IP Library Granted Patent US 7,793,338
Granted Patent B1
US 7,793,338 · App. 10/970,033 · Granted Sep 7, 2010

System and method of network endpoint security

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,793,338
App. No.
10/970,033
Granted
Sep 7, 2010
Kind
B1
Abstract

A system and a method enhance endpoint security of a computer network. The system and method generate security assessments of hosts on quarantined and non-quarantined networks. Based on the generated security assessments, secure hosts are connected to the non-quarantined network and non-secure or vulnerable hosts are connected to the quarantined network. A remediation engine assists with fixing vulnerabilities of the hosts on the quarantined network. Endpoint security agents, security scanners, and remediation engines that carry out the foregoing functions reside on each of the quarantined and non-quarantined networks on hosts that are different from the target hosts. Under such an architecture, the endpoint security system can advantageously be operating system agnostic and can provide complete and powerful endpoint security for targeted hosts without being installed on each individual targeted host. Alternatively, endpoint security agents, security scanners, and remediation agents can reside partially or wholly on one or more target hosts.

Claims (35)

1. An endpoint security system configured to reside on a quarantined virtual local area network and to manage the connection of a host to either the quarantined virtual local area network or to a non-quarantined virtual area network based on a security assessment of the added host, the endpoint security system comprising:

a security scanner configured to perform a security assessment on the host;

a dynamic host configuration protocol server configured to assign Internet Protocol addresses to hosts added to the quarantined virtual local area network; and

an endpoint security agent configured to:

extract, from at least one packet sent by the dynamic host configuration protocol server, an Internet Protocol address that has been assigned to a host added to the quarantined virtual local area network;

forward the extracted Internet Protocol address to the security scanner and cause the security scanner to perform a security assessment on the added host by scanning the added host, wherein the security scanner is located on a security engine on which the endpoint security agent is located;

receive the security assessment; and

cause a switch to connect the added host to the non-quarantined virtual local area network if, based on the security assessment of the added host, the added host is deemed to be a secure host.

2. The endpoint security system of claim 1 , wherein the security assessment is performed based, at least in part, on whether the host is vulnerable to a number of known viruses and on which ports of the host are open.

3. The endpoint security system of claim 2 , wherein the system is operable such that a remediation engine is configured to help fix at least one vulnerability of the vulnerable host by accessing the vulnerable host and executing an application that points a user to at least one resource for fixing the at least one vulnerability.

4. The endpoint security system of claim 3 , wherein the application includes a web browser.

5. The endpoint security system of claim 3 , wherein the at least one resource includes a patch management system.

6. The endpoint security system of claim 3 , wherein the remediation engine is configured to help fix the at least one vulnerability of the vulnerable host by causing a web browser launched by the user on the vulnerable host to be redirected to the at least one resource for fixing the at least one vulnerability.

7. The endpoint security system of claim 3 , wherein the remediation engine manages all remedial measures without receiving direction from the security engine.

8. The endpoint security system of claim 1 , wherein the security scanner is further configured to periodically generate a follow-up security assessment of a quarantined host and wherein the endpoint security agent is further configured to receive each follow-up security assessment and to cause the switch to connect the quarantined host to a non-quarantined virtual local area network if, based on at least one follow-up security assessment, the quarantined host is deemed to be a secure host.

9. The endpoint security system of claim 1 , further comprising causing the switch to direct a connection of the host to the quarantined virtual local area network if, based on at least a portion of the security assessment, the host is deemed to be a vulnerable host.

10. The endpoint security system of claim 9 , wherein causing the switch to direct the connection of the host to the quarantined virtual local area network includes leaving the host connected to the quarantined virtual local area network if the host is already connected to the quarantined virtual local area network.

11. The endpoint security system of claim 1 , wherein a remediation of at least one vulnerability of the host is managed.

12. A method, comprising:

performing, by a security scanner, a security assessment on a host; and

assigning, by a dynamic host configuration protocol server, Internet Protocol addresses to hosts added to a quarantined virtual local area network;

extracting, by an endpoint security agent, from at least one, packet sent by the dynamic host configuration protocol server, an Internet Protocol address that has been assigned to a host added to the quarantined virtual local area network;

forwarding, by the endpoint security agent, the extracted Internet Protocol address to the security scanner and cause the security scanner to perform a security assessment on the added host by scanning the added host, wherein the security scanner is located on a security engine on which the endpoint security agent is located;

receiving, by the endpoint security agent, the security assessment; and

causing, by the endpoint security agent, a switch to connect the added host to a non-quarantined virtual local area network if, based on the security assessment of the added host, the added host is deemed to be a secure host.

13. The method of claim 12 , wherein the security assessment is performed based, at least in part, on whether the host is vulnerable to a number of known viruses and on which ports of the host are open.

14. The method of claim 12 , wherein the security scanner is further configured to periodically generate a follow-up security assessment of a quarantined host and wherein the endpoint security agent is further configured to receive each follow-up security assessment and to cause the switch to connect the quarantined host to a non-quarantined virtual local area network if, based on at least one follow-up security assessment, the quarantined host is deemed to be a secure host.

15. The method of claim 12 , wherein a remediation engine is configured to help fix at least one vulnerability of the vulnerable host by accessing the vulnerable host and executing an application that points a user to at least one resource for fixing the at least one vulnerability.

16. The method of claim 15 , wherein the application includes a web browser.

17. The method of claim 15 , wherein the at least one resource includes a patch management system.

18. The method of claim 15 , wherein the remediation engine is configured to help fix the at least one vulnerability of the vulnerable host by causing a web browser launched by the user on the vulnerable host to be redirected to the at least one resource for fixing the at least one vulnerability.

19. The method of claim 15 , wherein the remediation engine manages all remedial measures without receiving direction from the security engine.

20. The method of claim 12 , further comprising directing a connection of the host to the quarantined virtual local area network if, based on at least a portion of the security assessment, the host is deemed to be a vulnerable host.

21. The method of claim 12 , wherein the directing of the connection of the host to the quarantined virtual local area network includes leaving the host connected to the quarantined virtual local area network if the host is already connected to the quarantined virtual local area network.

22. The method of claim 12 , wherein a remediation of at least one vulnerability of the host is managed.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →