IP Library Granted Patent US 8,621,077
Granted Patent B2
US 8,621,077 · App. 09/962,981 · Granted Dec 31, 2013

Distribution of security policies for small to medium-sized organizations

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,621,077
App. No.
09/962,981
Granted
Dec 31, 2013
Kind
B2
Abstract

A security policy distribution system encapsulates parameters for a security policy and instructions for applying the parameters to a corresponding security program into a self-contained configuration file. When the self-contained configuration file is executed on behalf of a computer, the corresponding security program on the computer is updated with the parameters, thus distributing the security policy to the computer.

Claims (43)

1. A method, comprising:

providing a configuration procedure for an antivirus program to determine which parameters of a security policy have changed;

creating a self-contained configuration file based on the changed security policy parameters and underlying security programs that are affected by the changed security policy parameters;

determining which of the underlying security programs are affected based on the determined changed security policy parameters;

encapsulating the changed parameters and execution instructions associated with the affected programs to create the self-contained configuration file;

providing the self-contained configuration file in an e-mail to be communicated over a network from a server to a client device for subsequent installation at the client device, wherein a login script, which was previously modified on the client device, is provided to search for updated self-contained configuration files as part of a client login procedure, and wherein detection of the updated self-contained configuration files results in an application of particular parameters of the updated self-contained configuration files being applied against corresponding security software of the client device to replicate the security policy, and wherein the self-contained configuration file includes a first instruction that renders the self-contained configuration file unusable by the client device after a certain period of time, and wherein the self-contained configuration file includes a second instruction for deleting the self-contained configuration file once it is executed; and

receiving an error message if the self-contained configuration file is not installed on the client device.

2. The method of claim 1 , wherein the self-contained configuration file is downloadable from a first computer to a second computer for execution.

3. The method of claim 1 further comprising:

storing the self-contained configuration file in a database.

4. The method of claim 1 , wherein a policy script that executes a subsequent self-contained configuration file is provided as part of an operating system task schedule.

5. The method of claim 1 , wherein the self-contained configuration file is one of an executable file, a registry file, and an extensible markup language file.

6. Computer executable instructions embodied in non-transitory computer readable media for execution in conjunction with a processor, the instructions being configured for performing operations, comprising:

providing a configuration procedure for an antivirus program to determine which parameters of a security policy have changed;

creating a self-contained configuration file based on the changed security policy parameters and underlying security programs that are affected by the changed security policy parameters;

determining which of the underlying security programs are affected based on the determined changed security policy parameters;

encapsulating the changed parameters and execution instructions associated with the affected programs to create the self-contained configuration file;

providing the self-contained configuration file in an e-mail to be communicated over a network from a server to a client device for subsequent installation at the client device, wherein a login script, which was previously modified on the client device, is provided to search for updated self-contained configuration files as part of a client login procedure, and wherein detection of the updated self-contained configuration files results in an application of particular parameters of the updated self-contained configuration files being applied against corresponding security software of the client device to replicate the security policy, and wherein the self-contained configuration file includes a first instruction that renders the self-contained configuration file unusable by the client device after a certain period of time, and wherein the self-contained configuration file includes a second instruction for deleting the self-contained configuration file once it is executed; and

receiving an error message if the self-contained configuration file is not installed on the client device.

7. The non-transitory computer-readable media of claim 6 , the operations further comprising:

storing the self-contained configuration file in a database.

8. A system comprising:

a processor;

a memory coupled to the processor through a bus, wherein the system is configured to: provide a configuration procedure for an antivirus program to determine which parameters of a security policy have changed;

create a self-contained configuration file based on the changed security policy parameters and underlying security programs that are affected by the changed security policy parameters;

determine which of the underlying security programs are affected based on the determined changed security policy parameters;

encapsulate the changed parameters and execution instructions associated with the affected programs to create the self-contained configuration file;

provide the self-contained configuration file in an e-mail to be communicated over a network from a server to a client device for subsequent installation at the client device, wherein a login script, which was previously modified on the client device, is provided to search for updated self-contained configuration files as part of a client login procedure, and wherein detection of the updated self-contained configuration files results in an application of particular parameters of the updated self-contained configuration files being applied against corresponding security software of the client device to replicate the security policy, and wherein the self-contained configuration file includes a first instruction that renders the self-contained configuration file unusable by the client device after a certain period of time, and wherein the self-contained configuration file includes a second instruction for deleting the self-contained configuration file once it is executed; and

receive an error message if the self-contained configuration file is not installed on the client device.

9. The system of claim 8 further comprising a network interface coupled to the processor through the bus.

10. The method of claim 1 , wherein the self-contained configuration file is determined to be uncontaminated before applying certain parameters of the security policy to the antivirus program.

11. The method of claim 1 , wherein certain parameters of the security policy include parameters that have changed since a previous self-configuration file was created.

12. The method of claim 4 , wherein the self-contained configuration file is manually stored on the server.

13. The method of claim 1 , wherein the application of the parameters of the security policy to the antivirus program installed on the client device is performed as a background task.

14. The method of claim 1 , further comprising:

storing the self-contained configuration file on the server for subsequent downloading by a plurality of devices.

15. The method of claim 1 , wherein the self-contained configuration file can be propagated between the client device and a peer client device in order to replicate the security policy at the peer client device.

16. The non-transitory computer-readable media of claim 6 , wherein a policy script that executes a subsequent self-contained configuration file is provided as part of an operating system task schedule.

17. The non-transitory computer-readable media of claim 6 , wherein the self-contained configuration file is one of an executable file, a registry file, and an extensible markup language file.

18. The non-transitory computer-readable media of claim 6 , wherein the application of the parameters of the security policy to the antivirus program installed on the client device is performed as a background task.

19. The non-transitory computer-readable media of claim 6 , the operations further comprising:

storing the self-contained configuration file on the server for subsequent downloading by a plurality of devices.

20. The non-transitory computer-readable media of claim 6 , wherein the self-contained configuration file can be propagated between the client device and a peer client device in order to replicate the security policy at the peer client device.

Assignments (22)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
MERGER Recorded Jun 23, 2005
From: NETWORKS ASSOCIATES TECHNOLOGY, INC.
To: MCAFEE, INC.
Reel/Frame 016646/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 21, 2001
From: HINCHLIFFE, ALEX; HOWARD, FRASER; RAI, BOBBY; KEMP, ANDREW
To: NETWORKS ASSOCIATES TECHNOLOGY, INC.
Reel/Frame 012205/0962 →