IP Library Granted Patent US 10,599,662
Granted Patent B2
US 10,599,662 · App. 14/751,560 · Granted Mar 24, 2020

Query engine for remote endpoint information retrieval

Inventors: Leandro Ignacio Costantino (Cabalango, AR); Cristian A. Sanchez (Córdoba, AR); Juan M. Olle (Córdoba, AR); Diego Naza Pamio (Córdoba, AR)
Assignee: McAfee, LLC
G06F16/2471G06F16/245
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,599,662
App. No.
14/751,560
Granted
Mar 24, 2020
Kind
B2
Abstract

Embodiments are disclosed herein for remote retrieval of information from endpoints and comprise receiving a master query at an endpoint in a network environment and executing a set of one or more subqueries defined in the master query. Embodiments also comprise an execution of a first subquery that includes executing a function to produce a first output, applying one or more conditions to the first output to determine a second output, and determining a result of the master query based, at least in part, on the second output. In specific embodiments, the master query is received from another node over a network connection. In more specific embodiments, the function is executed on the endpoint to collect real-time information based on one or more parameters. In further embodiments, the function is one of a plug-in or a script.

Claims (59)

1. At least one machine readable storage medium comprising instructions that, when executed by at least one processor, cause the at least one processor to:

receive a master query by a query engine in an endpoint in a network environment from a query service via a network of the environment;

execute a set of one or more subqueries defined in the master query, wherein an execution of a first subquery of the set of one or more subqueries is to include:

causing a first function to execute on the endpoint to collect data associated with the endpoint and produce a first output based on the collected data;

applying one or more conditions to the first output to determine a first result; and

determining a result of the master query based, at least in part, on the first result; and

responsive to the result of the master query indicating the endpoint is compromised, cause a script to be executed by the endpoint to perform a remedial action on the endpoint, wherein the remedial action performed includes one or more of: removing a file, deleting a file, terminating a process, rebooting, and shutting down.

2. The at least one machine readable storage medium according to claim 1 , wherein the master query is received from another node over a network connection.

3. The at least one machine readable storage medium according to claim 1 , wherein the data includes real-time information that is collected based on one or more parameters.

4. The at least one machine readable storage medium according to claim 1 , wherein the first function is one of a plug-in or a script.

5. The at least one machine readable storage medium according to claim 1 , wherein the applying the one or more conditions to the first output includes filtering the first output to determine the first result.

6. The at least one machine readable storage medium according to claim 1 , wherein the instructions, when executed by the at least one processor, cause the at least one processor to:

determine a type of action indicated in the master query; and

generate the set of one or more subqueries to be executed based, at least in part, on the type of action.

7. The at least one machine readable storage medium according to claim 6 , wherein the type of action is one of a search, a trigger, or a response.

8. The at least one machine readable storage medium according to claim 1 , wherein an execution of a second subquery of the set of one or more subqueries is to include:

causing a second function to execute on the endpoint to produce a second output; and

applying one or more other conditions to the second output to determine a second result, wherein the result of the master query is determined, at least in part, by evaluating the first and second results according to a logical operator.

9. The at least one machine readable storage medium according to claim 8 , wherein the first function and the second function are to perform different operations on the endpoint.

10. The at least one machine readable storage medium according to claim 1 , wherein the applying the one or more conditions to the first output is to include:

applying a first condition to the first output to determine a first condition result;

applying a second condition to the first output to determine a second condition result; and

determining a condition chain result based, at least in part, on the first condition result, the second condition result and a condition operator.

11. The at least one machine readable storage medium according to claim 1 , wherein the first result includes at least one string of information in the data returned from the first function.

12. The at least one machine readable storage medium according to claim 11 , wherein the first result is filtered to exclude at least some information from the string of information.

13. The at least one machine readable storage medium according to claim 1 , wherein the result of the master query is communicated to a query service in another node.

14. The at least one machine readable storage medium according to claim 1 , wherein the master query comprises:

a plurality of query chains including a first query chain, the first query chain including the set of one or more subqueries; and

a query chain operator, wherein the master query result is determined using the query chain operator to evaluate query chain results of the plurality query chains.

15. An apparatus, the apparatus being an endpoint in a network environment and comprising:

at least one processor;

a query engine operable to run on the at least one processor to:

receive a master query from a query service via a network of the network environment;

execute a set of one or more subqueries defined in the master query, wherein an execution of a first subquery of the set of one or more subqueries is to include:

causing a first function to execute to collect data associated with the apparatus and produce a first output based on the collected data;

applying one or more conditions to the first output to determine a first result; and

determining a result of the master query based, at least in part, on the first result; and

responsive to the result of the master query indicating the endpoint is compromised, cause a script to be executed by the endpoint to perform a remedial action on the endpoint, wherein the remedial action performed includes one or more of: removing a file, deleting a file, terminating a process, rebooting, and shutting down.

16. The apparatus of claim 15 , wherein the data includes real-time information that is collected based on one or more parameters.

17. The apparatus of claim 15 , wherein the applying the one or more conditions to the first output includes filtering the first output to determine the first result.

18. The apparatus of claim 15 , wherein the query engine operable to run on the at least one processor to:

execute a second function on the endpoint if the master query result indicates the endpoint is compromised.

19. The apparatus of claim 15 , wherein an execution of a second subquery of the set of one or more subqueries is to include:

causing a second function to execute to produce a second output;

applying one or more other conditions to the second output to determine a second result, wherein the result of the master query is determined, at least in part, by evaluating the first and second results according to a query operator.

20. The apparatus of claim 19 , wherein the first function and the second function are to perform different operations on the endpoint.

21. The apparatus of claim 15 , wherein the applying the one or more conditions to the first output is to include:

applying a first condition to the first output to determine a first condition result;

applying a second condition to the first output to determine a second condition result; and

determining the condition chain result based on the first condition result, the second condition result and a logical operator.

22. A method, the method comprising:

receiving a master query by a query engine of an endpoint in a network environment from a query service via a network of the environment;

executing a set of one or more subqueries defined in the master query, wherein an execution of a first subquery of the set of one or more subqueries is to include:

causing a first function to execute on the endpoint to collect data associated with the endpoint and produce a first output based on the collected data;

applying one or more conditions to the first output to determine a first result; and

determining a result of the master query based, at least in part, on the first result; and

responsive to the result of the master query indicating the endpoint is compromised, causing a script to be executed by the endpoint to perform a remedial action on the endpoint, wherein the remedial action performed includes one or more of: removing a file, deleting a file, terminating a process, rebooting, and shutting down.

23. The method of claim 22 , wherein the data includes real-time information that is collected based on one or more parameters.

24. The method of claim 22 , wherein the applying the one or more conditions to the first output includes filtering the first output to determine the first result.

Assignments (22)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 059249/0965 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2015
From: COSTANTINO, LEANDRO IGNACIO; SANCHEZ, CRISTIAN A.; OLLE, JUAN M.; PAMIO, DIEGO NAZA
To: MCAFEE, INC.
Reel/Frame 035914/0165 →
Continuity (1)
Related Publication 20160381121A1 · Dec 29, 2016
Cited By (13)
US 12,204,536 US 12,204,593 US 12,248,484 US 12,265,525 US 12,271,389 US 12,287,790 US 12,393,631 US 12,436,963 US 12,585,638 US 12,613,864 US 12,639,379 US 12,650,965 US 12,670,152