Method and device for detecting application by using network analysis information in wireless communication system
The disclosure relates to a fifth generation (5G) or sixth generation (6G) communication system for supporting a higher data transmission rate. Disclosed is a method and device for controlling a wireless communication system to detect information about an application in use by analyzing data from a user terminal. A method performed by a network data collection and analysis function (NWDAF) includes receiving, from a network exposure function (NEF), a first message including a terminal identifier (ID) to request analysis information on a validity of packet flow detection (PFD) information; transmitting, to the NEF, a second message as a response to the first message; transmitting, to the NEF, a third message including the terminal ID to request the PFD information; and receiving, from the NEF, a fourth message including the terminal ID and packet detection rule (PDR) information as a response to the third message.
1 . A method performed by a network data collection and analysis function (NWDAF) in a wireless communication system, the method comprising:
receiving, from a network exposure function (NEF), a first message including a terminal identifier (ID) to request analysis information on a validity of packet flow detection (PFD) information;
transmitting, to the NEF, a second message as a response to the first message;
transmitting, to the NEF, a third message including the terminal ID to request the PFD information; and
receiving, from the NEF, a fourth message including the terminal ID and packet detection rule (PDR) information as a response to the third message; and
determining the validity of the PFD information based on information on exception traffic for the PDR information and a ratio of information on traffic corresponding to the PDR information and information on traffic that does not correspond to the PDR information.
2 . The method of claim 1 , further comprising:
transmitting, to a user plane function (UPF), a fifth message including the terminal ID and the PDR information to request collection of information on traffic of the terminal; and
receiving, from the UPF, a sixth message as a response to the fifth message.
3 . The method of claim 2 , further comprising:
receiving, from the UPF, a seventh message including the information on traffic of the terminal,
wherein the information on traffic of the terminal includes the terminal ID, the information on exception traffic for the PDR information, and the ratio of the information on traffic corresponding to the PDR information and the information on traffic that does not correspond to the PDR information.
4 . The method of claim 3 , further comprising:
transmitting, to the NEF, an eighth message including a result of the validity of the PFD information.
5 . The method of claim 4 ,
wherein the eighth message further includes information on processing of the PFD information and at least one information included in the information on traffic of the terminal of the seventh message.
6 . The method of claim 3 ,
wherein the seventh message further includes at least one of filter information applied to detect traffic, period information related to traffic, area information related to traffic, time information related to traffic, or packet number information related to traffic.
7 . The method of claim 2 ,
wherein the fifth message further includes at least one of a report period, an interest area, threshold information, or an indicator indicating whether to collect the exception traffic.
8 . The method of claim 1 ,
wherein the first message further includes information on at least one of an analysis ID, a network slice ID, a data network name, a reporting time, or a region of interest,
wherein the third message further includes an event ID, and
wherein the fourth message further includes at least one of the event ID or an application ID.
9 . The method of claim 1 ,
wherein the PDR information includes packet filter information, and
wherein the packet filter information includes at least one of a source internet protocol (IP) address, a destination IP address, a source port, a destination port, a protocol type, a uniform resource locator (URL) list, or a domain name.
10 . A network data collection and analysis function (NWDAF) in a wireless communication system, the NWDAF comprising:
a transceiver; and
a controller configured to:
receive, from a network exposure function (NEF), a first message including a terminal identifier (ID) to request analysis information on a validity of packet flow detection (PFD) information,
transmit, to the NEF, a second message as a response to the first message,
transmit, to the NEF, a third message including the terminal ID to request the PFD information,
receive, from the NEF, a fourth message including the terminal ID and packet detection rule (PDR) information as a response to the third message, and
determine the validity of the PFD information based on information on exception traffic for the PDR information and a ratio of information on traffic corresponding to the PDR information and information on traffic that does not correspond to the PDR information.
11 . The NWDAF of claim 10 ,
wherein the controller is further configured to:
transmit, to a user plane function (UPF), a fifth message including the terminal ID and the PDR information to request collection of information on traffic of the terminal, and
receive, from the UPF, a sixth message as a response to the fifth message.
12 . The NWDAF of claim 11 ,
wherein the controller is further configured to receive, from the UPF, a seventh message including the information on traffic of the terminal, and
wherein the information on traffic of the terminal includes the terminal ID, the information on exception traffic for the PDR information, and the ratio of the information on traffic corresponding to the PDR information and the information on traffic that does not correspond to the PDR information.
13 . The NWDAF of claim 12 ,
wherein the controller is further configured to:
transmit, to the NEF, an eighth message including a result of the validity of the PFD information.
14 . The NWDAF of claim 13 ,
wherein the eighth message further includes information on processing of the PFD information and at least one information included in the information on traffic of the terminal of the seventh message.
15 . The NWDAF of claim 12 ,
wherein the seventh message further includes at least one of filter information applied to detect traffic, period information related to traffic, area information related to traffic, time information related to traffic, or packet number information related to traffic.
16 . The NWDAF of claim 11 ,
wherein the fifth message further includes at least one of a report period, an interest area, threshold information, or an indicator indicating whether to collect the exception traffic.
17 . The NWDAF of claim 10 ,
wherein the first message further includes information on at least one of an analysis ID, a network slice ID, a data network name, a reporting time, or a region of interest,
wherein third message further includes an event ID, and
wherein the fourth message further includes at least one of the event ID or an application ID.
18 . The NWDAF of claim 10 ,
wherein the PDR information includes packet filter information, and
wherein the packet filter information includes at least one of a source internet protocol (IP) address, a destination IP address, a source port, a destination port, a protocol type, a uniform resource locator (URL) list, or a domain name.