IP Library Granted Patent US 9,998,478
Granted Patent B2
US 9,998,478 · App. 14/499,754 · Granted Jun 12, 2018

Enterprise-wide security for computer devices

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,998,478
App. No.
14/499,754
Granted
Jun 12, 2018
Kind
B2
Abstract

A system and method for securing data in mobile devices ( 104 ) includes a computing mode ( 102 ) and a plurality of mobile devices ( 104 ). A node security program ( 202 ) executed in the computing node ( 102 ) interfaces with a device security program ( 204 ) executed at a mobile device ( 104 ). The computing node ( 102 ) is responsible for managing the security based on a node security profile ( 208 ) interpreted by a node security program ( 202 ) executed in the computing node ( 102 ). A device discovery method and arrangement ( 106 ) also detects and locates various information ( 120 ) about the mobile devices ( 104 ) based on a scan profile ( 206 ).

Claims (72)

1. At least one non-transitory computer readable medium that includes code for execution and when executed by a processor:

scans a network based on a scan profile defining one or more parameters associated with at least one of domains and computing nodes in the network;

detects at least one domain on the network in accordance with at least one parameter defined in the scan profile;

detects at least one computing node within the detected domain;

connects to the detected computing node;

detects, using a discovery program, one or more mobile devices connected to the detected computing node; and

determines information associated with at least one mobile device of the detected mobile devices, wherein the information is to include a type of computing platform of the at least one mobile device, and wherein the type of computing platform of the at least one mobile device is determined by querying one or more application registries on the computing node.

2. The at least one non-transitory computer readable medium of claim 1 , wherein the discovery program is to run in at least one of a remote central station or a local computing node.

3. The at least one non-transitory computer readable medium of claim 1 , which includes further code for execution and when executed by a processor:

groups the detected mobile devices by type.

4. The at least one non-transitory computer readable medium of claim 1 , wherein the scan profile contains information associated with at least one of the network, the domains, an IP address, a netmask, and a computer identity to be scanned.

5. The at least one non-transitory computer readable medium of claim 1 , which includes further code for execution and when executed by a processor:

analyzes results of the scanning to produce an analysis result; and

displays the analysis result to at least one user.

6. The at least one non-transitory computer readable medium of claim 1 , which includes further code for execution and when executed by a processor:

detects one or more resource devices connected to the detected computing node; and

determines information associated with at least one of the detected resource devices.

7. The at least one non-transitory computer readable medium of claim 1 , which includes further code for execution and when executed by a processor:

determines at least one of a connection profile and a location of the at least one mobile device.

8. The at least one non-transitory computer readable medium of claim 1 , wherein the determining the information of the mobile device is based on at least one of a registry resource, a file resource, a process resource, a network management parameter, a communication protocol parameter, a data format, a packet format, a synchronization log entry, a directory structure and a database entry.

9. The at least one non-transitory computer readable medium of claim 1 , which includes further code for execution and when executed by a processor:

detects one or more mobile devices previously connected to the detected computing node; and

determines information associated with at least one of the one or more mobile devices previously connected to the detected computing node.

10. The at least one non-transitory computer readable medium of claim 9 , wherein the detecting is based, at least in part, on an imprint in a registry structure of the detected computing node, the imprint associated with the at least one mobile device previously connected to the detected computing node.

11. An apparatus, comprising:

a processor; and

a discovery program configured to run on the processor to:

scan a network based on a scan profile defining one or more parameters associated with at least one of domains and computing nodes in the network;

detect at least one domain on the network in accordance with at least one parameter defined in the scan profile;

detect at least one computing node within the detected domain;

connect to the detected computing node;

detect, using a discovery program, one or more mobile devices connected to the detected computing node; and

determine information associated with at least one mobile device of the detected mobile devices, wherein the information is to include a type of computing platform of the at least one mobile device, and wherein the type of computing platform of the at least one mobile device is determined by querying one or more application registries on the computing node.

12. The apparatus of claim 11 , wherein the apparatus is one of a remote central station or a local computing node.

13. The apparatus of claim 11 , wherein the discovery program is configured to run on the processor to:

determine at least one of a device type, a connection profile, and a location of the at least one mobile device.

14. The apparatus of claim 11 , wherein the discovery program is configured to run on the processor to:

detect one or more mobile devices previously connected to the detected computing node; and

determine information associated with at least one of the one or more mobile devices previously connected to the detected computing node.

15. The apparatus of claim 14 , wherein the detecting is based, at least in part, on an imprint in a registry structure of the detected computing node, the imprint associated with the at least one mobile device previously connected to the detected computing node.

16. A method for managing a computer system on a network, the method comprising:

scanning a network based on a scan profile defining one or more parameters associated with at least one of domains and computing nodes in the network;

detecting at least one domain on the network in accordance with at least one parameter defined in the scan profile;

detecting at least one computing node within the detected domain;

connecting to the detected computing node;

detecting, using a discovery program, one or more mobile devices connected to the detected computing node; and

determining information regarding at least one mobile device of the detected mobile devices, wherein the information includes a type of computing platform of the at least one mobile device, and wherein the type of computing platform of the at least one mobile device is determined by querying one or more application registries on the computing node.

17. The method of claim 16 , further comprising:

determining at least one of a device type, a connection profile, and a location of the at least one mobile device.

18. The method of claim 16 , further comprising:

detecting one or more mobile devices previously connected to the detected computing node; and

determining information associated with at least one of the one or more mobile devices previously connected to the detected computing node.

19. At least one non-transitory computer readable medium that includes code for execution and when executed by a processor:

scans a network based on a scan profile defining one or more parameters associated with at least one of domains and computing nodes in the network;

detects at least one domain on the network in accordance with at least one parameter defined in the scan profile;

detects at least one computing node within the detected domain;

connects to the detected computing node;

detects, using a discovery program, one or more mobile devices previously connected to the detected computing node, wherein the detection of the one or more mobile devices previously connected to the detected computing node is based, at least in part, on an imprint in a registry structure of the detected computing node, the imprint associated with at least one mobile device of the one or more mobile devices previously connected to the detected computing node; and

determines information associated with at least one of the one or more mobile devices previously connected to the detected computing node.

20. At least one non-transitory computer readable medium that includes code for execution and when executed by a processor:

scans a network based on a scan profile defining one or more parameters associated with at least one of domains and computing nodes in the network;

detects at least one domain on the network in accordance with at least one parameter defined in the scan profile;

detects at least one computing node within the detected domain;

connects to the detected computing node;

detects, using a discovery program, one or more mobile devices connected to the detected computing node;

determines information associated with at least one mobile device of the detected mobile devices, wherein the information is to include a type of computing platform of the at least one mobile device;

detects one or more other mobile devices previously connected to the detected computing node; and

determines information associated with at least one of the one or more other mobile devices previously connected to the detected computing node based on information obtained from the detected computing node.

21. The at least one non-transitory computer readable medium of claim 20 , wherein the detecting is based, at least in part, on an imprint in a registry structure of the detected computing node, the imprint associated with a mobile device of the one or more other mobile devices previously connected to the detected computing node.

22. The at least one non-transitory computer readable medium of claim 19 , which includes further code for execution and when executed by a processor:

analyzes at least one result of the scanning to produce an analysis result; and

displays the analysis result to at least one user.

Assignments (13)
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →