UE User Data Detection With Central-Edge Abnormal Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The high bandwidth and low latency of 5G networks increase the risk of network attacks due to massive UE access and high service availability, necessitating efficient security detection of user data, while existing methods face challenges with heavy traffic and limited network resources.
Innovation Solution
A data filtering mechanism is employed to reduce the amount of data to be detected by identifying abnormal user equipment (UE) behavior through a central detection node, which determines abnormal group features and sends them to edge detection nodes for filtering, using AI engines to analyze and discard non-compliant data packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all user data is detected to ensure network security, then security detection coverage is improved, but detection efficiency deteriorates due to heavy traffic volume
Solution Approach 1:
The patent segments the detection system into two parts: a central detection node that analyzes signaling data to identify abnormal UE, and edge detection nodes that filter and detect only relevant data. This segmentation allows the system to maintain comprehensive security coverage while improving detection efficiency by distributing the detection workload and focusing resources on suspicious traffic.
Solution Approach 2:
The patent performs preliminary analysis of signaling data at the central detection node to identify abnormal UE and their characteristics before data reaches the edge detection nodes. This preliminary action enables the edge nodes to filter out normal traffic in advance, so only potentially malicious data requires detailed inspection, thereby improving overall detection efficiency without compromising security.
2Reliability
If detection resources are increased to handle massive UE access, then detection capability is improved, but network resource consumption worsens
Solution Approach 1:
The patent implements local quality by deploying detection capabilities at both central and edge nodes with different functions. The central node focuses on signaling analysis and abnormal UE identification, while edge nodes handle data filtering and inspection. This localized specialization allows the network to achieve comprehensive detection capability without uniformly increasing resources across all nodes, thereby reducing overall network resource consumption.
Solution Approach 2:
The patent applies partial action by having edge detection nodes filter and inspect only the data relevant to identified abnormal UE, rather than analyzing all user data. This partial inspection approach maintains detection capability for malicious traffic while significantly reducing the computational resources required compared to full-data analysis.
3Productivity
If data filtering is performed to reduce detection volume, then detection efficiency is improved, but detection precision may worsen due to selective filtering
Solution Approach 1:
The patent implements a feedback mechanism where the central detection node continuously analyzes signaling data, identifies abnormal UE, and provides updated abnormal group features to edge detection nodes. This feedback loop ensures that filtering criteria are dynamically adjusted based on actual threat patterns, maintaining detection precision while enabling efficient filtering of normal traffic.
Solution Approach 2:
The patent makes the detection system dynamic by continuously updating the abnormal group features based on real-time signaling data analysis. The edge detection nodes use these dynamic features to adapt their filtering criteria, ensuring that filtering remains precise even as attack patterns evolve, thereby maintaining detection precision while preserving efficiency benefits.
Data Source
AI summary
This application discloses a method and device for detecting user data of UE, and a storage medium. The central detection node device determines abnormal UE based on core network signaling data, determines an abnormal group feature based on the abnormal UE and sends the abnormal group feature to an edge detection node device. Where the abnormal UE is UE with an abnormal behavior and the abnormal group feature includes an identifier or a user data transmission mode used by the abnormal UE to perform communication.


