IP Library Granted Patent US 11,416,606
Granted Patent B2
US 11,416,606 · App. 15/513,783 · Granted Aug 16, 2022

Agent presence for self-healing

Inventors: Shashin Thakur (Ahmedabad, IN); Arvind K. Boggarapu (Benagaluru, IN); Harvir Singh (Portland, OR)
Assignee: Musarubra US LLC
G06F21/554G06F21/55G06F21/552G06F21/566G06F21/575G06F21/577H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/1458H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,416,606
App. No.
15/513,783
Granted
Aug 16, 2022
Kind
B2
Abstract

In one or more examples, there is disclosed a system and method of detecting agent presence for self-healing. An out-of-band monitoring process, such as Intel® AMT, or any process in firmware executing on a co-processor, may monitor one or more processes to determine if one goes down or otherwise meets a security criterion. Crashed processes may be reported to an enterprise security controller (ESC). The ESC may notice trends among affected machines and instruct the machines to take appropriate remedial action, such as booting from a remedial image.

Claims (38)

1. An enterprise security controller to provide security to an enterprise, comprising:

a processor and memory;

a network interface; and

executable instructions encoded within the memory to provide a security engine configured to

receive via the network interface a plurality of reports of security events from a plurality of client devices, the security events indicating that a plurality of malfunctions or crashes of an application has occurred across the plurality of client devices of the enterprise, wherein the application is indicated in a defined security policy;

perform a determination from the reports that the plurality of malfunctions or crashes occurred within a predetermined time; and

instruct, based on the determination, at least one of the plurality of client devices to take a remedial action, wherein the remedial action comprises causing the at least one of the plurality of client devices to boot the at least one of the plurality of client devices from a remediation image.

2. The enterprise security controller of claim 1 , wherein one of the security events comprises detecting that a monitored process uses excessive system resources.

3. The enterprise security controller of claim 1 , wherein one of the security events comprises detecting a change of process identifier for a monitored process.

4. The enterprise security controller of claim 1 , wherein one of the security events comprises detecting removal or uninstallation of a monitored application.

5. The enterprise security controller of claim 1 , wherein one of the security events comprises detecting a system resource leak from a monitored process.

6. The enterprise security controller of claim 1 , wherein the remedial action comprises causing the at least one of the plurality of client devices to reinstall a monitored application.

7. The enterprise security controller of claim 1 , wherein the remedial action comprises causing the at least one of the plurality of client devices to restart a monitored process.

8. The enterprise security controller of claim 1 , wherein the remedial action comprises causing the at least one of the plurality of client devices to run a diagnostic command.

9. The enterprise security controller of claim 1 , wherein the remedial action comprises causing the at least one of the plurality of client devices to reimage the at least one of the plurality of client devices with a clean operating system image.

10. One or more non-transitory, computer-readable mediums having stored thereon executable instructions to instruct a processor to provide a security server engine to provide security to an enterprise, the security server engine configured to:

receive via a network interface a plurality of reports of security events from a plurality of client devices, the security events indicating that a plurality of malfunctions or crashes of an application has occurred across the plurality of client devices of the enterprise, wherein the application is indicated in a defined security policy;

perform a determination from the reports that the plurality of malfunctions or crashes has occurred within a designated period; and

instruct, based on the determination, at least one of the plurality of client devices to take a remedial action, wherein the remedial action comprises causing the at least one of the plurality of client devices to boot the at least one of the plurality of client devices from a remediation image.

11. The one or more computer-readable mediums of claim 10 , wherein one of the security events comprises detecting that a monitored process uses excessive system resources.

12. The one or more computer-readable mediums of claim 10 , wherein one of the security events comprises detecting a change of process identifier for a monitored process.

13. The one or more computer-readable mediums of claim 10 , wherein one of the security events comprises detecting removal or uninstallation of a monitored application.

14. The one or more computer-readable mediums of claim 10 , wherein one of the security events comprises detecting an error in a monitored process.

15. The one or more computer-readable mediums of claim 10 , wherein one of the security events comprises detecting a system resource leak from a monitored process.

16. The one or more computer-readable mediums of claim 10 , further comprising:

a machine learning engine configured to detect and avoid false positives based on historical data.

17. The enterprise security controller of claim 1 , wherein the security engine is further configured to enforce a security policy.

18. The enterprise security controller of claim 1 , further comprising:

a machine learning engine configured to receive feedback to determine whether the at least one of the plurality of client devices hosted malware.

19. The enterprise security controller of claim 1 , wherein the remedial action comprises placing at least one of the plurality of client devices in a protected subnetwork.

20. A method, comprising:

receiving via a network interface a plurality of reports of security events from a plurality of client devices of an enterprise, the security events indicating that a plurality of malfunctions or crashes of an application has occurred across the plurality of client devices, wherein the application is indicated in a defined security policy;

performing, via a security engine within an enterprise security controller (ESC), a determination from the reports that the plurality of malfunctions or crashes occurred within a predetermined time; and

instructing, based on the determination, via the security engine, at least one of the plurality of client devices to take a remedial action, wherein the remedial action comprises causing the at least one of the plurality of client devices to boot the at least one of the plurality of client devices from a remediation image.

21. The method of claim 20 , wherein one of the security events comprises detecting that a monitored process uses excessive system resources, detecting a change of process identifier for a monitored process, detecting removal or uninstallation of a monitored application, detecting an error in a monitored process, or detecting a system resource leak from a monitored process.

22. The method of claim 20 , wherein the remedial action comprises causing the at least one of the plurality of client devices to reinstall a monitored application, causing the at least one of the plurality of client devices to restart a monitored process, causing the at least one of the plurality of client devices to run a diagnostic command, causing the at least one of the plurality of client devices to reimage the at least one of the plurality of client devices with a clean operating system image, or placing at least one of the plurality of client devices in a protected subnetwork.

23. The method of claim 20 , further comprising:

determining, with a machine learning engine, whether the at least one of the plurality of client devices hosted malware, based on received feedback.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 059855/0807 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →