×

Updating of malicious code patterns using public DNS servers

  • US 8,171,467 B1
  • Filed: 07/03/2007
  • Issued: 05/01/2012
  • Est. Priority Date: 07/03/2007
  • Status: Active Grant
First Claim
Patent Images

1. A method of updating currently existing malicious code patterns of an antivirus in a client computer, the method to be performed by the client computer and comprising:

  • making a first domain name system (DNS) query for a first DNS record of a first fully qualified domain name (FQDN);

    receiving a first DNS result responsive to the first DNS query;

    obtaining from a payload of the first DNS result information on obtaining an updated malicious code pattern for the antivirus in the client computer;

    making a second DNS query for a second DNS record of a second FQDN;

    receiving a second DNS result responsive to the second DNS query; and

    obtaining from a payload of the second DNS result a portion of the updated malicious code pattern, the updated malicious code pattern being divided into several portions for transmission in several DNS results; and

    updating the currently existing malicious code patterns in the client computer with a portion of the updated malicious code pattern extracted from the payload of the second DNS result;

    wherein the first and second DNS results are cached in a public DNS server computer when the first and second DNS records were published by a private DNS server computer operated for a vendor of the antivirus in the client computer and wherein the first DNS record includes information on a number of portions the updated malicious code pattern has been divided into.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×