Network Traffic Classification Using Distributed ML Models
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content providers and network operators, especially small ones, face challenges in accurately classifying traffic due to the lack of support for the 3GPP exposure framework, leading to reliance on vendor capabilities that require frequent updates and are inaccurate for encrypted traffic or when IP addresses, FQDNs, or CDN nodes host multiple applications.
Innovation Solution
A method involving the Network Data Analytics Function (NWDAF) develops a model for classifying traffic data using machine-learning techniques, which is then stored and installed at other network functions to accurately classify future traffic data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vendor capabilities with DPI engine and local OAM configuration are used for traffic classification, then traffic classification can be performed, but the classification accuracy deteriorates because rules require frequent updates and cannot handle encrypted traffic or multi-application CDN nodes
Solution Approach 1:
The patent implements dynamic traffic classification by transitioning from static local OAM configuration to a dynamic rule distribution system. The SMF receives classification rules from the PCF and dynamically distributes them to multiple UPF instances based on real-time traffic needs, enabling the system to adapt to changing traffic patterns and encrypted content without manual reconfiguration of each UPF device.
Solution Approach 2:
The patent creates a universal rule management system where the PCF serves as a central repository for classification rules that can be shared across multiple SMF and UPF instances. This multi-functional architecture allows any UPF in the network to access and apply the same classification rules, eliminating the need for each device to maintain separate local configurations and enabling consistent classification across diverse traffic types including encrypted content.
2Adaptability or versatility
If deterministic rules are provided through 3GPP exposure framework, then traffic classification can be standardized, but the system becomes inadequate when traffic is encrypted or when IP addresses, FQDNs, or CDN nodes are not valid
Solution Approach 1:
The patent introduces the PCF as an intermediary between the deterministic rule framework and the actual traffic classification process. The PCF receives classification rules, enriches them with additional context, and distributes them to UPFs. This intermediary layer enables the system to handle encrypted traffic and edge cases by providing enhanced rule processing capabilities that go beyond basic deterministic matching.
Solution Approach 2:
The patent transforms classification rules from simple deterministic patterns into enhanced parameters that include multiple identification methods (IP addresses, FQDNs, CDN node information, and other characteristics). By changing the parameter structure of classification rules to accommodate multiple traffic identification approaches, the system can accurately classify encrypted traffic and handle cases where traditional identification methods fail.
Data Source
AI summary
A method of classifying traffic data in a network comprises at a Network Data Analytics Function (NWDAF), receiving information relating to traffic data with a known classification from one or more first network functions, and developing a model for classifying future traffic data based on the information relating to the traffic data with a known classification. The method also involves at a second network function, storing a representation of the developed model. The method also involves at a third network function, receiving the representation of the developed model from the second network function, and installing the representation of the developed model at a fourth network function. The method also involves at the fourth network function, classifying traffic data using the developed model.


