one or more of a region range, a service type, a device type, a slice type, or a time range.

[0016] Through the above design, the policy control network element can determine the range of policy update.

[0017] In a possible design, determining, according to the detection data, whether the security event corresponding to the first analysis type exists includes: processing the detection data based on a security detection model or algorithm corresponding to the security event to obtain a result of whether the security event exists.

[0018] Through the above design, the network data analysis network element supports deploying a security detection model or algorithm related to security detection, which is used for security detection of a communication network.

[0019] In a possible design, the first information further indicates an event urgency corresponding to the security event, and the event urgency is used to determine a response priority of the security event.

[0020] Through the above design, the network data analysis network element can further indicate the event urgency corresponding to the security event, which is beneficial to the policy control network element to quickly respond to an urgent security event and improve security of the communication network.

[0021] In a second aspect, an embodiment of the present application provides a policy update method, which can be executed by a policy control network element, and the method includes: receiving first information from a network data analysis network element, where the first information indicates a security event corresponding to a first analysis type and a detection target; and sending a control policy corresponding to the security event and the detection target to a flow control node.

[0022] In a possible design, before receiving the first information, the method further includes: sending second information to the network data analysis network element, where the second information indicates the first analysis type.

[0023] In a possible design, the second information further indicates a detection threshold.

[0024] In a possible design, the first analysis type can be a network security aspect analysis type such as security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

[0025] In a possible design, the detection target includes one or more of a region range, a service type, a device type, a slice type, or a time range.

[0026] In a possible design, the first information further indicates an event urgency degree corresponding to the security event, and the event urgency degree is used to determine a response priority of the security event.

[0027] In a third aspect, an embodiment of the present application provides a communication apparatus, which has a function of implementing the method in the first aspect or the second aspect. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules (or units) corresponding to the above functions, such as an interface unit and a processing unit.

[0028] In a possible design, the apparatus can be a chip or an integrated circuit.

[0029] In a possible design, the apparatus includes a memory and a processor, the memory is used to store instructions executed by the processor, and when the instructions are executed by the processor, the apparatus can perform the method in the first aspect or the second aspect.

[0030] In a fourth aspect, an embodiment of the present application provides a communication apparatus, which includes an interface circuit and a processor, and the processor and the interface circuit are coupled with each other. The processor is used to implement the method in the first aspect or the second aspect by means of a logic circuit or executing instructions. The interface circuit is used to receive a signal from another communication apparatus outside the communication apparatus and transmit the signal to the processor, or send a signal from the processor to another communication apparatus outside the communication apparatus. It can be understood that the interface circuit can be a transceiver or a transceiver or a transceiver or an input-output interface.

[0031] Optionally, the communication apparatus can further include a memory, which is used to store instructions executed by the processor, or store input data required by the processor for executing the instructions, or store data generated after the processor executes the instructions. The memory can be a physically independent unit, or can be coupled with the processor, or the processor includes the memory (i.e., the processor and the memory are integrated together).

[0032] In a possible implementation, the communication apparatus is a chip.

[0033] In a fifth aspect, an embodiment of the present application provides a communication system, the communication system comprising a network data analysis network element and a policy control network element, the network data analysis network element being configured to implement the method of the first aspect, and the policy control network element being configured to implement the method of the second aspect.

[0034] In a sixth aspect, an embodiment of the present application provides a computer readable storage medium, the computer readable storage medium storing a computer program or instructions, when the computer program or instructions are executed by a processor, the method of the first aspect or the second aspect can be implemented.

[0035] In a seventh aspect, an embodiment of the present application further provides a computer program product, the computer program product comprising a computer program or instructions, when the computer program or instructions are executed by a processor, the method of the first aspect or the second aspect can be implemented.

[0036] In an eighth aspect, an embodiment of the present application further provides a chip system, the chip system comprising a processor and an interface, the processor being configured to call and execute instructions from the interface, when the processor executes the instructions, the method of the first aspect or the second aspect can be implemented.

[0037] The technical effects achieved by the second aspect to the eighth aspect can refer to the technical effects achieved by the first aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0038] FIG. 1 is a schematic diagram of a service identification and classification mechanism provided by an embodiment of the present application;

[0039] FIG. 2 is a schematic diagram of a configuration mechanism of a static security policy provided by an embodiment of the present application;

[0040] FIG. 3 is a schematic diagram of a data plane function architecture provided by an embodiment of the present application;

[0041] FIG. 4 is a schematic diagram of a policy architecture evolution provided by an embodiment of the present application;

[0042] FIG. 5 is a schematic diagram of a possible, non-limiting unified policy architecture provided by an embodiment of the present application;

[0043] FIG. 6 is a schematic diagram of a mapping relationship in the unified policy architecture provided by an embodiment of the present application;

[0044] FIG. 7 is a schematic diagram of a security policy update mechanism provided by an embodiment of the present application;

[0045] FIGS. 8, 9, 11, 12 and 13 are schematic diagrams of communication methods provided by embodiments of the present application;

[0046] FIG. 10 is a schematic diagram of a model training process provided by an embodiment of the present application;

[0047] FIG. 14 is a schematic diagram of a knowledge graph updating process according to an embodiment of the present application;

[0048] FIGS. 15 and 16 are schematic diagrams of a communication device according to an embodiment of the present application. DETAILED DESCRIPTION

[0049] The present application provides a policy updating method and device. In order to better understand the embodiments of the present application, the related technical features and names involved in the embodiments of the present application will be explained first. It should be noted that these explanations are to make the embodiments of the present application easier to understand, and should not be regarded as limiting the scope of protection required by the present application.

[0050] 1) Policy and charging control (PCC) architecture.

[0051] The PCC architecture is a common policy architecture in the current mobile communication network, mainly the 4G PCRF-based architecture and the 5G PCF-based architecture. In the PCC architecture of the 4G or LTE network, PCRF is the core, which is used to assist traffic data flow detection, policy implementation and flow-based charging, to ensure reliable monitoring of services or use cases and the cost related to each use case. In the PCC architecture of the 5G network, PCF is the core, which can be considered as the evolution of PCRF. PCF has the ability to request and monitor the quality of service in addition to the functions of PCRF. In addition to retaining the session-based function, PCF also has additional functions, including network slice control and new control mechanisms for terminal activity, such as roaming and mobility management.

[0052] The mapping relationship between the data channel and the underlying bearer in the policy architecture of 4G and 5G is different: 4G has end-to-end (E2E) bearers, such as evolved packet system (EPS) bearers, which implement end-to-end quality of service (QoS) through EPS bearers. The sender completes the mapping of data packets to EPS bearers, that is, the association of data packets to bearers can be achieved. The end-to-end E2E transmission of 5G is through quality of service flow (QoS flow), and the transmission involves two levels of mapping, the sender of the data packet maps the data packet to the quality of service flow (QoS flow), and the air interface side QoS flow to the radio bearer (RB) mapping, which can achieve the end-to-end association of data packets and QoS flow.

[0053] Figure 1 illustrates a 5G service identification and classification mechanism. Among them, the PCF makes policy decisions and distributes policy profiles to the user equipment (UE), base station and user plane function (UPF) three nodes, and the corresponding policies are executed by the three nodes. From the service side, 5G policies are mainly reflected in these three network elements, which are the QoS rules on the UE side: responsible for mapping uplink packet groups to QoS flows; QoS profiles of access network (AN) (including radio access network (RAN) and non-3GPP access network): help to manage air interface resource usage and perform aggregate rate control, etc.; service data flow (SDF) classification and QoS related information on the core network side: responsible for mapping downlink packets to QoS flows and performing aggregate rate control, etc.

[0054] Unlike the architecture of 4G policy, all data flows on the same bearer will obtain the same QoS guarantee (such as scheduling policy, buffer queue management, link layer configuration, etc.), and different QoS guarantees use different types of EPS bearers. The basic granularity of 5G QoS architecture is refined to QoS flow, and the two-level mapping of 5G QoS architecture allows the RAN side to have a certain degree of freedom compared to 4G QoS control. To a certain extent, the 5G QoS architecture improves the flexibility and adaptability of service bearer control.

[0055] Referring to the configuration mechanism of the static security policy shown in FIG. 2. Under the 5G policy architecture, the configuration mechanism of the security policy is configured locally in the session management function (SMF), that is, the PCF does not participate in the decision of the security policy. The local security configuration of the SMF can include the following information: user information, local configuration of the user plane (UP) security policy in the SMF, UE-aggregate maximum bit rate (UE-AMBR) based on the integrity protection of the data radio bearer (DRB), etc. The SMF can determine the security execution information of the UP based on the above information, and the security execution information of the UP can be transmitted by the SMF to the base station (such as gNB) through the AMF, and the base station executes the security policy of the user plane over the air, such as verifying the integrity of the data through the integrity key, encrypting and decrypting the data through the encryption and decryption key, etc.

[0056] 2) Data plane function architecture.

[0057] Based on the data plane, a normalized data service architecture can be constructed, which can provide trusted data for artificial intelligence (AI) and perception intelligent services in a communication network. FIG. 3 shows a data plane function architecture, which mainly includes data orchestration (DO), data agent (DA), trust anchor agent (TAA), and data storage function (DSF), wherein the DSF is not shown in FIG. 3.

[0058] Data orchestration DO: can be used to receive data application service requirements, select DA, and orchestrate DA functions, thereby dynamically establishing an E2E logical (overlay) data transmission network topology for data applications, and orchestrating the flow of data between DAs in the network, and feeding back the response to the request to the application.

[0059] Data Agent DA: can be used to provide data collection, preprocessing, storage, analysis, etc. DA can be deployed on network function (NF), radio access network (RAN), transfer network (TN) node, terminal, operation, administration, and maintenance (OAM) of operator network, etc. It can also be deployed independently (standalone).

[0060] In the embodiments of the present application, the DO can select DA according to the business requirements and the capabilities reported by each DA, and arrange DA to establish a dynamic data bearer for providing services for the business. A data bearer has an identifier (ID) of a business and a data service task ID (DSID), and a data bearer can be composed of multiple data pipelines, each data pipeline has its own ID, such as data pipeline ID (DPID). Each data pipeline is composed of a series of data processing units as needed and in sequence, the output of the previous unit is the input of the next unit. Thus, the data stream carried by the data bearer can be output from DA according to the business requirements from data collection, preprocessing, storage to application / analysis, and provided to external applications by DA through a service interface.

[0061] Data Storage Function DSF: DSF is an extension of DA storage, which supports streaming and batch type data; and supports distributed or centralized deployment.

[0062] Trusted Anchor Agent TAA: can be used to provide authentication authorization accounting (AAA) and other trusted services; can store unforgeable data, such as public keys of terminals or network devices, short transactions, indexes, or important data that cannot be tampered with. The data service architecture realizes the autonomous controllability of users to data through the trusted anchor agent, realizes data trust, auditability, traceability, and meets the compliance requirements of personal information protection law (PIPL) or general data protection regulation (GDPR).

[0063] 3) Architecture beyond connection.

[0064] With the introduction of new services such as AI, data, perception, etc., the existing policy architecture cannot support the policy requirements of new services. Therefore, it can be considered to increase policy services for security, data, sustainability, etc. in addition to the existing connection policy. These policy services can be referred to as connection-exceeded policy services, or other names, which are not limited by the present application.

[0065] Figure 4 shows several policy architectures provided by embodiments of the present application. In figure 4(1), a 3G policy architecture is shown. In figure 4(2), a 4G policy architecture is shown. It can be seen that the 3G and 4G policy architectures provide quality of service (QoS) management and charging. In figure 4(3), a 5G policy architecture is shown. It can be seen that the 5G policy architecture adds access management (AM) and UE access policy management. In summary, 3G to 5G is mainly a policy architecture for connection, i.e. a policy for establishing a communication channel between a UE and a network anchor point (such as a 4G public data network (PDN) gateway (GW) and a 5G UPF).

[0066] In figure 4(4), a policy architecture supporting connection-exceeded policy services is shown. Referring to figure 4(4), the policy architecture adds a connection-exceeded policy architecture to the connection policy architecture. The connection-exceeded policy architecture mainly includes policy control function (PCF), policy delivery function (PDF) and policy enforcement function (PEF) and other functions. For the original policy architecture including PCF, session management function (SMF) / access and mobility management function (AMF), user plane function (UPF), it can still be used to serve the connection policy. In combination with connection, plus the connection-exceeded policy architecture, a unified policy architecture is formed.

[0067] The functions of unified data management (UDM) include: for user subscription context management, responsible for managing the subscription data of the UE, and responsible for notifying the corresponding network element when the subscription data is modified.

[0068] The functions of PCF include: for providing user policy management, generating and managing user, session, QoS flow processing policies. It can also provide policy decisions for new services (security, data, sustainability, etc.).

[0069] The functions of the NWDAF include collecting data from NFs (such as SMF, UPF, AMF, etc.), application functions (AF), and operation, administration, and maintenance (OAM) systems of an operator network, then analyzing the collected data, and feeding back the analysis results to the NFs and AFs for subsequent processing.

[0070] The functions of the AMF include access management and mobility management of the UE, responsible for state maintenance of the UE, reachability management of the UE, forwarding of mobility management (MM) non-access-stratum (NAS) messages, forwarding of session management (SM) N2 messages, and the like.

[0071] The functions of the SMF include allocating resources for a session of the UE and releasing the resources. The resources include session quality of service (QoS), session path, forwarding rule, and the like. The SMF is responsible for selecting or reselecting a UPF, allocating an internet protocol (IP) address, and is also responsible for establishing, modifying, and releasing a bearer, and the like.

[0072] The functions of the service subscriber management (SSM) include storing / managing subscription information of users of a service, new user account opening requests, service subscription, and the like. The x in xSSM can be used to represent a corresponding service, and x can be a name or a code of the service, for example, x is sensing, or AI, or data, and the like. When the xSSM is a sensing SSM, it represents user management of a sensing service. When the xSSM is an AI SSM, it represents user management of an artificial intelligence service.

[0073] In the embodiments of the present application, the xSSM can be combined with a unified data management function UDM, or the xSSM can be combined with other storage / management network elements, or the xSSM can be independently deployed, and no limitation is made in this regard.

[0074] The functions of the PDF include: generating policy parameters corresponding to specific service dimensions (such as each data pipeline) according to the policy of the service from the PCF, in combination with the actual needs of the service, network state and other information, and sending the policy parameters to the PEF for execution. In the embodiments of the present application, the PDF can be deployed independently, or can be deployed inside any one of a data controller (DC), a sensing service control function (SSCF), a PCF, a task anchor / task scheduler (TA / TS), etc., and can also be co-located with any one of a data controller (DC), a service control function (SCF), a PCF, a task anchor / task scheduler (TA / TS), etc., in the same device, and no limitation is made in this regard.

[0075] The functions of the PEF include: the PEF receives the policy parameters issued by the PDF, and performs data collection and processing of the service, etc. In the embodiments of the present application, the PEF can be independently deployed, or can be built-in in a UE, a RAN node, a UPF, etc., and no limitation is made in this regard.

[0076] UE: User equipment can refer to a terminal or a terminal device, which can communicate with a core network through an access network AN, and can include an access subscriber unit, a user station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent or a user device. The access terminal can be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication function, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, a wearable device, a terminal in various communication systems evolved after 5G (such as a 6G communication system), etc.

[0077] Functions of the (R)AN include: mainly responsible for providing wireless connection for terminal devices, ensuring reliable transmission of uplink and downlink data of terminal devices, etc. The RAN node can be a base station, an evolved NodeB (eNodeB), an access point (AP), a transmission reception point (TRP), a next generation NodeB (gNB), or a base station in a future mobile communication system (such as a 6G communication system), etc.

[0078] FIG. 5 shows a possible, non-limiting unified policy architecture provided by the embodiments of the present application. As shown in FIG. 5, the policy architecture can include a UE, a (R)AN device, and network elements such as a UDM, a PCF, a network data analytics function (NWDAF), an AMF, an SMF, a UPF, etc.

[0079] In addition, in the policy architecture, a function / network element for providing a beyond connection policy service is added, which can also include: a beyond connection policy decision function, a beyond connection policy transmission function (such as PDF in FIG. 5), a beyond connection policy execution function (such as PEF in FIG. 5), and a beyond connection management function (such as x service subscriber management (xSSM) in FIG. 5).

[0080] Among them, the beyond connection policy decision function can obtain the user subscription information of the service (beyond connection service) from the beyond connection management function, and then formulate the policy of the service according to the user subscription information of the service, and send the policy of the service to the beyond connection policy transmission function; the beyond connection policy transmission function can generate policy parameters of a specific service dimension according to the policy of the service, combined with the actual demand of the service, network state and other information, and send the policy parameters of the specific service dimension to the beyond connection policy execution function for execution.

[0081] In the above, the beyond connection policy decision function can be integrated or built-in in the PCF in FIG. 5, or be a separate NF or network element, which is not limited.

[0082] Exemplarily, taking UE1 participating in three sensing services as an example, FIG. 6 shows the specific mapping relationship among UE1---RAN1---PEF in the unified policy architecture. As shown in FIG. 6, from the left, the PDF sends a NAS message carrying the QoS value corresponding to each service data pipe to the source node UE1, and sends the QoS value corresponding to each service data pipe to the destination node (i.e., RAN1, sensing data processing function (SDPF) 1), in addition, the xSCF also issues a QoS rule to the UE1. The UE1 side performs service identification and shunting processing on the data of the three sensing services collected according to the QoS rule (equivalent to a data packet filter), and adds a 6QI (QoS value), and the data stream of each service is transmitted through the corresponding data pipe. Air interface bearer mapping is performed on the UE1 side, that is, the data pipes of the three sensing services are mapped to the corresponding two DRBs, for example, the data pipe of the sensing service 1 and the data pipe of the sensing service 2 are mapped to the same DRB1, and the data pipe of the sensing service 3 is mapped to another DRB2, and the data of the three sensing services is transmitted to RAN1 through the two wireless air interfaces (also referred to as DRB1 and DRB2), since the destination node of the sensing service 3 is RAN1, the data of the sensing service 3 is no longer transmitted subsequently. For the DRB1 bearing the data of the sensing service 1 and the data of the sensing service 2, RAN1 divides two streams according to the Qos profiles (the Qos profiles include various quality of service parameters, used for RAN to perform air interface processing), that is, the streams corresponding to the sensing service 1 and the sensing service 2 respectively, the two streams are mapped to the tunnels corresponding to the data pipes, and are sent to SDPF1 (equivalent to the destination node PEF1 of the sensing service 1 and the destination node PEF2 of the sensing service 2, which are deployed in SDPF1). SDPF1 further allocates transmission resources (such as bandwidth, delay, priority, etc.) for the sensing service 1 stream by using the QoS value corresponding to the sensing service 1 data pipe, and allocates transmission resources (such as bandwidth, delay, priority, etc.) for the sensing service 2 stream by using the QoS value corresponding to the sensing service 2 data pipe. Based on the unified policy architecture, multi-source and multi-destination mapping can be realized, and policies can be issued to multiple PEFs (i.e., multiple nodes).

[0083] 4) sending / receiving information, in this application, "sending information" can be understood as that a device sends information to another device, or can also be understood as that a logical module in a device sends information to another logical module. For example, "the access network node sends information" can be understood as that the access network node sends information to another device (such as a terminal), or can be understood as that a logical module 1 in the access network node sends information to a logical module 2 in the access network node.

[0084] In the present application, "receiving information" can be understood as a device receiving information from another device, or also can be understood as a logical module in a device receiving information from another logical module. For example, "access network node receiving information" can be understood as the access network node receiving information from another device (such as a terminal), or can be understood as a logical module 1 in the access network node receiving information from a logical module 2 in the access network node.

[0085] In the present application, "sending information to (for example, a terminal)" or related illustrations in the drawings can be understood as that the destination of the information is the terminal. It can include directly or indirectly sending information to the terminal. "Receiving information from (for example, a terminal)" or "receiving information sent by (for example, a terminal)" or "receiving information sent by (for example, a terminal)", or related illustrations in the drawings can be understood as that the source of the information is the terminal, and can include directly or indirectly receiving information from the terminal. The information can be processed as necessary between the source and the destination of the information, such as format change, etc., but the destination can understand the valid information from the source. Similar expressions in the present application can be understood similarly, and will not be repeated here.

[0086] As can be known from the above introduction of the policy architecture, the existing policy architecture mainly focuses on service identification and classification, lacks detection and response mechanisms for security, and cannot meet the security needs of communication networks. For example, the configuration mechanism of the static security configuration in the existing SMF has the following problems:

[0087] (1) In the existing PCC rule, there is no corresponding parameter to identify security events in service data flow detection.

[0088] (2) There is currently no policy security control action for security protection measures after security needs / events occur; for example, a certain service needs to use strong encryption algorithms or longer encryption keys in DRB, etc.

[0089] (3) For new services such as perception and AI, there is a lack of global security real-time monitoring and dynamic response mechanism.

[0090] (4) The firewall, intrusion detection system, etc. in the existing network is mainly to protect the entire network, or to protect a limited part of the network according to its position in the network, without considering linkage with the policy architecture.

[0091] (5) Currently, OAM only collects data such as measurement reports (MR) and minimization of drive tests (MDT), NWDAF mainly connects control plane network elements, mainly receives these data from OAM for analysis, lacks real-time performance, and lacks analysis of security incidents and accidents; UPF only reports statistical information, and it is difficult to find security threats from the statistical information;

[0092] (6) Currently, testing in the network is generally performed manually or by simple automated processes. This method requires experience, is inefficient, cannot be expanded, and often only adjusts defense strategies after a hazard occurs, resulting in significant losses, and the actual defense effect is unknown.

[0093] (7) Collecting traffic will inevitably affect network performance. How to minimize the impact on the network while meeting the sampling requirements of detection is also a problem to be considered.

[0094] Based on this, the embodiment of the application provides a security policy updating scheme, which adds an analysis type such as security situation awareness, is used for detecting whether a security event exists, and responds to a security policy when the security event exists, so as to improve the security response capability of the network.

[0095] The security policy updating scheme provided by the embodiment of the application can be applied to various policy architectures. Taking application to the above-mentioned unified policy architecture as an example, the security policy updating mechanism can be as shown in FIG. 7. The security policy updating mechanism can be divided into two stages: a security detection algorithm or model preparation stage and a security threat detection stage.

[0096] The security detection algorithm or model preparation stage can include the following contents:

[0097] Stage A: Security detection algorithm or model generation.

[0098] (1) Different security detection algorithms or models can be generated for different analysis types (or analysis IDs). For model training that needs to collect data (such as using a supervised machine learning algorithm to train a classification model capable of detecting slow port scanning in a sampling data collection scenario, a malicious software detection model for encrypted traffic, etc.), different sampling rates and / or different matching conditions can be used to collect business data from flow control nodes; data that needs to be collected for a long time can be stored in the DSF; and data collected from other NFs can be combined to train a security detection model or algorithm, so as to detect security events (or security threats) from the flow-through traffic.

[0099] (2) Algorithm or model deployment: local NWDAF, or central NWDAF.

[0100] Stage B: security detection stage. In this stage, PCF, OAM, NEF, AF, etc. can act as consumers and propose detection requirements; UPF, SDPF, OAM, NF, AF, etc. can provide detection data.

[0101] (1) A new analysis type ID (also referred to as a collection event ID, a security event ID, or a security threat detection policy event ID) can be added in a flow control node (such as a UPF or an SDPF) to start security detection. The NWDAF can send the analysis type ID and collection requirements to the flow control node (such as a UPF / SDPF). Unlike the existing flow control node that mainly collects traffic statistical information, the flow control node needs to collect data according to the terminal group, service type, slice type, device type, etc., and the sampling rate. The authorized traffic is collected (sampled). The (sampled) data can be stored in the DSF, which can be used to collect / collect authorized service data from the UPF / SDPF; or the collected / collected service data is directly sent to the NWDAF, or transmitted to the NWDAF through the SMF.

[0102] (2) According to the analysis type ID requested by the consumer, the NWDAF can decide which analysis type ID needs to be used, and what data is collected from the UPF and other NFs, and what sampling rate is used, etc. If the PCF / OAM, etc. subscribes to the "security detection (or security threat detection)" notification, the NWDAF can send a notification about the risk to the subscriber according to the analysis type ID in the abnormal list or the expected analysis type ID indicated by the consumer; the NWDAF can also determine other information elements to be provided according to the observed abnormality, such as the event urgency (or security event level).

[0103] (3) PCF performs security policy update. The NWDAF can analyze based on real-time (sampled) data, security detection model / algorithm, and if a security event (or security threat) is detected, the PCF can be notified to update the policy. For example, allow, prohibit, redirect (such as traffic bypass, redirect to isolation area) traffic, use stronger encryption algorithm, longer encryption key, and issue the action to be executed to the PEF to execute the security update policy, etc.

[0104] The embodiments of the present application will be described in detail below with reference to the accompanying drawings. In addition, it should be understood that the "first", "second", etc. ordinal numbers mentioned in the embodiments of the present application are used to distinguish a plurality of objects, and are not used to limit the size, content, order, time sequence, priority or importance of the plurality of objects. For example, the first information and the second information do not mean that the priority or importance of the two information is different.

[0105] In the embodiments of the present application, the number of nouns represents "a singular noun or a plural noun", that is, "one or more" unless otherwise specified. "At least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent the following cases: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects in front and behind. For example, A / B means A or B. "At least one of the following" or similar expressions means any combination of these items, including any combination of single item or multiple items. For example, at least one of a, b, or c means a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.

[0106] It is worth noting that in the embodiments of the present application, the policy control network element can be the PCF described above, or a network element with the above-mentioned NRF function in a future communication system such as a 6G system, and the network data analysis network element can be the NWDAF described above, or a network element with the above-mentioned NWDAF function in a future communication system such as a 6G system. Similarly, other network elements can also be network elements with corresponding functions in a future communication system such as a 6G system. For ease of illustration, in the embodiments of the present application, the policy control network element is taken as the PCF and the network data analysis network element is taken as the NWDAF for illustration.

[0107] FIG. 8 is one of the communication method diagrams provided by the embodiments of the present application, which includes the following steps:

[0108] S801: The NWDAF obtains detection data corresponding to a first analysis type.

[0109] In the embodiments of the present application, the NWDAF can support security (or security threat) related analysis types, such as security-related analysis types such as security posture awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling. The NWDAF can obtain detection data corresponding to a first analysis type according to a preconfigured first analysis type, or obtain detection data corresponding to a first analysis type according to a first analysis type indicated by a requester (such as a PCF or an OAM). The first analysis type can be any one of the security-related analysis types such as security posture awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

[0110] In a possible implementation, for the existing analytics information, analytics ID and response description of the NWDAF, analytics information, analytics ID and response description corresponding to security-related analytics types such as security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker capability profile can be added.

[0111] For example, referring to Table 1, based on the existing slice load information, observed service experience information and other analytics information, analytics ID and impact description, analytics information, analytics ID and impact description of security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker capability profile can be added. It should be noted that Table 1 only shows part of the analytics information, analytics ID (or request description) and impact description, and more analytics information, analytics ID (or request description) and impact description can be included in Table 1.

[0112] Table 1

[0113] After the NWDAF receives the second information indicating the first analytics type from the requester (such as OAM or PCF), the detection data corresponding to the first analytics type can be obtained based on the sampling rate and / or matching condition corresponding to the first analytics type.

[0114] The second information can be information carried in an analytics information request (Nnwdaf_AnalyticsInfo_Request) message / analytics subscription (Nnwdaf_analytics subscription subscribe) message, etc. For example, the analytics type field can be included in the analytics information request message / analytics subscription message, which can be used to indicate the first analytics type.

[0115] Taking the first analysis type, security situation awareness, as an example, the analysis information request message can adopt the following format, and in the analysis information request message, information of the analysis type being security situation awareness can be included, and one or more of the following information, such as a detection threshold (or a reporting threshold), can also be included.

[0116] Nnwdaf_AnalyticsInfo_Request(

[0117] • Target for Analytics = any UE,

[0118] • type of analytics = security situation awareness,

[0119] • Analytics Filter info = location,

[0120] • Optional Reporting Threshold,

[0121] • Preferred level of accuracy of the analytics,

[0122] • Preferred order of results for the list of Security Situation Awareness statistics or predictions: time, the urgency of the security incident or event, Severity of the security incident or accident,

[0123] • An Analytics target period indicates the time period / regional scope / business type / terminal type over which the statistics or predictions are requested, either in the past or in the future.

[0124] •Optionally, temporal granularity size; and (optionally, time granularity size; and)

[0125] • In a subscription, the Notification Correlation ID and the Notification Target Address are included.

[0126] • Existing situational awareness version / time, such as for updating the knowledge graph)

[0127] Taking the first analysis type as abnormal traffic awareness as an example, the analysis information request message can adopt the following format. The analysis information request message can include information on the analysis type as abnormal traffic awareness, and can also include one or more of the following: detection threshold (or reporting threshold).

[0128] Nnwdaf_AnalyticsInfo_Request(

[0129] • Target for Analytics = any User Experience (UE)

[0130] • Type of analytics = Abnormal traffic awareness

[0131] • Analytics Filter info = location (Analytics Filter Information = Location)

[0132] • Optional Reporting Threshold scan traffic detection threshold, attack traffic like (D)DoS attack based time / traffic threshold (optional reporting threshold / detection threshold, such as scan traffic detection threshold, attack traffic like (D)DoS attack based time / traffic threshold),

[0133] • Preferred level of accuracy of the analytics (analysis of the preferred level of accuracy),

[0134] • Preferred order of results for the list of Abnormal traffic awareness statistics or predictions: time, the urgency of the security incident or event, Severity of the security incident or accident (preferred order of results for the list of Abnormal traffic awareness statistics or predictions: time, the urgency of the security incident or event, Severity of the security incident or accident),

[0135] • An Analytics target period indicates the time period / area range / business type / terminal type over which the statistics or prediction are requested, either in the past or in the future (Analytics target period indicates the time period / area range / business type / terminal type over which the statistics or prediction are requested, either in the past or in the future);

[0136] • Optionally, Temporal granularity size; and (Optionally, Temporal granularity size; and);

[0137] • In a subscription, the Notification Correlation Id and the Notification Target Address are included (In a subscription, the Notification Correlation Id and the Notification Target Address are included).

[0138] Taking the first analysis type as an unknown attack traffic awareness as an example, the analysis information request message can adopt the following format, and one or more of the information of the analysis type being unknown attack traffic awareness, and the detection threshold (or reporting threshold) and the like can be included in the analysis information request message.

[0139] Nnwdaf_AnalyticsInfo_Request(

[0140] • Target for Analytics = any UE,

[0141] • type of analytics = Unknown attack traffic awareness,

[0142] • Analytics Filter info = location,

[0143] • Optional Reporting Threshold,

[0144] • Preferred level of accuracy of the analytics,

[0145] • Preferred order of results for the list of Unknown attack traffic awareness statistics or predictions: time, the urgency of the security incident or event, Severity of the security incident or accident,

[0146] • An Analytics target period indicates the time period / regional scope / business type / terminal type over which the statistics or predictions are requested, either in the past or in the future.

[0147] •Optionally, temporal granularity size; and (optionally, time granularity size; and)

[0148] • In a subscription, the Notification Correlation ID and the Notification Target Address are included.

[0149] Taking the first analysis type as an attacker profile as an example, the analysis information request message can adopt the following format. The analysis information request message can include information on the analysis type of attacker profile, and can also include one or more of the following: detection threshold (or reporting threshold).

[0150] Nnwdaf_AnalyticsInfo_Request(

[0151] • Target for Analytics = a single UE (SUPI) or a group of UEs (i.e., a list of Internal Group IDs)

[0152] • Type of analytics = Attacker capability profile

[0153] •Optionally, Analytics Filter info = location.

[0154] • Optional Reporting Threshold

[0155] • Preferred level of accuracy of the analytics,

[0156] • Preferred order of results for the list of Attacker capability profile statistics or predictions: time, the urgency of the security incident or event, Severity of the security incident or accident

[0157] • Optionally, preferred granularity of location information: TA level or cell level, IP

[0158] • Optionally, Temporal granularity size; and

[0159] • In a subscription, the Notification Correlation Id and the Notification Target Address are included

[0160] It should be noted that the above is only a possible example of the analysis information request message in the case where the first analysis type is security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profile, and does not constitute a limitation on the analysis information request message. In application, the analysis information request message can include more or less information than the above analysis information request message example, or can include different information from the above analysis information request message example.

[0161] After the NDWAF receives the first analysis type analysis information request message / analysis subscription message, it can acquire detection data according to the data collection strategy corresponding to the first analysis type (which can also be referred to as data collection configuration or data collection requirement). For example, collecting service data from a flow control node, or collecting control plane data from an NF, or collecting MDT or MR data from an OAM, wherein the flow control node in the embodiments of the present application can include a UPF and / or an SDPF, and can also include a RAN device and / or a UE.

[0162] In a possible implementation, in order to implement the collection of service data, it is necessary to add monitoring key indicator information on the PCF side, which is used to issue data collection strategies and update the execution of the strategies.

[0163] Example: The monitoring key indicator information shown in Table 2 includes attribute, description, PCF permitted to modify for dynamically provided information, and scope. Based on the existing policy control request trigger, usage monitoring control related, monitoring key, and other monitoring key indicator information, the monitoring key indicator information such as security threat monitoring control related information, security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker capability profile can be added.

[0164] Table 2

[0165] The PCF can indicate which traffic to collect at the flow control node based on the filtering condition. There can be two configuration methods.

[0166] Manner one: when the security detection algorithm or model in the NWDAF needs to collect data from the flow control nodes such as the UPF / SDPF, the data type, sampling rate, etc. are input to the PCF, and the PCF determines the data type collected in the flow control nodes such as the UPF / SDPF, sets the filtering conditions such as service type, terminal type, and area range, and the sampling rate in combination with user or service subscription data, etc. These filtering conditions and collection setting information correspond to the monitoring key such as the abnormal traffic perception monitoring key, but after the NWDAF receives the analysis information request message (corresponding to the abnormal traffic perception), it sends the abnormal traffic perception collection request to the UPF / SDPF, etc. to open the collection switch of these data. The UPF / SDPF matches the data packets passing through, and the matching is successful. The sampling rate is collected and stored in the DSF, or directly to the NWDAF.

[0167] Manner two, optionally, the PCF can only issue monitoring keys such as abnormal traffic perception, and the NWDAF tells the flow control nodes such as the UPF / SDPF to collect specific data and the sampling rate. The PCF corresponds the filtering conditions and collection operations to the monitoring keys such as the abnormal traffic perception.

[0168] S802: The NWDAF determines whether the security event corresponding to the first analysis type exists according to the detection data.

[0169] In the embodiments of the present application, the security detection model (or algorithm) corresponding to each analysis type (such as abnormal traffic perception) can be deployed in the NWDAF, which can be used to detect the security event (or multiple security events) corresponding to the analysis type. Wherein, the security detection model (or algorithm) corresponding to each analysis type can be one or more, wherein any security detection model (or algorithm) can be used to detect one or more security events. For any security detection model (or algorithm) corresponding to the analysis type, it can be trained by a training device and deployed in the NWDAF, or it can be trained and deployed by the NWDAF. The present application does not limit the manner of deploying the security detection model (or algorithm) in the NWDAF.

[0170] In addition, it can be understood that the security event in the embodiments of the present application refers to the event related to network security, such as hijacking of communication network (or device in the communication network), distributed denial of service attack (DDoS) attack, port scanning, denial of service attack, password attack, malware attack, unknown traffic attack, etc. rather than communication aspect exceptions such as signal instability.

[0171] In addition, in some implementations, the security-related analysis types in the embodiments of the present application, such as security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling, can also be security events.

[0172] For example, abnormal traffic awareness can correspond to events such as slow port scanning, DDoS attacks, etc. The security detection model or algorithm deployed for slow port scanning can be a classification model for detecting slow port scanning, the security detection model or algorithm deployed for DDoS attacks can be a neural network model for detecting whether a DDoS attack is suffered, etc.

[0173] After the NWDAF obtains the detection data, the NWDAF can analyze the detection data according to the security detection model or algorithm corresponding to the first analysis type, to determine whether there is a security event corresponding to the first analysis type.

[0174] S803: The NWDAF sends first information to the PCF in the case that the security event corresponding to the first analysis type exists, and the PCF receives the first information correspondingly. The first information indicates the detection target corresponding to the security event and the detection data.

[0175] The detection target includes one or more of a regional range, a service type, a device type, a slice type, or a time range, etc.

[0176] S804: The PCF sends a control policy corresponding to the security event and the detection target to a flow control node, and the flow control node receives the control policy correspondingly.

[0177] When the NWDAF analyzes that there is a security event, a security incident report can be triggered. The NWDAF can report the security event and the sampling target to the PCF (for example, through an Nwdaf_Analysis_Report service operation), the PCF can formulate a control policy according to the security event and the sampling target, and send the control policy to the flow control node, so as to execute security operations such as isolation, bypass traffic, encryption, etc. for the security event, thereby minimizing the impact of the security event on the network, users, etc.

[0178] As an example: the security event is a DDoS attack, and the detection target is a slice type A. The PCF can send a control policy (such as isolating traffic corresponding to the slice type A) to a flow control node (such as a UPF / SDPF) or a PEF in the flow control node via an SMF / PDF, and the flow control node (such as a UPF / SDPF) or the PEF in the flow control node executes the control policy.

[0179] For example, if the security event is a slow port scanning and the target of detection is device type B, the PCF can send a control policy (e.g., bypassing the traffic corresponding to device type B) to the PEF in the flow control node (e.g., UPF / SDPF) via the SMF / PDF, and the control policy is executed by the flow control node (e.g., UPF / SDPF) or the PEF in the flow control node.

[0180] In some embodiments, when reporting the security event to the PCF, the NWDAF can also report the event urgency corresponding to the security event to the PCF, and the event urgency can be used to determine the response priority of the security event, and the higher the event urgency, the higher the response priority.

[0181] For example, the NWDAF can also be configured with a security event whitelist and a security event blacklist, and for the detected security event, the NWDAF can also determine the event urgency of the security event according to the security event whitelist and the security event blacklist, such as the event urgency 1 corresponding to the security event in the whitelist and the event urgency 2 corresponding to the security event in the blacklist, and the event urgency 2 is higher than the event urgency 1, and the PCF can preferentially send the control policy corresponding to the security event with higher event urgency to the flow control node.

[0182] In some embodiments, the control policy sent by the PCF to the flow control node can also include the first analysis type, the analysis ID, the event urgency, the collection target, and the like.

[0183] The above embodiment of FIG. 8 is described below by taking the first analysis type as security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling, and in combination with the specific embodiments of FIG. 9, FIG. 11, FIG. 12, and FIG. 13.

[0184] FIG. 9 is a schematic diagram of a policy updating method according to an embodiment of the present application. In the embodiment shown in FIG. 9, the first analysis type is taken as abnormal traffic awareness, and the method includes the following steps:

[0185] S901: The PCF sends an analysis information request message to the NWDAF, and correspondingly, the NWDAF receives the analysis information request message.

[0186] The analysis information request message (e.g., the second information carried by the message) can indicate that the analysis type is abnormal traffic awareness, and can also indicate one or more of the detection threshold (e.g., the number threshold or the frequency threshold), whether the event urgency corresponding to the security event needs to be reported when the security event is detected, the information (e.g., the area range, the service type, the device type, the slice type, or the time range) that needs to be included in the detection target, and the like.

[0187] In a possible implementation, the OAM can also trigger the NWDAF to perform data analysis of the analysis type of abnormal traffic awareness. For example, the OAM can send an analysis subscription message to the NWDAF, indicating that the analysis type is abnormal traffic awareness, and subscribing to security detection corresponding to abnormal traffic awareness. The analysis subscription message can also indicate one or more of the following information: a detection threshold, whether the event urgency corresponding to the security event needs to be reported when the security event is detected, information that needs to be included in the report of the detection target, and the like.

[0188] The security detection model (or algorithm) corresponding to abnormal traffic awareness can be deployed in the NWDAF and can be used to detect one or more security events corresponding to abnormal traffic awareness. Any security detection model can be used to detect one or more security events. The security detection model corresponding to abnormal traffic awareness can be trained by a model training device and then deployed in the NWDAF, or the NWDAF can train the security detection model corresponding to abnormal traffic awareness and then deploy it after training. The application does not limit the way the security detection model corresponding to abnormal traffic awareness is deployed in the NWDAF.

[0189] For example, the security detection model corresponding to abnormal traffic awareness can include a slow port scanning classification model, a DDoS attack detection model, and the like, which can detect slow port scanning and DDoS attack detection events, respectively. For example, the security detection model corresponding to abnormal traffic awareness includes a slow port scanning classification model, which is trained by the NWDAF. Referring to FIG. 10, a possible model training process provided by an embodiment of the application is shown, which includes the following steps:

[0190] S1001: The OAM sends a model training request to the NWDAF, and the NWDAF receives the model training request accordingly.

[0191] The model training request can indicate abnormal traffic awareness, and be used to request the NWDAF to train a security detection model corresponding to abnormal traffic awareness.

[0192] S1002: The NWDAF obtains training data.

[0193] Abnormal traffic awareness supports slow port scanning detection in a massive data scenario of a high-speed network. After receiving the model training request, the NWDAF can train a classification model for slow port scanning.

[0194] In training the slow port scanning classification model, the NWDAF can obtain training data. For example, the NWDAF can obtain service data in a flow control node (such as a UPF, or an SDPF, etc.), such as setting different sampling rates, different matching conditions (such as one or more of source / desitination IP address, port, protocol, application identification, user identification capability, terminal group, service type, slice type, device type, or time range, etc.) for the flow control node (such as a UPF, or an SDPF, etc.), collecting service data at the flow control node, wherein the NWDAF can also set a collection event ID (such as abnormal traffic perception) for the flow control node, and the service data collected by the flow control node can also be classified and stored (such as classified and stored according to different sampling rates, matching conditions) in the DSF, and the NWDAF can obtain the service data from the DSF. In addition, the NWDAF can also obtain terminal road test, base station KPI, etc. information in the MDT / MR information from the OAM; collect data of other NFs, such as terminal and location data collection of the AMF, session data collection of the SMF, etc.

[0195] S1003: The NWDAF trains the security detection model according to the training data.

[0196] As an example: for any training data, the training data can be marked as whether there is slow port scanning, and a feature extraction algorithm (such as sketch structure, etc.) is used to extract features, and a supervised learning machine learning (ML) algorithm, etc. is used to train a classification model capable of detecting slow port scanning in a sampling data collection scenario.

[0197] Among them, Sketch means sketch, which can use expert knowledge, etc. to depict the characteristics of attack data (which can also be called attack traffic, such as scanning traffic, DDoS attack traffic), which can be used to extract features of service data in the embodiments of the present application. Through the extracted features of the training data, such as the periodicity of UE communication, the duration of communication, or certain traffic characteristics (for example, unusual ports, suspicious DNNs, other useful information, etc.), capacity upload / download (average and variance), etc. can be used for prediction of security events by classification model.

[0198] S1004: The NWDAF deploys the security detection model.

[0199] By a large number of training data marked as whether there is slow port scanning, the classification model for detecting slow port scanning can be continuously trained, and when the detection accuracy of the classification model for detecting slow port scanning meets the performance requirements, the classification model for detecting slow port scanning can be deployed in the NWDAF.

[0200] It can be understood that the above classification model for training detection of slow port scanning is only an example of training an abnormal traffic awareness corresponding model provided by the embodiments of the present application. Other models (such as a DDoS attack detection model) corresponding to abnormal traffic awareness can also be trained by obtaining training data, marking whether the training data exists corresponding security events (such as DDoS attacks), and training the model (such as the DDoS attack detection model) by marking whether the training data exists corresponding security events (such as DDoS attacks).

[0201] Returning to FIG. 9, S902: the NDWAF obtains detection data corresponding to abnormal traffic awareness.

[0202] After the NDWAF receives the analysis information request corresponding to the abnormal traffic awareness, the NDWAF can obtain the detection data corresponding to the abnormal traffic awareness according to the configured data collection strategy (also referred to as data collection requirements) corresponding to the abnormal traffic awareness.

[0203] As an example: the NWDAF can obtain service data in a flow control node (such as a UPF, or an SDPF, etc.), such as setting different sampling rates, different matching conditions (such as one or more of source / desitination IP address, port, protocol, application identification, user identification capability, terminal group, service type, slice type, device type, or time range, etc.) for the flow control node (such as a UPF, or an SDPF, etc.), collecting service data at the flow control node, wherein the NWDAF can also set event ID (such as abnormal traffic awareness) for the flow control node, and the service data collected by the flow control node can also be stored in the DSF in a classified manner (such as classified storage according to different sampling rates and matching conditions), and the NWFAF can obtain the service data from the DSF. In addition, the NWDAF can also obtain terminal road test, base station KPI, etc. information from the MDT / MR information of the OAM; collect data of other NFs, such as terminal and location data collection of the AMF, session data collection of the SMF, etc.

[0204] S903: The NWDAF determines whether the security event corresponding to the abnormal traffic awareness exists according to the detection data.

[0205] After the NWDAF obtains the detection data, the NWDAF can analyze the detection data based on the security detection model (such as a slow port scanning detection model, or a DDoS attack detection model, etc.) corresponding to the abnormal traffic awareness, and obtain the detection result output by the detection model, including whether the security event (such as slow port scanning, or DDoS attack, etc.) corresponding to the abnormal traffic awareness exists.

[0206] S904: The NWDAF sends an analytics information response (Nnwdaf_AnalyticsInfo_Repond) message to the PCF in the case that the abnormal traffic sensing corresponding security event exists, and the PCF receives the analytics information response message accordingly.

[0207] In a possible implementation, if the NWDAF detects that the abnormal traffic sensing corresponding security event exists, the NWDAF can send an analytics information response message to the PCF, and the analytics information response message (such as first information carried in the message) can indicate the security event, and the detection target (such as the area range, the service type, the device type, the slice type, or the time range, etc.) corresponding to the detection data.

[0208] In addition, if the analytics information request message also indicates a detection threshold, the detection threshold can be one or more of a number threshold, or a frequency threshold, etc. Before the NWDAF sends the analytics information response message to the PCF, it can also be determined that the detection result meets the detection threshold, that is, the analytics information response message is sent in the case that the detection result meets the detection threshold requirement.

[0209] For example, if the analytics information request message indicates a number threshold, the NWDAF can send the analytics information response message to the PCF in the case that the number of times of detecting that the security event exists is not less than the number threshold.

[0210] Or, if the analytics information request message indicates a frequency threshold, the NWDAF can send the analytics information response message to the PCF in the case that the frequency of detecting that the security event exists is not less than the frequency threshold.

[0211] In some implementations, if the OAM also subscribes to the security detection of the abnormal traffic sensing, the NWDAF can also send the analytics information response message to the OAM.

[0212] S905: The PCF sends a control policy corresponding to the security event and the detection target to the flow control node, and the flow control node receives the control policy accordingly.

[0213] In the embodiments of the present application, the PCF receives the analytics information response message, can determine the control policy according to the security event and the detection target, and deliver it to the flow control node for execution, and the specific implementation can refer to the implementation of S804 and will not be described again.

[0214] FIG. 11 is a third schematic diagram of a policy updating method provided by the embodiments of the present application. In the embodiment shown in FIG. 11, the first analysis type is taken as an example of attacker profiling, and the method includes the following steps:

[0215] S1101: The PCF sends an analytics information request message to the NWDAF, and the NWDAF receives the analytics information request message accordingly.

[0216] The analysis information request message (such as the second information carried by the message) can indicate one or more of the following: the analysis type is attacker profiling, and can also indicate a detection threshold (such as a malicious traffic detection threshold, a number of times threshold, or a frequency threshold, etc.), whether the event urgency corresponding to the security event needs to be reported when it is detected that the security event exists, information that needs to be included in the reporting of the detection target (such as a regional range, a service type, a device type, a slice type, or a time range, etc.), and the like.

[0217] In a possible implementation, the NWDAF can also be triggered by the OAM to perform data analysis of the analysis type of attacker profiling. For example, the OAM can send an analysis subscription message to the NWDAF indicating that the analysis type is attacker profiling, and subscribe to security detection corresponding to the attacker profiling. The analysis subscription message can also indicate one or more of the following: a detection threshold, whether the event urgency corresponding to the security event needs to be reported when it is detected that the security event exists, and information that needs to be included in the reporting of the detection target.

[0218] The NWDAF can be deployed with a security detection model (or algorithm) corresponding to the attacker profiling, which can be used to detect one or more security events corresponding to the attacker profiling. The security detection model corresponding to the attacker profiling can be one or more, and any security detection model can be used to detect one or more security events. The security detection model corresponding to the attacker profiling can be trained by a model training device and deployed in the NWDAF, or the NWDAF can train the security detection model corresponding to the attacker profiling and deploy it after training is completed. The application does not limit the manner in which the security detection model corresponding to the attacker profiling is deployed in the NWDAF.

[0219] For example, the security detection model corresponding to the attacker profiling can include an encrypted malicious traffic detection model based on a hidden Markov model (profile HMM). The trained encrypted malicious traffic detection model based on the hidden Markov model can be deployed in the NWDAF and can be used to detect malicious software traffic under multiple encryption protocols. The application of the hidden Markov model to encrypted malicious traffic detection can retain the key sequence in the traffic sequence generated by a malicious attack, thereby retaining the characteristics of the malicious attack. By analogy with biological homology analysis, the core gene fragment carried by the homologous sequence is used to trace the gene family to which it belongs. The detection sample is converted into a symbol sequence and compared with known sequences to achieve the purpose of detection.

[0220] S1102: The NWDAF obtains detection data corresponding to the attacker profiling.

[0221] After receiving the analysis information request corresponding to the attacker profile, the NDWAF can acquire the detection data corresponding to the attacker profile according to the configured data acquisition strategy (which can also be referred to as data acquisition requirement) corresponding to the attacker profile.

[0222] As an example: the NWDAF can acquire service data in a flow control node (such as a UPF, or an SDPF, etc.), such as setting different sampling rates, different matching conditions (such as one or more of source / desitination IP address, port, protocol, application identification, user identification capability, terminal group, service type, slice type, device type, or time range, etc.) for the flow control node (such as a UPF, or an SDPF, etc.), and collecting service data at the flow control node, wherein the NWDAF can also set an event ID (such as an attacker profile) for the flow control node, and the service data collected by the flow control node can also be stored in the DSF in a classified manner (such as classified storage according to different sampling rates and matching conditions), and the NWDAF can acquire the service data from the DSF. In addition, the NWDAF can also acquire terminal road test, base station KPI, etc. information in the MDT / MR information from the OAM; collect data of other NFs, such as terminal and location data collection of the AMF, session data collection of the SMF, etc.

[0223] S1103: The NWDAF determines whether the security event corresponding to the attacker profile exists according to the detection data.

[0224] After the NWDAF acquires the detection data, the NWDAF can analyze the detection data based on a security detection model (such as an encrypted malicious traffic detection model based on a Profile HMM) corresponding to the attacker profile, and identify the detection results of the existing malicious traffic (which can also be referred to as malicious data), information of the attacker (such as attacker address information), etc.

[0225] S1104: The NWDAF sends an analysis information response message to the PCF in the case that the security event corresponding to the attacker profile exists, and correspondingly, the PCF receives the analysis information response message.

[0226] In a possible implementation, if the NWDAF detects that the security event corresponding to the attacker profile exists (such as detecting malicious traffic), the NWDAF can send an analysis information response message to the PCF, and the analysis information response message (such as first information carried in the message) can indicate the detection target (such as regional range, service type, device type, slice type, or time range, etc.) corresponding to the security event and the detection data, and can also indicate the attacker address information.

[0227] In addition, if the analysis information request message further indicates a detection threshold, the detection threshold can be one or more of a malicious traffic detection threshold, a number threshold, or a frequency threshold, etc. Before the NWDAF sends the analysis information response message to the PCF, it can also be determined that the detection result meets the detection threshold.

[0228] For example, if the analysis information request message indicates a malicious traffic detection threshold, the NWDAF can send the analysis information response message to the PCF if the detected malicious traffic is not less than (i.e., greater than or equal to) the malicious traffic detection threshold.

[0229] If the analysis information request message indicates a number threshold, the NWDAF can send the analysis information response message to the PCF if the number of times that the security event is detected to exist is not less than the number threshold.

[0230] Or, if the analysis information request message indicates a frequency threshold, the NWDAF can send the analysis information response message to the PCF if the frequency of detecting the existence of the security event is not less than the frequency threshold.

[0231] In some implementations, if the OAM also subscribes to security detection of the attacker profile, the NWDAF can also send the analysis information response message to the OAM.

[0232] S1105: The PCF sends a control policy corresponding to the security event and the detection target to the flow control node, and accordingly, the flow control node receives the control policy.

[0233] In the embodiments of the present application, the PCF receives the analysis information response message, can determine the control policy according to the security event and the detection target, and deliver it to the flow control node for execution. The specific implementation can refer to the implementation at S804 and will not be described again.

[0234] FIG. 12 is a fourth schematic diagram of a policy updating method provided by the embodiments of the present application. In the embodiment shown in FIG. 12, taking unknown traffic awareness as the first analysis type for example, the method includes the following steps:

[0235] S1201: The PCF sends an analysis information request message to the NWDAF, and accordingly, the NWDAF receives the analysis information request message.

[0236] The analysis information request message (such as the second information carried by the message) can indicate that the analysis type is unknown attack traffic awareness, and can also indicate one or more of a detection threshold (such as a number threshold or a frequency threshold, etc.), whether the event urgency corresponding to the security event needs to be reported when the security event is detected to exist, information that needs to be included in the reporting detection target (such as regional range, service type, device type, slice type, or time range, etc.), etc.

[0237] In a possible implementation, the NWDAF can also be triggered by the OAM to perform data analysis of the unknown attack traffic perception type. For example, the OAM can send an analysis subscription message to the NWDAF, indicating that the analysis type is unknown attack traffic perception, and subscribe to security detection of unknown attack traffic perception. The analysis subscription message can also indicate one or more of the following information: a detection threshold, whether the event emergency degree corresponding to the security event needs to be reported when it is detected that the security event exists, information that needs to be included in the report of the detection target, and the like.

[0238] The security detection model (or algorithm) corresponding to the unknown attack traffic perception can be deployed in the NWDAF, and can be used to detect the security event (or events) corresponding to the unknown attack traffic perception. The security detection model corresponding to the unknown attack traffic perception can be one or more, and any security detection model can be used to detect one or more security events. The security detection model corresponding to the unknown attack traffic perception can be trained by a model training device and then deployed in the NWDAF, or the NWDAF can train the security detection model corresponding to the unknown attack traffic perception and then deploy it after the training is completed. The application does not limit the way in which the security detection model corresponding to the unknown attack traffic perception is deployed in the NWDAF.

[0239] For example, the security detection model corresponding to the unknown attack traffic perception can include a feature sketch model, which can detect packet loss of TCP and UDP. For example, X features and Y features can be selected for TCP and UDP protocols respectively to match the packet loss situation, and X and Y are greater than or equal to 1.

[0240] S1202: The NWDAF obtains detection data corresponding to the unknown attack traffic perception.

[0241] After receiving the analysis information request corresponding to the unknown attack traffic perception, the NWDAF can obtain the detection data corresponding to the unknown attack traffic perception according to the configured data collection strategy (which can also be referred to as data collection requirement) corresponding to the unknown attack traffic perception.

[0242] As an example: the NWDAF can acquire service data in a flow control node (such as a UPF, or an SDPF, etc.), such as setting different sampling rates, different matching conditions (such as one or more of different source / destination IP addresses, ports, protocols, application identifications, user identification capabilities, terminal groups, service types, slice types, device types, or time ranges, etc.) for the flow control node (such as a UPF, or an SDPF, etc.), collecting service data at the flow control node, wherein the NWDAF can also set a collection event ID (such as unknown attack traffic perception) for the flow control node, and the service data collected by the flow control node can also be stored in the DSF in a classified manner (such as classified storage according to different sampling rates, matching conditions). The NWDAF can acquire service data from the DSF. In addition, the NWDAF can also acquire terminal road test, base station KPI, etc. information in the MDT / MR information from the OAM; collect data of other NFs, such as terminal and location data collection of the AMF, session data collection of the SMF, etc.

[0243] S1203: The NWDAF determines whether the security event corresponding to the unknown attack traffic perception exists according to the detection data.

[0244] After the NWDAF acquires the detection data, the NWDAF can analyze the detection data based on the security detection model (such as the feature sketch model) corresponding to the unknown attack traffic perception, and obtain detection results such as packet loss rate.

[0245] For example, after the NWDAF acquires the detection data, the NWDAF can obtain the packet loss rate according to the feature sketch model, and determine that there is unknown attack traffic in the case where the packet loss rate is greater than the packet loss rate threshold.

[0246] S1204: The NWDAF sends an analysis information response message to the PCF in the case where the security event corresponding to the unknown attack traffic perception exists, and correspondingly, the PCF receives the analysis information response message.

[0247] In a possible implementation, if the NWDAF detects that the security event corresponding to the unknown attack traffic perception exists, the NWDAF can send an analysis information response message to the PCF. The analysis information response message (such as the first information carried in the message) can indicate the detection target (such as the area range, service type, device type, slice type, or time range, etc.) corresponding to the security event and the detection data.

[0248] In addition, if the analysis information request message also indicates a detection threshold, the detection threshold can be one or more of a number threshold or a frequency threshold, etc. Before the NWDAF sends the analysis information response message to the PCF, it can also be determined that the detection result meets the detection threshold.

[0249] For example, if the analysis information request message indicates a times threshold, the NWDAF can send the analysis information response message to the PCF in a case that the number of times that the security event is detected is not less than the times threshold.

[0250] Or, if the analysis information request message indicates a frequency threshold, the NWDAF can send the analysis information response message to the PCF in a case that the frequency that the security event is detected is not less than the frequency threshold.

[0251] In some implementations, if the OAM also subscribes to the security detection of the unknown attack traffic awareness, the NWDAF can also send the analysis information response message to the OAM.

[0252] S1205: The PCF sends a control policy corresponding to the security event and the detection target to the flow control node, and accordingly, the flow control node receives the control policy.

[0253] In the embodiments of the present application, the PCF receives the analysis information response message, can determine the control policy according to the security event and the detection target, and deliver the control policy to the flow control node for execution. The specific implementation can refer to the implementation at S804 and will not be described again.

[0254] FIG. 13 is a fifth schematic diagram of a policy updating method provided by the embodiments of the present application. In the embodiment shown in FIG. 13, taking the first analysis type as security situation awareness as an example, the method includes the following steps:

[0255] S1301: The PCF sends an analysis information request message to the NWDAF, and accordingly, the NWDAF receives the analysis information request message.

[0256] The analysis information request message (such as the second information carried by the message) can indicate that the analysis type is security situation awareness, and can also indicate one or more of the following information: a detection threshold (such as a times threshold, or a frequency threshold, etc.), whether the event urgency corresponding to the security event needs to be reported when the security event is detected to exist, information that needs to be included in the reporting detection target (such as a regional range, a service type, a device type, a slice type, or a time range, etc.).

[0257] In a possible implementation, the NWDAF can also be triggered by the OAM to perform data analysis of the analysis type of security situation awareness. For example, the OAM can send an analysis subscription message indicating that the analysis type is security situation awareness to the NWDAF, and subscribe to the security detection of the security situation awareness. The analysis subscription message can also indicate one or more of the following information: a detection threshold, whether the event urgency corresponding to the security event needs to be reported when the security event is detected to exist, information that needs to be included in the reporting detection target, etc.

[0258] The security detection algorithm corresponding to the security situation awareness can be deployed in the NWDAF, and can be used to detect the security event(s) corresponding to the security situation awareness.

[0259] An example: the algorithm corresponding to the security situation awareness can be a knowledge graph-based detection algorithm. The constructed knowledge graph can include features / information of various security events. The initial indication graph can be constructed based on expert knowledge, etc., and can be continuously updated.

[0260] S1302: The NWDAF obtains detection data corresponding to the security situation awareness.

[0261] After the NWDAF receives the analysis information request corresponding to the security situation awareness, it can obtain the detection data corresponding to the security situation awareness according to the configured data collection strategy (also referred to as data collection requirement) corresponding to the security situation awareness.

[0262] As an example: the NWDAF can obtain service data in a flow control node (such as a UPF or an SDPF, etc.). For example, different sampling rates and different matching conditions (such as one or more of source / desination IP address, port, protocol, application identification, user identification capability, terminal group, service type, slice type, device type, or time range, etc.) can be set for the flow control node (such as a UPF or an SDPF, etc.), and service data at the flow control node can be collected. The NWDAF can also set event ID (such as security situation awareness) for the flow control node, and the service data collected by the flow control node can be stored in the DSF in a classified manner (such as according to different sampling rates and matching conditions). The NWDAF can also obtain terminal road test and base station KPI information from the MDT / MR information from the OAM; collect data of other NFs, such as terminal and location data collection of the AMF, session data collection of the SMF, etc.

[0263] S1303: The NWDAF determines whether the security event corresponding to the security situation awareness exists according to the detection data.

[0264] After the NWDAF obtains the detection data, it can process the detection data based on the knowledge graph corresponding to the security situation awareness, and obtain a detection result of whether the security event (such as abnormal traffic attack, unknown traffic attack, traffic congestion, UE anomaly, etc.) corresponding to the security situation awareness exists.

[0265] In some implementations, for the detection data corresponding to the detected security event, the NWDAF can also extract the features of the detection data, supplement them to the knowledge graph, and update the knowledge graph.

[0266] In some embodiments, the NWDAF can also actively update the knowledge graph, such as obtaining detection data and updating the knowledge graph without receiving the analysis information request message of the PCF or the analysis subscription message of the OAM.

[0267] As an example, referring to FIG. 14, after the security situation awareness knowledge graph constructed based on expert knowledge, operation and maintenance experience, historical alarm information, etc. is deployed to the NWDAF as an initial graph, the NWDAF can obtain detection data and update the knowledge graph based on the detection data. For example: fuse data information (such as fusing the packet content of the detection data into flow statistical characteristics, combining terminal location, connection state, etc.), add all security situation awareness related and analysis results and associated information (such as root cause, alarm, security event, involved network element, etc.) to the knowledge graph, and constantly update the knowledge graph.

[0268] S1304: The NWDAF sends an analysis information response message to the PCF in the case where the security event corresponding to the security situation awareness exists, and correspondingly, the PCF receives the analysis information response message.

[0269] In a possible implementation, if the NWDAF detects that the security event corresponding to the security situation awareness exists, the NWDAF can send an analysis information response message to the PCF. The analysis information response message (such as the first information carried by the message) can indicate the security event and the detection target (such as the area range, service type, device type, slice type, or time range, etc.) corresponding to the detection data.

[0270] In addition, if the analysis information request message also indicates a detection threshold, the detection threshold can be one or more of a number threshold or a frequency threshold, etc. Before the NWDAF sends the analysis information response message to the PCF, it can also be determined that the detection result meets the detection threshold.

[0271] For example: if the analysis information request message indicates a number threshold, the NWDAF can send an analysis information response message to the PCF in the case where the number of times of detecting that the security event exists is not less than the number threshold.

[0272] Or, if the analysis information request message indicates a frequency threshold, the NWDAF can send an analysis information response message to the PCF in the case where the frequency of detecting that the security event exists is not less than the frequency threshold.

[0273] In some embodiments, if the OAM also subscribes to security detection of the security situation awareness, the NWDAF can also send an analysis information response message to the OAM.

[0274] S1305: The PCF sends a control policy corresponding to the security event and the detection target to the flow control node. Correspondingly, the flow control node receives the control policy.

[0275] In the embodiments of the present application, the PCF receives the analysis information response message, can determine the control policy according to the security event and the detection target, and deliver it to the flow control node for execution. The specific implementation can refer to the implementation at S804 and will not be described again.

[0276] It can be understood that, in order to implement the functions in the above embodiments, the network data analysis network element (such as NWDAF) or the policy control network element (such as PCF) includes a hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that, in combination with the units and method steps of each example described in the embodiments disclosed in the present application, the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driven hardware depends on the specific application scenario and design constraints of the technical solution.

[0277] FIGS. 15 and 16 are structural schematic diagrams of possible communication apparatuses provided by the embodiments of the present application. These communication apparatuses can be used to implement the functions of the network data analysis network element or the policy control network element in the above method embodiments, and thus can also achieve the beneficial effects possessed by the above method embodiments.

[0278] As shown in FIG. 15, the communication apparatus 1500 includes a processing unit 1510 and an interface unit 1520, wherein the processing unit 1510 can be a processor or processing circuit, and the interface unit 1520 can also be a transceiver unit or an input / output interface or a transceiver, etc. The communication apparatus 1500 can be used to implement the steps executed by the network data analysis network element or the policy control network element in the above embodiments.

[0279] When the communication apparatus 1500 is used to implement the steps executed by the network data analysis network element (such as NWDAF) in the above embodiments, the processing unit 1510 is configured to:

[0280] The interface unit 1520 is configured to acquire detection data corresponding to a first analysis type; the processing unit 1510 is configured to determine whether a security event corresponding to the first analysis type exists according to the detection data; and the interface unit 1520 is further configured to send first information to a policy control network element in a case where the security event corresponding to the first analysis type exists, the first information indicating a detection target corresponding to the security event and the detection data.

[0281] In a possible design, when the interface unit 1520 acquires the detection data corresponding to the first analysis type, it is specifically configured to send a data collection requirement to a flow control node, the data collection requirement indicating the first analysis type and the detection target; and receive the detection data from the flow control node.

[0282] In a possible design, before the interface unit 1520 acquires the detection data corresponding to the first analysis type, the interface unit 1520 is further configured to receive second information from the policy control network element, where the second information indicates the first analysis type. Optionally, the second information further indicates the detection threshold.

[0283] In a possible design, the first analysis type is security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

[0284] In a possible design, the detection target includes one or more of the following information: a region range, a service type, a device type, a slice type, or a time range.

[0285] In a possible design, when the processing unit 1510 determines whether the security event corresponding to the first analysis type exists according to the detection data, the processing unit 1510 is specifically configured to process the detection data based on a security detection model or algorithm corresponding to the security event, to obtain a result of whether the security event exists.

[0286] In a possible design, the first information further indicates an event urgency degree corresponding to the security event, and the event urgency degree is used to determine a response priority of the security event.

[0287] When the communication apparatus 1500 is configured to implement the steps performed by the policy control network element (for example, the PCF) in the above-described embodiments, the following specifically applies:

[0288] The interface unit 1520 is configured to receive first information from a network data analysis network element, where the first information indicates a security event and a detection target corresponding to a first analysis type; the processing unit 1510 is configured to determine a control policy corresponding to the security event and the detection target; and the interface unit 1520 is further configured to send the control policy to a flow control node.

[0289] In a possible design, before the interface unit 1520 receives the first information, the interface unit 1520 is further configured to send second information to the network data analysis network element, where the second information indicates the first analysis type. Optionally, the second information further indicates the detection threshold.

[0290] In a possible design, the first analysis type is security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

[0291] In a possible design, the detection target includes one or more of the following information: a region range, a service type, a device type, a slice type, or a time range.

[0292] In a possible design, the first information further indicates an event urgency degree corresponding to the security event, and the event urgency degree is used to determine a response priority of the security event.

[0293] As shown in FIG. 16, the application further provides a communication device 1600, which comprises a processor 1610 and can further comprise a communication interface 1620. The processor 1610 and the communication interface 1620 are coupled with each other. It can be understood that the communication interface 1620 can be a transceiver, an input / output interface, an input interface, an output interface, an interface circuit, etc. Optionally, the communication device 1600 can further comprise a memory 1630 for storing instructions executed by the processor 1610 or storing input data required by the processor 1610 for executing instructions or storing data generated after the processor 1610 executes instructions. The memory 1630 can be a physically independent unit coupled with the processor 1610 or the processor 1610 and the memory 1630 can be integrated together.

[0294] When the communication device 1600 is used to implement steps performed by the network data analysis network element or the policy control network element in the above-mentioned embodiments, the processor 1610 can be used to implement functions of the processing unit 1510 and the communication interface 1620 can be used to implement functions of the interface unit 1520.

[0295] It can be understood that the processor in the embodiments of the application can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), logic circuits, field programmable gate arrays (FPGA) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.

[0296] The method steps in the embodiments of the present application can be realized by hardware or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an erasable programmable read-only memory, an electrically erasable programmable read-only memory, a register, a hard disk, a mobile hard disk, a CD-ROM, or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an ASIC. In addition, the ASIC can be located in a network device or a terminal device. Of course, the processor and the storage medium can also exist as discrete components in a network device or a terminal device.

[0297] In the above embodiments, the implementation can be wholly or partially realized by software, hardware, firmware or any combination thereof. When realized by software, the implementation can be wholly or partially realized in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When loaded and executed by a computer, the computer programs or instructions perform the flow or function described in the embodiments of the present application. The computer can be a general purpose computer, a special purpose computer, a computer network, a network device, a user equipment or other programmable apparatus. The computer programs or instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another, for example, the computer programs or instructions can be transferred from one network device, terminal, computer, server or data center to another network device, terminal, computer, server or data center through a wired or wireless manner. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center or the like integrated with one or more available media. The available medium can be a magnetic medium, for example, a floppy disk, a hard disk, a magnetic tape; an optical medium, for example, a digital video disc; or a semiconductor medium, for example, a solid state disk. The computer readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile storage media.

[0298] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be mutually referred to if there is no special description and no logical conflict. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0299] In addition, it should be understood that the word "exemplary" is used only to mean that an example is provided, and that the example is not to be construed as being more preferred or advantageous than other examples. Rather, the word "exemplary" is used to present concepts in a concrete manner.

[0300] It can be understood that various numbers involved in the embodiments of the present application are only for the convenience of differentiation, and are not used to limit the scope of the embodiments of the present application. The size of the serial numbers of the above processes does not mean the order of execution, and the execution order of the processes should be determined according to their functions and inherent logic.

Claims

1. A policy updating method characterized by comprising: The method comprises: obtaining detection data corresponding to a first analysis type; determining whether a security event corresponding to the first analysis type exists according to the detection data; in the case where the security event corresponding to the first analysis type exists, sending first information to a policy control network element, the first information indicating the security event and a detection target corresponding to the detection data.

2. The method of claim 1, wherein, The obtaining of the detection data corresponding to the first analysis type comprises: sending a data collection requirement to a flow control node, the data collection requirement indicating the first analysis type and the detection target; receiving the detection data from the flow control node.

3. The method of claim 1 or 2, wherein, Before the obtaining of the detection data corresponding to the first analysis type, the method further comprises: receiving second information from the policy control network element, the second information indicating the first analysis type.

4. The method of claim 3, wherein, The second information further indicates a detection threshold.

5. The method of any one of claims 1-4, wherein, The first analysis type is security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

6. The method of any one of claims 1-5, wherein, The detection target comprises one or more of the following information: a regional range, a service type, a device type, a slice type, or a time range.

7. The method of any one of claims 1-6, wherein, The determining of whether the security event corresponding to the first analysis type exists according to the detection data comprises: processing the detection data based on a security detection model or algorithm corresponding to the security event to obtain a result of whether the security event exists.

8. The method of any one of claims 1-7, wherein, The first information further indicates an event urgency degree corresponding to the security event, the event urgency degree being used to determine a response priority of the security event.

9. A policy updating method characterized by comprising: The method comprises: receiving first information from a network data analysis network element, the first information indicating a security event corresponding to a first analysis type and a detection target; sending a control policy corresponding to the security event and the detection target to a flow control node.

10. The method of claim 9, wherein, Before the receiving of the first information, the method further comprises: sending second information to the network data analysis network element, the second information indicating the first analysis type.

11. The method of claim 10, wherein, The second information further indicates a detection threshold.

12. The method of any one of claims 9-11, wherein, The first analysis type is security situation awareness, abnormal traffic awareness, unknown attack traffic awareness, or attacker profiling.

13. The method of any one of claims 9-12, wherein, The detection target comprises one or more of the following information: a regional range, a service type, a device type, a slice type, or a time range.

14. The method of any one of claims 9-13, wherein, The first information further indicates an event urgency degree corresponding to the security event, the event urgency degree being used to determine a response priority of the security event.

15. A communications device, characterized by The apparatus comprises units for performing the method of any one of claims 1-8, or the method of any one of claims 9-14.

16. A communications device, characterized by The apparatus comprises a processor and an interface circuit for receiving a signal from another communication apparatus outside the communication apparatus and transmitting the signal to the processor, or transmitting a signal from the processor to another communication apparatus outside the communication apparatus, the processor being used to implement the method of any one of claims 1-8, or the method of any one of claims 9-14 through a logic circuit or an execution instruction.

17. A computer program product, characterised in that, A computer program product tangibly embodying a program of instructions executable by a processor to perform a method as claimed in any of claims 1-8, or a method as claimed in any of claims 9-14.

18. A chip system, characterized by The chip system comprises: a processor and an interface, the processor being configured to call and execute instructions from the interface, the processor being configured to implement a method as claimed in any of claims 1-8, or a method as claimed in any of claims 9-14, when executing the instructions.

19. A computer-readable storage medium, characterized in that, The storage medium has stored therein a computer program or instructions, which, when executed by a processor, cause a method as claimed in any of claims 1-8, or a method as claimed in any of claims 9-14, to be implemented.

20. A communication system, characterized by comprising a network data analytics network element and a policy control network element; the network data analytics network element being configured to implement a method as claimed in any of claims 1-8; the policy control network element being configured to implement a method as claimed in any of claims 9-14.

Citation Information

Patent Citations

  • Terminal UE management and control method and device

    CN110351229A

  • Access control method and device

    CN115767542A

  • Data analysis method and device

    CN116235526A

  • Network event processing method and apparatus, and readable storage medium

    WO2021151335A1