Invention Grant
- Patent Title: Detection of downloaded malware using DNS information
- Patent Title (中): 使用DNS信息检测下载的恶意软件
-
Application No.: US12503253Application Date: 2009-07-15
-
Publication No.: US08347394B1Publication Date: 2013-01-01
- Inventor: Andrew Lee
- Applicant: Andrew Lee
- Applicant Address: JP Tokyo
- Assignee: Trend Micro, Inc.
- Current Assignee: Trend Micro, Inc.
- Current Assignee Address: JP Tokyo
- Agency: Beyer Law Group LLP
- Main IPC: G08B23/00
- IPC: G08B23/00

Abstract:
A DNS engine monitors domain name system (DNS) network activity occurring between a user computer and a remote computer server. The engine collects DNS traffic information during a specified time window at the user computer using the monitored DNS network activity. The engine generates a local DNS reputation for the user computer and stores the local DNS reputation on the user computer. When a triggering event is received at the user computer the engine determines that the triggering event is abnormal in comparison to the stored local DNS reputation. An alert is issued to a software product on the user computer. The engine takes an action using a software product upon the alert. The reputation may be a frequency distribution for each accessed domain name and IP address. A triggering event may be an abnormal access to a domain name or IP address, or a mismatch between DNS queries and DNS responses of the user computer.
Information query