IP Library Granted Patent US 8,955,036
Granted Patent B2
US 8,955,036 · App. 13/444,281 · Granted Feb 10, 2015

System asset repository management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,955,036
App. No.
13/444,281
Granted
Feb 10, 2015
Kind
B2
Abstract

A plurality of system entities described in an asset repository are identified, the asset repository defining a particular hierarchical organization of the plurality of system entities within a computing environment. A particular system entity in the plurality of system entities is tagged with a particular tag. The particular system entity is associated with a particular security policy based on the particular system entity being tagged with the particular tag. The particular security policy is applied to system entities in the asset repository tagged with one or more tags in a particular set of tags including the particular tag.

Claims (41)

1. At least one non-transitory, machine-accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

identify a plurality of system entities described in an asset repository, the asset repository defining a particular hierarchical organization of the plurality of system entities within a computing environment;

receive data describing one or more attributes of a particular system entity in the plurality of system entities identified by a first pluggable discovery sensor in a set of discovery sensors of a pluggable asset detection engine;

tag a particular record of the asset repository corresponding to the particular system entity in the plurality of system entities with a particular tag based on the one or more attribute, wherein the particular tag associates the particular system entity with a particular one of a plurality of logical groupings defined for system entities in the plurality of system entities; and

associate the particular system entity with a particular security policy based on the particular system entity being tagged with the particular tag, wherein the particular security policy is applied to system entities in the asset repository tagged with one or more tags in a particular set of tags including the particular tag and the particular security policy is to apply to each system entity in the particular logical grouping.

2. The storage medium of claim 1 , wherein the logical groupings are different from associations defined in the particular hierarchical organization.

3. The storage medium of claim 1 , wherein the instructions, when executed, further cause the machine to identify one or more attributes of the particular system entity, wherein the particular system entity is tagged with the particular tag based at least in part on the one or more identified attributes.

4. The storage medium of claim 3 , wherein the one or more attributes are identified using one or more asset detection engines deployed within the computing environment.

5. The storage medium of claim 4 , wherein the asset detection engine is a pluggable asset detection engine including a set of pluggable discovery sensors, wherein the pluggable discovery sensors enable identification of the attributes by the asset detection engine.

6. The storage medium of claim 5 , wherein the pluggable discovery sensors include one or more passive discovery sensors adapted to identify attributes of the particular system entity without communicating with the particular system entity.

7. The storage medium of claim 6 , wherein the pluggable discovery sensors further include active discovery sensors adapted to send data to the particular system entity and monitor responses to the sent data by the particular system entity.

8. The storage medium of claim 6 , wherein the passive discovery sensors include at least one of a latent-type discovery sensor, event-based discovery sensor, and indirect-type discovery sensor.

9. The storage medium of claim 3 , wherein the attributes include at least one of address information, operating systems, active ports, and applications of the particular system entity.

10. The storage medium of claim 1 , wherein the tagging is performed by a user.

11. The storage medium of claim 1 , wherein each system entity in the plurality of system entities is of a type from a set including network-type entities, system-type entities, person-type entities, and application-type entities.

12. The storage medium of claim 11 , wherein the particular hierarchical organization defines system-type entities as children of network-type entities, person-type entities as children of system-type entities, and application-type entities as children of system-type entities.

13. The storage medium of claim 11 , wherein the particular tag is a type-specific tag.

14. The storage medium of claim 11 , wherein entities of different types can be tagged with the particular tag.

15. The storage medium of claim 1 , wherein applying the particular security policy includes causing the particular security policy to be enforced for each of system entities tagged with one or more of the particular set of tags.

16. The storage medium of claim 15 , wherein the particular security policy is enforced on the particular system entity using an agent on the particular system entity.

17. The storage medium of claim 15 , wherein the particular security policy is enforced for the particular system entity using network security components remote from the particular system entity.

18. The storage medium of claim 17 , wherein the network security component includes at least one of a firewall, a web gateway, a mail gateway, a host intrusion protection (HIP) tool, a network intrusion protection (NIP) tool, an anti-malware tool, a data loss prevention (DLP) tool, a system vulnerability manager, a system policy compliance manager, an asset criticality tool, and a security information management (SIM) tool of the computing environment.

19. The storage medium of claim 1 , wherein applying the particular security policy includes causing a patch to be downloaded on each of system entities tagged with one or more of the particular set of tags.

20. A method comprising:

identifying a plurality of system entities described in an asset repository, the asset repository defining a particular hierarchical organization of the plurality of system entities within a computing environment;

tagging a particular record of the asset repository corresponding to the particular system entity in the plurality of system entities with a particular tag based on the one or more attribute, wherein the particular tag associates the particular system entity with a particular one of a plurality of logical groupings defined for system entities in the plurality of system entities; and

associating the particular system entity with a particular security policy based on the particular system entity being tagged with the particular tag, wherein the particular security policy is applied to system entities in the asset repository tagged with one or more tags in a particular set of tags including the particular tag and the particular security policy is to apply to each system entity in the particular logical grouping.

21. A system comprising:

at least one processor device;

at least one memory element; and

an asset management system, adapted when executed by the at least one processor device to:

identify a plurality of system entities described in an asset repository, the asset repository defining a particular hierarchical organization of the plurality of system entities within a computing environment;

receive data describing one or more attributes of a particular system entity in the plurality of system entities identified by a first pluggable discovery sensor in a set of discovery sensors of a pluggable asset detection engine;

tag a particular record of the asset repository corresponding to the particular system entity in the plurality of system entities with a particular tag based on the one or more attribute, wherein the particular tag associates the particular system entity with a particular one of a plurality of logical groupings defined for system entities in the plurality of system entities; and

associate the particular system entity with a particular security policy based on the particular system entity being tagged with the particular tag, wherein the particular security policy is applied to system entities in the asset repository tagged with one or more tags in a particular set of tags including the particular tag and the particular security policy is to apply to each system entity in the particular logical grouping.

22. The system of claim 21 , further comprising a pluggable asset detection engine including a set of pluggable discovery sensors, the pluggable asset detection engine adapted when executed by the at least one processor device to:

identify an attribute of the particular system entity using a first pluggable discovery sensor in the set of discovery sensors; and

send an identification of the particular attribute to the asset management system,

wherein tagging of the particular record corresponding to the particular system entity is based at least in part on the identified attribute.

23. The system of claim 21 , wherein the particular system entity is one of a human user of the computing environment, an executable application in the computing environment, or a hardware system entity in the computing environment.

24. The system of claim 21 , wherein the set of pluggable discovery sensors comprise one or more passive discovery sensors and one or more active discovery sensors.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2012
From: HUGARD, JAMES MICHAEL, IV; KEIR, ROBIN; REBELO, JOSHUA CAJETAN; ARKIN, OFIR
To: MCAFEE, INC.
Reel/Frame 028028/0147 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2012
From: HUGARD, JAMES MICHAEL, IV; KEIR, ROBIN; REBELO, JOSHUA CAJETAN; ARKIN, OFIR; SCHRECKER, SVEN
To: MCAFEE, INC.
Reel/Frame 028028/0399 →