METHOD AND APPARATUS TO BLOCK FAST-SPREADING COMPUTER WORMS THAT USE DNS MX RECORD QUERIES

Patent №

US 7,634,808

Granted

2009-12-15

Filed 2004

Owner

SYMANTEC CORPORATION

Lab

AI components

2

kr · planning

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

10923589

Parameters of DNS transactions associated with DNS MX record queries, which may be performed by mass-mailing worms from a host computer system, are detected at a DNS proxy and collected. An outbound SMTP transaction, such as an e-mail message, received at an SMTP proxy is stalled at the SMTP proxy and a determination is made whether malicious code activity is detected on the host computer system by correlating the parameters associated with the DNS MX record queries and the e-mail message. In one embodiment, above a specified threshold rate of DNS MX record queries to resolve SMTP server IP addresses, followed by the use of a resolved SMTP server IP address to send the e-mail message, an assumption is made that the e-mail message is generated by a worm, such as a mass-mailing worm, and protective action is taken thus preventing propagation of the worm, or other malicious code, via the outbound e-mail message.

AI classification

Planning0.98
Knowledge representation0.57
Vision0.02
Natural language0.02
Machine learning0.01
AI hardware0.01
Evolutionary computation0.00
Speech0.00

Ownership

SYMANTEC CORPORATION

assignment · 157240070

Assignors

SZOR, PETER, PERRIOT, FREDERIC

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC