Autoencoder-based method and apparatus for detecting abnormal terminal in wireless communication system

WO2026160563A1PCT designated stage Publication Date: 2026-07-30SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2025-10-20
Publication Date
2026-07-30

Smart Images

  • Figure KR2025016596_30072026_PF_FP_ABST
    Figure KR2025016596_30072026_PF_FP_ABST
Patent Text Reader

Abstract

A method performed by an electronic device according to an embodiment may comprise the operations of: acquiring data regarding a designated terminal operation according to an abnormal operation type with respect to a target terminal to be checked as to whether same performs an abnormal operation; acquiring output data by applying the data regarding the designated terminal operation of the target terminal to an autoencoder-based artificial intelligence model; and determining whether the target terminal performs an abnormal operation on the basis of whether a reconstruction loss of the output data exceeds a designated reconstruction range.
Need to check novelty before this filing date? Find Prior Art

Description

Autoencoder-based method and device for detecting abnormal terminals in a wireless communication system

[0001] The present disclosure relates to a technology for detecting abnormal terminals within a network using artificial intelligence, and in particular, to a technology for detecting abnormal patterns in network traffic and identifying terminals exhibiting abnormal behavior using an autoencoder algorithm.

[0002] With the recent proliferation of 5G networks and the surge in IoT devices, the number of devices connected to networks is increasing explosively. Consequently, the importance of network security is becoming more prominent, and in particular, the rapid detection and response to devices exhibiting abnormal behavior is emerging as a key challenge in network management.

[0003] Existing network anomaly detection technologies have primarily relied on rule-based methods. Since these approaches detect anomalous behavior based on predefined patterns or critical ranges (or thresholds), they were able to effectively respond to known attack patterns. However, their detection capabilities were limited against new types of attacks or sophisticated threats, and there was a problem of rising false positive rates as the complexity of network traffic increased.

[0004] To overcome these limitations, anomaly detection methods utilizing artificial intelligence and machine learning technologies have recently been gaining attention. AI-based anomaly detection technology learns from large volumes of network traffic data to identify normal patterns and, based on this, can identify abnormal behavior. In particular, the use of unsupervised learning algorithms enables the effective detection of anomaly patterns, allowing for a response to new and unknown types of threats.

[0005] An autoencoder is a neural network structure based on unsupervised learning that can learn data features through a process of encoding input data into a compressed representation and then decoding it back into its original form. In the field of network anomaly detection, autoencoders can be utilized to learn normal traffic patterns and, based on this, identify abnormal patterns.

[0006] However, network traffic data involves a complex interplay of various protocols, services, and user behavior patterns, making it difficult for simple autoencoders to effectively learn all normal patterns. Furthermore, extracting inappropriate features from network traffic and using them as input to the autoencoder can degrade detection performance. Additionally, while network traffic exhibits characteristics that change over time, existing autoencoder structures struggle to adequately reflect these temporal properties. Moreover, although traffic patterns can vary depending on different locations within the network, models that do not account for this spatial variability suffer from high false positive rates in specific areas.

[0007] The present disclosure aims to effectively classify and process traffic data for detecting network anomalies by considering the characteristics of network traffic, and to enhance the learning efficiency of an autoencoder-based anomaly detection model by extracting features that reflect temporal and spatial characteristics, thereby ultimately improving the accuracy and reliability of detecting abnormal terminals within a network.

[0008] A method performed by an electronic device according to one embodiment may include, for a target terminal for determining whether to perform an abnormal operation, an operation of obtaining data for a terminal operation specified according to an abnormal operation type; an operation of obtaining output data by applying the data for the specified terminal operation of the target terminal to an autoencoder-based artificial intelligence model; and an operation of determining whether the target terminal performs an abnormal operation based on whether the reconstruction loss of the output data exceeds the specified reconstruction range.

[0009] An electronic device according to one embodiment may include a transceiver; and a control unit coupled to the transceiver. The control unit may be configured to acquire data regarding a terminal operation specified according to an abnormal operation type for a target terminal to determine whether an abnormal operation is performed, acquire output data by applying the data regarding the specified terminal operation of the target terminal to an autoencoder-based artificial intelligence model, and determine whether the target terminal is performing an abnormal operation based on whether the reconstruction loss of the output data exceeds the specified reconstruction range.

[0010] The present disclosure is expected to improve the learning and detection performance of an autoencoder and enable more effective response to abnormal terminals in a 5G network environment by collecting and analyzing data according to characteristics associated with the terminal, such as the type of terminal and the service provided by the terminal, and according to the type of abnormal pattern to be detected.

[0011] FIG. 1 illustrates network entities included in a core network according to one embodiment.

[0012] FIG. 2 is a diagram illustrating the process of an electronic device according to one embodiment acquiring and using data for a designated terminal operation.

[0013] FIG. 3 is a diagram illustrating an autoencoder-based artificial intelligence technology according to one embodiment.

[0014] FIG. 4 is a diagram illustrating the process of training an autoencoder-based artificial intelligence model and detecting abnormal terminals according to one embodiment.

[0015] FIG. 5 is a diagram illustrating terminal grouping according to one embodiment.

[0016] FIG. 6 is a diagram illustrating a judgment model according to one embodiment.

[0017] FIG. 7 is a diagram illustrating a judgment model according to one embodiment.

[0018] FIG. 8 is a diagram illustrating the process of an electronic device acquiring and classifying data regarding a terminal operation specified according to an abnormal operation type during a learning step according to one embodiment.

[0019] FIG. 9 illustrates an example of the functional structure of a terminal according to one embodiment.

[0020] FIG. 10 illustrates an example of the functional structure of a network entity according to one embodiment.

[0021] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the attached drawings.

[0022] In describing the embodiments, technical details that are well known in the technical field to which this disclosure belongs and are not directly related to this disclosure are omitted. This is intended to convey the essence of this disclosure more clearly without obscuring it by omitting unnecessary explanations.

[0023] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the dimensions of each component do not entirely reflect their actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.

[0024] The advantages and features of the present disclosure, and the methods for achieving them, will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments disclosed below but may be implemented in various different forms. These embodiments are provided merely to ensure that the disclosure is complete and to fully inform those skilled in the art of the scope of the disclosure, and the present disclosure is defined only by the scope of the claims. Throughout the specification, the same reference numerals refer to the same components. Furthermore, in describing the present disclosure, if it is determined that a detailed description of related functions or configurations might unnecessarily obscure the essence of the present disclosure, such detailed description is omitted. Additionally, the terms described below are defined considering their functions in the present disclosure, and these may vary depending on the intentions or conventions of the user or operator. Therefore, their definitions should be based on the content throughout the specification.

[0025] Hereinafter, a base station is an entity that performs resource allocation for terminals and may be at least one of a gNode B, eNode B, Node B, BS (Base Station), wireless access unit, base station controller, or a node on a network. A terminal may include a UE (User Equipment), MS (Mobile Station), cellular phone, smartphone, computer, or a multimedia system capable of performing communication functions. In this disclosure, a downlink (DL) refers to a wireless transmission path of a signal transmitted by a base station to a terminal, and an uplink (UL) refers to a wireless transmission path of a signal transmitted by a terminal to a base station. Furthermore, while LTE, LTE-A, or 5G systems may be described as examples below, embodiments of this disclosure may also be applied to other communication systems having similar technical backgrounds or channel types. For example, 5th generation mobile communication technology (5G, new radio, NR) developed after LTE-A may be included therein, and the 5G below may be a concept that includes existing LTE, LTE-A, and other similar services. In addition, the present disclosure may be applied to other communication systems with some modifications made at the discretion of a person with skilled technical knowledge, without significantly departing from the scope of the present disclosure.

[0026] At this point, it will be understood that each block of the process flow diagrams and combinations of the flow diagrams can be executed by computer program instructions. Since these computer program instructions can be loaded into the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing equipment, the instructions executed through the processor of the computer or other programmable data processing equipment create means to perform the functions described in the flow diagram block(s). Since these computer program instructions can also be stored in computer-available or computer-readable memory that can be directed toward the computer or other programmable data processing equipment to implement the function in a specific way, the instructions stored in computer-available or computer-readable memory can also produce a manufactured item containing instruction means to perform the function described in the flow diagram block(s). Since computer program instructions can be loaded onto a computer or other programmable data processing equipment, instructions that perform a series of operation steps on the computer or other programmable data processing equipment to create a process executed by the computer can also provide steps for executing the functions described in the flowchart block(s).

[0027] Additionally, each block may represent a module, segment, or part of code containing one or more executable instructions for executing a specific logical function(s). It should also be noted that in some alternative execution examples, the functions mentioned in the blocks may occur out of order. For example, two blocks described in succession may actually be executed substantially simultaneously, or the blocks may sometimes be executed in reverse order according to their corresponding functions.

[0028] In this embodiment, the term "part" refers to a software or hardware component such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit), and the "part" performs certain roles. However, the meaning of "part" is not limited to software or hardware. The "part" may be configured to reside in an addressable storage medium or may be configured to run one or more processors. Accordingly, as an example, the "part" includes components such as software components, object-oriented software components, class components, and task components, as well as processes, functions, attributes, procedures, subroutines, segments of program code, drivers, firmware, microcode, circuits, data, databases, data structures, tables, arrays, and variables. The functions provided within the components and "parts" may be combined into a smaller number of components and "parts" or further separated into additional components and "parts." In addition, the components and 'parts' may be implemented to utilize one or more CPUs within the device or secure multimedia card. Furthermore, in the embodiment, the 'part' may include one or more processors.

[0029] Wireless communication systems are evolving from providing early voice-oriented services to broadband wireless communication systems that provide high-speed, high-quality packet data services, such as communication standards like 3GPP’s HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution or E-UTRA (Evolved Universal Terrestrial Radio Access)), LTE-Advanced (LTE-A), LTE-Pro, 3GPP2’s HRPD (High Rate Packet Data), UMB (Ultra Mobile Broadband), and IEEE’s 802.16e.

[0030] As a representative example of the above-mentioned broadband wireless communication system, the LTE system employs the Orthogonal Frequency Division Multiplexing (OFDM) method for the downlink (DL) and the Single Carrier Frequency Division Multiple Access (SC-FDMA) method for the uplink (UL). The uplink refers to a wireless link through which a terminal (User Equipment (UE) or Mobile Station (MS)) transmits data or control signals to a base station (eNode B, gNode B, or base station (BS)), and the downlink refers to a wireless link through which a base station transmits data or control signals to a terminal. The above-mentioned multiple access method can distinguish the data or control information of each user by allocating and operating time-frequency resources to be sent for each user so that they do not overlap, that is, so that orthogonality is established.

[0031] As a future communication system following LTE, that is, a 5G communication system, it must be able to freely reflect the diverse requirements of users and service providers, and therefore, services that satisfy various requirements simultaneously must be supported. Services being considered for the 5G communication system include enhanced Mobile Broadband (eMBB), massive Machine Type Communication (mMTC), and Ultra Reliability Low Latency Communication (URLLC).

[0032] eMBB aims to provide data transmission speeds that are superior to those supported by existing LTE, LTE-A, or LTE-Pro. For example, in a 5G communication system, eMBB must be able to provide a peak data rate of 20 Gbps in the downlink and 10 Gbps in the uplink from the perspective of a single base station. Furthermore, while providing these peak data rates, the 5G communication system must also provide an increased user-perceived data rate. To satisfy these requirements, it necessitates improvements in various transmission and reception technologies, including enhanced multi-input multi-output (MIMO) transmission technology. Additionally, while LTE transmits signals using a maximum bandwidth of 20 MHz in the 2 GHz band, the 5G communication system can meet the data transmission speeds required by using a frequency bandwidth wider than 20 MHz in frequency bands of 3–6 GHz or above 6 GHz.

[0033] Simultaneously, mMTC is being considered to support application services such as the Internet of Things (IoT) in 5G communication systems. To efficiently provide IoT, mMTC requires support for a large number of terminal connections within a cell, improved terminal coverage, enhanced battery life, and reduced terminal costs. Since IoT devices are attached to various sensors and equipment to provide communication functions, the system must be able to support a large number of terminals within a cell (e.g., 1,000,000 terminals / km²). Furthermore, due to the nature of the service, terminals supporting mMTC are likely to be located in dead zones not covered by cells, such as building basements; therefore, they may require wider coverage compared to other services provided by 5G communication systems. Terminals supporting mMTC must consist of low-cost devices, and since it is difficult to frequently replace terminal batteries, a very long battery life of 10 to 15 years may be required.

[0034] Finally, URLLC is a mission-critical cellular-based wireless communication service. Examples include services used for remote control of robots or machinery, industrial automation, unmanned aerial vehicles, remote health care, and emergency alerts. Therefore, the communication provided by URLLC must offer very low latency and very high reliability. For instance, services supporting URLLC must satisfy an air interface latency of less than 0.5 milliseconds and simultaneously require a packet error rate of 10^-5 or less. Consequently, for services supporting URLLC, 5G systems must provide a Transmission Time Interval (TTI) smaller than other services, and design considerations may be required to allocate wide resources within the frequency band to ensure the reliability of the communication link.

[0035] The three 5G services, namely eMBB, URLLC, and mMTC, can be multiplexed and transmitted within a single system. In this case, different transmission and reception techniques and parameters may be used between the services to satisfy the different requirements of each service. Of course, 5G is not limited to the three services mentioned above.

[0036] With the advancement of Internet of Things (IoT) technology, the number of network-connected devices is increasing explosively. Consequently, the importance of network security is becoming more prominent, and in particular, rapidly detecting and responding to devices exhibiting abnormal behavior has become a key challenge in network management.

[0037] Autoencoder-based artificial intelligence technology can be effectively utilized for detecting such abnormal terminals. Autoencoders are neural network structures based on unsupervised learning that learn normal traffic patterns and demonstrate excellent performance in identifying abnormal patterns based on this learning.

[0038] However, due to the complexity and diversity of the IoT environment, it may be difficult to effectively detect all abnormal patterns using only simple autoencoder models. Therefore, methods for effectively classifying and processing data are essential to improve the performance of autoencoder-based anomaly detection models. This enables the construction of a more accurate and reliable abnormal terminal detection system.

[0039] The present disclosure can provide a method and apparatus for more effectively responding to abnormal terminals in a 5G network environment by collecting and analyzing data according to characteristics associated with the terminal, such as the type of terminal and the service provided by the terminal, and according to the type of abnormal pattern to be detected, thereby improving the learning and detection performance of an autoencoder.

[0040] FIG. 1 illustrates network entities included in a core network according to one embodiment.

[0041] FIG. 1 illustrates only some of the various network entities constituting a core network, but this is merely an example and does not limit the present disclosure.

[0042] An AMF (access and mobility management function) entity is a device for managing the access and mobility of a terminal and can serve as a terminal-core network endpoint through which the terminal connects with other devices in the core network via the RAN (radio access network). Functions provided by an AMF entity may include, for example, terminal registration, connection, reachability, mobility management, access verification / authentication, and the generation of mobility events.

[0043] According to one embodiment, an AMF entity may collect information for detecting abnormal terminals. For example, when a terminal initiates a service request (SR), the AMF entity may collect information regarding the time of occurrence of the service request. For example, when a terminal triggers a control plane message and / or a user plane message, the AMF entity may count the number of triggered messages to collect information regarding the number of messages and / or information regarding frequency and / or size. Control plane messages may include registration, deregistration, establishment of a protocol data unit (PDU) session, modification of a PDU session, and release of a PDU session. For example, the AMF entity may determine the number of concurrently connected terminals. For example, when a terminal transmits data to a server or another terminal over a network, the AMF entity may collect information regarding the size of the transmitted data packets and the frequency of data transmission.

[0044] According to one embodiment, an AMF entity can preprocess collected information. For example, the AMF entity can identify information regarding normal operation and information regarding abnormal operation by using the mean and standard deviation of each terminal group from each type of information among the collected information. For example, the AMF entity can extract data from the collected information to be input into and / or applied to an artificial intelligence model. The collected information may include at least one type of information among information regarding the time of occurrence of a service request initiated by a terminal, information regarding the number of control plane messages triggered by a terminal, information regarding the number of concurrently connected terminals, and information regarding the packet size of data and the frequency of data transmission.

[0045] According to one embodiment, an AMF entity can detect a terminal that has performed abnormal operations. For example, if a terminal initiates a service request, the AMF entity can determine whether the terminal is an abnormal terminal that has performed abnormal operations based on information regarding the time at which the service request occurred. For example, if a terminal triggers a control plane message and / or a user plane message, the AMF entity can determine whether the terminal is an abnormal terminal that has performed abnormal operations based on information regarding the time at which the message was triggered. For example, if a terminal triggers a control plane message and / or a user plane message, the AMF entity can determine whether the terminal is an abnormal terminal that has performed abnormal operations based on information regarding the packet size of the data and the frequency of data transmission.

[0046] The SMF (session management function) entity can perform the management of a terminal's PDU session. For example, the SMF entity can perform session management functions such as establishing, modifying, and releasing sessions and maintaining a tunnel between the UPF entity and the AN required for this, IP address allocation and management functions for the terminal, ARP Proxy functions, user plane selection and control, traffic processing control in the UPF entity, and billing data collection control.

[0047] An SMF entity according to one embodiment may collect information for detecting abnormal terminals. For example, when a terminal triggers a control plane message and / or a user plane message, the SMF entity may count the number of triggered messages to collect information about the number of messages and / or information about the frequency and / or size. For example, the SMF entity may collect information about the number of concurrently connected terminals, the size of data packets, and the frequency of data transmission.

[0048] An SMF entity according to one embodiment can preprocess collected information. For example, the SMF entity can identify information regarding normal operation and information regarding abnormal operation by using the mean and standard deviation of each terminal group from each type of information among the collected information. For example, the SMF entity can extract data from the collected information to be input into and / or applied to an artificial intelligence model. The collected information may include at least one type of information among information regarding the number of control plane messages triggered by a terminal, information regarding the number of concurrently connected terminals, and information regarding the packet size of data and the frequency of data transmission.

[0049] An SMF entity according to one embodiment can detect a terminal that has performed an abnormal operation. For example, at the time when the SMF entity receives a PDU session establishment message from a terminal, it can determine whether the terminal that transmitted the message is an abnormal terminal that has performed an abnormal operation based on at least one of information about that time, information about the frequency of receiving similar messages, or information about the size of the message.

[0050] The PCF (policy control function) entity can perform the role of determining and disseminating policies regarding access / mobility and session management applied by the AMF entity and SMF entity. For example, the PCF entity can govern the behavior of the entire network and provide policies to be implemented to the NFs (network functions) that constitute the control plane.

[0051] The NEF (network exposure function) entity can be responsible for transmitting or receiving events and supported capabilities occurring in the mobile communication network to or from the outside. For example, the NEF entity can perform functions such as securely provisioning information of external applications to the core network, converting internal / external information, and storing and redistributing functions received from other NFs in a repository such as a UDR (unified data repository) entity.

[0052] The UDM (unified data management) entity can perform tasks such as generating AKA authentication information for 3GPP security, processing user IDs, reverse concealing subscriber concealed IDs (SUPI), managing a list of NFs supporting the current UE, managing subscription information, and managing short message services (SMS).

[0053] The UPF (user plane function) entity performs the role of processing actual user data and can handle packets to forward packets generated by the terminal to an external data network or to deliver data received from the external data network to the terminal. Key functions provided by the UPF entity may include, for example, acting as an anchor between radio access technologies, providing connectivity between PDU sessions and external data networks, packet routing and forwarding, packet inspection, application of user plane policies, generation of traffic usage reports, and buffering.

[0054] A UPF entity according to one embodiment may collect information for detecting abnormal terminals. For example, the UPF entity may collect information regarding the session retention time of a terminal. The session retention time may include the time during which resources, such as an assigned IP address or bearer, are maintained while the terminal is connected to a network. For example, when the terminal transmits data, the UPF entity may collect information regarding at least one of the data rate or the data transmission frequency. For example, when the terminal triggers control plane messages and / or user plane messages, the UPF entity may count the number of triggered messages to collect information regarding the number of messages and / or information regarding the frequency and / or information regarding the size.

[0055] A UPF entity according to one embodiment can preprocess collected information. For example, the UPF entity can identify information regarding normal operation and information regarding abnormal operation by using the mean and standard deviation of each terminal group from each type of information among the collected information. For example, the UPF entity can extract data from the collected information to be input into and / or applied to an artificial intelligence model. The collected information may include at least one type of information among information regarding the number of control plane messages triggered by a terminal, information regarding the number of concurrently connected terminals, information regarding the size of data packets, information regarding the frequency of data transmission, or information regarding the data transmission rate.

[0056] A UPF entity according to one embodiment can detect a terminal that has performed abnormal operations. For example, during a periodic audit, the UPF entity can determine whether the terminal is an abnormal terminal that has performed abnormal operations based on at least one of session maintenance time information or transmission speed. An audit may refer to a process of evaluating and verifying the security and performance of a terminal.

[0057] The NWDAF (network data analytics function) entity can collect events or information occurring within the network and use tools such as analysis tools or machine learning to transmit statistics, predictions, and recommendations related to specific information to NFs, AFs, and OAMs. For example, the NWDAF entity can perform functions such as collecting data from NFs, AFs, and OAMs (Operation, administration, and maintenance), registering NWDAF entity services and exposing metadata, and providing network analysis information to NFs and AFs. In other words, the NWDAF entity analyzes collected network data using intelligent technologies such as machine learning and provides the analysis results to other 5G core network functions (e.g., NFs, AFs, or OAMs), thereby helping to optimize and improve the performance of each network function.

[0058] An NWDAF entity according to one embodiment may collect information for detecting abnormal terminals. For example, the NWDAF entity may collect at least one of information regarding the session maintenance time of a terminal, information regarding the data transmission speed of a terminal, or information regarding the data transmission frequency. For example, the NWDAF entity may collect information regarding the time of occurrence of a service request initiated by a terminal, information regarding the number of control plane messages and / or user plane messages triggered by a terminal, information regarding the frequency of messages, or information regarding the size of messages. For example, the NWDAF entity may collect information regarding the number of concurrently connected terminals.

[0059] An NWDAF entity according to one embodiment can preprocess collected information. For example, the NWDAF entity can identify information regarding normal operation and information regarding abnormal operation by using the mean and standard deviation of each terminal group from each type of information among the collected information. For example, the NWDAF entity can extract data from the collected information to be input into and / or applied to an artificial intelligence model. The collected information may include information regarding at least one of the session maintenance time of a terminal, the transmission speed of data transmitted by the terminal, the time of occurrence of a service request initiated by the terminal, the number of control plane messages triggered by the terminal, the number of concurrently connected terminals, the size of a data packet, or the frequency of data transmission.

[0060] According to one embodiment, an NWDAF entity can detect a terminal that has performed an abnormal operation. For example, if a terminal initiates a service request, the NWDAF entity can determine whether the terminal is an abnormal terminal that has performed an abnormal operation based on information about the time at which the service request occurred. For example, if a terminal triggers a control plane message and / or a user plane message, the NWDAF entity can determine whether the terminal is an abnormal terminal that has performed an abnormal operation based on information about the time at which the message was triggered. For example, if a terminal triggers a control plane message and / or a user plane message, the NWDAF entity can determine whether the terminal is an abnormal terminal that has performed an abnormal operation based on information about the packet size of the data and the frequency of data transmission. For example, when receiving a PDU session establishment message from a terminal, the NWDAF entity can determine whether the terminal that transmitted the message is an abnormal terminal that has performed an abnormal operation based on at least one of information about the time at which the PDU session establishment message is received, information about the frequency of receiving similar messages, or information about the size of the message. For example, the NWDAF entity can determine whether a terminal is an abnormal terminal that has performed abnormal operations based on at least one of session maintenance time information or transmission speed during a periodic audit.

[0061] According to one embodiment, an NWDAF entity can provide information necessary for another network entity to detect a terminal that has performed abnormal operations by providing information that is collected and preprocessed to another network entity. For example, the NWDAF entity may transmit information regarding at least one of the terminal's session duration or the transmission rate of data transmitted by the terminal to a UPF entity. For example, the NWDAF entity may transmit information regarding at least one of the time of occurrence of a service request initiated by the terminal, the number of control plane messages triggered by the terminal, the number of concurrently connected terminals, the size of a data packet, or the frequency of data transmission to an AMF entity and / or an SMF entity.

[0062] An AF (application function) entity can perform functions that interact with the 3GPP core network to provide services. Unlike NEF entities, AF entities can utilize the services of network functions located within the core network without separate intermediate functions. Typical functions provided by AF entities may include application influence on traffic routing, utilization of network information exposure functions, interaction with policy frameworks for policy control, and IMS-related interactions.

[0063] User equipment (UE) can be connected to a radio access network (RAN) to access core network devices of the network. The core network of a network (e.g., a 5G network) may include functions as described above. The described RAN may include a 5G-RAN and may refer to a base station that provides radio communication functions to the user equipment. The user equipment can access an AMF through the base station and exchange control plane signaling messages with the 5G core network. Additionally, the user equipment can access a UPF through the base station and exchange user plane data with a data network (DN) entity.

[0064] According to one embodiment, information for detecting an abnormal terminal includes information related to the operation of the terminal and may vary depending on the type of abnormal operation. Information for detecting an abnormal terminal may include predefined information depending on the type of abnormal operation. In the present disclosure, abnormal operations may include unexpected long-live / large rate flows, unexpected wake-up, suspicion of a DDoS attack, and too frequent service access. For example, unexpected wake-up and suspicion of a DDoS attack may be understood as different types of abnormal operations.

[0065] Unexpected long-live / large rate flows refer to traffic flows that deviate from normal patterns in a wireless network, persist for a long time or exhibit a large amount of data, or large-scale data transmission by a specific terminal, which can cause network load. To detect unexpected long-live / large rate flows, at least one of the UPF entity or NWDAF entity collects information on at least one of session duration or transmission rate, and can train an artificial intelligence model or detect abnormal terminals based on this information.

[0066] That is, the terminal operation specified to detect abnormal behavior such as an abnormal long-term / high-volume traffic flow may include at least one of an operation to maintain a session with the network or an operation to transmit data. And, the data for the terminal operation specified to detect abnormal behavior such as an abnormal long-term / high-volume traffic flow may include at least one of a session maintenance time or a transmission rate.

[0067] Unexpected wakeup refers to a situation in a wireless network where a terminal suddenly becomes active or wakes up at an unexpected time to access the network, deviating from normal patterns; this can waste network resources and threaten security. To detect unexpected wakeup, at least one of the AMF entity or NWDAF entity collects information regarding the time of occurrence of a service request initiated by the terminal, and can train an artificial intelligence model or detect the unexpected terminal based on this information.

[0068] That is, a terminal operation designated to detect an abnormal operation known as abnormal terminal activation may include an operation in which the terminal initiates a service request. Furthermore, data regarding the terminal operation designated to detect an abnormal operation known as abnormal terminal activation may include the time of occurrence of the service request.

[0069] A suspicion of a DDoS attack refers to multiple terminals simultaneously making excessive requests to the network, which can exhaust network resources. To detect a suspicion of a DDoS attack, at least one of the AMF entity, SMF entity, UPF entity, or NWDAF entity collects information on the number of control plane messages and / or user plane messages triggered by terminals, the frequency or size of the messages, or the NWDAF entity collects information on at least one of the number of concurrently connected terminals, and can train an artificial intelligence model or detect abnormal terminals based on this information.

[0070] That is, a terminal operation designated to detect abnormal behavior suspected of being a DDoS attack may include at least one of the operation of the terminal transmitting a control plane message, the operation of transmitting a user plane message, the operation of transmitting data, or the operation of being connected to a network. Furthermore, data regarding the terminal operation designated to detect abnormal behavior suspected of being a DDoS attack may include at least one of the number of control plane messages and / or user plane messages triggered by the terminal, the frequency of messages, the size of messages, or the number of concurrently connected terminals.

[0071] Too frequent service access refers to abnormally frequent attempts to access wireless network services or a specific terminal accessing the network at a frequency exceeding the statistical average to perform service requests, which can degrade network performance and threaten security. To detect too frequent service access, at least one of the AMF entity or NWDAF entity collects information regarding the time of occurrence of service requests initiated by terminals, and can train an artificial intelligence model or detect abnormal terminals based on this information.

[0072] That is, the terminal action designated to detect abnormal behavior such as excessive service access may include an action of initiating a service request. And, the data regarding the terminal action designated to detect abnormal behavior such as excessive service access may include the time of occurrence of the service request.

[0073] An electronic device according to one embodiment can learn an artificial intelligence model or detect an abnormal terminal based on the data regarding the specified terminal operation when it obtains data regarding the abnormal operation type through at least one network entity.

[0074] FIG. 2 is a diagram illustrating the process of an electronic device according to one embodiment acquiring and using data regarding a designated terminal operation. Referring to FIG. 2, the process of an electronic device acquiring and using data regarding a designated terminal operation may include operations before the learning of an artificial intelligence model is completed and operations after the learning of an artificial intelligence model is completed. Before the learning of the artificial intelligence model is completed, the electronic device may acquire data regarding a designated terminal operation based on the operations of a plurality of terminals. The data of a plurality of terminals acquired before the learning of the artificial intelligence model is completed may be used as input data for the learning phase (operations 210 to 240) and the verification and testing phase (operation 250) of the artificial intelligence model. After the learning of the artificial intelligence model is completed, the electronic device may acquire data regarding a newly acquired designated terminal operation based on the operation of a target terminal. The data of a target terminal newly acquired after the learning of the artificial intelligence model is completed may be used as application data for a prediction phase (operations 260 to 290) for determining whether the target terminal is abnormal.

[0075] That is, the electronic device may use data acquired before training is completed as training data to train an artificial intelligence model, or data acquired after training is completed as input data to detect (or predict) a specific type of abnormal operation using the artificial intelligence model. In this case, the data refers to data regarding terminal operation specified according to the type of abnormal operation, and the artificial intelligence model may refer to an artificial intelligence model for detecting a specific type of abnormal operation.

[0076] Abnormal behavior may include at least one of abnormal long-term / high-volume traffic flow, abnormal terminal activation, suspected DDoS attack, or excessive service access. Data for a terminal behavior specified to detect abnormal behavior, such as abnormal long-term / high-volume traffic flow, may include data regarding at least one of session retention time, data rate, data transmission frequency, or data packet size. Data for a terminal behavior specified to detect abnormal behavior, such as at least one of abnormal terminal activation or excessive service access, may include data regarding at least one of the time of occurrence of a service request or the frequency of occurrence of a service request. Data for a terminal behavior specified to detect abnormal behavior, such as suspected DDoS attack, may include data regarding at least one of the number of control plane messages, user plane messages, or data, the size of transmission packets, the frequency of data transmission, or the number of concurrent connections of the terminal.

[0077] Before the training of an artificial intelligence model is completed, the electronic device may acquire data regarding a designated terminal operation according to the type of abnormal operation associated with a plurality of terminals. When the electronic device according to one embodiment identifies a terminal that maintains a session with a network or transmits data, it may acquire data regarding at least one of a session maintenance time, a data rate, a data transmission frequency, or a data packet size through at least one network entity, and may use the acquired data as training data for an artificial intelligence model to detect abnormal long-term / high-volume traffic flows. When the electronic device according to one embodiment identifies a terminal that initiates a service request, it may acquire data regarding at least one of the time of occurrence of the service request or the frequency of occurrence of the service request through at least one network entity, and may use the acquired data as training data for an artificial intelligence model to detect at least one of abnormal terminal activation or excessive service access. An electronic device according to one embodiment, when identifying a terminal transmitting at least one of a control plane message, a user plane message, or data, acquires information regarding at least one of the number of at least one of the control plane message, the user plane message, or data, the size of the transmission packet, the frequency of data transmission, or the number of simultaneous connections of the terminal, and can use the acquired data as training data for an artificial intelligence model for detecting suspected DDoS attacks.

[0078] Additionally, data regarding the target terminal can be acquired after the training of the artificial intelligence model is completed. In the present disclosure, a terminal that is the subject of verification regarding whether it performs abnormal operation may be referred to as the target terminal. To this end, an electronic device for detecting an abnormal terminal may acquire data associated with the operation of the target terminal and according to the type of abnormal operation. According to one embodiment, when the target terminal maintains a session with a network or transmits data, the electronic device acquires data regarding at least one of the session maintenance time, data rate, data transmission frequency, or data packet size, and may use the acquired data as input data for an artificial intelligence model trained to detect abnormal long-term / high-volume traffic flow. According to one embodiment, when the target terminal initiates a service request, the electronic device acquires data regarding at least one of the time of occurrence of the service request or the frequency of occurrence of the service request, and may use the acquired data as input data for an artificial intelligence model trained to detect at least one of abnormal terminal activation or excessive service access. According to one embodiment, when a target terminal transmits at least one of a control plane message, a user plane message, or data, the electronic device acquires data regarding at least one of the number of at least one of the control plane message, the user plane message, or data, the size of the transmission packet, the frequency of data transmission, or the number of simultaneous connections of the terminal, and can use the acquired data as input data for an artificial intelligence model trained to detect suspected DDoS attacks.

[0079] According to one embodiment, at least one network entity may be used to obtain data regarding terminal behavior specified according to an abnormal behavior type. For example, to obtain data according to an abnormal behavior type such as an abnormal long-term / high-volume traffic flow, at least one of a UPF entity or an NWDAF entity may be used. For example, to obtain data according to at least one abnormal behavior type such as abnormal terminal activation or excessive service access, at least one of an AMF entity or an NWDAF entity may be used. For example, to obtain data according to an abnormal behavior type such as suspected DDoS attack, at least one of an AMF entity, an SMF entity, a UPF entity, or an NWDAF entity may be used.

[0080] According to one embodiment, after the electronic device acquires data in operation 230, the electronic device may further perform data preprocessing. Data preprocessing may include an operation to perform normalization and standardization of data, an operation to process missing values, an operation to classify data into normal data and abnormal data, an operation to identify data by terminal group, and / or an operation to classify data according to the type of abnormal operation.

[0081] Specifically, the electronic device can classify data regarding a specified terminal operation into normal data and abnormal data according to the type of abnormal operation through data normalization and standardization. In the present disclosure, normal data may be used as training data for an autoencoder-based artificial intelligence model or for verification or testing, and abnormal data may be used for verification or testing. Accordingly, the operation of classifying acquired data into normal data and abnormal data may include the operation of classifying the acquired data into normal data to be used as training data, normal data to be used for verification, abnormal data to be used for verification, normal data to be used for testing, and abnormal data to be used for testing.

[0082] In addition, the electronic device can classify acquired data by terminal group and / or by type of abnormal operation, group and analyze the data according to its characteristics, and apply a corresponding artificial intelligence model, thereby increasing learning efficiency and prediction accuracy.

[0083] In the present disclosure, normal data may refer to data in which the reconstruction error between input and output is small or data distributed in the area to which the majority of data belongs. Abnormal data may refer to data in which the reconstruction error between input and output exceeds a specified reconstruction range or data distributed outside the normal data area. For example, for a plurality of terminals included in a terminal group, if the normal data for packet size is in the range of 300 bytes or more and 400 bytes or less, the reconstruction range of an artificial intelligence model that has learned the characteristics of normal data associated with packet size may be set to 10 bytes, and if the output data is included in the range of 290 bytes or more and 410 bytes or less, it may be understood that the reconstruction error of the output data does not exceed the specified reconstruction range. For example, for multiple terminals included in a terminal group, if the normal data for the data rate is within the range of 150 kbps or more and 250 kbps, the reconstruction range of an artificial intelligence model that has learned the characteristics of the normal data associated with the data rate can be set to 10 kbps, and if the output data is included in the range of 140 kbps or more and 260 kbps or less, it can be understood that the reconstruction error of the output data does not exceed the specified reconstruction range.

[0084] FIG. 3 is a diagram illustrating an autoencoder-based artificial intelligence technology according to one embodiment.

[0085] In one embodiment, another electronic device can detect a terminal performing abnormal operations using an autoencoder-based artificial intelligence technology such as FIG. 3. The autoencoder may include an encoder that converts input data into a compressed representation and a decoder that restores the compressed representation into a form similar to the original data.

[0086] In a learning step according to one embodiment (e.g., operations 210 to 240 of FIG. 2), the electronic device may proceed with learning in a direction in which the reconstruction error of the autoencoder is minimized or the reconstruction error is included within a specified reconstruction range, using normal data for terminal operations specified according to the type of abnormal operation. When data for terminal operations specified according to the type of abnormal operation is input to the autoencoder, the autoencoder may convert the input data into a lower-dimensional compressed representation using an encoder and reconstruct the compressed representation to be as similar as possible to the original data using a decoder. At this time, the normal data for terminal operations specified according to the type of abnormal operation may refer to data classified as normal data using the mean and standard deviation of each terminal group among the data for terminal operations specified according to the type of abnormal operation.

[0087] In one embodiment, in another verification and test step (e.g., operation 250 of FIG. 2), the electronic device can verify and test the reconstruction error of the autoencoder using normal data for a terminal operation specified according to the type of abnormal operation so that it is within the reconstruction range (or below a threshold), and can verify and test the reconstruction error of the autoencoder using abnormal data so that it is beyond the reconstruction range (or above a threshold).

[0088] Based on the above learning, verification, and testing phases, the autoencoder learns normal traffic patterns and can identify abnormal patterns based on this.

[0089] In a prediction step (operation 260 to operation 290) according to one embodiment, the electronic device may acquire data regarding a terminal operation specified as an abnormal operation type for a target terminal, and use the acquired data to determine whether the reconstruction error of the autoencoder exceeds the reconstruction range. If the reconstruction error of the autoencoder exceeds the reconstruction range for the data of the target terminal, the electronic device may determine that the target terminal is performing an abnormal operation, and if the reconstruction error of the autoencoder is included within the reconstruction range for the data of the target terminal, the electronic device may determine that the target terminal is not performing an abnormal operation.

[0090] An autoencoder-based artificial intelligence model according to one embodiment receives data classified by terminal group and / or by type of abnormal behavior as training data and input data for prediction, so it can effectively detect abnormal patterns that vary depending on characteristics associated with the terminal and / or the type of abnormal behavior to be detected.

[0091] FIG. 4 is a diagram illustrating the process of training an autoencoder-based artificial intelligence model and detecting abnormal terminals according to one embodiment.

[0092] In operation 410, the electronic device may obtain data regarding a terminal operation specified according to the type of abnormal operation for a target terminal to determine whether the electronic device performs an abnormal operation. Operation 410 may be performed after the training of an autoencoder-based artificial intelligence model is completed, and the target terminal may refer to a terminal that is the subject of checking whether the electronic device performs an abnormal operation using the trained artificial intelligence model.

[0093] Data regarding terminal operations specified according to the type of abnormal operation may include data regarding terminal operations specified to detect abnormal operation. Data regarding terminal operations specified to detect abnormal operation such as abnormal long-term / high-volume traffic flow according to one embodiment may include at least one of session maintenance time or transmission speed. Data regarding terminal operations specified to detect abnormal operation such as abnormal terminal activation according to one embodiment may include the time of occurrence of a service request. Data regarding terminal operations specified to detect abnormal operation such as suspected DDoS attack according to one embodiment may include at least one of the number of control plane messages and / or user plane messages triggered by the terminal, the frequency of messages, the size of messages, or the number of concurrently connected terminals. Data regarding terminal operations specified to detect abnormal operation such as excessive service access according to one embodiment may include the time of occurrence of a service request.

[0094] Data regarding a specified terminal operation may be obtained by a core network. According to one embodiment, an electronic device may use an AMF entity to obtain information regarding the time of occurrence of a service request (SR) initiated by a terminal, information regarding the number of control plane messages and / or user plane messages triggered by the terminal, information regarding the frequency of messages, information regarding the size of messages, information regarding the number of concurrently connected terminals, information regarding the size of data packets transmitted by the terminal, and / or information regarding the frequency of data transmission. According to one embodiment, an electronic device may use an SMF entity to obtain information regarding the number of control plane messages and / or user plane messages triggered by the terminal, information regarding the number of concurrently connected terminals, and information regarding the size of data packets and the frequency of data transmission. According to one embodiment, an electronic device can obtain information regarding at least one of the terminal's session duration, the terminal's data rate, the terminal's data transmission frequency, the number or frequency of control plane messages triggered by the terminal, the number or frequency of user plane messages triggered by the terminal, and the size of data transmitted by the terminal using a UPF entity. According to one embodiment, an electronic device can collect information regarding at least one of the terminal's session duration, the terminal's data rate, the terminal's data transmission frequency, the time of occurrence of a service request initiated by the terminal, the number of control plane messages triggered by the terminal, the number of user plane messages, the frequency of messages transmitted by the terminal, the size of messages transmitted by the terminal, or the number of concurrently connected terminals using an NWDAF entity.

[0095] In operation 420, the electronic device can obtain output data by applying data for a specified terminal operation of a target terminal to an autoencoder-based artificial intelligence model. The autoencoder-based artificial intelligence model of operation 420 may be an artificial intelligence model that has been trained to output output data in which the reconstruction error is included within the reconstruction range when normal data for a specified terminal operation is input, and output output data in which the reconstruction error exceeds the reconstruction range when abnormal data is input.

[0096] In operation 430, the electronic device can determine whether the target terminal is performing an abnormal operation based on whether the reconstruction error of the output data exceeds a specified reconstruction range. The reconstruction error of the output data may refer to the difference between the output data obtained in operation 420 and the input data applied to the autoencoder-based artificial intelligence model in operation 420.

[0097] An autoencoder-based artificial intelligence model according to one embodiment may include a model trained such that when normal data for a terminal operation specified according to an abnormal operation type is received as input, the reconstruction error is included within the reconstruction range, and when abnormal data is received as input, the reconstruction error exceeds the reconstruction range.

[0098] The procedures of operations 410 and 430 may be initiated by at least one network entity. For example, a UPF entity may acquire data regarding at least one of the session duration or the data transmission rate of a target terminal during a periodic audit, apply the acquired data to an artificial intelligence model for detecting abnormal long-term / high-volume traffic flow to acquire output data, and determine whether the target terminal is performing an abnormal operation such as an abnormal long-term / high-volume traffic flow based on whether the reconstruction error of the acquired output data exceeds a specified reconstruction range. For example, an AMF entity may acquire data regarding at least one of the time of occurrence, the occurrence period, or the frequency at the time a service request is made by a target terminal, apply the acquired data to an artificial intelligence model for detecting abnormal terminal activation and / or an artificial intelligence model for detecting excessive service access to acquire output data, and determine whether the target terminal is performing an abnormal operation such as abnormal terminal activation and / or excessive service access based on whether the reconstruction error of the acquired output data exceeds a specified reconstruction range. For example, an AMF entity acquires data regarding at least one of the occurrence period, frequency, and / or size of each message at the time when a control plane message (e.g., a registration message) and / or a user plane message is triggered or received by a target terminal, applies the acquired data to an artificial intelligence model for detecting suspected DDoS attacks to acquire output data, and can determine whether the target terminal is performing abnormal behavior, such as suspected DDoS attacks, based on whether the reconstruction error of the acquired output data exceeds a specified reconstruction range.For example, at the time an SMF entity receives a PDU session setup request from a target terminal, it obtains data regarding at least one of the number of messages, the number of concurrently connected terminals, the size of data packets, or the frequency of data transmission, applies the obtained data to an artificial intelligence model for detecting suspected DDoS attacks to obtain output data, and determines whether the target terminal is performing abnormal behavior such as suspected DDoS attacks based on whether the reconstruction error of the obtained output data exceeds a specified reconstruction range.

[0099] FIG. 5 is a diagram illustrating terminal grouping according to one embodiment.

[0100] According to one embodiment, by classifying acquired data by terminal group, data is also classified according to the characteristics of the terminal, and as a result of using the classified data set, the learning efficiency and prediction accuracy using an artificial intelligence model can be enhanced.

[0101] According to one embodiment, the identification information of a terminal refers to a criterion for identifying a terminal group and may include at least one of a DNN (data network name) used by the terminal, a network slice used by the terminal, an application used by the terminal, location information of the terminal, type / model / manufacturer of the terminal, and a service type.

[0102] According to one embodiment, terminals using the same DNN may be grouped together. For example, terminals using a DNN for general internet access may be classified into a first terminal group, terminals using a DNN for IoT (internet of things) devices may be classified into a second terminal group, and terminals using a DNN for video streaming services may be classified into a third terminal group.

[0103] According to one embodiment, terminals using the same network slice (e.g., S-NSSAI (single network slice selection assistance information)) may be grouped together. For example, terminals using an eMBB (enhanced mobile broadband) slice may be classified into a fourth terminal group, terminals using an URLLC (ultra-reliable low latency communications) slice may be classified into a fifth terminal group, and terminals using a MioT (massive internet of things) slice may be classified into a sixth terminal group.

[0104] According to one embodiment, terminals using a specific application (APP ID (Application Identifier)) may be classified into the same terminal group. For example, a terminal using a general app identifier may be classified into a seventh terminal group, and a terminal using a widget identifier may be classified into an eighth terminal group.

[0105] According to one embodiment, terminals with similar location information (e.g., Cell ID (cell identifier), TAC (tracking area code)) may be grouped together. Terminals located in a specific area may be considered to have similar traffic patterns. For example, a terminal with the same Cell ID: 10234 may be classified into the 9th terminal group, and a terminal with Cell ID: 20456 may be classified into the 10th terminal group. In this way, when terminal groups are classified into terminals belonging to different base station cells, the number of users, traffic volume, distance from the base station, signal strength based on terrain, buildings, etc., frequency band used, radio access technology (RAT) used, and network settings differ for each cell; therefore, the average values ​​of data regarding the specified terminal operation (e.g., data rate, session duration) may differ for each terminal group. For example, in a congested cell, the average value of the data rate may decrease, and the average value of the session duration may decrease.

[0106] According to one embodiment, terminals can be grouped together based on the IMEI TAC (international mobile equipment identity type allocation code) such that at least one of the type, model, or manufacturer is the same. The IMEI TAC may include identification information for specific models to which special services or restrictions apply. For example, terminals that support VoLTE (voice over LTE) services may be classified into a 11th terminal group, and terminals to which 5G services are restricted may be classified into a 12th terminal group.

[0107] According to one embodiment, terminals can be grouped by service type. For example, terminals using eMBB services may be classified into terminal group 13, terminals using URLLC services may be classified into terminal group 14, and terminals using mMTC (massive Machine Type Communications) services may be classified into terminal group 15.

[0108] Data regarding terminal operations specified according to abnormal operation types may vary in average values ​​and normal patterns across terminal groups. Therefore, by classifying data by terminal group and learning from the classified data, it is possible to determine whether an abnormality exists based on the situation and characteristics of each terminal group. The terminal groups presented in this disclosure are merely examples to aid in understanding the operation of classifying data by terminal group and are not intended to limit this disclosure.

[0109] Data regarding terminal operations specified according to an abnormal operation type according to one embodiment may be classified into at least one terminal group. For example, if multiple terminal groups are identified in the data obtained during the process of collecting training data, the data may be used as training, verification, or test data for an artificial intelligence model for each of the multiple terminal groups. For example, if multiple terminal groups are identified in the data obtained during the prediction process, the data may be applied to an artificial intelligence model for each of the multiple terminal groups. In this case, if it is determined that at least one terminal group is performing an abnormal operation, the corresponding terminal may be determined as an abnormal terminal.

[0110] According to one embodiment, an electronic device acquires data to be used for learning, verification, and / or testing, and can classify the acquired data by terminal group. Based on the data classified by terminal group, the electronic device can individually train an artificial intelligence model according to the characteristics of each terminal group.

[0111] According to one embodiment, an electronic device can acquire data to be applied to an artificial intelligence model from a target terminal and classify the acquired data by terminal group. The electronic device can acquire output data by applying the data classified by terminal group to an artificial intelligence model that has completed training according to the characteristics of each terminal group. In operation 510, the electronic device can identify at least one terminal group to which the target terminal belongs based on the identification information of the target terminal.

[0112] FIGS. 6 and 7 are drawings for explaining a judgment model according to one embodiment.

[0113] Figures 6 and 7 can be applied to the learning phase of an artificial intelligence model and / or the prediction phase after learning is completed.

[0114] Referring to FIGS. 6 and 7, the electronic device acquires data (600, 700) for a terminal operation specified according to an abnormal operation type, identifies at least one terminal group for the data (600, 700), and can input or apply the data (600, 700) to an abnormal operation determination model. In FIGS. 6 and 7, the abnormal operation determination model (610, 720) may refer to an autoencoder-based artificial intelligence model that determines whether a terminal performs an abnormal operation.

[0115] The abnormal operation determination model (610) illustrated in FIG. 6 may receive as input data for a terminal operation specified according to the type of abnormal operation and information for at least one terminal group identified for that terminal. After acquiring data for the specified terminal operation, the electronic device may identify at least one terminal group for the acquired data. For example, if the acquired data is data to be used for learning, verification, and / or testing, the electronic device may classify the acquired data by terminal group and perform individual learning for each terminal group. For example, even if the acquired data is used in a prediction step, the electronic device may classify the acquired data by terminal group (e.g., operation 510 in FIG. 5) and determine whether the target terminal performs an abnormal operation by applying the classified data to an artificial intelligence model.

[0116] The abnormal operation determination model (610) may receive as input information about at least one terminal group along with data regarding a terminal operation specified according to the abnormal operation type. At this time, the information about at least one terminal group may refer to information about at least one terminal group to which a terminal associated with the terminal operation specified according to the abnormal operation type belongs. The information about at least one terminal group may be identified based on the terminal identification information. The terminal identification information refers to a criterion for identifying a terminal group and may include at least one of the following: a DNN (data network name) used by the terminal, a network slice used by the terminal, an application used by the terminal, location information of the terminal, type / model / manufacturer of the terminal, and a service type.

[0117] The abnormal operation determination model (720) illustrated in FIG. 7 may include a plurality of sub-models, such as an abnormal operation determination model for a first terminal group, an abnormal operation determination model for a second terminal group, ..., an abnormal operation determination model for an Nth terminal group. Each of the plurality of sub-models may include an autoencoder-based artificial intelligence model that detects or determines whether a terminal included in one terminal group performs an abnormal operation. The abnormal operation determination model for each terminal group may receive data regarding a terminal operation specified according to the abnormal operation type as input.

[0118] In the learning, verification, and testing steps according to one embodiment, an abnormal operation determination model for each terminal group can learn the communication patterns of the terminals included in each terminal group based on the operation data of the terminals included in each terminal group. The electronic device can input data regarding a specified terminal operation into the abnormal operation determination model for each terminal group and proceed with learning in a direction that obtains output data within a specified reconstruction range. For example, the electronic device can classify the data obtained in the learning step into the first terminal group and the second terminal group among the first terminal group, the second terminal group, ..., the Nth terminal group, and use it as data for learning, verification, or testing for the abnormal operation determination model for the first terminal group and the abnormal operation determination model for the second terminal group, respectively.

[0119] In a prediction step according to one embodiment, the electronic device may apply data regarding a specified terminal operation of a target terminal to at least one sub-model corresponding to at least one identified terminal group and obtain output data. For example, the electronic device may obtain data regarding the target terminal in the prediction step, determine that the target terminal is included in the second terminal group and the N terminal group among the first terminal group, the second terminal group, ..., the N terminal group, and apply it to the abnormal operation determination model for the second terminal group and the abnormal operation determination model for the N terminal group, respectively. The electronic device may obtain output data by applying data regarding a specified terminal operation of the target terminal to the abnormal operation determination model for the second terminal group and the abnormal operation determination model for the N terminal group, respectively. The electronic device may determine whether the target terminal performs an abnormal operation based on whether the reconstruction error of the output data exceeds a specified reconstruction range. For example, if the reconstruction error of the output data obtained by applying data regarding the specified terminal operation of the target terminal to the abnormal operation determination model for the second terminal group is within the reconstruction range, and the reconstruction error of the output data obtained by applying data regarding the specified terminal operation of the target terminal to the abnormal operation determination model for the Nth terminal group exceeds the reconstruction range, the electronic device may determine that the target terminal performs an abnormal operation.

[0120] An electronic device according to one embodiment may, when detecting a target terminal performing an abnormal operation or when determining that a target terminal is performing an abnormal operation, transmit a warning message to an operator notifying them of the type of abnormal operation and / or the target terminal, and collect logs. When determining that a target terminal is performing an abnormal operation, it may include cases where at least one of an abnormal long-term / high-volume traffic flow, abnormal terminal activation, suspected DDoS attack, or excessive service access is detected.

[0121] Alternatively, the electronic device may block, restrict, and / or reject the signaling of an abnormal terminal. The electronic device may send a back-off time message to the target terminal. Back-off time is a waiting time used to prevent collisions during data transmission, and the electronic device may send a back-off time message to the target terminal to request that the target terminal wait for any back-off time and then attempt transmission again. Alternatively, the electronic device may discard the signaling received from the target terminal.

[0122] Alternatively, the electronic device may limit the quality of service (QoS) of the target terminal. For example, the electronic device may reduce or adjust the bitrate of data transmitted per unit time by a certain amount relative to the default value by reducing the quality of service (QoS) of a terminal group including the target terminal or by adjusting the QoS level.

[0123] An electronic device according to one embodiment logs the detection of abnormal behavior of a target terminal, and based on the log, if abnormal behavior is repeatedly detected for a specific target terminal, it may block, restrict, and / or deny the terminal's signaling, or apply weights to the level of QoS reduction. For example, if abnormal behavior is repeatedly detected for a target terminal, or if the number of times the target terminal is detected as abnormal exceeds a predetermined threshold, the electronic device may block, restrict, and / or deny the terminal's signaling for a longer period, or reduce the QoS for the target terminal and / or the terminal group to which the target terminal belongs more significantly. Additionally, as the number of times the target terminal is detected as abnormal increases or as the interval between detections of abnormality narrows, the blocking time may be increased in steps or the QoS may be reduced in steps. In this case, the blocking time may include a back-off time (i.e., waiting time) and a time for discarding the signaling.

[0124] An electronic device according to one embodiment acquires data regarding terminal operations specified according to an abnormal operation type, identifies at least one terminal group with respect to the acquired data, and then classifies the data associated with each terminal group into normal data for training, verification, and testing of an artificial intelligence model and abnormal data for verification and testing of an artificial intelligence model using the mean and standard deviation of each terminal group. The electronic device can identify information regarding normal operations and information regarding abnormal operations using network entities.

[0125] FIG. 8 is a diagram illustrating the process of an electronic device acquiring and classifying data regarding a terminal operation specified according to an abnormal operation type during a learning step according to one embodiment.

[0126] In operation 810, the electronic device may collect training data for a terminal operation specified according to an abnormal operation type. The training data for a terminal operation specified according to the abnormal operation type of operation 810 is similar to the data for a terminal operation specified according to the abnormal operation type of operation 410; however, there is a difference in usage because the training data of operation 810 is input to the artificial intelligence model during the training phase before the artificial intelligence model's training is completed, whereas the data of operation 410 is input to the artificial intelligence model after the artificial intelligence model's training is completed. However, referring to the data for a terminal operation specified according to the abnormal operation type obtained by the electronic device in FIG. 8 as "training data" is merely to prevent confusion with operation 410 of FIG. 4 and does not limit the present disclosure. For example, in the present disclosure, the training data of FIG. 8 is sometimes simply referred to as "data."

[0127] In operation 820, the electronic device can identify at least one group of terminals for training data. The electronic device can identify a group of terminals for training data based on identification information of terminals. The identification information of terminals refers to criteria for identifying a group of terminals and may include at least one of a DNN used by the terminal, a network slice used by the terminal, an application used by the terminal, location information of the terminal, type / model / manufacturer of the terminal, and a service type.

[0128] In operation 830, the electronic device can classify the training data associated with each terminal group into normal data for training, verification, and testing of the artificial intelligence model and abnormal data for verification and testing of the artificial intelligence model by using the mean and standard deviation of each terminal group. Specifically, the electronic device can classify the training data for a specified terminal operation into normal data and abnormal data according to the abnormal operation type through normalization and standardization of the training data.

[0129] In operation 840, the electronic device may train an artificial intelligence model to output reconstructed data having a reconstruction error of a specified range by using at least a portion of the training data as input data. The electronic device may use training data classified as normal data as input data for training, verification, or testing the artificial intelligence model. The electronic device may use training data classified as abnormal data as input data for verification or testing the artificial intelligence model.

[0130] FIG. 9 illustrates an example of the functional structure of a terminal according to one embodiment. The configuration exemplified in FIG. 9 can be understood as a configuration of a terminal. Terms such as '...part', '...unit', etc. used below refer to a unit that processes at least one function or operation, and this may be implemented in hardware or software, or a combination of hardware and software. The terminal of FIG. 9 may correspond to the terminal of FIG. 1.

[0131] Referring to FIG. 9, the terminal may include a communication unit (905), a storage unit (910), and a control unit (915).

[0132] The communication unit (905) can perform functions for transmitting and receiving signals through a wireless channel. For example, the communication unit (905) can perform a conversion function between a baseband signal and a bit sequence according to the physical layer specifications of the system. For example, when transmitting data, the communication unit (905) can generate complex symbols by encoding and modulating the transmitted bit sequence. Also, when receiving data, the communication unit (905) can restore the received bit sequence by demodulating and decoding the baseband signal. Additionally, the communication unit (905) can up-convert the baseband signal into an RF band signal and transmit it through an antenna, and down-convert the RF band signal received through the antenna into a baseband signal. For example, the communication unit (905) may include a transmission filter, a reception filter, an amplifier, a mixer, an oscillator, a DAC, an ADC, etc.

[0133] Additionally, the communication unit (905) may include a plurality of transmission and reception paths. Furthermore, the communication unit (905) may include at least one antenna array composed of a plurality of antenna elements. In terms of hardware, the communication unit (905) may be composed of digital circuits and analog circuits (e.g., radio frequency integrated circuits (RFICs)). Here, the digital circuits and analog circuits may be implemented as a single package. Additionally, the communication unit (905) may include a plurality of RF chains. Furthermore, the communication unit (905) may perform beamforming.

[0134] The communication unit (905) can transmit and receive signals as described above. Accordingly, all or part of the communication unit (905) may be referred to as a 'transmitter', a 'receiver', or a 'transmitter / receiver'. Furthermore, in the following description, transmission and reception performed via a wireless channel are used to mean that processing as described above is performed by the communication unit (905).

[0135] The storage unit (910) can store data such as basic programs, application programs, and setting information for the operation of the terminal. The storage unit (910) may be composed of volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. Additionally, the storage unit (910) can provide the stored data upon request from the control unit (915).

[0136] The control unit (915) can control the overall operations of the terminal. For example, the control unit (915) can transmit and receive signals through the communication unit (905). Additionally, the control unit (915) writes and reads data to and from the storage unit (910). Furthermore, the control unit (915) can perform the functions of the protocol stack required by the communication standard. To this end, the control unit (915) may include at least one processor or microprocessor, or be part of a processor. Additionally, part of the communication unit (905) and the control unit (915) may be referred to as a communication processor (CP). According to various embodiments, the control unit (915) can control the terminal to perform synchronization using a wireless communication network. For example, the control unit (915) can control the terminal to perform operations according to various embodiments described below.

[0137] According to various embodiments of the present disclosure, a terminal may be composed of ME (mobile equipment) and USIM (Universal Mobile Telecommunications Service (UMTS) Subscriber Identity Module). The ME may include MT (mobile terminal) and TE (terminal equipment). The MT may be a part where a wireless access protocol operates, and the TE may be a part where a control function operates. For example, in the case of a wireless communication terminal (e.g., a mobile phone), the MT and TE may be integrated, and in the case of a laptop, the MT and TE may be separated. The present disclosure may describe the ME and USIM as distinct entities depending on the operation of each component, but is not limited thereto; it is understood that the various embodiments of the present disclosure may be described by including the ME and USIM as a terminal (e.g., UE) or by referring to the ME as a terminal.

[0138] FIG. 10 illustrates an example of the functional structure of a network entity according to one embodiment. Terms such as '...part', '...unit' used below refer to a unit that processes at least one function or operation, and this may be implemented in hardware or software, or a combination of hardware and software. The network entity of FIG. 10 may correspond to the NWDAF entity, UPF entity, AMF entity, SMF entity, UDM entity, NEF entity, PCF entity, AF entity, or DN entity illustrated in FIG. 1.

[0139] Referring to FIG. 10, the core network entity is configured to include a communication unit (1005), a storage unit (1010), and a control unit (1015).

[0140] The communication unit (1005) can provide an interface for performing communication with other devices within the network. That is, the communication unit (1005) can convert a bit sequence transmitted from a network entity to another device into a physical signal, and convert a physical signal received from another device into a bit sequence. That is, the communication unit (1005) can transmit and receive signals. Accordingly, the communication unit (1005) may be referred to as a modem, a transmitter, a receiver, or a transceiver. At this time, the communication unit (1005) can enable the network entity to communicate with other devices or systems via a backhaul connection (e.g., wired backhaul or wireless backhaul) or via the network.

[0141] The storage unit (1010) can store data such as basic programs, application programs, and configuration information for the operation of a network entity. The storage unit (1010) may be composed of volatile memory, non-volatile memory, or a combination of volatile memory and non-volatile memory. Additionally, the storage unit (1010) can provide the stored data upon request from the control unit (1015).

[0142] The control unit (1015) can control the overall operations of the network entity. For example, the control unit (1015) can transmit and receive signals through the communication unit (1005). Additionally, the control unit (1015) writes and reads data to and from the storage unit (1010). To this end, the control unit (1015) may include at least one processor. According to various embodiments of the present disclosure, the control unit (1015) can control the network entity to perform synchronization using a wireless communication network. For example, the control unit (1015) can control the network entity to perform operations according to various embodiments described below.

[0143] Terms used in the foregoing description to identify connection nodes, terms referring to network entities, terms referring to messages, terms referring to interfaces between network entities, terms referring to various identification information, etc., are examples provided for the convenience of explanation. Accordingly, the present disclosure is not limited to the foregoing terms, and other terms referring to objects having equivalent technical meanings may be used.

[0144] The operations of the embodiments described above can be realized by providing a memory device storing program code in any component within the device. That is, the control unit within the device can execute the operations described above by reading and executing the program code stored in the memory device by a processor or a CPU (Central Processing Unit).

[0145] The entities or various components of terminal devices and modules described in this disclosure may be operated using hardware circuits, such as, for example, complementary metal oxide semiconductor-based logic circuits, firmware, software, and / or a combination of hardware and firmware and / or software embedded in a machine-readable medium. For example, various electrical structures and methods may be implemented using electrical circuits such as transistors, logic gates, and application-specific semiconductors.

[0146] Methods according to the claims or embodiments described in the specification of the present disclosure may be implemented in the form of hardware, software, or a combination of hardware and software.

[0147] When implemented in software, a computer-readable storage medium may be provided for storing one or more programs (software modules). One or more programs stored in the computer-readable storage medium are configured for execution by one or more processors within an electronic device. One or more programs include instructions that cause the electronic device to execute methods according to the claims or embodiments described in the specification of this disclosure.

[0148] These programs (software modules, software) may be stored in random access memory, non-volatile memory including flash memory, read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic disc storage device, compact disc-ROM (CD-ROM), digital versatile discs (DVDs), or other forms of optical storage devices, magnetic cassettes. Alternatively, they may be stored in a memory composed of some or all of these. Additionally, each constituent memory may include multiple units.

[0149] Additionally, the program may be stored on an attachable storage device that can be accessed via a communication network such as the Internet, Intranet, LAN (local area network), WAN (wide area network), or SAN (storage area network), or a combination thereof. Such a storage device may be connected to a device performing an embodiment of the present disclosure through an external port. Additionally, a separate storage device on a communication network may be connected to a device performing an embodiment of the present disclosure.

[0150] In the specific embodiments of the present disclosure described above, the components included in the disclosure are expressed in a singular or plural form according to the specific embodiments presented. However, the singular or plural expression is selected to suit the situation presented for convenience of explanation, and the present disclosure is not limited to singular or plural components; even if a component is expressed in the plural form, it may be composed of a singular form, and even if a component is expressed in the singular form, it may be composed of a plural form.

[0151] Meanwhile, although specific embodiments have been described in the detailed description of the present disclosure, it is understood that various modifications are possible within the scope of the present disclosure. Therefore, the scope of the present disclosure should not be limited to the described embodiments, but should be defined by the claims set forth below as well as equivalents thereof.

Claims

1. In a method performed by an electronic device, For a target terminal to determine whether an abnormal operation is performed, an operation to obtain data regarding a terminal operation specified according to the type of abnormal operation; An operation of obtaining output data by applying data regarding the specified terminal operation of the above target terminal to an autoencoder-based artificial intelligence model; and A method comprising determining whether the target terminal performs an abnormal operation based on whether the reconstruction loss of the output data exceeds the specified reconstruction range.

2. In Paragraph 1, The above artificial intelligence model includes a plurality of sub-models, and Each of the multiple sub-models is intended to detect whether a terminal included in a terminal group is performing an abnormal operation, and The operation of obtaining output data by applying data regarding the specified terminal operation of the above target terminal to the above artificial intelligence model is, An operation to identify at least one terminal group to which the target terminal belongs, based on the identification information of the target terminal; and A method comprising applying data regarding a specified terminal operation of the above target terminal to at least one sub-model corresponding to the identified at least one terminal group.

3. In Paragraph 1, A method further comprising, when it is determined that the target terminal is performing an abnormal operation, discarding the signaling received from the target terminal, sending a back-off time message to the target terminal, or limiting the quality of service (QoS) of the target terminal.

4. In Paragraph 1, A method in which, when the type of abnormal operation is an unexpected long-live / large rate flow, the data according to the type of abnormal operation includes at least one of session maintenance time, data rate, packet size, or frequency of data transmission.

5. In Paragraph 1, A method in which, when the type of abnormal operation is an unexpected wake-up or too frequent service access, the data regarding the type of abnormal operation includes at least one of the time of occurrence of a service request initiated by the terminal or the frequency of said service request.

6. In Paragraph 1, If the type of the above abnormal behavior is a suspected DDoS attack, Data regarding the above abnormal operation type includes at least one of the number of control plane messages triggered by the terminal, the number of user plane messages, the number of concurrent connections of the terminal, the size of the transmitted packet, or the frequency of packet transmission. The above control plane message is a method including registration, deregistration, establishment of a PDU (protocol data unit) session, modification of a PDU session, and release of a PDU session.

7. In Paragraph 1, An operation to collect training data for terminal operations specified according to abnormal operation types; and A method further comprising the operation of training the artificial intelligence model to output reconstructed data having a reconstruction error of a specified range by using at least a portion of the above training data as input data.

8. In Paragraph 7, An operation to identify at least one terminal group for the above-mentioned training data; and A method further comprising the operation of classifying the training data associated with each terminal group into normal data for training, verification, and testing of the artificial intelligence model and abnormal data for verification and testing of the artificial intelligence model using the mean and standard deviation of each terminal group.

9. In electronic devices, Transmitter / receiver; Memory for storing instructions; and Includes one or more processors, The above instructions are executed by the above one or more processors, and the electronic device: For a target terminal to determine whether it performs an abnormal operation, data regarding the terminal operation specified according to the type of abnormal operation is obtained, and Output data is obtained by applying data regarding the specified terminal operation of the above target terminal to an autoencoder-based artificial intelligence model, and An electronic device that determines whether the target terminal performs an abnormal operation based on whether the reconstruction loss of the output data exceeds the specified reconstruction range.

10. In Paragraph 9, The above artificial intelligence model includes a plurality of sub-models, and Each of the multiple sub-models is intended to detect whether a terminal included in a terminal group is performing an abnormal operation, and The above instructions are executed by the above one or more processors, and the electronic device: Based on the identification information of the target terminal, at least one terminal group to which the target terminal belongs is identified, and An electronic device that applies data regarding a specified terminal operation of the above target terminal to at least one sub-model corresponding to the identified at least one terminal group.

11. In Paragraph 9, The above instructions are executed by the above one or more processors, and the electronic device: An electronic device that, when it is determined that the target terminal is performing an abnormal operation, discards the signaling received from the target terminal, sends a back-off time message to the target terminal, or limits the quality of service (QoS) of the target terminal.

12. In Paragraph 9, An electronic device in which, when the type of abnormal operation is an unexpected long-live / large rate flow, the data according to the type of abnormal operation includes at least one of a session duration, a data rate, a packet size, or a frequency of data transmission.

13. In Paragraph 9, An electronic device in which, when the type of abnormal operation is an unexpected wake-up or too frequent service access, the data regarding the type of abnormal operation includes at least one of the time of occurrence of a service request initiated by the terminal or the frequency of said service request.

14. In Paragraph 9, If the type of the above abnormal behavior is a suspected DDoS attack, Data regarding the above abnormal operation type includes at least one of the number of control plane messages triggered by the terminal, the number of user plane messages, the number of concurrent connections of the terminal, the size of the transmitted packet, or the frequency of packet transmission. The above control plane message is an electronic device including registration, deregistration, establishment of a PDU (protocol data unit) session, modification of a PDU session, and release of a PDU session.

15. In Paragraph 9, The above instructions are executed by the above one or more processors, and the electronic device: Collect training data for terminal operations specified according to abnormal operation types, and The artificial intelligence model is trained to output reconstructed data having a reconstruction error of a specified range by using at least a portion of the above training data as input data, and Identify at least one terminal group for the above training data, and An electronic device that classifies the training data associated with each terminal group into normal data for training, verification, and testing of the artificial intelligence model and abnormal data for verification and testing of the artificial intelligence model, using the mean and standard deviation of each terminal group.