IP Library Granted Patent US 9,088,615
Granted Patent B1
US 9,088,615 · App. 12/183,628 · Granted Jul 21, 2015

Determining a reduced set of remediation actions for endpoint integrity

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,088,615
App. No.
12/183,628
Granted
Jul 21, 2015
Kind
B1
Abstract

In general, the disclosure relates to techniques for identifying a reduced set of remediation actions that are to be performed by a network endpoint to achieve compliance with a security policy defined by a network entity. One example method comprises receiving integrity data via a network from a network endpoint, performing a plurality of tests on the integrity data to generate corresponding test results, identifying a set of remediation actions based upon the test results, and comparing the remediation actions in the set. The method further comprises eliminating at least one remediation action in the set based upon the comparison to form a reduced set of remediation actions, and sending the reduced set of remediation actions to the network endpoint, wherein each remediation action in the reduced set specifies an action to be performed by the network endpoint to achieve compliance with a security policy.

Claims (49)

1. A method comprising:

receiving integrity data via a network from a network endpoint;

determining, by a plurality of verification modules and based upon one or more rules defined by a security policy, a plurality of verification tests for the integrity data, wherein the plurality of verification modules includes at least one of an operating system data verification module, a firewall data verification module, or an anti-virus data verification module;

performing, by the plurality of verification modules, the plurality of verification tests on the integrity data to generate a plurality of verification test results, wherein each verification module of the plurality of verification modules performs at least one verification test of the plurality of verification tests to generate at least one corresponding verification test result of the plurality of verification test results;

responsive to determining that at least two of the verification test results indicate a failure, identifying a set of remediation actions and associated weighting factors to achieve compliance with the security policy, wherein each remediation action in the set of remediation actions is associated with a weighting factor, and wherein each verification module of the plurality of verification modules that generates at least one corresponding verification test result indicating a failure is configured to identify at least one corresponding remediation action in the set of remediation actions and at least one associated weighting factor;

combining, using the one or more rules defined by the security policy, the at least two of the verification test results to obtain a combined result;

responsive to determining that the combined result indicates a failure:

comparing a first weighting factor associated with a first remediation action to a second weighting factor associated with a second remediation action, wherein the first remediation action and the second remediation action are each included in the set of remediation actions and are identified by the at least one of the operating system data verification module, the firewall data verification module, or the anti-virus data verification module; and

eliminating, based upon the comparison of the first weighting factor to the second weighting factor, at least the first remediation action from the set of remediation actions to form a reduced set of remediation actions, wherein the first remediation action is at least one of a conflicting or a redundant action with respect to the second remediation action, and wherein the reduced set of remediation actions includes the second remediation action but not the first remediation action; and

sending the reduced set of remediation actions to the network endpoint.

2. The method of claim 1 , wherein the reduced set of remediation actions comprises multiple remediation actions.

3. The method of claim 1 , wherein eliminating the first remediation action based upon the comparison of the first weighting factor to the second weighting factor comprises eliminating the first remediation action based upon the first weighting factor being greater than the second weighting factor.

4. The method of claim 1 , wherein eliminating the first remediation action based upon the comparison of the first weighting factor to the second weighting factor comprises eliminating the first remediation action based upon the first weighting factor being less than the second weighting factor.

5. The method of claim 1 , wherein:

receiving the integrity data comprises receiving the integrity data from one or more data collection modules on the network endpoint; and

performing the plurality of verification tests on the integrity data comprises performing a verification test on corresponding integrity data received from each individual data collection module to generate the corresponding verification test result.

6. The method of claim 1 , further comprising repeating the performing of the verification tests, the identifying of the set of remediation actions, the combining, the comparing, and the eliminating for multiple iterations to form the reduced set of remediation actions.

7. A non-transitory computer-readable storage medium comprising instructions that cause one or more processors to:

receive integrity data via a network from a network endpoint;

determine, by a plurality of verification modules and based upon one or more rules defined by a security policy, a plurality of verification tests for the integrity data, wherein the plurality of verification modules includes at least one of an operating system data verification module, a firewall data verification module, or an anti-virus data verification module;

perform, by the plurality of verification modules, the plurality of verification tests on the integrity data to generate a plurality of verification test results, wherein each verification module of the plurality of verification modules performs at least one verification test of the plurality of verification tests to generate at least one corresponding verification test result of the plurality of verification test results;

responsive to determining that at least two of the verification test results indicate a failure, identify a set of remediation actions and associated weighting factors to achieve compliance with the security policy, wherein each remediation action in the set of remediation actions is associated with a weighting factor, and wherein each verification module of the plurality of verification modules that generates at least one corresponding verification test result indicating a failure is configured to identify at least one corresponding remediation action in the set of remediation actions and at least one associated weighting factor;

combine, using the one or more rules defined by the security policy, the at least two of the verification test results to determine a combined result;

responsive to determining that the combined result indicates a failure:

compare a first weighting factor associated with a first remediation action to a second weighting factor associated with a second remediation action, wherein the first remediation action and the second remediation action are each included in the set of remediation actions and are identified by the at least one of the operating system data verification module, the firewall data verification module, or the anti-virus data verification module; and

eliminate, based upon the comparison of the first weighting factor to the second weighting factor, at least the first remediation action from the set of remediation actions to form a reduced set of remediation actions, wherein the first remediation action is at least one of a conflicting or a redundant action with respect to the second remediation action, and wherein the reduced set of remediation actions includes the second remediation action but not the first remediation action; and

send the reduced set of remediation actions to the network endpoint.

8. An apparatus comprising:

one or more computer processors; and

a non-transitory computer-readable storage medium configured to store a plurality of verification modules and an integrity evaluation module, wherein the plurality of verification modules includes at least one of an operating system data verification module, a firewall data verification module, or an anti-virus data verification module, and wherein the plurality of verification modules are executable by the one or more computer processors to:

receive integrity data via a network from a network endpoint;

determine, based upon one or more rules defined by a security policy, a plurality of verification tests for the integrity data;

perform the plurality of verification tests on the integrity data to generate a plurality of verification test results, wherein each verification module of the plurality of verification modules performs at least one verification test of the plurality of verification tests to generate at least one corresponding verification test result of the plurality of verification test results; and

responsive to determining that at least two of the verification test results indicate a failure, identify a set of remediation actions and associated weighting factors to achieve compliance with the security policy, wherein each remediation action in the set of remediation actions is associated with a weighting factor, and wherein each verification module of the plurality of verification modules that generates at least one corresponding verification test result indicating a failure is configured to identify at least one corresponding remediation action in the set of remediation actions and at least one associated weighting factor; and

wherein the integrity evaluation module is executable by the one or more computer processors to:

combine, using the one or more rules defined by the security policy, the at least two of the verification test results to determine a combined result;

responsive to determining that the combined result indicates a failure:

compare a first weighting factor associated with a first remediation action to a second weighting factor associated with a second remediation action, wherein the first remediation action and the second remediation action are each included in the set of remediation actions and are identified by the at least one of the operating system data verification module, the firewall data verification module, or the anti-virus data verification module; and

eliminate, based upon the comparison of the first weighting factor to the second weighting factor, at least the first remediation action from the set of remediation actions to form a reduced set of remediation actions, wherein the first remediation action is at least one of a conflicting or a redundant action with respect to the second remediation action, and wherein the reduced set of remediation actions includes the second remediation action but not the first remediation action; and

send the reduced set of remediation actions to the network endpoint.

9. The apparatus of claim 8 , wherein the reduced set of remediation actions comprises multiple remediation actions.

10. The apparatus of claim 8 , wherein the integrity evaluation module is configured to eliminate the first remediation action based upon the comparison of the first weighting factor to the second weighting factor at least by eliminating the first remediation action based upon the first weighting factor being greater than the second weighting factor.

11. The apparatus of claim 8 , wherein the integrity evaluation module is configured to eliminate the first remediation action based upon the comparison of the first weighting factor to the second weighting factor at least by eliminating the first remediation action based upon the first weighting factor being less than the second weighting factor.

12. The apparatus of claim 8 , wherein:

the one or more verification modules are configured to receive the integrity data at least by receiving the integrity data from one or more data collection modules on the network endpoint; and

the one or more verification modules are configured to perform the plurality of verification tests on corresponding integrity data at least by performing a verification test on the integrity data received from each individual data collection module to generate the corresponding verification test result.

13. The apparatus of claim 8 , wherein:

the one or more verification modules are configured to repeat the performing of the verification tests and the identifying of the set of remediation actions for multiple iterations; and

the integrity evaluation module is configured to repeat the comparing and the eliminating for multiple iterations to form the reduced set of remediation actions.

Assignments (16)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY 14633493 WHICH WAS ENTERED INCORRECTLY AS 14633793 PREVIOUSLY RECORDED ON REEL 71176 FRAME 315. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST LIEN NEWCO SECURITY AGREEMENT. Recorded Nov 10, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 073818/0515 →
FIRST LIEN NEWCO SECURITY AGREEMENT Recorded May 5, 2025
From: PULSE SECURE, LLC; IVANTI, INC.; IVANTI US LLC; IVANTI SECURITY HOLDINGS LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071176/0315 →
SECURITY INTEREST Recorded May 3, 2025
From: PULSE SECURE LLC
To: ALTER DOMUS (US) LLC
Reel/Frame 071165/0027 →
NOTICE OF SUCCESSION OF AGENCY FOR SECURITY INTEREST AT REEL/FRAME 054665/0873 Recorded Apr 29, 2025
From: BANK OF AMERICA, N.A., AS RESIGNING AGENT
To: ALTER DOMUS (US) LLC, AS SUCCESSOR AGENT
Reel/Frame 071123/0386 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; IVANTI, INC.; MOBILEIRON, INC.; IVANTI US LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 054665/0062 →
SECURITY INTEREST Recorded Dec 9, 2020
From: CELLSEC, INC.; PULSE SECURE, LLC; INVANTI, INC.; MOBILEIRON, INC.; INVANTI US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 054665/0873 →
RELEASE OF SECURITY INTEREST : RECORDED AT REEL/FRAME - 053638-0220 Recorded Dec 1, 2020
From: KKR LOAN ADMINISTRATION SERVICES LLC
To: PULSE SECURE, LLC
Reel/Frame 054559/0368 →
SECURITY INTEREST Recorded Aug 29, 2020
From: PULSE SECURE, LLC
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 053638/0220 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 042380/0859 Recorded Aug 29, 2020
From: CERBERUS BUSINESS FINANCE, LLC, AS AGENT
To: PULSE SECURE, LLC
Reel/Frame 053638/0259 →
RELEASE OF SECURITY INTEREST Recorded Jul 21, 2020
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
Reel/Frame 053271/0307 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL 037338, FRAME 0408 Recorded May 1, 2017
From: US BANK NATIONAL ASSOCIATION
To: PULSE SECURE, LLC
Reel/Frame 042381/0568 →
GRANT OF SECURITY INTEREST PATENTS Recorded May 1, 2017
From: PULSE SECURE, LLC
To: CERBERUS BUSINESS FINANCE, LLC, AS COLLATERAL AGENT
Reel/Frame 042380/0859 →
SECURITY INTEREST Recorded Dec 21, 2015
From: PULSE SECURE, LLC
To: U.S BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 037338/0408 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2014
From: JUNIPER NETWORKS, INC.
To: PULSE SECURE, LLC
Reel/Frame 034036/0904 →
SECURITY INTEREST Recorded Oct 23, 2014
From: PULSE SECURE, LLC; SMOBILE SYSTEMS, INC.
To: JUNIPER NETWORKS, INC.
Reel/Frame 034037/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 31, 2008
From: AVLASOV, YAN; ERICKSON, STEVEN
To: JUNIPER NETWORKS, INC.
Reel/Frame 021324/0298 →