Network Traffic Classification Using Distributed ML Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content providers and network operators, especially small ones, face challenges in accurately classifying traffic due to the lack of support for the 3GPP exposure framework, leading to reliance on vendor capabilities that require frequent updates and are inaccurate for encrypted traffic or when IP addresses, FQDNs, or CDN nodes host multiple applications.

Innovation Solution

A method involving the Network Data Analytics Function (NWDAF) develops a model for classifying traffic data using machine-learning techniques, which is then stored and installed at other network functions to accurately classify future traffic data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vendor capabilities with DPI engine and local OAM configuration are used for traffic classification, then traffic classification can be performed, but the classification accuracy deteriorates because rules require frequent updates and cannot handle encrypted traffic or multi-application CDN nodes

Engineering Contradiction:
Improvetraffic classification accuracyVSAvoidrule update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic traffic classification by transitioning from static local OAM configuration to a dynamic rule distribution system. The SMF receives classification rules from the PCF and dynamically distributes them to multiple UPF instances based on real-time traffic needs, enabling the system to adapt to changing traffic patterns and encrypted content without manual reconfiguration of each UPF device.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal rule management system where the PCF serves as a central repository for classification rules that can be shared across multiple SMF and UPF instances. This multi-functional architecture allows any UPF in the network to access and apply the same classification rules, eliminating the need for each device to maintain separate local configurations and enabling consistent classification across diverse traffic types including encrypted content.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If deterministic rules are provided through 3GPP exposure framework, then traffic classification can be standardized, but the system becomes inadequate when traffic is encrypted or when IP addresses, FQDNs, or CDN nodes are not valid

Engineering Contradiction:
Improvetraffic classification coverageVSAvoidclassification accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces the PCF as an intermediary between the deterministic rule framework and the actual traffic classification process. The PCF receives classification rules, enriches them with additional context, and distributes them to UPFs. This intermediary layer enables the system to handle encrypted traffic and edge cases by providing enhanced rule processing capabilities that go beyond basic deterministic matching.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms classification rules from simple deterministic patterns into enhanced parameters that include multiple identification methods (IP addresses, FQDNs, CDN node information, and other characteristics). By changing the parameter structure of classification rules to accommodate multiple traffic identification approaches, the system can accurately classify encrypted traffic and handle cases where traditional identification methods fail.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12481985B2Classifying traffic data
Publication Date: 2025.11.25 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12481985B2 patent drawing
  • US12481985B2 patent drawing
  • US12481985B2 patent drawing

AI summary

A method of classifying traffic data in a network comprises at a Network Data Analytics Function (NWDAF), receiving information relating to traffic data with a known classification from one or more first network functions, and developing a model for classifying future traffic data based on the information relating to the traffic data with a known classification. The method also involves at a second network function, storing a representation of the developed model. The method also involves at a third network function, receiving the representation of the developed model from the second network function, and installing the representation of the developed model at a fourth network function. The method also involves at the fourth network function, classifying traffic data using the developed model.