3GPP 23.501 v20.2.0 — the document's own text
5.54 Mitigating abnormal user plane traffic
Taught in 27. Overload, energy, deployment and the rest (The 5G system architecture, in depth).
Abnormal user plane traffic can be mitigated based on PCF control, direct SMF control, indirect SMF control or AF control.
When PCF control applies: The PCF may subscribe to notifications of analytics related to "Abnormal user plane traffic" and update SM policies to mitigation abnormal user plane traffic based on the analytics as described in TS 23.503 [4].
When direct SMF control applies: The SMF may subscribe to notifications or sends a request to NWDAF for the analytics related to "Abnormal user plane traffic" using the Nnwdaf_AnalyticsSubscription or Nnwdaf_AnalyticsInfo_Request service including the Analytics ID "Abnormal user plane traffic", according to clause 6.24.1 of TS 23.288 [86]. The SMF is notified about observed or predicted abnormal user plane traffic, including information related to type of detected anomaly and information about affected traffic flows.
The SMF can alternatively directly subscribe to Nupf_EventExposure for the "Abnormal Traffic Pattern" event and will then be notified by the UPF when it detects abnormal traffic, including information related to type of detected anomaly and information about affected traffic flows.
The SMF as consumer of NWDAF analytics or the Nupf_EventExposure "Abnormal Traffic Pattern" event may determine mitigation actions. for example:
- UPF reselection to distribute the load across UPF instances (as defined in clause 6.3.3 and clause 4.3.5 of TS 23.502 [3]).
- Configuring UPF to enforce downlink traffic dropping, to shape abnormal traffic to enforce bandwidth limitations, or to suppress Downlink Data Reporting. The SMF may use related UPF configuration on a PDU session level (using N4 rules) or on node level (using Node Level rules, defined in clause 5.8.6, in the N4 Association Update procedure, as described in clause 4.4.3.2 in TS 23.502 [3]).
The UPF may be provisioned by SMF with Packet Detection Rules for a PDU Session to detect abnormal traffic. When the abnormal traffic is detected, the UPF enforces actions, as instructed in the N4 rules (such as QER or FAR), to improve user plane performance. The enforced actions depend on the type of anomaly detected by the PDR; some examples are downlink traffic suppression or abnormal traffic shaping or suppression of downlink data notifications to the SMF. The detection of the abnormal traffic at the UPF may be independent of the use of any Analytics ID provided by NWDAF in TS 23.288 [86].
The UPF may be provisioned by SMF with Node Level rules for any DL traffic not associated to a PDU Session to detect abnormal traffic as described in the N4 Association Update procedure, see clause 4.4.3.2 in TS 23.502 [3]. When the abnormal traffic is detected the UPF enforces actions, as those described in the N4 Association Update procedure. The detection of the abnormal traffic at the UPF may be independent of the use of any Analytics ID provided by NWDAF in TS 23.288 [86]. The format of the Node Level rule sent from SMF to UPF is defined in clause 5.8.6.
NOTE 1: When SMF is the consumer of NWDAF analytics, the Type of Abnormal traffic attribute is not provided in the Node Level rule.
When indirect SMF control applies: The SMF subscribes on behalf of the UPF to notifications of analytics related to "Abnormal user plane traffic" using the Nnwdaf_AnalyticsSubscription service including the Analytics ID "Abnormal user plane traffic" following the subscription pattern in Figure 7.1.2-3. The SMF indicate in the subscription that reduced output is requested, that "any UE" is targeted, and a notification address of the UPF as indicated in the NF profile of the UPF, configured at the SMF, or received during N4 Association Setup procedure. The NWDAF then sends directly to the UPF the analytics with reduced output. The UPF is notified about observed or predicted abnormal user plane traffic via the output parameters Abnormal traffic type and Packet Filter Set (see clause 6.24.3 of TS 23.288 [86]). In this scenario, the SMF configures Node Level rule(s) (defined in clause 5.8.6) at the UPF in the N4 Association Update procedure (as described in clause 4.4.3.2 in TS 23.502 [3]) and sets the Traffic Filters attribute as empty. The UPF as consumer of NWDAF analytics identifies the Node Level rule that has the same value for the Abnormal traffic type as the one received in the analytics output, and adds the Packet Filter Set or Application ID received in the analytics output to the Traffic Filters of the Node Level rule. In addition, the UPF starts a timer for this Packet Filter Set or Application ID with a value based on the Time Information received in the analytics output.
Whenever the Traffic Filters of a Node Level rule contains any Packet Filter Set or Application ID, the UPF applies mitigation actions as indicated by this Node Level rule for the affected traffic flows. A Packer Filter Set or Application ID will be deleted from the Node Level rule when its corresponding timer expires.
Alternatively, the UPF can be configured with Node Level rules by OAM (instead of the SMF) and apply those mitigation actions based on the analytics obtained from the NWDAF.
An AF may subscribe to notifications of analytics related to "Abnormal user plane traffic" using the Nnwdaf_AnalyticsSubscription service including the Analytics ID "Abnormal user plane traffic" and providing a target of analytics reporting, according to clause 6.24.1 of TS 23.288 [86].
NOTE 2: The AF as consumer of NWDAF analytics may determine mitigation actions. The AF can be configured with possible values of the traffic abnormality type and corresponding mitigation actions. As an example, an AF as IoT server can reconfigure UEs it supervises that cause abnormal traffic due to misconfiguration.
OAM (e.g. via MDAF) may also subscribe to notifications of analytics related to "Abnormal user plane traffic" using the Nnwdaf_AnalyticsSubscription service including the Analytics ID "Abnormal user plane traffic", according to clause 6.24.1 of TS 23.288 [86] and may determine mitigation actions based on the analytics.