| CPC H04W 12/12 (2013.01) [H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04W 48/06 (2013.01)] | 20 Claims |

|
1. A method for determining class information, comprising:
sending, by a security detection function network element, a subscription data collection event to a mobility management network element, wherein the subscription data collection event comprises a collection range and a reporting condition, wherein the collection range indicates that data is collected based on class information of a terminal, and wherein the reporting condition indicates a condition for triggering reporting of traffic data;
receiving, by the security detection function network element, a data collection service response message from the mobility management network element, wherein the data collection service response message comprises first class information and first traffic data corresponding to the first class information, and wherein the first traffic data meets the reporting condition;
determining, by the security detection function network element, abnormal class information based on the first traffic data, wherein the determining comprises determining, based on the first traffic data, at least one parameter indicating whether a distributed denial of service (DDoS) attack occurs; and
sending, by the security detection function network element, the abnormal class information to a policy control network element, wherein flow matching information and a flow processing method are generated, wherein the flow matching information is used to match user plane traffic, and wherein the flow processing method is used to control user plane traffic that matches the flow matching information and that is from a terminal matching the abnormal class information.
|