METHOD AND APPARATUS FOR IDENTIFYING AN APPLICATION ASSOCIATED WITH AN IP FLOW USING DNS DATA
A method of identifying application data associated with IP flows traveling between a plurality of mobiles and a network element in a communications network includes receiving, at a network element, one or more domain name system (DNS) packets being sent to one or more mobiles from among of the plurality of mobiles; and building, at the network element, a mapping table mapping one or more IP addresses, respectively, to corresponding application information, based on mapping information within the one or more DNS packets received at the network element.
1 . A method of handling application data associated with IP flows traveling between a plurality of mobiles and a network element in a communications network, the method comprising:
receiving, at a network element, one or more domain name system (DNS) packets being sent to one or more mobiles from among of the plurality of mobiles; and
building, at the network element, a mapping table mapping one or more IP addresses, respectively, to corresponding application information, based on mapping information within the one or more DNS packets received at the network element.
2 . The method of claim 1 , wherein the application information is at least one of a host name read from the one or more DNS packets received at the network element, and a name of an application corresponding to the read host name.
3 . The method of claim 2 , wherein the received DNS packets are DNS response packets, and building the mapping table includes reading the one or more IP addresses and one or more host names corresponding to the one or more IP addresses from the one or more DNS packets received at the network element.
4 . The method of claim 2 , further comprising:
receiving, at the network element, an IP data packet being sent to or from a mobile of the plurality of mobiles; and
identifying application information associated with the received IP data packet by searching the mapping table based on the IP data packet.
5 . The method of claim 4 , wherein
the searching the mapping table includes selecting application data in the mapping table corresponding to a sender IP address in the mapping table as the identified application information, if the received IP data packet is a packet being sent to one of the plurality of mobiles, the sender IP address being a sender IP address of the received IP data packet, and
the searching the mapping table includes selecting application information corresponding to a destination IP address in the mapping table as the identified application information, if the received IP data packet is a packet being sent from one of the plurality of mobiles, the destination IP address being a destination IP address of the received IP data packet.
6 . The method of claim 2 , further comprising:
identifying, at the network element, the mobile from among the one or more mobiles the IP data packet received at the network element is being sent to or from;
building a tracking database including sections corresponding to each of the plurality of mobile devices; and
forming an entry in the tracking database corresponding to the identified application information, the entry being formed in the section of the tracking database which corresponds to the identified mobile.
7 . The method of claim 6 , wherein the identified application information is a host name, and the entry formed in the tracking database is a name of an application corresponding to the host name.
8 . The method of claim 2 , wherein the mapping table is a hash table.
9 . A network apparatus for identifying application data associated with IP flows traveling between a plurality of mobiles and the network apparatus in a communications network, the apparatus comprising:
a data receiving unit;
a data transmitting unit;
a memory unit configured to store parameters corresponding with a plurality mobiles in communication with the network element; and
a processing unit coupled to the data transmitting unit, the data receiving unit, and the memory unit and configured to control operations including,
receiving one or more domain name system (DNS) packets being sent to one or more mobiles from among the plurality of mobiles; and
building a mapping table mapping one or more IP addresses, respectively, to corresponding application information, based on mapping information within the one or more DNS packets received at the network apparatus.
10 . The network apparatus of claim 9 , wherein the application information is at least one of a host name read from the one or more DNS packets received at the network element, and a name of an application corresponding to the read host name.
11 . The network apparatus of claim 10 , wherein the received DNS packets are DNS response packets, and the processing unit is configured such that the building the mapping table includes reading the one or more IP addresses and one or more host names corresponding to the one or more IP address from the one or more DNS packets received at the network apparatus.
12 . The network apparatus of claim 10 , wherein the processing unit is further configured to control operations including,
receiving an IP data packet being sent to or from a mobile from among the plurality of mobiles; and
identifying application information associated with the received IP data packet by searching the mapping table based on the IP data packet.
13 . The network apparatus of claim 12 , wherein the processing unit is configured such that,
the searching the mapping table includes selecting application data in the mapping table corresponding to a sender IP address in the mapping table as the identified application information, if the received IP data packet is a packet being sent to one of the plurality of mobiles, the sender IP address being a sender IP address of the received IP data packet, and
the searching the mapping table includes selecting application information corresponding to a destination IP address in the mapping table as the identified application information, if the received IP data packet is a packet being sent from one of the plurality of mobiles, the destination IP address being a destination IP address of the received IP data packet.
14 . The network apparatus of claim 10 , wherein the processing unit is further configured to control operations including,
identifying the mobile from among the one or more mobiles the received IP data packet is being sent to or from;
building a tracking database including sections corresponding to each of the plurality of mobile devices; and
forming an entry in the tracking database corresponding to the identified application information, the entry being formed in the section of the tracking database which corresponds to the identified mobile.
15 . The network apparatus of claim 14 , wherein the application information is a host name, and the entry formed in the tracking database is a name of an application corresponding to the host name.
16 . The method of claim 10 , wherein the mapping table is a hash table.